Every week I meet business owners who have no privacy policy, no terms of service, and no idea the law requires either one. Most of them built a beautiful website. Almost none of them checked whether it’s legally covered, because nobody ever told them that part matters too.
This isn’t about scaring you into buying something you don’t need. It’s about a handful of pages. They take an afternoon to set up. They can save you a genuinely bad year, if a visitor, a regulator, or a competitor’s lawyer ever comes looking.
Do you actually need a privacy policy?
Almost certainly, yes. A contact form counts as collecting personal information. So does an email signup. If your site has either one, Canada’s federal privacy law applies to you. PIPEDA requires businesses to follow ten fair information principles. Among them: tell people what you collect, tell them why, and get their consent first. A privacy policy is where all of that goes in writing. Anyone can check it, instead of taking your word for it.
If you email your list, or plan to, Canada’s Anti-Spam Legislation requires consent before you send commercial electronic messages. That’s the legal reason behind every “opt in” checkbox you’ve ever filled out. Your own signup form needs to be doing that correctly too, not just collecting addresses and hoping for the best.
Beyond those two, most small business websites also need terms of service. This spells out what visitors can and can’t do on your site. Most also need a disclaimer. It makes clear that your blog posts and advice aren’t professional guidance tailored to any one reader’s situation. None of these are exotic. They’re closer to a seatbelt than a legal minefield. Boring, easy to forget, and exactly the thing you want already in place before you need it.
What actually happens if you skip it
Most of the time, nothing happens, for a long time. That’s exactly what makes this easy to ignore. You launch the site, get some clients, and nothing goes wrong. It starts to feel like the warnings were overblown.
Then one day a client asks what you do with the information from your intake form. You don’t have a clean answer, because you never actually decided. Or someone unsubscribes from a list they don’t remember opting into, and files a complaint. Now you’re explaining your email practices to a regulator instead of a curious client. Or a competitor, or a disgruntled former client, decides to make a point of exactly how uncovered your site is.
None of these are hypothetical scenarios dreamed up to scare you into buying a template. They’re the ordinary, unglamorous ways this actually shows up for small business owners. Usually years after the site went live. Long after everyone had stopped thinking about it, and right when you have the least time to deal with it properly.
The fines for non-compliance with Canadian privacy law can be real money. For most small businesses, though, the bigger cost is smaller and more immediate: the scramble. Getting a legal page written properly while you’re also responding to a complaint is a much worse afternoon. Writing it now, on a slow Tuesday before anyone is asking, is the easier version of this.
Why this keeps getting skipped
Nobody starts a business because writing a privacy policy sounded exciting. The actual work excited you. So did the clients, and the thing you’re good at. You push legal pages to “later” because they don’t feel like progress, and later has a way of becoming never.
I get it. Tech and legal language both have a way of making smart, capable people feel instantly out of their depth. But skipping these pages doesn’t make the requirement go away. It just means you find out about it at the worst possible time. Usually after something has already gone wrong, instead of on an ordinary afternoon when fixing it would have been simple.
Getting this done doesn’t have to eat your week
You don’t need a law degree to get compliant. Most of this is a few well-written pages, built once and updated occasionally as your business changes. If you’re using a website builder, check whether it has a built-in privacy policy generator first. Several do, and they’re a reasonable starting point even if you have a professional review the result afterward.
What matters more than which route you take is actually doing it, on purpose, this month. Not adding it to the pile of things you’ll get to eventually. That pile has a way of never getting smaller. Set a single afternoon aside. Draft the privacy policy first. It’s the one the law is most likely to require, regardless of what your business does. Add the others once that’s done.
Do it now, not later
Think of it the way you’d think of insurance. You hope you never need it, and you’re genuinely relieved when you don’t. You’d never skip it just because nothing bad has happened yet, though, and a legal page works the same way. Most years it sits quietly, doing nothing. The one year it matters, you’d rather already have it handled. Better that than searching for a template while a client is waiting on an answer.
If tech and legal paperwork both make you want to close the laptop and deal with it another day, you’re not alone in that. You’re also not behind some invisible schedule everyone else is keeping. Most business owners figure this out the same way you are about to: after the site is already live, usually when something prompts the question. The only real difference between doing it now and doing it later is which afternoon ends up getting interrupted.
Related reading: for the specific privacy laws that apply, depending on where your clients live, read Include These Privacy Laws on Your Website.
Frequently Asked Questions
Does my small business website legally need a privacy policy?
If your site collects any personal information, including through a contact form or email signup, PIPEDA applies to you, and it requires a privacy policy. This is true for almost every small business site in Canada.
What is CASL and does it apply to my email list?
Canada’s Anti-Spam Legislation requires you to get consent before sending commercial electronic messages, including marketing emails. It’s the legal reason your signup forms need proper opt-in language, not just an email field.
What’s the difference between a privacy policy and terms of service?
A privacy policy explains what personal information you collect and how you use it. Terms of service set the rules for how visitors can use your site and protect you from certain disputes. Most sites need both.
Can I use a free template for my website’s legal pages?
A template or built-in generator is a reasonable starting point, especially if your website builder offers one. Having a professional review the result afterward is worth doing once your business is generating real revenue.
Go check your own site’s footer right now, before you close this tab. Is there a link to a privacy policy on it, or has this been sitting on your someday list a lot longer than you’d like to admit?

