Nestor Logic
PIPEDA · PrivacyCASL · Anti-spamProvincial rules

Two federal laws touch every Canadian website.

Outside Québec there is no single provincial statute to point at — but the federal privacy and anti-spam rules bind you today, carry real numbers, and are enforced by name.

Rules for

One free scan. We keep the result for 12 months, along with the address and approximate location your request came from — read the Scanner Terms and our Privacy Policy.

// The scan reads what is publicly visible on your site. It is a starting point for review — not a legal opinion or a certification of compliance.

What the laws actually ask for

PIPEDA governs the data. CASL governs the message.

Most operators have heard the acronyms and never seen the requirements written plainly. These are the obligations that apply to a public-facing site — no legalese, no size exemptions.

// PIPEDA · In force

Federal privacy law

Governs how a business collects, uses and discloses personal information in the course of commercial activity — customer names, emails, order history. Ten principles, and no small-business exemption.

A findable, specific privacy policy

What is collected, why, who it goes to, how long it is kept, and how to reach the person accountable. "As long as necessary" is not a retention period.

A named accountable person

Someone in the business is responsible for privacy, and their identity is available on request. A privacy notice with no contact behind it does not satisfy it.

Meaningful consent at the point of collection

The purpose is stated where the data is taken, in words a customer can understand — on the reservation form, the catering enquiry, the newsletter box.

Access and correction within 30 days

A person can ask what you hold about them and have errors fixed, and you have 30 days to answer. That needs a workable way to receive the request.

Safeguards proportionate to the data

Transport encryption everywhere and access control on the store behind the site — the baseline for anything holding contact details and order history.

Breach reporting and a 24-month log

A breach that creates a real risk of significant harm must be reported to the Privacy Commissioner and to the people affected — and every breach, reportable or not, is recorded for 24 months.

// CASL · In force

Canada's anti-spam legislation

Governs every commercial electronic message you send — email, text, direct message. A receipt or a reservation confirmation is transactional; the review request, the birthday offer and the newsletter that follow are not.

Consent before you send

Express consent is opt-in and lasts until withdrawn. Implied consent is narrow and time-limited — typically 24 months after a purchase, 6 months after an enquiry.

No pre-checked boxes

A request for consent states the purpose, names the sender and gives a mailing address plus one other way to reach you. A box ticked in advance is not consent.

Every message identifies the sender

Sender name, a mailing address valid for at least 60 days, and a working phone number, email or web address — on every commercial message.

An unsubscribe that works

No login required, live for 60 days after the send, honoured within 10 business days. Nestor's own path applies it at once.

You carry the burden of proof

Due diligence is a defence, which is why the record matters more than the intention: dated, per-address records of what the person was told when they agreed.

Liability reaches the people in charge

Officers and directors can be personally liable, and a business answers for what an employee or an agency sends on its behalf.

Provincial rules layer on top

Alberta and British Columbia run their own private-sector privacy acts, Ontario its accessibility standard, and Québec Law 25 and the Charter of the French language. Which ones bind you follows where you operate and where your customers are.

Straight answer: the scanner checks the federal items it can see from outside — encryption, the privacy policy, consent on your forms — and asks you the rest. Checks for the provincial rules outside Québec are still being built, and a scan says plainly what it did not examine — never a clean bill of health for rules nobody looked at.

What's at stake

The numbers, from the statutes themselves.

Federal privacy law is enforced by publication and the courts; anti-spam law by penalties. Each figure links to the section of the Act that sets it — check us in one click.

Up to $10,000,000

Anti-spam penalties (CASL)

Administrative monetary penalties reach $1 million per violation for an individual and $10 million for an organization — and one marketing message without the right consent is a violation.

Source: CASL s. 20(4)

Up to $100,000

Federal privacy offences (PIPEDA)

Knowingly failing to report or record a breach, failing to notify the people affected, or obstructing the Privacy Commissioner is an offence — a fine of up to $100,000.

Source: PIPEDA s. 28

Personal liability

Officers and directors answer too

Under CASL the people who direct a business can be held personally liable, and the business answers for messages an employee or an agency sends on its behalf.

Published by name

Privacy findings are public

The Privacy Commissioner cannot fine directly, but investigates, makes findings and publishes them — and the Federal Court can award damages after a finding. The report is the penalty.

10 business days

A late unsubscribe is a violation

CASL counts every message sent after the deadline. The mail log is the only evidence that an unsubscribe was applied on time.

Per address

Consent is proven one recipient at a time

The sender carries the burden of proving consent for each recipient — dated, with the wording shown. Without that record, due diligence is not available as a defence.

// Statutory maximums, not predictions about any business. What a regulator or court actually imposes depends on the facts. Nothing here is legal advice.

How we close the gaps

Scan, rebuild, approve, stay compliant.

Compliance isn't a one-time fix — the law follows every content change you make. Nestor handles the first pass and then keeps it from drifting.

// 01 · Scan

We read your public site

Every page, form, tracker and signup box. You get a plain-language readout of what's in place, what's missing, and what a scan can't confirm from the outside.

// 02 · Rebuild

Fixes go into real code

Consent statements beside every form, a privacy policy that matches what the site collects, marketing consent kept separate from orders and reservations — built into the site itself, never a bolt-on widget.

// 03 · Approve

Nothing ships without you

Every change is staged and previewed. You approve by SMS or in the panel — one tap to publish, one tap to send it back.

// 04 · Maintain

The record keeps itself

Consent events recorded with their date and wording, unsubscribes applied at once, a 30-day clock on access requests and an append-only breach log. Ongoing checks catch drift before a complaint does.

The sovereign vault

Your customer data stays in Canada.

Hosting, encryption keys and operators inside the country — so the residency question is answered before anyone asks it.

// Handled for you

Requests, done

When a customer asks what data you hold — or wants it deleted — the request is logged, actioned and recorded. Old data clears itself on schedule.

// Stays put

Hosted in Canada

Servers, keys and operators in-country, with immutable audit logs showing where data has been the whole time. No cross-border assessment to write.

// One snippet

Nothing to migrate

No re-platforming and no IT project. Nestor takes over the build, keeps your existing tools in place, and runs the compliance layer underneath.

Let Nestor run it. Get your life back.

No integrations to build. No systems to replace.