Free heuristic tool
How strong is your privacy policy?
Paste a policy and I'll run 11 plain-language checks against Law 25 and PIPEDA expectations, then score it in seconds. Nothing you paste ever leaves your browser.
A quick disclaimer from me: this is an educational smell-test, not legal advice and not a compliance audit. Law 25 and PIPEDA have requirements no automated keyword check can assess — whether your actual practices match the words, whether consent was truly informed, how your vendors handle data, and more. Read the results as questions to explore, not conclusions.
Grade a privacy policy
Everything runs in your browser \u2014 the text never leaves your device.
If the fetch fails, paste the text instead \u2014 it always works.
Here's what I check
Each check looks for bilingual (English/French) keywords and patterns, weighted by how heavily Law 25 and PIPEDA lean on them. The privacy officer and individual rights carry the most weight; everything is scored out of 100.
01Privacy officer named, with contact
Accountability starts with a person — Law 25 expects one designated.
02Purposes of collection stated
People must know why you're collecting their information.
03Individual rights mentioned
Access, correction, deletion, and withdrawing consent.
04Retention periods stated
How long data is kept — and what happens when it isn't needed.
05Cross-border transfer disclosure
Law 25's s. 17 territory: data leaving Québec needs a PIA and notice.
06Consent language
Valid consent is informed and specific — not just browsewrap.
07Breach / confidentiality incident mention
Serious-harm incidents trigger CAI and individual notification.
08Children's data addressed
Under-14 information gets heightened protection under Law 25.
09Automated decision-making disclosed
Law 25 s. 8.5 covers exclusively automated decisions.
10Last-updated date present and recent
A stale policy erodes trust — and may not reflect current practice.
11Complaint path to the regulator
People should know they can complain to the CAI or the OPC.
What the score can't tell you
A perfect score means the policy says the right things. Regulators — and customers — care just as much about what you actually do: whether consent was truly informed, whether data is really deleted on schedule, whether the PIA for that cross-border transfer exists. No automated tool can verify that.
If the gaps look worth closing properly, you're welcome to send me a note — I help Canadian teams turn policies like these into programs that hold up.
Make the score shareable.
Turn this result into a privacy nutrition label — a one-glance grade card you can publish on your site or share with stakeholders.
Generate a nutrition label →