Almost certainly yes. If your website collects any personal information from a visitor, including a contact form, a newsletter signup, an ecommerce checkout, or analytics and advertising cookies, Canadian privacy law requires you to publish a privacy policy and make it easy to find. In Quebec it is an explicit statutory requirement. Everywhere else it is how you satisfy PIPEDA’s openness principle.

Last updated 23 September 2026. Written by Cody Wise, founder of Wise Media. This is general information, not legal advice. Verify your own obligations with counsel.

Summary

  • PIPEDA does not use the words “privacy policy.” It requires that your personal information practices be readily available and easy to understand. A published policy is how that obligation is met in practice.
  • Quebec is different. Section 8.2 of the Act respecting the protection of personal information in the private sector requires anyone collecting personal information through technological means to publish a confidentiality policy in clear and simple language.
  • Alberta and BC have their own statutes. Both PIPA regimes require a designated person responsible for compliance and written policies, with contact information made available.
  • Business contact information is carved out of PIPEDA when it is collected solely to communicate with someone about their job. A B2B site still usually collects more than that.
  • The OPC does not issue fines. It investigates, publishes findings and can refer matters to the Attorney General. Knowingly breaking the breach reporting and record-keeping rules is an offence carrying fines up to 100,000 CAD.
  • A generated template is a starting point, not compliance. The policy has to describe what your site actually does, including every third-party script you load.
Working through website documentation on a laptop beside printed paperwork in a window-lit cafe
The policy is the easy part. The inventory of what your site actually collects is the work.

Table of Contents

  • Does Canadian law actually require a privacy policy?
  • Which law applies to your business?
  • What has to be on the page
  • Cookies, analytics and advertising scripts
  • What happens if you get it wrong
  • Common mistakes
  • Frequently asked questions
  • The bottom line

Does Canadian Law Actually Require a Privacy Policy?

Yes in Quebec explicitly, and yes everywhere else in effect. The difference matters, because it changes what a good policy has to look like.

Federally: PIPEDA’s openness principle

The Personal Information Protection and Electronic Documents Act sets out ten fair information principles in Schedule 1. The eighth is Openness. The Office of the Privacy Commissioner states it plainly: your organization’s detailed personal information management practices must be clear and easy to understand, and they must be readily available.

The OPC’s guidance on fulfilling that responsibility lists six things you must provide in easy-to-understand terms: the name or title and contact information of the person accountable for your privacy policies, the name or title and contact information of the person to whom access requests should be sent, how an individual can gain access to their own personal information, how an individual can complain to your organization, any documents explaining your policies or codes, and a description of what personal information you disclose to other organizations including subsidiaries and third parties, and why.

The OPC also says this information should be available in a variety of ways, naming your organization’s website among them, and that the information presented should be consistent regardless of format. In practice that means one canonical policy page, linked from the footer of every page, and staff who can answer the same questions over the phone.

Quebec: an explicit publication requirement

Quebec is the one province where the obligation is written as a publication duty rather than an availability duty. Under section 8.2 of the provincial private sector privacy act, as amended by Law 25, anyone who collects personal information through technological means must publish a confidentiality policy drafted in clear and simple language. The policy must be published on the website and disseminated by any appropriate means, and a notice is required when it is amended.

If your organization has a privacy officer who is not the chief executive, their name, title and contact information also has to be published on the site. If you sell to Quebec customers, this binds you even if your office is in Calgary. We covered the related cookie banner mechanics in our guide to Law 25 cookie consent for Canadian websites.

Which Law Applies to Your Business?

PIPEDA applies to private sector organizations across Canada that collect, use or disclose personal information in the course of a commercial activity. Alberta, British Columbia and Quebec have their own private sector statutes that have been deemed substantially similar, so organizations subject to those laws are generally exempt from PIPEDA for activity that happens entirely inside that province.

The catch that most business owners miss: if the personal information crosses a provincial or national border in the course of commercial activity, PIPEDA applies regardless of where you are based. A Calgary business whose form submissions land in a US-hosted CRM is handling information that crossed a border.

