Law 25 Privacy Policy: What the Law Requires (+ Template)
Create and publish a clear policy explaining how you handle personal information.
The essentials
Since September 22, 2023, every business that collects personal information through technological means (website, online form, newsletter) must publish a privacy policy on its site, written in clear and simple language (s. 8.2, P-39.1 Act (in French)).
The policy must explain what data you collect, why, how, who has access to it, your protection measures and individuals' rights, along with the contact information of your privacy officer.
It is the most visible compliance gap: anyone, client or CAI inspector, can check in 30 seconds whether your site has one.
What the law says
Law 25 requires every business that collects personal information to publish a clear, accessible and up-to-date privacy policy.
This policy must explain:
- The types of information collected
- The purposes for which it is used
- How it is collected and stored
- The protection measures in place
- The rights of the individuals concerned and how to exercise them
- The contact information of the person in charge of the protection of personal information (privacy officer)
The policy must be written in plain language and available on your website or, if you do not have one, provided through another easily accessible means.
For a small business
A small business can write its policy from a Law 25 compliant template, then adapt it to its own practices. It is recommended to:
- Keep the tone clear and avoid legal jargon
- Update the policy after every significant change
- Make sure it is easy to find (e.g. a link in the website footer)
Good to know
A privacy policy that is missing, incomplete or hard to find can lead to complaints to the Commission d'accès à l'information (CAI) and to penalties. It is often the first document that clients and authorities check.
Concrete examples
Example 1: A dental clinic writes a policy stating that it collects information such as name, date of birth and medical history in order to plan and provide care.
It specifies that this information is stored in secure software, accessible only to authorized staff, and that patients can exercise their rights by contacting the privacy officer whose contact information is provided.
Example 2: A freelance photographer publishes a simple policy on his website explaining that he collects names and emails through his contact form.
He specifies that this data is used only to respond to quote requests, that it is kept for 1 year and then deleted, and that anyone can request access to or deletion of their data by contacting him directly.
What the policy must cover at a minimum
The information collected and its purposes, the means of collection (forms, cookies, analytics tools), the people who have access to it, the retention period, the security measures, and individuals' rights: access, rectification, withdrawal of consent, with instructions on how to exercise them.
The title and contact information of the person in charge of the protection of personal information must appear in it. The policy must be easy to find: the standard is a link in the footer of every page of the site.
What a compliant privacy policy must cover
| Element | What to specify |
|---|---|
| Information collected | The categories of data: identity, contact details, browsing data, payment |
| Purposes of collection | Why each category is collected, in concrete terms |
| Means of collection | Forms, cookies, analytics tools, newsletter |
| Access and disclosure | Who accesses it internally and which third parties receive it (host, payment processor) |
| Retention | How long the data is kept and what happens to it afterwards |
| Security measures | The protections in place, described without exploitable details |
| Individuals' rights | Access, rectification, withdrawal of consent, and how to exercise them |
| Privacy officer contact information | The officer's title and how to reach them, as required by law |
Mistakes to avoid
- Copying and pasting a policy found online without adapting it
- Using overly complex or legalistic language
- Forgetting to include the privacy officer's contact information
- Not updating the policy after a change in practices
Step-by-step instructions
Checklist: Step 3 complete?
- My policy describes the information collected and how it is used
- Individuals' rights and how to exercise them are explained
- The privacy officer's contact information is included
- The policy is written in plain language
- The policy is published and easy to find
- I have a process to update it when needed
Templates included in the Law 25 Kit
- Law 25 Compliant Privacy Policy template
Your policy is written but not yet published on your website? RayV, the agency behind Kit Loi 25, publishes your policy, displays your privacy officer and sets up your cookie banner. Flat fee: $495.
See the implementation packageFrequently asked questions
Does my policy have to be written by a lawyer?
The law does not require it. A template properly adapted to your reality covers most small-business situations. A legal review is still recommended if you process sensitive data (health, finances) or large volumes.
How is it different from the governance policy?
The privacy policy is public facing: it tells visitors and clients what you do with their data. The governance policy is an internal document that governs your team's practices. The law requires both.
Does a brochure site without a form need a policy?
If it collects information through technological means, yes. And almost every site does: an analytics tool (Google Analytics), cookies, a contact button. In practice, the answer is almost always yes.
What does a business risk without a privacy policy?
It is a direct breach of section 8.2, subject to Law 25's administrative and penal penalties (in French). The most immediate risk remains a client complaint to the CAI, which triggers an inspection.