Step 3 of 933%
3

Law 25 Privacy Policy: What the Law Requires (+ Template)

Create and publish a clear policy explaining how you handle personal information.

Estimated time: 1 hour
Updated July 30, 2026

The essentials

Since September 22, 2023, every business that collects personal information through technological means (website, online form, newsletter) must publish a privacy policy on its site, written in clear and simple language (s. 8.2, P-39.1 Act (in French)).

The policy must explain what data you collect, why, how, who has access to it, your protection measures and individuals' rights, along with the contact information of your privacy officer.

It is the most visible compliance gap: anyone, client or CAI inspector, can check in 30 seconds whether your site has one.

What the law says

Law 25 requires every business that collects personal information to publish a clear, accessible and up-to-date privacy policy.

This policy must explain:

  • The types of information collected
  • The purposes for which it is used
  • How it is collected and stored
  • The protection measures in place
  • The rights of the individuals concerned and how to exercise them
  • The contact information of the person in charge of the protection of personal information (privacy officer)

The policy must be written in plain language and available on your website or, if you do not have one, provided through another easily accessible means.

For a small business

A small business can write its policy from a Law 25 compliant template, then adapt it to its own practices. It is recommended to:

  • Keep the tone clear and avoid legal jargon
  • Update the policy after every significant change
  • Make sure it is easy to find (e.g. a link in the website footer)

Good to know

A privacy policy that is missing, incomplete or hard to find can lead to complaints to the Commission d'accès à l'information (CAI) and to penalties. It is often the first document that clients and authorities check.

Concrete examples

Example 1: A dental clinic writes a policy stating that it collects information such as name, date of birth and medical history in order to plan and provide care.

It specifies that this information is stored in secure software, accessible only to authorized staff, and that patients can exercise their rights by contacting the privacy officer whose contact information is provided.

Example 2: A freelance photographer publishes a simple policy on his website explaining that he collects names and emails through his contact form.

He specifies that this data is used only to respond to quote requests, that it is kept for 1 year and then deleted, and that anyone can request access to or deletion of their data by contacting him directly.

What the policy must cover at a minimum

The information collected and its purposes, the means of collection (forms, cookies, analytics tools), the people who have access to it, the retention period, the security measures, and individuals' rights: access, rectification, withdrawal of consent, with instructions on how to exercise them.

The title and contact information of the person in charge of the protection of personal information must appear in it. The policy must be easy to find: the standard is a link in the footer of every page of the site.

What a compliant privacy policy must cover

ElementWhat to specify
Information collectedThe categories of data: identity, contact details, browsing data, payment
Purposes of collectionWhy each category is collected, in concrete terms
Means of collectionForms, cookies, analytics tools, newsletter
Access and disclosureWho accesses it internally and which third parties receive it (host, payment processor)
RetentionHow long the data is kept and what happens to it afterwards
Security measuresThe protections in place, described without exploitable details
Individuals' rightsAccess, rectification, withdrawal of consent, and how to exercise them
Privacy officer contact informationThe officer's title and how to reach them, as required by law

Mistakes to avoid

  • Copying and pasting a policy found online without adapting it
  • Using overly complex or legalistic language
  • Forgetting to include the privacy officer's contact information
  • Not updating the policy after a change in practices

Step-by-step instructions

1
List the information collected and its purpose
2
Describe how the information is collected, used, stored and protected
3
State individuals' rights and how they can exercise them
4
Include the privacy officer's full contact information
5
Format the policy and publish it on your website
6
Keep an internal copy and archive each updated version

Checklist: Step 3 complete?

  • My policy describes the information collected and how it is used
  • Individuals' rights and how to exercise them are explained
  • The privacy officer's contact information is included
  • The policy is written in plain language
  • The policy is published and easy to find
  • I have a process to update it when needed

Templates included in the Law 25 Kit

  • Law 25 Compliant Privacy Policy template
Get these templates

Your policy is written but not yet published on your website? RayV, the agency behind Kit Loi 25, publishes your policy, displays your privacy officer and sets up your cookie banner. Flat fee: $495.

See the implementation package

Frequently asked questions

Does my policy have to be written by a lawyer?

The law does not require it. A template properly adapted to your reality covers most small-business situations. A legal review is still recommended if you process sensitive data (health, finances) or large volumes.

How is it different from the governance policy?

The privacy policy is public facing: it tells visitors and clients what you do with their data. The governance policy is an internal document that governs your team's practices. The law requires both.

Does a brochure site without a form need a policy?

If it collects information through technological means, yes. And almost every site does: an analytics tool (Google Analytics), cookies, a contact button. In practice, the answer is almost always yes.

What does a business risk without a privacy policy?

It is a direct breach of section 8.2, subject to Law 25's administrative and penal penalties (in French). The most immediate risk remains a client complaint to the CAI, which triggers an inspection.