Confidentiality Policy

This is a translation of the French version of this policy. In case of discrepancy, the French version prevails.

Policy on the protection of personal information and procedure in the event of a breach

REVISION DATE: 2026-09-24 

Table of contents

Our commitment
Accountability 
Consent 
Reasons for collection / use / retention
Limits on collection
Limits on use / disclosure / retention
Accuracy of information
Measures taken to protect your personal information
Retention period of your personal information
Your choices regarding personal information
Cookies and measurement tools on the website
Your right to make a complaint
APPENDIX A – Procedure in the event of a failure / breach / incident
APPENDIX B – References from the Chambre de la sécurité financière


Our commitment

To give you access to financial products and services, we collect some of your personal information and ensure its protection. We comply with the Personal Information Protection and Electronic Documents Act (PIPEDA), a federal privacy law, and with any applicable provincial law. We also base this policy on the recommendations and the code of ethics of the Chambre de la sécurité financière, the self-regulatory organization of our industry. See Appendix B for the references to the code of ethics and frequently asked questions.

Accountability  

We are responsible for the personal information we receive from our clients. We will protect this information, whatever the means used to transmit it.

Consent

We will collect information only with your consent. Your personal information, including your name, address, date of birth, medical history and lifestyle habits, will be used to find financial products, concepts and services that meet the needs you have identified. By signing the authorization form, you consent, on your own behalf and on behalf of your liquidators, administrators or assigns, to:

  • Provide accurate information throughout our business relationship and as your situation changes.
  • Allow us to use, transmit and disclose this information as needed to our suppliers, associates and managing general agents, who may keep some information in their files for later use and recommendation by us, our suppliers and any assignee.
  • Allow us to keep your personal information, including the medical information appearing on your applications, in our paper and electronic files for as long as you wish to do business with us or as long as we must meet a business or regulatory need by keeping the information.
  • Transfer your file, including your personal information, to another agent and/or MGA, to continue meeting your needs, in the event of disability, death, retirement or any other major event affecting our firm. You nevertheless have the right to choose your own agent at that time, should you disagree with the one assigned to you.

Reasons for collection / use / retention

We collect all personal information (including medical and financial information, as well as information about the company and related information) with your consent. We use and keep it only to provide advice, to administer products or services you purchase through us, and to recommend new products or services that may interest you.

Limits on collection

We collect and keep  only the information that helps us advise you, including personal, financial and medical information, and meet our regulatory obligations. We use only fair and lawful means to collect this information.  

Limits on use / disclosure / retention

We will use and disclose your personal information to perform our functions, to advise you and, where applicable, to comply with the law. The personal information in your client file will be disclosed only:

  • To our employees and to persons we have authorized, such as professionals, to help you in areas outside our field of practice.
  • To the companies whose products and services we offer, and to their employees and agents, for their activities aimed at providing or seeking to provide you with financial products and services, or for any other related activity (and in connection with any other purpose you have authorized);
  • To selected third-party service providers we have authorized; if they are located abroad, your personal information may then be subject to the applicable laws of other countries, including laws on access to information by public authorities;
  • To persons or entities to whom you have given access or who are authorized by law to access it.

We are required to keep most of the information we collect for regulatory reasons, including the requirement to demonstrate that the recommendations we make are appropriate and meet your identified needs.  

In accordance with applicable laws and your written authorization, you have the right to consult the personal information contained in your file. At your request, copies (not originals) of other personal documents, such as insurance policies, wills or mandates (powers of attorney), may be kept in your file.

Accuracy of information

To make appropriate recommendations, we must receive accurate information. It is our responsibility to keep the information about you as accurate and up to date as possible. When the situation allows, we will try to update your personal information to determine whether the recommendations we have made are still appropriate as your situation changes. However, we also rely on you to provide us with regular updates for the same reason. You may review the personal information we keep about you on request.  

