After Bill C-27: Quebec Law 25 and Canadian Privacy Costs
For three years, the dominant story in Canadian privacy law was the federal one. Bill C-27, the Digital Charter Implementation Act, was on track to ...
Find out which privacy laws reach your company, Law 25, PIPEDA or GDPR, how much of the work your SOC 2 program already covers, and what is left to build.
Co-Founder & Principal Consultant
Former security architect for Bank of Canada and Payments Canada. CISSP, CCSP, more than twenty years in enterprise security. Leads every engagement.
Connect on LinkedInFind out which privacy laws reach you, and how much of the work your security program has already done.
Which privacy laws reach you, decided on where the individuals are, wherever the company is incorporated. In writing.
What you hold, why, where it flows, and which transfers leave the province or the country.
The Law 25 section 3.3 assessment and the separate section 17 assessment for information communicated outside Quebec, plus the register that shows the process exists.
Law 25, PIPEDA and the GDPR mapped to the SOC 2 criteria and ISO 27001 controls that already produce the evidence.
An owner and an effort estimate against each item.
Written answers to the privacy sections of customer security questionnaires and vendor reviews.
The assessment is the project; the standing officer role afterwards is a separate engagement. A documented methodology, led by a senior architect with more than ten years of enterprise security experience and a CISSP.
Scoping read, inventory, data flow map and gap analysis, built from your systems and interviews inside your environment.
Retention rules, consent and lawful-basis records, PIA process and register, transfer assessments, and the privacy sections of your questionnaire library.
Where no one in the company can hold the privacy officer role, Truvo offers it separately as an ongoing engagement.
Built once against the real set of laws, mapped to the controls you already operate.
Applicability determination, in writing
Personal information inventory
Data flow and transfer map
Privacy impact assessment register
Gap analysis against Law 25, PIPEDA and GDPR
Control mapping to SOC 2 and ISO 27001
Remediation plan with owners and effort
Questionnaire answer set
More of the safeguard work is already done than most teams expect. Less of the rest is.
Decided on where the individuals are, so the program is built once against the real set.
Access control, encryption, logging, vendor management and incident response evidence is filed under section numbers as well as control numbers.
What personal information you hold, why, for how long, and where it goes. The part no security framework produces.
The privacy section of a customer's questionnaire has written answers and a register behind them.
Truvo is not a law firm. Where an obligation turns on a contested reading, the assessment names it for your counsel.
You hold personal information about people in Quebec, elsewhere in Canada, or in Europe
A customer, regulator or board has asked how that information is handled
You hold SOC 2 or ISO 27001 and want to know how far it carries into privacy
Projects that touch personal information have never had a privacy impact assessment
You need legal advice on a specific obligation; bring your counsel and we work beside them
You need someone to hold the privacy officer role now; that is the fractional privacy officer engagement
You handle no personal information at all
It follows the people whose information you hold, so a company anywhere in Canada that serves customers in Quebec is inside Law 25, and one with users in Europe is inside the GDPR. PIPEDA applies federally to commercial activity, and several provinces have their own statutes for health information. The scoping read settles which of these reach you and which do not, in writing, so the program is built once against the real set. Truvo is not a law firm and this is not legal advice. Where an obligation turns on a genuinely contested reading, the assessment says so and names it for your counsel instead of guessing.
More than most teams expect on the security half, and less than they expect on the rest. Access control, encryption, logging, vendor management and incident response already produce most of the safeguard evidence a privacy regulator would look for, filed under a control number instead of a section number. What those frameworks do not produce is the inventory of what personal information you hold and why, the lawful basis or consent record behind each use, retention rules that are enforced instead of stated, and the workflow for answering an individual who asks for their data. The gap analysis marks which rows are done and which are the real work.
No, and the two are worth keeping apart. Law 25 requires that the role be designated, defaulting to the person with the highest authority unless it is delegated in writing, and PIPEDA requires an accountable individual as well. That is a standing role someone has to hold. This service is the assessment work: finding out where you stand and what has to change. If the outcome is that no one in the company can hold the role, Truvo offers it separately as an ongoing engagement.
It is part of it, and under Law 25 section 3.3 it is mandatory for any project that acquires, develops or overhauls a system handling personal information, with the privacy officer involved from the start. Truvo runs those assessments as part of the engagement and leaves behind the register that shows the process exists, since a single completed document does not demonstrate one. Teams that want to run the first one themselves can start from the template Truvo publishes, which includes the crosswalk from each safeguard to the SOC 2 and ISO 27001 controls already covering it.
No. The inventory and the data flow mapping are built from your systems, your documentation and interviews with the people who operate them, working inside your environment. Truvo does not take custody of, store, or host your production data or the personal information inside it in order to assess how it is handled. On an engagement about privacy that answer matters more than usual, and it is one your own customers are increasingly asking you for in vendor review.
A 30-minute call. We look at your environment and say plainly whether we can help and what it would take.
For three years, the dominant story in Canadian privacy law was the federal one. Bill C-27, the Digital Charter Implementation Act, was on track to ...