Trois-Rivières, serving all of Quebec 450 231-3836 info@oktosolutions.ca
FR

Saint-Jean-sur-Richelieu

IT services in Saint-Jean-sur-Richelieu: the technical side of Law 25

Law 25 makes no distinction between a multinational and an office of eight. It asks for a privacy officer, a register and security measures, and the last of those is where a small business gets stuck. OKTO Solutions takes on the part that happens inside your systems, from Trois-Rivières, about 180 km from Saint-Jean-sur-Richelieu.

Magnifying glass resting on an IT audit report with charts

For an SMB in Saint-Jean-sur-Richelieu, Law 25 comes down to three things that can be checked: a named privacy officer whose title is published, a register of every confidentiality incident, and security measures in place. OKTO Solutions handles the technical side from Trois-Rivières, about 180 km away. The legal assessment stays with the company and its advisor.

What does Law 25 require from an SMB in Saint-Jean-sur-Richelieu?

A small business in Saint-Jean-sur-Richelieu falls under Law 25 as soon as it holds personal information, whatever its headcount. Three obligations are quick to check. A privacy officer holds the role, with a title and contact details shown on the company website. A register records each confidentiality incident, reported or not. Reasonable security measures protect the data. OKTO Solutions works on that third obligation and feeds the second: a technical inventory of where the information lives, multi-factor authentication, a review of permissions, encryption of laptops, monitoring of workstations and accounts, and dated documentation of what was put in place. OKTO is not a law firm and does not declare any business compliant. The work is carried out from Trois-Rivières, about 180 km away, with no office and no staff in Saint-Jean-sur-Richelieu. Decisions that are legal in nature stay with the company and with the advisor it chooses.

The first move

Who is the privacy officer in a small company?

You already have one. The law gives the role to the person with the highest authority, whether or not that person volunteered. In a small business that means the owner or the president, who often finds out by reading a page like this one.

The role can be delegated in writing, to an HR director, a controller, sometimes an outside advisor. The role itself does not go away. The designated person answers when someone asks where their data is, rules on whether an incident has to be reported, and keeps the register.

Then comes the visible part: publishing the officer’s title and contact details on the website. It is the fastest step in the whole process, and the first thing a customer or a partner looks at to see whether you have started.

The role moves from the president to a director through a written delegation, then her title appears on the site.

The division of work

What falls to your management, and what falls to OKTO?

Part of the process is about decisions and documents. The other part happens in servers, mailboxes and accounts. The table draws the line.

ObligationYour companyOKTO
Privacy officer named and published (s. 3.1)Your management decides who holds the role and signs the delegation.Supplies the web page and the technical point of contact.
Confidentiality incident register (s. 3.8)Your privacy officer keeps the register and hands it to the Commission on request.Supplies the technical trail for each incident.
Notice to the Commission and to individuals (s. 3.5)The decision to notify belongs to your company.Establishes the scope, the date and what was affected.
Governance policies (s. 3.2)Your management writes them with its legal advisor.Then applies the retention periods in the tools.
Reasonable security measures (s. 10)You decide who is entitled to what.Handles almost all of it.

The sections cited are from the Act respecting the protection of personal information in the private sector. Each obligation and the official sources are covered in our Law 25 guide for Quebec SMBs.

The technical work

Which technical measures support compliance?

None of them makes a business compliant on its own. Together, they let you show what was done, and when.

  1. The technical inventory. Where personal information lives: workstations, servers, mailboxes, SharePoint, OneDrive, backups, third-party applications.
  2. Access control. Multi-factor authentication, a review of permissions, closing former employees’ accounts, a log of what gets opened.
  3. Encryption. Laptops, removable media and backups, so a lost device does not mean lost files.
  4. Detection. Monitoring of workstations and accounts that leaves a usable trail when something happens.
  5. Retention and destruction. The periods stated in your policies, applied in the tools and not left on paper.
  6. Dated documentation. Proof of the measures and of the moment they were put in place.
Read this before going further. This content is for information and does not replace legal advice. Whether a specific incident gets reported is up to your company and its legal advisor, never to us.

The register

Why is the incident register a technical problem?

On paper, it is a table. Date of the incident, date you learned of it, nature of the information, number of people concerned, cause, measures taken, decision to report or not. Seven columns.

The hard part is filling them with facts. Most incidents in a small business are mundane: the payroll list sent to the wrong recipient, a misplaced USB key, an HR folder open to the whole office for years, the account of someone who left six months ago and was never closed. For each of them, somebody has to be able to piece together what happened in the systems.

Without centralized logging, the register gets filled with guesses. Monitoring produces the trail, and the trail feeds the register your privacy officer keeps.

One record in the register: the officer, the date, the nature of the incident, the measures taken.

The ground

Saint-Jean-sur-Richelieu, about 180 km from Trois-Rivières

Saint-Jean-sur-Richelieu is the seat of the Le Haut-Richelieu regional county municipality, in Montérégie. The city sits on both banks of the Richelieu River, and Autoroute 35 crosses it from north to south.

OKTO Solutions offers its services to SMBs in Saint-Jean-sur-Richelieu without being established there. For this kind of mandate, distance matters little: finding where personal information sits, reviewing who can reach what, turning on multi-factor authentication and setting up monitoring are all done over the network. The file handed over afterwards documents what was done and when.

What follows is routine. Access gets reviewed, inactive accounts get removed and backups get tested as part of our managed IT services, at the level chosen among our Base, Standard and Complet plans. Hardening of email and shared files goes through our Microsoft 365 services. To find out where to begin, write to us through the contact page.

Questions and answers

Your questions about Law 25 in Saint-Jean-sur-Richelieu

Does Law 25 apply to a Saint-Jean-sur-Richelieu business with eight employees?
Yes. The law covers any person carrying on an enterprise in Quebec who holds personal information about others. It sets no threshold for headcount or revenue. What varies with size is the scale expected: policies must be proportionate to the nature and scope of the activities.
Who is our privacy officer?
If you have not decided anything, it is the person with the highest authority in the company. That person can delegate the role in writing, in whole or in part. The title and contact details then have to be published on the company website, and that is the step most often forgotten.
Does an email sent to the wrong person really go in the register?
Yes, if it contained personal information. An unauthorized communication is a confidentiality incident under section 3.6. The register takes every incident, including those that are not reported to the Commission d’accès à l’information.
Can OKTO tell us whether we are compliant?
No. OKTO Solutions is not a law firm and does not declare a business compliant within the meaning of the law. We take on the technical side: finding the data, locking down access, detecting incidents and documenting what was done. For a legal opinion, consult a Quebec lawyer or notary.
Who decides whether an incident has to be reported to the Commission?
Your company, with its privacy officer and its legal advisor. Our part is to supply the facts: what was affected, on what date, through which account and how far it went. A decision resting on facts is easier to defend than one resting on guesses.
Do we need to meet you in person in Saint-Jean-sur-Richelieu to get started?
No. The technical inventory and the access review are done remotely. Our only office is in Trois-Rivières, about 180 km away, and we have nobody stationed in Saint-Jean-sur-Richelieu. A visit is scheduled if the mandate calls for it.

Do you know where your personal information is?

If the answer is no, that is where we start: the technical inventory, then access. You receive a file stating what was done, and on what date.

Reviewed by , president of OKTO Solutions · updated