Published July 29, 2026 · Updated July 29, 2026
Almost every Canadian small business website has a privacy policy, and a large share of them were copied from a generator, describe practices the business does not follow, and have not been read by anyone since the site launched. That is worse than having none, because an inaccurate policy is a statement about your business that is not true.
This guide covers what a privacy policy is for, what belongs in one, the specifically Canadian considerations, and how to keep it accurate as your site changes. It is written for owners rather than lawyers.
Read this first: This article is general information about a common website requirement. It is not legal advice, obligations differ by province and by what your business actually collects, and nothing here substitutes for advice from a qualified professional about your specific situation.
What is a website privacy policy?
A website privacy policy is a public statement describing what personal information your site collects, why you collect it, how you use and store it, who else receives it, and how someone can access or correct their own information. Its purpose is transparency, and its usefulness depends entirely on it being accurate.
Key takeaways
- Accuracy matters more than completeness. A short policy describing what you actually do beats a long one describing a template.
- You probably collect more than you think. Contact forms, analytics, chat widgets and booking tools all count.
- Federal and provincial rules both exist. Which applies depends on your province and your activities.
- Third parties are your responsibility to disclose, including analytics, advertising pixels and embedded tools.
- It needs reviewing when your site changes, not once at launch and never again.
What this guide covers
- Why it matters beyond compliance
- Working out what you actually collect
- The Canadian legal context, briefly
- What belongs in the policy
- Third parties, pixels and embedded tools
- Cookies and consent banners
- Forms, and the data you did not need
- Writing it so people can read it
- Keeping it accurate
- If something goes wrong
- Email marketing and consent
- Choosing tools with privacy in mind
- Privacy in a B2B context
- Terms of service
- Where privacy, security and accessibility overlap
- A twenty minute review of your policy
- Frequently asked questions
Why it matters beyond compliance
The compliance argument is real and it is not the most persuasive one for a small business. The practical arguments are more immediate: customers increasingly check, business clients ask for it during vendor review, and payment providers and advertising platforms require one before approving an account.
There is also a trust dimension. A clear, human privacy policy signals a business that has thought about how it handles information. A generic one that mentions services you do not use signals the opposite, and people notice the mismatch more often than owners assume.
The risk of an inaccurate policy is specific. If your policy says you do not share information with third parties while your site runs an advertising pixel, the statement is untrue, and that is a worse position than saying nothing.
Working out what you actually collect
Most small business owners underestimate this, because collection happens through tools rather than through deliberate decisions. Before writing anything, list what your site genuinely gathers.
Sources of collection to check
- Contact and enquiry forms, including every field, not just name and email
- Booking or appointment tools, which frequently collect more than the booking requires
- Analytics, including whether IP addresses are stored and for how long
- Advertising pixels and remarketing tags
- Live chat widgets, which typically store transcripts
- Newsletter signup and the email platform behind it
- Payment processing, and what data touches your systems versus the processor’s
- Server logs, which record IP addresses whether you look at them or not
- Embedded maps, videos and social feeds, which set their own cookies
Two questions are worth asking about each item. Do we need this to run the business, and where does the data actually go? A surprising amount of small business collection is incidental, arriving with a plugin nobody chose for that purpose.
Where the answer is that you do not need it, the best privacy decision is to stop collecting it. Data you do not hold cannot be misused, breached or misdescribed.
“The simplest way to improve your privacy position is to collect less. It costs nothing and it removes the obligation rather than managing it.”
The Canadian legal context, briefly
Canada has a federal private-sector privacy law, the Personal Information Protection and Electronic Documents Act, alongside substantially similar provincial legislation in some provinces. Which framework applies to a given business depends on the province and the nature of the activity.
The Office of the Privacy Commissioner of Canada publishes plain-language guidance, and its overview of privacy laws in Canada is the sensible starting point for understanding which rules apply to you. Its material on PIPEDA covers the federal framework in more detail.
Beyond Canada, if you have customers elsewhere, other regimes may be relevant. A business selling to European customers, for instance, may have obligations that Canadian law does not impose. This is exactly the kind of question worth putting to a professional rather than resolving from a blog post, including this one.

