Saint-Jean-sur-Richelieu
IT services in Saint-Jean-sur-Richelieu: the technical side of Law 25
Law 25 makes no distinction between a multinational and an office of eight. It asks for a privacy officer, a register and security measures, and the last of those is where a small business gets stuck. OKTO Solutions takes on the part that happens inside your systems, from Trois-Rivières, about 180 km from Saint-Jean-sur-Richelieu.
For an SMB in Saint-Jean-sur-Richelieu, Law 25 comes down to three things that can be checked: a named privacy officer whose title is published, a register of every confidentiality incident, and security measures in place. OKTO Solutions handles the technical side from Trois-Rivières, about 180 km away. The legal assessment stays with the company and its advisor.
What does Law 25 require from an SMB in Saint-Jean-sur-Richelieu?
A small business in Saint-Jean-sur-Richelieu falls under Law 25 as soon as it holds personal information, whatever its headcount. Three obligations are quick to check. A privacy officer holds the role, with a title and contact details shown on the company website. A register records each confidentiality incident, reported or not. Reasonable security measures protect the data. OKTO Solutions works on that third obligation and feeds the second: a technical inventory of where the information lives, multi-factor authentication, a review of permissions, encryption of laptops, monitoring of workstations and accounts, and dated documentation of what was put in place. OKTO is not a law firm and does not declare any business compliant. The work is carried out from Trois-Rivières, about 180 km away, with no office and no staff in Saint-Jean-sur-Richelieu. Decisions that are legal in nature stay with the company and with the advisor it chooses.
The first move
Who is the privacy officer in a small company?
You already have one. The law gives the role to the person with the highest authority, whether or not that person volunteered. In a small business that means the owner or the president, who often finds out by reading a page like this one.
The role can be delegated in writing, to an HR director, a controller, sometimes an outside advisor. The role itself does not go away. The designated person answers when someone asks where their data is, rules on whether an incident has to be reported, and keeps the register.
Then comes the visible part: publishing the officer’s title and contact details on the website. It is the fastest step in the whole process, and the first thing a customer or a partner looks at to see whether you have started.
The role moves from the president to a director through a written delegation, then her title appears on the site.
The division of work
What falls to your management, and what falls to OKTO?
Part of the process is about decisions and documents. The other part happens in servers, mailboxes and accounts. The table draws the line.
| Obligation | Your company | OKTO |
|---|---|---|
| Privacy officer named and published (s. 3.1) | Your management decides who holds the role and signs the delegation. | Supplies the web page and the technical point of contact. |
| Confidentiality incident register (s. 3.8) | Your privacy officer keeps the register and hands it to the Commission on request. | Supplies the technical trail for each incident. |
| Notice to the Commission and to individuals (s. 3.5) | The decision to notify belongs to your company. | Establishes the scope, the date and what was affected. |
| Governance policies (s. 3.2) | Your management writes them with its legal advisor. | Then applies the retention periods in the tools. |
| Reasonable security measures (s. 10) | You decide who is entitled to what. | Handles almost all of it. |
The sections cited are from the Act respecting the protection of personal information in the private sector. Each obligation and the official sources are covered in our Law 25 guide for Quebec SMBs.
The technical work
Which technical measures support compliance?
None of them makes a business compliant on its own. Together, they let you show what was done, and when.
- The technical inventory. Where personal information lives: workstations, servers, mailboxes, SharePoint, OneDrive, backups, third-party applications.
- Access control. Multi-factor authentication, a review of permissions, closing former employees’ accounts, a log of what gets opened.
- Encryption. Laptops, removable media and backups, so a lost device does not mean lost files.
- Detection. Monitoring of workstations and accounts that leaves a usable trail when something happens.
- Retention and destruction. The periods stated in your policies, applied in the tools and not left on paper.
- Dated documentation. Proof of the measures and of the moment they were put in place.
The register
Why is the incident register a technical problem?
On paper, it is a table. Date of the incident, date you learned of it, nature of the information, number of people concerned, cause, measures taken, decision to report or not. Seven columns.
The hard part is filling them with facts. Most incidents in a small business are mundane: the payroll list sent to the wrong recipient, a misplaced USB key, an HR folder open to the whole office for years, the account of someone who left six months ago and was never closed. For each of them, somebody has to be able to piece together what happened in the systems.
Without centralized logging, the register gets filled with guesses. Monitoring produces the trail, and the trail feeds the register your privacy officer keeps.
One record in the register: the officer, the date, the nature of the incident, the measures taken.
The ground
Saint-Jean-sur-Richelieu, about 180 km from Trois-Rivières
Saint-Jean-sur-Richelieu is the seat of the Le Haut-Richelieu regional county municipality, in Montérégie. The city sits on both banks of the Richelieu River, and Autoroute 35 crosses it from north to south.
OKTO Solutions offers its services to SMBs in Saint-Jean-sur-Richelieu without being established there. For this kind of mandate, distance matters little: finding where personal information sits, reviewing who can reach what, turning on multi-factor authentication and setting up monitoring are all done over the network. The file handed over afterwards documents what was done and when.
What follows is routine. Access gets reviewed, inactive accounts get removed and backups get tested as part of our managed IT services, at the level chosen among our Base, Standard and Complet plans. Hardening of email and shared files goes through our Microsoft 365 services. To find out where to begin, write to us through the contact page.
Questions and answers
Your questions about Law 25 in Saint-Jean-sur-Richelieu
Does Law 25 apply to a Saint-Jean-sur-Richelieu business with eight employees?
Who is our privacy officer?
Does an email sent to the wrong person really go in the register?
Can OKTO tell us whether we are compliant?
Who decides whether an incident has to be reported to the Commission?
Do we need to meet you in person in Saint-Jean-sur-Richelieu to get started?
Do you know where your personal information is?
If the answer is no, that is where we start: the technical inventory, then access. You receive a file stating what was done, and on what date.
Reviewed by Antonio Pazzi, president of OKTO Solutions · updated