Law 25: what boards actually need to document
Beyond the incident register, three obligations still fly under the radar of Quebec organizations.
By SpaceNet
Since Law 25 came fully into force, most organizations have appointed a person in charge of personal information and opened an incident register. That is necessary, but it is not enough.
1. Privacy impact assessments
Any project to acquire, develop or overhaul a system handling personal information requires an assessment. In practice, they are rarely documented before go-live.
2. Transfers outside Quebec
A cloud provider hosting data outside the province triggers a prior assessment. Many organizations do not know where their SaaS vendors actually store data.
3. Published governance policies
The rules governing personal information must be published in plain language. A twenty-page legal document does not meet that requirement.
What the board should ask for
- The list of assessments completed in the last twelve months
- The inventory of vendors hosting personal information outside Quebec
- The date of the last review of the published policy
References: Act to modernize legislative provisions as regards the protection of personal information (S.Q. 2021, c. 25); Commission d’accès à l’information guidance.