Outsourced Privacy Officer for Quebec (RPRP)
A statutory role, not a job title
Under the Act respecting the protection of personal information in the private sector, as amended by Law 25 (An Act to modernize legislative provisions as regards the protection of personal information), every enterprise must have a person in charge of the protection of personal information. The role is commonly called the Privacy Officer, and in French the responsable de la protection des renseignements personnels, or RPRP.
The default holder is not chosen. The Act assigns the function to the person exercising the highest authority within the enterprise: the chief executive, the president, the managing partner. That person may delegate the function, in whole or in part, in writing, to any person, including a person who is not part of the enterprise. The title and contact information of the person in charge must be published on the enterprise’s website.
This matters for companies outside Quebec because the obligation attaches to the enterprise’s activity in Quebec, not to its address. A company in Chicago or Amsterdam with Quebec customers or Quebec employees has a person in charge under Quebec law whether or not it has ever named one. If nobody was named, the role sits with the chief executive by operation of the statute.
Why the function is delegated to outside counsel
Quebec’s Privacy Officer carries defined statutory duties rather than a general advisory brief. Handing them to an executive with no background in the Act tends to produce one of two outcomes: the duties are performed nominally, or they consume time the executive does not have. Delegating outside the organization is expressly contemplated by the Act.
Where the delegate is a member of the Barreau du Québec, the exchanges that feed the function are covered by professional secrecy, and the analysis behind a decision (whether an incident presents a risk of serious injury, whether an access request may be refused) is legal analysis from the outset rather than an internal opinion later reviewed by counsel.
What the mandate covers
Governance and documentation. The enterprise must establish and implement governance policies and practices for personal information, proportionate to its size and activities, covering retention and destruction, the roles and responsibilities of staff throughout the information life cycle, and a process for handling complaints. The person in charge approves them. Detailed information about them is published on the website in clear and simple language.
Requests from individuals. Access, rectification, withdrawal of consent, de-indexing and portability requests are received and answered under the person in charge. The Act sets a 30-day response period. A refusal is given in writing, with reasons, and with the information the person needs to apply to the Commission d’accès à l’information du Québec (CAI) for review.
Confidentiality incidents. Quebec’s term is a confidentiality incident: unauthorized access to, use or communication of personal information, its loss, or any other breach in its protection. The person in charge assesses whether the incident presents a risk of serious injury, decides on notification to the CAI and to the persons concerned, documents the reasonable measures taken to reduce the risk and prevent recurrence, and maintains the register of incidents that the enterprise must be able to produce to the CAI on request.
Privacy impact assessments. The Act requires the person in charge to be involved from the outset of any project to acquire, develop or overhaul an information system or electronic service delivery involving personal information, and a PIA is also required before personal information is communicated outside Quebec.
Dealings with the CAI. Complaints, requests for review, inspections and investigations are handled through the person in charge, with the enterprise’s own counsel where litigation counsel is separately retained.
What the arrangement does not do
Delegation moves the function; it does not move the enterprise’s liability. The enterprise remains answerable for its own compliance. An outsourced Privacy Officer also depends on being told things: the mandate is only as good as the organization’s willingness to route incidents, new projects and vendor changes through it. Those escalation paths are set out at the start of an engagement rather than discovered during an incident.
How an engagement is set up
It begins with a written delegation instrument, signed by the person exercising the highest authority, defining which parts of the function are delegated and which are retained. Then an intake review of what already exists: policies, notices, registers, vendor agreements, records of past incidents. The published contact details are updated. Internal escalation paths and response times are agreed. From there the function runs on an ongoing basis, with a defined route for urgent matters, because incident timelines in Quebec are measured in days.
Companies that already run a GDPR data protection officer usually keep it. The two roles coexist; the Quebec function has its own statutory content and its own regulator, and the delegation is drafted so the boundary between them is explicit.
Jurisdiction
Erwan Jonchères is a member of the Barreau du Québec and practises Quebec law. Satoshi Legal does not provide legal services governed by the law of another Canadian province or territory.
Frequently asked questions
Must the person in charge be located in Quebec? The Act does not impose a place of residence. It requires that the function be held, that the title and contact information be published, and that the duties actually be carried out within the deadlines the Act sets. What causes problems in practice is not geography but availability: a published contact that nobody monitors, or a delegate who cannot be reached when an incident timeline is running.
Can our GDPR data protection officer simply take on the Quebec role? They can be the delegate, if the delegation is made in writing by the person exercising the highest authority and they are equipped for the Quebec duties. The roles are not interchangeable in content. A DPO brief built around GDPR tasks does not cover the Quebec incident register, the Quebec assessment triggers, or the review path to the CAI.
If we delegate the role, is our chief executive off the hook? Not entirely. Delegation transfers the exercise of the function, not the enterprise’s compliance obligations. The delegation instrument should say plainly what has been delegated and what has been retained, so that both sides know who decides what.
Do we still need this if we only have a handful of Quebec customers? The obligation to have a person in charge does not scale down to zero, though the governance framework itself is expressly proportionate to the enterprise’s size and activities. For a small Quebec footprint, the practical answer is usually a light mandate: a valid written delegation, a published contact, workable incident and request procedures, and analysis called on when something actually happens.
Discuss a delegation mandate
If your organization needs a person in charge of the protection of personal information for Quebec, or wants a written delegation reviewed before it is signed, the first conversation is a scoping one. Book a consultation at satoshilegal.cliogrow.com/book, write to bonjour@satoshi.legal, or call +1 438 506-1792.
