TechZone Grid Pulse
Articles · PIPEDA 2025-04-16

PIPEDA and your business: what Canadian small business owners actually need to know

A consultant's plain-language guide to Canada's federal privacy law — what it covers, who it touches, and where small businesses quietly fall short.
S
Susan Dunmore
Consultant
2025-04-16
small business, e commerce, order packing, business owner, online store, packaging, shipping orders, home business, star

A bakery owner in Kitchener collects customer email addresses at checkout, stores them in a spreadsheet on a shared Google Drive, and sends a monthly newsletter using a free Mailchimp account — and has never once thought about whether any of that is governed by federal privacy law. A physiotherapy clinic in Halifax keeps scanned intake forms in a folder on a receptionist's desktop, password-protected with the clinic name followed by an exclamation mark. A two-person e-commerce shop in Calgary accepts online payments, logs customer addresses, and uses a third-party analytics platform that drops cookies tracking behaviour across the internet — and their privacy policy, if they have one at all, was copied from a competitor's website sometime in 2019. These are not outliers. They are, in my experience reviewing small business operations across Canada, remarkably ordinary situations — and all three of them carry real legal exposure under PIPEDA, the Personal Information Protection and Electronic Documents Act, a federal statute that has been in force since 2001 and that most small business owners have heard of only vaguely, if at all.

What PIPEDA actually is, and why it still matters in 2024

PIPEDA came into force federally on January 1, 2001, and was extended to cover most private-sector organisations collecting personal information in the course of commercial activity by 2004. It is administered by the Office of the Privacy Commissioner of Canada, a parliamentary officer who can investigate complaints, publish findings, and — since amendments introduced in 2015 under the Digital Privacy Act — require organisations to notify affected individuals and the Commissioner when a breach of security safeguards creates a real risk of significant harm. The law is built around ten fair information principles drawn from the Canadian Standards Association's Model Code for the Protection of Personal Information, and those principles cover everything from accountability and identifying purposes to individual access and challenging compliance.

Quebec, Alberta, and British Columbia each have substantially similar provincial legislation — Quebec's Law 25 being the most recently overhauled and the strictest of the three — and organisations operating in those provinces are generally exempt from PIPEDA for activities covered by the provincial law. But for the majority of small businesses operating federally, in Ontario, Nova Scotia, Manitoba, Saskatchewan, or any other province without a designated substantially similar law, PIPEDA is the operative statute. The point is simply this: if your business collects, uses, or discloses personal information about customers, employees, or website visitors in the course of commercial activity, there is almost certainly a federal privacy law that applies to you, and it has teeth.

Which businesses PIPEDA applies to — and the exemption that trips people up

The threshold question most small business owners ask is whether their business is large enough to matter. The honest answer is that size is almost entirely irrelevant under PIPEDA. A sole proprietor selling handmade jewellery through an online storefront, processing payments through Square, and retaining customer shipping addresses is conducting commercial activity and collecting personal information — both elements that trigger the Act. The same applies to a freelance graphic designer who keeps a client contact list, a personal trainer who collects health information on intake forms, and a small landlord who screens rental applicants.

The one exemption worth understanding is the employee information exemption for federally regulated businesses — banks, airlines, telecommunications companies, and the like — where employee information collected and used in the employment context is excluded from PIPEDA's scope. But most small businesses in Canada are provincially regulated, and in provinces without substantially similar legislation, that employment information exemption does not apply in the same way. The result is that a small Ontario manufacturer, for example, may have PIPEDA obligations with respect to both its customers and its employees, though in practice the Commissioner's enforcement focus has been overwhelmingly on customer-facing data practices.

The consent requirement, and what 'meaningful' actually means in practice

The principle that causes the most confusion in small business settings is consent — specifically, the requirement under PIPEDA that individuals must give meaningful consent to the collection, use, or disclosure of their personal information, and that this consent must be informed. The Office of the Privacy Commissioner released updated guidance on consent in 2019 that is worth reading carefully, because it shifted the standard in ways that many businesses have not kept pace with. Meaningful consent requires that individuals understand what information is being collected, why it is being collected, who it may be shared with, and what the risks of that sharing might be — and it must be expressed in plain language that an ordinary person can reasonably be expected to understand.

Where businesses go wrong most often is in treating consent as a one-time checkbox event rather than an ongoing relationship. Collecting an email address to process an order and then adding that address to a marketing list without separately disclosing that use — and obtaining consent for it — is a textbook PIPEDA violation. So is updating a privacy policy to cover new data uses without notifying existing customers and obtaining their fresh consent for the new purposes. The law does recognise implied consent in some circumstances, particularly where the purpose is obvious and the person voluntarily provides the information, but implied consent has limits, and those limits are narrower than most small business owners assume.