Your situationWhat governs youPractical effect on the page
Business anywhere in Canada, data stays in one of Alberta, BC or QuebecThat province’s private sector actProvincial rules, plus the named-contact expectations
Data crosses a provincial or national borderPIPEDAOpenness principle, full ten principles
Anyone collecting from Quebec residents by technological meansQuebec section 8.2Published policy, clear and simple language, amendment notice
Bank, airline, telecom, broadcaster, interprovincial transportPIPEDA always, including employee dataHighest bar, employee information included
Business in NWT, Yukon or NunavutTreated as federally regulated, so PIPEDAPIPEDA applies
Registered charity or not-for-profit, no commercial activityGenerally outside PIPEDAStill publish one, for trust and for provincial exposure

What counts as personal information

Under PIPEDA, personal information is any factual or subjective information, recorded or not, about an identifiable individual. That reaches further than most website owners assume. Age, name, ID numbers, income, ethnic origin and blood type are on the OPC’s own list, and so are opinions, evaluations, comments, social status, and an individual’s intentions, including an intention to acquire goods or services.

That last item is worth reading twice. A form submission that says someone intends to buy from you is personal information about an identifiable individual. So is an IP address tied to a session in most analytics configurations.

The business contact information carve-out

PIPEDA does not cover business contact information such as an employee’s name, title, business address, telephone number or email address, when it is collected, used or disclosed solely to communicate with that person in relation to their employment or profession. B2B operators sometimes read this as a blanket exemption. It is not. The moment you enrich that record with behaviour, interests, buying signals or anything outside the job-communication purpose, the carve-out stops covering you.

What Has to Be On the Page?

A defensible Canadian privacy policy answers nine questions in plain language. Work through this as a checklist against your existing page.

  1. Who you are and who is accountable. Legal entity name, mailing address, and the name or title plus contact details of the person responsible for privacy compliance. A bare info@ address does not satisfy the OPC’s wording, which asks for a name or title.
  2. What you collect. Itemised, not categorised into vagueness. Form fields, account data, payment data, uploaded files, support tickets, call recordings, analytics identifiers, advertising identifiers.
  3. Why you collect it. PIPEDA’s second principle requires that purposes be identified at or before collection. Write the purpose next to the item, not in a separate paragraph.
  4. How consent works. Express or implied, how a person can withdraw it, and what happens to the service if they do.
  5. Who you share it with and why. Named third parties where possible: the CRM, the email platform, the payment processor, the ad networks, the hosting provider. The OPC asks for a description of what you disclose to other organizations, including subsidiaries and third parties, and why.
  6. Where the data lives. If your stack is US or EU hosted, say so and say that information stored outside Canada may be accessible to foreign authorities under that country’s law. Cross-border transfer is not prohibited, but it is a transparency obligation.
  7. How long you keep it. Retention periods by data type. “As long as necessary” is the sentence that gets a policy flagged as boilerplate.
  8. How you protect it. Safeguards proportionate to sensitivity. Encryption in transit, access controls, who inside the company can see what.
  9. How to access, correct and complain. Contact for access requests, your response timeline, and an explicit statement that the individual may escalate to the Office of the Privacy Commissioner of Canada or their provincial regulator if unsatisfied.

Where the page has to live

Readily available means reachable in one click from any page on the site. Standard practice, and the one we build by default into every website package: a footer link on every template, a link next to every form submit button, and a link inside the cookie banner. If your policy is only reachable from the homepage or is buried in a terms-of-service PDF, it is not readily available.

Two more build requirements that come from the same principle. The page should be a real page, not a modal, so it can be linked and cited. And it needs a visible last-updated date, because Quebec requires notice of amendments and because a policy with no date is indistinguishable from a policy nobody has read since it was pasted in.

If your site serves Quebec, the policy also falls inside the province’s language rules. We covered those in detail in does my website need to be in French.

Flat lay of a laptop, notebook, pen and phone on a desk, representing the script and data inventory behind a Canadian website privacy policy
Every third-party script on the page is a disclosure you owe the reader. Start with the network tab, not the copy.

Cookies, Analytics and Advertising Scripts

This is where most Canadian policies fail an audit, because the policy was written once and the marketing stack kept growing.

