What PIPEDA is and who it covers

The Personal Information Protection and Electronic Documents Act — PIPEDA — is Canada's federal private-sector privacy law. It has been in force since 2001 and governs how organizations collect, use, and disclose personal information in the course of commercial activity. In 2019, the federal government passed Bill C-58, which added mandatory breach reporting requirements. The law is administered by the Office of the Privacy Commissioner of Canada (OPC).

Personal information under PIPEDA is defined broadly: any information about an identifiable individual. A name, an email address, a phone number, an IP address, a purchasing history, a customer enquiry — all of these qualify. If your website collects any of this, PIPEDA applies to how you handle it.

The law applies to private-sector organizations across Canada engaged in commercial activity, with one significant exception: organizations in Quebec, British Columbia, and Alberta that collect personal information entirely within those provinces may fall under substantially similar provincial legislation instead. We will return to that distinction in the section on provincial laws. For most businesses operating across provincial lines, or operating online where visitors come from multiple provinces, PIPEDA is the governing framework.

Notably, PIPEDA applies regardless of the size of your business. There is no employee-count threshold, no revenue threshold. A sole proprietor with a contact form on their website is subject to the same principles as a national retailer. The enforcement response is proportionate to the scale of harm, but the obligations are the same.

The ten principles — and what they require of your website

PIPEDA is structured around ten Fair Information Principles, originally developed by the Canadian Standards Association and incorporated into the Act as Schedule 1. Each principle creates specific obligations. Here is what each one means in practice for a website operator.

1. Accountability. Your organization is responsible for the personal information it holds, including information transferred to third parties for processing. Someone in your organization must be accountable for PIPEDA compliance — in a small business, that is you. If you use a third-party email marketing service, a payment processor, or a web analytics platform, you remain accountable for how they handle your customers' data and you should have data processing agreements in place.

2. Identifying purposes. You must identify the purposes for which personal information is collected at or before the time of collection. This means your contact form needs to tell people what you will do with the information they submit — not buried in a privacy policy no one reads, but clearly stated near the form itself. "We will use your email to respond to your enquiry and may send occasional updates. You can unsubscribe at any time." That level of clarity satisfies the principle.

3. Consent. You need meaningful consent for collection, use, and disclosure of personal information. Consent must be informed — people need to know what they are consenting to — and it must be voluntary. Pre-ticked checkboxes do not constitute consent. Implied consent is permitted for non-sensitive information in low-stakes contexts (someone filling out a contact form is implicitly consenting to being contacted), but express consent is required for uses beyond what the person would reasonably expect.

4. Limiting collection. Collect only what you actually need. If your contact form asks for name, email, and message, that is likely defensible. If it also asks for date of birth, income range, and number of employees for a small business enquiry, you need a specific, articulable reason for each field. The principle of data minimization is not just good practice under PIPEDA — it is a legal requirement.

5. Limiting use, disclosure, and retention. Personal information collected for one purpose cannot be used for another without consent. If someone gives you their email to receive a quote, you cannot add them to your marketing list without asking. You also cannot retain information indefinitely — when the purpose for which information was collected has been fulfilled, it should be destroyed or anonymized. This applies to your contact form submissions, your email lists, your customer records, and your web server logs.

6. Accuracy. You must keep personal information accurate, complete, and current to the extent necessary for its purposes. For a mailing list, this means having a process for people to update their contact information. For a customer database, it means correcting errors when customers report them. The obligation scales with the stakes: inaccurate information used to make decisions that affect people (credit decisions, employment, health services) carries more risk than inaccurate information in a low-stakes marketing list.

7. Safeguards. You must protect personal information with security appropriate to its sensitivity. For most small business websites, this means: using HTTPS across your entire site, storing form submissions securely (not in a publicly accessible file or an unencrypted spreadsheet), using strong and unique passwords for your hosting, email, and CRM accounts, and keeping your website software patched and updated. A data breach is not just a reputational event — under mandatory breach reporting rules, you may be legally required to report it.

8. Openness. You must make your privacy policies and practices readily available. This is where the privacy policy comes in — but the policy itself is only one part of openness. The principle requires that people can easily understand what you do with their information, including how to contact you with questions. A privacy policy linked in your footer satisfies the technical requirement; a privacy policy that is readable and specific satisfies the spirit.

