What You Can Legally Ask on a Client Intake Form in Canada

Under PIPEDA you can ask for anything a reasonable person would agree you actually need to do the work, and almost nothing beyond that. Here is how that plays out field by field, plus consent wording short enough that people will read it.

Ayla RadiesCo-Founder · Prince George, BCPublished August 28, 20268 min read

You can ask for anything you genuinely need in order to do the work, quote it accurately, get paid, or meet a legal obligation. You cannot ask for things that would merely be nice to have, and you cannot make answering those optional questions a condition of hiring you. That is the whole of PIPEDA's collection rule in two sentences, and it decides almost every field on an intake form without you needing to read the Act. (https://www.priv.gc.ca/en/privacy-topics/privacy-laws-in-canada/the-personal-information-protection-and-electronic-documents-act-pipeda/pipeda_brief/)

The two sentences that matter are section 5(3), which says you may only collect personal information for purposes "a reasonable person would consider appropriate in the circumstances," and Principle 4.3.3, which says you cannot require someone to consent to collection beyond what is needed to fulfil the purposes you actually stated. So the test for every field is: if a client emailed and asked "why do you need this?", could you answer in one sentence without saying "for our records"? If not, cut the field.

One quick jurisdiction note before the fields. PIPEDA covers commercial activity across Canada, except that Alberta, British Columbia and Quebec have their own substantially similar private-sector laws for provincially regulated organizations.

In practice the collection and consent rules are close enough that one carefully built form works everywhere. Quebec's Law 25 adds a few things: you need a designated person responsible for privacy protection named somewhere reachable, and consent has to be sought for each purpose separately rather than as one lump. Being a one-person business does not exempt you from any of it. There is no small-business carve-out.

Field by field

FieldUsually fine?ConditionName, email, phone, business nameYesNeeded to quote, deliver and invoiceBilling addressYesNeeded for invoicing and GST/HST rate by provinceService address or site detailsYes, if you go thereNot if all work is remoteBudget range, deadline, scope questionsYesDirectly tied to producing a quoteDate of birthRarelyOnly for real identity or age verificationSocial Insurance NumberAlmost neverOnly for a specific tax slip you must fileHealth, dietary or accessibility notesOnly if you must act on themSensitive: express consent, short retentionCard number, expiry, CVVNoUse a checkout that tokenizes insteadFile uploadsDepends entirely on the fileAsk for the narrowest version that works"Add me to your newsletter"Yes, as a separate unchecked boxCASL rules apply, not PIPEDA's alone

Date of birth

Most professional-services intake forms have no legitimate use for a full date of birth. If what you actually need is confirmation that someone is of legal age, ask that question instead: a yes-or-no confirmation collects far less and answers your question exactly. A full DOB paired with a name and address is a strong identity-theft building block, which means collecting it raises your risk of significant harm if you are ever breached, for no operational benefit.

Social Insurance Number

No law forbids a business from asking, which is exactly why the field keeps showing up on forms it has no business being on. The Office of the Privacy Commissioner has been consistent for years that the private sector should not use the SIN as a general identifier. The realistic cases where you do need one are narrow and all tax-driven: filing a T4A for fees for services paid to an individual, a T5018 for construction subcontractors, or a T5 for investment income. If none of those apply to your relationship with the client, the SIN field is indefensible.

And when you do need it, a web intake form is the wrong place to gather it. The number ends up in your form submission record, in the notification email, in that email's copy on your phone, and in every backup of both. Collect it once through a channel you control, at the point you actually need to file, and note in writing why you needed it.

Health, dietary and accessibility information

Health information is sensitive under PIPEDA, which means implied consent is not enough. You need express consent, a clearly stated purpose, and a plan to delete it. There are legitimate reasons a non-medical business collects some of this. An event organizer arranging catering and venue access needs to know about a severe allergy or a mobility requirement, because someone will act on that information on the day. That is a defensible purpose with a natural end date, and the honest thing to do is delete the notes after the event rather than let them sit in a customer record for years. If nobody in your business would ever take an action based on the answer, do not ask the question.

Payment card details

Never as form fields. Not in a text input, not in a "notes" box, not over email as a follow-up. The moment a card number is typed into an ordinary form, that number exists in your database, your email inbox, your form provider's logs and your backups, and every one of those copies is now yours to protect under PCI DSS and PIPEDA's safeguards principle. There is no version of this that is worth the convenience.

The alternative is a checkout or invoice link where the card is tokenized at the moment of entry, so what your business receives is a reference token rather than the number itself. That is how payments work in Chronly: Finix processes them, cards and bank details are tokenized on entry, and raw card or bank numbers are never stored by Chronly. So the correct intake-form field for payment is a sentence saying you will send a secure payment link, and nothing more.

File uploads

An upload field inherits the sensitivity of whatever people put in it, and people are generous. Ask a bookkeeping client for "any relevant documents" and you will receive full prior-year returns, bank statements and occasionally a photo of a driver's license nobody requested. Two habits help: name the specific document you want rather than inviting a general dump, and say plainly what you will do with it and how long you will keep it. If you only need to confirm a figure, ask for the figure.

This is where most intake forms quietly break the law, and it is not PIPEDA that catches them. It is CASL (https://ised-isde.canada.ca/site/canada-anti-spam-legislation/en). Someone filling out your quote request form has clearly consented to you replying about that request, and CASL's implied-consent rules cover an inquiry for six months and a purchase or contract for two years. What that consent does not cover is your monthly newsletter.

