Personal Information Governance Policy: Law 25 Guide
Adopt an internal policy that governs how personal information is managed in your business.
The essentials
Section 3.2 of the P-39.1 Act (in French) requires every business to adopt governance policies and practices for personal information: staff roles and responsibilities, rules for data retention and destruction, and a complaint-handling process.
These rules must be proportionate to the nature and scope of your activities, written in clear and simple language, and information about them must be published on your website.
For a small business, a document of a few pages is enough. What matters is that it reflects your actual practices, not a theoretical ideal.
What the law says
Law 25 requires businesses to adopt a governance policy for the protection of personal information.
This policy must specify, among other things:
- The practices governing the collection, use, disclosure and retention of personal information
- The roles and responsibilities of team members regarding data protection
- The measures in place to ensure security and confidentiality
- The processes for managing confidentiality incidents
- How the policy is kept up to date
The policy must be proportionate to the size and nature of the company's activities.
For a small business
In a small business, the governance policy can be simple and concise while covering the essential elements required by law. It can serve:
- As a reference for employees
- As proof of compliance in an audit or after an incident
- As an internal document explaining the procedures to follow
Good to know
The governance policy is a mandatory internal document. In the event of an incident or an audit, it is the proof that your business took concrete steps to protect personal information. Its absence can make penalties worse.
Concrete examples
Example 1: A marketing agency adopts a policy stating that all personal information is collected solely to carry out client mandates.
It states that the information is stored on secure Canadian servers, that only authorized employees have access to it, and that any confidentiality incident must be reported immediately to the privacy officer.
Example 2: An accounting firm creates a one-page policy establishing that the owner is the privacy officer and that client files are kept for 7 years and then securely destroyed.
The policy also states that employees must lock their workstations, never share their passwords, and report any anomaly to the owner.
Internal governance and public policy: two complementary documents
The governance policy is the house rules for your data: who can access what, how a client file gets destroyed, what to do if an employee receives an access request. The privacy policy is its public version, intended for your clients.
Your privacy officer is responsible for establishing and enforcing these policies. They also serve as the reference for training your employees.
Where to start when nothing exists
Start from your inventory: it tells you what you hold and where. Then write down what you already actually do (who accesses what, how you archive, how you destroy), rather than a theoretical ideal no one will follow.
Then set three simple, sustainable rules: access limited to each role's real needs, retention periods per data category, and a single point of contact for complaints and requests. An annual review completes the cycle.
Privacy policy vs. governance policy: the difference
| Aspect | Privacy policy | Governance policy |
|---|---|---|
| Audience | Your clients and visitors | Your team |
| Role | Inform people about your practices | Govern internal practices |
| Publication | Published in full on the website | Information about it is published; the details stay internal |
| Legal basis | Section 8.2, in force since September 22, 2023 | Section 3.2, in force since September 22, 2023 |
Mistakes to avoid
- Using a document too complex for the size of the business
- Not involving employees in the rollout
- Forgetting to spell out the incident procedures
- Never updating the policy after internal changes
Step-by-step instructions
Checklist: Step 4 complete?
- My policy covers data collection, use and retention
- Roles and responsibilities are defined
- Security measures are described
- The incident procedure is documented
- My employees have been trained on the policy
- An annual review process is in place
Templates included in the Law 25 Kit
- Personal Information Governance Policy template
- Supplier Assessment Questionnaire template
Frequently asked questions
Since when has this obligation been in force?
Since September 22, 2023, the second wave of Law 25 provisions, at the same time as the requirement to publish a privacy policy on the website.
Do you have to publish the full governance policy?
The law requires you to publish information about these policies in clear and simple language on your website. In practice, the corresponding section of your privacy policy can play that role. The detailed internal document does not have to be public.
What must the policy contain for a small business?
At a minimum: staff roles and responsibilities regarding personal information, retention and destruction rules, the complaint-handling process, and the framework for access requests. A few well-applied pages are worth more than a binder no one reads.
Who writes and maintains this document?
The privacy officer is responsible for it. In a small business, the owner often adapts it from a template, then keeps it alive: annual review and updates whenever practices change.