Governance, security and information life cycle

Personal Information Protection and Governance Policy

This policy describes how SOS Sciatica organizes the protection of personal information: responsibilities, decisions, service providers, access controls, retention, destruction, privacy impact assessments and incident management.

It complements the Privacy Policy, which explains to visitors what personal information may be collected, why it is needed and how they can exercise their rights.

Professional reviewing SOS Sciatica data protection and governance
Generated illustration: the person shown is not an actual member of SOS Sciatica.
Public scope. This policy presents governance principles and responsibilities. It does not disclose configurations, addresses, credentials, infrastructure plans or detailed technical procedures that could weaken the website’s security.

Our four governance principles

1

Accountability

Every processing activity must have a defined purpose, an accountable person, authorized participants and a documented decision.

2

Minimization

The website limits collection, access, copying, disclosure and retention to what is necessary.

3

Continuous protection

Safeguards are adapted to the sensitivity, volume, use, medium and actual risks involved.

4

Improvement

Incidents, audits, technological changes and individual requests inform corrective actions.

Scope and related documents

This policy applies to personal information in the custody or control of the operator of sossciatique.com in connection with the information website, its administration and requests submitted to it. It covers the entire information life cycle, regardless of the medium used.

Privacy Policy

It informs visitors about collection, purposes, cookies, disclosures, retention and their rights.

Read the policy

This policy

It governs internal accountability, roles, assessments, service providers, security and incident response.

TAGMED Clinic

Appointments, services and patient records are governed by the clinic’s own policies, systems and obligations and those of its service providers.

General forms. SOS Sciatica must not be used as a repository for medical records. Do not send imaging reports, health insurance numbers, prescriptions or detailed medical histories through an editorial form.

Governance and the Privacy Officer

The operator identified in the Legal Notice remains accountable for personal information in its custody. In Quebec, the person exercising the highest authority within the enterprise acts by default as the person in charge of the protection of personal information, unless that function is delegated in writing, in whole or in part, in accordance with applicable requirements.

Information to be published

Name or title: to be confirmed by the operator before publication.

Professional contact information: to be confirmed and displayed here before the page goes live.

The Privacy Officer’s title and contact information must also be easy to find from the Privacy Policy and Contact page.

Mandate

The Privacy Officer approves rules, advises on projects, participates in privacy impact assessments, handles requests and complaints, coordinates incidents, documents decisions and reports to management.

Mandatory information to complete. The Privacy Officer’s name or functional title and professional contact information must not be guessed. They must be validated by the website owner before publication.

Roles and responsibilities

RoleMain responsibilitiesEvidence to retain
Management or operatorApprove the rules, provide resources, accept residual risks and review accountability reports.Approvals, decisions and periodic reviews.
Privacy OfficerOversee compliance, PIAs, requests, complaints, incidents and required communications.Written delegation, registers and documented advice.
WordPress administrationLimit accounts, maintain the website, apply updates, monitor events and protect backups.Account inventory, changes and access reviews.
Editorial teamAvoid copying personal information into content, handle corrections carefully and exclude identifying details.Training, editorial rules and correction history.
Service providersProcess only the information required for the mandate, apply agreed safeguards and report events.Contracts, assessments, subprocessor lists and relevant attestations.
Authorized usersUse their own accounts, protect access credentials, follow approved channels and promptly report errors.Commitments, training and access removal at the end of the mandate.

Team organizing the secure life cycle of personal information
Every stage, from collection to destruction, must be justified and governed.

Managing the entire information life cycle

  1. Plan: define the purpose, authorized basis, individuals concerned, risks and duration before activating a function.
  2. Collect: request only what is necessary, provide the required information and avoid excessive free-text fields.
  3. Use: limit use to the stated purposes and document any new purpose.
  4. Disclose: verify the recipient, necessity, consent or applicable exception and contractual safeguards.
  5. Retain: apply an approved period and protect active copies, archives, emails, logs and backups.
  6. Destroy: securely delete copies that are no longer required or use genuine anonymization when it is permitted and justified.

A new plugin, form, analytics tool, integration, artificial intelligence service or provider must not be activated until its processing of personal information is understood and approved.

Information inventory and classification

An internal inventory must connect each category of information to its source, purpose, storage location, recipients, accountable persons, retention period and destruction method. It must include both direct processing and processing performed by service providers.

Public

Content intended for publication after verification of rights, accuracy and the absence of private information.

Internal

Non-public procedures and operational information containing no sensitive personal information.

Confidential

Contact details, requests, technical logs and other information that can identify an individual.

Sensitive

Information whose nature or context increases the risk of injury, including health or authentication information.

Health information. Its sensitivity requires greater caution. SOS Sciatica’s general form must not become a clinical channel or a parallel copy of a patient record.