Run this audit before you touch the copy. Open your site in a clean browser profile, open the developer tools network tab, load the homepage and a form page, and list every third-party domain the page contacts. Then load the tag manager container and list every tag inside it, including the paused ones. Then check the theme and plugin list for anything that injects a pixel. The output of that exercise is the real list of who receives data from your website, and it is almost never the list in the current policy.

Script typeTypical examplesPolicy treatment
Strictly necessarySession, cart, CSRF, load balancingDisclose, no consent gate required
AnalyticsGA4, Plausible, Matomo, Clarity, HotjarDisclose, name the vendor, name the data region, consent required in Quebec
Advertising and retargetingGoogle Ads, Meta Pixel, LinkedIn Insight, TikTokDisclose, name each one, consent required, offer withdrawal
Session replay and heatmapsHotjar recordings, Clarity recordingsHighest sensitivity. Disclose explicitly and mask form fields at source
Embedded media and chatYouTube, Vimeo, Intercom, CalendlyDisclose as a third-party disclosure, not just as a feature

Session replay deserves its own line. A recording tool that captures keystrokes inside a form is collecting whatever the visitor typed, including the things they typed and then deleted. Mask input fields at the tool level rather than trusting a policy paragraph to cover it.

The CASL overlap nobody connects

Privacy law governs whether you may collect an email address. Canada’s Anti-Spam Legislation governs whether you may send to it. They are separate statutes with separate consent standards and separate penalty regimes, and a form that satisfies one can still breach the other. The classic failure is a pre-ticked newsletter checkbox on a quote request form: the privacy policy covers the collection, and the implied consent for the marketing send does not exist. We went through the form mechanics in is my website CASL compliant.

What Happens If You Get It Wrong?

Under PIPEDA as it stands, the Office of the Privacy Commissioner does not prosecute offences and does not issue fines. It investigates complaints, makes findings, and can refer information about a possible offence to the Attorney General of Canada, which could lead to prosecution by the Director of Public Prosecutions. Findings are published, which is its own commercial penalty.

The teeth are in the breach provisions. Since the mandatory breach reporting rules came into force, an organization must report any breach of security safeguards involving personal information under its control where it is reasonable to believe the breach creates a real risk of significant harm to an individual. Separately, you must keep a record of every breach, whether or not it met that threshold, for 24 months, in enough detail for the OPC to verify compliance. Knowingly contravening the reporting, notification or record-keeping requirements is an offence, and the published maximum is 100,000 CAD per affected individual on indictment.

Read that record-keeping rule against how most small businesses actually operate. A misconfigured form that emailed twelve quote requests to the wrong inbox is a breach of security safeguards. It probably does not meet the real-risk threshold, and you are still supposed to have written down that it happened, and why you concluded it did not need reporting.

The commercial cost, which arrives sooner

Regulatory exposure is the slow risk. The fast one is procurement. Any enterprise or public sector buyer runs a vendor privacy review, and a missing or templated policy stalls the deal while someone in legal asks questions. The same applies to payment processors, insurers underwriting cyber liability, and increasingly to partner integrations. A specific, current, accurate policy is cheap. Explaining a vague one in a security questionnaire is not.

Common Mistakes

  • Copying a US policy. CCPA language about the right to opt out of the sale of personal information is not a Canadian concept and signals to a regulator that nobody adapted the document.
  • Citing the GDPR because the generator offered it. If you do not target EU residents, referencing a lawful basis under Article 6 just tells readers the page is unread boilerplate.
  • Naming a privacy officer who left. An accountable contact who no longer works there is a failure of the accountability principle, not a typo.
  • Listing tools you no longer use, and omitting the ones you added. The policy was accurate on the day the site launched and has not tracked the marketing stack since.
  • No last-updated date. Required in substance in Quebec and expected everywhere.
  • Policy only linked from the homepage. Readily available means from every page, including landing pages built outside the main template.
  • Treating consent as permanent. Individuals can withdraw consent. If your policy does not say how, you have not actually offered the choice.
  • Silence on cross-border storage. Most Canadian small business stacks are US hosted. Saying so is transparency. Not saying so is the gap an auditor finds first.

