Business IT projects · Across Québec Request a quoteFrançais

Law 25 IT assessment

A Law 25 IT assessment examines the IT measures that support your personal information obligations: where that information sits in your systems, who can access it, how incidents are recorded, what your vendors do with it, how it is destroyed and which security measures protect it. It produces a status review and a list of measures to prioritize.

Updated on

It is neither legal advice nor a compliance project: the assessment does not make the company compliant and does not certify it. Under section 3.1 of the Act respecting the protection of personal information in the private sector, the company is responsible for protecting the personal information it holds, and "the person exercising the highest authority" acts as the person in charge of the protection of personal information, a function that may be delegated in writing. The obligations themselves are explained in the guide Law 25: what Quebec SMBs must do on the IT side; this page describes the assessment of IT measures.

Short answer

You describe your systems, your vendors and the personal information you handle: your request is reviewed by the Courtier TI team, then entrusted to the IT services company that will prepare your quote. The scope of the assessment and the deliverables are set with you.

What the quote should cover

  • The scope: systems, vendors and types of information covered
  • Mapping of personal information in your systems and cloud services
  • Review of access and accounts
  • Verification of the IT means that feed the incident register
  • The list of vendors that process information, with their processing location
  • Review of retention, destruction and backup practices
  • A findings report and a prioritized action plan, delivered to your person in charge

The steps of a Law 25 IT assessment

  1. Scoping meeting with management and the person in charge of the protection of personal information
  2. Inventory of systems, cloud services and vendors
  3. Mapping of personal information and its flows
  4. Review of access, logs, backups and destruction practices
  5. Findings report and prioritized action plan
  6. Presentation to the person in charge and management

What the assessment examines, section by section

  • Security measures (s. 10): are the measures in place reasonable given the sensitivity, purpose, quantity, distribution and medium of the information?
  • Access within the company (s. 20): does each employee access only the information needed for their duties?
  • Incident register (s. 3.8): can your systems retrieve the information the Regulation respecting confidentiality incidents requires in the register (s. 7), such as the date of the incident and the number of persons concerned?
  • Destruction or anonymization (s. 23): is information whose purposes have been achieved actually destroyed, including in backups, old computers and mailboxes?
  • Vendors (ss. 18.3 and 17): does each vendor that processes information have a written contract, and are those processing it outside Québec identified?
  • System projects (s. 3.3): are ongoing acquisition, development or redesign projects flagged to the person in charge for a privacy impact assessment?

For security measures, the assessment relies on the Canadian Centre for Cyber Security's baseline cyber security controls, which serve as a reference point for SMBs. For each item, it records what is in place, what is missing and the evidence observed.

The deliverables

The main deliverable is a findings report: the mapping of personal information in your systems, the status of each item examined and the gaps found. It comes with an action plan ranked by priority, with the person responsible and the estimated effort for each measure.

The report also serves the person in charge of the protection of personal information: vendors to review, projects to submit to a privacy impact assessment, information useful for describing the company's practices. It does not replace the decisions the Act assigns to that person.

What the assessment does not do

  • It does not give legal advice on interpreting the Act
  • It does not draft the governance policies and practices required by section 3.2; it can provide the IT input for them
  • It does not assess, in the company's place, the risk of injury from an incident (s. 3.7)
  • It does not transfer the responsibility of the company or of its person in charge

If the assessment uncovers a confidentiality incident, the Incident response page describes what to do; the decision to notify the Commission d'accès à l'information and the persons concerned belongs to the company.

Questions to ask yourself before requesting a quote

  • Who acts as the person in charge of the protection of personal information?
  • Which systems hold information about your clients and employees?
  • Do you have a list of your IT and cloud vendors?
  • Do you already keep a register of confidentiality incidents?
  • Are new system projects under way?
  • Who will receive the report and follow up on the action plan?

Pitfalls to avoid

  • Presenting the assessment as proof that the company meets the Act
  • Leaving the person in charge of the protection of personal information out of the process
  • Limiting the assessment to servers and forgetting cloud services and shared files
  • Forgetting backups and old devices when looking at destruction
  • A report with no owners or priorities for the measures
  • Never repeating the exercise after adding systems or vendors

What to specify in your request

  • The approximate number of employees and computers
  • The main systems and cloud services used
  • The types of personal information handled
  • Your current IT vendors
  • Existing documents: policies, register, contracts
  • The deliverables wanted: report, action plan, presentation

You can then describe your project: the team will contact you to clarify your needs and provide a quote.

Frequently asked questions

Does the assessment make our company compliant with Law 25?

No. It describes the state of your IT measures and proposes a plan. Responsibility for protecting personal information remains with the company and its person in charge of the protection of personal information, under section 3.1 of the Act.

Is this legal advice?

No. The assessment covers IT measures. For interpreting the Act, the company turns to its legal advisers; the guide Law 25: what Quebec SMBs must do on the IT side presents the obligations in plain terms.

Who should take part in the assessment?

The person in charge of the protection of personal information, someone from management, your current IT provider if you have one, and the owners of the main systems. Cloud vendors may be asked for some answers.

Does the assessment cover our vendors?

It lists the vendors that process personal information for you, checks that a written contract exists (s. 18.3) and identifies those that process information outside Québec (s. 17). The legal analysis of contracts remains with your advisers.

Should the assessment be repeated?

It is useful to repeat it after a significant change: a new system, a new vendor, a move to the cloud. The action plan also helps track progress between two assessments.

Law 25 IT assessment

Audits, penetration testing and compliance

Request a quote