Many small business owners are searching for someone to appoint as their privacy officer. That’s the wrong question. Until action is taken, the role is already assigned, and it belongs to the person with the highest authority in the organization.
This page explains who is responsible by default, how to properly delegate, what needs to be published, and the specific tasks the law assigns to this person.
Quick answer: By default, the privacy officer is the person with the highest authority in the organization, typically the president or owner. The role can be delegated, in whole or in part, but only in writing. The privacy officer’s title and contact information must be published on the company’s website.
1. Who Is Responsible by Default
Article 3.1 sets the rule. Anyone who operates a business is responsible for the personal information it holds. Within the organization, the person with the highest authority is responsible for ensuring compliance with and implementation of the law, and holds the role of privacy officer.
In plain terms: if you haven’t done anything, your privacy officer is your president, CEO, or owner. This is not an empty box waiting to be filled. The role is already assigned, along with every obligation that comes with it.

2. How to Delegate Properly
The same Article 3.1 permits delegation: the person with the highest authority can delegate this role in writing, in whole or in part, to anyone. Three things to keep in mind.
- The delegation must be in writing. A note in board minutes or a signed letter will do. A verbal agreement does not satisfy the law.
- It can be partial. You can assign access request handling to one person and incident management to another.
- It can apply to anyone. The law does not restrict delegation to employees, so an external consultant can be named.
One caution: delegating does not erase the company’s responsibility under the first paragraph of Article 3.1.
3. The Publication Requirement
The third paragraph of Article 3.1 is the first thing an outsider can verify. The privacy officer’s title and contact information must be published on the company’s website, or if the company has no website, made accessible by any other appropriate means.
The law says “title and contact information.” It does not say “name.” Publishing a line such as “Privacy Officer, dedicated email address, phone number” satisfies the letter of the law and avoids having to update the website every time the person changes. Whether to publish a name is a business decision, worth validating with your legal counsel.
One practical point follows from this requirement: the published address must be monitored. Access requests arrive through it, and the 30-day response deadline starts running the moment they land, as do incident reports.
4. What the Privacy Officer Actually Does
The law assigns specific tasks to this person, scattered throughout the text.
- They approve governance policies and practices, under Article 3.2.
- They are consulted at the outset of any project subject to a privacy impact assessment, under Article 3.3, and can recommend protective measures at any stage of the project, under Article 3.4.
- They are consulted when assessing the risk of harm following a confidentiality incident, under Article 3.7.
- They document communications made without consent to a person or organization capable of reducing risk after an incident, under Article 3.5.
- They respond in writing to access and correction requests within 30 days, under Article 32.
Nothing on this list requires a law degree. Everything on it requires access to information and authority to act.

5. Internal or External: How to Choose
The useful criterion is not legal expertise. It’s access to information and authority to act.
Choose someone internal if they know your processes, have the authority to stop a project, and can bring leadership into action during an incident. In a small business, that’s often the CEO, CFO, or HR director.
Bring in an external resource if no one internally has the time or the perspective. Plan for an internal point of contact in that case, because an external consultant has neither system access nor operational authority in the middle of the night.
A common mistake is naming the IT manager. This role is not a technical one. Your IT person, or your managed IT services provider, is an essential support for inventory, logging, and documentation, not the decision-maker.
6. The Governance Policy Under Article 3.2
This is the document the privacy officer approves and the company must publish. Article 3.2 sets the minimum content: the framework for retaining and destroying personal information, the roles and responsibilities of staff throughout the information lifecycle, and a complaint-handling process.
These policies must be proportionate to the nature and scale of the company’s activities. The second paragraph requires publication: detailed information about them must be published in plain, clear language on the company’s website. The wording leaves room for a public version that is shorter than the internal document.
Article 3.3 also requires a privacy impact assessment for any project involving the acquisition, development, or overhaul of an information system. The word “acquisition” is the one that catches people off guard: switching payroll software, adopting a new CRM, or migrating to a cloud service all qualify.
Frequently Asked Questions
Who should be the privacy officer in a small business?
By default, the person with the highest authority, typically the president, CEO, or owner. The role can be delegated in writing to another person, internal or external, in whole or in part.
Does the privacy officer’s name have to be published on the website?
The law requires the title and contact information. Many companies publish a role title and a dedicated email address rather than a name, which avoids updating the site every time the person changes. Have your legal counsel validate that choice.
Can you assign this role to your IT provider?
The law allows delegation to anyone, but this is not a technical role. An IT provider handles inventory, logging, and security measures. Governance decisions and responses to requests require internal authority.
Appoint, Publish, Then Equip, in Mauricie and Beyond
Appointing a privacy officer takes an hour. Giving that person the tools to do the job takes a bit more: a data inventory, access logs, search procedures, and backup records. That’s what our IT services for small businesses cover, serving clients from Trois-Rivières across Quebec. To talk it over, use our contact form or call 450-231-3836.
This guide simplifies legal obligations. It is not legal advice and does not replace reading the actual legislation or consulting a legal professional. Legal references point to the Act Respecting the Protection of Personal Information in the Private Sector (CQLR, chapter P-39.1), as amended by Law 25.