Privacy by design and privacy impact assessments

Privacy protection must be integrated from the beginning of a project and reassessed as the project evolves. A privacy impact assessment, or PIA, is conducted where required by law and used as a risk-management practice when a change may have a significant impact on individuals.

Triggers

A new or redesigned system, electronic service delivery, increased collection, sensitive information, profiling, automation, a new use, an integration or a transfer outside Quebec.

Analysis

Necessity, proportionality, sensitivity, volume, distribution, media, recipients, threats, consequences and risk-reduction measures.

Decision

Mandatory safeguards, accountable person, deadline, residual risk, approval, contractual conditions and reassessment date.

Before disclosing personal information outside Quebec or entrusting its processing outside Quebec, the organization must conduct the required assessment, verify that the information will receive adequate protection and enter into the applicable written agreement.

No unsupported claim. Publishing this policy does not prove that a PIA has been completed. Each assessment must exist in a dated internal record adapted to the actual project.

Selecting and monitoring service providers

The operator remains accountable when a service provider processes information on its behalf. Before activation and throughout the mandate, it must understand the service, the information involved, processing locations, subprocessors and return or deletion mechanisms.

StageExpected checks
Before selectionNecessary function, reputation, safeguards, location, subcontracting, retention, portability and deletion.
ContractPurposes and instructions, confidentiality, safeguards, access, incidents, assistance with rights, audits, return or destruction and end of mandate.
ConfigurationAppropriate privacy-protective settings, unnecessary functions disabled, individual accounts and limited access.
MonitoringChanges in terms, new subprocessors, incidents, attestations, actual retention periods and fulfilment of commitments.
End of serviceRequired export, removal of access, deletion of information and integrations, confirmation and inventory update.

The inventory must specifically verify the hosting provider, backups, WordPress, BeTheme, BeBuilder, Slider Revolution, Polylang Pro, Rank Math, Wordfence, caching, forms, email, anti-spam, consent management, analytics, the CDN and appointment links actually in use.

Administrative, technical and physical safeguards

Safeguards are proportionate to the sensitivity, purpose, quantity, distribution and medium of the information. They are reviewed after a significant change or incident.

  • need-to-know access and the principle of least privilege;
  • individual accounts, strong authentication and prompt removal of unnecessary access;
  • encrypted connections and channels suited to the level of sensitivity;
  • updates, a reduced number of plugins, protected backups and restoration tests;
  • proportionate logging and monitoring without excessive collection;
  • management of vulnerabilities, changes and authorized devices;
  • training, handling rules and prompt reporting of errors;
  • protection of physical premises and documents where applicable.
No organization can guarantee zero risk. This policy describes categories of safeguards without disclosing the precise settings that must remain in internal documentation.
Administrator using strong authentication to protect access to data
Access must be individual, limited, reviewed and removed as soon as it is no longer required.

Retention, backups and destruction

Personal information is retained for the period required for its purpose and applicable obligations, then securely destroyed. An internal schedule must specify categories, triggering events, periods, exceptions, accountable persons and destruction methods.

Documented periods

Forms, emails, logs, consent records, rights requests, incidents, archives and backups must each have a verifiable rule.

Justified suspension

Deletion may be suspended when required by a legal obligation, investigation, complaint or defence of legal rights. The suspension must be limited and documented.

Verifiable destruction

The method takes account of the medium, copies, providers and backups. Access to copies awaiting expiry remains protected.

Anonymization must not be confused with de-identification. It may replace destruction only in permitted circumstances and when it is reasonable to expect that the individual can no longer be identified, directly or indirectly, on an irreversible basis.

Team coordinating a privacy incident response procedure
A structured response aims to contain the event, protect individuals and prevent a recurrence.

Managing confidentiality incidents

An internal procedure must allow every authorized person to promptly report a loss or unauthorized access, use or disclosure, as well as any other breach involving the protection of personal information.

  1. Detect and report: preserve relevant facts and alert the Privacy Officer without undue delay.
  2. Contain: limit access or dissemination without destroying information required for the analysis.
  3. Assess: determine the information, individuals, causes, consequences, safeguards and likelihood of harmful use.
  4. Notify: when there is a risk of serious injury, promptly notify the Commission d’accès à l’information and the individuals concerned in accordance with applicable rules.
  5. Record: enter the incident in the register even when the conclusion does not require public notification.
  6. Correct: address the cause, monitor the effects, document decisions and verify the effectiveness of measures.

Report a concern

Rights requests and complaint handling

The process must enable the secure receipt, authentication, routing, search, decision and response for access requests, correction requests, applicable withdrawal requests and complaints. Identity verification must be proportionate to the risk and must not unnecessarily create a new copy of a sensitive document.

