Privacy Protection and Plain Language: 3 Things to Know
The privacy regulations that Quebec and Canada are set to adopt may require you to completely revise the content of your privacy policy. Are you ready? Here are three key points for a successful transition.
1. You will be required to produce texts in clear and simple language
Based on current legislation, a lack of clarity could result in heavy fines. Beyond the penalties provided for, a lack of transparency regarding privacy protection can damage your organization’s reputation. Your communications must therefore accurately reflect your practices.
Which organizations are involved?
Whether you are a public or private entity, subject to federal or provincial regulations, the principles of plain language information design are essentially the same.
Your Privacy Policy is likely your most important communication tool in this regard, and the one on which you should focus your efforts. But your obligation to use clear and simple language isn’t limited to that. Consider, for example, the notices, consent forms, or emails you produce. All of these communications must be written in clear and simple language.
Clear and simple for whom?
At the federal level, the suggested best practices already state that you must: “explain your practices in a way that the average user visiting your site can understand.” The Guidelines on Obtaining Valid Consent are along the same lines.
[Updated November 17, 2020]
Bill C-11 establishes plain language requirements for:
Obtaining Consumer Consent
The information contained in the privacy policies (which must also be easily accessible)
Requests for access to collected personal information
[End of update]
At the provincial level, Bill 64 (#pl64) goes a step further by introducing—somewhat by accident—the concept of “target audience” [as of October 20, 2020].
Privacy Policy
8.2. Any person who collects personal information using technological means must post a privacy policy written in clear and simple language on the company’s website, where applicable, and disseminate it through any means likely to reach the individuals concerned. The same applies to any notice regarding changes to this policy.
Consent
14. Consent under this Act must be explicit, freely given, informed, and provided for specific purposes. It must be requested for each such purpose, in plain and clear language, separately from any other information provided to the data subject. Upon request, the data subject must be provided with assistance to help them understand the scope of the consent being sought.
The content must therefore be “written in simple and clear terms” and “disseminated by any means appropriate for reaching the individuals concerned.” When consent is required, it must be requested explicitly, “in simple and clear terms,” and relate to “specific purposes,” so as to enable the individual concerned to give “explicit, free, and informed” consent.
One question has already arisen: With the increasing number of requests for specific consent, how can we avoid cognitive fatigue—sometimes referred to as “consent fatigue”?
Regulations and guidelines will most likely clarify provincial expectations regarding clear and simple language.
A whole year to get ready for Quebec?!
Does your current policy require a Ph.D. to understand it? You're not the only ones!
You will, however, need to act quickly once Bill 64 goes into effect. According to the current version of the bill, Bill 64 will become law one year after receiving parliamentary approval. As of this writing, the bill is being reviewed by a parliamentary committee. It’s reasonable to assume that the vote will take place no later than the end of 2021 and that you will then have exactly one year to comply with the new requirements. Let’s say… December 2022!
It's tomorrow morning—if you consider the magnitude of the task ahead of you in terms of compliance!
How can you prepare?
In the meantime, here are a few best practices that the Office of the Privacy Commissioner expects to be implemented ( ), which are directly inspired by the European guidelines on transparency and consent adopted following the General Data Protection Regulation (GDPR).
Avoid legal jargon. It may seem obvious, but it's not always easy to put into practice!
Structure your policy so that it is easy to read. Using “clear and simple language” means more than just everyday words and short sentences. It is a matter of usability and navigability. The information should therefore be presented in a user-friendly format and organized using clear and informative headings.
Avoid making your policy too dense or overloaded with information. Even though precision may seem synonymous with transparency, your policy should be as concise as possible. Of course, conciseness isn’t achieved by simply condensing information. Strive to strike a balance so that every word counts, and aim for a reasonable reading time for your readers.
Use visual aids as needed. Diagrams can be effective for explaining multidimensional information. For example, a graphic illustration of a complaint process over time might be worth a thousand words!
2. Put your target audience at the center of your approach, and document your decisions
How can you prove that your content is truly clear and simple? Hint: Privacy experts aren't the best people to judge whether a text is truly clear and simple.
Here are a few things to keep in mind to avoid trouble.
Define your target audience precisely
Consciously and deliberately, ask yourself who your customers or users are. Identify their characteristics, unique traits, needs, and expectations regarding privacy.
To determine who your target audience is and what their needs are, gather the data your organization already has from various departments (sales and marketing, customer service, complaints and disputes). Also, look for demographic statistics on the population segments you serve. And take the time to review all of this as a team!
Keep in mind that your target audience may change over time. Did your organization’s client base consist of 18- to 25-year-olds 10 years ago? Have they grown up with you and are now between 28 and 35 years old? Instagram, which was a bit of a troublemaker a few years ago, had a significant number of users between the ages of 13 and 18. But its privacy policy was anything but suitable for these users. And journalists pointed this out on several occasions!
Create personas to foster empathy
Personas are fictional yet realistic representations of your target audience. They synthesize the data you’ve gathered while helping your team members empathize with your audience. Give them a name, a face, a story, and motivations that help keep your target audience’s needs front and center.
Here’s an example. Christina, 35, is a mother of two and a full-time nurse. Before signing up for your service, she reads your policy. She does this on her cell phone during one of the few free moments she has in her day: on a rather noisy bus, on her way to pick up her kids from school. She has about 10 minutes. Christina tends to lose interest if the content doesn’t grab her attention within a few seconds. Her real goal? She wants to know if you’ll use photos of her children to recognize their faces and if you’ll sell information about her. If you reassure her quickly, she’ll sign up for your service.
Save your drafts and document your decisions
Developing a policy is a process. Keep in mind that it will likely take several drafts to finalize your policy. The important thing is to have a system in place that allows you to track changes and, above all, the reasons behind those changes.
3. Test your content
Clarity and simplicity are judged from the readers’ perspective, not from the creators’ perspective. As an organization, adopt a neutral stance regarding the clarity and simplicity of the content you produce. Comprehension tests almost always reveal unexpected issues—even for the most experienced writers!
Not only is this a good idea and a best practice, but it is also a clear expectation on the part of the Office of the Privacy Commissioner, which expects that affected consumers be consulted when developing your policy regarding the collection and use of their personal information.
Here are a few things to consider
Estimate the reading time based on the number of words, and ask yourself if it's realistic for your readers.
Use the readability tests for reference only (with great, great caution).
Recruit testers with diverse backgrounds, but who are always representative of your target audience.
Select a number of testers that is appropriate for your project. Testing with just a few people may not be representative of the broader user base, but it often provides significant value and helps identify what isn't working.
Place your testers in conditions that are as close as possible to the real-world usage context. During lab tests, readers' attention is often held for much longer periods than would be the case in "real life."
Document the results and make a list of the changes that need to be made.
Repeat the process until you achieve a satisfactory result!
Learn More
Sign up for our webinar on privacy and plain language!
Learn about our service for simplifying privacy policies.