9. Individual access. People have the right to access the personal information you hold about them and to challenge its accuracy. A small business handling modest volumes of customer data can generally respond to access requests informally — someone emails asking what information you have about them, you tell them. Larger volumes require more systematic processes. PIPEDA gives organizations 30 days to respond to access requests.

10. Challenging compliance. People have the right to challenge your compliance with PIPEDA and to have complaints addressed. You must have a process for handling privacy complaints — at minimum, a contact address for privacy enquiries — and you must investigate and respond to complaints received.

What PIPEDA means for your website specifically (contact forms, analytics, email lists)

The principles above become very concrete when applied to the three most common data collection points on a small business website: contact forms, web analytics, and email lists.

Contact forms collect personal information the moment someone submits them. PIPEDA requires that you identify the purpose of collection at the point of submission, store the information securely, use it only for the stated purpose, and not retain it longer than necessary. In practice: add a brief note near your form explaining what the information is used for, ensure form submissions are stored in a secure location (not an unencrypted email inbox shared among staff, and not a publicly accessible server folder), and set a retention policy — if enquiries older than two years are not being acted on, delete them.

Web analytics are more complicated than most people realize. Google Analytics collects IP addresses, which are personal information under PIPEDA. If you are running Google Analytics without disclosure and without configuring IP anonymization, you are almost certainly not PIPEDA-compliant. The minimum steps are: disclose your analytics use in your privacy policy, enable IP anonymization in Google Analytics (or switch to a privacy-first analytics platform that does not collect personally identifiable information), and if you are using Google Analytics 4 and targeting EU users, address GDPR requirements separately. For Canadian visitors under PIPEDA, disclosure and anonymization cover the essentials.

Email lists require express consent before you send marketing communications. This is reinforced by Canada's Anti-Spam Legislation (CASL), which operates alongside PIPEDA and is, in some respects, stricter. Under CASL, you need express or implied consent before sending commercial electronic messages. Implied consent applies to existing customers within two years of a transaction. Express consent requires a clear affirmative action — checking a box, filling out a form — with a clear description of what the person is signing up for. You must honour unsubscribe requests within ten business days.

CASL and PIPEDA overlap but are not identical. PIPEDA governs privacy — how you collect, use, and protect personal information. CASL governs commercial electronic messages — when you can email or text someone for marketing purposes. Both apply to your website. A PIPEDA-compliant email list that lacks CASL consent records is still exposed to CASL enforcement, and vice versa.

How PIPEDA interacts with provincial privacy laws (Quebec Law 25, BC PIPA, Alberta PIPA)

Three provinces — Quebec, British Columbia, and Alberta — have private-sector privacy legislation that the federal government has deemed "substantially similar" to PIPEDA. Organizations operating entirely within those provinces and collecting information solely within provincial borders may be governed by provincial law rather than PIPEDA.

Quebec's Law 25 (formally An Act to modernize legislative provisions as regards the protection of personal information) came into full force in September 2023 and is significantly stricter than PIPEDA in several areas. It requires privacy impact assessments before collecting personal information by technological means (including most website analytics and contact forms), a published privacy policy on any website, explicit consent for non-essential cookies, and a designated privacy officer — even for small businesses. It also introduces the right to data portability and the right to be forgotten. If you have customers in Quebec, Law 25 applies regardless of where your business is based.

British Columbia's Personal Information Protection Act (BC PIPA) and Alberta's Personal Information Protection Act (Alberta PIPA) are both substantially similar to PIPEDA and govern organizations operating within those provinces. Both are administered by provincial privacy commissioners. The practical differences from PIPEDA are modest for most small businesses, but it is worth knowing that if you are a BC-based business dealing primarily with BC customers, BC PIPA is your primary framework.

The interaction between these laws is manageable in practice. If you build your website to meet PIPEDA's requirements and address Quebec Law 25's additional consent and cookie requirements, you will be in reasonable shape across all four frameworks. The key additions for Law 25 compliance are: a cookie consent mechanism for Quebec visitors, an explicit privacy policy page (not just a footer link), and a named privacy contact.

