COCo
  • About Us
    • Our Mission and Theory of Change
    • COCo Team
    • Our Board of Directors
    • Become a COCo Member
    • Our Bylaws
    • Our Structure
    • Annual Reports
    • Our Funders
  • Organizational Development
    • Services
    • Organizational Support
    • Information Sessions
    • Anti-Oppression
    • Conflict Resolution
  • Technology, Cybersecurity and Communications
  • Ateliers C
  • Resources
    • Toolbox
    • Legal Information
    • FAQs
  • Community Jobs
    • Job Postings
    • Add a Community Job Posting
  • Projects
    • Navigating Data
    • Learning Organizations Lab
    • Conflit à l’Oeuvre: Conflict and Diversity
    • Diversité d’Abord
    • Quebec on the Move
    • By & For Us?: The Community at the Head of the Organization
    • Communities Connecting the Digital Dots
    • Portes Ouvertes
    • In the Know: Identifying multiple aspects of Quebec’s community sector
  • Contact Us
  • FR
  • Click to open the search input field Click to open the search input field Search
  • Menu Menu

Five Privacy Compliance Suggestions for Quebec Non-Profit Organizations

November 20, 2024/in COCo Highlight, Front Page, Legal Information, ToolBox

What is Loi 25 and how does it apply to my organization?

Quebec adopted la Loi 25 in September 2021. The law makes wide-ranging amendments to the province’s existing law regulating private-sector personal information protection that took (and will take) effect in stages over 2022, 2023 and 2024.

In principle, not-for-profits and charities are just as bound to comply with its provisions as are for-profit businesses. Although the law’s scope is limited to regulating personal information that is collected, used, held, or disclosed “in the course of carrying on an enterprise”, the courts have interpreted this as a broad concept that encompasses any organized economic activity related to goods or services—including when performed by not-for-profits and charities. Public bodies, however, are excluded from the law’s scope.

This blog post provides information on a few key areas of the changes as they relate to not-for-profits and charities and some general best practices that work well in many situations. But it’s not a comprehensive look at the changes and, as always, this publication shouldn’t be taken as legal advice. Please consult a lawyer regarding your own specific compliance strategy.

 

  1. Designate a privacy officer

Although the law doesn’t technically require that organizations designate a privacy officer, unless they delegate the responsibility for ensuring the organization’s compliance with Loi 25 and implementation of the relevant measures in writing, then that responsibility automatically lies with the person who exercises the highest authority within the organization. Although we’re using the term “privacy officer” for ease in this blog post, the law uses the longer phrase “the person in charge of the protection of personal information”.

Best practice: Organizations should ensure that the person exercising the highest authority delegates the role of privacy officer in writing to another person in the organization, and should ensure that this person has the knowledge, training, and resources required to fulfill that role.

 

  1. Conduct a personal information inventory

It’s helpful for organizations to begin by compiling an inventory of all personal information that they hold or use, throughout the data life cycle, as well as of any existing privacy policies, practices or roles. Although the law doesn’t explicitly require you to do this, being able to refer to this type of data map is generally invaluable when working toward compliance with the law’s obligations.

 

Best practice: Conduct a personal information inventory that identifies the personal information that your organization uses, collects or discloses. Be thoughtful to ensure you cover everything, keeping in mind that “personal information” is a broad concept that includes information such as the IP addresses of visitors to your website, even if you don’t know the names or addresses of those people. The specific approach to compiling this inventory may vary by the organization’s size and its activities, but one approach is to go through each type of personal information collected, retained or used, make a brief note as to (1) what the information is, (2) whether it includes any sensitive data, including data of minors or health data, (3) what software or platforms are involved in its collection, retention or processing, (4) where it’s stored or hosted geographically and (5) the purposes for which the organization collects, uses and discloses it, and any other contexts in which it’s used or disclosed. This exercise should cover all of the organization’s activities, including any personal information of its members, its staff, related to its website, involved in electronic services used, or in any other context. Plan how this inventory will be updated as the organization begins to use new digital services or undertakes new activities.

