Compliance

Phase 1, Phase 2, then keep it running

A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.

All compliance →
Security

Testing, review and leadership

Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.

All security →
Who we help

Prove you are secure

To the people you sell to, raise from or answer to.

All industries →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
All Tools

Law 25 Privacy Officer Checker

Quebec Law 25 and PIPEDA both expect a named person to own privacy, with specific things in place. Mark what you have and see which obligations are met and which are missing.

Which law applies to you?

Pick the closest match. Organizations with Quebec customers or staff usually need both.

What does your privacy officer have in place?

Answer for how things are today, not how they are planned.

Obligations met
0 of 0
Not started
Obligation by obligation
What is missing, and what to do
    Outsourced privacy officer, From $750/mo CAD
    A checklist, not legal advice. It covers the duties a privacy officer is expected to have in place under Quebec's Act respecting the protection of personal information in the private sector (as amended by Law 25) and PIPEDA. Sector rules, such as health information statutes, can add to them.

    Questions

    Who is the privacy officer under Law 25 by default?

    The person with the highest authority in the organization, usually the CEO. That person can delegate the role, in whole or in part, to someone else, and the delegation should be in writing.

    Can the privacy officer role be outsourced?

    Yes. The function can be delegated to a person outside the organization. Accountability stays with the organization, so the delegation, the published contact details and the internal escalation path still need to be in place.

    How long do we have to answer an access request?

    Under Law 25 and under PIPEDA, the general rule is 30 days from receipt of the request. An organization that does not answer in time is deemed to have refused, so the request process needs an owner and a log.

    Is this checker free?

    Yes, free and no signup. Your answers stay in your browser.

    Not ready for a call yet?

    Get your checklist results by email

    Your results to keep, then a few short notes from Jacob on running privacy under Law 25 and PIPEDA without drowning in legalese. Unsubscribe in one click. Reply anytime; it reaches him directly.

    From Jacob Masse, principal of traztech: the files by email, then a few short notes over the next month. No spam, unsubscribe in one click.

    Want it done for you?

    Outsourced Privacy Officer

    A named privacy officer who keeps the register, the requests and the PIAs moving.

    Explore Outsourced Privacy Officer →

    Have someone own privacy, properly.

    Our outsourced privacy officer takes the delegated role: published contact, access requests answered on time, the incident register kept, and PIAs done before projects and transfers. From $750/mo CAD.

    See the outsourced privacy officer Book a call

    Want the full picture on Quebec Law 25?

    This gives you the shape of the problem. The full picture is all 39 obligations of Quebec Law 25, each one explained in plain English, with somewhere to attach the evidence and a readiness score that moves as you close gaps. Start a free assessment and walk every control.

    Start your free Quebec Law 25 assessment See what is in the Workspace

    No credit card, no trial clock, no locked features. TrazTech makes money when someone wants help closing the gaps, not from the Workspace itself.

    Track record

    Who is actually doing the work

    5
    Published CVEs, including a CVSS 9.1
    Zero
    Exceptions on a SOC 2 Type II built from nothing in-house

    Published vulnerability research

    Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

    A SOC 2 Type II built from nothing

    At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation with zero exceptions.