Security & Privacy

PIPEDA for Websites: What Canadian Businesses Must Do

What PIPEDA means for a Canadian business website in practice: which law applies, consent, forms, analytics, safeguards, access requests and breach handling.

Illustration of a Canadian maple leaf on a shield beside a website form with a consent checkbox and a padlock

Almost every business website collects personal information, even if it only has a contact form and an analytics script. In Canada that brings privacy law into play, yet most site owners have never mapped what their website actually collects or where it goes. This guide explains PIPEDA compliance website requirements in practical terms: which law applies to you, what your forms, cookies and privacy policy need to do, how to protect the data, and what to do if something goes wrong. It is general information, not legal advice, so use it to prepare good questions for your privacy lawyer.

First: does PIPEDA or a provincial law apply?

The Personal Information Protection and Electronic Documents Act (PIPEDA) is Canada's federal private-sector privacy law. It applies to organizations that collect, use or disclose personal information in the course of commercial activity. But it is not the only law in play:

  • British Columbia has the Personal Information Protection Act (BC PIPA), which generally applies to private organizations handling personal information within BC.
  • Alberta has its own PIPA, and Quebec has its private-sector law, significantly strengthened by Law 25.
  • PIPEDA still applies to federally regulated businesses (such as banks and airlines) and to personal information that crosses provincial or national borders in commercial activity.
  • Health information may also be covered by provincial health privacy laws, depending on the province and the type of organization.

In practice, a BC company selling online to customers across Canada may need to think about both BC PIPA and PIPEDA. The good news is that these laws share the same core principles, so a website built to meet them carefully will be in a strong position under either. This is exactly the kind of question to settle with a lawyer early.

The ten principles, translated for your website

PIPEDA is built on ten fair information principles. Here is what each one means for a typical business website.

Principle What it means on your website
Accountability Name someone responsible for privacy; ensure vendors (host, CRM, email tools) protect data under contract
Identifying purposes Explain why you collect each piece of information, at or before collection
Consent Obtain meaningful consent; use express consent for sensitive data or unexpected uses
Limiting collection Ask only for fields you genuinely need
Limiting use, disclosure and retention Use data only for stated purposes; delete it when no longer needed
Accuracy Let people update their details, for example in account profiles
Safeguards Protect data with security measures appropriate to its sensitivity
Openness Publish a clear, readable privacy policy
Individual access Be able to find and provide someone's information on request
Challenging compliance Offer a way to raise privacy complaints

Key takeaway: Compliance is less about legal wording and more about knowing your data. If you cannot list what your website collects, where it is stored and who can see it, start there.

Step 1: map the personal information your site handles

Before touching your privacy policy, build a simple data inventory. Walk through the site and list every point where personal information enters:

  1. Contact, quote and job application forms.
  2. Account registration and customer portals.
  3. Checkout and order history.
  4. Newsletter signups.
  5. Live chat and chatbot widgets.
  6. Analytics, advertising pixels and session recording tools.
  7. Server logs, which typically record IP addresses.

For each, note what fields are collected, why, where the data is stored (database, inbox, CRM, third-party platform), who can access it, and how long it is kept. Many businesses discover that form submissions are being copied to several inboxes and a third-party tool, with no deletion schedule anywhere.

Consent under PIPEDA must be meaningful, which means people should understand what they are agreeing to. On a website, that usually means:

  • Short notice at the point of collection. A line under the form explaining the purpose and linking to the privacy policy.
  • Separate choices for separate purposes. Responding to an enquiry and adding someone to a mailing list are different purposes; use a separate, unticked checkbox for marketing.
  • No unnecessary required fields. If you do not need a phone number, do not make it mandatory.
  • Extra care for sensitive information. Health, financial and identity documents call for express consent and stronger safeguards.

Commercial email also falls under CASL, which has its own consent, identification and unsubscribe requirements. Keep your opt-in records.

Step 3: handle cookies and tracking honestly

Analytics and advertising tools collect information about visitors, often including identifiers that count as personal information. The Office of the Privacy Commissioner of Canada has signalled that online tracking and behavioural advertising need clear notice and an easy way to opt out, with express consent more appropriate for intrusive practices.

