
Featured · client work
PIPEDA is the federal privacy law covering personal information collected in the course of commercial activity. A website privacy policy has to say what is collected, why, how it is used and shared, how long it is kept, how it is protected, how someone can see or correct their own information, and who is accountable for it.
This is a plain-language summary, not legal advice. Rules change and thresholds get revised, so confirm anything you are relying on against the regulator's own page.
Personal information includes anything that identifies a person, so it covers form submissions, email addresses, call recordings, booking systems, and in many readings the analytics and advertising identifiers dropped by third-party scripts. A policy that describes only the contact form while the site runs four tracking pixels is describing a fraction of what is happening.
Quebec, British Columbia, and Alberta have private-sector privacy laws recognised as substantially similar, and those apply to businesses operating within those provinces. Quebec's is now the strictest of the set. A business operating across provinces generally builds to the highest bar rather than maintaining several policies.
A breach creating a real risk of significant harm has to be reported to the federal Privacy Commissioner and to the affected individuals, as soon as feasible. Separately, records of every breach have to be kept for twenty-four months, including the ones judged minor. Most small businesses have neither the record nor the process until the day they need it.
The law requires an identifiable individual accountable for compliance, reachable through the policy. A generic info address with nobody behind it does not satisfy it, and it is the first thing a complaint tests.
Free written audit. No call required, no commitment, no upsell at the end.
Reply within two business days