In 2023, a lot of Quebec small businesses added a privacy policy to their website and ticked the Law 25 box. It's also a page we add by default to the websites we build. The follow-up question rarely comes up: where is the other document?
The other document is the privacy governance policy. The law has required it since September 22, 2023, but it isn't written for your site's visitors: it tells your team who opens and closes access, when a file has to be erased and where to send an unhappy customer. Our article on the privacy policy and its template covers the public document. This one covers the internal one, section by section, for a ten-person business.
The short answer, for the busy
A privacy governance policy is an internal document required by section 3.2 of Quebec's Act respecting the protection of personal information in the private sector, in force since September 22, 2023. At a minimum, it must provide a framework for keeping and destroying personal information, define the roles and responsibilities of staff throughout the information's life cycle, and set out a process for handling privacy complaints. It must be proportionate to the nature and scope of the business's activities and approved by the person in charge of the protection of personal information. Detailed information about it must be published on the business's website in simple and clear language. It does not replace the confidentiality policy required by section 8.2, which tells visitors what the site collects and why. The two depend on each other: the public policy points to a complaint process that the governance policy has to actually define.
Two sections, two readers
In everyday speech, "privacy policy" and "personal information protection policy" mean the same thing. In the law, they are two separate obligations.
Section 8.2 applies to any business that collects personal information through technological means: it must publish on its website "a confidentiality policy drafted in clear and simple language." Its reader is the person filling in your form.
Section 3.2 applies to anyone carrying on an enterprise, website or not. It requires "governance policies and practices regarding personal information." Its reader is, first of all, your team. The Commission d'accès à l'information (CAI) makes the same point in its guide to writing a privacy policy: the governance policy is aimed first at your own organization, because it frames your activities, while still concerning the people whose information you collect.
According to the same guide, your privacy policy should tell people they can file a complaint under the process set out in your governance policies and practices. So the public document promises a process that only the internal document defines. The day an unhappy customer follows that reference, they go looking for a procedure nobody in the business ever wrote down.
What section 3.2 requires, word for word
The first paragraph of section 3.2 sets three minimum contents. The policies and practices must "in particular, provide a framework for the keeping and destruction of the information, define the roles and responsibilities of the members of its personnel throughout the life cycle of the information and provide a process for dealing with complaints regarding the protection of the information." They must also "be proportionate to the nature and scope of the enterprise's activities and be approved by the person in charge of the protection of personal information."
The second paragraph adds publication: "Detailed information about those policies and practices, in particular as concerns the content required under the first paragraph, must be published in simple and clear language on the enterprise's website," or by other appropriate means if there is no website.
"In particular" makes the list a floor. "Practices" means paper isn't enough: the law asks you to establish the policies and implement them. "Proportionate" spares a ten-person business from copying a bank's framework.
There is no official template: among the guides and fact sheets the CAI publishes, none covers the governance policy. You write from the text of the section.
The document, section by section
For a small business, the document runs a few pages.
Purpose and scope. Which information the policy covers (customers, employees, job applicants), in what formats, and who it applies to. The CAI extends its own policy to interns, contractors and information held for it by a third party. For a small business, that last point is most of the job: the accounting software, the CRM, the newsletter tool.
The inventory. In its checklist for businesses, the CAI lists an inventory of the personal information held by the business, or on its behalf by a third party, as the first task needed to establish these policies, and asks that it be kept up to date. An appendix is enough: each category of information, where it lives, who can see it.
Roles and responsibilities. The heart of the document. It first names the person in charge of the protection of personal information: by default the person with the highest authority in the business, who can delegate the function in writing (section 3.1). It then says who grants and removes access, who receives access and correction requests (the person in charge, who has 30 days to respond, per the CAI), who reports an incident and to whom, and each employee's commitment to access only the information their work requires. Vendors belong here too: section 18.3 requires a written contract with any service provider you entrust with personal information, and obliges the provider to notify your person in charge without delay of any breach.
Keeping and destruction. For each inventory category, a retention period or a triggering event, then the destruction method. The law sets no retention periods: section 23 requires you to destroy or anonymize information once the purposes of its collection are achieved, subject to a retention period set by another statute. This section points to your retention schedule and names who maintains it; tax minimums and backups are covered in our article on data retention under Law 25.
Complaints. Who receives a complaint, by what means, how fast you acknowledge and respond, and the right to go to the CAI. Section 3.2 sets no deadlines: whatever you choose, you'll have to meet. This is the section your privacy policy refers to, so it's the one whose absence shows first.
Confidentiality incidents. Section 3.2 doesn't name them, but section 3.8 requires an incident register, whose content is set by the Regulation respecting confidentiality incidents, along with a minimum of five years' retention for each entry. The policy says who keeps the incident register and points to the incident response procedure.
Adoption and review. The date the person in charge approved it, and a review cycle. The CAI reviews its own policy every three years, or sooner if circumstances warrant. Add a concrete trigger: a new tool that handles personal information.
Proportionate, in practice
The CAI's own governance policy, dated September 11, 2024, runs 13 pages and spreads responsibilities across eight roles, including a committee and a working group. It's a good example of structure and a poor example of scale: the CAI is a public body, governed by a different statute.
In a ten-person business, those eight roles shrink to three: the owner or manager (the person in charge by default), whoever manages accounts and tools, and the rest of the team. The CAI's January 2026 guide on preventing incidents does list a committee among its examples of governance measures, but nothing in section 3.2 requires one. At this size, the committee is an item on the management meeting agenda.
Proportionality is measured against the nature and scope of your activities, not just headcount. An eight-person recruitment agency holding résumés, references and background checks justifies a tighter policy than a thirty-employee contractor whose only personal information is invoices and contact details.
What has to appear on your website
The law doesn't require you to publish the internal document as is. The CAI's guide puts it plainly: you may make the governance policy public, and you must at least publish detailed information about your practices.
Two options hold up: publish the full policy, if it's written in simple and clear language, or publish a summary page covering the three required contents (your keeping and destruction rules, who does what in the business, how to file a complaint). That page sits next to the privacy policy, with links both ways, and shows the title and contact information of the person in charge, which section 3.1 requires you to publish.
One formal caution: the CAI notes that your terms of use may refer to these policies but must not be merged with them. Keep separate pages, linked to each other.
The thread that ties it together
The governance policy holds the other documents together. The person in charge approves it. The retention schedule is its appendix, the incident register and response procedure flow from it, and the privacy policy refers to its complaint process. Employee training is what turns written roles into known roles.
On penalties, a detail worth reading closely: section 3.2 itself is not on the list of failures that can draw an administrative monetary penalty under section 90.1. That doesn't make it optional: after an inquiry, the CAI can order any corrective measure (section 83), and failing to comply with an order is a penal offence (section 91, paragraph 10). Keeping or destroying personal information in contravention of the Act, however, is on it (paragraph 2), and among the penal offences in section 91. Without written retention rules, that is the failure you're most likely to commit.
Where to start
Do the inventory, then write the three required sections: roles, retention, complaints. Have your person in charge approve the whole thing, date it, and publish the summary page. Then reread your privacy policy: the complaint process it announces has to be the one you just wrote.
The policy is yours: you write it and you approve it. The visible part, the pages on your site and the links between them, is part of our web services.
→ Let's talk about your website
This article explains legal obligations to help a small business ask the right questions; it is not legal advice. The text of the Act respecting the protection of personal information in the private sector, the Regulation respecting confidentiality incidents and the positions of the Commission d'accès à l'information govern: for a specific situation, consult a lawyer.
