Website privacy laws in Canada: PIPEDA, Quebec Law 25 and CASL
If your Canadian business website collects any personal information — a contact form, a newsletter signup, analytics cookies — three laws apply: PIPEDA federally, Quebec's Law 25 if you serve anyone in Quebec, and CASL for every marketing email you send. In practice that means a real privacy policy, meaningful consent for tracking, a compliant cookie banner where Law 25 applies, and opt-in email lists with a working unsubscribe. This guide explains what each law requires and gives you a practical checklist. It is general information, not legal advice.
Key takeaways
- PIPEDA is the federal baseline: any business collecting personal information in commercial activity needs identified purposes, meaningful consent and an accessible privacy policy.
- Quebec Law 25 reaches beyond Quebec — it applies to any business handling personal information of people in Quebec, wherever the business is located.
- Law 25 penalties are serious: administrative penalties up to $10 million or 2% of worldwide turnover, and penal fines up to $25 million or 4%, whichever is greater.
- CASL is opt-in, not opt-out: you need express or limited implied consent before sending commercial email, with penalties up to $10 million per violation for businesses and $1 million for individuals.
- Cookie banners are not decoration: under Law 25, non-essential tracking such as analytics and ad pixels should stay off until the visitor agrees.
- Most compliance is one-time setup: a proper policy, a consent-mode banner, unbundled form checkboxes and an unsubscribe flow cover the bulk of it.
The three laws at a glance
Canadian privacy law is a patchwork, but for a typical small-business website it reduces to three regimes with different jobs:
- PIPEDA (Personal Information Protection and Electronic Documents Act) — the federal private-sector law governing how you collect, use and disclose personal information in commercial activity. Alberta, BC and Quebec have their own substantially similar provincial laws for activity inside those provinces.
- Quebec Law 25 — Quebec's modernized private-sector privacy law, phased in between 2022 and 2024. It is the strictest regime in Canada, with GDPR-style consent rules and GDPR-scale fines.
- CASL (Canada's Anti-Spam Legislation) — governs commercial electronic messages: marketing emails, newsletters, promotional texts. It regulates the sending, not the storing, of data.
"Personal information" is broader than most owners assume: names and emails, obviously, but also IP addresses, device identifiers and behavioural data collected by analytics tools and ad pixels.
PIPEDA: the federal baseline for every business
PIPEDA applies when you collect, use or disclose personal information in the course of commercial activity — which describes almost every business website with a form. Its core demands are principles rather than checkboxes:
- Identify purposes: know and state why you collect each piece of information, at or before collection.
- Meaningful consent: people must understand what they are agreeing to; consent buried in legalese does not qualify.
- Limit collection: gather only what you need. A quote form does not need a birthdate.
- Safeguards: protect the data you hold with security appropriate to its sensitivity — HTTPS, access controls, patched software (see our website security basics).
- Openness and access: publish an accessible privacy policy and be able to show people their data on request.
- Breach reporting: report breaches posing a real risk of significant harm to the Privacy Commissioner and affected individuals, and keep records of all breaches.
Enforcement is complaint-driven and historically proportionate for small businesses, but not toothless: specific offences — failing to report a breach, failing to keep breach records, obstructing an investigation — carry fines up to $100,000 per violation.
Quebec Law 25: the strictest rules in Canada
Law 25 modernized Quebec's private-sector privacy law in three waves (2022, 2023, 2024), and its reach surprises people: it applies to any organization handling the personal information of people in Quebec, whether the business sits in Montreal, Toronto or Vancouver. If Quebecers can submit your forms or be tracked by your cookies, you are in scope.
What it requires of a website operator
- A privacy officer: by default the CEO, but the role can be delegated; the officer's title and contact details must be published on your website.
- Transparency: a clear privacy policy in plain language — and if your audience is in Quebec, French matters for both law and trust (see multilingual sites that rank).
- Consent for tracking: technologies that identify, locate or profile users must not run until the user is informed and agrees — this is the legal basis for real cookie consent.
- Privacy by default: the highest-privacy settings must be the starting point for products and services offered to the public.
- Privacy impact assessments when transferring personal information outside Quebec — relevant if your form data lands in US-hosted tools.
The fines
This is where Law 25 changed the conversation. Quebec's regulator (the CAI) can impose administrative monetary penalties up to $10 million or 2% of worldwide turnover, whichever is greater. Penal fines go up to $25 million or 4% of worldwide turnover, doubling for repeat offences, with a minimum of $15,000 for corporations. Enforcement against a small business will not start at those ceilings, but the exposure makes "we never bothered with a banner" a poor position.
Cookie consent: what your site actually needs
Strictly necessary cookies — session, cart, security — need no consent. Everything optional does, at least for Quebec visitors: analytics, heatmaps, ad pixels, embedded social widgets. A compliant setup looks like this:
- A banner that loads before non-essential scripts fire, with equally easy "accept" and "decline" options — no pre-ticked boxes, no dark patterns.
