Data is a valuable currency, and you’re trusting your ISP with a lot of sensitive information. They know where you are. They know which websites you visit. And they have almost all the personal information about you imaginable: who you are, where you live, banking details, and more.
Have you ever wondered whether they’re selling your information to third parties? Online privacy is a big issue these days, and you might want to know whether your ISP is to blame for that odd increase in marketing phone calls or spam messages.
Your personal information may be safer than you thought – provided you remain alert. Here’s what you need to know.
Your Online Privacy: A Canadian Perspective
According to the General Data Protection Regulation (GDPR) applied in Canada, you have more and better privacy protections than users in the US may have.
But there’s a caveat, according to Tomas Novosad from NetSpeed Canada. If you give them permission to do so, your ISP can gather and disseminate your information as they please.
The details may be hidden in the small print: those little checkboxes that say you’ve read a privacy policy, the permission to share with “our partners,” or the terms of use agreements you accept without a closer look. The message is clear: if you’re interested in online privacy, always read the T&C and never accept a bunch of checkboxes without taking a closer look at what you’re agreeing to.
At the same time, there’s a heartening increase in legal challenges surrounding unclear privacy policies, and providers are generally compliant, working to help you see how your data is used.
What ISPs Can Do With Your Data
Bell’s privacy policy provides a reasonably clear picture of what Canadian ISPs can legally do with your data.
Unsurprisingly, they will use your data in their marketing efforts, and this may extend to “third-party suppliers.” Things they’re looking for may include your eligibility for and interest in services sold through Bell or its partners. So, if you signed up for an internet plan, don’t be surprised if you get a call offering mobile phone services.
In line with GDPR regulations, there are valid reasons for storing information that are generally accepted and fully understandable. For example, Bell may use third parties to collect outstanding bills and can share your details with them. Naturally, government organisations can ask for and get information about you when they suspect fraud or in case of emergencies.
In theory, other outside institutions can access your information if you grant consent. However, there has been a fair amount of controversy around this, leading ISPs to be more careful about how they use your data and how they ask you for consent to do so.
Looking for a clear, simple answer? Canadian ISPs may not give or sell personal information to third parties without informed consent – a picture far different to that which can currently be seen in the US.
What to Look for in Privacy Policies
The important thing for Canadians to remember is that, under GDPR, your ISP can only collect and use information that’s required by law and that’s needed in order to do business with you. And they can only share it under circumstances that indicate an emergency or breach of law unless you consent. All the same, never mark a checkbox without reading the accompanying privacy policy. Things to look for include:
- What information will be collected and how
- Why the information is collected and under what circumstances it would be shared
- Who your information may be shared with
Offering some relief, the old pre-checked permission box may be a thing of the past. There have been advances in securing user privacy based on the knowledge that most people don’t read, or struggle to understand, privacy policies. For example, many ISP websites are now using icons or simplified summaries with lead-ins to full information, and explainers showing why they need certain data and what they will do with it.
When Can You Say “No?”
You can refuse to disclose personal data at any time. However, it’s impossible to do business with an ISP without disclosing some very sensitive information including your name, address, and banking details.
Your ISP is required to protect your information and only use it for necessary operational purposes, for example, collecting debts. Now, your only concern will be any additional permissions that you grant. And, since you are the one who approves or declines requests like this, you’re in the drivers’ seat – as long as you remain alert.
But, you may be wondering, what about your browsing history? Let’s look at that next.
Are ISPs Storing Your Browsing Data?
Despite strong privacy laws in Canada, your browsing history is being saved by your ISP. The Personal Information Protection and Electronic Documents Act (PIPEDA) requires ISPs to keep a record of your online activities over the last six months. It’s not information they can share with just anyone, but it serves as a record of online activity that can be used if you’re under investigation for one reason or another.
The main problem with PIPEDA is that it only sets a minimum storage time, not a maximum. So, your information may be stored for much longer than six months. Two years is fairly standard. Although this should not be problematic for most users, there are concerns that hackers might access this information, leading to a severe privacy breach. And of course, the longer data is stored, the greater the risk exposure.
The USA: A Wild West For Data Privacy?
In 2017, the Republican government in the USA gave ISPs the green light to sell user data to third parties, leading to widespread concern over data privacy. However, this was followed by the hasty promulgation or drafting of state-based online privacy laws.
California, Virginia, and Colorado had reasonably robust online privacy laws by 2021. Florida, Oregon and Texas followed suit in July 2024. Montana is set to implement its privacy law in October 2024. Delaware, Iowa, Tennessee and New Jersey will pass their privacy laws in 2025, and Indiana is preparing itself for an online privacy law rollout in 2026.
Meanwhile, other states are relying on a hodge-podge of laws aimed at protecting privacy in specific contexts and there are calls for the introduction of a federal law similar to GDPR that specifically addresses data gathering, retention and protection.
GDPR in Canada Offers Protection, But Always Read That Privacy Policy!
Around the world, GDPR has been recognized as a reasonable protection that prevents ISPs from selling your data for profit, sharing it unnecessarily, or otherwise misusing it. Fortunately for Canadians, GDPR is applied in Canada. However, be careful about granting permissions, and always read privacy policies. And, if you’re still worried about Big Brother watching you, you can always resort to an encrypted VPN to help hide your browsing data.