What belongs in the policy
A workable small business privacy policy is shorter than most templates and considerably more specific. It should answer the questions a reasonable visitor would ask, in the order they would ask them.
- Who you are and how to contact you about privacy specifically, with a real address or email.
- What you collect, listed concretely rather than as categories. Name the form fields and the tools.
- Why you collect it, purpose by purpose. Enquiry handling and marketing are different purposes.
- Who else receives it, including your email platform, analytics provider, booking tool and payment processor.
- How long you keep it, at least approximately. “Indefinitely” is an answer, and it is one worth reconsidering.
- How someone accesses, corrects or deletes their information, with a route that actually works.
- How you protect it, described honestly rather than with security theatre.
- When the policy was last updated, dated, at the top or bottom.
That last item is the one templates omit and the one that most clearly signals whether the policy is maintained. An undated policy tells a reader nothing about whether it still describes the business.
Third parties, pixels and embedded tools
This is where small business policies are most often inaccurate, because third-party collection is invisible in the page and easy to forget. Every embedded tool is a party receiving information about your visitors.
Audit them directly rather than from memory. Open your site in a private browsing window and check which external domains the page contacts, using your browser’s developer tools. Most owners find at least one they had forgotten about entirely.
Then disclose them by function rather than only by name, so a reader understands what is happening. “We use an analytics service to understand how the site is used” is more useful to a visitor than a list of vendor names with no explanation.
Advertising and remarketing pixels deserve particular attention because they involve sharing behavioural data for marketing purposes, which is a materially different proposition from measuring page views. If you run them, say so plainly.
Cookies and consent banners
Consent banners have spread across Canadian sites largely by imitation, and many of them do nothing. A banner that says “we use cookies” with a single accept button, while all the cookies have already been set before anyone clicked, is not obtaining consent. It is an announcement.
If you deploy a banner, configure it so that non-essential cookies genuinely do not load until consent is given, and so that declining is as easy as accepting. A banner that only blocks after acceptance is a decorative element that also annoys visitors.
For many small business sites, the better answer is to reduce what needs consent in the first place. A site running only privacy-respecting analytics and no advertising pixels has a much simpler position than one carrying four marketing tags, and it loads faster too.
A useful check: Load your site in a private window, decline the banner, then look at what cookies are set. If the answer is the same as accepting, your banner is not doing the job it appears to do.
Forms, and the data you did not need
Forms are the most deliberate collection on your site and the easiest to over-specify. Fields get added because they might be useful, and each one becomes information you hold, store, secure and describe.
Review every field against a single question: what would we do differently if we did not have this? Postal addresses on a general enquiry form, dates of birth, and detailed circumstances collected before any conversation has happened are common examples of collection without a purpose.
Shorter forms also convert better, which makes this one of the few privacy improvements with an immediate commercial return. Removing three unnecessary fields typically increases completions and reduces your obligations at the same time.
Consider where submissions go and how long they stay there. Enquiries sitting in a shared inbox indefinitely, or in a form plugin’s database for years, are a retention decision made by default rather than deliberately.
Writing it so people can read it
Most privacy policies are written to be defensible rather than to be understood, which is why nobody reads them. For a small business, a policy someone can actually follow is more useful than one that mimics enterprise legal language.
Write in plain sentences, use headings that match the questions people have, and keep it as short as accuracy allows. Where you must include something technical, explain it once in ordinary words rather than assuming.
Make it accessible in the practical sense too: a real HTML page rather than a PDF, readable on a phone, linked from your footer on every page, with adequate contrast. A policy nobody can read on the device they are using is not transparency, a point we made at more length in our guide to website accessibility standards.
Keeping it accurate
A privacy policy describes a moment in time and your website keeps changing. A new booking tool, a marketing pixel added for one campaign and never removed, a switch of email platform: each changes what the policy should say, and none of them prompts anyone to update it.
