Living Websites

Do I Need a Cookie Banner? What a Small Ontario Business Actually Has to Do

The short version: if your Ontario business website runs analytics or advertising tools, you owe visitors a clear, accurate disclosure and a real way to say no. Whether that has to be a click-to-accept banner is a different question, and Canada's own privacy regulator answers it less absolutely than most of the pages selling banners do.

Which law is actually pointed at your site

Start by naming the rule, because the answer changes with it. The Office of the Privacy Commissioner of Canada states that PIPEDA applies to private-sector organizations across Canada that collect, use, or disclose personal information in the course of a commercial activity. Its own summary page sets out no exemption for business size, employee count, or revenue. A two-person shop and a two-hundred-person firm sit under the same statute.

Alberta, British Columbia and Quebec have their own private-sector privacy laws that the federal government has deemed substantially similar to PIPEDA. Ontario is not one of them. Ontario's substantially similar legislation covers personal health information only. If you are an ordinary Ontario business selling goods or services, PIPEDA is the law reading your website, and the OPC's published guidance is the closest thing you have to an official answer.

That matters because a large share of the cookie-banner advice on the internet is written against the GDPR, which is a European law with a genuinely stricter default. Advice built for that rule will tell you to block everything until a visitor clicks. That is a defensible thing to do. It is not, on its own, what Canadian law says.

What Canada's privacy regulator actually asks for

The OPC's meaningful-consent guidance sets the bar by category rather than by mechanism. It requires express consent where the information being collected, used or disclosed is sensitive, where the collection, use or disclosure is outside of the reasonable expectations of the individual, or where the collection creates a meaningful residual risk of significant harm. Outside those circumstances, implied consent is permitted.

On tracking specifically, the OPC's guidelines on privacy and online behavioural advertising say that opt-out consent for online behavioural advertising could be considered reasonable, provided a set of conditions is met: people are made aware of the purposes in a clear and understandable manner, they are told at or before the time of collection, the opt-out is easy and takes effect immediately and persistently, the information is limited to non-sensitive information, and it is destroyed as soon as possible or effectively de-identified.

The same guidelines draw a hard line in the other direction. Where a person cannot decline because there is no viable possibility for them to exert control, which the OPC illustrates with zombie cookies, super cookies and device fingerprinting, it says organizations should not be employing that type of technology for online behavioural advertising purposes. It also asks organizations to avoid tracking children and tracking on websites aimed at children.

Read those together and the Canadian requirement is about substance, not furniture. People have to know what is running, understand why, and be able to stop it. A banner is one way to deliver that. A short, honest privacy page that names every tool and every opt-out route is another, and for a brochure site running only ordinary analytics it can be the more truthful one, because it is a page a visitor can actually read rather than a box they click away.

The anti-spam rule that also covers cookies, which most guides skip

There is a second Canadian rule almost nobody mentions in this conversation. Canada's anti-spam legislation governs installing a computer program on someone else's device in the course of a commercial activity, and a cookie is a computer program for that purpose.

The Government of Canada's own page on how CASL applies to software resolves it in the direction a small business would hope. It says a person is considered to have expressly consented to the software installation if their conduct is such that it is reasonable to believe they consent to the program's installation, and that you may also be considered to have expressly consented to the use of cookies when you visit certain websites. In other words, the anti-spam rule does not add a separate click requirement on top of the privacy rule.

This is worth knowing because CASL is the statute Canadian owners have heard of and are nervous about. It is a real rule with real reach, and on this specific point the government's own published guidance is the reassuring one.

Two obligations that are not optional, whatever you decide about the banner

The first is contractual rather than legal, and it binds you the moment you paste in a tracking tag. The Google Analytics Terms of Service state that you must post a Privacy Policy and that the Privacy Policy must provide notice of your use of cookies, identifiers for mobile devices or similar technology used to collect data, and that you must disclose the use of Google Analytics, and how it collects and processes data. Running Analytics without a privacy page that names it is a breach of the terms you agreed to, regardless of what any privacy statute says.

The second is a scoping fact that saves a lot of confusion. Google's EU user consent policy, the one that drives most of the consent-banner behaviour you see on the web, applies to end users in the European Economic Area, the UK and Switzerland. It requires valid consent for cookies or other local storage where legally required and for personal data used to personalize ads, plus records of consent and clear revocation instructions. If your customers are in Niagara, that policy is not the reason you need a banner. If you sell to Europe, it is.

