Security

Real offensive depth

Testing and defence led by a published security researcher with six CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Independent assurance

Outsourced privacy
officer and DPO.

Privacy law requires a named person, not a policy page. GDPR calls it a data protection officer, Quebec Law 25 calls it the person in charge of the protection of personal information, and PIPEDA calls it the accountable individual. We hold that role for you, publish as the contact point, and handle the requests, assessments and breach decisions that come with it.

The reason this role gets outsourced. GDPR Article 38(6) says the DPO must not hold a position that determines the purposes and means of processing personal data. At most companies that disqualifies the chief executive, the CTO, the head of marketing and the head of IT, which is very nearly everyone senior enough to do it. Article 37(6) permits an external appointment under a service contract precisely so the role can exist without the conflict.

Talk about the role

Which laws require a privacy officer

Three different obligations that get treated as one. They are satisfied differently, and a single appointment can cover them only if you track them separately.

LawWhat it requiresThe part that catches people
GDPR
Articles 37, 38 and 39
A data protection officer must be designated where your core activities involve regular and systematic monitoring of individuals on a large scale, or large-scale processing of special category data. Article 37(6) allows the DPO to be external, appointed under a service contract. The DPO must report to the highest level of management, must not receive instructions on how to perform the role, and under Article 38(6) must not hold a position that determines the purposes and means of processing.
Quebec Law 25
Section 3.1 of the Private Sector Act
Every enterprise must have a person in charge of the protection of personal information. The role defaults to the person with the highest authority in the organisation, and it can be delegated in writing. The title and contact details of the person in charge have to be published on your website. This is the requirement most often missed, and it is trivially checkable by a regulator or a complainant.
PIPEDA
Principle 4.1.1 and 4.1.2
You must designate an individual accountable for compliance, and make their identity available on request. Accountability stays with the organisation even where processing is transferred to a third party. Smaller obligation than GDPR, but the accountable individual is who a complaint or an Office of the Privacy Commissioner enquiry lands on.
ISO 27701
Clause 5 and 6 extensions
The privacy information management extension to ISO 27001 expects defined privacy roles and responsibilities, assigned and documented, sitting on top of your existing ISMS. Where you already run ISO 27001, the privacy role plugs into the same governance rather than becoming a parallel structure.
Alberta and BC PIPA
Provincial private sector acts
Both require a designated individual responsible for compliance, on the same accountability pattern as PIPEDA. If you operate across provinces, one appointment usually covers the set, but the published contact point still has to exist.

Who you cannot appoint

Article 38(6) is a conflict-of-interest test, not a seniority test. Any role that determines the purposes or the means of processing is disqualified, and European regulators have enforced this more than once against companies who appointed the obvious internal candidate.

Chief Executive

Determines the purposes of processing at the highest level.

CTO or Head of Engineering

Determines the means of processing, which is the other half of the Article 38(6) test.

Head of Marketing

Owns the largest set of processing purposes in most companies.

Head of HR

Determines purposes and means for employee data specifically.

Head of IT or Security

Regulators have repeatedly found this to be conflicted, because the role decides how data is processed and stored.

What we actually do in the seat

The role is an operating commitment rather than a name on a page, which is why it is priced as an ongoing engagement.

A named, published contact point

The person a regulator, a customer or a data subject reaches. Named on your privacy notice and, for Quebec Law 25, published on your website with a title and contact details.

Monitoring compliance

Reviewing what you actually do against what your privacy notice and your records of processing say you do. Article 39 puts this on the DPO explicitly.

Records of processing (ROPA)

Building and maintaining the Article 30 record, which is the artifact regulators request first and the one most companies cannot produce.

DPIAs and privacy impact assessments

Advising on whether an assessment is required, and running it. Required under GDPR Article 35 for high-risk processing and under Law 25 for any project involving personal information.

Data subject and access requests

Handling requests within statutory deadlines, including the ones that arrive as a complaint rather than a form.

Breach assessment and notification

Deciding whether a confidentiality incident meets the reporting threshold, and running the notification inside the deadline. Law 25 and GDPR set different tests and different clocks.

Vendor and cross-border transfers

Assessing processors, transfer mechanisms and the Law 25 obligation to assess privacy protection before disclosing outside Quebec.

Training and advice

Practical guidance to the teams that touch personal data, rather than an annual slide deck nobody remembers.

What we cannot be. We cannot act as your Article 27 EU representative. That appointment has to be established in a member state where your data subjects are, and we are a Canadian firm. If you are a non-EU controller offering goods or services into the EU, that is a separate appointment, and we will tell you when it applies rather than selling around it. The same honesty applies elsewhere in our work: see what we cannot sign on the internal audit page.

Privacy and security, run together

Privacy and security overlap on access control, retention, vendor management and breach response, and they contradict each other when they are run by people who do not talk. Where we already run your SOC 2 or ISO 27001 programme, the privacy role attaches to the same governance and the same evidence rather than building a parallel structure that has to be reconciled later.

If your gap is security leadership rather than privacy accountability, that is a fractional CISO engagement instead, and the two are frequently bought together. For the specific Quebec obligations, our Law 25 readiness work covers the wider programme, and the privacy law finder will tell you for free which laws apply to you before you talk to anybody.

Privacy officer questions, answered

Can a data protection officer be external?