Tie the review to the change rather than to the calendar. Add one line to whatever process you use for site changes: does this affect what we collect or who receives it? That catches most of it at the moment it happens.
Then review annually regardless, alongside your other maintenance. Update the date, confirm the contact route still works, and remove anything describing a tool you no longer use. Ten minutes a year keeps the document honest.
If something goes wrong
Privacy incidents at small businesses are usually mundane rather than dramatic: a form plugin left unpatched, an email sent to the wrong list with everyone visible, a laptop lost, a contractor still holding access months after finishing. None of these feels like a breach until it is.
Have a basic response plan before you need one. Who is told, in what order. Whether the incident involves a real risk of significant harm, which is the relevant threshold in the federal framework and the point at which reporting obligations may arise. What you say to the people affected, and when.
Keep a record of incidents even where no reporting obligation applies. Businesses that record small incidents notice patterns, and patterns are what allow a problem to be fixed before it becomes a serious one.
The prevention side overlaps almost entirely with ordinary website security: keeping software current, limiting who has access, removing accounts when people leave, and taking backups. We set that out in our guide to small business website security, and it is the same work whether you frame it as security or privacy.
The most common small business exposure: Old contractor and former staff accounts that were never removed. It is invisible, it costs nothing to fix, and it is worth auditing today rather than at the next review.
Email marketing and consent
Email marketing carries its own Canadian rules, separate from privacy law, and small businesses trip over them regularly because the requirements are more specific than most assume. Consent, identification and a working unsubscribe are the three practical pillars.
Consent is the one most often misunderstood. Someone who submitted an enquiry form has consented to being contacted about that enquiry. Whether they have consented to a monthly newsletter is a separate question, and treating one as the other is how businesses end up with a list they cannot legitimately use.
Practical email hygiene
- Separate the enquiry form from the newsletter signup, with a distinct opt-in for marketing
- Record when and how each subscriber consented, and keep that record
- Identify your business clearly in every message, including a mailing address
- Make unsubscribing one click, and process it promptly rather than at the next send
- Never add customers to a marketing list automatically because they bought something
- Review the list periodically and remove addresses that have not engaged in a long time
Buying or renting lists is the practice worth avoiding entirely. Beyond the consent problem, purchased lists perform badly, damage your sending reputation, and create exactly the kind of record-keeping gap that is difficult to explain afterwards.
Choosing tools with privacy in mind
Every tool you add to your site is a decision about where your customers’ information goes. Small businesses rarely have leverage to negotiate terms, and they do have a choice about which vendors they use, which is most of the influence available.
Three questions cover most of it. Where is the data stored, since data location can matter for some obligations and for some clients. What does the vendor do with it beyond providing the service. And can you export and delete it if you leave.
That last question is worth asking before you commit rather than after. Tools that make export difficult create a dependency that becomes expensive later, and a vendor that cannot explain its deletion process is telling you something.
Prefer fewer tools doing more. Every additional vendor is another party receiving data, another entry in your policy, another set of terms nobody read and another account that needs removing when someone leaves. Consolidation is a privacy improvement as well as an administrative one.
Privacy in a business-to-business context
Businesses selling to other businesses sometimes assume privacy rules are a consumer matter. In practice, information about individuals at those businesses is still information about individuals, and larger clients increasingly ask about your practices during procurement.
That vendor review is worth preparing for. Being able to answer what you collect, where it is stored, who has access and how you handle an incident is frequently the difference between a smooth onboarding and a stalled one, particularly with public sector and enterprise clients.
A clear, accurate, dated privacy policy does a surprising amount of that work on your behalf. It is one of the few compliance documents that also functions as a sales asset, which makes the effort easier to justify.
“For a small business, the privacy policy nobody reads is also the document a large client reads first.”
Terms of service and the other page people forget
Privacy policies get attention and terms of service rarely do, yet for many small businesses the terms page is the one that matters commercially. It sets out what you are agreeing to when someone buys, books or submits an enquiry through your site.
For a service business, terms typically cover what is included, payment and cancellation, how disputes are handled, and limits on liability. For anything selling online, refund and return terms are frequently a legal requirement as well as a commercial one.