So the honest floor for an Ontario shop is lower than the industry implies and higher than doing nothing: an accurate privacy page that names every tool, says what each one collects, and tells people how to turn it off. Our own is at /privacy/, and it is deliberately boring: it names both analytics tools, says which one uses cookies and which does not, and links the opt-out routes.

Quebec is the case where the answer genuinely changes

If you have customers in Quebec, treat this as a different question. Quebec's privacy regulator states that since September 2023, a business that collects personal information from a person using a technology with functions allowing that person to be identified, located or profiled must inform the person beforehand of the means available to activate those functions, that those technologies may not be activated by default and it is for the person concerned to activate them, and that the privacy settings of a technological product or service offered to the public must ensure the highest level of confidentiality without any intervention by the person concerned.

That is an opt-in default, and it is the reason most Canadian sites with any national reach end up running a banner anyway. It is a real reason. It is a different reason from the one the vendor pages usually give, and knowing which reason applies to you is the difference between buying a tool because it fits and buying one because a blog post frightened you.

One honest limit on this paragraph: the underlying statutory text was not independently retrievable by this site's own fetcher, so everything above is what the Quebec regulator's own plain-language page says, and nothing more. If Quebec customers are a real part of your business, this is the point to ask a privacy lawyer rather than a website.

So what is the actual ongoing maintenance?

Here is the part the original question was really about, and the vendors answer it more clearly in their pricing than in their marketing. The recurring work in cookie compliance is not showing the banner. It is keeping the disclosure accurate as the site changes, because every new embed, chat widget, booking tool, or ad pixel can add a cookie your policy does not mention.

That is why the re-scan cadence is sold as a plan feature rather than included. CookieYes lists monthly scheduled scanning on its Pro plan at $25 a month per domain and weekly scheduled scanning on its Ultimate plan at $55 a month per domain; its free and Basic tiers are not listed with scheduled scanning at all. Read plainly, the paid tiers are selling you the thing that would otherwise be a recurring task on your calendar.

The free tiers are real, and they are sized for small sites. CookieYes lists a free plan at $0 per domain covering 5,000 pageviews a month and 100 pages per scan. Cookiebot's free Core plan covers up to 50 subpages on 1 domain, with paid tiers starting at 7 euros a month. Termly's free plan includes 1 basic legal policy and 10,000 banner views a month, with Starter at $10 per website a month billed annually and Pro+ at $15 per website a month billed annually. Any of those will run a competent banner on a small brochure site for very little.

What none of them removes is the judgement call. The OPC's guidance asks organizations to be accountable and stand ready to demonstrate compliance, and to treat consent as an ongoing process, obtaining fresh consent for significant changes to privacy practices. A scanner can tell you a new cookie appeared. It cannot decide whether the tool that set it changed what you are doing with people's information. That decision stays with the business, and it is the one part of this that never gets automated away.

A plain order of operations

If you want the shortest honest path from where most small sites are today, it runs in this order.

  • Inventory what is actually running. Open your site in a browser with developer tools and look at what sets cookies, or run a free scan. You cannot disclose what you have not counted.
  • Write the privacy page first, before buying anything. Name every tool, say what each collects, say how to turn it off. This is what Google Analytics' own terms require of you, and it is the cheapest thing on the list.
  • Decide whether you have European or Quebec visitors. If yes, an opt-in banner stops being optional and a paid consent tool starts earning its money. If no, and you run only ordinary non-sensitive analytics, the OPC's own opt-out conditions are the standard you are meeting.
  • If you install a banner, install one that actually works. An opt-out that does not take effect immediately, or does not persist, fails the OPC's stated conditions. A banner that sets the cookies before the click is worse than no banner, because it looks like consent and is not.
  • Put a reminder on the calendar for the day you add a new tool. Not a monthly one. A conditional one. The disclosure goes stale when the site changes, not when the month does.

Continue reading

The reason this goes stale is that a website changes and the disclosure does not. A living website keeps its own pages current as the site grows, which is the same habit this problem needs.

See your living website

FAQ

Does an Ontario small business legally need a cookie banner?