Yes. GDPR Article 37(6) states that the DPO may be a staff member or may fulfil the tasks on the basis of a service contract, so an external appointment carries exactly the same standing as an internal one. For most companies under a few hundred people an external appointment is also the only way to satisfy Article 38(6), because everyone senior enough to do the job is already conflicted.

Do we actually need a DPO?

Under GDPR it is mandatory if you are a public authority, if your core activities involve regular and systematic monitoring of individuals on a large scale, or if your core activities involve large-scale processing of special category or criminal conviction data. Plenty of companies fall outside that and appoint one anyway, because enterprise buyers and their security questionnaires ask who the privacy contact is. Under Quebec Law 25 the requirement is not conditional: every enterprise needs a person in charge.

Who can we not appoint as DPO?

Anyone who determines the purposes and means of processing personal data, which is the Article 38(6) conflict test. In practice that rules out the chief executive, the CTO or head of engineering, the head of marketing, the head of HR and, in several enforcement decisions, the head of IT or security. This is the requirement companies most often get wrong, usually by appointing the person who seemed most technically qualified.

What is the difference between a DPO and a Quebec Law 25 privacy officer?

Different laws with different mechanics. The GDPR DPO is conditional, carries independence protections and cannot be conflicted. The Law 25 person in charge is required of every enterprise, defaults to the person with the highest authority, can be delegated in writing, and their title and contact details must be published on your website. One person can hold both roles, but the obligations should be tracked separately because they are satisfied differently.

Does Law 25 require the privacy officer to be published?

Yes, and it is the fastest thing for anyone to check. The title and contact information of the person in charge of the protection of personal information have to be published on your website. A privacy policy that does not name a contact is visible non-compliance.

Can you act as our EU representative under Article 27?

No. An Article 27 representative has to be established in a member state where the data subjects are, and we are a Canadian firm. If you are a non-EU controller offering goods or services into the EU, you need a separate representative appointment, and we will tell you where that obligation applies rather than quietly selling around it.

How does an outsourced privacy officer work alongside our security programme?

Well, if they are not fighting each other. Privacy and security overlap heavily on access control, retention, vendor management and breach response, which is why we run the role alongside SOC 2 and ISO 27001 work rather than as a separate track. Where you are already running an ISMS, the privacy role attaches to the same governance instead of creating a second one.

What happens when there is a breach?

We assess whether the incident meets the reporting threshold, which differs by law: GDPR runs a risk-to-rights test with a 72-hour notification clock, Law 25 uses a risk of serious injury test with notification to the Commission and affected individuals, and PIPEDA turns on real risk of significant harm. We make the determination, document the reasoning, and run the notification. The documented reasoning matters as much as the decision, because a regulator will ask why you concluded what you concluded.

Is this the same as a fractional CISO?

No, though they are often bought together. A fractional CISO owns security posture: controls, architecture, audits and the security questionnaire. A privacy officer owns lawful handling of personal data: purposes, retention, transfers, subject rights and breach notification. Companies with a security lead and no privacy contact usually discover the gap when a Law 25 or GDPR question arrives.

What does an outsourced privacy officer cost?

It is priced as an ongoing engagement, scoped to how much personal data you handle, which laws apply and how often requests arrive. It is a fraction of a privacy hire, which is the entire reason the role is outsourceable in the first place. Ask us for a fixed monthly number.

Track record

Who is actually doing the work

We are deliberately not a large firm, and we would rather show you the work than a wall of logos. Here is what is behind the advice.

6
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
75 days
Readiness window we have hit every time we have run it

Published vulnerability research

Six published CVEs, of which two show the range. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, and it handed defenders a way to shut down attacker infrastructure. CVE-2026-42626, issued through MITRE, is a denial-of-service flaw in HP ENVY 5000 series printers: the raw printing port enforces no connection timeout and no session limit, so one unauthenticated device on the same network can hold the printer offline until somebody physically restarts it.

That second one is the reason this belongs on a compliance page. An asset nobody thinks of as a computer, sitting on a flat network, taken down by a device that never had to authenticate. Auditors ask how controls fail. Finding out first-hand is what separates a policy that reads well from one that holds up when somebody asks for the evidence behind it.

A SOC 2 Type II built from nothing

Before founding traztech, Jacob was Head of Operations at Humera, a venture-backed US security company whose bot-detection platform sits in the request path of its customers' applications, and he built its compliance programme in-house: no report, no policies, no documented controls at the start. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15, having inventoried 60-plus assets and put a five-stage change-approval flow in front of production.

The platform stayed at 99.9% uptime and sub-100ms latency throughout, which is the part most readiness projects get wrong: controls are easy to design and hard to add to a system people are already depending on. That programme is why we sell fixed windows rather than open-ended retainers.

Recent engagements

For a Waterloo data centre operator we scoped and assessed SOC 2 Type II (Security, Availability and Confidentiality) against ISO 27001:2022 including the Climate Action Amendment, run together rather than one after the other. Scope covered the production campus, a datacenter platform, an AI compute platform and a self-hosted collaboration stack, written so further Ontario and Quebec sites enter as they reach production. Findings delivered and remediated.

For an Ontario medtech company putting an AI clinical assistant in front of practitioners, we ran the gap analysis and built the evidence programme behind their SOC 2.

Before you go

Notes on Canadian privacy obligations

What Law 25 actually asks for, how the breach thresholds differ between laws, and what a records of processing exercise involves. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.