Keep the two documents separate and link both from the footer. Merging them produces a document that answers neither question well, and it makes updating either one harder than it needs to be.
As with privacy, a template is a starting structure rather than a finished document, and the terms that matter most are the ones specific to how your business actually operates. This is general information rather than legal advice, and terms are exactly the sort of thing worth having a professional look over once.
Where privacy, security and accessibility overlap
These three get treated as separate compliance topics and they share most of the same underlying work. Knowing what is on your site, who has access, what it collects and whether people can actually use it are four questions with one answer: an accurate picture of your own website.
One audit, three outcomes
- Inventory every third-party script: a privacy disclosure, a security surface and a speed cost all at once
- Review who has admin access: a security control and a privacy control simultaneously
- Check forms: field minimisation is privacy, validation is security, labelling is accessibility
- Keep software current: security first, and it prevents the data incidents privacy law cares about
- Publish policies as readable HTML pages: accessibility and transparency together
Doing these as one exercise rather than three separate projects is considerably less work and produces a more accurate result, because the same person is looking at the same site with the whole picture in view. It is also why we treat them as one maintenance stream rather than three.
A twenty minute review of your current policy
Most businesses reading this already have a privacy policy and have not looked at it in years. Before rewriting anything, it is worth finding out how far the existing one is from reality, which takes about twenty minutes.
- Read it end to end. Most owners have never done this, and it is frequently the point at which the problems become obvious.
- Highlight every specific claim. Anything saying you do or do not do something is a factual statement that is either true or is not.
- Open your site in a private window and list every external domain it contacts. Compare that to what the policy discloses.
- List your live forms and their fields. Check the policy describes what you collect and why.
- Check the contact route works. Send an email to the address in the policy and see whether it arrives anywhere anyone reads.
- Look for the last-updated date. If there is not one, that is the first thing to add.
The usual finding is not that the policy is badly written. It is that it describes a website that no longer exists, mentioning tools removed years ago and omitting three added since. That is a maintenance problem rather than a drafting one, and it is much cheaper to fix.
Where the gap is large enough that you are rewriting rather than amending, that is the moment to get professional input rather than reaching for another template. It is a small cost once, against a document that represents your business to every customer and every prospective client who checks.
Not sure what your website is actually collecting?
Every GoWebsited plan includes ongoing maintenance, so third-party scripts, forms and tracking get reviewed rather than accumulating unnoticed.
Frequently asked questions
Does my small business website need a privacy policy?
If your site collects any personal information, including through contact forms or analytics, you should describe that publicly. Payment providers and advertising platforms also commonly require one. Whether a specific legal obligation applies depends on your province and activities, so confirm your position with a qualified advisor.
Can I use a privacy policy template?
A template is a reasonable starting structure and a poor finished document. The problem is that templates describe generic practices, and a policy that does not match what your site actually does is inaccurate, which is a worse position than a short accurate one.
What counts as personal information on a website?
More than most owners expect: form submissions, email addresses, IP addresses in server logs and analytics, chat transcripts, booking details and behavioural data collected by advertising pixels.
Do I need a cookie consent banner in Canada?
It depends on what you set and your specific obligations. What matters practically is that a banner should actually control loading rather than appearing after cookies are already set, and that declining should be as easy as accepting.
Where should the privacy policy link go?
In the footer, on every page, as a normal HTML page rather than a PDF. It should be readable on a phone and reachable from anywhere on the site, including your forms.
How often should I update it?
Whenever you change what you collect or add a tool that receives visitor data, and at minimum once a year as a scheduled check. Include the last-updated date so readers can see it is maintained.
Do I have to list every third-party tool by name?
Describing them by function helps readers understand what is happening, and naming the significant ones is clearer still. The important thing is that a visitor can tell what categories of party receive information and why.
What is the simplest way to reduce my privacy obligations?
Collect less. Remove form fields you do not use, remove tracking tags you are not acting on, and remove embedded widgets nobody engages with. Data you never collect requires no policy, no storage and no protection.