Law 25: 5 questions to ask before building or buying software
Since September 2023, Québec's Law 25 requires a privacy impact assessment at the start of any information system project. Here are the questions to ask your vendor.
Since September 22, 2023, most of the new obligations under Québec's Law 25 apply to businesses. One of them directly affects your IT projects: any acquisition, development or overhaul of a system that processes personal information requires a privacy impact assessment (PIA) from the very start of the project.
In other words, privacy is no longer something you fix at the end. It is decided when you choose and design the software. Here are five questions to ask before you sign.
1. Where will the data be hosted?
If personal information is communicated outside Québec, the law requires a prior assessment to make sure it will be adequately protected. Hosting in Canada, ideally in Québec, makes that analysis much simpler.
2. Who will have access to what?
Insist on role-based access: each user only sees the information they need for their work. Also ask how access is removed when an employee leaves.
3. Are settings confidential by default?
The law requires technology products and services offered to the public to provide the highest level of confidentiality by default. Well-designed software applies this principle everywhere: minimal collection, limited retention, sharing turned off until it is needed.
4. What happens if there is an incident?
The software should log access and changes so you can tell what happened. Your vendor should also help you assess an incident and meet your obligations: keeping a register, and notifying the Commission d'accès à l'information and the people affected when there is a risk of serious injury.
5. Is data destroyed at the end?
Information must not be kept longer than necessary. Ask how the software handles retention periods, destruction or anonymization, and how you get your data back if you change vendors.
Why it matters
Non-compliance can be costly: the law provides for administrative monetary penalties of up to $10M or 2% of worldwide revenue, and penal fines of up to $25M or 4%, according to this analysis by McCarthy Tétrault. Beyond the risk, an application designed for privacy earns the trust of your clients and employees.
To go further, the Commission d'accès à l'information publishes a guide to privacy impact assessments (in French). At Synergice, we document the safeguards of every piece of software we deliver to make your assessment easier.
This article provides general information and is not legal advice.