Not automatically. PIPEDA applies to any private-sector organization collecting personal information in the course of a commercial activity, with no size exemption, but it sets a consent standard rather than mandating a banner. The Office of the Privacy Commissioner of Canada's own guidelines say opt-out consent for online behavioural advertising can be reasonable when five conditions are met: clear and understandable purposes, notice at or before collection, an easy opt-out that is immediate and persistent, non-sensitive information only, and prompt destruction or effective de-identification. An accurate privacy page with working opt-out routes can meet that standard for a site running ordinary analytics.

Do tracking cookies require opt-in consent under PIPEDA?

Not as a blanket rule. The OPC's meaningful-consent guidance requires express consent where the information is sensitive, where the use is outside the individual's reasonable expectations, or where collection creates a meaningful residual risk of significant harm. Its online behavioural advertising guidelines separately state that opt-out consent for that advertising could be considered reasonable when the stated conditions are met. Several guides currently ranking for this question describe a flat opt-in requirement under PIPEDA. That is stricter than what the regulator's own published pages say.

Does Quebec change the answer?

Yes, and this is the case where a banner usually becomes the practical choice. Quebec's privacy regulator states that since September 2023, technology with functions allowing a person to be identified, located or profiled may not be activated by default, that the person concerned must be informed beforehand of the means to activate them, and that privacy settings on a product or service offered to the public must give the highest level of confidentiality without any intervention by the person. If Quebec customers are a real part of your business, confirm your position with a privacy lawyer rather than a checklist.

What does Google Analytics require me to have?

The Google Analytics Terms of Service state that you must post a Privacy Policy, that the policy must give notice of your use of cookies or similar technology used to collect data, and that you must disclose the use of Google Analytics and how it collects and processes data. That is a contractual obligation you take on when you use the product, separate from any privacy statute. Google's separate EU user consent policy, which drives the click-to-accept behaviour on many sites, applies to end users in the European Economic Area, the UK and Switzerland.

How much ongoing work is a cookie-consent tool, really?

Less than the marketing suggests to set up, and more than it suggests to keep honest. The banner itself is close to install-and-forget. The recurring work is re-checking what your site sets after you add an embed, a chat widget, or a booking tool, and updating the disclosure to match. The vendors price that cadence directly: CookieYes lists monthly scheduled scanning on its $25 a month Pro plan and weekly scanning on its $55 a month Ultimate plan, and does not list scheduled scanning on its free or Basic tiers.

Is this legal advice?

No. This page summarizes what Canadian regulators and Google have published, in plain language, so you can work out which situation you are in. It is general information, not legal advice, and privacy rules change. Confirm your own obligations against the current regulator pages or with a qualified professional.

