Skip to main content
All of CanadaUpdated September 2026

Privacy by Design for Small Business

A practical guide for Canadian small businesses to comply with PIPEDA, provincial private-sector laws, and CASL.

TL;DR

Canadian privacy law expects a business to have a privacy officer, a clear policy, limited collection, meaningful consent, security safeguards, and a breach plan. The obligations are heavier for health, financial, or biometric data and for businesses operating in BC, Alberta, or Quebec.

Key obligations

The obligations that apply to every Canadian business:

  • Designate a privacy officer (the person accountable for compliance).
  • Publish a clear privacy policy describing what you collect, why, with whom you share it.
  • Obtain meaningful consent, especially for sensitive or unexpected uses.
  • Limit collection to what is necessary for stated purposes.
  • Implement reasonable security safeguards, including encryption at rest and in transit.
  • Have a breach response plan with 24/7 contacts and templates.

Province-specific extras

If you operate in:

  • BC: BC PIPA applies, including its employee personal information rules; the OIPC BC publishes guidance on them.
  • Alberta: Alberta PIPA applies. Breach notification is mandatory and Alberta was the first province to require it.
  • Quebec: the private-sector Act as amended by Law 25 applies. A PIA is required for projects involving personal information (s.3.3), and a biometric database must be disclosed to the CAI at least 60 days before it goes into service.

CASL basics

A business that sends commercial electronic messages must:

  • Obtain express or implied consent.
  • Include sender identification and contact information.
  • Provide a working unsubscribe mechanism for 60 days.
  • Process unsubscribe requests within 10 business days.

Resources

The OPC publishes a free Privacy Guide for Businesses. Provincial commissioners publish industry-specific guidance.

Related topics

Ask AI