Compliance How-To
Featured

Privacy Policy Template Canada: How to Write a PIPEDA-Compliant Policy in 2026

What a Canadian privacy policy must actually say under PIPEDA, section by section, and the wording choices that trip up small businesses.

Canada Compliance AI• Compliance Team
March 3, 2026
Updated September 12, 2026
16 min read
Privacy Policy
PIPEDA
Law 25
Templates
Compliance

A privacy policy is the most visible compliance document your business has. It's often the first thing regulators review during an investigation, and customers increasingly read them before sharing personal information. Here's how to create one that's legally compliant and builds trust.

What Canadian Law Requires in a Privacy Policy

PIPEDA Requirements (Federal)

PIPEDA's 10 Fair Information Principles require your privacy policy to address:

  1. Accountability — Who is responsible for your privacy practices
  2. Identifying Purposes — Why you collect personal information
  3. Consent — How you obtain and manage consent
  4. Limiting Collection — What you collect and why it's necessary
  5. Limiting Use, Disclosure, and Retention — How you use, share, and keep data
  6. Accuracy — How you keep information up to date
  7. Safeguards — How you protect personal information
  8. Openness — Making your practices transparent
  9. Individual Access — How individuals can access their information
  10. Challenging Compliance — How to make a complaint

Quebec Law 25 Additional Requirements

Law 25 adds several disclosure obligations:

  • Title and contact information of the person in charge of the protection of personal information, published on your website (s. 3.1)
  • A confidentiality policy in clear and simple language if you collect personal information by technological means (s. 8.2)
  • Purposes and means of collection, and the rights of access, rectification and withdrawal of consent (s. 8)
  • Names or categories of third parties to whom information must be communicated, and the possibility that information could be communicated outside Québec (s. 8)
  • Rights specific to Quebec residents (portability, de-indexing)
  • Automated decision-making disclosures
  • On request: the categories of persons with access to the information and how long it will be kept (s. 8)

Essential Sections of a Canadian Privacy Policy

1. Introduction and Scope

  • Company name and contact information
  • What the policy covers (website, app, services)
  • Effective date and last updated date
  • Geographic scope (Canadian operations, international)

2. Privacy Officer Contact Information

  • Name or title of designated privacy officer
  • Direct contact method (email, phone, mailing address)
  • Law 25 Requirement: Must be published on your website

3. Types of Personal Information Collected

Clearly list each category:

CategoryExamplesPurpose
IdentityName, email, phoneAccount creation
FinancialCredit card, bank detailsPayment processing
TechnicalIP address, browser typeWebsite functionality
UsagePages visited, clicksService improvement
MarketingPreferences, survey responsesCommunications
LocationIP-based location, GPSService localization

4. Purposes for Collection

For each type of information, explain:

  • The specific purpose
  • The legal basis (consent, contract, legitimate interest)
  • Whether it's optional or required
  • Consequences of not providing it

5. Consent Mechanisms

Describe how you obtain consent:

  • Express consent: For sensitive data, marketing, third-party sharing
  • Implied consent: For data necessary to fulfill a service
  • Opt-out consent: Where legally permitted (e.g., business contact information)
  • Withdrawal: How to withdraw consent and what happens when you do

6. Third-Party Sharing

Disclose all categories of third parties:

  • Service providers (hosting, payment, analytics)
  • Business partners
  • Government and law enforcement
  • Advertising networks
  • Professional advisors

For each third party, specify:

  • Purpose of sharing
  • Type of data shared
  • Location of the third party
  • Safeguards in place

7. Cross-Border Transfers

PIPEDA Requirement: Inform individuals that their data may be transferred outside Canada.

Law 25 Requirement: Inform individuals of the possibility that their information could be communicated outside Québec (s. 8). Before communicating information outside Québec, conduct a privacy impact assessment that considers the sensitivity of the information, the purposes, the protection measures (including contractual ones) and the legal framework of the destination, and put the communication in a written agreement (s. 17). For transparency, you may also list:

  • Countries where data is transferred
  • Purpose of each transfer
  • Safeguards applied

8. Data Retention

Specify retention periods:

  • Account data: Duration of account + [X] years
  • Transaction data: [X] years (consider tax requirements)
  • Marketing data: Until consent withdrawn
  • Analytics data: [X] months
  • Legal hold data: As required by law

