TREADSTONE LAW · ONTARIO · DIGITAL LEGAL SERVICES · EST. MMXXI ·TSL
Home/Articles/Corporate
№ 344 Corporate

Privacy Policy Checklist for Ontario Business Websites: What It Must Say

A plain-language checklist of what an Ontario business website's privacy policy should cover under federal privacy law, and where businesses fall short.

Corporate5 min readTSLBy the Treadstone Law team · OntarioUpdated 2026-07
All articles
Key takeaways
  • PIPEDA's core idea is straightforward even if the compliance details aren't: businesses need meaningful consent to collect, use, or disclose someone's personal information for a business…
  • - [ ] What personal information you collect — name, contact details, payment information, browsing behaviour, and anything else gathered through forms, accounts, or tracking tools - [ ]…
  • Copy-pasted policies that don't match reality A privacy policy borrowed from another company's website may describe practices — data sharing arrangements, retention periods, security…

Almost every business website has a privacy policy link buried in the footer — and a surprising number of them are copied from a template, another company's site, or a generator, without much thought about whether they actually reflect what the business does with visitor and customer data. That gap matters: a privacy policy isn't just a formality, it's the document that's supposed to tell people, honestly, what you collect and why.

For most Ontario businesses, the federal Personal Information Protection and Electronic Documents Act (PIPEDA) sets the baseline for what a privacy policy needs to address, because Ontario itself has no separate general private-sector privacy law of its own. This article walks through what a privacy policy should generally cover.

What PIPEDA Actually Expects

PIPEDA's core idea is straightforward even if the compliance details aren't: businesses need meaningful consent to collect, use, or disclose someone's personal information for a business purpose, and they need to be able to explain — clearly, not buried in legal boilerplate — what they collect and why. A privacy policy is the primary way most businesses communicate that explanation to the public.

This applies broadly: to e-commerce sites, service businesses collecting contact forms, employers collecting applicant information, and any website using tools (analytics, chat widgets, marketing pixels) that gather visitor data.

The Checklist: What a Privacy Policy Should Cover

Where Businesses Commonly Fall Short

Copy-pasted policies that don't match reality

A privacy policy borrowed from another company's website may describe practices — data sharing arrangements, retention periods, security measures — that don't actually match what your business does. That mismatch is arguably worse than having a thin but accurate policy, because it amounts to a written misrepresentation about your own practices.

Vague purpose statements

"We may use your information to improve our services" tells a visitor almost nothing. Being specific about actual purposes is both more useful to the reader and more defensible if a complaint is ever made.

No visible way to ask questions or complain

PIPEDA expects organizations to be accountable and reachable. A privacy policy with no contact method, or only a generic address buried elsewhere on the site, undercuts that.

Silence on cookies and tracking tools

Many policies were written before the business added analytics, retargeting pixels, or chat tools — and were never updated to reflect the data those tools now collect.

Who Actually Needs One

If your website collects any personal information — even just names and emails through a contact form — you're collecting personal information in the course of commercial activity, which is exactly what PIPEDA is aimed at. There's no small-business carve-out from having a policy that accurately reflects your practices, even though enforcement in practice tends to focus on complaints and larger-scale issues.

Frequently asked questions

Do I need a lawyer to write a privacy policy, or can I use a generator?

Generators can produce a reasonable starting point, but they don't know what your business actually does with data — and a policy that doesn't match reality can be its own problem. Having a lawyer review or tailor the document, even briefly, catches mismatches a generic template can't.

Does a privacy policy need to be a separate page, or can it be part of our terms of service?

It's generally clearer, and more consistent with what visitors expect, to keep a privacy policy as its own clearly labelled document, separate from terms of service. They answer different questions and serve different purposes.

What happens if someone complains that our privacy policy doesn't reflect what we actually do?

Complaints about a business's personal information practices can be raised with the federal privacy regulator. The specific outcome depends on the facts, but an inaccurate or misleading privacy policy is generally worse for a business than an honest, if modest, one.

Do we need consent every single time we use someone's information?

Not for every use — consent can cover a range of related purposes if they're clearly explained upfront. But using information for a materially different purpose than what was originally disclosed generally requires fresh consent.

This article is general information, not legal advice. Reading it does not create a lawyer-client relationship. Ontario laws, tax rates, and government programs change, and how the law applies depends on your specific facts. For advice about your situation, speak with a licensed Ontario lawyer. Treadstone Law is licensed by the Law Society of Ontario — reach us at 1-844-900-1070 or start a file online.

This is a corporate question

Start a file online — flat, published fees, reviewed by a licensed Ontario lawyer before a dollar is owed.

ContactStart a File →