The first common gap I find: the privacy policy that does not actually reflect what the business does

In strategy reviews, the single most frequent compliance gap I encounter is a privacy policy that was drafted — or more often copied — years ago and has never been updated to reflect how the business actually operates today. A retailer who added a loyalty program in 2021 but whose privacy policy still describes only basic order processing. A service business that started using a CRM platform with built-in email sequencing but whose policy says customer contact information is never shared with third parties. A medical aesthetics clinic that integrated a booking software platform that stores client health information on servers in the United States, with no cross-border disclosure in sight.

PIPEDA requires that privacy policies be accurate, current, and written in plain language. They must identify the organisation, the person accountable for compliance (the 'privacy officer,' even if that person is the owner), the purposes for which information is collected, and how individuals can access their own information or submit a complaint. They must also disclose any cross-border transfers of data, including the country to which it is transferred and the fact that it may be subject to that country's laws — an obligation that becomes immediately relevant the moment a business adopts any cloud-based software with servers outside Canada, which in practice means almost every business using popular SaaS tools.

The fix is not complicated, but it requires honesty about what the business actually does. I usually ask owners to walk me through every point at which customer information is collected, every platform or tool that touches it, and every person inside or outside the business who has access. That inventory, done carefully, becomes the foundation of a policy that actually reflects reality — which is the only kind that provides meaningful legal protection.

A privacy policy that doesn't match your actual data practices isn't just a compliance gap — it's a liability you've written yourself.

The second and third gaps: breach response plans and vendor contracts

The second gap, and in some ways the more consequential one, is the absence of any breach response plan. Since the mandatory breach notification amendments took effect in November 2018, organisations subject to PIPEDA have been required to report to the Privacy Commissioner any breach of security safeguards that creates a real risk of significant harm to an individual. They must also notify the affected individuals directly, and they must maintain records of all breaches — even those assessed as not meeting the reporting threshold — for a minimum of 24 months. Most small business owners I work with have never heard of the 24-month record-keeping requirement, and fewer still have a documented plan for what to do in the first 72 hours after discovering that customer data has been exposed.

A breach response plan does not have to be lengthy. What it does have to do is specify who inside the organisation is responsible for managing the response, what the immediate containment steps are, how the business will assess whether the real-risk-of-significant-harm threshold is met, who the business's legal counsel is, and how notifications will be drafted and delivered. Having thought through these questions before an incident — rather than scrambling through them at two in the morning after discovering that a phishing email compromised an employee's inbox — makes an enormous practical difference.

The third gap is vendor contracts, sometimes called data processing agreements or privacy agreements. PIPEDA's accountability principle holds that an organisation remains responsible for personal information it transfers to a third party for processing, and it must use contractual or other means to provide a comparable level of protection while the information is in the third party's hands. In practice, this means that if you are handing customer data to a payroll processor, a marketing platform, a cloud storage provider, or any other vendor, you should have a written agreement that addresses how that vendor will protect the data, what they will do in the event of a breach, and how the data will be handled when the relationship ends. Many small business owners have accepted vendor terms of service without reading them carefully enough to know whether these protections exist — or, in some cases, have no formal agreement with vendors at all.

Where to start if you are not sure where you stand

The Office of the Privacy Commissioner of Canada publishes genuinely useful guidance documents at priv.gc.ca, including a self-assessment tool for small and medium-sized businesses and a plain-language guide to PIPEDA's requirements. These are worth reading before engaging any consultant, because they will help you formulate better questions and give you a clearer sense of where your gaps are likely to be. The Commissioner's published findings in complaint cases are also instructive — they are searchable by topic and give a sense of what enforcement actually looks like in practice, which tends to be far more concerned with systemic failures and lack of accountability than with technical minutiae.

If you are in Quebec, the requirements under Law 25 are more prescriptive and the penalties more severe — up to 4% of worldwide turnover for the most serious violations — and the timeline for compliance has been rolling out in phases since September 2022, with additional obligations coming into force in September 2023. Even if your business is small and your operations seem straightforward, the Quebec framework warrants specific attention from anyone serving Quebec residents.

The honest starting point, regardless of province, is a data inventory: what personal information does your business collect, from whom, for what purposes, where is it stored, who has access to it, and where does it go when it leaves your systems. That inventory, completed carefully and honestly, is the foundation on which everything else — policy, consent practices, breach response, vendor agreements — is built. It is not glamorous work. But it is the work, and doing it before a complaint is filed or a breach occurs is considerably easier than doing it after.

Privacy compliance for small businesses in Canada is genuinely achievable without a legal department or an enterprise budget — it mostly requires slowing down long enough to understand what information you actually hold and what obligations attach to it. If you have questions about where your business stands, I am glad to talk through it.

#PIPEDA#Canadian privacy law#small business compliance#data protection#privacy policy

Related reading

See all news

Straightforward technology consulting for Canadian businesses.

Home

Home

Learn more about what we do.

Read more →
About

The story behind the practice

Meet the people behind the work.

Read more →
Contact

How to reach susan

Come visit, or drop us a line.

Read more →
Privacy

Privacy

Learn more about what we do.

Read more →
Terms

Terms

Learn more about what we do.

Read more →