The 12 checks in this quiz
Answer each one No, In progress, or Yes. Anything not fully in place comes with a concrete next step.
Accountability
-
Have you formally put someone in charge of privacy (a privacy officer), as Law 25 requires?
Appoint a person accountable for privacy and publish their contact. Law 25 requires it, and it gives privacy a clear owner.
-
Do you have a clear, current privacy policy published where customers can easily find it?
Publish a plain-language privacy policy that reflects what you actually do, and keep it current.
Data & consent
-
Do you know what personal information you collect, why, where it is stored, and who can access it (a data inventory)?
Build a simple data inventory: what you collect, why, where it lives, and who can reach it. Nearly every other privacy obligation depends on it.
-
Do you get meaningful consent to collect and use personal information, and let people withdraw it?
Collect meaningful consent for how you use personal data and make it easy to withdraw. Law 25 raised the bar on what counts as valid consent.
Rights & retention
-
Do you keep personal information only as long as you need it, then securely dispose of it?
Set retention periods and securely delete or anonymise data you no longer need. Holding data forever is both a risk and a compliance gap.
-
Do you have a process to handle access, correction and deletion requests from individuals?
Create a process to respond to access, correction and deletion (de-indexing) requests within the required timeframes.
-
If you send personal data outside Quebec/Canada or to vendors, have you assessed and disclosed it?
Identify where personal data goes, including cloud vendors abroad, assess the privacy implications, and disclose transfers. Law 25 requires this.
Breach & vendors
-
Do you have a breach-response process, including notifying the regulator and affected people when required?
Document a breach-response process covering containment and the notifications Law 25 and PIPEDA require, plus a register of incidents.
-
Do you assess privacy impact before new projects or systems that use personal data (a privacy impact assessment)?
Run a privacy impact assessment before significant new uses of personal data, Law 25 expects this for higher-risk projects.
-
Are your vendors and processors bound by contracts that protect the personal data you share with them?
Put privacy terms in vendor contracts so processors are obligated to protect the data you share, and confirm they can.
-
Do staff who handle personal information get privacy training?
Train staff who handle personal information on consent, handling and breach reporting.
-
If you use automated decision-making or profiling, can you explain it to the people affected?
If you make automated decisions about people, be ready to inform them and explain the logic, Law 25 grants individuals that right.
Privacy is a programme, not a policy page
Real privacy readiness is part legal, part operational: knowing what data you hold, controlling who can reach it, and being able to respond when someone asks or something goes wrong. We help Canadian businesses put the practical, technical side in place, the inventory, access controls, retention and breach response, so the policy actually reflects reality.