The short answer
Yes, if your website collects any personal information at all - and a contact form counts. Canada's federal privacy law applies to organizations collecting personal information during commercial activity, and Principle 8 requires you to make your handling practices readily available. A privacy policy page is how a website satisfies that.
Most Canadian small business owners assume a privacy policy is something large companies need - a legal formality that arrives with a compliance department. The threshold is much lower than that, and it is worth understanding exactly where it sits, because almost every business website in the country crosses it on day one.
The trigger is collection, not company size
The Personal Information Protection and Electronic Documents Act applies to private-sector organizations across Canada that collect, use, or disclose personal information in the course of a commercial activity [3]. There is no employee-count exemption, no revenue floor, and no carve-out for sole proprietors. A two-person landscaping company and a national retailer are governed by the same statute [2].
Responsibility also travels with the data. Clause 4.1.3 makes an organization responsible for personal information in its possession or custody, including information transferred to a third party for processing, and requires contractual or other means to provide a comparable level of protection while that third party holds it [1]. For a website that means your booking platform, your email provider and your host are your responsibility, not separate ones. The Privacy Commissioner publishes practical compliance material for businesses working through exactly this [4].
The word doing the work is collect. If your website has a contact form, you are collecting a name and an email address. If it has a booking widget, you are collecting a name, a phone number, and a time. If it has a newsletter signup, you are collecting an email address and, implicitly, an interest. All of that is personal information, and all of it is collected in the course of commercial activity - you are running a business, and the form exists to get you customers.
This is why the common instinct - "my site is just a brochure, it does not really do anything" - usually fails on inspection. The brochure site with a Contact us button is a collecting site.
What the law actually requires you to publish
Principle 8, the Openness principle, states that an organization shall make readily available to individuals specific information about its policies and practices relating to the management of personal information [1]. The same principle adds that individuals must be able to acquire this information without unreasonable effort, and that it must be in a form that is generally understandable [1].
That second half matters more than most templates acknowledge. A policy written in dense legal boilerplate technically exists but arguably fails the "generally understandable" test, and the Privacy Commissioner's consent guidance reinforces the same idea - material has to be comprehensible to the people it affects, not merely present on the server [7].
Clause 4.8.2 is unusually specific about contents. The information you make available must include:
- The name or title and address of the person accountable for your policies and practices, and to whom complaints or inquiries can be forwarded [1]. Not a generic info@ address - an accountable person.
- The means of gaining access to the personal information you hold [1]. Someone must be able to find out how to ask you what you have about them.
- A description of the type of personal information held, including a general account of its use [1].
- A copy of any brochures or other material explaining your policies, standards, or codes [1].
- What personal information is made available to related organizations, such as subsidiaries [1].
Notably, the Act does not mandate that this live on a web page. Clause 4.8.3 explicitly allows brochures in your place of business, mail, online access, or a toll-free number [1]. But for a business whose collection happens through a website, the web page is the only method that meets people at the point of collection, which is where Principle 2 wants them met anyway.
The policy is downstream of two other obligations
A privacy policy written in isolation tends to be wrong, because it describes practices that were never designed. Two principles sit upstream of it.
Principle 2, Identifying Purposes, requires that the purposes for which personal information is collected be identified at or before the time of collection, and that the organization document those purposes specifically in order to comply with the Openness principle [1]. The documentation is not optional paperwork; it is the input your policy is written from.
Principle 4, Limiting Collection, requires that collection be limited to what is necessary for the identified purposes, and states plainly that organizations shall not collect personal information indiscriminately [1]. This is the principle most often broken by website forms, and it is broken by well-meaning design: the contact form that asks for a mailing address when you only ever reply by email, or the quote form with a mandatory phone number you never call.
The practical consequence is pleasant. Trimming a form to the fields you genuinely use makes the form convert better and shortens the policy you have to write. Compliance and conversion point the same direction here, which is not always the case.
Access requests are a real obligation
Principle 9 gives individuals the right, on request, to be informed of the existence, use, and disclosure of their personal information, and to be given access to it, along with the ability to challenge its accuracy and have it amended [1]. For a small business this is rarely exercised, but when it is, the question becomes operational rather than legal: do you actually know where the last two years of contact form submissions went?
If the answer is "an inbox, probably, and maybe a spreadsheet," you can still comply - but you will comply slowly and incompletely. Knowing where submissions land is worth sorting out before someone asks.
Breaches carry a separate, harder obligation
Since 2018, breach reporting has been mandatory. Where a breach of security safeguards creates a real risk of significant harm to an individual, the organization must report to the Privacy Commissioner and notify the affected individuals [6]. Separately, and this is the part small businesses miss, you must maintain a record of every breach of security safeguards involving personal information - including the ones that fall below the reporting threshold [5].
The record-keeping duty is not conditional on severity. A minor exposure that harms nobody still generates a record-keeping obligation, and the Commissioner may request those records [5].
Where provincial law takes over
Alberta, British Columbia and Quebec have their own private-sector privacy laws deemed substantially similar to PIPEDA, and organizations in those provinces are generally exempt from PIPEDA for collection, use, or disclosure occurring within the province [3]. This is a change of governing statute, not a holiday from disclosure - each of those laws carries its own openness requirement.
The nuance that catches people: PIPEDA continues to apply to personal information that crosses provincial or national borders [3]. A Vancouver business using a hosting provider in another province is moving data across a border, and a business selling to customers in Ontario is collecting across one too. Most small businesses with a website are, in practice, subject to at least one federal touchpoint.
What a workable policy looks like
For a typical small business site, an honest policy runs about a page. It names the accountable person with a real email address. It says what the forms collect, field by field. It says what happens to submissions and roughly how long they are kept. It says who else sees the data - your booking platform, your email provider - in plain terms. It explains how to ask for access or a correction, and where to complain if you are unsatisfied.
That page is more defensible than three thousand words of copied boilerplate describing cookie categories you do not use and international transfers you do not make. Clause 4.8.2(c) asks for a description of the information you hold [1]. A copied policy answers that question about a different company.
The one thing to do this week
Open your own contact form and write down every field. For each one, answer: what do I use this for, and what would break if I removed it? Fields that survive belong in your policy. Fields that do not survive should come off the form, which is what Principle 4 has been asking for all along [1]. That list - not a template - is the raw material for a policy that is both accurate and short.
