Testing and defence led by a published security researcher with six CVEs, including a CVSS 9.1 Mirai botnet kill-switch.
All security →SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.
All frameworks →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →Quebec Law 25 is the province's modernized private-sector privacy law, which significantly strengthened how organizations collect, use, and protect personal information about Quebec residents. It introduced mandatory breach reporting, privacy-by-default, consent rules, and transparency around automated decision-making. Its requirements phased in through 2022, 2023, and 2024.
Law 25 requires organizations to appoint a person responsible for privacy, run privacy impact assessments for certain projects, and report confidentiality incidents that pose a risk of serious injury to the regulator (the CAI) and affected individuals.
Section 12.1 requires meaningful disclosure when a decision is based exclusively on automated processing, which directly affects AI products. Penal fines can reach 25 million CAD or 4 percent of worldwide turnover, with administrative monetary penalties capped at 10 million CAD or 2 percent.
traztech delivers Quebec Law 25 readiness sprints for startups and growth-stage companies, led by a published security researcher.
Book a callFor a broader look at getting audit-ready, see our SOC 2 readiness work, or talk to a fractional CISO about building a program around it.