Skip to content
IT White GloveManaged IT support · Advisory · Canada
Menu

Law 25 and PIPEDA guide · Canada · EN / FR

Turn Law 25 and PIPEDA into decisions someone actually owns.

Ce guide est aussi tenu en français. Conformité Loi 25 et LPRPDE →

Law 25 and PIPEDA are usually handed to IT as a compliance checklist instead of a set of decisions. Leadership needs to know which choices—about data inventory, consent, vendor contracts, and breach notice—are genuinely theirs to make, and which a lawyer or privacy officer must confirm.

The decision to enable

Decide who owns each privacy obligation, what evidence proves it is met, and what still needs legal confirmation—before a regulator or a client asks first.

Start with what data actually exists, not the policy template

Law 25 and PIPEDA both assume the organization can say what personal information it holds, where it lives, who can reach it, and why it is kept. A privacy policy copied from a template does not answer that. Build a plain inventory of personal information by system and vendor before writing any compliance language around it.

  • Systems and vendors that store or process personal information
  • Purpose for keeping each category, not just its existence
  • Retention or deletion practice for information no longer needed

Separate legal obligations from IT decisions that support them

A lawyer or privacy officer determines what the law requires in a given case. IT’s job is to make the supporting decisions real: who can access personal information, how consent choices are technically enforced, and how a breach would actually be detected and contained. Confusing the two leaves both roles assuming the other has it covered.

Confirm vendor contracts say what the relationship actually is

Cloud, payroll, and line-of-business vendors that handle personal information need contract language covering their obligations, sub-processors, breach notification timelines, and data location—not just a general privacy statement on their website. Review this at renewal, not only when a new vendor is onboarded.

  • Named sub-processors and where they operate
  • Breach notification timeline the vendor commits to in writing
  • What happens to the data if the contract ends

Rehearse breach notice before you need it

Both regimes set expectations for notifying affected people and, for Law 25, Quebec’s regulator, within a defined process. Waiting until an actual incident to figure out who drafts the notice, who approves it, and how affected individuals are contacted turns a bad day into a worse one. Confirm the sequence and the accountable people now.

Decision frame

What leadership should be able to verify.

These criteria do not produce a score. They expose the questions that need resolution before a responsible decision.

CriterionUseful signalLeadership question
InventoryPersonal information is mapped by system and vendor, not assumed.Could you name every system holding personal information today?
OwnershipIT decisions and legal obligations have separate, named owners.Who confirms what the law requires, and who implements the control?
Vendor termsContracts name sub-processors, breach timelines, and data location.Which vendor contracts have never been checked for this language?
Breach readinessThe notification sequence and approvers are agreed before an incident.Who drafts and approves a breach notice, and how fast can it go out?

Practical scenarios

The same discipline applied to different decisions.

A Quebec client asks where their data is processed

Situation: A client or partner asks, in writing, which vendors process their personal information and where those vendors are located.

Useful response: Answer from the inventory and vendor contract review, not from memory—confirm the answer with the vendor if a gap appears rather than guessing.

Boundary: This guide does not provide legal advice on Law 25 or PIPEDA obligations; a privacy lawyer or officer should confirm what applies to your specific situation.

A departing employee had broad access to client files

Situation: An employee leaves the organization, and no one can confirm exactly what personal information they could access or export before departure.

Useful response: Treat this as an access-control gap to close immediately—not an isolated HR event—and use it to test whether access reviews happen on a schedule or only after something goes wrong.

Boundary: This guide does not investigate a specific incident or determine whether a breach notification obligation was triggered.