A Practical Rollout, in Order

  1. Inventory. Run the network-tab and tag-manager audit above. Write down every third party that receives data.
  2. Map purposes. For each data item, write one sentence saying why you have it. Anything you cannot justify, stop collecting. Limiting collection is a principle in its own right.
  3. Name an accountable person. A title is acceptable. An unattended shared inbox is not.
  4. Draft in plain language. Write for the customer, not for a court. The openness principle is explicit that people should not have to decipher complex legal language.
  5. Wire the links. Footer on every template, next to every form, inside the cookie banner.
  6. Set a review cadence. Quarterly, and immediately after any new tool goes into the stack. Put the date on the page.
  7. Build the breach log now. A one-page template with date, what happened, what data, risk assessment, decision, rationale. It has to exist before you need it.
  8. Have counsel review it if you handle health data, financial data, children’s data or anything that would cause real harm if it leaked.

Steps one, five and six are website work and belong with whoever maintains the site. If nobody owns that, they drift, which is how a policy ends up three tools out of date. Our website growth packages fold this review into the regular maintenance cycle rather than leaving it as an annual scramble.

Hands holding a printed policy document at a desk, representing the plain-language readability standard Canadian privacy law expects
The OPC is explicit that people should not have to decipher complex legal language to give informed consent.

Frequently Asked Questions

Do I need a privacy policy if my website has no forms?

If the site loads analytics or advertising scripts, yes. Those collect identifiers tied to an individual’s browsing. A genuinely static brochure page with no analytics, no cookies, no embeds and no forms is the rare case where nothing is collected, and even then a short policy saying exactly that is worth publishing.

Can I use a free privacy policy generator?

As a structure, yes. As the finished page, no. A generator does not know which scripts your site loads, where your CRM stores data, who your accountable person is, or how long you keep records. Those are the specifics a regulator and an enterprise buyer both look for. Use a generator to get the headings, then replace every generic sentence with what your business actually does.

Does a privacy policy have to be in French for Quebec?

If you are doing business in Quebec, the province’s language rules apply to your commercial publications and your website, and the privacy policy is part of the site. The Law 25 requirement is separately that the policy be in clear and simple language, which is a readability requirement rather than a language one. Treat them as two obligations that both bite.

Is a privacy policy the same as a cookie banner?

No. The banner is a consent mechanism at the moment of collection. The policy is the standing disclosure of your practices. Quebec requires both in most configurations, and a banner that links to nothing is worse than no banner, because it demonstrates you knew consent was needed.

How often should I update it?

Review quarterly and update immediately whenever you add a tool that touches visitor data, change where data is stored, change your retention practice, or change who is accountable. In Quebec, an amendment triggers a notice obligation, so plan for how you will give that notice before you make the change.

Does PIPEDA apply to my one-person consulting business?

PIPEDA has no employee-count or revenue threshold. It applies to organizations collecting personal information in the course of commercial activity, and a sole proprietorship doing commercial work is included. Size changes what proportionate safeguards look like. It does not change whether the law applies.

The Bottom Line

The question is not really whether Canadian law requires a privacy policy. It requires that your practices be open, understandable and available, and a published page is the only practical way to do that for a website. Quebec then writes the publication duty into the statute directly.

The work that makes a policy defensible is not the drafting. It is the inventory: knowing every script on the site, every third party that receives data, where that data physically sits, and how long you keep it. Most businesses have never done that audit. Once you have, the page writes itself, and it says something specific rather than something generic.

Compliance pages also share a structural overlap with the rest of good site hygiene: clear headings, plain language, keyboard reachable, linked from everywhere. The same build standard that makes a site legally accessible makes a privacy policy readable.

Get Your Site Audited

Wise Media builds and maintains Canadian business websites with the compliance layer handled as part of the build rather than bolted on afterward: script inventory, consent mechanics, policy structure, and a review cadence that keeps the page current. If you want the third-party audit done properly, start with our website packages or tell us what you are running at wisemedia.io/intake.

Sources

This article is general information about Canadian privacy legislation and is not legal advice. Privacy obligations depend on your specific operations, data flows and jurisdiction. Confirm your position with a qualified privacy lawyer before relying on any of it.