The situation
'How much is this going to cost us, and how long until we know it's fixed?' That was Radu's first question on the call, before he had even finished explaining what had gone wrong. Not whether the company was in serious trouble. Not who was at fault. He wanted a number and a date, because he had learned over eight years of running a business that the two things that actually keep him up at night are open-ended legal bills and problems with no visible end.
Radu and Farid had built their company together after leaving their respective careers, Radu as a respiratory therapist and Farid as a surveyor, to start a business supplying and servicing equipment for home care providers across the Windsor region. The company had grown steadily into an established operation with several million dollars in annual revenue, a customer list running into the thousands, and a marketing program that sent out regular emails about new products, service reminders and seasonal offers.
The complaint came from a customer named Jamal, who had bought a single piece of equipment through a one-time order years earlier and had never signed up for anything beyond that transaction. He began receiving marketing emails anyway, unsubscribed once, kept receiving them for another month, and then wrote a pointed message asking how his information had ended up on a marketing list he never agreed to join.
Farid, who handled most of the company's back-office systems, pulled the customer database and found the honest answer was that nobody could say for certain. The marketing list had been built up over years, folded together from several sources, without a clear record of who had actually opted in and who had simply been added because they were customers. Jamal's complaint was not really about one email. It was a symptom of a consent process that had never been designed on purpose in the first place.
Radu's question about cost was not idle. The company had weathered a slow first two years after he and Farid left stable, salaried work to start it, financing the early inventory on a line of credit that took most of a decade to pay down. He had learned, in that stretch, to treat every unplanned expense as a threat to be sized up immediately rather than absorbed quietly and hoped away, and a privacy complaint that could, in theory, touch every customer on a list built up over years read to him like exactly that kind of threat until someone could tell him otherwise, in concrete terms he could plan around.
The gap nobody had noticed
When we reviewed the company's privacy policy against how it actually collected and used customer information, the mismatch was immediate. The published policy said the company would use contact information 'as needed for business purposes,' language broad enough to mean almost anything and specific enough to mean almost nothing. It did not distinguish between the information needed to fulfil an order and the separate, additional step of adding someone to a marketing list.
The actual practice was worse than the vague policy suggested. Every customer who placed an order, whether through the website, over the phone, or in person, was automatically added to the marketing email list unless they specifically asked to be left off. There was no separate checkbox, no clear moment where a customer agreed to receive marketing communications distinct from agreeing to complete a purchase. Consent for the transaction and consent for marketing had been treated as the same thing, when they are not.
This is the gap privacy compliance turns on: a business can generally use customer information to complete the transaction the customer asked for, but using that same information for an ongoing purpose like marketing usually calls for the customer's separate, informed agreement, along with a clear and working way to withdraw it. Jamal's unsubscribe request had also been mishandled at a technical level, routed to a list the marketing platform did not actually check before sending the next batch, which explained why he kept receiving emails after asking to stop.
None of this had been deliberate. Farid had set up the customer database years earlier using the marketing platform's default settings, and nobody had revisited those settings as the company grew from a handful of customers to several thousand. The gap had been sitting there the entire time, invisible until one customer's complaint forced a closer look.
Radu had heard, in a general way, that privacy rules mattered for businesses that collected customer information, but he had always treated it as background noise, something covered by the boilerplate policy their web developer had installed years earlier along with the rest of the site template. It had never occurred to him that the policy on the website and the actual behaviour of the marketing platform behind it could tell two different stories, or that Jamal's single complaint was really a question about a much larger group of customers who had never noticed, let alone objected.
Federal privacy law governing private-sector businesses expects an organization to be able to explain, in plain terms, what it does with personal information and to make that explanation meaningful rather than boilerplate. A policy that says information will be used 'as needed for business purposes' does not meet that expectation, because it does not tell a customer anything they could actually use to decide whether to agree. The gap Jamal's complaint exposed was not only a settings problem inside the marketing platform; it was that the company's public commitment about its own data practices had never matched what those practices actually were, and nobody had checked the two against each other since the policy first went up.
What we did
- Gave Radu and Farid a fixed-scope plan before starting any drafting. Because predictability mattered as much to them as the outcome, we laid out the specific deliverables, an audit summary, a rewritten policy, and revised collection points, along with a firm estimate for each, before doing any of the underlying work. This let them approve the plan once rather than worry about the cost growing as we went.