Practical options:

  • Audit every script on the site and remove tools nobody uses.
  • Use a consent banner that actually controls which scripts load. Our guide to cookie consent banners in Canada, the UAE and the EU covers the design choices.
  • Consider privacy-friendly or self-hosted analytics, such as Dideban Analytics, which keeps data on your own infrastructure and reduces third-party sharing.

Step 4: write a privacy policy people can read

Your privacy policy should describe what the website actually does, not a generic template. Include:

  • Who you are and how to contact your privacy officer.
  • What information you collect, through which features, and why.
  • Which third parties receive it (hosting, payment processors, email platforms, analytics) and that it may be processed outside Canada if applicable.
  • How long you keep it.
  • How people can access, correct or withdraw consent.
  • How to make a complaint.

Review it whenever you add a new form, tool or integration.

Step 5: put real safeguards in place

The safeguards principle requires protection appropriate to the sensitivity of the information. For a website, that typically includes:

  • HTTPS everywhere, with modern TLS configuration.
  • Strong authentication and two-factor login for admin users.
  • Role-based access so staff only see the records they need.
  • Encryption of sensitive fields and backups.
  • Timely software updates and server patching.
  • Logging of access to personal data in admin panels.
  • Contracts with your hosting, email and software providers that require comparable protection.

Our website security checklist is a good starting point for the technical side.

Step 6: be ready for access requests and breaches

Access requests

Individuals can ask what personal information you hold about them. If your data is scattered across inboxes and tools, this becomes slow and error-prone. Build an admin search or export that pulls a person's records from your main systems.

Breach reporting

Under PIPEDA, organizations must report breaches of security safeguards to the Privacy Commissioner and notify affected individuals when the breach creates a real risk of significant harm. You must also keep records of every breach, even those that do not meet the reporting threshold. Provincial laws have their own rules, so your incident plan should name who decides whether a breach is reportable and who contacts legal counsel.

PIPEDA compliance website mistakes we see often

  • Pre-ticked marketing checkboxes.
  • Contact forms that email full submissions, including attachments, to shared mailboxes with no retention policy.
  • Old job applications sitting in a database for years.
  • Analytics and ad pixels added by marketing without anyone updating the privacy policy.
  • Admin accounts shared between several staff, so access cannot be traced.
  • No written agreement with the agency or host that manages the server.

Keep an eye on reform

Canadian privacy law has been under active reform, at both federal and provincial levels, and Quebec's Law 25 has already raised expectations for organizations operating there. Design your website so consent, retention and access are configurable rather than hard-coded; that way, adapting to new rules is an update, not a rebuild.

Next steps

Start with the data inventory in Step 1. It usually takes an afternoon and reveals the most important gaps. Then align your forms, scripts and privacy policy with what you found, and confirm the legal points with a privacy professional.

If you need technical help, DigiVort can audit your website's data flows and implement the fixes through our security and compliance service. For new builds, we design consent and retention into the platform from the start; start your project here.

Frequently asked questions

Does PIPEDA apply to my small business website?

If your organization collects, uses or discloses personal information in the course of commercial activity, PIPEDA may apply regardless of size. However, in British Columbia, Alberta and Quebec, provincial private-sector privacy laws generally apply to activity within the province, while PIPEDA covers interprovincial and international activity and federally regulated businesses. A privacy lawyer can confirm which law applies to you.

Do I need a cookie banner to comply with PIPEDA?

PIPEDA does not prescribe a specific banner, but it requires meaningful consent appropriate to the sensitivity of the information and the reasonable expectations of the individual. For tracking and advertising cookies, clear notice and an easy way to opt out are expected, and express consent is the safer approach for more intrusive tracking.

Is it a problem if my website is hosted outside Canada?

PIPEDA does not ban storing personal information outside Canada, but you remain accountable for it. You should use contracts that require comparable protection and tell users that their information may be processed in other jurisdictions. Some sectors and public-sector clients have stricter residency expectations.

What counts as a privacy breach on a website?

Any loss of, unauthorized access to, or unauthorized disclosure of personal information resulting from a failure of security safeguards. Examples include an exposed database, a hacked admin account or a form that emails submissions to the wrong address. Breaches that create a real risk of significant harm must be reported and individuals notified.

Can I use contact form submissions for my newsletter?

Not automatically. Using information for a new purpose generally needs consent, and commercial email is also governed by Canada's anti-spam legislation (CASL), which has its own consent and unsubscribe rules. Add a separate, unticked opt-in checkbox if you want to market to form submitters.