Privacy Impact Assessments (PIA) Under Quebec Law
A Quebec obligation with no exact equivalent elsewhere
Law 25 (An Act to modernize legislative provisions as regards the protection of personal information) added a privacy impact assessment (PIA) requirement to the Act respecting the protection of personal information in the private sector. In French the exercise is called an évaluation des facteurs relatifs à la vie privée, or EFVP.
Teams arriving from the GDPR often assume the PIA is Quebec’s version of the data protection impact assessment. The two are cousins, not twins. A DPIA is triggered by a risk threshold: processing likely to result in a high risk. The Quebec PIA is triggered by the nature of the project itself. Two of its three triggers have nothing to do with how risky the processing looks, and one of them (sending personal information out of the province) catches ordinary operations that most companies outside Quebec run every day.
When the Act requires one
Information system and electronic service delivery projects. An enterprise must conduct a PIA for any project to acquire, develop or overhaul an information system or an electronic service delivery involving personal information. Buying a CRM, migrating a payroll platform, rebuilding a customer portal, adding an analytics layer: if personal information is involved, the trigger is met, whatever the perceived risk level. The person in charge of the protection of personal information must be consulted from the outset of the project, not shown the result at the end.
Communicating personal information outside Quebec. Before personal information is communicated outside Quebec, the enterprise must conduct a PIA. The same rule applies when the enterprise entrusts a person or body outside Quebec with collecting, using, communicating or keeping personal information on its behalf.
Two points matter for a non-Quebec reader. First, outside Quebec means outside Quebec. Ontario counts. Delaware counts. Ireland counts. There is no internal-market carve-out and no distinction between another Canadian province and a foreign country. Second, an enterprise headquartered elsewhere that collects personal information from people in Quebec and routes it to its own servers abroad is communicating that information outside Quebec, and the assessment falls on it.
Use or communication without consent for study, research or statistics. Where personal information is to be communicated without the consent of the persons concerned for those purposes, a PIA must be conducted before the communication takes place, and the communication is governed by a written agreement.
What the assessment must weigh
The Act does not prescribe a template. It sets a standard of proportionality: the PIA must be proportionate to the sensitivity of the information concerned, the purpose for which it is to be used, its quantity, its distribution and the medium on which it is stored. A short assessment for a low-volume, low-sensitivity project is not a defect. A short assessment for a health data platform is.
For a communication outside Quebec, the analysis has a defined content. It considers the sensitivity of the information, the purposes for which it will be used, the protection measures that would apply to it (including contractual measures), and the legal framework applicable in the state where it would be communicated, including the personal information protection principles applicable there. The information may be communicated only if the assessment establishes that it would receive adequate protection, in particular in light of generally recognized principles regarding the protection of personal information. The communication must then be the subject of a written agreement that takes into account the results of the assessment and any terms agreed on to mitigate the risks identified.
There is no adequacy list in Quebec. The CAI has not issued mandatory standard clauses. Each enterprise reaches its own conclusion on its own record, and the CAI may ask to see the assessment.
How the exercise runs
The work is usually four stages. Mapping the project: what personal information, from whom, for what, through which systems and which suppliers, held where. Identifying the risks to the persons concerned, not only to the enterprise. Testing the project against the obligations the Act imposes (consent, transparency, retention and destruction, security, privacy by default for technological products and services, automated decision transparency where it applies). Then recording the mitigation measures adopted, the residual risk accepted, and who accepted it.
The output is a document the enterprise keeps. Its value is largely evidentiary: it shows what was considered, when, and on what basis, at a point when nothing had gone wrong yet.
Where teams get caught
Three patterns recur. A GDPR transfer impact assessment is reused as if it were the Quebec assessment, though it answers a different statutory question and does not address the written agreement requirement. A vendor’s certifications are treated as proof of adequate protection, when the analysis calls for a view on the legal framework of the receiving state. And the PIA is opened after the vendor contract is signed, at which point the mitigation options have narrowed to whatever the supplier will agree to renegotiate.
Jurisdiction
Erwan Jonchères is a member of the Barreau du Québec and practises Quebec law. Satoshi Legal does not provide legal services governed by the law of another Canadian province or territory.
Frequently asked questions
Is a Quebec PIA the same as a GDPR data protection impact assessment? No. A DPIA is required when processing is likely to result in a high risk to individuals. The Quebec PIA is required by project type: information system and electronic service delivery projects involving personal information, communications of personal information outside Quebec, and communications without consent for study, research or statistical purposes. A DPIA can be a useful input, but it does not answer the Quebec questions on its own.
Do we need a PIA to send Quebec customer data to our head office in another province or country? Yes, where personal information is communicated outside Quebec, including to an affiliate or to your own infrastructure. The same applies when a person outside Quebec is entrusted with collecting, using, communicating or keeping the information on your behalf. The communication also has to be covered by a written agreement reflecting the results of the assessment.
How long does a PIA take? It depends on proportionality. A single low-sensitivity vendor migration can be assessed in a short, focused document. A platform handling sensitive information across several jurisdictions takes considerably longer, mostly because of the mapping stage. The determining factor is usually how well the organization already knows where its data lives.
Does the CAI have to approve the assessment? There is no prior approval or filing step. The enterprise conducts the assessment, documents its conclusion, and keeps it. The CAI may ask the enterprise to provide it, which is why the reasoning, not just the conclusion, needs to be on the page.
Have a project that may need a PIA
New platform, vendor migration, cross-border data flow, or a Quebec client asking to see your assessment: the sooner the analysis starts, the more options remain open. Book a consultation at satoshilegal.cliogrow.com/book, write to bonjour@satoshi.legal, or call +1 438 506-1792.
