Skip to contentSkip to content
Back to guides
Privacy and the law

Does my website need a privacy policy in Canada? And a cookie banner?

Most small business sites collect a name and an email on day one. That brings a privacy law with it. Here is which law applies to a BC business, what a plain policy says, and when a cookie banner is worth it. I read every rule on the official government pages in September 2026.

9 minPublished September 23, 2026Updated September 23, 2026
A tall cedar privacy fence and a latched wooden gate along a backyard garden, forested hills behind

Key takeaways

  • The Government of BC says every organization must have a privacy policy, available on request, and a named privacy officer (checked September 2026).
  • BC’s PIPA covers a BC business. The federal PIPEDA also applies when personal information crosses provincial or national borders.
  • A plain policy names what the site collects, why, which tools see it, how long you keep it, and who to ask.
  • No Canadian law names a cookie banner. Ad pixels and retargeting change the picture, because the federal guidance asks for a clear notice and an easy opt-out.
  • Quebec’s law asks for a policy on the website itself, and for tracking that can profile people to be explained first.
On this page
  1. 01Do you need one?
  2. 02PIPEDA or PIPA
  3. 03What the policy says
  4. 04The cookie banner question
  5. 05What my own site does
  6. 06Customers in Quebec
  7. 07Write yours this week
  8. 08Sources
  9. 09FAQ

Does my website need a privacy policy in Canada?

Yes, for a business in BC. The province says every organization must have a privacy policy, available on request, and a named privacy officer. BC’s law does not force you to post the policy online. A site with a contact form is where people look for it, so post it there.

The rule comes from BC’s Personal Information Protection Act, called PIPA. The Government of BC page on protecting personal information lists four steps for a business: name a privacy officer, check what you collect, write a privacy policy, and follow it. I read that page on September 23, 2026. It was last updated June 11, 2026.

Personal information is broad. The province’s own examples include contact information, purchases and spending habits. A name and an email typed into your contact form count. So does a delivery address in an order, or a phone number in a booking. One exception is contact information for a person at their place of business, used to reach them about that business.

Which privacy law applies to a BC business, PIPEDA or PIPA?

PIPA covers a business in BC. The federal law, PIPEDA, steps in when personal information crosses provincial or national borders. Many small businesses can meet both, because a customer, a supplier or an online tool sits outside BC. Both laws are built on ten privacy principles, and the policy headings below follow them.

The federal Privacy Commissioner puts it this way. PIPEDA does not apply to organizations operating entirely within Alberta, BC or Quebec, because those three provinces have their own private-sector laws. It does apply to every business in Canada that handles personal information crossing a provincial or national border. Federally regulated businesses, like banks and airlines, fall under PIPEDA everywhere.

What is being comparedBC PIPAFederal PIPEDA
Who it coversPrivate organizations in BC, including businesses, charities and non-profitsBusinesses in commercial activity across Canada, outside AB, BC and QC
When a BC business meets itAlways, for information handled in BCWhen personal information crosses provincial or national borders
Who oversees itBC’s Information and Privacy Commissioner (OIPC)The Privacy Commissioner of Canada
Built onTen principles of privacy protectionTen fair information principles

What should a small business privacy policy say?

It says what you collect, why, who sees it, how long you keep it, and how someone asks about it. BC’s privacy office publishes the headings. Use real examples from your own site. Name the actual tools. Leave out anything that is not true of your business.

  • What you collect, with real examples: the name, email and message from the contact form, an order address, a booking time.
  • Why you collect each thing. Answering the message, shipping the order, and sending a newsletter they asked for are three different purposes.
  • How people agree to it, and how they can take that back. Say what they lose if they do, like a booking you can no longer confirm.
  • Who else sees it. Name the real tools: the form service, the booking system, the payment processor, the email tool, the analytics.
  • How long you keep it, and how you delete it after that.
  • How you protect it: passwords, two-step logins, and who on your team can open the inbox.
  • How someone asks for a copy of their own information, and how fast you answer.
  • Who your privacy officer is, how to reach them, and how to complain to BC’s Information and Privacy Commissioner if they are not satisfied.

Two numbers from the OIPC’s guide belong in the policy. If you use someone’s information to make a decision about them, keep it for at least one year, so they have a fair chance to see it. Answer a written request for their own information within 30 business days, unless the law allows more time.

The worst policy is a copied one. A template promises practices the business never had, like sharing with “trusted partners” who do not exist. A policy that lies is worse than a short one that tells the truth. If your site collects a name, an email and a message, three honest paragraphs can cover it.

A newsletter sign-up also falls under Canada’s anti-spam law, CASL. The guide to CASL and email marketing in Canada covers the consent checkbox and the unsubscribe link.

No Canadian law names a cookie banner. The law asks for knowledge and consent. For ad tracking, the federal Privacy Commissioner says people must be told clearly at or before collection, never only in a buried policy, and be able to opt out easily. A banner is one way to do that.

The federal guidance on online behavioural advertising is specific. Ad tracking follows people across sites and over time to show them ads matched to what they seem to like. The Commissioner says opt-out consent for that can be reasonable when all of these hold:

  • The purpose is obvious, and is not buried in a privacy policy.
  • People learn about it at or before the moment the tracking starts, along with who else is involved.
  • They can opt out easily, ideally before anything is collected.
  • The opt-out works right away and stays in place.
  • The tracking avoids sensitive information, such as health details or bank records.
  • The information is destroyed or de-identified as soon as possible.