Measures taken to protect your personal information  

All staff members, associate advisors, managing general agents and suppliers who have access to client files must protect this information, keep it confidential and use it only for the intended purposes. We have also put in place physical and computer safeguards, as well as other processes, to protect client information from unauthorized access. In line with the principles and recommendations of PIPEDA, staff are required to sign a confidentiality agreement at the start of employment, and we keep ourselves aware on a regular basis through training and content on the importance of personal information protection and cybersecurity.

Appendix A sets out our procedure in the event of a failure / breach / incident involving the protection of your personal information.

Retention period of your personal information

Your personal information will be kept only for 1) the time needed to achieve the purposes for which it was collected, 2) the time required by the laws applicable to the products or services you have subscribed to with us, and 3) the time required to protect our rights in the event of legal action. 
For more information on the exact period for which this information will be kept, please contact the Person in charge of the protection of personal information identified later in this Policy.

Your choices regarding personal information

You may withdraw your consent at any time (subject to contractual or legal restrictions and to giving us reasonable notice) by contacting us. If you withdraw your consent, we may be unable to provide you with the requested products or services and we may have to end our business relationship.

Cookies and measurement tools on the website

Our website does not activate any audience measurement, advertising or tracking tool until you have accepted it in the banner displayed on your first visit. If you refuse, or if you make no choice, these tools remain disabled. Only a cookie that remembers your choice (loi25_consent, kept for 12 months) is then placed.

If you accept, the following tools are activated:

  • Google Analytics and Google Tag Manager (Google): measurement of traffic and of the pages viewed;
  • Microsoft Clarity (Microsoft): measurement of how pages are used, including the recording of clicks, scrolling and mouse movements, to improve the site;
  • Google Ads and Facebook pixel (Google, Meta): measurement of the effectiveness of our advertising and display of more relevant advertising on other sites;
  • Mautic: tracking of your visits in connection with our communications (for example, the newsletter). This tool is hosted on a server we operate ourselves;
  • TrustedSite: display of the site’s security seal and measurement of its visits.

These tools may collect, in particular, your IP address, the type of device and browser, the pages viewed and the length of the visit. Google, Microsoft, Meta and TrustedSite process this information outside Québec, notably in the United States, where it may be subject to the laws of those jurisdictions.

You may change your mind at any time by clicking Manage cookies, at the bottom of every page of the site. You may also delete cookies in your browser settings.

Your right to make a complaint

If you have concerns about the collection, use or disclosure of your personal information, you have the right to make a complaint to us or to the federal or provincial privacy authority where you live:

Chief privacy officer:

Lawrence Shaw 
2484 rue Viau, Montréal, Québec, H1V 3H9 
Tel.: 514-316-1401 ext. 200 
Email: lawrence@lacliniquefinanciere.com


APPENDIX A

Procedure in the event of a failure / breach / incident

A privacy breach occurs when there is unauthorized access to personal information, or unauthorized collection, use or disclosure of such information. These activities are “unauthorized” when they contravene applicable privacy laws, such as the Personal Information Protection and Electronic Documents Act (PIPEDA), Québec’s Law 25 or other provincial and federal privacy laws. Some of the most common privacy breaches occur when the personal information of a consumer, patient, client or employee is stolen, lost or distributed by mistake (e.g., theft of a computer containing personal information, or an email containing personal information sent to the wrong person by mistake). A breach may also result from a deficient procedure or an operational failure.

