Quebec Law 25 Readiness Assessment
Achieve full compliance with Quebec's modernized private-sector privacy regime before CAI regulatory audits and severe statutory penalties.
What This Engagement Covers
Quebec's Law 25 (formerly Bill 64) represents Canada's most stringent privacy legislation, introducing GDPR-caliber requirements and penalties. Any business collecting, storing, or handling personal information of Quebec residents - regardless of where the business is headquartered - must comply. We assess your privacy operations against every phase of the law, establishing mandatory governance, privacy impact assessments, consent controls, and cross-border transfer protections before the Commission d'accès à l'information (CAI) investigates.
What This Means for Canadian Businesses
Law 25 carries Canada's highest statutory privacy penalties: administrative monetary penalties up to $10,000,000 CAD or 2% of worldwide turnover, and penal fines up to $25,000,000 CAD or 4% of worldwide turnover. Furthermore, Law 25 mandates that any transfer of personal information outside Quebec (including to other Canadian provinces) requires a documented Privacy Impact Assessment (Évaluation des facteurs relatifs à la vie privée - EFVP). Lorikeet Security Canada equips Canadian and international organizations with the policies, impact assessments, and technical controls required to satisfy CAI standards.
Domains & Controls We Assess
We evaluate every technical, operational, and administrative requirement against authoritative criteria.
Privacy Governance & Officer Designation
- Designation and public publishing of the Privacy Officer (Personne responsable de la protection des renseignements personnels)
- Governance policies, retention schedules, and data lifecycle management documentation
- Workplace privacy training and staff accountability framework
Privacy Impact Assessments (EFVP / PIA)
- Mandatory EFVP protocol for electronic service development, acquisition, and redesign
- Documented cross-border and inter-provincial transfer assessments (transfers outside Quebec)
- Risk mitigation and contractual privacy safeguards with third-party service providers
Consent Framework & Confidentiality by Default
- Default highest-level confidentiality settings on all consumer-facing technology
- Clear, granular consent mechanisms separate from general terms and conditions
- Opt-in requirements for sensitive personal information, profiling, and tracking technologies
Mandatory Confidentiality Incident Response
- Confidentiality Incident Log maintenance (mandated by CAI regulation)
- Real risk of serious injury threshold assessment protocol
- Expedited dual-notification procedures for CAI and affected individuals
Data Subject Rights & Transparency
- Right to de-indexing / erasure (\"right to be forgotten\") fulfilment workflow
- Data portability protocols for structured, commonly used technological formats
- Transparency notices for automated processing and individual profiling algorithms
Engagement Deliverables
Everything you need to prove control operating effectiveness to your auditors and enterprise clients.
Law 25 Statutory Compliance Gap Assessment Report
Privacy Impact Assessment (EFVP) Policy and Working Templates
Cross-Border and Inter-Provincial Transfer Risk Assessment Matrix
CAI-Compliant Confidentiality Incident Registry and Playbook
Governance Policies and Clear-Language Consent Notices
Executive Briefing on CAI Enforcement Priorities and Penalties
Trusted by Growing Businesses
We came to Lorikeet Security with not so small task of tracking down the source of a cyber incident. Lorikeet Security looked at attack vectors and they set up a full test environment and really showed they knew what they were doing. With amazing analytics reports on down to the minute of login attempts. The level of detail that Cyber Insurance Companies wish they had in house - Those reports are an invaluable tool and give confidence and value add to the executive level for pre or post ransomware attacks.
We used Lorikeet Security for a PTaaS pentest and briefly tried their ASM tool - both were amazing. Fast tests, accurate findings, and everything handled through a modern interface. The report summary, live chat, asset management, and live quoting features of the portal really stand out. Their 'white glove' touch contributed to a 10/10 experience. They're truly changing the pentest game with the new portal clients can use.
Common Questions
Yes. Law 25 applies to any organization that collects, holds, uses, or communicates the personal information of individuals residing in Quebec, even if the enterprise has no physical office or employees in the province. Cross-border SaaS providers, e-commerce retailers, and service firms serving Quebec clients fall under CAI jurisdiction.
An Évaluation des facteurs relatifs à la vie privée (EFVP), or Privacy Impact Assessment (PIA), is legally mandatory under Law 25 before embarking on any electronic service delivery, software acquisition, or data system overhaul that touches personal information. Crucially, an EFVP is also mandatory before transferring personal data outside Quebec - including transfers to cloud providers located in other Canadian provinces or the United States.
Law 25 introduces two tiers of enforcement: administrative monetary penalties issued directly by the CAI of up to $10,000,000 CAD or 2% of worldwide turnover, and penal proceedings with fines reaching up to $25,000,000 CAD or 4% of worldwide turnover. Additionally, individuals have a private right of action for statutory damages of at least $1,000 CAD for intentional or gross negligence.
Often Scoped Together
Ready for Your Law 25 (Loi 25) Readiness Assessment?
Speak directly with our senior Canadian compliance team. We establish your exact scope, quote a fixed flat-rate price, and deliver a definitive timeline.