If your website or application collects personal information, such as names, email addresses, IP addresses, cookies, payment details or account activity, then privacy law applies to you, whatever your size. The European Union's General Data Protection Regulation (GDPR) is the best-known regime and applies to organisations anywhere that offer goods or services to people in the EU or monitor their behaviour. Canada has its own framework, including PIPEDA, provincial laws and Quebec's Law 25, along with the anti-spam law CASL. This article gives developers and business owners a practical orientation. It is general information, not legal advice; consult a lawyer or privacy professional about your specific obligations.

What counts as personal data
Personal data is any information relating to an identifiable person: obvious items like names and emails, but also IP addresses, device identifiers, cookie IDs, location data, photographs, account IDs and behavioural profiles. Some categories, such as health, biometric data, religion, political views and children's data, are sensitive and demand extra care. Even data you have pseudonymised, such as replacing names with IDs, is still personal if it can be linked back. Start by knowing what you collect: create a data inventory listing each type of personal data, where it comes from, why you collect it, where it is stored, who can access it, which vendors receive it and how long you keep it.

Core principles that recur across laws
- Purpose limitation. Collect data for specified, legitimate purposes and do not use it for unrelated ones without a new basis.
- Data minimisation. Collect only what you need. Every field you do not collect is one you cannot lose.
- Transparency. Tell people, in plain language and at the time of collection, what you collect, why, who receives it and how to exercise their rights.
- Lawful basis and consent. Under GDPR you need a lawful basis, such as consent, contract, legitimate interests or legal obligation. Canadian law generally centres on meaningful consent, with exceptions.
- Accuracy and retention. Keep data correct, and delete or anonymise it when you no longer need it.
- Security safeguards. Protect data appropriate to its sensitivity.
- Accountability. Be able to demonstrate compliance: policies, records, training and assessments.
Consent done properly
Where you rely on consent, it must be specific, informed, freely given and easy to withdraw, and you must be able to prove it. Pre-ticked boxes, bundled consent and consent hidden in terms do not qualify under GDPR. For cookies and similar technologies that are not strictly necessary, such as analytics and advertising, EU rules require prior opt-in; other jurisdictions have their own expectations. Practical steps: implement a consent management mechanism that blocks non-essential scripts until consent is given, records the choice with a timestamp and version of the notice, offers granular options and lets users change their mind as easily as they agreed. For email marketing in Canada, CASL requires consent, sender identification and unsubscribe; our CRM and email integration article explains how to synchronise consent across tools.
Respecting individual rights
People have rights over their data. Under GDPR these include access to their data, correction, erasure in certain cases, restriction of processing, portability in a machine-readable format and objection to certain processing. Canadian laws provide access and correction rights, and Quebec's Law 25 adds portability and rules around automated decisions. Applications should make these requests manageable: identify a person's data across systems, export it in a common format, delete or anonymise it when required including in caches, search indexes, backups within retention cycles and third-party tools, and respond within statutory deadlines, typically about a month. Building an admin tool for access and deletion requests early is far easier than handling them manually later. Propagating deletion across integrations is one reason to design synchronisation carefully; see our data synchronisation guide.
Security and privacy by design
Privacy regulators expect appropriate technical and organisational measures. Encrypt data in transit and at rest, apply strict access control and audit logging, minimise who can see personal information, separate production and test data, and protect backups. Design new features with privacy in mind: conduct a short privacy impact assessment when introducing new data uses, particularly profiling, sensitive data or large-scale processing. Use techniques such as pseudonymisation, aggregation and shorter retention to reduce risk. Security fundamentals are covered in our security audit guide and our web vulnerabilities guide.

Vendors, processors and international transfers
Most applications send personal data to third parties: hosting, email, analytics, payment processors, support tools, AI services. You remain responsible for what they do with it on your behalf. Maintain a register of vendors, understand what data each receives, and sign data processing agreements where required. Review their security and where they process data. GDPR restricts transfers of personal data outside the EU unless safeguards are in place; Canadian law requires accountability for data transferred for processing, including notice to individuals in some circumstances, and Quebec law has specific requirements for transfers outside the province. Data residency, and where backups and logs reside, matters; our hosting comparison in cloud hosting options touches on location choices.

Breach response
Have a plan before an incident. Under GDPR, breaches likely to harm individuals must be reported to the regulator within 72 hours of becoming aware, and affected individuals informed where the risk is high. In Canada, PIPEDA requires reporting breaches that pose a real risk of significant harm to the Privacy Commissioner and affected individuals, and keeping records of all breaches. Your plan should cover detection, containment, assessment of what data and who is affected, notification steps and templates, and post-incident review. Logging and monitoring, per our monitoring guide, are what make timely detection possible.
Children and sensitive contexts
If your service is aimed at children or likely to be used by them, stricter rules apply, including verifiable parental consent thresholds that vary by jurisdiction. Health, financial and education contexts often have sector-specific laws layered on top. If you operate in those areas, involve a specialist early.
Documentation and governance
Keep a privacy policy that accurately reflects practice, a cookie policy, records of processing activities where required, retention schedules, vendor records, training records and evidence of consents. Appoint someone responsible for privacy, and a designated officer where the law requires it, as Quebec does. Review documentation when you change systems or features, since inaccurate privacy notices are a compliance risk in themselves.
A practical starting plan
- Build a data inventory and map the flows.
- Reduce what you collect and how long you keep it.
- Fix your notices and consent mechanisms, including cookies and email.
- Build or configure tools for access, export and deletion requests.
- Review vendors and contracts.
- Strengthen security and logging.
- Write and rehearse your breach response.
- Review annually and with each significant change.
Privacy compliance is easier and cheaper when it is designed in. Our software team builds consent, data-subject-request tooling and privacy-conscious architecture into applications, and a maintenance plan keeps dependencies, configurations and documentation current as regulations and your systems evolve.
Put this into practice with CodeLuma
CodeLuma builds privacy into the design of applications, with consent management, data minimisation, export and deletion tools and vendor mapping, so compliance is part of the product, not a last-minute scramble.
- Custom software development - tailored systems, integrations and internal tools.
- Website and web application development - fast, accessible, search-friendly builds.
- Maintenance and support plans - updates, monitoring and ongoing improvement.
Start a conversation. Tell us about your project and we will reply with practical next steps, or browse all CodeLuma services. CodeLuma Development Inc. is based in Nova Scotia and works with teams across Canada and remotely.