Express consent for commercial electronic messages has to be separate, and it cannot be bundled into your terms of service or a general "I agree" checkbox and it cannot be pre-checked. The request has to identify who is asking, include a mailing address plus a phone number, email or web address, and say that consent can be withdrawn. Penalties run to $1 million for an individual and $10 million for an organization, which is a strange amount of exposure to take on for a checkbox most people would happily tick anyway if you just asked properly.

You also need to keep the record. If someone complains two years from now, "we're pretty sure they signed up" is not a defense, so whatever tool holds your form should hold the submission with its timestamp.

Meaningful consent, in the OPC's framing, means emphasizing the key elements: what you are collecting, what you will use it for, who else sees it, and any risk of harm. That does not require a wall of legal jargon. It requires four specifics. Something like this sits under the fields and will do the job:

We use the information above to prepare your quote, deliver the work and keep the records the CRA requires. We do not sell it. We share it only with the service providers we use to run the business, such as our payment processor and accountant. You can ask to see, correct or delete your information any time at [email protected].

Then, separately, unchecked, and clearly not required in order to submit the form:

Email me occasionally about services and updates from Example Studio Inc., 123 Example St, Vancouver BC. Unsubscribe any time.

(If your clients include anyone in Quebec, add the name or title of the person responsible for privacy at your business, and split the purposes into distinct consents rather than one combined statement.)

What happens to the answers after submission

Consent is the front half of the obligation. Safeguards and retention are the back half, and they are what an actual complaint tends to turn on. Three things worth settling before you publish the form:

  • Where submissions land. Every place a copy of the form data exists is a place you have to protect. A form that emails answers to three people and stores them in a spreadsheet has five copies. Fewer copies is better security than any policy document.

  • How long you keep it. CRA generally wants records supporting a transaction kept six years from the end of the last tax year they relate to, so quotes, invoices and the customer details attached to them have a clear floor. Intake answers that never became a transaction do not get that excuse. Neither do one-off notes like event dietary requirements. Set a date and delete.

  • What you do if something leaks. PIPEDA requires you to report breaches of security safeguards to the OPC and notify affected individuals where there is a real risk of significant harm, and to keep records of all breaches for 24 months, including the ones you decided were not reportable. Knowing that in advance is much easier than learning it on the day.

On the practical side, this is the reason forms and form pages in Chronly land the submission straight into the same place your quotes, invoices and customer records live rather than scattering it across inboxes, and it is included on the free plan because a client onboarding form is not a premium feature. When it comes time to collect money, the payment side is separate from the form by design, so there is nowhere on the form for a card number to end up.

One honest caveat: this is a walkthrough of how the rules apply to ordinary intake fields, not legal advice, and neither we nor any software can tell you whether your particular field is defensible. The OPC's guidance on meaningful consent and the CRTC's CASL guidance are both readable and free, and if you are collecting anything sensitive at volume, a lawyer's hour is cheaper than a complaint.

If you have any questions regarding the Forms feature, please do not hesitate to reach out to us at: [email protected]

Questions

Common questions

Can I ask for a client's SIN on my intake form?

Only if you have a specific tax filing that requires it, such as a T4A for fees for services, a T5018 for a construction subcontractor, or a T5. Even then, collect it at the point you need to file through a channel you control rather than through a web form, because a form submission creates copies in your database, your notification emails and your backups. Using a SIN as a customer identifier or collecting it "just in case" is not a legitimate purpose under PIPEDA.

Does PIPEDA apply to a one-person consultancy?

Yes. PIPEDA applies to organizations that collect, use or disclose personal information in the course of commercial activity, and there is no exemption based on revenue or headcount. If you operate in Alberta, British Columbia or Quebec you may fall under that province's substantially similar private-sector law instead, and Quebec's Law 25 adds requirements such as naming a person responsible for privacy.

Is a pre-checked newsletter box legal in Canada?

No, not for express consent under CASL. Express consent to send commercial electronic messages has to be actively given, cannot be pre-checked, and cannot be bundled into your terms of service or a general agreement checkbox. You also need to identify who is asking, provide a mailing address and a second contact method, and state that consent can be withdrawn.

How long should I keep client intake form submissions?

It depends on what the information supports. If the submission became a quote, invoice or contract, CRA record-keeping generally means holding supporting records for six years from the end of the last tax year they relate to. Submissions that never became a transaction, and sensitive one-off details like event dietary or accessibility notes, should be deleted once the stated purpose is finished. PIPEDA does not set a fixed number, but it does require you to have a retention practice rather than keeping everything forever.

What should I do instead of asking for card details on the form?

Say on the form that you will send a payment link once the quote is approved, and leave it there. A checkout or invoice payment page that tokenizes the card at entry means the number never enters your form database, your email or your backups, which keeps you out of scope for storing cardholder data at all.

Can I ask about allergies or accessibility needs if I am not a health business?

Yes, if someone in your business will act on the answer, such as arranging catering or venue access for an event. Health information is sensitive under PIPEDA, so you need express consent rather than implied, a clearly stated purpose, and a plan to delete the information once the event or engagement is over. If no one would take an action based on the answer, do not ask.

Run the whole job in one place

Quote it, schedule it, do it, invoice it, get paid. Start free today and add Pro when you need jobs and scheduling.

Drafted with AI assistance and edited by Ayla Radies.