What a small Canadian business actually has to do with customer data
The short version
If you run a business in Ontario and hold customers' names, phone numbers, addresses or photos of their property, PIPEDA applies to you. There is no revenue floor and no employee threshold, unlike the AODA website rules. In practice it comes down to five duties: say why you are collecting information, collect only what you need, keep it secure, get rid of it when the purpose is finished, and give people their own information when they ask for it. If information leaks, PIPEDA requires you to report the breach to the Privacy Commissioner and tell the people affected whenever there is a real risk of significant harm, and to keep a record of every breach for 24 months whether it was serious or not. Knowingly skipping the record or the report is an offence carrying a fine of up to $100,000. If any of your customers are in Quebec, Law 25 adds its own duties, including a five-year incident register. Marketing email is a third law again: CASL requires consent, your contact details and a working unsubscribe honoured within 10 business days.
A one-van repair business keeps its customer records in three places: a phone full of photographs taken on jobs, a messaging thread per customer, and a spreadsheet of names, numbers and addresses. The owner would not describe himself as running a business that processes personal data. Legally he is running exactly that, and has been since the first invoice.
This is not a warning. Most of what the law asks for is what a careful person does anyway, and the parts that are genuinely required are shorter than the marketing around them suggests. Here is the whole picture in one place.
Which law applies to you
PIPEDA, the federal privacy act, covers private-sector organisations across Canada that collect, use or disclose personal information in the course of a commercial activity. Commercial activity is defined broadly: any transaction, act or regular course of conduct of a commercial character. There is no headcount threshold and no revenue floor. A sole trader taking a deposit is inside it.
Three provinces, Alberta, British Columbia and Quebec, have their own private-sector privacy laws that the federal government has declared substantially similar, and businesses operating inside those provinces generally follow the provincial law instead for information collected there. Ontario has no such law for general private-sector business, so an Ontario shop is on PIPEDA.
What counts as personal information
The definition is wider than most people assume. It is any factual or subjective information, recorded or not, about an identifiable individual. In a small business that usually means:
- Names, phone numbers, email addresses and postal addresses on quotes and invoices.
- Photographs taken on a job where a vehicle, a house or a licence plate identifies whose it is.
- The enquiry emails your contact form has been sending you for years, sitting in an inbox nobody has ever cleared out.
- Text and messaging threads with customers, which are records like any other.
- Payment details, especially card numbers written on a job sheet.
- Camera footage of customers on your premises.
- Your own opinions about a customer. Subjective information counts, so a note reading "difficult, do not take on again" is personal information about that person, and they can ask to see it.
The five duties that actually bite
PIPEDA is built on ten fair information principles. For a business of this size they collapse into five practical obligations plus one that sits behind them all.
- Say why you are collecting it, at or before the moment you collect it. On a website that is one line under the form, not a legal document nobody reads.
- Collect only what you need for that purpose. A quote form that demands a full postal address before it will show a price is collecting for the business's convenience, not for the stated purpose.
- Keep it secure, with safeguards proportionate to how sensitive the information is. In practice the weak point is almost never the website, it is the email account holding every enquiry since 2021 with a reused password on it.
- Get rid of it once the purpose is finished. Retention is the duty everyone ignores, and job photographs from six years ago are the clearest example: they serve no remaining purpose and every one of them is a record you are still responsible for.
- Give people their own information when they ask, and correct it if it is wrong.
The sixth is accountability: someone has to be responsible for this. In a business of one that person is you, and the point of naming it is that the duty does not evaporate because there is no compliance department to hand it to.
What you must do if something leaks
This is the part with hard rules and dates attached, and the part almost nobody knows about until it happens. A breach of security safeguards is not only a hacked server. A laptop left in a van, an invoice emailed to the wrong customer and a stolen phone all qualify.
| Requirement | PIPEDA (federal) | Quebec Law 25 |
|---|---|---|
| Threshold for telling anyone | Real risk of significant harm | Risk of serious injury |
| Who gets told | The Privacy Commissioner of Canada and the affected individuals | The Commission d'accès à l'information and the affected individuals |
| Timing | As soon as feasible after you determine the threshold is met | Promptly, with the incident register kept current |
| Record of every incident | Required, whether or not it met the threshold | Required, including the ones you judged minor |
| How long records are kept | 24 months | 5 years |
Note the second-to-last row, because it is the one that catches people. You are required to keep a record of every breach, including the minor ones you correctly decided not to report. The Privacy Commissioner can ask to see that record, and having decided sensibly but written nothing down looks identical to having done nothing at all.
Significant harm is defined in the Act rather than left to judgement. It covers bodily harm, humiliation, damage to reputation or relationships, loss of employment or business or professional opportunities, financial loss, identity theft, negative effects on a credit record, and damage to or loss of property. Whether the risk is real turns on how sensitive the information was and how likely it is to be misused.
Under section 28 of PIPEDA, knowingly failing to report a qualifying breach, notify the people affected, or keep the records is an offence: a fine of up to $10,000 on summary conviction and up to $100,000 on indictment. Worth being precise about what that means in practice, because it is routinely misquoted. The Privacy Commissioner does not levy fines. The office investigates and can refer a matter to the Attorney General, and prosecution is a separate step that rarely arrives for a small business acting in good faith. The realistic cost of a breach handled badly is the customers who find out from somebody else.
