How to write a Law 25 privacy policy
A policy copied from another site says nothing about your activities. Here are the sections to write, and the ones to remove.
Since 22 September 2023, an enterprise that collects personal information has to make its practices available in clear and simple language. The policy names the person in charge, says why information is collected, how long it is kept, and how a person can use their rights. A text that only promises to respect privacy does not do that.
Sections to write
1. Who is responsible
Title and contact details of the person in charge of the protection of personal information. A generic address such as info@ is enough if someone behind it reads messages the same day.
2. What you collect, and why
List the real categories: clients, employees, applicants, site visitors. For each one, state the purpose. "To improve our services" without saying which services does not let the person understand.
3. How you obtain it
Form, contract, cookie, a supplier who sends it to you. If you buy a list, say so. The person should be able to connect the collection to something they did, or to a source you name.
4. Who you communicate it to
Host, payroll, cloud, accounting firm. Name the role, not only "our partners". If information may leave Quebec, the policy says so. The assessment itself is documented separately.
5. How long
A period, or the criterion used to set it, per category. Point to your internal rules. Do not copy one tax period across the whole file.
6. Rights and how to use them
Access, correction, withdrawal of consent, and portability when the information is computerized and was collected from the person. Give the address for requests and the 30-day response time.
What to take out
A clause that allows any future use described as compatible, without describing it.
A link to an American vendor policy as if it replaced yours.
A missing update date. The person, and the Commission, need to see which version applies.
Where to publish it
On the site, at a stable link in the footer, not only in a welcome email. If you have no site, hand the text over at the time of collection, on paper or in the contract. The published version and the version your teams apply have to be the same.
A policy that matches the processing register
CapPRP links activities, retention periods and the text you publish, so the policy does not drift away from the register.
