- What applies instead is Canada's general federal privacy law, the Personal Information Protection and Electronic Documents Act (PIPEDA), which governs how organizations collect, use, and…
- The more a tracking tool can be used to identify or build a profile of a specific individual, the more clearly it falls within PIPEDA's scope.
- PIPEDA's consent requirement is meant to be meaningful, not just technically present.
If you've built a website recently, you've probably wondered whether you need one of those cookie consent banners that seem to be everywhere. The honest answer for an Ontario business is more nuanced than a simple yes or no — Canada doesn't have a specific "cookie law" the way some other jurisdictions do, but that doesn't mean website tracking is unregulated.
This article explains how Canadian privacy law actually applies to cookies, analytics, and other tracking tools, and what a reasonable approach looks like in practice.
Does Canada Have a "Cookie Law"?
Not in the sense of a standalone statute that specifically regulates cookies and requires a particular style of consent banner. What applies instead is Canada's general federal privacy law, the Personal Information Protection and Electronic Documents Act (PIPEDA), which governs how organizations collect, use, and disclose personal information in the course of commercial activity. Ontario has no separate general private-sector privacy statute of its own, so PIPEDA is the framework that matters here.
The practical question isn't "is this a cookie," it's "does this tracking tool collect personal information, and if so, have we obtained meaningful consent for that."
When Does Tracking Data Count as "Personal Information"?
Not every cookie collects personal information in a legally meaningful sense — a cookie that only remembers a language preference is different from a tracking tool that builds an identifiable profile of a visitor's browsing behaviour across sites, especially if it can be linked back to a name, account, or other identifying detail. The more a tracking tool can be used to identify or build a profile of a specific individual, the more clearly it falls within PIPEDA's scope.
Because this is a fact-specific assessment rather than a bright-line test, businesses using analytics, advertising pixels, or retargeting tools should generally assume PIPEDA's consent principles apply, rather than assuming they don't.
What Meaningful Consent Looks Like
PIPEDA's consent requirement is meant to be meaningful, not just technically present. In the website context, that generally points toward:
- Clear, upfront disclosure — telling visitors, before or at the point of collection, what tracking tools are in use and roughly what they do
- A real choice where practical — for tracking that isn't strictly necessary to run the site (marketing and advertising cookies, for example), giving visitors a way to decline
- Layered information — a short, plain-language notice (like a cookie banner) backed by a fuller privacy policy for anyone who wants more detail
- Consent proportional to sensitivity — the more identifiable or sensitive the tracking, the more explicit the consent should be
Types of Website Tracking and General Consent Considerations
| Tracking type | Typical purpose | General consent consideration |
|---|---|---|
| Strictly necessary cookies (login sessions, cart contents) | Make the site function | Lower consent expectations — usually implied by using the site |
| Analytics cookies | Measure traffic and usage patterns | Depends on whether data is identifiable; disclosure is good practice regardless |
| Advertising/retargeting pixels | Build profiles for targeted ads across sites | Higher consent expectations — a meaningful opt-out matters |
| Third-party embedded content (video, chat widgets) | Functionality provided by another company | Disclose that a third party may also collect data through the embed |
This table describes general tendencies, not a fixed legal classification — the right approach for a specific tool depends on what it actually does with the data it collects.
Common Mistakes
- Posting a privacy policy that doesn't mention analytics or advertising tools the site actually uses
- Assuming that because "everyone has cookies," no disclosure or choice is needed
- Treating a cookie banner as decorative rather than functional — for example, tracking continuing to run even after a visitor declines
- Not updating the privacy policy or tracking disclosures after adding new marketing tools
Frequently asked questions
Do we legally need a cookie consent banner on our Ontario business website?
There's no specific Canadian law that mandates a particular banner format the way some other countries require. But if your site uses tracking tools that collect personal information, you generally need to meet PIPEDA's consent and disclosure expectations — a well-designed banner and privacy policy are common, practical ways to do that.
Is Google Analytics considered personal information collection?
It can be, depending on configuration and what data is collected or linked. This is a fact-specific question rather than a blanket yes or no, and businesses using analytics tools should address them specifically in their privacy policy.
What's the risk if we don't address tracking properly?
Complaints about a business's personal information practices, including website tracking, can be raised with the federal privacy regulator. Beyond that, an inaccurate privacy disclosure can also affect customer trust regardless of formal enforcement.
Do the rules change if our website sells to customers outside Ontario?
Possibly. Businesses dealing with residents of other provinces or countries may need to consider other privacy regimes in addition to PIPEDA — this is worth flagging to a lawyer if your customer base isn't purely Ontario-based.
This is a corporate question
Start a file online — flat, published fees, reviewed by a licensed Ontario lawyer before a dollar is owed.