Quebec, if any of your customers are there
Law 25 is Quebec's privacy regime and it phased in over three years: a designated person in charge of personal information protection, an incident register and incident notification from 22 September 2022; the substance of the regime, including governance policies, clearer consent, privacy impact assessments and transparency about automated decisions, from 22 September 2023; and data portability from September 2024.
The penalties are the reason Law 25 gets written about so much. The Commission can impose administrative monetary penalties of up to 2 percent of worldwide turnover or $10 million, whichever is higher. Penal proceedings against a company run from $15,000 to the greater of $25 million or 4 percent of worldwide turnover, and are doubled for a repeat offence.
Those numbers are aimed at organisations holding data on a scale a repair shop does not approach. What matters for a small Ontario business is narrower: Law 25 is written around the personal information of people in Quebec rather than around where the business has its office, so being in Ontario is not on its own the answer to whether it applies. If Quebec customers are a real part of your business rather than an occasional one, that is a question worth putting to a lawyer instead of to a website.
The email rule people break without noticing
Canada's anti-spam legislation is a separate law with separate rules, and the common breach is entirely accidental: a business exports every address it has ever received an email from and sends them all an offer. Some of those people never consented, and consent is the whole basis of the Act.
| Basis for sending | How long it lasts |
|---|---|
| Express consent, given knowingly | Until the person withdraws it |
| An existing business relationship, such as a purchase | 2 years from the transaction |
| An enquiry or application about a purchase | 6 months from the enquiry |
Every commercial message also has to identify who is sending it and include a mailing address that stays valid for at least 60 days, plus an unsubscribe mechanism that is simple to use, remains working for at least 60 days, and is honoured without delay and no later than 10 business days after the request.
The maximum penalties are $1 million per violation for an individual and $10 million for a business. Enforcement in practice has concentrated on volume senders, and the total collected since 2014 is measured in the low millions, so the realistic risk to a small business is not a headline fine. It is that a complaint from one annoyed recipient is what opens the file, and the six-month and two-year clocks above are what decide whether you were entitled to send at all.
Six things worth doing this week
- Turn on two-factor authentication for the email account that receives your enquiries. That inbox is the largest store of customer data most small businesses own and usually the least protected part of the operation.
- Write four sentences and put them on your site: what you collect, why, how long you keep it, and who to contact about it. For a business of this size that is a privacy policy, and a borrowed one naming a company in another country is worse than four honest sentences.
- Pick a retention period and actually delete. Old job photographs, quotes that never closed, enquiries from three years ago. Anything you no longer have a reason to hold is only a liability now.
- Read your own quote form as a stranger would and remove any field that is not needed to answer the question being asked.
- If you send marketing email, put your business name, a real mailing address and a working unsubscribe into the template, and stop sending to anyone whose consent has run out.
- Write down, on one page, what you would do if a phone or a laptop went missing: who you call, who you tell, and where you record it. Twenty minutes now, and it is the record the law expects you to have.
Where we sit on this
We build the site, the forms and the automations, so we are the ones deciding what a form asks for, where submissions are stored and how long they live there. Those defaults are a privacy decision whether or not anybody calls it one, which is why our builds collect the minimum a form needs, host in Canada, and come with the four sentences written rather than left as a task for you.
What we do not do is sell compliance as a product or quote you a penalty figure to make the point. For a business of the size described at the top of this page, the honest summary is that the requirements are modest, the housekeeping is genuinely worth doing, and the horror stories are aimed at somebody much larger than you.
Sources
- Office of the Privacy Commissioner of Canada, PIPEDA in briefWho PIPEDA covers, the definition of commercial activity and of personal information, the ten principles, and the provinces with substantially similar laws. Read 12 August 2026.
- Office of the Privacy Commissioner of Canada, What you need to know about mandatory reporting of breaches of security safeguardsThe real risk of significant harm threshold, notification content, and the requirement to keep records of all breaches for two years. Read 12 August 2026.
- Justice Canada, PIPEDA sections 10.1 and 28The statutory definition of significant harm, and the offence provisions carrying fines up to $10,000 on summary conviction and $100,000 on indictment. Read 12 August 2026.
- Commission d'accès à l'information du Québec, SanctionsAdministrative monetary penalties up to 2 percent of worldwide turnover or $10 million, and penal fines for companies from $15,000 to the greater of $25 million or 4 percent. Read 12 August 2026.
- Commission d'accès à l'information du Québec, Incidents de confidentialité et mesures de sécuritéThe duty to notify on a risk of serious injury and to keep the incident register for five years. In French. Read 12 August 2026.
- CRTC, Frequently asked questions about Canada's anti-spam legislationIdentification and mailing address requirements, the 60-day validity of the unsubscribe mechanism, the 10 business days to honour a request, the two-year and six-month implied consent periods, and the maximum penalties. Read 12 August 2026.
Every figure above was read off the regulator's own page on 12 August 2026 and each source is linked so you can check it rather than take our word for it. Privacy law in Canada is being reworked at the federal level, so if you are reading this long after that date, check the sources before relying on it.
Working out a budget for a project in Ontario? We'll give you a fixed number on a 20-minute call, whether or not you end up hiring us.