Personal Information Protection and Governance Policy
This policy describes how SOS Sciatica organizes the protection of personal information: responsibilities, decisions, service providers, access controls, retention, destruction, privacy impact assessments and incident management.
It complements the Privacy Policy, which explains to visitors what personal information may be collected, why it is needed and how they can exercise their rights.

Scope and related documents
This policy applies to personal information in the custody or control of the operator of sossciatique.com in connection with the information website, its administration and requests submitted to it. It covers the entire information life cycle, regardless of the medium used.
Privacy Policy
It informs visitors about collection, purposes, cookies, disclosures, retention and their rights.
This policy
It governs internal accountability, roles, assessments, service providers, security and incident response.
TAGMED Clinic
Appointments, services and patient records are governed by the clinic’s own policies, systems and obligations and those of its service providers.
Governance and the Privacy Officer
The operator identified in the Legal Notice remains accountable for personal information in its custody. In Quebec, the person exercising the highest authority within the enterprise acts by default as the person in charge of the protection of personal information, unless that function is delegated in writing, in whole or in part, in accordance with applicable requirements.
Information to be published
Name or title: to be confirmed by the operator before publication.
Professional contact information: to be confirmed and displayed here before the page goes live.
The Privacy Officer’s title and contact information must also be easy to find from the Privacy Policy and Contact page.
Mandate
The Privacy Officer approves rules, advises on projects, participates in privacy impact assessments, handles requests and complaints, coordinates incidents, documents decisions and reports to management.
Roles and responsibilities
| Role | Main responsibilities | Evidence to retain |
|---|---|---|
| Management or operator | Approve the rules, provide resources, accept residual risks and review accountability reports. | Approvals, decisions and periodic reviews. |
| Privacy Officer | Oversee compliance, PIAs, requests, complaints, incidents and required communications. | Written delegation, registers and documented advice. |
| WordPress administration | Limit accounts, maintain the website, apply updates, monitor events and protect backups. | Account inventory, changes and access reviews. |
| Editorial team | Avoid copying personal information into content, handle corrections carefully and exclude identifying details. | Training, editorial rules and correction history. |
| Service providers | Process only the information required for the mandate, apply agreed safeguards and report events. | Contracts, assessments, subprocessor lists and relevant attestations. |
| Authorized users | Use their own accounts, protect access credentials, follow approved channels and promptly report errors. | Commitments, training and access removal at the end of the mandate. |

Managing the entire information life cycle
- Plan: define the purpose, authorized basis, individuals concerned, risks and duration before activating a function.
- Collect: request only what is necessary, provide the required information and avoid excessive free-text fields.
- Use: limit use to the stated purposes and document any new purpose.
- Disclose: verify the recipient, necessity, consent or applicable exception and contractual safeguards.
- Retain: apply an approved period and protect active copies, archives, emails, logs and backups.
- Destroy: securely delete copies that are no longer required or use genuine anonymization when it is permitted and justified.
A new plugin, form, analytics tool, integration, artificial intelligence service or provider must not be activated until its processing of personal information is understood and approved.
Information inventory and classification
An internal inventory must connect each category of information to its source, purpose, storage location, recipients, accountable persons, retention period and destruction method. It must include both direct processing and processing performed by service providers.
Public
Content intended for publication after verification of rights, accuracy and the absence of private information.
Internal
Non-public procedures and operational information containing no sensitive personal information.
Confidential
Contact details, requests, technical logs and other information that can identify an individual.
Sensitive
Information whose nature or context increases the risk of injury, including health or authentication information.
Privacy by design and privacy impact assessments
Privacy protection must be integrated from the beginning of a project and reassessed as the project evolves. A privacy impact assessment, or PIA, is conducted where required by law and used as a risk-management practice when a change may have a significant impact on individuals.
Triggers
A new or redesigned system, electronic service delivery, increased collection, sensitive information, profiling, automation, a new use, an integration or a transfer outside Quebec.
Analysis
Necessity, proportionality, sensitivity, volume, distribution, media, recipients, threats, consequences and risk-reduction measures.
Decision
Mandatory safeguards, accountable person, deadline, residual risk, approval, contractual conditions and reassessment date.