The same page names the tools for giving that notice: online banners, layered approaches and interactive tools. It also says to avoid tracking children, and to avoid tracking on sites aimed at them.

So the question is what your site runs. A site with a contact form and plain visit counting has a short policy that names the analytics tool. A site with an ad pixel, like the Meta Pixel, or a retargeting tag that shows your ads again to past visitors, is doing ad tracking. That site needs a visible notice and a real way to turn it off.

A cookie banner answers one question: what does this site track, and can I say no? If your site tracks nothing for ads, the honest answer fits in the policy.

What does my own site do?

This site runs Google Analytics and a Meta Pixel for my own Facebook and Instagram ads. Both are named on the privacy page. Every page has a button at the bottom that turns ad measurement off. It also stays off when a browser sends a Global Privacy Control signal.

I mention it because it is the exact case this guide describes. I run ads, so the calculus changed for my own site. The privacy page on kootenaymade.ca says what the pixel sends to Meta, what the analytics measure, and which providers store data outside Canada. Read it as a worked example of naming real tools, and write yours from what your own site runs.

When I build a site for someone else, the privacy page gets written after walking the real forms, embeds and tools on that site. It says only what is true there.

What if my website serves customers in Quebec?

Quebec has its own private-sector privacy law, with changes from 2021 that many people call Law 25. It asks for a confidentiality policy in clear and simple language on the business’s website. It also asks that tracking which can identify, locate or profile a person be explained before it runs.

The Act is chapter P-39.1 on LégisQuébec, current to June 10, 2026. Four sections touch a website. Section 3.1 asks for the title and contact information of the person in charge of personal information to be published on the website. Section 8.1 covers technology that can identify, locate or profile a person. People must be told first, along with how to switch those functions on. Section 8.2 asks for the confidentiality policy on the website. Section 9.1 asks for the most private settings by default, and says that rule does not apply to browser cookie settings.

Whether Quebec’s law reaches a BC business that ships to Quebec customers depends on the facts. That is a question for a lawyer. If Quebec is a real market for you, ask before you launch a campaign there.

How do I write a privacy policy this week?

Start from what the site actually does. List every form and tool, write down where the data goes, then write the policy under the OIPC’s headings. Name yourself as privacy officer and link the policy from every page. Six steps and an afternoon will do it.

  1. 01Walk your own site. List every form, every embed, every tool and every tag. Check the booking widget, the map, the chat bubble and the newsletter box.
  2. 02Write down what each one collects and where the data goes. If you are unsure what a tag does, ask whoever added it, or remove it.
  3. 03Write the policy under the headings above, in plain sentences. Name each tool. Leave out any practice you do not actually have.
  4. 04Name the privacy officer. In a one-person business that is you. Put your name or title and a working email in the policy.
  5. 05Link the policy from the footer of every page and from every form that collects personal information.
  6. 06Set a date to review it. Any new tool, form or ad campaign means the policy changes the same week.

The privacy page usually sits beside an accessibility statement in the footer. The website accessibility guide for Canada covers that page and the standard it should name.

This guide is general information, not legal advice. For your own situation, ask a lawyer who works in privacy law.

Sources and further reading

Frequently asked questions

Is a privacy policy required by law for a BC business?

Yes. The Government of BC says every organization must have a privacy policy, available upon request, that explains how personal information is collected, used, disclosed, stored and disposed of. It must include a way to handle complaints. BC’s law leaves the choice of where to share it to you. The website is where people look. Checked September 2026.

Do I need a privacy policy if my website only has a contact form?

Yes. A customer’s name, email and message are personal information, and the form collects them. The policy can be short. Say what the form collects, why, which service receives it, how long you keep it, and who to ask about it.

Does Google Analytics need a cookie banner in Canada?

No Canadian law names a cookie banner. Name the analytics tool in your policy and say what it measures. Ad features change the picture. The federal Privacy Commissioner’s ad tracking guidance asks for a clear notice at or before collection and an easy opt-out that lasts. A banner is one way to give that notice.

Who is the privacy officer in a one-person business?

You are. BC says every organization must designate at least one privacy officer. The OIPC says their identity and contact information must be available to the public. A name or title and a working email in the policy covers it.

Can I copy another business’s privacy policy?

Borrow the headings, never the promises. A copied policy describes someone else’s tools. The OIPC’s guide on developing a privacy policy lists the sections to cover. Fill each one with what your own site actually runs, and delete anything that is not true of you.

Kootenay Made Digital

I build websites, local presence, and calm AI setups for Kootenay small businesses. Plain language, published prices, and clear work that makes you easier to find and easier to choose.

Share this

Want a site that comes with its legal pages?

Legal and contact pages come with every Trailhead and do not count against its 3 custom page designs. The Trailhead is $2,000, or $500 at signing and 12 payments of $142 ($2,204 total) on Own It Monthly. Tell me what your site needs to collect and I will tell you what its privacy page has to say.

No website yet?

Start My First Website

Already have one?

Get a Free Check-Up

Custom websites from $2,000, or Own It Monthly at $500 today and $142 a month ($2,204 total), yours outright at payment 12.