TREADSTONE LAW · ONTARIO · DIGITAL LEGAL SERVICES · EST. MMXXI ·TSL
Home/Articles/Corporate
№ 345 Corporate

What an Ontario Small Business Privacy Policy Must Actually Say

What a legally sufficient Ontario small business privacy policy must cover under PIPEDA, plus the most common drafting mistakes to avoid making.

Corporate5 min readTSLBy the Treadstone Law team · OntarioUpdated 2026-07
All articles
Key takeaways
  • Most Ontario businesses that collect personal information from customers or clients in the course of commercial activity are subject to the Personal Information Protection and Electronic…
  • A genuinely useful privacy policy generally addresses: A policy that's vague on all of these — "we may collect information and use it for business purposes" — technically exists but does…
  • Meaningful consent is the backbone of PIPEDA compliance, and your privacy policy is one of the main tools you use to obtain and support it.

A privacy policy that exists only to be pasted into a website footer and never read again isn't doing its job, legally or practically. The privacy policy requirements that flow from Ontario businesses' obligations under federal privacy law are about substance, not just having a document with the word "privacy" in the title.

Here's what actually needs to be in it, and where small businesses commonly fall short.

Why a Privacy Policy Isn't Optional

Most Ontario businesses that collect personal information from customers or clients in the course of commercial activity are subject to the Personal Information Protection and Electronic Documents Act (PIPEDA), a federal statute. PIPEDA expects organizations to be able to explain, openly, what personal information they collect and why. A clear privacy policy is the standard, practical way businesses demonstrate that openness — not a legal nicety.

What Your Privacy Policy Must Actually Explain

A genuinely useful privacy policy generally addresses:

ElementWhat it should cover
What you collectThe categories of personal information you actually gather — names, contact details, payment data, browsing data, and so on
Why you collect itThe specific purposes: order fulfillment, marketing, account management, and similar
How you use and share itWhether it's used only internally, or shared with service providers such as payment processors, shippers, or marketing platforms
How consent worksHow customers can consent, and how they can withdraw consent or ask questions
How it's protectedA general statement about your security practices
How to reach youA real contact point for privacy questions or complaints

A policy that's vague on all of these — "we may collect information and use it for business purposes" — technically exists but does little to meet the substance of what's expected.

Consent: The Core Requirement

Meaningful consent is the backbone of PIPEDA compliance, and your privacy policy is one of the main tools you use to obtain and support it. Consent generally needs to be informed — customers should reasonably understand what they're agreeing to, in language they can actually follow, not just legal boilerplate.

Consent expectations can also vary with sensitivity: routine information collected for an obvious purpose, like an email address used to send a receipt, generally needs less formal consent than more sensitive uses, such as sharing information with an unrelated third party or using data for a materially different purpose than originally collected.

Common Mistakes in Small-Business Privacy Policies

A Practical Checklist Before You Publish

Keeping Your Policy Current

A privacy policy is not a "set it and forget it" document. Every time your business adopts a new tool that touches customer data — a new booking system, a new payment provider, a new marketing platform — your policy should be reviewed to confirm it still accurately reflects what you're doing.

Frequently asked questions

Is there a legally required format or length for a privacy policy?

There's no fixed template mandated by law. What matters is that the policy accurately and clearly explains your actual practices in a way customers can understand, covering the core elements PIPEDA expects.

Do I need a lawyer to write my privacy policy, or can I use a generator?

Online generators can produce a starting draft, but they often don't reflect your business's actual data practices accurately, which can create a mismatch between what you say and what you do. Having a lawyer review or tailor it is worth considering, especially once you're relying on customer or payment data in any meaningful way.

Does my privacy policy need to mention specific third-party tools by name?

Not necessarily by brand name, but it should clearly describe the categories of third parties you share information with, such as payment processors, shipping providers, or marketing platforms, so customers understand where their information might go.

What should I do if I realize my current policy doesn't match what my business actually does?

Update it as soon as practical, and consider whether any past collection or use needs to be addressed separately. A stale or inaccurate policy is a compliance gap worth fixing proactively rather than waiting for a complaint.

This article is general information, not legal advice. Reading it does not create a lawyer-client relationship. Ontario laws, tax rates, and government programs change, and how the law applies depends on your specific facts. For advice about your situation, speak with a licensed Ontario lawyer. Treadstone Law is licensed by the Law Society of Ontario — reach us at 1-844-900-1070 or start a file online.

This is a corporate question

Start a file online — flat, published fees, reviewed by a licensed Ontario lawyer before a dollar is owed.

ContactStart a File →