Back to Blog
PIPEDA August 3, 2026 7 min read

PIPEDA for Your E-commerce Online Store: What Canadian Sellers Actually Owe Their Customers

Your Shopify store collects more personal data than most law firms. Here is what PIPEDA, Law 25, and CASL actually expect from a Canadian online seller, and where the real risk hides.

By Valdra Team

PIPEDA for Your E-commerce Online Store: What Canadian Sellers Actually Owe Their Customers

A customer in Trois-Rivières buys a $40 hoodie from your store. In the ninety seconds that takes, you collect her name, billing and shipping addresses, email, phone number, the last four digits of her card, her IP address, her device fingerprint, the products she looked at but didn't buy, and a behavioural profile stitched together by four third-party scripts she never agreed to. You probably don't think of yourself as a data company. The Office of the Privacy Commissioner of Canada doesn't care what you think you are. Under federal law you are a custodian of personal information, and the rules land on a one-person Shopify shop exactly as they land on Amazon.

That gap, between how online sellers see themselves and how the law sees them, is where almost every privacy problem in Canadian e-commerce starts.

What PIPEDA for an e-commerce online store actually covers

The Personal Information Protection and Electronic Documents Act governs every business that collects, uses, or discloses personal information in the course of commercial activity. Selling things online is commercial activity. There is no small-business exemption. The $1 million revenue threshold people sometimes repeat does not exist in PIPEDA; you may be thinking of CASL chatter or a provincial statute. Take one order from a customer in Canada and PIPEDA applies.

PIPEDA rests on ten fair information principles, and you don't need to memorize them. They collapse into a handful of duties. You need a reason for every piece of data you collect, and "it might be useful later" is not a reason. You need meaningful consent. You have to safeguard the data with security that matches its sensitivity. You must let a customer see what you hold about them and correct it. And you have to be accountable, which in plain terms means a named person in your business owns this and can answer for it.

The principle most stores trip over is data minimization, which lives inside the consent and purpose rules. Your checkout form asks for a date of birth because the theme template shipped with the field. You will never use it. Collecting it anyway is a PIPEDA problem, because you have no identified, reasonable purpose for it. Every field you add is something you then have to justify, secure, and eventually delete.

The four places customer data leaks out of your store

Checkout is the obvious one, and oddly it's the least of your worries, because Stripe, Shopify Payments, Moneris, and the rest carry the heavy PCI-DSS load. You should still understand that you stay accountable for the data even when a processor handles it. PIPEDA's accountability principle is blunt on this: handing data to a third party for processing does not hand off your responsibility. If your payment processor suffers a breach involving your customers, part of the explaining falls to you.

Analytics is the quiet leak. Google Analytics, the Meta Pixel, the TikTok Pixel, session-recording tools, that abandoned-cart app you installed in 2022 and forgot. Each loads JavaScript that ships customer behaviour, and frequently IP addresses and identifiers, to servers outside Canada. The OPC treats IP addresses as personal information in most contexts. Cross-border transfer is allowed under PIPEDA, but you have to tell customers it is happening and that their data may become subject to foreign law. Most Canadian online stores run a privacy policy that mentions none of the dozen trackers actually firing on the page.

Marketing answers to a different statute, and it catches sellers off guard. CASL, enforced by the CRTC, requires consent before you send commercial electronic messages. That promo email to everyone who ever bought from you needs express or valid implied consent, clear identification of your business, and a working unsubscribe that you honour within ten business days. CASL penalties reach up to $10 million for a business. The CRTC has handed seven-figure penalties to companies far smaller than they assumed it would bother with.

Then there is the leak almost nobody is tracking yet.

The AI tools quietly handling your customers' data

You bolted an AI chat widget onto support. It's genuinely useful. It also reads every conversation, and depending on the vendor, those conversations may train models, sit indefinitely on US servers, or pass to a sub-processor you have never heard of. Same story for AI recommendation engines, AI review summaries, fraud-scoring tools, and the "smart" search bar profiling what shoppers type.

Personalization is just profiling that the marketing team likes the sound of.

PIPEDA doesn't ban any of this. It asks you to be honest about it. When an automated system makes a meaningful decision about a customer, such as flagging them as a fraud risk and blocking a purchase, that customer reasonably expects to know it. Quebec's Law 25 goes further: residents have an explicit right to be told when a decision relies exclusively on automated processing, plus the right to ask for the reasons and the main factors behind it. An online store running an off-the-shelf fraud filter against Quebec customers is squarely inside that rule, whether or not anyone clocked it.

Quebec changes the math

Ship to Quebec, as almost every Canadian store does, and Law 25 applies. It is stricter than PIPEDA on nearly every axis. Its regulator, the Commission d'accès à l'information (the CAI), can impose administrative monetary penalties of up to $10 million or 2% of worldwide turnover, whichever is higher, with a separate penal track that climbs to $25 million or 4%.

Three Law 25 obligations bite e-commerce hardest. You must appoint a person responsible for the protection of personal information, and their title and contact details must be published where a visitor can find them, not buried in a PDF. You must run a privacy impact assessment before moving personal information outside Quebec or rolling out a high-risk system, which sweeps in a lot of ordinary store tech. And your site's privacy settings must default to the most protective option, the requirement people mean by "privacy by default." A cookie banner that pre-checks every tracking category fails this outright. Plenty of Canadian stores still ship exactly that banner.

For health-adjacent sellers, a pharmacy, a supplement shop, a clinic running a storefront, Ontario's PHIPA can pull personal health information into scope under its own regulator, the Information and Privacy Commissioner of Ontario, with a consent and safeguard regime layered on top.

What to actually do this quarter

Map your data before you write a single line of policy. Open your store's app and script list and write down every tool that touches customer information and where it sends that data. Most sellers find half a dozen surprises. Cut the fields and trackers you can't tie to a real purpose. Rewrite the privacy policy so it names the categories of data, the third parties, the cross-border transfers, and your retention periods in language a customer can read. Fix the cookie banner so nothing non-essential fires before consent and the defaults sit off for Quebec. Name your responsible person. Stand up a basic process for handling an access request and a breach, because PIPEDA's mandatory breach reporting bites hard: when a breach poses a real risk of significant harm you must report to the OPC and notify affected individuals as soon as feasible, keep a breach log for 24 months, and knowingly failing those duties is an offence carrying fines up to $100,000.

None of this demands a $500,000 consultant, which is the whole reason Valdra exists: automated, bilingual, Canada-hosted compliance built for the ordinary online business rather than the Fortune 500. To see where your store stands against PIPEDA and Law 25 before a customer complaint forces the question, start with a free PIPEDA assessment for your online store.

PIPEDA for e-commerce online storeCanadian online store privacy lawPIPEDA compliance ecommerceQuebec Law 25 online storeecommerce data privacy Canadaonline store consent requirements

AI governance and privacy compliance, simplified.

Valdra helps Canadian companies govern AI and meet PIPEDA and Law 25 — hosted in Canada.

Try Valdra

Our own compliance

We run our own compliance programme inside Valdra — the product we sell. Our SOC 2, ISO 27001 and ISO 42001 programmes are actively in progress; we do not claim certifications we do not yet hold.

Valdra compliance badge — click to verify
  • PIPEDA
  • Law 25 (Quebec)
  • CASL
  • Data hosted in Canada 🇨🇦
  • AI governance
View our Trust Centre

Self-declared, not audited by a third party. Click the badge to verify it is genuine and see what it covers.

PIPEDA for an E-commerce Online Store | Valdra