Many businesses collect personal information every day without thinking of themselves as “data-driven” businesses. A contact form, newsletter signup, online booking tool, payment platform, CRM, employee file, website analytics tool, chatbot, or customer intake form can all involve personal information.
That information may be useful, and often necessary. But privacy compliance depends on more than having a privacy policy somewhere on the website. Businesses should understand what information they collect, why they collect it, where it is stored, who can access it, how long it is kept, and whether customers, clients, employees, and website users are clearly informed.
In June 2026, the federal government introduced Bill C-36, the Protecting Privacy and Consumer Data Act, which proposes changes to Canada’s private-sector privacy framework. For business owners, this is a good time to review privacy practices while the proposed legislation is before Parliament.
The goal is to collect it carefully, explain it clearly, protect it properly, and avoid using it in ways that clients or customers would not reasonably expect.
Privacy problems rarely begin with a dramatic breach or formal investigation. They often start with ordinary business habits that were never reviewed.
A business adds a new website plugin. A manager starts using a new scheduling tool. Employees store client information in shared folders. A marketing team uploads customer lists into an advertising platform. Staff use AI tools to summarize notes or draft emails. A vendor stores data outside Canada. A privacy policy is copied from an old template and never updated.
Each step may seem small. Together, they can create a privacy gap.
A practical privacy review asks whether the business can clearly answer basic questions about its own data practices. If the answer is no, the policy may not match reality.

Before updating a privacy policy or consent form, a business should understand what personal information it actually collects.
That includes obvious information such as names, phone numbers, email addresses, billing details, account information, and identification documents. It can also include less obvious information such as IP addresses, website analytics, chat transcripts, purchase history, appointment details, employment records, video footage, location data, preferences, complaints, and notes about customer interactions.
A data inventory does not need to be complicated at the beginning. The point is to map the main categories of personal information across the business.
Business owners should ask:
If a business does not know what it collects, it cannot reliably explain, protect, retain, or delete it.
Privacy compliance is closely tied to purpose. Businesses should be able to explain why they collect each type of personal information.
For example, a business may collect contact information to respond to inquiries, billing information to process payment, delivery information to fulfill orders, employee banking information for payroll, or website analytics to understand site performance.
Problems arise when information is collected for one reason and later used for another. A customer who provides an email address to receive a receipt may not expect to be added to a marketing list. A client who provides information for a service may not expect it to be entered into an AI tool. An employee who provides information for payroll may not expect it to be used for unrelated monitoring.
If the purpose changes, the consent language and privacy policy may need to change too.
A good review connects each category of data to a specific purpose. If the business cannot explain the purpose, it should ask whether the information should be collected at all.
Consent should be meaningful. That means people should understand what information is being collected, how it will be used, who it may be shared with, and what consequences may follow.
Consent language often fails because it is too broad. Phrases like “we may use your information to improve our services” may not be enough if the business is using the information for detailed profiling, targeted advertising, AI training, third-party analytics, or automated decision-making.
Business owners should review consent language in:
The wording should match what the business actually does. If the business shares information with vendors, uses analytics tools, relies on AI tools, or transfers information outside Canada, those practices should be addressed clearly.
A privacy policy should not be treated as a document that exists only because the website needs a footer link. It should be a practical explanation of the business’s privacy practices.
A strong privacy policy usually explains:
The policy should be accurate. If the business uses tools that collect website data, the policy should not suggest that no tracking happens. If the business uses cloud software, the policy should not imply that all records are stored only in-house. If staff use AI tools, the policy and internal rules should address what information may or may not be entered.
A policy that does not match actual practice can create risk because it may mislead customers and give staff the wrong guidance.

Many businesses do not know exactly where personal information is stored. That is a problem.
Customer and client data may sit in email inboxes, spreadsheets, cloud drives, CRMs, payment processors, marketing platforms, scheduling systems, file-sharing tools, accounting software, helpdesk systems, backups, mobile phones, paper files, and vendor portals.
The location matters because storage affects access, security, retention, breach response, and cross-border transfer risk.
Businesses should identify:
This is not just an IT issue. It is a legal and operational issue.
Access should be tied to role and need. Not everyone in the business needs access to every customer file, employee record, payment record, or client note.
Overbroad access increases risk. It can also make it harder to investigate if information is misused, lost, or disclosed improperly.
Businesses should review internal access to:
Access should be updated when employees change roles or leave the business. Shared passwords should be avoided. Sensitive information should have stronger controls.
A simple access review can prevent many avoidable privacy problems.
Many businesses rely on vendors to collect, store, process, analyze, or support personal information. These vendors may include payment processors, website hosts, email marketing platforms, CRMs, payroll providers, accountants, IT providers, cloud storage providers, analytics tools, booking platforms, call centres, and AI tools.
If a vendor handles personal information, the agreement should address privacy and security.
Business owners should consider whether vendor agreements explain:
A vendor’s standard terms may not protect the business in the way the owner expects. If the business remains accountable to customers or clients, the vendor relationship should be reviewed before data is shared.
