Managed Security

Fractional privacy officer

A named privacy officer for Law 25, PIPEDA and GDPR, doing the assessments, breach decisions and access requests every month, without a full-time hire.

Ali Aleali

Ali Aleali, CISSP, CCSP

Co-Founder & Principal Consultant

Former security architect for Bank of Canada and Payments Canada. CISSP, CCSP, more than twenty years in enterprise security. Leads every engagement.

Connect on LinkedIn

What the role covers

A named senior practitioner, the same person month to month, working to the designation your company records in writing.

icon-8

A named practitioner beside your designated officer

Your company keeps the designation with a named person inside it. Truvo does the work of the role and is the standing contact for the operational load.

icon-6

Privacy impact assessments

The Law 25 section 3.3 assessment, the section 17 assessment before personal information is communicated outside Quebec, and the register that shows both happen.

icon-2

Breach assessment and the reporting decision

With the record regulators expect to see afterwards.

icon-9

Individual requests

Access, correction, erasure and portability, and the retention rules behind them.

icon-7

Privacy review before release

New products, features and vendors reviewed before they go live.

icon-4

Questionnaires and the public contact point

The privacy sections of customer security questionnaires and vendor reviews, and the standing contact your website has to publish.

Assess, Build, Operate, applied to the privacy officer role

The standing role is the Operate phase; the assessment sizes it. A documented methodology, led by a senior architect with more than ten years of enterprise security experience and a CISSP.

01

Assess

Which laws reach you, what personal information you hold, where it flows, and how much of an officer's week the role will take.

02

Build

The designation recorded in writing, the register, the request and breach procedures, and the published contact point.

03

Operate

Assessments, requests, breach decisions, vendor and product reviews, and questionnaire answers, month to month, by the same person.

What your company holds

The record a regulator, a customer or a board asks to see, kept current by the person doing the work.

  • Written delegation of the privacy officer role

  • Published officer title and contact point

  • Privacy impact assessment register

  • Section 17 transfer assessments

  • Breach assessment and reporting records

  • Individual request log with retention rules

  • Vendor and product privacy review records

What changes in the first quarter

The role has an owner, a record and a rhythm. The CEO stops being the default.

When a fractional privacy officer is the right call, and when it is not

Most companies want the privacy assessment first, because it sizes how much of an officer's week the role will take.

Frequently asked questions

It requires the role to exist and to be held by someone. Under section 3.1 the person exercising the highest authority in the organization carries it, which means it lands on your CEO unless it is delegated in writing. Where it is delegated, the officer's title and contact details have to be published on your website, so the designation is a public fact. PIPEDA asks for an accountable individual as well. Truvo is not a law firm and this is not legal advice. Where an obligation turns on a contested reading, we name it for your counsel instead of guessing.

This is the question to settle with your counsel before anything is signed, and it is worth settling early. Section 3.1 places the responsibility on the person exercising the highest authority and allows it to be delegated to a member of the organization's personnel, which is not obviously the same thing as handing it to an outside supplier. The structure that avoids the argument is the one we use: your company keeps the designation with a named person inside it, and Truvo does the work of the role beside them, from the assessments through to the regulator contact. Your board still has a named owner and that owner is no longer carrying it alone.

A named senior practitioner, the same person month to month, and you meet them before you commit. Truvo's privacy line is led by co-founder Oksana Zbyranyk, whose background is third-party risk and security architecture. This is not a helpdesk queue and it is not a template pack with a mailbox behind it.

The assessment is a project with an end. It establishes which laws reach you, what you hold, where the gaps are, and what to do about them. This is the standing role afterwards. Most companies want the assessment first, because it is what tells you how much of an officer's week the role will take. Companies already carrying an obligation, or already asked by a customer or a regulator who their privacy officer is, tend to start here and fold the assessment into the first quarter.

Not as the statutory appointment. The GDPR's data protection officer is a defined role with its own independence and reporting conditions, and a company established outside the EU may also need an EU representative, which Truvo based in Ottawa cannot be. What we do cover is the work underneath: mapping what you hold about people in Europe, the assessments, the vendor and transfer reviews, and the answers your customers ask for. If your GDPR exposure is the reason you are reading this page, say so on the call and we will tell you plainly which parts we can hold and which you need somebody in Europe for.

Talk to the architect who would do the work

A 30-minute call. We look at your environment and say plainly whether we can help and what it would take.

From the blog: Law 25 and PIPEDA

After Bill C-27: Quebec Law 25 and Canadian Privacy Costs

For three years, the dominant story in Canadian privacy law was the federal one. Bill C-27, the Digital Charter Implementation Act, was on track to ...