Managed Compliance

Privacy program consulting for Law 25, PIPEDA and GDPR

Find out which privacy laws reach your company, Law 25, PIPEDA or GDPR, how much of the work your SOC 2 program already covers, and what is left to build.

Ali Aleali

Ali Aleali, CISSP, CCSP

Co-Founder & Principal Consultant

Former security architect for Bank of Canada and Payments Canada. CISSP, CCSP, more than twenty years in enterprise security. Leads every engagement.

Connect on LinkedIn

What the engagement covers

Find out which privacy laws reach you, and how much of the work your security program has already done.

icon-5

Scoping read

Which privacy laws reach you, decided on where the individuals are, wherever the company is incorporated. In writing.

icon-9

Personal information inventory and data flow map

What you hold, why, where it flows, and which transfers leave the province or the country.

icon-6

Privacy impact assessments

The Law 25 section 3.3 assessment and the separate section 17 assessment for information communicated outside Quebec, plus the register that shows the process exists.

icon-7

Gap analysis mapped to your existing controls

Law 25, PIPEDA and the GDPR mapped to the SOC 2 criteria and ISO 27001 controls that already produce the evidence.

icon-3

Remediation plan sequenced by dependency

An owner and an effort estimate against each item.

icon-4

Questionnaire answers

Written answers to the privacy sections of customer security questionnaires and vendor reviews.

Assess, Build, Operate, applied to privacy

The assessment is the project; the standing officer role afterwards is a separate engagement. A documented methodology, led by a senior architect with more than ten years of enterprise security experience and a CISSP.

01

Assess

Scoping read, inventory, data flow map and gap analysis, built from your systems and interviews inside your environment.

02

Build

Retention rules, consent and lawful-basis records, PIA process and register, transfer assessments, and the privacy sections of your questionnaire library.

03

Operate

Where no one in the company can hold the privacy officer role, Truvo offers it separately as an ongoing engagement.

What you hold at the end

Built once against the real set of laws, mapped to the controls you already operate.

  • Applicability determination, in writing

  • Personal information inventory

  • Data flow and transfer map

  • Privacy impact assessment register

  • Gap analysis against Law 25, PIPEDA and GDPR

  • Control mapping to SOC 2 and ISO 27001

  • Remediation plan with owners and effort

  • Questionnaire answer set

What changes

More of the safeguard work is already done than most teams expect. Less of the rest is.

Who this is for, and who it is not

Truvo is not a law firm. Where an obligation turns on a contested reading, the assessment names it for your counsel.

Frequently asked questions

It follows the people whose information you hold, so a company anywhere in Canada that serves customers in Quebec is inside Law 25, and one with users in Europe is inside the GDPR. PIPEDA applies federally to commercial activity, and several provinces have their own statutes for health information. The scoping read settles which of these reach you and which do not, in writing, so the program is built once against the real set. Truvo is not a law firm and this is not legal advice. Where an obligation turns on a genuinely contested reading, the assessment says so and names it for your counsel instead of guessing.

More than most teams expect on the security half, and less than they expect on the rest. Access control, encryption, logging, vendor management and incident response already produce most of the safeguard evidence a privacy regulator would look for, filed under a control number instead of a section number. What those frameworks do not produce is the inventory of what personal information you hold and why, the lawful basis or consent record behind each use, retention rules that are enforced instead of stated, and the workflow for answering an individual who asks for their data. The gap analysis marks which rows are done and which are the real work.

No, and the two are worth keeping apart. Law 25 requires that the role be designated, defaulting to the person with the highest authority unless it is delegated in writing, and PIPEDA requires an accountable individual as well. That is a standing role someone has to hold. This service is the assessment work: finding out where you stand and what has to change. If the outcome is that no one in the company can hold the role, Truvo offers it separately as an ongoing engagement.

It is part of it, and under Law 25 section 3.3 it is mandatory for any project that acquires, develops or overhauls a system handling personal information, with the privacy officer involved from the start. Truvo runs those assessments as part of the engagement and leaves behind the register that shows the process exists, since a single completed document does not demonstrate one. Teams that want to run the first one themselves can start from the template Truvo publishes, which includes the crosswalk from each safeguard to the SOC 2 and ISO 27001 controls already covering it.

No. The inventory and the data flow mapping are built from your systems, your documentation and interviews with the people who operate them, working inside your environment. Truvo does not take custody of, store, or host your production data or the personal information inside it in order to assess how it is handled. On an engagement about privacy that answer matters more than usual, and it is one your own customers are increasingly asking you for in vendor review.

Talk to the architect who would do the work

A 30-minute call. We look at your environment and say plainly whether we can help and what it would take.

From the blog: privacy law in Canada

After Bill C-27: Quebec Law 25 and Canadian Privacy Costs

For three years, the dominant story in Canadian privacy law was the federal one. Bill C-27, the Digital Charter Implementation Act, was on track to ...