iluvfreetools
Site & safety46 of 46

Risk assessments, method statements, SWMS and job hazard analyses, for the UK, US, Australia and Canada. Finished documents, no empty boxes left for you.

All 46 ›
Structure & materials35 of 35

Steel, timber, concrete, brickwork, boards, groundworks and roofs. Section data, indicative sizing, quantities and the reference tables you normally go hunting for.

All 35 ›
Home & property32 of 32

See what it would look like before you commit, then work out what it takes. Upload a photo of your own wall, drive or house and try things on it.

All 32 ›
Invoices & docs20 of 20

Invoices, quotes, receipts and the rest of the paperwork, generated properly. No account, no watermark, and Download is the only button.

All 20 ›
Money & tax39 of 39

Wages, mortgages, tax and the everyday sums. What you actually take home, what it actually costs, and what you actually owe.

All 39 ›
People & hours46 of 46

Rotas, rosters and schedules, holiday and PTO, timesheets and staff paperwork. The admin that eats a Sunday evening, done in ten minutes.

All 46 ›
Business & marketing50 of 50

Starting up, getting found and keeping the admin straight. Everything downloadable, nothing paywalled at the last step.

All 50 ›
PDF & documents27 of 27

Merge, split, crop, sign, number and compress. Everything runs in your browser, so the contract you open here never reaches a server.

All 27 ›
Image tools24 of 24

Convert, resize, compress, crop and adjust. All of it on your own machine, with no upload, no account and no watermark on anything.

All 24 ›
Text & dates20 of 20

Word counts, case, days between dates, working days and ages. The ten-second look-ups, with no account and nothing stored.

All 20 ›
Random & party27 of 27

Secret Santa, draws, brackets, sweepstakes, printables and party quantities. The bit that is just for fun, done properly.

All 27 ›
Training & tests21 of 21

Practice tests for the cards and licences that decide whether you can work. Every answer cites the guidance it came from, not a forum.

All 21 ›

PIPEDA privacy policy

Free. No account, no email, nothing uploaded.

Built round PIPEDA's ten fair information principles, not the UK GDPR's Article 13 or Australia's thirteen APPs. The consent question below is the one that actually differs: express or implied, purpose by purpose, rather than a lawful basis picked once.

1. Accountability2. Identifying purposes3. Consent4. Limiting collection5. Limiting use, disclosure and retention6. Accuracy7. Safeguards8. Openness9. Individual access10. Challenging compliance

Thing you do 1

Where you operate

Alberta, British Columbia and Quebec each run their own private sector privacy law instead of PIPEDA. Tick any that genuinely apply, rather than leaving this notice silent about them.

PIPEDA privacy notice 0 purposes

Put your organization name in. Principle 1, Accountability, starts with saying who is responsible, and that is you.

Nothing paywalled, nothing uploaded. A template built from PIPEDA's ten principles, not legal advice.

Worked out on this device, by this page. Nothing you typed was sent anywhere or stored, and closing the tab loses it.

Next in the same job

A different Act asks a different question, not the same one relabelled

A Canadian privacy notice is not a UK GDPR notice with the nouns swapped, and the difference is structural. UK GDPR gives six lawful bases and asks you to pick one per purpose. PIPEDA has no lawful basis system at all. Its third principle, Consent, asks a sharper question for everything you do: does this need express consent, a real opt-in, or can it rely on implied consent, the kind that follows from someone simply doing business with you. That turns on three things: whether the information is sensitive, whether the use sits within what a reasonable person would expect, and whether getting it wrong carries a meaningful risk of real harm. A policy built on six lawful bases has nowhere to put that answer, which is why this is a separate tool rather than a country switch on the UK one.

Ten principles, not Article 13 and not the thirteen APPs

Schedule 1 to PIPEDA lists ten fair information principles: accountability, identifying purposes, consent, limiting collection, limiting use disclosure and retention, accuracy, safeguards, openness, individual access, and challenging compliance. Ten, in that order, neither the UK's Article 13 list nor Australia's thirteen Privacy Principles. This tool builds a section for each one that applies and prints the Principle beside it, so it can be checked against the Act rather than taken on trust. One shapes the first field on this page: Accountability requires every organization, whatever its size, to designate someone answerable for how it handles personal information. That is a real requirement, unlike a UK data protection officer, but a lighter one than it sounds. It need not be a dedicated privacy officer, and in a business of one it can simply be you, named rather than left blank.

Alberta, British Columbia and Quebec, and why Quebec reads differently

All three have private sector privacy laws the federal Privacy Commissioner has declared substantially similar to PIPEDA: Alberta's and British Columbia's own Personal Information Protection Acts, and Quebec's Act respecting the protection of personal information in the private sector. An organization covered by one of those laws is generally exempt from PIPEDA for information handled inside that province. Cross-border disclosures and federally regulated businesses, banks and telecoms among them, stay under PIPEDA regardless. Tick the provinces that genuinely apply and the notice names the right law and regulator, rather than leaving a business assuming a federal notice covers it in full.

