Data location inventory
Shared drives, mailboxes, line-of-business applications, and any device that stores or syncs personal information are identified in plain language your advisor can use.
Privacy law readiness
Quebec’s Law 25 and the federal PIPEDA create real obligations around personal information—consent, incident notification, access records, and demonstrable safeguards. We are not privacy lawyers or certified auditors. What we do is the technical groundwork a privacy review actually asks for: access control, an encryption baseline, logging, and an inventory of where personal information actually lives.
Most privacy gaps start with an incomplete picture of where data sits, not with a missing policy document.
Shared drives, mailboxes, line-of-business applications, and any device that stores or syncs personal information are identified in plain language your advisor can use.
Who can currently reach client, employee, or patient information is documented—often the first thing a review actually asks to see.
Cloud applications and vendors that receive or store personal information on the business’s behalf are listed as a tracked dependency.
A review looks for demonstrable safeguards, not intentions. Ordinary, well-maintained IT hygiene covers most of this ground.
Multi-factor sign-in, least-privilege access, and account review are documented as evidence of the everyday practices already described in security essentials.
Device encryption, secure disposal, and mobile-device safeguards are confirmed and recorded rather than assumed.
What systems log, for how long, and who can review that log are clarified—an area reviews frequently probe.
Readiness support is not a substitute for legal judgment. Some decisions must stay with an accountable specialist.
Whether a specific practice satisfies Law 25 or PIPEDA, and what a privacy impact assessment must contain, is a legal or privacy-specialist determination—not ours to certify.
Whether an incident triggers a mandatory notification obligation, and to whom, is a legal decision made with qualified counsel, supported by our technical incident record.
We do not issue compliance certifications or attestations. Any required sign-off must come from a qualified, accountable assessor or legal advisor.
Prepare this
Continue
Bring the context; keep credentials out of the message.
Request an introductionDescribe the interruption, the change ahead, and how your team prefers to be kept informed. A short note is enough to begin a service-fit conversation.