Skip to main content
Free tool for Canadian businesses

Free Canadian privacy policy generator

Enter your website. Mochi finds the forms, booking tools, payments, analytics and ad pixels that collect visitor data, then writes a PIPEDA-based privacy policy you can paste into your site. Free, no sign-up.

No website yet, or prefer to answer yourself?

What a Canadian privacy policy needs to cover

PIPEDA, Canada's federal private-sector privacy law, expects businesses to be open about how they handle personal information. The policy this generator writes covers:

  • Who is accountable: the person responsible for privacy, with a mailing address and email.
  • What you collect and why, based on what your website actually does.
  • Consent, and how people can withdraw it.
  • Cookies, analytics and ad pixels, with opt-out links for the tools you use.
  • Every third-party service that receives visitor data, with a link to its privacy policy.
  • Storage outside Canada, which PIPEDA expects you to disclose.
  • Access and correction requests, answered within 30 days.
  • Breach notification and how to complain to the Office of the Privacy Commissioner.
  • CASL email consent if you send newsletters, and Alberta or BC PIPA wording if you operate there.

Related guides: CASL compliance for small business, AI chatbot compliance in Canada and AI receptionists for Ontario clinics (PHIPA).

Frequently asked questions

Does my small business need a privacy policy in Canada?

If your business collects personal information, such as names and emails from a contact form, booking details or analytics data, PIPEDA requires you to make information about your privacy practices readily available. A privacy policy on your website is the standard way to do that. Alberta and British Columbia have their own private-sector privacy laws (PIPA) with similar expectations.

What does a Canadian privacy policy have to include?

Under PIPEDA's openness principle it should name the person accountable for privacy and how to reach them, describe what personal information you hold and how you use it, and explain how people can access their information. In practice it should also cover consent, who you share information with, storage outside Canada, how long you keep information, safeguards, and how to complain to the Office of the Privacy Commissioner of Canada.

Do I need a cookie banner in Canada?

Outside Quebec, Canadian law doesn't require a GDPR-style banner for every cookie. If you use advertising pixels such as the Meta Pixel or Google Ads remarketing, the Privacy Commissioner expects people to be told about it clearly when it happens, not only in a privacy policy, and to be able to opt out easily. A short cookie notice is the simplest way to do that.

Does this generator cover Quebec's Law 25?

No. Quebec's Law 25 adds requirements this tool doesn't handle, so businesses based in Quebec should work with a Quebec privacy lawyer.

I run a clinic. Is a website privacy policy enough?

No. Your website policy covers enquiries, bookings and your site's tools. Patient health information is governed by provincial health privacy law, such as PHIPA in Ontario, and your regulatory college's rules. The generator adds a note that points patients to the right place, but your clinical privacy practices need their own policy.

Is this free, and do you keep my answers?

It's free with no sign-up. Your answers stay in your browser: the policy is put together on your device. Only your website address is sent to our server, to scan it.

This generator gives you a starting point based on PIPEDA and is not legal advice. Every business is different: review the policy so it matches what you actually do, and have a lawyer check it if you handle sensitive information such as health or financial data.