Skip to main content

Transparency, on purpose

How the label is calculated

Nothing here is a black box. The label is a direct rendering of the privacy policy grader's11 checks: each check becomes one row, and the weighted score becomes the letter grade. Same checks, same weights, no extra judgment.

The pipeline

  1. 1Check

    The policy text is scanned for bilingual (English/French) keywords and patterns across 11 checks mapped to Law 25 and PIPEDA expectations. Each check returns pass, partial, or missing.

  2. 2Score

    Each check carries a weight (accountability and rights weigh most). Pass earns full weight, partial earns half, missing earns none. The total is scaled to 0–100.

  3. 3Render

    Each check becomes one row on the card with a plain-language value (e.g. “Named, with contact”, “Browsewrap only”, “Not stated”). The score becomes the letter grade. Everything happens in your browser.

Check → row mapping

The weight column shows each check's influence on the score. A dash means that check never returns that status — for example, “purposes of collection” is either stated or not.

CheckLabel rowWeightPassPartialMissing
Privacy officer named, with contactPrivacy officerNamed, with contactNamed, no contactNot stated
Purposes of collection statedPurposes of collection1.5×StatedNot stated
Individual rights mentionedYour rights1.5×Access, correction, deletionSome rights listedNot stated
Retention periods statedRetention limitsStatedMentioned onlyNot stated
Cross-border transfer disclosureData leaving Québec/CanadaDisclosedVagueNot disclosed
Consent languageConsent basisStatedBrowsewrap onlyNot stated
Breach / confidentiality incident mentionBreach notificationAddressedMentioned, no notification detailNot stated
Children's data addressedChildren's data0.75×AddressedNot addressed
Automated decision-making disclosedAutomated decisions0.75×DisclosedNot disclosed
Last-updated date present and recentLast updatedDated, recentUnclearNot dated
Complaint path to the regulatorComplaint pathCAI / OPC namedNo regulator namedNot stated

Score → grade bands

GradeScoreWhat it signals
A+97–100Exceptional. The policy reads as though it went through serious Law 25 work.
A93–96Excellent. Core expectations covered with, at most, minor gaps.
A−90–92Strong. A couple of soft spots worth a second look.
B+87–89Good. Solid foundations with a few fixable gaps.
B83–86Above average. Noticeable gaps, none fatal on its own.
B−80–82Decent. Several checks came back partial or missing.
C+77–79Fair. Roughly a quarter of the expectations look unmet.
C73–76Mediocre. A Law 25-sized gap or two is likely.
C−70–72Weak. Multiple core expectations missing.
D+67–69Poor. The policy reads as incomplete.
D63–66Very poor. Most of what regulators look for is absent.
D−60–62Failing. Little more than a placeholder policy.
FBelow 60Failing. Major Law 25 and PIPEDA expectations look absent.

What the label cannot tell you

The checks read words. They cannot verify practices: whether consent was truly informed, whether data is really deleted on schedule, whether the PIA for a cross-border transfer exists, how vendors handle data, or whether the policy matches what the company actually does. Keyword matching can also miss well-written policies that use unusual phrasing — a missing row is a question, not a verdict.

That is why every card carries the line “Heuristic grade, not legal advice.”Treat labels as a starting point for diligence and conversation — for procurement shortlists, for customer trust, for deciding which policy deserves a closer read — never as a compliance conclusion.

If a label surfaces gaps worth closing properly, you're welcome to send me a note — I help Canadian teams turn policies like these into programs that hold up.