What Law 25 requires in a privacy policy, a full template a Quebec SMB can adapt, and a worked example section by section.

Search for "privacy policy template" and you will find dozens of free models to copy and paste. Most were written for the European GDPR, often for French websites. Dropped as-is onto a Quebec SMB's site, they produce a document that looks compliant and isn't. As our summary of Law 25 obligations for SMBs shows, Quebec's law follows its own logic, and the privacy policy is where that shows most visibly.
Since September 22, 2023, publishing a privacy policy has been a legal obligation the moment your business collects personal information through technological means. A contact form qualifies. So does a customer service email address.
This article walks through what the law requires you to disclose, offers a structure and then a full template to adapt, section by section, and clarifies the distinction most SMBs miss: the policy published on your site is not the only document the law demands.
Since September 22, 2023, any business that collects personal information through technological means (a website, a form, an email address) must publish a privacy policy written in simple and clear terms: that is section 8.2 of Quebec's Act respecting the protection of personal information in the private sector, as amended by Law 25. The policy must cover what section 8 requires you to disclose: the purposes of collection, the means used, the rights of access and rectification, the right to withdraw consent, the third parties who receive the information, and the possibility that it may be communicated outside Quebec. Add the title and contact information of your person in charge of the protection of personal information (section 3.1) and, if the site uses identification, geolocation or profiling technologies, the disclosures required by section 8.1, with those functions turned off by default. This public document is distinct from the internal governance policies required by section 3.2.
The requirement comes from section 8.2 of the Act: anyone collecting personal information through technological means must publish a privacy policy on their website, written "in simple and clear terms", and give notice of every change to it. The explanatory guide from Quebec's privacy regulator, the Commission d'accès à l'information (CAI), published in December 2023, lists a website, an app, or simply an email address as qualifying technological means.
The penalty ceilings are oversized for an SMB: up to $10 million or 2% of worldwide turnover in administrative monetary penalties (section 90.12), up to $25 million or 4% under the penal regime (section 91). Nobody will levy those amounts on a twelve-person company. But failing to inform people as section 8 requires is explicitly on the list of sanctionable defaults (section 90.1), and it is the easiest one to spot: a regulator only has to visit your site.
The law actually requires two distinct things, and nearly every free template conflates them.
The first, in section 3.2, is the "governance policies and practices": an internal framework covering the rules for retaining and destroying personal information, the roles and responsibilities of your staff throughout the information's life cycle, and a process for handling complaints. This framework must be approved by your privacy officer, be proportionate to your activities, and detailed information about it must also be published on your website.
The second, in section 8.2, is the privacy policy itself: the public document that tells your visitors what you collect and why.
The CAI's guide devotes a full section to keeping these apart. The privacy policy speaks to your visitors; the governance policies frame your internal practices, including what your employees do with personal information, right down to the AI tools they sometimes use without telling you. A template that merges the two, or ignores the second, satisfies neither obligation properly.
Section 8 sets the list: the purposes of collection, the means used, the rights of access and rectification, the right to withdraw consent and, where applicable, the third parties for whom the information is collected or to whom it is communicated, and the possibility that it may be communicated outside Quebec.
On that last point, a very Quebec-specific detail: "outside Quebec" includes the rest of Canada. A cloud provider with servers in Ontario triggers section 17, which requires a privacy impact assessment before the information leaves the province.
Section 8 has a second list, to be provided "on request": the personal information collected, the categories of people who have access to it within the business, how long it is kept, and the privacy officer's contact information. The CAI's guide suggests including these up front, and the math is simple: answering those requests one at a time costs more than publishing once.
Section 3.1 has also required, since September 2022, that the title and contact information of your person in charge of the protection of personal information appear on your website. By default, that person is the highest authority in the business: in an SMB, the president, unless the role is delegated in writing.
Finally, if one of your tools makes decisions based exclusively on automated processing (a credit score, resume screening, some AI agents), section 12.1 obliges you to inform the person no later than the moment of the decision; the policy is the natural place to announce it.
Section 8.1 targets technologies with functions that can identify a person, locate them, or profile them. If your site uses any, you must inform people beforehand, along with the means available to activate those functions. The CAI's guide is explicit: they must be deactivated by default.
Quebec's logic is therefore not the European cookie banner's. The GDPR reasons in terms of prior consent to placing cookies; the Quebec law reasons in terms of activation: profiling functions stay off until the person turns them on. A curious detail: section 9.1, which imposes maximum privacy by default on technological products, expressly excludes cookies; section 8.1 does not. The practical consequence: an analytics tool that identifies or profiles visitors needs an activation mechanism and a clear mention in the policy. A tool that identifies, locates and profiles no one falls outside section 8.1. That is a serious argument for cookieless analytics, which is what we install by default for our clients.