Sources

  1. Office of the Privacy Commissioner of Canada: PIPEDA in brief (last modified 2024-05-01; fetched 2026-09-07)
    • PIPEDA applies to private-sector organizations across Canada that collect, use, or disclose personal information in the course of a commercial activity. The page sets out no exemption based on business size, employee count, or revenue.
    • Alberta, British Columbia and Quebec have private-sector privacy laws deemed substantially similar to PIPEDA. Ontario is not among them; Ontario's substantially similar legislation covers personal health information only. So PIPEDA is the law that governs an ordinary Ontario small business website.
  2. Office of the Privacy Commissioner of Canada: Guidelines for obtaining meaningful consent (last modified 2025-08-11; fetched 2026-09-07)
    • The OPC's meaningful-consent guidance requires express consent where the information being collected, used or disclosed is sensitive, where the collection, use or disclosure is outside of the reasonable expectations of the individual, or where the collection creates a meaningful residual risk of significant harm. Implied consent is permitted outside those circumstances.
    • The same guidance's seventh guiding principle is accountability: organizations must stand ready to demonstrate compliance. Its sixth asks organizations to treat consent as an ongoing process and obtain fresh consent for significant changes to privacy practices.
  3. Office of the Privacy Commissioner of Canada: Guidelines on privacy and online behavioural advertising (last modified 2025-08-11; fetched 2026-09-07)
    • The OPC's online behavioural advertising guidelines state that opt-out consent for online behavioural advertising could be considered reasonable provided individuals are made aware of the purposes in a clear and understandable manner, are told at or before the time of collection, can easily opt out with an opt-out that takes effect immediately and is persistent, the information collected and used is limited to non-sensitive information, and that information is destroyed as soon as possible or effectively de-identified.
    • The same OPC guidelines say that where individuals cannot decline tracking because there is no viable possibility for them to exert control, including zombie cookies, super cookies and device fingerprinting, organizations should not be employing that type of technology for online behavioural advertising purposes. The guidelines also say organizations should avoid tracking children and tracking on websites aimed at children.
  4. Innovation, Science and Economic Development Canada: How Canada's anti-spam legislation applies to software (date modified 2019-04-01; fetched 2026-09-07)
    • Under Canada's anti-spam legislation, installing a computer program on another person's device in the course of a commercial activity requires consent, and a person is considered to have expressly consented to the software installation if their conduct is such that it is reasonable to believe they consent to the program's installation. The Government of Canada's own CASL software page states that you may also be considered to have expressly consented to the use of cookies when you visit certain websites.
  5. Commission d'acces a l'information du Quebec: Principaux changements apportes par la Loi 25 (French-language page, fetched 2026-09-07)
    • Quebec's privacy regulator states that since September 2023, a business collecting personal information from a person using a technology that includes functions allowing that person to be identified, located or profiled must inform the person beforehand of the means available to activate those functions, that those technologies may not be activated by default and it is for the person concerned to activate them, and that the privacy settings of a technological product or service offered to the public must ensure the highest level of confidentiality without any intervention by the person concerned. The source page is in French; the wording here is a plain-language English rendering of it.
  6. Google: Google Analytics Terms of Service, section 7 Privacy (effective May 15, 2023; fetched 2026-09-07)
    • The Google Analytics Terms of Service require that you must post a Privacy Policy and that Privacy Policy must provide notice of your use of cookies, identifiers for mobile devices or similar technology used to collect data, and that you must disclose the use of Google Analytics, and how it collects and processes data.
  7. Google: EU user consent policy (fetched 2026-09-07)
    • Google's EU user consent policy applies to end users in the European Economic Area, the UK and Switzerland, and requires legally valid consent for the use of cookies or other local storage where legally required and for the collection, sharing and use of personal data for personalization of ads, along with retaining records of consent and giving users clear instructions for revoking it.
  8. Cookiebot: Cookiebot pricing (fetched 2026-09-07)
    • Cookiebot's published pricing lists a free Cookiebot Core plan limited to 50 subpages and 1 domain, a Premium Lite plan at 7 euros a month with the same 50-subpage and single-domain limit, and Premium plans per domain at 15 euros a month for up to 350 subpages, 30 euros a month for up to 3,500 subpages, 50 euros a month for up to 7,000 subpages, and 90 euros a month above that. Prices are shown in euros, excluding VAT.
  9. CookieYes: CookieYes pricing (fetched 2026-09-07)
    • CookieYes' published pricing lists a free plan at $0 per month per domain with 5,000 pageviews a month and 100 pages per scan, a Basic plan at $10 a month per domain with 100,000 pageviews a month and 600 pages per scan, a Pro plan at $25 a month per domain with 300,000 pageviews and 4000 pages per scan, and an Ultimate plan at $55 a month per domain with unlimited pageviews and 8000 pages per scan. Prices are in USD, with local taxes charged in addition.
    • CookieYes sells the re-scan cadence itself as a plan feature: monthly scheduled scanning appears on the Pro plan at $25 a month per domain, and weekly scheduled scanning appears on the Ultimate plan at $55 a month per domain. The free and Basic plans are not listed with scheduled scanning.
    • The CookieYes Ultimate plan, which carries weekly scheduled scanning and unlimited pageviews, is listed at $55 a month per domain.
    • CookieYes lists a free plan at $0 per month per domain, and Termly lists a free plan at $0 that includes 1 basic legal policy and 10,000 banner views a month.
  10. Termly: Termly pricing (fetched 2026-09-07)
    • Termly's published pricing lists a free plan including 1 basic legal policy and 10,000 banner views a month, a Starter plan at $10 per website a month billed annually with 2 legal policies, 10 policy edits and 50,000 monthly banner views, and a Pro+ plan at $15 per website a month billed annually with unlimited policies, edits and banner views. Prices are in USD.