As determined by the Commission d’accès à l’information du Québec (www.cai.gouv.qc.ca), we will follow these seven (7) steps in the event of a breach involving your personal information:

  1. Incident form
  2. Preliminary assessment of the situation
  3. Containment of the privacy breach
  4. Assessment of the risks associated with the breach
  5. Notification of the persons concerned
  6. Prevention
  7. Follow-up

Incident form

We will complete a privacy incident and breach report form, in table format, containing the following information, and will submit it to the Commission d’accès à l’information du Québec:

Date 
Name of the person completing the form 
Location and date of the incident 
Description of the incident 
Cause (if known) 
Persons affected by the incident (client, employee, advisor, third party) 
Type(s) of personal information involved 
Brief description of the actions taken to contain the breach 
Who was notified? (Include the date of notice) 
Additional comments

Preliminary assessment of the situation

a)    Briefly define the context of the loss or theft of personal information:

  • Identify the personal information affected and its medium;
  • Identify the persons, their number and the group of persons (clients, employees, etc.) affected;
  • Establish the context of the events (date, time, place, etc.);
  • Identify, if possible, the circumstances of the loss (cause, persons likely to be involved in the incident, etc.);
  • List the physical and computer security measures in place at the time of the incident.

b)    Inform the external authorities concerned that must be notified of the incident immediately: (before the risk assessment)

  • Police department (if the circumstances suggest a possible crime);
  • Commission d’accès à l’information (link to the form)

c)    Designate a person or team responsible for managing the situation.

d)    Inform the internal stakeholders concerned:

  • Officers of the organization or company;
  • Head of the administrative unit concerned;
  • Person in charge of the protection of personal information;
  • Legal counsel;
  • Communications department (management of media and client calls).

Containment of the privacy breach

Take appropriate measures without delay to limit the consequences for the persons concerned of a possible malicious use of their personal information, or of identity fraud or theft:

a)    Take measures to immediately limit the consequences of a loss or theft of personal information, making sure to end the non-compliant practice, if any;

b)    Recover the physical or digital files, as the case may be;

c)    Revoke or change passwords or computer access codes;

d)    Check for gaps in security systems.

Assessment of the risks associated with the breach

a)    Complete a preliminary risk assessment, considering the sensitivity of the personal information involved, taking into account its nature, its quantity, the possibility of combining it with other information, the persons concerned, etc.;

b)    Determine the context of the incident, including:

  • the cause (e.g., whether the loss or theft of personal information was deliberate or not, human error, a computer flaw, etc.);
  • the known or probable perpetrators of the loss or theft of personal information (e.g., criminal organization, general public, etc.);
  • the extent of the situation (number of persons affected and sectors affected);
  • whether or not the disappearance of personal information is systemic (particularly when the loss is not directly caused by human intervention);
  • an assessment of the likelihood of a similar event recurring.

c)    Assess the possibility that the personal information concerned could be used to the detriment of the persons concerned, taking into account, in particular, the security measures taken to protect it, how difficult it is to access and how intelligible it is (password, encryption, etc.);

d)    Assess whether or not the situation is reversible, including the possibility of recovering the personal information;

e)    Assess whether the immediate measures taken were adequate to limit the breach and supplement them if necessary;

f)    Determine the potential harm, in particular by assessing the possibilities of future use of the personal information by malicious persons, notably for identity theft;

g)    Determine priorities and identify the actions to take based on the results of this risk assessment.


Notification of the persons concerned

a)    Determine who must be informed of the loss or theft of personal information based on the risk assessment:

  • Police department: Where the disappearance may result from the commission of a crime, the police department concerned must first be notified of the circumstances of the disappearance and, afterwards, of all subsequent steps. Particular care is needed not to hinder the investigation and to preserve evidence that may be relevant;
  • Persons concerned: If the loss or theft of personal information presents a risk of harm to the persons concerned, they should be notified without delay. The aim is not to alarm them but to warn them so that they can take appropriate measures to protect their personal information;
  • Commission d’accès à l’information: If the persons concerned by the personal information are from Québec, the Commission may initiate an inspection or investigation and act as an advisor in finding a solution;
  • Others: It may also be necessary to notify other parties, such as credit agencies, a mandatary, a co-contracting party, a government body, a union, a professional order, etc.

