ComplianceBy Xavier Peich

Privacy impact assessments in Quebec: a guide for private businesses

Three sections of Quebec's private-sector privacy law require a PIA. When your business owes one, what goes in it, who writes it and who signs it.

Privacy impact assessments in Quebec: a guide for private businesses

Search Google from Montréal for "efvp", the French acronym for a privacy impact assessment. Of the nine results on the first page, seven come from a public body or a university, from the Commission d'accès à l'information to Université Laval. They are written for a ministry or a campus. When we build a client area or an online store for a business (our web services), the assessment still belongs to that business, even when we are the ones writing the code.

This is the private-sector version: the three situations in which the law requires a privacy impact assessment (PIA), what the document contains, how big it should be, and who holds the pen. If your project is an AI agent, our article on PIAs before deploying an AI agent covers that case in detail. This one sets out the general rule.

The short answer, for the busy

A private business in Quebec must conduct a privacy impact assessment (PIA) in three situations set out in the Act respecting the protection of personal information in the private sector: before any project to acquire, develop or overhaul an information system or electronic service delivery system involving personal information (section 3.3), before communicating personal information outside Québec or entrusting a provider outside Québec with collecting, using, communicating or keeping it on its behalf (section 17), and before communicating information without consent for study, research or statistical purposes (section 21). The law prescribes neither a format nor a content. The Commission d'accès à l'information publishes a guide and an optional report template. The assessment must be proportionate to the sensitivity of the information, the purposes of its use, its quantity, its distribution and the medium on which it is stored. The person in charge of the protection of personal information is consulted from the outset of the project, and senior management approves the conclusions.

Three triggers, and no more

The CAI's guide lists five situations in which an assessment is mandatory. Two apply only to public bodies. A business is left with three, each tied to a specific section of the Act.

A system project (section 3.3). Any project to acquire, develop or overhaul an information system or electronic service delivery system that collects, uses, communicates, keeps or destroys personal information. The obligation has applied since September 22, 2023. "System" is broader than it sounds: the CAI says it is not necessarily computerized, and its examples include payroll software, video surveillance and artificial intelligence systems. On the electronic services side, it lists the members' area of a website and the mobile app. The same section adds a detail most SMBs miss: the new system must be able to hand a person the computerized information collected from them in a structured, commonly used technological format.

A communication outside Québec (section 17). Before communicating personal information outside Québec, and also before entrusting a provider outside Québec with collecting, using, communicating or keeping it on your behalf. That second sentence is aimed squarely at cloud hosting. And "outside Québec" means outside Québec: a server in Toronto counts. We covered this case in detail in the article on data processed outside Quebec.

A communication for research (section 21). You may pass information to a researcher without consent (the Act also covers study and statistics) if the PIA concludes that five criteria set by the Act are met, including that only the necessary information is communicated. The agreement that follows is sent to the CAI and takes effect 30 days after it is received.

When the answer is no

The CAI's guide offers two ways out. The first is a project that involves no personal information and clearly poses no privacy risk. One warning, though: harmless-looking data, once cross-referenced, can reveal something about a person. The second is a project that was already complete when the obligation came into force. A system installed before September 22, 2023 and used as is triggers nothing. The day you overhaul it, the obligation comes back.

Even then, the CAI recommends writing a very simple note: the outline of the project and the reason you are not doing a PIA. Half a page, dated, filed with the project. If someone asks two years from now, you will have a written answer instead of a memory.

What the document contains, and how big it should be

The guide is blunt about it: the law does not say how to conduct a PIA, nor what form or content the report should take. The CAI boils the thinking down to three factors: the project's compliance with the law and its underlying principles, the identification of privacy risks and their consequences, and the strategies to avoid or reduce those risks.

Its report template (version 1.1, April 2024, a Word file, in French like the guide) breaks the work into a summary and seven sections: project description, roles and responsibilities, personal information involved and scope of the assessment, compliance with obligations, risks and mitigation strategies, action plan, and report approval. The template is optional. It does show you what an inspector expects to find.

