Canada, Quebec and Privacy Simple

Digital Compliance

PIPEDA, Explained

For Business Owners, Not Lawyers

By Tyler Hackbart 1 month ago 4 min read

Personal Information Protection and Electronic Documents Act, Canada's federal privacy law stands for the Personal Information Protection and Electronic Documents Act. It is Canada's federal privacy law, it has been in force since the early 2000s, and it governs how private businesses handle the personal information of the people they deal with. If you run a commercial website in most of Canada, it applies to you.

Here is the part that surprises people. The Accessibility for Ontarians with Disabilities Act's web standard only reaches organizations with fifty or more employees in Ontario, so a smaller business can read that rule, correctly decide it is not caught, and then quietly assume nothing else applies. Personal Information Protection and Electronic Documents Act, Canada's federal privacy law has no threshold at all. A one person shop collecting personal information is covered on the same terms as a company of five hundred. Size does not get you out of this one.

What counts as personal information

You might think you do not collect personal information because you never ask for a name. But the law reaches further than that. A persistent identifier, like the client ID that Google Analytics stores in a visitor's browser, or the data a Meta pixel sends back, can count as personal information even with no name attached. It is tied to a person and it follows them around, and that is enough to bring it into scope.

So the pixel firing on your homepage the instant a stranger lands, before they have clicked anything or agreed to anything, is not a neutral technical detail. It is a collection of personal information, and the law has expectations about how you do that.

The three ideas that matter most

  1. Meaningful consent. People should understand what you are collecting and agree to it in a way that actually means something. Sometimes that agreement can be implied and sometimes it has to be an explicit yes, which is the next section.
  2. Openness. You need a real privacy policy that a person can find and read, that says what you collect and why. Openness is not optional decoration. It is a core principle of the law.
  3. Identifying purposes. You tell people why you are collecting, at the time you collect it, not after the fact.

When consent can be implied, and when it cannot

This is the part that gets sold back to you wrongly more than anything else in this lane. Canada has no cookie banner law. There is no Canadian rule that a wall has to appear before a cookie can be set, and anyone telling you otherwise is describing Europe.

Under Personal Information Protection and Electronic Documents Act, Canada's federal privacy law, consent can be implied for information that is not sensitive. That is the path ordinary website analytics usually sit on, and it comes with conditions. Your notice has to be findable rather than buried. The purpose has to be written in plain language a person can follow. Opting out has to be easy. And the opt out has to actually take effect. A decline button that leaves the tags firing fails that last one, and it is the failure we find most often.

Express consent, a clear opt in before anything collects, is required in narrower situations. Sensitive information needs it. So does a profiling or tracking purpose that a reasonable person would not expect from a site like yours. So does a site aimed at children. So does session recording that captures what someone types into a form. Quebec's Law 25 goes further still and expects technology that profiles, locates or identifies a person to be off by default.

So the honest answer to whether you need a banner is that it depends on what you run and who you serve. What is not optional is that people can find out what you collect and that saying no does something.

A quick example

A visitor lands on your booking page. Before they touch anything, analytics and an advertising pixel fire, storing an identifier and sending their visit off to a couple of third parties. There is no notice and no privacy policy that names those tools. That is a gap against consent, against openness, and against identifying purposes, all at once, and the business usually has no idea it is happening.

None of this is a claim that you are breaking the law today. It is a gap to review. Most sites we look at have some version of it, and most of it is straightforward to fix.

We are not lawyers and this is not legal advice. It is what the Act says and what we find on real sites. For a ruling on your own obligations, talk to a lawyer.

The reassuring part is that Personal Information Protection and Electronic Documents Act, Canada's federal privacy law is principle based, not a checklist of traps. Once you know what it expects, the fixes are ordinary web work: a proper notice, a consent step that works, and an honest policy. If you want to know where your site stands, that is exactly what we check.

Want to know where your own site stands? See what the audit covers, or reach out and we'll get the ball rolling.

Reach out
#