
Outside Québec there is no single provincial statute to point at — but the federal privacy and anti-spam rules bind you today, carry real numbers, and are enforced by name.
// The scan reads what is publicly visible on your site. It is a starting point for review — not a legal opinion or a certification of compliance.
Most operators have heard the acronyms and never seen the requirements written plainly. These are the obligations that apply to a public-facing site — no legalese, no size exemptions.
// PIPEDA · In force
Federal privacy law
Governs how a business collects, uses and discloses personal information in the course of commercial activity — customer names, emails, order history. Ten principles, and no small-business exemption.
A findable, specific privacy policy
What is collected, why, who it goes to, how long it is kept, and how to reach the person accountable. "As long as necessary" is not a retention period.
A named accountable person
Someone in the business is responsible for privacy, and their identity is available on request. A privacy notice with no contact behind it does not satisfy it.
Meaningful consent at the point of collection
The purpose is stated where the data is taken, in words a customer can understand — on the reservation form, the catering enquiry, the newsletter box.
Access and correction within 30 days
A person can ask what you hold about them and have errors fixed, and you have 30 days to answer. That needs a workable way to receive the request.
Safeguards proportionate to the data
Transport encryption everywhere and access control on the store behind the site — the baseline for anything holding contact details and order history.
Breach reporting and a 24-month log
A breach that creates a real risk of significant harm must be reported to the Privacy Commissioner and to the people affected — and every breach, reportable or not, is recorded for 24 months.
// CASL · In force
Canada's anti-spam legislation
Governs every commercial electronic message you send — email, text, direct message. A receipt or a reservation confirmation is transactional; the review request, the birthday offer and the newsletter that follow are not.
Consent before you send
Express consent is opt-in and lasts until withdrawn. Implied consent is narrow and time-limited — typically 24 months after a purchase, 6 months after an enquiry.
No pre-checked boxes
A request for consent states the purpose, names the sender and gives a mailing address plus one other way to reach you. A box ticked in advance is not consent.
Every message identifies the sender
Sender name, a mailing address valid for at least 60 days, and a working phone number, email or web address — on every commercial message.
An unsubscribe that works
No login required, live for 60 days after the send, honoured within 10 business days. Nestor's own path applies it at once.
You carry the burden of proof
Due diligence is a defence, which is why the record matters more than the intention: dated, per-address records of what the person was told when they agreed.
Liability reaches the people in charge
Officers and directors can be personally liable, and a business answers for what an employee or an agency sends on its behalf.
Provincial rules layer on top
Alberta and British Columbia run their own private-sector privacy acts, Ontario its accessibility standard, and Québec Law 25 and the Charter of the French language. Which ones bind you follows where you operate and where your customers are.
Straight answer: the scanner checks the federal items it can see from outside — encryption, the privacy policy, consent on your forms — and asks you the rest. Checks for the provincial rules outside Québec are still being built, and a scan says plainly what it did not examine — never a clean bill of health for rules nobody looked at.
Federal privacy law is enforced by publication and the courts; anti-spam law by penalties. Each figure links to the section of the Act that sets it — check us in one click.
Up to $10,000,000
Anti-spam penalties (CASL)
Administrative monetary penalties reach $1 million per violation for an individual and $10 million for an organization — and one marketing message without the right consent is a violation.
Source: CASL s. 20(4)Up to $100,000
Federal privacy offences (PIPEDA)
Knowingly failing to report or record a breach, failing to notify the people affected, or obstructing the Privacy Commissioner is an offence — a fine of up to $100,000.
Source: PIPEDA s. 28Personal liability
Officers and directors answer too
Under CASL the people who direct a business can be held personally liable, and the business answers for messages an employee or an agency sends on its behalf.
Published by name
Privacy findings are public
The Privacy Commissioner cannot fine directly, but investigates, makes findings and publishes them — and the Federal Court can award damages after a finding. The report is the penalty.
10 business days
A late unsubscribe is a violation
CASL counts every message sent after the deadline. The mail log is the only evidence that an unsubscribe was applied on time.
Per address
Consent is proven one recipient at a time
The sender carries the burden of proving consent for each recipient — dated, with the wording shown. Without that record, due diligence is not available as a defence.
// Statutory maximums, not predictions about any business. What a regulator or court actually imposes depends on the facts. Nothing here is legal advice.
Compliance isn't a one-time fix — the law follows every content change you make. Nestor handles the first pass and then keeps it from drifting.
// 01 · Scan
We read your public site
Every page, form, tracker and signup box. You get a plain-language readout of what's in place, what's missing, and what a scan can't confirm from the outside.
// 02 · Rebuild
Fixes go into real code
Consent statements beside every form, a privacy policy that matches what the site collects, marketing consent kept separate from orders and reservations — built into the site itself, never a bolt-on widget.
// 03 · Approve
Nothing ships without you
Every change is staged and previewed. You approve by SMS or in the panel — one tap to publish, one tap to send it back.
// 04 · Maintain
The record keeps itself
Consent events recorded with their date and wording, unsubscribes applied at once, a 30-day clock on access requests and an append-only breach log. Ongoing checks catch drift before a complaint does.
Hosting, encryption keys and operators inside the country — so the residency question is answered before anyone asks it.
// Handled for you
When a customer asks what data you hold — or wants it deleted — the request is logged, actioned and recorded. Old data clears itself on schedule.
// Stays put
Servers, keys and operators in-country, with immutable audit logs showing where data has been the whole time. No cross-border assessment to write.
// One snippet
No re-platforming and no IT project. Nestor takes over the build, keeps your existing tools in place, and runs the compliance layer underneath.
No integrations to build. No systems to replace.