Even a well-drafted GDPR template fails in Quebec on at least four specific points.
Legitimate interest does not exist here. European templates justify half their processing with that GDPR legal basis, which has no equivalent in the Quebec statute: the regime rests on consent plus narrow statutory exceptions. Every paragraph invoking legitimate interest describes processing whose legal basis remains to be established.
The geography is wrong. "Outside the EU" corresponds to nothing in section 17; the Quebec threshold is crossed at the Ottawa River, Toronto included.
The DPO is not the privacy officer. The GDPR requires a data protection officer only in specific cases; the Quebec law designates the business's highest authority by default and requires their title and contact information to be published.
The recourse is not the CNIL. A compliant policy points to your internal complaint process, the one section 3.2 obliges you to have, and to the Commission d'accès à l'information, not to a French authority.
Add data portability, in force in Quebec since September 22, 2024 and limited to information collected from the person (not information created or inferred about them), and the conclusion is hard to avoid: seriously adapting a GDPR template is more work than writing a Quebec policy from the right structure.
Here is the structure we use, aligned with section 8 and the CAI's guide.
1. Who we are. Business name, the policy's effective date, the date of the last update.
2. How we collect your information. Forms, email, newsletter, cookies; third parties collecting on your behalf (payments, newsletter provider).
3. What we collect, and why. Categories of information and the matching purposes; the options for refusing certain collection and their consequences.
4. Tracking technologies. Cookies and analytics tools; profiling functions if any, off by default, with how to activate them.
5. Who has access. Internal categories of staff; third-party recipients; whether information may be communicated outside Quebec.
6. Retention and security. Retention periods; a brief description of security measures.
7. Your rights. Access, rectification, withdrawal of consent, portability, complaints through your internal process, with the CAI as recourse.
8. Privacy officer. Title and contact information.
9. Changes. How updates will be announced, the notice being required by section 8.2.
It is a structure, not text to copy: each section must describe your actual practices. A policy that promises practices you don't have is worse than no policy at all, because it documents the gap. The next section gives the text that fills out this structure.
What follows is a complete template written for an ordinary Quebec SMB: a brochure site with a contact form, a newsletter, sometimes a shop. The CAI publishes no official template for the private sector, and its guide explains why: a regulation sets the required content for public bodies' policies, and no equivalent regulation exists for businesses. Its explanatory guide, "Rédiger une politique de confidentialité", published in December 2023, downloadable from cai.gouv.qc.ca and available in French only, therefore describes suggested content rather than imposed wording. The template below follows that guide and the statute.
How to use it: replace each bracket with your own information, delete the sections that describe nothing you actually do, add the ones that are missing, then reread every sentence asking whether it matches your practices. Under each heading, an italic line says what to check or adjust.
[Business name] operates the website [site address] and provides [one-sentence description of your products or services]. This policy explains what personal information we collect through technological means, for what purposes, who has access to it, how long we keep it, and what rights you can exercise. It has been in effect since [effective date] and was last updated on [last update date].
What to adapt: both dates are asked for by the CAI's guide, and they are the first thing a visitor checks. If you run several sites or an app, name them all here.
We collect personal information when you fill in the contact form on our site, when you write to us at [business email address], when you subscribe to our newsletter, and when you browse the site, through the cookies described below. [Add your other collection points: account creation, online orders, appointment booking, video surveillance, connected devices.] Some of this information is collected on our behalf by service providers: [newsletter service], [payment platform] and [hosting provider].
What to adapt: inventory before you write this section. Section 8 requires you to state the means of collection, and the CAI's guide asks you to name the third parties collecting for you. A tool left out here becomes a documented gap.
We collect identifying information (name, email address, phone number, and [postal address] if you place an order) in order to answer your requests, deliver our services and handle billing. We collect technical information (IP address, connection date and time, pages visited) in order to keep the site secure and measure its traffic. We collect [other category] in order to [matching purpose]. You can decline to give us certain information: [describe the options, for example calling us instead of using the form, or ordering without creating an account]; in that case, [consequence, for example we will not be able to keep a history of your orders].
What to adapt: one purpose per category, in plain language. "Improve your experience" means nothing to anyone; "send you an appointment reminder" does. The options for refusing and their consequences are asked for by the CAI's guide.
Our site uses cookies necessary for it to work, plus [describe your other cookies]. [If your tool identifies, locates or profiles visitors:] We use [tool name], which includes functions that can identify you, locate you or build a profile of you. Those functions are off by default. You can turn them on [describe the means offered, for example the preferences panel at the bottom of every page] and turn them off again the same way at any time. [If that is not the case:] Our analytics tool, [tool name], has no function that can identify you, locate you or build a profile of you.
