After Bill C-27: Quebec Law 25 and Canadian Privacy Costs
For three years, the dominant story in Canadian privacy law was the federal one. Bill C-27, the Digital Charter Implementation Act, was on track to ...
A named privacy officer for Law 25, PIPEDA and GDPR, doing the assessments, breach decisions and access requests every month, without a full-time hire.
Co-Founder & Principal Consultant
Former security architect for Bank of Canada and Payments Canada. CISSP, CCSP, more than twenty years in enterprise security. Leads every engagement.
Connect on LinkedInA named senior practitioner, the same person month to month, working to the designation your company records in writing.
Your company keeps the designation with a named person inside it. Truvo does the work of the role and is the standing contact for the operational load.
The Law 25 section 3.3 assessment, the section 17 assessment before personal information is communicated outside Quebec, and the register that shows both happen.
With the record regulators expect to see afterwards.
Access, correction, erasure and portability, and the retention rules behind them.
New products, features and vendors reviewed before they go live.
The privacy sections of customer security questionnaires and vendor reviews, and the standing contact your website has to publish.
The standing role is the Operate phase; the assessment sizes it. A documented methodology, led by a senior architect with more than ten years of enterprise security experience and a CISSP.
Which laws reach you, what personal information you hold, where it flows, and how much of an officer's week the role will take.
The designation recorded in writing, the register, the request and breach procedures, and the published contact point.
Assessments, requests, breach decisions, vendor and product reviews, and questionnaire answers, month to month, by the same person.
The record a regulator, a customer or a board asks to see, kept current by the person doing the work.
Written delegation of the privacy officer role
Published officer title and contact point
Privacy impact assessment register
Section 17 transfer assessments
Breach assessment and reporting records
Individual request log with retention rules
Vendor and product privacy review records
The role has an owner, a record and a rhythm. The CEO stops being the default.
A named person inside your company holds the designation, and a named practitioner does the work beside them.
Products, features and vendors get reviewed before they go live, and the register shows it.
Access requests and breach decisions get handled on time, with the record regulators expect afterwards.
The privacy sections of customer security reviews go to the practitioner, not back to engineering or the CEO.
Most companies want the privacy assessment first, because it sizes how much of an officer's week the role will take.
You hold personal information about people in Quebec or elsewhere in Canada and have to name a privacy officer
The role rests with an executive who has neither the time nor the background for it
A customer or regulator has asked who your privacy officer is
Privacy impact assessments, breach assessments and individual requests have no standing owner
You need the statutory data protection officer appointment under the GDPR, or an EU representative
You want a template pack with a mailbox behind it
You have not yet established which privacy laws reach you; start with the privacy program assessment
It requires the role to exist and to be held by someone. Under section 3.1 the person exercising the highest authority in the organization carries it, which means it lands on your CEO unless it is delegated in writing. Where it is delegated, the officer's title and contact details have to be published on your website, so the designation is a public fact. PIPEDA asks for an accountable individual as well. Truvo is not a law firm and this is not legal advice. Where an obligation turns on a contested reading, we name it for your counsel instead of guessing.
This is the question to settle with your counsel before anything is signed, and it is worth settling early. Section 3.1 places the responsibility on the person exercising the highest authority and allows it to be delegated to a member of the organization's personnel, which is not obviously the same thing as handing it to an outside supplier. The structure that avoids the argument is the one we use: your company keeps the designation with a named person inside it, and Truvo does the work of the role beside them, from the assessments through to the regulator contact. Your board still has a named owner and that owner is no longer carrying it alone.
A named senior practitioner, the same person month to month, and you meet them before you commit. Truvo's privacy line is led by co-founder Oksana Zbyranyk, whose background is third-party risk and security architecture. This is not a helpdesk queue and it is not a template pack with a mailbox behind it.
The assessment is a project with an end. It establishes which laws reach you, what you hold, where the gaps are, and what to do about them. This is the standing role afterwards. Most companies want the assessment first, because it is what tells you how much of an officer's week the role will take. Companies already carrying an obligation, or already asked by a customer or a regulator who their privacy officer is, tend to start here and fold the assessment into the first quarter.
Not as the statutory appointment. The GDPR's data protection officer is a defined role with its own independence and reporting conditions, and a company established outside the EU may also need an EU representative, which Truvo based in Ottawa cannot be. What we do cover is the work underneath: mapping what you hold about people in Europe, the assessments, the vendor and transfer reviews, and the answers your customers ask for. If your GDPR exposure is the reason you are reading this page, say so on the call and we will tell you plainly which parts we can hold and which you need somebody in Europe for.
A 30-minute call. We look at your environment and say plainly whether we can help and what it would take.
For three years, the dominant story in Canadian privacy law was the federal one. Bill C-27, the Digital Charter Implementation Act, was on track to ...