Compliance · July 28, 2026 · Ruby Team

Do You Need a Privacy Policy? What PIPEDA Actually Requires

If you collect anyone's name, email address, or payment information as part of running your business in Canada, PIPEDA almost certainly requires you to have a privacy policy. It doesn't matter if you're two people in an apartment or a fifty-person company — the law doesn't have a size exemption for “we haven't gotten to it yet.”

Who PIPEDA actually applies to

PIPEDA covers private-sector organizations that collect personal information in the course of commercial activity, which is a broader net than most founders assume. Running an email list counts. Taking payments counts. A contact form on your website counts. Quebec, Alberta, and BC have their own substantially similar legislation (Law 25, PIPA), so if you operate there the specifics shift slightly, but the underlying obligation doesn't disappear.

What a compliant policy actually needs

A privacy policy isn't a legal formality you paste at the bottom of your site. Under PIPEDA's fair information principles, it needs to actually say, in plain language: what personal information you collect, why you're collecting it, how you use it, who you share it with and why, how long you keep it, how someone can access or correct their own information, and who to contact with a privacy concern. Miss any of those and the policy isn't doing its job, even if it looks the part.

The generic template problem

The same mistake shows up here as everywhere else: a founder finds a template, swaps in the company name, and publishes it. It rarely reflects what the business actually collects or does with that data, which means it's not actually compliant — it just looks compliant. If a regulator or a customer ever asks what happens to their information, the policy needs to hold up to the real answer, not a generic one.

When you need one

The moment you're collecting emails for a waitlist, running e-commerce, or building a SaaS product with user accounts. If you're already running email marketing, this pairs directly with CASL compliance, which governs the consent side of the same problem — we covered that in CASL Compliance for Canadian E-Commerce and SaaS Businesses.

A properly scoped privacy policy takes a lawyer about twenty minutes to draft once we understand what you're actually collecting — flat fee starting at $299, lawyer-reviewed. Tell us about your matter and a Ruby lawyer will follow up directly.

Ready to put this into practice?

Tell us about your matter and a Ruby lawyer will follow up directly.

Ask Ruby