What non-compliance looks like — and what it costs

PIPEDA enforcement has historically been complaint-driven — someone files a complaint with the Office of the Privacy Commissioner, the OPC investigates, and if a finding of non-compliance results, the OPC can make recommendations and, in some cases, take matters to Federal Court. The OPC cannot levy fines directly under PIPEDA; Federal Court can award damages and make orders, and failure to comply with OPC findings can result in fines up to $100,000.

Mandatory breach reporting, added in 2018, creates additional exposure. If your website is breached and personal information is compromised in a way that creates a real risk of significant harm to individuals, you must report to the OPC and notify affected individuals. Failure to report a qualifying breach is itself an offence, punishable by fines up to $100,000. The definition of "real risk of significant harm" includes things like identity theft, financial loss, reputational damage, and loss of employment — all plausible consequences of a contact list or customer database being exposed.

Quebec Law 25 has a sharper enforcement mechanism. The Commission d'accès à l'information (CAI) can impose administrative penalties of up to $10 million or 2% of worldwide turnover for some violations, and up to $25 million or 4% of worldwide turnover for serious offences. These are GDPR-scale penalties applied to Quebec's provincial privacy law. For a business with Quebec customers, Law 25 compliance is not optional and not low-stakes.

Beyond regulatory enforcement, non-compliance creates reputational risk. A data breach, a complaint that becomes public, or a privacy policy that is obviously inadequate damages customer trust in ways that are difficult to quantify and expensive to repair. Privacy compliance is also increasingly a vendor requirement — if you want to work with larger organizations or government entities, they will ask about your privacy practices.

A practical PIPEDA compliance checklist for small business websites

The following steps cover the essentials for most Canadian small business websites. This is not legal advice, and complex situations warrant professional guidance — but for a typical service business with a contact form, a website, and an email list, this checklist addresses the core obligations.

Publish a real privacy policy. Not a generic template — a policy that specifically describes what information your website collects (contact form submissions, analytics, cookies), what you use it for, who you share it with (your web host, your email service provider, your analytics platform), how long you retain it, and how people can access or correct their information or file a privacy complaint. Link it from your footer on every page.

Add a purpose statement to your contact form. A single sentence near the submit button: "We use this information to respond to your enquiry. We do not share it with third parties or add you to marketing lists without your consent." This satisfies Principle 2 (Identifying purposes) at the point of collection.

Audit your third-party tools. List every service your website uses that collects or processes personal information: analytics platforms, chat widgets, booking systems, email marketing services, payment processors. For each, confirm they are processing data in compliance with PIPEDA, and that this is disclosed in your privacy policy.

Enable IP anonymization in your analytics. In Google Analytics 4, this is handled via consent mode and data settings. Alternatively, switch to a privacy-first analytics platform that does not collect personally identifiable information.

Secure your stored data. Form submissions stored in a database or email inbox should be accessible only to authorized staff. Use HTTPS across your entire site (not just checkout pages). Keep your website software, plugins, and themes updated to close known security vulnerabilities.

Set a data retention policy and enforce it. Decide how long you keep contact form submissions, customer records, and email list data. Three years is a reasonable default for most business records; adjust based on your actual operational needs. Delete or anonymize records that have outlived their purpose.

Create a process for access requests and complaints. You need a named contact for privacy enquiries — this can be as simple as a privacy@yourdomain.ca email address. Make sure someone checks it and knows how to respond. A written response acknowledging the request within 30 days is what PIPEDA requires.

The goal is genuine compliance, not paperwork. A privacy policy that accurately describes your actual practices, a contact form that tells people why you need their information, and secure storage of what you collect — these are the substance of PIPEDA compliance. The documentation follows from the practices, not the other way around.

PIPEDA compliance for a small business website is achievable without a legal team. It requires attention, honesty about what your website actually does with personal information, and a willingness to build that honesty into your public-facing communications. The businesses that struggle with privacy compliance are typically not those with complex data operations — they are the ones who have never stopped to ask what information their website collects, why, and what happens to it afterward. Asking those questions is the first step.