Law 25 Compliance Review for Organizations Operating in Quebec
Why a company outside Quebec ends up in scope
Law 25 (An Act to modernize legislative provisions as regards the protection of personal information) applies to the personal information an enterprise collects, holds, uses or communicates in the course of activities carried on in Quebec. Where your servers sit and where your company is incorporated are not the deciding factors. If you sell to Quebec residents, employ people in Quebec, run a platform with Quebec users, or process personal information on behalf of a Quebec client, the obligations reach you.
Companies that already run a GDPR programme, a CCPA programme or a federal Canadian programme usually have most of the raw material. What they do not have is the Quebec overlay: the designated Privacy Officer, the confidentiality incident register, the assessment obligation attached to communications outside Quebec, the transparency rules that apply when technology is used to identify, locate or profile a person, and the private right of action Quebec added.
What the compliance review covers
Mapping and inventory. We identify the categories of personal information you hold, the purposes they serve, where the data physically resides, which service providers touch it, and how long you keep it. The output is a picture of your actual flows, not a description of your intended flows.
Governance and internal documentation. Designation of the Privacy Officer and publication of that role, the governance policies and practices required by the Act, retention and destruction rules, staff training, and the internal register of confidentiality incidents.
Contracts and service providers. Review of the clauses in your supplier, processor and client agreements against what Quebec requires, including the written mandate to a service provider and the confidentiality undertakings that must accompany it.
Communications outside Quebec. Where personal information is sent to another province or another country, an assessment is required before the transfer and, in many cases, contractual terms must follow the data. We work through that assessment with you rather than handing you a blank template.
Privacy impact assessments (PIA). We identify the projects that call for a PIA, including acquisitions, developments or overhauls of information systems and electronic service delivery projects, and set up a process your team can run on its own afterwards.
Individual rights and incident response. Access, rectification, de-indexing, portability and the disclosure of automated decision making, plus the notification path to the Commission d’accès à l’information du Québec (CAI) and to affected individuals when a confidentiality incident presents a risk of serious injury.
How the review runs
The engagement begins with a scoping call to confirm what is in scope and who needs to be involved. We then send a structured request for documents and run working sessions with the people who actually handle the data, usually product, engineering, HR and whoever owns your vendor relationships. We analyse the gap between your current practices and the requirements in force, then deliver and walk through the findings.
What you receive
A written report setting out, obligation by obligation, what is in place, what is missing and what is exposed. Findings are ranked so that you can distinguish what needs fixing before your next release from what belongs in a twelve month plan. The report includes drafting priorities for the documents you are missing, a proposed governance structure sized to your organisation, and a remediation sequence with owners. It is written to be handed to a board, an acquirer or an enterprise client conducting vendor due diligence.
Who does the work
Erwan Jonchères has been a member of the Barreau du Québec since 2018 and has taught personal information protection at the university level. The review is carried out by the lawyer you speak to, not passed down a chain.
Jurisdiction
Erwan Jonchères is a member of the Barreau du Québec and practises Quebec law. Satoshi Legal does not provide legal services governed by the law of another Canadian province or territory. Where your situation also engages federal, foreign or other provincial law, we say so and work alongside your existing counsel in those jurisdictions.
Find out where you actually stand
Book a scoping call at satoshilegal.cliogrow.com/book, or write to bonjour@satoshi.legal describing your connection to Quebec (customers, employees, an establishment or data). Answered within one business day.