However, when disseminating information about the loss of personal information, particular care must be taken not to aggravate the harm the persons concerned could suffer (e.g., keep personal information in notices to a minimum).

b)    Designate the persons responsible for notifying the external parties identified above, as well as the timing and the means (letter, email, telephone);

c)    Where applicable, identify and record the reasons for the decision not to notify the persons concerned and the other parties.

 
Notice to persons affected by a loss or theft of their personal information:

Depending on the circumstances, it may be necessary to notify the victims of the loss or theft of their personal information. This notice could include some of the following elements:

  • The context of the incident and when it occurred, as well as a description of the nature of the personal information affected or potentially affected, without disclosing specific personal information; 
  • A brief description of the measures taken to limit or prevent any harm, as well as the list of persons who were informed of the situation (police department, Commission d’accès à l’information, etc.); 
  • The actions taken by organizations and companies to help the persons concerned (help and information service, credit alert subscription, etc.); 
  • The measures the persons concerned can take to reduce the risk of harm or to better protect themselves (reference to the document “Identity theft” available from the Commission d’accès à l’information); 
  • Other general information documents designed to help people protect themselves against identity theft; 
  • The contact information of a person in the organization who can answer questions and to whom any report can be made; 
  • The main measures that will be taken to prevent the situation from recurring (change of practice or process, staff training, review or development of policies, an audit, periodic follow-up, etc.).

Prevention

  1. Further analyze the circumstances of the loss or theft of personal information and prepare a chronological description of the events and of the actions taken in response to the incident, including the dates and the parties involved;
  2. List and review the internal standards, policies or directives in place at the time of the incident, both for computer security, when information is involved, and for the protection of personal information in general;
  3. Check whether these internal standards, policies or directives were followed by the persons involved and, if not, identify why;
  4. If it is a procedural error or an operational failure, record it in the security file and adapt the processes to prevent such an incident from happening again;
  5. Assess the need to develop a policy on handling a loss or theft of personal information within the organization or company;
  6. Formulate recommendations on medium- and long-term solutions and prevention strategies;
  7. Make sure that the collection of the personal information concerned is truly necessary for the organization or company;
  8. Plan the follow-up to be given. 

Follow-up

It is important to follow up on:

a)    the handling process to be applied in the event of a loss or theft of personal information and the results obtained, in order to improve it if necessary;

b)    the security measures required following the incident and their performance, in order to improve the processes in place and to update the Policy on the protection of personal information;

c)    the communication of relevant information to the Commission d’accès à l’information and to the police department involved, if applicable.


Record keeping

It is also mandatory to keep a record of all privacy breaches, even those that present no risk of serious harm. Every event must be kept for at least two years so that the Office of the Privacy Commissioner can review it on request.

Records must include, at a minimum, the following elements:

  • the date or estimated period of the breach;
  • a description of the circumstances of the breach;
  • the nature of the information involved in the breach;
  • whether the breach was reported to the Office of the Privacy Commissioner, or the names of the other organizations notified, if applicable;
  • a brief explanation of why the organization determined that there was no risk of serious harm, if the breach was not reported to the Office of the Privacy Commissioner.

Resources

Detailed information on all your obligations regarding the protection of personal information is available at www.priv.gc.ca.


APPENDIX B

References from the Chambre de la sécurité financière

Code of ethics

A representative must ensure that the information held about clients remains confidential, unless certain legal provisions or a court order allow it to be disclosed. The representative must also use the information collected only for the purposes for which it was obtained and never use it to the client’s detriment.

These obligations are set out in sections 26 and 27 of the Code of ethics of the Chambre de la sécurité financière.

Sec. 26 – A representative must respect the confidentiality of all personal information obtained about a client and use it for the purposes for which it was obtained, unless a provision of an Act or an order of a competent court relieves the representative of that obligation.

Sec. 27 – A representative must not disclose personal or confidential information obtained other than in accordance with the law, nor use it to the client’s detriment or with a view to obtaining an advantage for the representative or for another person.