- Audited the full customer data flow, not just the marketing list. We traced how contact information moved from each intake point, the website, phone orders, in-person sales, into the customer database and from there into the marketing platform, because fixing only the channel Jamal happened to use would have left the same default-opt-in problem sitting in the other two. This showed us every place consent needed to be captured, not just the one his complaint had surfaced.
- Rewrote the privacy policy in plain, specific language. We replaced the vague 'business purposes' language with a clear description of what customer information is used for, including a distinct section on marketing communications and how to opt out of them. A policy customers can actually read and understand is also one that holds up if a complaint is ever escalated.
- Separated transaction consent from marketing consent at every intake point. We had Farid's team add a distinct, unchecked marketing opt-in at checkout and on the website contact form, because a customer completing a purchase had agreed only to that transaction and nothing about receiving ongoing marketing communications. Once in place, completing a purchase no longer automatically added a customer to the marketing list, which was the single change that closed the actual gap.
- Fixed the unsubscribe mechanism. We worked with Farid to confirm that unsubscribe requests were actually removing customers from every list the marketing platform used to send emails, not just one of several, which is what had caused Jamal to keep receiving messages after asking to stop. We tested the fix ourselves with a dummy account rather than accepting Farid's word that the settings screen looked correct, since an interface that appears fixed is not the same as a send process that has actually changed.
- Reviewed the existing marketing list against the new consent standard. Rather than assume the historic list was fine because nobody besides Jamal had complained about it, we had the company send a one-time re-consent email to everyone on it, asking recipients to confirm they wanted to keep receiving marketing communications, and removed anyone who did not respond within the stated window. This brought years of accumulated names into line with the same standard the new intake points now enforced.
- Responded to Jamal directly. We drafted a response acknowledging the error, confirming he had been removed from all marketing lists, and explaining the fix the company had put in place so the same failure could not recur for another customer. The letter offered nothing beyond the acknowledgment and the fix, since overcompensating a single complainant risked signalling the company saw this as a liability to be bought off rather than a process it had genuinely corrected.
- Set a standing annual review as the last item, not an afterthought. To keep the fix from quietly decaying the way the original settings had, we built a short annual checklist for Farid covering the intake points, the unsubscribe mechanism and the policy wording, timed to a fixed date each year so it would not depend on anyone remembering to think of it.
The outcome
The whole engagement ran to the estimate Radu had asked for on that first call, both in scope and in cost, which mattered to him more than any other single measure of success. The consent gap was closed: transaction and marketing consent are now separate, the unsubscribe mechanism works across every list, and the privacy policy describes what actually happens to customer information rather than a vague catch-all.
Jamal accepted the company's response and did not pursue the complaint further. The re-consent process trimmed the marketing list by roughly a third, which Radu had initially worried about as a business cost, since fewer people meant fewer potential customers for each campaign. In practice the smaller list performed no worse, made up of people who had actually agreed to hear from the company rather than people added by default.
Farid now reviews the intake settings on the marketing platform once a year as a standing item, a habit that cost the company nothing and closes off the kind of drift that let the original gap open in the first place. For a business built by two people who left stable careers to run something of their own, the fix that mattered most was not the specific wording of the policy but knowing, going forward, exactly what the company was agreeing to when a customer handed over their information.
Radu, still keeping an eye on the number he had asked about first, said afterward that the predictability of the process mattered more to him than he had expected going in. He had braced for the kind of open-ended review that drags on for months while the invoices keep coming, and instead got a defined start and end point, which let him plan around the engagement rather than treat it as an unresolved worry sitting in the background of the business.
What you can learn from this
- Agreeing to a purchase is not the same as agreeing to marketing emails, and treating them as one consent instead of two is a common, quietly serious gap that grows with every new customer added to the list.
- An unsubscribe request only works if it actually reaches every list a company uses to send communications, which is worth testing directly rather than assuming the software handles it correctly.
- A privacy policy written in vague, catch-all language often signals that the underlying data practice has never actually been mapped out, not just that the wording needs polish.
- If predictable cost matters to you as much as the legal outcome, ask for a fixed-scope plan with a firm estimate up front, rather than agreeing to open-ended hourly work.
- Reviewing the default settings on the software tools a business relies on, even years after setup, can surface consent and data-handling problems nobody built into the system on purpose.
This is a corporate problem we handle
Start a file online — flat, published fees, reviewed by a licensed lawyer before a dollar is owed.