Skip to content

Last updated

What does PIPEDA require in a small business privacy policy?

PIPEDA is the federal privacy law covering personal information collected in the course of commercial activity, at any business size. Its openness principle means a privacy policy has to say what personal information the business holds and how it is used, what goes to related companies, how someone can see their own information, and who is accountable for it.

This is a plain-language summary, not legal advice. Rules change and thresholds get revised, so confirm anything you are relying on against the sources listed with each answer.

It applies to more than the contact form

Personal information includes anything that identifies a person, so it covers form submissions, email addresses, call recordings, booking systems, and, in the Privacy Commissioner's view, the analytics and advertising identifiers dropped by third-party scripts. A policy that describes only the contact form while the site runs four tracking pixels is describing a fraction of what is happening.

The required list is short. A useful policy also says how long information is kept and how it is protected, which the law's retention and safeguards principles make the business decide anyway.

Some provinces have their own law

Quebec, British Columbia, and Alberta have private-sector privacy laws recognised as substantially similar, and those apply to businesses operating within those provinces. Ontario, New Brunswick, Newfoundland and Labrador, and Nova Scotia have the same status for health information, which is why an Ontario dental clinic answers to the provincial PHIPA for patient records. PIPEDA still covers information that crosses a provincial or national border, and federally regulated businesses everywhere. Quebec's law is now the strictest of the set, and a business operating across provinces generally builds to the highest bar rather than maintaining several policies.

The breach duty owners do not expect

A breach creating a real risk of significant harm has to be reported to the federal Privacy Commissioner and to the affected individuals, as soon as feasible. Separately, records of every breach have to be kept for twenty-four months, including the ones judged minor. Businesses under Alberta's or Quebec's law report to their own provincial commissioner instead. Most small businesses have neither the record nor the process until the day they need it.

Designate a person

The law requires the business to designate someone accountable for compliance, and to make that person's name or title available with an address people can write to. A role address works as long as someone real sits behind it, and the person's identity has to be given to anyone who asks. A generic info inbox that nobody owns does not satisfy it.

Start with the free audit.

Get a free audit

Send the link. We read the site by hand and write back inside five business days.

No call, no commitment