It is also important to note the requirement of section 23 of the Act respecting the distribution of financial products and services, under which a representative must transmit to the establishment to which the representative is attached all the information collected about clients. The representative may disclose it only to a person authorized by law to receive it.

(Unofficial translation of the provisions cited. Only the French text has legal force.)


Frequently asked questions

Q: Must the files and records kept be stored in a locked filing cabinet and in a locked room?

A: The general rule is that files must be kept in a safe and secure place. This place must therefore not be easily accessible, other than by authorized persons. Obviously, it must also be ensured that these files can easily be located, within a reasonable time, when a duly authorized person wishes to access them. Keeping files in locked filing cabinets in a locked room is therefore a good way of meeting these obligations. However, any other safe and secure method achieving the same objective would be just as acceptable.

Q: What about keeping electronic files?

A: For electronic files, the same rule as for physical files applies, insofar as their storage method must be safe and secure. This means that the information must be kept so that no one other than a duly authorized person has access to it. In addition, it must be ensured that this information cannot be falsified or destroyed involuntarily. 
The use of an access code, antivirus software and network access protection are examples of ways to achieve these objectives.

 
Q: Must there be a filing cabinet for each type of record or file kept?

A: An essential principle of record keeping is that records must be kept so that they can easily be found within a reasonable time. This implies using an effective filing method that makes it possible to trace each type of file or record. Using a separate filing cabinet for each type of file, combined with appropriate coding, could therefore prove effective, even though nothing requires it.

Q: In a client file, must the contract sold be described in detail, even when a copy of the application and the illustration of the products sold are attached to the file?

A: What matters in record keeping is that all the information required under the Regulation respecting the keeping and preservation of books and registers is found in your files. Do not lose sight of the fact that these files will also allow you to provide professional service to your clients. The purpose of these files should therefore be easy access to all the information that will be useful to properly advise your clients. Your client files should include, in particular, the following information: the client’s contact information (name, date of birth, address, telephone number, fax number and email address), the object, nature and cost of the product sold or service rendered, the policy number, the dates of issue of the contract and of signature of the application or service request, the name of the representative involved in the transaction, the representative’s method of remuneration, for each product sold or service rendered, the date and method of payment of the product sold or service rendered, a copy of the client’s financial needs analysis (FNA), a copy of the form required when replacing a policy, as well as any other information collected from the client, and any related document. Thus, when the copy of the application and the illustration of the products sold contain all this information, nothing requires the contract sold to be described in detail. However, you may very well decide to add more than necessary, provided it is relevant. Also make sure to comply with the record-keeping standards imposed by the establishment to which you are attached.

Q: If an individual is the only life and health insurance representative in the firm, what rules must that individual comply with?

A: Under the obligations set out in the Act respecting the distribution of financial products and services, the Regulation respecting the keeping and preservation of books and registers and the Regulation respecting firms, independent representatives and independent partnerships, you must apply the rules according to the mode of practice under which you practise. In fact, for a representative to obtain the right to practise, the representative must hold a certificate issued by the AMF as well as professional liability insurance, and must be authorized to practise under a particular mode of practice, in accordance with section 14 of the Act respecting the distribution of financial products and services. You must therefore refer to that mode of practice. Thus, if you are an independent representative and are therefore not attached to a firm or an independent partnership, you must apply the rules governing independent representatives. If you instead practise your activities for a firm or an independent partnership, these must apply the rules imposed on them.

Q: May a financial security advisor keep a copy of all insurance applications submitted during the review of a file?

A: Nothing in the Act or regulations prohibits the representative from keeping insurance applications in the client file if it is relevant information. Moreover, the Regulation respecting the keeping and preservation of books and registers provides that any other useful and necessary information collected from the client, as well as any related document, must be kept in the register. In addition, your ethical obligations state that you must have complete knowledge of the facts. It would therefore be logical to keep this information in your files.