AI tools are now part of ordinary business workflows. Staff may use them to draft emails, summarize meeting notes, analyze spreadsheets, prepare marketing copy, translate content, or organize customer information.
The privacy issue is simple: personal information entered into an AI tool may be collected, stored, reviewed, used to improve systems, or disclosed in ways the business has not assessed.
Businesses should not wait until after sensitive information has been pasted into a tool to decide what the rules are.
An AI-use policy should address:
The goal is not to ban useful tools automatically. The goal is to prevent accidental disclosure, improper use, or unclear accountability.
Employee and applicant information can include resumes, references, interview notes, payroll records, banking information, performance records, medical or accommodation information, discipline records, monitoring data, login activity, surveillance footage, and workplace investigation materials.
Businesses should be careful about who can access this information and why.
Employee privacy obligations can depend on the type of organization, the province, the sector, and whether the business is federally regulated. Even where a specific privacy statute does not apply to every employee record, employers still face legal, contractual, workplace, and reputational risks if employee information is mishandled.
Practical steps include limiting access, collecting only what is needed, separating sensitive files, creating retention rules, documenting monitoring practices, and being clear with employees about workplace tools that collect information.
Keeping personal information forever may feel safe, but it can create unnecessary risk. The more information a business keeps, the more it may have to protect, search, produce, correct, or delete.
Businesses should decide how long different types of information need to be kept. Some records may need to be retained for tax, accounting, legal, regulatory, employment, insurance, or dispute-related reasons. Other information may no longer be necessary.
A retention policy should explain:
Retention rules should be practical. A policy no one follows is not much help.
Before collecting more customer, client, employee, or website data, business owners should clarify:
Canada is considering significant changes to its private-sector privacy framework through Bill C-36, including stronger accountability and transparency requirements. Business owners do not need to wait for the proposed legislation to become law before reviewing their current privacy practices.
The most useful first step is to understand the business’s own data practices. What is collected? Why is it collected? Where does it go? Who can access it? What have customers, clients, employees, and website users been told?
Privacy compliance is easier when those questions are answered before a complaint, breach, vendor issue, or regulatory change forces the business to respond quickly.
Need help reviewing privacy policies, consent language, vendor agreements, or AI-use rules? Pace Law Firm can help business owners identify privacy risks, update documents, and build clearer data practices as privacy requirements continue to evolve.
Businesses should review what personal information they collect, why they collect it, how consent is obtained, where the information is stored, who can access it, which vendors receive it, how long it is kept, and whether customers are clearly informed.
Many businesses that collect, use, or disclose personal information should have a clear privacy policy. The policy should explain what information is collected, how it is used, when it may be shared, how it is protected, and who individuals can contact with privacy questions.
A business privacy policy should generally describe the types of personal information collected, the purposes for collection, consent practices, use and disclosure, vendor involvement, cross-border storage or access, safeguards, retention, access and correction rights, and privacy contact information.
Yes. If a vendor handles personal information, the agreement should address what the vendor can access, how the information may be used, where it is stored, what safeguards apply, breach notification, subcontractors, and what happens to the information when the relationship ends.
Businesses should set clear rules before employees use AI tools with customer, client, employee, financial, health, or confidential information. AI-use policies should identify approved tools, restricted information, review requirements, and whether customers or clients need to be informed.
A data inventory is a record of the personal information a business collects, where it comes from, why it is collected, where it is stored, who can access it, which vendors receive it, and how long it is kept.
Updating privacy practices early can help businesses reduce risk, improve transparency, address outdated consent language, review vendor arrangements, and avoid rushed changes if new privacy legislation creates stricter obligations.
Call us now or fill out the form to discuss your case with an experienced legal professional.
191 The West Mall, Suite 1100
Toronto, ON M9C 5K8
Phone: 1-877-236-3060
Fax: 416-236-1809
191 The West Mall, Suite 1100
Toronto, ON M9C 5K8
Phone: 1-877-236-3060
Fax: 416-236-1809
143 Pine Street
Collingwood, ON L9Y 2P1
Phone: 705-444-0031
Fax: 416-236-1809
143 Pine Street
Collingwood, ON L9Y 2P1
Phone: 705-444-0031
Fax: 416-236-1809
136 Main St. South
Kenora, ON P9N 1S9
Phone: 1-877-335-1178
Fax: 416-236-1809
136 Main St. South
Kenora, ON P9N 1S9
Phone: 1-877-335-1178
Fax: 416-236-1809
675 Cochrane Drive, #623A
East Tower, 6th Floor
Markham
ON L3R 0B8, Canada
Phone: 1-877-236-3060
Fax: 416-236-1809
675 Cochrane Drive, #623A
East Tower, 6th Floor
Markham
ON L3R 0B8, Canada
Phone: 1-877-236-3060
Fax: 416-236-1809
400-291 King Street
London
ON N6B 1R8, Canada
Phone: +1-877-236-3060
Fax: 416-236-1809
675 Cochrane Drive, #623A
East Tower, 6th Floor
Markham
ON L3R 0B8, Canada
Phone: 1-877-236-3060
Fax: 416-236-1809