What to adapt: this is section 8.1, and it is where European templates go wrong most often. Keep whichever wording matches your tool and delete the other. If you offer a technological product or service with privacy settings, add a sentence confirming they are set to the highest level by default, as section 9.1 requires.
Internally, your information is accessible to the people who need it for their work: [categories, for example the customer service team, the person handling billing, management]. Externally, we share some information with [provider name] for [purpose], and with [provider name] for [purpose]. We do not sell your personal information and we do not disclose it to anyone else without your consent, except where the law permits or requires us to.
What to adapt: name categories of people, not individuals. The list of third-party recipients is required by the second paragraph of section 8. Keep the last sentence only if it is true.
Some of our providers store or process information outside Quebec: [provider name, province or country]. Before communicating personal information outside Quebec, we carry out a privacy impact assessment and enter into the written agreement the law requires with the provider.
What to adapt: a reminder worth keeping, "outside Quebec" includes Ontario and the rest of Canada. Only promise the section 17 assessment if you have actually done it; if not, do it before you publish.
We keep your personal information for as long as it is needed for the purposes described above: [period or criterion, for example seven years for accounting records, three years after last contact for information requests, until unsubscribe for the newsletter]. Once those purposes are fulfilled and no law requires us to keep it longer, we destroy or anonymize it. We take reasonable security measures to protect it: [for example password-protected access with two-factor authentication, encrypted transmission, locked premises, staff training].
What to adapt: section 23 requires destruction or anonymization once the purposes are fulfilled, and section 10 requires reasonable security measures. A real retention period beats an unqualified "as long as necessary".
[If this applies to you:] Some decisions about you are made exclusively by automated processing, with no human involvement: [describe, for example the automatic approval of a financing request]. We inform you of this no later than the moment we tell you the decision. On request, we will tell you what personal information was used, the reasons and the main factors that led to the decision, and your right to have that information corrected. You can submit your observations to a member of our staff able to review the decision, by writing to [privacy officer's email address].
What to adapt: this is section 12.1. Delete the section if nothing you do is a fully automated decision. Automated resume screening or a score assigned by an AI agent counts.
You have the right to access the personal information we hold about you and to obtain a copy of it. You have the right to have it corrected if it is inaccurate, incomplete or ambiguous. You can withdraw at any time the consent you gave us for its use or disclosure. You can also ask us to give you, in a structured and commonly used technological format, the computerized information we collected from you. To exercise any of these rights, write to [privacy officer's email address] or to [postal address]. We must be able to verify your identity. We reply in writing within 30 days of receiving the request, and access is free of charge.
What to adapt: the 30-day deadline and the free access come from sections 32 and 33, access and rectification from sections 27 and 28. The portability right, in the third paragraph of section 27, covers only information collected from the person, not information you created or inferred about them. Mention any technological means you offer here, such as a client area where people correct their own contact details.
The person in charge of the protection of personal information at [Business name] is [the person's title, for example the president], reachable at [privacy officer's email address] or at [phone number]. If you are unhappy with how we handle your personal information, you can complain to that person: [describe your process briefly, for example acknowledgment within five business days and a reasoned answer within 30 days]. You can also contact Quebec's Commission d'accès à l'information.
What to adapt: section 3.1 requires the officer's title and contact information to be published on your site. The complaint process described here must be the one in your internal governance policies (section 3.2); announcing a process that does not exist is the most common trap. The same section also obliges you to publish detailed information about those policies.
We may change this policy. Any change is announced [describe the means, for example a notice on the home page for 30 days and an email to newsletter subscribers], and the update date shown above is revised accordingly.
What to adapt: notice of changes is required by section 8.2 just as the policy itself is. Pick a means you will actually use.
This template covers the public document, and only that. It replaces neither the governance policies of section 3.2 nor the privacy impact assessment section 17 requires before any communication outside Quebec. To check that nothing is missing at the level of the business as a whole, the CAI also publishes a checklist of business responsibilities, dated February 8, 2023, covering the obligations that came into force in 2022, 2023 and 2024. And all of this remains a plain-language rendering: where there is doubt, the CAI's guide and the text of the Act prevail.
The work comes down to three steps: inventory what your site actually collects (every form, every third-party tool, every cookie), write the policy from the skeleton above, then put your internal governance policies in writing so the complaint process you announce actually exists. For a simple site, that is a few days of work, not a few months.
If you would rather hand off the inventory, it is something we do regularly for our clients, alongside redesigning or maintaining their site.
This article explains legal obligations in plain language to help an SMB ask the right questions; it is not legal advice. The text of the Act respecting the protection of personal information in the private sector and the positions of the Commission d'accès à l'information prevail: for a specific situation, consult a lawyer.
Written by