// Blog / Guide

Consent under Canadian privacy law

Share

Consent is the backbone of Canadian privacy law. As a general rule, you need a person's permission to collect, use, or share their personal information, and they need to understand what they are agreeing to. But "get consent" is more nuanced than adding a checkbox. Sometimes a clear yes is required, sometimes it is reasonably assumed, and consent buried in fine print barely counts at all. Here is how it works in plain language, so you can collect data properly without drowning your customers in legalese. This is orientation, not legal advice.

The starting point: you need consent

Under PIPEDA and Quebec's Law 25, the default is that you must have someone's knowledge and consent to collect, use, or disclose their personal information, with some specific exceptions. In practice that means people should not be surprised by what you do with their data. The cleanest way to meet this is to tell them, at the point you collect it, what you are collecting and why, usually through a short, readable privacy notice rather than a wall of text.

Express versus implied consent

Not all consent has to be a formal opt-in. The law recognizes two forms, and the sensitivity of the data decides which you need:

  • Implied consent can be enough for obvious, expected, low-sensitivity uses. If a customer gives you their address to ship an order, you do not need a separate form to use it for shipping, the purpose is obvious.
  • Express consent (a clear, active yes) is required for anything sensitive or anything a person would not reasonably expect. Health, financial, and biometric data, and uses like sharing with third parties or marketing, generally need express consent. Law 25 raised this bar, and for sensitive information express consent is the expectation.

What makes consent actually valid

Consent only counts if it is meaningful. That means it should be:

  • Informed: the person understands what you are collecting, why, and who you might share it with, in plain language.
  • Specific: tied to a purpose. Consent to ship an order is not consent to add them to a mailing list.
  • Freely given: not forced. You should not refuse a service over consent to something the service does not actually require.
  • Easy to withdraw: people can change their mind, and pulling consent should be about as easy as giving it.

Consent that is bundled ("agree to everything to continue"), pre-checked, or hidden in a forty-page policy is weak, and under Law 25 a consent request for sensitive data must be clear and presented separately.

Getting it right in practice

  • Say it at the point of collection. A short notice at the form, the signup, or the checkout beats a policy nobody opens.
  • Separate the extras. Marketing email is a clear opt-in, an unchecked box the person ticks on purpose, never a default. In Canada, sending marketing email also has its own consent rules under the anti-spam law (CASL), so this is doubly important.
  • Make withdrawal real. An unsubscribe link that works, and a simple way to ask you to stop using their data.
  • Re-ask for new purposes. A new use that people would not expect needs fresh consent, you cannot quietly repurpose data collected for something else.
  • Take extra care with minors and sensitive data, where the bar is higher.

Not sure whether your signup forms, marketing, and data sharing are collecting consent the way Canadian law expects? We help small businesses get consent right, so it is compliant and not a nuisance to your customers.

Talk to us

Related