- PIPEDA's core idea is straightforward even if the compliance details aren't: businesses need meaningful consent to collect, use, or disclose someone's personal information for a business…
- - [ ] What personal information you collect — name, contact details, payment information, browsing behaviour, and anything else gathered through forms, accounts, or tracking tools - [ ]…
- Copy-pasted policies that don't match reality A privacy policy borrowed from another company's website may describe practices — data sharing arrangements, retention periods, security…
Almost every business website has a privacy policy link buried in the footer — and a surprising number of them are copied from a template, another company's site, or a generator, without much thought about whether they actually reflect what the business does with visitor and customer data. That gap matters: a privacy policy isn't just a formality, it's the document that's supposed to tell people, honestly, what you collect and why.
For most Ontario businesses, the federal Personal Information Protection and Electronic Documents Act (PIPEDA) sets the baseline for what a privacy policy needs to address, because Ontario itself has no separate general private-sector privacy law of its own. This article walks through what a privacy policy should generally cover.
What PIPEDA Actually Expects
PIPEDA's core idea is straightforward even if the compliance details aren't: businesses need meaningful consent to collect, use, or disclose someone's personal information for a business purpose, and they need to be able to explain — clearly, not buried in legal boilerplate — what they collect and why. A privacy policy is the primary way most businesses communicate that explanation to the public.
This applies broadly: to e-commerce sites, service businesses collecting contact forms, employers collecting applicant information, and any website using tools (analytics, chat widgets, marketing pixels) that gather visitor data.
The Checklist: What a Privacy Policy Should Cover
- [ ] What personal information you collect — name, contact details, payment information, browsing behaviour, and anything else gathered through forms, accounts, or tracking tools
- [ ] How you collect it — directly from the individual, through cookies or analytics, or from third parties
- [ ] Why you collect it — the specific purposes (processing orders, running a newsletter, improving the site), not just vague language like "to serve you better"
- [ ] Who you share it with — payment processors, shipping companies, marketing platforms, or other third-party service providers
- [ ] Where it's stored or processed — including whether any vendor stores data outside Canada
- [ ] How individuals can access or correct their own information — a contact method for these requests
- [ ] How individuals can withdraw consent — and what that means practically (unsubscribing, closing an account)
- [ ] How long you retain information — described generally if a precise retention schedule isn't practical
- [ ] How you safeguard it — a general statement about security measures
- [ ] Who to contact with privacy questions or complaints — a named privacy contact or role, even in a small business
- [ ] The date the policy was last updated
Where Businesses Commonly Fall Short
Copy-pasted policies that don't match reality
A privacy policy borrowed from another company's website may describe practices — data sharing arrangements, retention periods, security measures — that don't actually match what your business does. That mismatch is arguably worse than having a thin but accurate policy, because it amounts to a written misrepresentation about your own practices.
Vague purpose statements
"We may use your information to improve our services" tells a visitor almost nothing. Being specific about actual purposes is both more useful to the reader and more defensible if a complaint is ever made.
No visible way to ask questions or complain
PIPEDA expects organizations to be accountable and reachable. A privacy policy with no contact method, or only a generic address buried elsewhere on the site, undercuts that.
Silence on cookies and tracking tools
Many policies were written before the business added analytics, retargeting pixels, or chat tools — and were never updated to reflect the data those tools now collect.
Who Actually Needs One
If your website collects any personal information — even just names and emails through a contact form — you're collecting personal information in the course of commercial activity, which is exactly what PIPEDA is aimed at. There's no small-business carve-out from having a policy that accurately reflects your practices, even though enforcement in practice tends to focus on complaints and larger-scale issues.
Frequently asked questions
Do I need a lawyer to write a privacy policy, or can I use a generator?
Generators can produce a reasonable starting point, but they don't know what your business actually does with data — and a policy that doesn't match reality can be its own problem. Having a lawyer review or tailor the document, even briefly, catches mismatches a generic template can't.
Does a privacy policy need to be a separate page, or can it be part of our terms of service?
It's generally clearer, and more consistent with what visitors expect, to keep a privacy policy as its own clearly labelled document, separate from terms of service. They answer different questions and serve different purposes.
What happens if someone complains that our privacy policy doesn't reflect what we actually do?
Complaints about a business's personal information practices can be raised with the federal privacy regulator. The specific outcome depends on the facts, but an inaccurate or misleading privacy policy is generally worse for a business than an honest, if modest, one.
Do we need consent every single time we use someone's information?
Not for every use — consent can cover a range of related purposes if they're clearly explained upfront. But using information for a materially different purpose than what was originally disclosed generally requires fresh consent.
This is a corporate question
Start a file online — flat, published fees, reviewed by a licensed Ontario lawyer before a dollar is owed.