A privacy policy describes intended practices. A technical audit observes what the website actually does. Quebec organizations need both views because cookies, forms, analytics, embedded media and vendor scripts can change without the policy changing with them.
This checklist supports technical and documentary review under Quebec’s private-sector privacy framework. It is general information, not a legal conclusion about a particular organization.
Map personal information before reviewing the banner
Inventory every collection point: contact and newsletter forms, account creation, analytics events, scheduling tools, payment providers, chat widgets, video embeds and server logs. Record the data, purpose, recipient, retention path and system owner.
The exercise should include information collected indirectly by third-party scripts. A field-free page may still disclose an identifier, IP address or device information to an external service.
Verify consent behaviour technically
Where consent is the applicable basis, confirm that optional technologies do not load before the visitor’s choice. Test accept, refuse and granular preference paths in a clean browser session. Verify that the decision persists for the stated period and can be changed later.
| Control | What to test | Evidence to retain |
|---|---|---|
| Initial state | Optional tags before a choice | Network and storage capture |
| Refusal | Behaviour after “refuse” | Requests, cookies and local storage |
| Acceptance | Only selected purposes activate | Consent record and tag sequence |
| Withdrawal | Preferences can be reopened | User path and resulting deletion/blocking |
| Documentation | Notice matches real tools | Vendor inventory and policy version |
A banner that merely says “By continuing, you accept” does not demonstrate that choices control the underlying scripts.
Make purposes understandable
Form notices and consent interfaces should explain why information is requested in language appropriate to the context. Avoid bundling unrelated purposes into a vague statement. Collect only fields needed for the stated task, and identify mandatory versus optional information where relevant.
Review validation errors, confirmation pages and automated emails as part of the same journey. Privacy information hidden on a separate legal page may not provide the contextual transparency a visitor needs when submitting data.
Reconcile vendors with public documentation
For every processor or embedded service, document what it receives, the configured purpose, relevant retention settings and where the data may be handled. Compare that record with the privacy and cookie notices.
Remove dormant tags and duplicate trackers. They add privacy exposure, performance cost and audit uncertainty without delivering value.
Respect language access in the privacy journey
On a bilingual Quebec site, the French experience should not break when the visitor reaches consent controls, form errors, vendor widgets or privacy rights instructions. The English version should be an accurate, useful adaptation rather than an outdated copy.
Use consistent version dates and identify which text governs if the organization needs such a clause. Legal review should determine the appropriate formulation.
Build an auditable operating process
Privacy compliance is not a one-time banner installation. Establish an owner, review cadence and change trigger. A new marketing tag, form field or vendor should require an update to the inventory before deployment.
Keep dated evidence of scans, manual tests, policy versions, consent configuration and remediation decisions. Do not publish claims such as “100% Law 25 compliant,” “certified” or “legal compliance guaranteed.” Technical controls reduce gaps; final legal validation remains a separate responsibility.
A practical remediation order
- Stop unexpected or unjustified optional collection.
- Repair consent so the choice controls script execution.
- Minimize forms and secure their transmission.
- Remove unused vendors and stale data paths.
- Align privacy and cookie notices with the inventory.
- Verify French and English end-to-end journeys.
- Obtain legal review for unresolved interpretations.
- Repeat after material releases and vendor changes.
Sources
- Commission d’accès à l’information du Québec
- Act respecting the protection of personal information in the private sector, CQLR c P-39.1
- Office québécois de la langue française
This article is a technical audit resource and does not replace legal advice based on the organization’s specific facts.
FAQ
Is a cookie banner enough to address Law 25 requirements?
No. Optional scripts must also remain blocked before a choice, withdrawal must work in practice, and public documentation should match the processing observed on the site.
What should a technical audit review first?
Start with an inventory of scripts, forms, vendors and transmitted data. Then verify purpose-specific consent, minimization, retention settings and the complete withdrawal journey.
Can a technical audit certify legal compliance?
No. It can document observable controls and gaps. A legal conclusion depends on the organization’s specific circumstances and separate professional review.