RES-04Printable list
Law 25 checklist for your website
16 items to tick: what your site must display, what it must ask, and what the business must manage. Detailed explanations are in the guide.
- Business
- ____________________________
- Website
- ____________________________
- Checked by
- ____________________________
- Date
- ____________________________
What the site must display
- AFF-01A person in charge of the protection of personal information is designatedBy default, this is the person with the highest authority in the business; the role can be delegated in writing. Their title and contact information are published on the website (s. 3.1).
- AFF-02A privacy policy is published on the websiteRequired when information is collected through technological means, such as a form. Written in clear and simple terms (s. 8.2). A visible link in the footer and next to every form is good practice.
- AFF-03The policy says what, why, how, and what your rights areInformation collected, purposes, means of collection, rights of access and rectification, right to withdraw consent, contact details of the person in charge, possible communication outside Québec, retention period.
- AFF-04Governance rules are summarized on the websiteThe business adopts policies and practices governing personal information (retention, destruction, roles, complaint handling) and publishes detailed information about them, in clear and simple terms, on its website (s. 3.2).
What the site must ask, and how
- DEM-01Every form explains why it collects the informationAt the time of collection, the person is told the purposes, the means, their rights of access and rectification and their right to withdraw consent (s. 8).
- DEM-02Only necessary information is requestedOnly what is necessary for the purposes determined before collection is collected (s. 5). A contact form usually doesn’t need a mailing address or a date of birth.
- DEM-03Consent is clear, free, informed and given for specific purposesRequested for each purpose in clear and simple terms and, in writing, presented separately from any other information (s. 14). According to the Commission’s guidance, a pre-ticked box or consent buried in the terms of use does not meet these criteria.
- DEM-04The newsletter has its own checkboxAnswering a request and sending marketing are two separate purposes: commercial prospecting cannot be considered a consistent purpose (s. 12). Two purposes, two consents. (Commercial messages are also governed by Canada’s anti-spam legislation.)
- DEM-05Functions that identify, locate or profile are disclosed and activated by the visitorIf the site uses technology that can identify, locate or profile a visitor (some advertising or analytics tools), it must inform them beforehand, along with the means to activate those functions (s. 8.1).
- DEM-06Third parties and communication outside Québec are disclosedWhere applicable, state the name of the third parties or categories of third parties the information is shared with (form tool, newsletter, host) and the possibility that it is communicated outside Québec (s. 8).
What the business must manage behind the scenes
- GER-01A register of confidentiality incidents is keptEvery incident is recorded (s. 3.8). If it presents a risk of serious injury, the Commission d’accès à l’information and the people concerned are notified promptly (s. 3.5).
- GER-02An assessment is done before sending information outside QuébecBefore communicating information outside Québec, for example to a host or cloud tool located elsewhere, a privacy impact assessment is carried out (s. 17).
- GER-03A retention period is set, then data is destroyedOnce the purpose is achieved, the information is destroyed or anonymized, subject to retention periods required by law (s. 23). Think of form messages piling up in an inbox.
- GER-04Access, rectification and portability requests have a procedureThe person in charge responds in writing within 30 days of receipt (s. 32). Since September 2024, a person can also request their information in a structured, commonly used technological format (s. 27).
- GER-05Providers that handle information have a written agreementEntrusting information to a provider (host, email tool, developer) requires a written contract specifying the protective measures (s. 18.3).
- GER-06Reasonable security measures protect the dataHTTPS site, access to messages limited to those who need it, strong passwords, updates applied: measures suited to the sensitivity of the information (s. 10).
References: Act respecting the protection of personal information in the private sector (CQLR, c. P-39.1); sections are cited in the guide. A checking tool, not legal advice. Fix ProTech — https://fix-protech.com/en/resources/law-25-printable-checklist/