The CAI states the central test flatly: a project that is not necessary and proportionate is not lawful. According to the guide, that means a legitimate and real objective, a rational link between the project and that objective, minimal intrusion on privacy, and benefits that outweigh the harm to the people concerned.

On size, section 3.3 sets the rule: the assessment is proportionate to the sensitivity of the information, its purposes, its quantity, its distribution and its medium. According to the guide, the number of people involved, the time invested and the level of detail therefore vary with the project. For a limited project, meeting notes or emails can even document the process, but a pile of scattered pieces makes follow-up and any audit harder. One short document beats ten emails.

Who writes it, who signs it

Responsibility lies with the organization that holds the information. The guide expressly rules out subcontractors, suppliers and partners: they can help with the analysis, but the PIA is not theirs. Your provider owes you precise answers. The document is yours.

Internally, the law requires one consultation: the person in charge of the protection of personal information, from the outset of the project (section 3.3). That person may suggest protection measures at any stage (section 3.4). By default, it is the person with the highest authority in the business, who can delegate the function in writing (section 3.1).

The signature comes from the guide rather than the Act: senior management must accept the conclusions and endorse the risks that remain despite the measures taken. The template provides for names, titles, signatures and dates. In an SMB where the owner has stayed privacy officer by default, the same person is consulted and signs. That is legal, but you lose the second look. A split that works better: whoever knows the system drafts, the privacy officer reviews and suggests measures, the owner signs.

A worked example: the client list in a US-hosted CRM

Take a fictional 25-employee business moving its client list, until now a spreadsheet on an office server, to a customer relationship management system (CRM) hosted in the United States. Names, contact details, purchase history, and a free-text notes field where sales reps write whatever they like.

Two triggers apply at once: acquiring a system (section 3.3) and having a provider outside Québec keep the information (section 17). Since the law imposes no format, a single document can cover both, as long as it addresses the four elements of section 17: sensitivity, purposes, protection measures (contractual ones included) and the legal framework of the destination State.

The inventory is short and not very sensitive, with one exception: the free-text notes. That is where you find "off work until March", a piece of health information nobody decided to collect. On the probability-severity grid the guide proposes (two scales from 1 to 4, multiplied), this risk scores high probability and high severity, 3 × 3 = 9, "very high". The fix is simple: a written rule on what never goes into the CRM, and structured fields instead of free text wherever possible. Probability drops to 1 and the level to 3, "moderate".

Then come role-based access instead of "everyone sees everything", and a check that the CRM can export a client's record in a structured format, as section 3.3 requires. Finally, the written agreement section 17 demands, which must take the assessment's results into account: the provider's data processing agreement gets read against the PIA instead of accepted with one click. The owner signs, and the document is reopened the day the business plugs in a marketing automation module, because a PIA has to follow the project over time.

A project this size fits in a few pages. Most of the time goes into the free-text field, and that is where the exercise pays off.

Where to start

List the projects under way or planned that touch personal information, and test each one against the three triggers. For those that trip one, download the CAI's guide and template, consult your privacy officer now, and document the scale you chose. For the others, write the half page explaining why not.

The report is mainly your evidence: the CAI can ask to see it, and it is what shows your process during an inspection or investigation. For the full tour of the other obligations, see our Law 25 summary for SMBs.

Launching a site with a client area, an online store or an internal tool? Ask your provider, us included, the three questions your PIA will need answered: where the data lives, who can reach it, and how it exports.

→ Let's talk about your project, or see what our web services include.

This article explains legal obligations to help an SMB ask the right questions; it is not legal advice. The text of the Act respecting the protection of personal information in the private sector and the positions of the Commission d'accès à l'information govern: for your specific situation, consult a lawyer.

Xavier PeichWritten byXavier Peich