Privacy rules apply to you, even without a legal team
If you run a business with a handful of staff, take orders through a website, and keep a customer list somewhere, you are handling personal information. Canadian privacy law does not have a small-business exemption that lets you opt out of that. There is no employee threshold, no revenue floor, no grace period for companies that have never thought about it before.
That sounds heavier than it is. Most of what the law asks for is the kind of thing a careful owner already half does: know what you collect, say so honestly, keep it safe, delete what you do not need, and tell people when something goes wrong. The gap for most small businesses is not intent. It is that nobody has written any of it down, and nobody is sure which law they are under.
Who this applies to
Canada's federal private-sector privacy law is the Personal Information Protection and Electronic Documents Act, usually called PIPEDA. It is overseen by the Office of the Privacy Commissioner of Canada at priv.gc.ca. PIPEDA covers personal information you collect, use or disclose in the course of commercial activity.
Three provinces — Alberta, British Columbia and Quebec — have their own private-sector privacy laws deemed substantially similar to PIPEDA. If your business operates wholly within one of those provinces, you follow the provincial law rather than the federal one. That word "wholly" does a lot of work. PIPEDA still governs personal information crossing a provincial or national border in the course of commercial activity, and applies to federally regulated businesses such as banks, airlines and telecoms.
For an online seller, that usually means both. A Vancouver shop selling to customers in Ontario is moving personal information across a provincial border, so PIPEDA is in the picture alongside British Columbia's law. The underlying principles are close enough that building to the stricter of the two is more practical than holding two rulebooks in your head.
Quebec is the exception worth taking seriously. Its regime, known as Law 25, is the strictest in the country, and it is in force now. If you have customers, staff or a storefront in Quebec, read the Quebec section below carefully.
What you actually have to do
Get consent that means something. People have to know what they are agreeing to and agree to it. A checkbox buried in terms nobody reads is a weak foundation. The more sensitive the information — health details, financial records, anything about children — the more you should expect to need clear, express consent rather than an assumption that silence means yes.
Limit collection to purposes you can name. You may collect personal information for purposes a reasonable person would consider appropriate in the circumstances, and you must identify those purposes at or before the point of collection. The practical test is whether you can finish the sentence "we collect this because." If you cannot, drop the field. Date of birth on a newsletter form, a phone number you never call, a shipping address kept for years after the last order — these are what turn a minor incident into a serious one.
Be open about your practices. Openness is its own obligation, not just good manners. Your privacy policy should be findable, readable, and accurate about what you actually do — including the third-party tools that see your customers' data. Your payment processor, email platform, analytics tool, chat widget and ad pixels all count. A policy that describes a business you no longer run is worse than a short one that is true.
Put safeguards in place that match the sensitivity. The standard is proportionality, not perfection. Nobody expects a five-person business to run a security operations centre. They do expect that customer records are not in a shared folder anyone can open, that accounts have multi-factor authentication, that former employees lose access on their last day, and that anything sensitive is encrypted. Write down what you have done — the record of reasonable precautions is what you will be judged against.
Answer access requests. Individuals can ask what personal information you hold about them, how it is being used, and to whom it has been disclosed, and they can ask for corrections. This is manageable for a small business, but only if you know where the data lives. If a request would send you hunting through three inboxes, a spreadsheet, a CRM and an old shop platform, map that before the request arrives.
Report breaches that pose a real risk of significant harm — and log all of them. If a breach of security safeguards creates a real risk of significant harm to an individual, you must report it to the Privacy Commissioner and notify the affected people. Separately, and often missed, you have to keep records of every breach of security safeguards, including the ones you decide are not reportable. That log is what demonstrates you assessed the incident rather than ignored it, and the Commissioner can ask for it.
Treat your marketing email as a separate legal problem. Canada's Anti-Spam Legislation, CASL, governs commercial electronic messages and is enforced separately, principally by the CRTC. Small businesses routinely overlook it because they file it mentally under "marketing" rather than "privacy." CASL requires express or implied consent before you send, clear identification of who is sending, and a working unsubscribe mechanism that you honour within 10 business days. Having a lawful privacy policy does not make your mailing list CASL-compliant, and buying or scraping a list is exactly the practice CASL exists to stop.
If Quebec applies to you
Law 25 adds duties that go beyond PIPEDA and are already in force. You must designate a person responsible for the protection of personal information; by default that is the most senior person in the enterprise, which for a small business means you, the owner, unless you formally assign it. Certain projects require a privacy impact assessment before you proceed. Confidentiality incidents must be reported to the Commission d'accès à l'information. If a decision about someone is made exclusively by automated processing, you have to tell them. Technology that collects personal information and offers privacy settings must default to the most privacy-protective option. And individuals have a right to data portability — to receive their information in a usable form.
What's coming
The federal picture is unsettled, and you should be sceptical of anyone describing it otherwise. Bill C-27, which would have brought in the Consumer Privacy Protection Act and the Artificial Intelligence and Data Act, died when Parliament was prorogued in January 2025. It did not pass, and nothing in it is law.
Bill C-36, the Protecting Privacy and Consumer Data Act, received first reading on 15 June 2026. If it passed, it would replace Part 1 of PIPEDA. It is at an early stage, it is not law, and bills at first reading often change or disappear. It would provide for a Privacy and Consumer Data Commissioner and Division sitting within a structure created by a companion bill, Bill C-34, which is what would establish the Digital Safety and Data Protection Commission of Canada. C-36's coming into force would depend on C-34.
The useful takeaway is not to prepare for a specific future statute. It is that the direction of travel — clearer consent, real accountability, documented practices — is the same in every proposal on the table and already reflected in Quebec's law. Doing PIPEDA properly today is the best hedge available.
Common mistakes
The most common is copying another company's privacy policy. It describes their vendors, their retention periods and sometimes their jurisdiction, and a policy that misdescribes your business is a written record of an inaccurate statement.
The second is assuming provincial law makes federal law irrelevant. If information crosses a border in the course of commercial activity, PIPEDA is engaged regardless of where your office is.
The third is forgetting the tools. Every analytics script, pixel, embedded chat and form builder on your site may be collecting or transmitting personal information, and you are accountable for it even though someone else wrote the code.
The fourth is treating the breach log as optional; it covers all breaches of security safeguards, not only the ones you report. The fifth is treating CASL as somebody else's job.
Where Dxtra fits
Dxtra generates a privacy program from a questionnaire about how your business actually works: a privacy policy, a cookie notice, consent records, processing records, a public Transparency Center and a process for handling data subject access requests. It covers more than 500 obligations across 140-plus countries and starts at $10 a month. It will not replace a lawyer on a hard question, and it cannot fix a practice you have not told it about.
Where to start
Spend an hour writing down every place customer data currently sits, and who else can see it. That single list makes the rest tractable — you cannot write an honest privacy policy or answer an access request without it. Then confirm which law governs you, read your existing policy against the list, and check your mailing list against CASL.
If you want an outside look first, Dxtra's free scan reads your site's public pages in about two minutes with no signup and returns a risk band with findings mapped to named sources — a starting point for review, not a determination of compliance.
This article is general information, not legal advice. Rules change; confirm anything that matters with the Office of the Privacy Commissioner of Canada (priv.gc.ca) or a qualified adviser before you rely on it.
