Skip to content

Privacy law is a responsibility question before it is a legal one.

Law 25 in Quebec and PIPEDA at the federal level both start with the same practical question: who is accountable for personal information, and can they show it? IT support is part of the answer. It is not the whole answer, and this page does not pretend otherwise.

Lire cette page en français

Scope of this page

What this page is — and is not.

This page explains, in plain terms, where day-to-day IT practice intersects with Law 25 and PIPEDA obligations: access control, retention, breach-readiness, and vendor data handling. It is not legal advice, not a compliance certification, and not a substitute for qualified privacy counsel reviewing your specific obligations. A business subject to Law 25, PIPEDA, or both should confirm its exact requirements with a lawyer or privacy professional.

Where practice meets obligation

IT can maintain the mechanism. It cannot set the policy.

Obligation areaWhat IT can help maintainWhat stays a business/legal decision
Access controlWho can technically reach personal information, and a record of changesWho should be authorized to access it, by role
Retention & disposalApplying a defined retention or deletion schedule to systemsSetting what that schedule actually is
Incident readinessBackups, logs, and technical detail available if an incident happensLegal breach-notification obligations and timelines
Vendor & cloud dataDocumenting where data is stored and which vendors touch itReviewing vendor contracts for privacy terms

Before a review

Questions worth answering before someone else asks them.

A privacy review — self-initiated or prompted by an inquiry — usually starts with questions IT infrastructure can help answer directly.

  • Where does personal information actually live: which systems, which vendors, which country
  • Who currently has access, and does that match who should have access
  • What happens, technically, if an employee's device holding client data is lost
  • How long is data kept after it is no longer needed, and is that enforced or just written down
See how Microsoft 365 identity and data changes are handled day to day

What this covers / what it doesn't

A useful line, not a blurred one.

IT practice can help withAccess logs, retention settings, encrypted devices, a documented vendor list, and technical support during an incident.

A privacy professional should confirmWhether your organization is subject to Law 25, PIPEDA, or both; exact notification obligations; and whether a privacy impact assessment is legally required.

Provincial differences compound this

More than one province means more than one layer.

A team with people or offices in more than one province may face different provincial rules layered on top of PIPEDA. See how provincial differences are tracked across locations . The responsible move is naming the gap and finding the right professional to close it — not guessing.

Turn your IT context into a clear scope.

A scope conversation covers your team, Microsoft 365, devices, vendors, and responsibilities to transfer. You leave with the scope questions that need answers—without sharing secrets.

Discuss your IT scope