Skip to main content
SpaceNet Cybersécurité
FR EN
Request a consultation

Governance 1 min read

Law 25: what boards actually need to document

Beyond the incident register, three obligations still fly under the radar of Quebec organizations.

By SpaceNet

Since Law 25 came fully into force, most organizations have appointed a person in charge of personal information and opened an incident register. That is necessary, but it is not enough.

1. Privacy impact assessments

Any project to acquire, develop or overhaul a system handling personal information requires an assessment. In practice, they are rarely documented before go-live.

2. Transfers outside Quebec

A cloud provider hosting data outside the province triggers a prior assessment. Many organizations do not know where their SaaS vendors actually store data.

3. Published governance policies

The rules governing personal information must be published in plain language. A twenty-page legal document does not meet that requirement.

What the board should ask for

  • The list of assessments completed in the last twelve months
  • The inventory of vendors hosting personal information outside Quebec
  • The date of the last review of the published policy

References: Act to modernize legislative provisions as regards the protection of personal information (S.Q. 2021, c. 25); Commission d’accès à l’information guidance.