9. Individual Rights

List rights clearly:

Under PIPEDA:

  • Right to access personal information
  • Right to correct inaccurate information
  • Right to withdraw consent
  • Right to file a complaint with the OPC

Additional Rights Under Law 25:

  • Right to data portability
  • Right to de-indexing (search engine removal)
  • Right to information about automated decisions
  • Right to have automated decisions reviewed by a human

10. Security Measures

Describe safeguards (without revealing exploitable details):

  • Encryption (at rest and in transit)
  • Access controls
  • Employee training
  • Regular security assessments
  • Incident response procedures

11. Cookies and Tracking

  • Types of cookies used (necessary, functional, analytics, advertising)
  • How to manage cookie preferences
  • Third-party tracking technologies
  • Link to separate cookie policy if applicable

12. Changes to the Policy

  • How you'll notify of changes (email, website notice)
  • When changes take effect
  • How to review previous versions

13. Contact and Complaints

  • Privacy officer contact details
  • How to submit a request or complaint
  • Response timeline (30 days under PIPEDA)
  • Right to escalate to the OPC or provincial commissioner

Common Privacy Policy Mistakes

1. Copy-Pasting US Templates

American privacy policies reference CCPA, COPPA, and state laws that don't apply in Canada. Canadian policies must reference PIPEDA, CASL, and applicable provincial laws.

2. Vague Purpose Statements

❌ "We collect data to improve our services" ✅ "We collect your browsing history on our website to personalize product recommendations and improve navigation"

3. Missing Third-Party Disclosures

Failing to name categories of third parties who receive data is a violation of both PIPEDA and Law 25.

4. No Retention Periods

Law 25 requires your governance policies to provide a framework for keeping and destroying personal information (s. 3.2), and individuals can ask how long their information will be kept (s. 8). Stating concrete retention periods is clearer than "as long as necessary."

5. Inaccessible Language

Privacy policies must be understandable to the average person. Avoid legal jargon where possible.

6. Missing French Version (Quebec)

If you operate in Quebec, your privacy policy must be available in French (Charter of the French Language).

7. No Version History

Not maintaining dated versions makes it impossible to demonstrate compliance at a point in time.


Bilingual Requirements

When You Need a French Privacy Policy

Mandatory in Quebec: Charter of the French Language requires French versions of all consumer-facing documents.

Best Practice Everywhere: If you serve French-speaking customers across Canada, offering a French version demonstrates good faith.

Translation Tips

  • Use professional legal translators, not machine translation
  • Ensure legal terms are accurately translated
  • Both versions should be legally equivalent
  • Date both versions consistently

Privacy Policy Maintenance Schedule

TaskFrequencyResponsible
Full review and updateAnnualPrivacy Officer
New service/feature reviewAs neededProduct + Privacy
Third-party vendor changesAs changes occurProcurement + Privacy
Regulatory change assessmentQuarterlyLegal + Privacy
Accessibility checkSemi-annualWeb team
French translation syncWith every English updateTranslation team

How to Display Your Privacy Policy

Website Placement

  • Footer link on every page
  • During account registration
  • Before form submissions
  • At checkout
  • Cookie consent banner link

Mobile App

  • Link during onboarding
  • In Settings/Privacy section
  • Before first data collection
  • Accessible without login

Frequently Asked Questions

Q: How long should a Canadian privacy policy be? There's no legal length requirement, but aim for comprehensive yet readable. Consider a layered approach with a summary and full version.

Q: Do I need a separate cookie policy? Not legally required under Canadian law, but recommended for clarity, especially if you have complex cookie/tracking implementations.

Q: Can I use a privacy policy generator? Generators provide a starting point but should always be reviewed by someone familiar with Canadian privacy law. Generic templates often miss provincial requirements.

Q: How often should I update my privacy policy? At minimum annually, and whenever you change data practices, add new services, change vendors, or new laws come into effect.


Canada Compliance AI helps Canadian SMEs work through CASL, PIPEDA and Quebec Law 25: a free two-minute compliance check, readiness scores, a prioritized task plan, a 24-month breach register and an exportable audit log. See what's live and what's planned.

Related Articles:

Found this article helpful?

Share it with your team or save it for later reference.

Related compliance guides

Explore step-by-step guidance for PIPEDA, CASL, and Quebec Law 25.