Receipt

A distinct “Privacy and Data” reason must be available on the Contact page and directed to the Privacy Officer.

Processing

The request, searches, decision, communications and applicable deadline are documented in a protected record.

Response

The response uses an appropriate channel, explains any limitation or refusal and identifies the available remedies.

To understand the information that may be held and the rights available to visitors, see the Your rights section of the Privacy Policy.

Training, controls and continuous improvement

Compliance does not depend solely on a public webpage. It requires ongoing practices, evidence and regular review.

Training

Upon onboarding, after a change of role and periodically according to risk: confidentiality, phishing, access, forms and incidents.

Access review

Periodic review of WordPress, hosting, email, service provider, backup and external tool accounts.

Audit

Review of forms, cookies, third-party domains, retention periods, contracts, translations, plugins, logs and configurations.

Indicators

Requests, complaints, incidents, response times, removed access, reviewed providers, completed safeguards and outstanding risks.

This policy is reviewed periodically and after a significant change in technology, provider, purpose, information flow, law or risk. Significant versions and their approvals must be retained.

Transparency and publication limits

What must be public

Governance rules in clear language, the Privacy Officer’s title and contact information, the Privacy Policy, the complaint process and ways to exercise individual rights.

What remains internal

The detailed inventory, architecture, accounts, technical addresses, detection rules, vulnerabilities, keys, backup locations and complete response plans.

Effective date: to be added after approval by the operator, confirmation of the Privacy Officer and validation of the actual inventory. Last editorial review: July 19, 2026.

Frequently asked questions about data protection

Does this page replace the Privacy Policy?

No. The Privacy Policy informs visitors about collection and their rights. This policy explains how the organization governs responsibilities, risks, service providers, access, retention periods and incidents.

Who is responsible for protecting personal information?

The person exercising the highest authority within the enterprise assumes this function by default, unless it is properly delegated in writing. The exact title and contact information must be confirmed and published before this page goes live.

Does SOS Sciatica retain patient records?

The information website must not be used as a patient record. Appointments and clinical records are governed by TAGMED Clinic’s own systems and policies.

Why is a service provider inventory necessary?

Hosting, email, security, forms, backups and other tools may process information. The operator must know which tools do so, why, where, for how long and under which safeguards.

What is a PIA?

A privacy impact assessment is a preventive and evolving process that analyzes a project’s effects on privacy, its risks and the measures available to avoid or reduce those risks.

When must a PIA be completed?

Among other circumstances prescribed by law, a PIA is required for certain information system or electronic service delivery projects involving personal information and before information is disclosed outside Quebec. It is also useful when a change presents a significant risk.

How long is personal information retained?

Only for the period required for the stated purpose and applicable obligations. Exact periods must appear in an internal schedule aligned with WordPress, emails, logs, backups and service providers.

What happens during a confidentiality incident?

The organization must contain the event, assess the risk, take measures to reduce injury, maintain a register and, where there is a risk of serious injury, promptly notify the CAI and affected individuals in accordance with applicable rules.

Can I request access or a correction?

Yes, subject to the conditions prescribed by law. Use the Contact page and select the privacy-related reason without immediately sending a complete identity document or medical record.

Does this policy guarantee that no incident will occur?

No. It defines a framework for prevention, detection, response and improvement. No measure eliminates every risk, which is why controls, backups, reviews and an incident procedure are important.

Do you have a question or concern?

Contact the Privacy Officer

Submit a request, complaint or report through the privacy channel. Describe the context without attaching a medical record or complete identity document to your first message.

Dr Sylvain Desforges, B.Sc., D.O., N.D., osteopath

Editorial information, sources and limitations

This content is intended to inform patients about sciatica, possible causes, warning signs, and care options. It does not replace an individualized assessment.

AuthorDr Sylvain Desforges, B.Sc., D.O., N.D., osteopath
Medical or editorial reviewSOS Sciatique / TAGMED editorial team
Publication dateJuly 3, 2026
Last reviewedJuly 19, 2026

Reference sources

References are selected according to the subject of the page: guidelines, systematic reviews, then institutional resources.

Complementary resources from the TAGMED network

These internal resources complement the clinical information and thematic linking. They do not replace national guidelines or systematic reviews.

Limitations of this information

The information on this page is general. It does not constitute a diagnosis, prescription, or guarantee of results. Pain radiating into the leg may have several causes; assessment should consider clinical history, examination findings, symptom progression, and, when appropriate, complementary tests.

When to seek urgent medical care

Seek urgent medical care if you experience loss of bladder or bowel control, saddle anesthesia, major or progressive leg weakness, unexplained fever, pain after significant trauma, or severe pain that rapidly worsens.