Skip to main content

Free heuristic tool

How strong is your privacy policy?

Paste a policy and I'll run 11 plain-language checks against Law 25 and PIPEDA expectations, then score it in seconds. Nothing you paste ever leaves your browser.

A quick disclaimer from me: this is an educational smell-test, not legal advice and not a compliance audit. Law 25 and PIPEDA have requirements no automated keyword check can assess — whether your actual practices match the words, whether consent was truly informed, how your vendors handle data, and more. Read the results as questions to explore, not conclusions.

Grade a privacy policy

Everything runs in your browser \u2014 the text never leaves your device.

If the fetch fails, paste the text instead \u2014 it always works.

Here's what I check

Each check looks for bilingual (English/French) keywords and patterns, weighted by how heavily Law 25 and PIPEDA lean on them. The privacy officer and individual rights carry the most weight; everything is scored out of 100.

  1. 01Privacy officer named, with contact

    Accountability starts with a person — Law 25 expects one designated.

  2. 02Purposes of collection stated

    People must know why you're collecting their information.

  3. 03Individual rights mentioned

    Access, correction, deletion, and withdrawing consent.

  4. 04Retention periods stated

    How long data is kept — and what happens when it isn't needed.

  5. 05Cross-border transfer disclosure

    Law 25's s. 17 territory: data leaving Québec needs a PIA and notice.

  6. 06Consent language

    Valid consent is informed and specific — not just browsewrap.

  7. 07Breach / confidentiality incident mention

    Serious-harm incidents trigger CAI and individual notification.

  8. 08Children's data addressed

    Under-14 information gets heightened protection under Law 25.

  9. 09Automated decision-making disclosed

    Law 25 s. 8.5 covers exclusively automated decisions.

  10. 10Last-updated date present and recent

    A stale policy erodes trust — and may not reflect current practice.

  11. 11Complaint path to the regulator

    People should know they can complain to the CAI or the OPC.

What the score can't tell you

A perfect score means the policy says the right things. Regulators — and customers — care just as much about what you actually do: whether consent was truly informed, whether data is really deleted on schedule, whether the PIA for that cross-border transfer exists. No automated tool can verify that.

If the gaps look worth closing properly, you're welcome to send me a note — I help Canadian teams turn policies like these into programs that hold up.

Make the score shareable.

Turn this result into a privacy nutrition label — a one-glance grade card you can publish on your site or share with stakeholders.

Generate a nutrition label →