Before disclosing personal information outside Quebec or entrusting its processing outside Quebec, the organization must conduct the required assessment, verify that the information will receive adequate protection and enter into the applicable written agreement.
Selecting and monitoring service providers
The operator remains accountable when a service provider processes information on its behalf. Before activation and throughout the mandate, it must understand the service, the information involved, processing locations, subprocessors and return or deletion mechanisms.
| Stage | Expected checks |
|---|---|
| Before selection | Necessary function, reputation, safeguards, location, subcontracting, retention, portability and deletion. |
| Contract | Purposes and instructions, confidentiality, safeguards, access, incidents, assistance with rights, audits, return or destruction and end of mandate. |
| Configuration | Appropriate privacy-protective settings, unnecessary functions disabled, individual accounts and limited access. |
| Monitoring | Changes in terms, new subprocessors, incidents, attestations, actual retention periods and fulfilment of commitments. |
| End of service | Required export, removal of access, deletion of information and integrations, confirmation and inventory update. |
The inventory must specifically verify the hosting provider, backups, WordPress, BeTheme, BeBuilder, Slider Revolution, Polylang Pro, Rank Math, Wordfence, caching, forms, email, anti-spam, consent management, analytics, the CDN and appointment links actually in use.
Administrative, technical and physical safeguards
Safeguards are proportionate to the sensitivity, purpose, quantity, distribution and medium of the information. They are reviewed after a significant change or incident.
- need-to-know access and the principle of least privilege;
- individual accounts, strong authentication and prompt removal of unnecessary access;
- encrypted connections and channels suited to the level of sensitivity;
- updates, a reduced number of plugins, protected backups and restoration tests;
- proportionate logging and monitoring without excessive collection;
- management of vulnerabilities, changes and authorized devices;
- training, handling rules and prompt reporting of errors;
- protection of physical premises and documents where applicable.

Retention, backups and destruction
Personal information is retained for the period required for its purpose and applicable obligations, then securely destroyed. An internal schedule must specify categories, triggering events, periods, exceptions, accountable persons and destruction methods.
Documented periods
Forms, emails, logs, consent records, rights requests, incidents, archives and backups must each have a verifiable rule.
Justified suspension
Deletion may be suspended when required by a legal obligation, investigation, complaint or defence of legal rights. The suspension must be limited and documented.
Verifiable destruction
The method takes account of the medium, copies, providers and backups. Access to copies awaiting expiry remains protected.
Anonymization must not be confused with de-identification. It may replace destruction only in permitted circumstances and when it is reasonable to expect that the individual can no longer be identified, directly or indirectly, on an irreversible basis.

Managing confidentiality incidents
An internal procedure must allow every authorized person to promptly report a loss or unauthorized access, use or disclosure, as well as any other breach involving the protection of personal information.
- Detect and report: preserve relevant facts and alert the Privacy Officer without undue delay.
- Contain: limit access or dissemination without destroying information required for the analysis.
- Assess: determine the information, individuals, causes, consequences, safeguards and likelihood of harmful use.
- Notify: when there is a risk of serious injury, promptly notify the Commission d’accès à l’information and the individuals concerned in accordance with applicable rules.
- Record: enter the incident in the register even when the conclusion does not require public notification.
- Correct: address the cause, monitor the effects, document decisions and verify the effectiveness of measures.
Rights requests and complaint handling
The process must enable the secure receipt, authentication, routing, search, decision and response for access requests, correction requests, applicable withdrawal requests and complaints. Identity verification must be proportionate to the risk and must not unnecessarily create a new copy of a sensitive document.
Receipt
A distinct “Privacy and Data” reason must be available on the Contact page and directed to the Privacy Officer.
Processing
The request, searches, decision, communications and applicable deadline are documented in a protected record.
Response
The response uses an appropriate channel, explains any limitation or refusal and identifies the available remedies.
To understand the information that may be held and the rights available to visitors, see the Your rights section of the Privacy Policy.
Training, controls and continuous improvement
Compliance does not depend solely on a public webpage. It requires ongoing practices, evidence and regular review.
Training
Upon onboarding, after a change of role and periodically according to risk: confidentiality, phishing, access, forms and incidents.
Access review
Periodic review of WordPress, hosting, email, service provider, backup and external tool accounts.
Audit
Review of forms, cookies, third-party domains, retention periods, contracts, translations, plugins, logs and configurations.