Quebec is not simply the strict one. Its own Act, read directly rather than taken from a summary, requires a named person in charge of privacy to be published on your own website, which PIPEDA asks of nobody. It uses its own breach trigger, a risk of serious injury, worded differently from PIPEDA's real risk of significant harm. It grants rights PIPEDA does not grant federally, to receive certain information in a structured, commonly used format and, in some circumstances, to have harmful dissemination stopped. And its penalties go well beyond PIPEDA's own maximum of $100,000: administrative penalties reported up to $10 million or 2% of worldwide turnover, and separate fines reported up to $25 million or 4% of worldwide turnover. That is why the Quebec paragraph here reads differently from the Alberta and British Columbia ones.

What happens if something goes wrong, and what this does not do

PIPEDA's breach duty is narrower in one direction and wider in the other than most summaries suggest. Only once a breach creates a real risk of significant harm must you report it to the Office of the Privacy Commissioner of Canada and notify the people affected, as soon as you reasonably can. But every breach, whether it clears that bar or not, has to be recorded and kept for at least two years. A business that only thinks about the reportable kind has half the duty in view.

This tool does not make your notice compliant, and no free tool could promise that honestly. It builds only what you told it, and will not let you finish without naming who is accountable or how long you keep what you collect. Whether it is accurate for your business, and whether Alberta, British Columbia or Quebec law applies instead of PIPEDA for any part of what you do, is a question only you can answer. This is a template built from the Act, not legal advice.

The notice is built from what you type, on your machine

The notice is built in your browser from what you type in, and the PDF is generated and saved on your own machine. No account, no email address, and no copy of your privacy notice sitting on a server you do not control.

Common questions

What has to be in a PIPEDA privacy notice?

Schedule 1 to PIPEDA sets out ten fair information principles, and a notice worth publishing works through them: accountability, identifying purposes, consent, limiting collection, limiting use disclosure and retention, accuracy, safeguards, openness, individual access, and challenging compliance. This tool builds one section per purpose you actually have, and prints the Principle beside each part of the notice so you can check it against the Act rather than take the tool's word for it.

Why is this a different tool from the UK GDPR privacy policy generator?

Because the question it asks is genuinely different, not translated. UK GDPR wants one of six lawful bases picked for each purpose. PIPEDA asks whether consent should be express or can be implied, and that turns on whether the information is sensitive, whether the use sits within reasonable expectations, and whether getting it wrong carries a meaningful risk of harm. A policy built on six lawful bases has nowhere to put that answer, which is why this exists as its own tool rather than a country switch on the other one.

Is consent always required, and can it ever be implied?

Consent is always required under Principle 3. What varies is its form. The Privacy Commissioner's own guidance says consent should generally be express, and must be express wherever the information is sensitive, the use is outside what someone would reasonably expect, or there is a meaningful risk of real harm if it goes wrong. Outside those three, implied consent can be enough, provided it is genuinely obvious rather than merely convenient. This tool asks the three questions per purpose and tells you which form its answer points to.

Do Alberta, British Columbia and Quebec really run their own rules?

Yes, and this is the part a flattened summary tends to lose. All three have private sector privacy laws the federal regulator has declared substantially similar to PIPEDA: Alberta's and British Columbia's own Personal Information Protection Acts, and Quebec's Act respecting the protection of personal information in the private sector. An organization covered by one of those laws is generally exempt from PIPEDA for information handled inside that province. Cross-border disclosures and federally regulated businesses, banks and telecoms among them, stay under PIPEDA regardless of province.

What makes Quebec different, specifically?

More than a stricter version of the same rules. Quebec's Act requires a named person in charge of privacy to be published on your own website, which PIPEDA does not ask of anybody. It uses its own breach trigger, a risk of serious injury, worded differently from PIPEDA's real risk of significant harm. It grants a right to receive some information in a portable, structured format and, in some circumstances, to have harmful dissemination stopped, neither of which PIPEDA grants federally. And its penalties go well beyond PIPEDA's own maximum of $100,000: administrative penalties reported up to $10 million or 2% of worldwide turnover, and separate fines reported up to $25 million or 4% of worldwide turnover. A Quebec organization reading a plain PIPEDA notice and assuming it is covered is exactly the mistake this tool is built to stop.

What has to happen if there is a data breach?

Under PIPEDA, once it is reasonable to believe a breach of security safeguards creates a real risk of significant harm, you must report it to the Office of the Privacy Commissioner of Canada and notify the people affected, as soon as you reasonably can. That is narrower than it sounds in one direction and wider in another: only breaches meeting that threshold need reporting, but every breach, whether it meets the threshold or not, has to be recorded and kept for at least two years. A notice that only mentions the reportable kind is describing half the duty.

Do my company details get sent anywhere?

No. The notice is built in your browser from what you type in, and the PDF is generated and saved on your own machine. No account, no email address, and no copy of your privacy notice sitting on a server you do not control.