- Consent mode wired into your tag manager so analytics and pixels only run after agreement.
- A way to change or withdraw consent later (a "cookie settings" footer link).
- A cookie section in your privacy policy listing what you use and why.
Many businesses simply apply the Law 25 standard Canada-wide: it is simpler than geo-targeting banners, it satisfies the strictest regime, and it matches where federal reform is heading.
CASL: email forms, newsletters and the 10-day rule
CASL applies the moment your website collects emails for marketing — a newsletter box, a lead magnet, a checkbox on a quote form. It is an opt-in law: you need consent before sending commercial messages, not an unsubscribe afterwards.
Consent: express beats implied
Express consent is a clear, active opt-in — an unticked checkbox saying what the person will receive — and it lasts until withdrawn. Implied consent covers limited cases, mainly an existing business relationship such as a purchase, and generally expires after two years. Two rules trip up website forms constantly: consent checkboxes must be unbundled (not merged with "I accept the terms") and never pre-checked. Keep records of when and how each subscriber consented; the burden of proof is on the sender.
Every message needs three things
- Identification of who is sending (business name and contact details, including a mailing address).
- A working unsubscribe mechanism that is honoured within 10 business days — in practice, instantly via your email platform.
- Content that matches what the person consented to receive.
Penalties reach $10 million per violation for organizations and $1 million for individuals, and the CRTC has issued six- and seven-figure penalties to real companies. Directors can be personally liable. For small senders the realistic risk is complaints and investigations, but the fix is so cheap that non-compliance is indefensible.
Practical compliance checklist
Most of this is one-time setup work your web studio can build in from day one:
- Publish a plain-language privacy policy: what you collect, why, who you share it with, retention, and how to reach your privacy contact.
- Name a privacy officer and list their contact details on the site (required for Law 25).
- Install a consent-mode cookie banner that blocks non-essential scripts until accepted, with a decline option and a settings link.
- Audit your forms: collect only what you need, unbundle marketing checkboxes, never pre-check them.
- Keep consent records — date, source and wording — in your email platform or CRM.
- Verify your email footer has your business name, mailing address and a working unsubscribe.
- Serve the site over HTTPS and keep software patched; review who on your team can access customer data.
- Write down a simple breach plan: who assesses harm, who notifies whom, and where you log incidents.
- If Quebec is a real market, provide the policy and banner in French.
- Recheck annually — tools change, pixels creep in, and laws keep moving.
Common mistakes we see on Canadian small-business sites
- A copy-pasted US privacy policy referencing CCPA and an American company that is not you.
- A decorative cookie banner that says "we use cookies" while every pixel already fired on page load.
- Pre-checked newsletter boxes or consent bundled into the terms of service — invalid under CASL.
- Buying or scraping email lists. You cannot inherit consent; a purchased list is a liability, not an asset.
- No unsubscribe records and manual list management that misses the 10-business-day deadline.
- Forgetting the forms you forgot: old popups, chat widgets and booking tools quietly collecting data your policy never mentions.
Frequently asked questions
Does my small business website legally need a privacy policy in Canada?
Yes, in practice. PIPEDA's openness principle requires you to make your data practices available, and Quebec Law 25 explicitly requires publishing clear privacy information. If your site has a contact form, analytics or a newsletter, a plain-language privacy policy is the baseline expectation.
Do I need a cookie banner if I am not in Quebec?
If people in Quebec can use your site, Law 25 applies to their data regardless of where your business is located, and non-essential tracking should wait for consent. Most Canadian businesses apply one compliant banner nationally rather than geo-targeting, which also future-proofs against federal reform.
What are the fines under Quebec Law 25?
The regulator can levy administrative monetary penalties up to $10 million or 2% of worldwide turnover, whichever is greater. Penal fines reach $25 million or 4% of worldwide turnover, and can double for repeat offences. Small businesses will not face ceilings for first issues, but the exposure is real.
Can I email people who filled out my contact form?
You can reply to their enquiry — that is not marketing. Adding them to a newsletter is different: you need express consent via an unticked checkbox, or implied consent from an existing business relationship, which generally lapses after two years. Reply first, invite them to subscribe separately.
What does CASL require in every marketing email?
Three things: clear identification of your business with contact details including a mailing address, a working unsubscribe mechanism honoured within 10 business days, and consent obtained before sending. Penalties run up to $10 million per violation for organizations and $1 million for individuals.
Is Google Analytics legal on a Canadian website?
Yes, used correctly. Analytics cookies are non-essential, so for Quebec visitors they should load only after consent, and your privacy policy should disclose the tool and any transfer of data outside Canada. Consent mode in your tag manager handles the technical side cleanly.
Every site we build ships with a proper privacy policy structure, consent-mode cookie banner, CASL-safe forms and secure hosting — so you can market confidently. Get a free quote within 24 hours.
Get a free quote