Indicators
Requests, complaints, incidents, response times, removed access, reviewed providers, completed safeguards and outstanding risks.
This policy is reviewed periodically and after a significant change in technology, provider, purpose, information flow, law or risk. Significant versions and their approvals must be retained.
Transparency and publication limits
What must be public
Governance rules in clear language, the Privacy Officer’s title and contact information, the Privacy Policy, the complaint process and ways to exercise individual rights.
What remains internal
The detailed inventory, architecture, accounts, technical addresses, detection rules, vulnerabilities, keys, backup locations and complete response plans.
Frequently asked questions about data protection
Does this page replace the Privacy Policy?
No. The Privacy Policy informs visitors about collection and their rights. This policy explains how the organization governs responsibilities, risks, service providers, access, retention periods and incidents.
Who is responsible for protecting personal information?
The person exercising the highest authority within the enterprise assumes this function by default, unless it is properly delegated in writing. The exact title and contact information must be confirmed and published before this page goes live.
Does SOS Sciatica retain patient records?
The information website must not be used as a patient record. Appointments and clinical records are governed by TAGMED Clinic’s own systems and policies.
Why is a service provider inventory necessary?
Hosting, email, security, forms, backups and other tools may process information. The operator must know which tools do so, why, where, for how long and under which safeguards.
What is a PIA?
A privacy impact assessment is a preventive and evolving process that analyzes a project’s effects on privacy, its risks and the measures available to avoid or reduce those risks.
When must a PIA be completed?
Among other circumstances prescribed by law, a PIA is required for certain information system or electronic service delivery projects involving personal information and before information is disclosed outside Quebec. It is also useful when a change presents a significant risk.
How long is personal information retained?
Only for the period required for the stated purpose and applicable obligations. Exact periods must appear in an internal schedule aligned with WordPress, emails, logs, backups and service providers.
What happens during a confidentiality incident?
The organization must contain the event, assess the risk, take measures to reduce injury, maintain a register and, where there is a risk of serious injury, promptly notify the CAI and affected individuals in accordance with applicable rules.
Can I request access or a correction?
Yes, subject to the conditions prescribed by law. Use the Contact page and select the privacy-related reason without immediately sending a complete identity document or medical record.
Does this policy guarantee that no incident will occur?
No. It defines a framework for prevention, detection, response and improvement. No measure eliminates every risk, which is why controls, backups, reviews and an incident procedure are important.
Official references
- Act respecting the protection of personal information in the private sector.
- Commission d’accès à l’information — enterprise accountability and privacy impact assessments.
- Commission d’accès à l’information — retention and destruction.
- Commission d’accès à l’information — confidentiality incidents and security safeguards.
- Commission d’accès à l’information — use, disclosure and processing outside Quebec.
Official legislation and the operator’s actual practices prevail over this summary. A Quebec legal review is recommended before publication.
Contact the Privacy Officer
Submit a request, complaint or report through the privacy channel. Describe the context without attaching a medical record or complete identity document to your first message.
Dr Sylvain Desforges, B.Sc., D.O., N.D., osteopath
Editorial information, sources and limitations
This content is intended to inform patients about sciatica, possible causes, warning signs, and care options. It does not replace an individualized assessment.
Reference sources
References are selected according to the subject of the page: guidelines, systematic reviews, then institutional resources.
- NICE NG59 – Low back pain and sciatica in over 16s — National guideline
- HAS – Management of patients with common low back pain — French national guideline
- BMJ – Surgical versus non-surgical treatment for sciatica — Systematic review and meta-analysis
- AAOS OrthoInfo – Sciatica — Patient resource from a professional society
Complementary resources from the TAGMED network
These internal resources complement the clinical information and thematic linking. They do not replace national guidelines or systematic reviews.
Limitations of this information
The information on this page is general. It does not constitute a diagnosis, prescription, or guarantee of results. Pain radiating into the leg may have several causes; assessment should consider clinical history, examination findings, symptom progression, and, when appropriate, complementary tests.
When to seek urgent medical care
Seek urgent medical care if you experience loss of bladder or bowel control, saddle anesthesia, major or progressive leg weakness, unexplained fever, pain after significant trauma, or severe pain that rapidly worsens.