 

  1. Adopt or revise privacy policies

The law requires your organization to implement personal information policies and practices that:

  • ensure that personal information is protected;
  • provide a framework for its retention and destruction;
  • provide a process for dealing with complaints regarding the information’s protection;
  • define roles and responsibilities for your personnel throughout the information life cycle;
  • are proportionate to the nature and scope of your activities; and
  • are approved by your privacy officer.

You must publish detailed information about these policies and practices in simple and clear language on your website (or, if you don’t have one, make it available by any other appropriate means). If you collect personal information by technological means, you must disseminate a “confidentiality policy” (and any notices of amendment to the policy) drafted in clear and simple terms by any appropriate means to reach the persons concerned.

Your public (and internal) policies can also be used to help fulfill the law’s other requirements. For example, when you collect personal information directly from the person concerned, the law requires you to communicate certain information from them at the time of collection, including the purposes for which you’re collecting any given information, the means by which it’s collected, their rights of access and rectification provided by law and their right to withdraw consent to the communication or use of the information collected. Including this information in a policy that you make accessible to them can be an efficient way to do this, and the process will of course be facilitated by having already conducted a personal information inventory.

Best practice: Develop at least one publicly accessible confidentiality policy, as well as at least one internal, non-public policy. Tailor these so that they satisfy the law’s requirements regarding policies and practices (some of which are listed above), and so that they facilitate your organization’s compliance with its other obligations under Loi 25. Publish the publicly accessible policy on your website, if you have one. Include your privacy officer’s contact information in the public policy, and make clear that this is the person to contact for the purpose of exercising the rights to access and rectification, withdrawing consent, or making a complaint. As far as the internal, non-public policy, it can be designed so as to serve as a training manual and reference for your privacy officer, including codifying in more detail how they should fulfill their obligations and carry out the organization’s privacy practices in specific situations. Because privacy compliance is an ongoing obligation that evolves along with your organization’s activities, use this internal policy as an additional safeguard to ensure that your privacy officer is aware of the various future situations that may require them to respond, even if no such situation is yet relevant to the organization. These include (1) if the organization begins using a new service that stores personal information outside of Quebec or otherwise communicates personal information outside of Quebec, (2) if a confidentiality incident occurs (and by extension, what a confidentiality incident is), (3) if the organization acquires, develops or overhauls an information system involving personal information, (4) if the organization receives notice that a person has withdrawn their consent to the use or retention of their personal information, among others. Depending on considerations that include how likely the organization believes each possible scenario to be, the internal guide can either describe in detail how the privacy officer should address the situation, or instead simply indicate that the privacy officer should promptly seek legal advice or otherwise adequately inform themself about how to appropriately respond.

 

  1. Be aware of outsourcing obligations

Platforms and online services that store information in the United States (among other foreign jurisdictions) are ubiquitous. Loi 25 recognizes that its protections would be hollow if Quebec organizations could simply transfer personal information to another country without legal protections. Loi 25 doesn’t prohibit organizations from transferring personal information outside of Quebec, but to do so they must:

  • Inform individuals of that possibility when collecting their personal information from them.
  • Conduct a privacy impact assessment prior to the transfer, which must establish that the information would receive adequate protection after being transferred. The law specifies some requirements about how this assessment must be conducted.
  • Enter into a prior written agreement that the information is subject to that takes into account, in particular, the results of the assessment and sets out protections to mitigate the risks identified in the assessment, if applicable.

Organizations that use private, third-party services or platforms in connection with personal information without the consent of the person concerned, whether inside or outside of Quebec, must also under Loi 25 enter into a written agreement with the third party that:

  • specifies the measures that the third party must take to protect the confidentiality of the personal information received;
  • specifies that the third party shall use the information only for carrying out the agreement; and
  • specifies that the third party shall not keep the information after the agreement expires.

 

Best practice: Adapt the organization’s existing outsourcing or procurement processes, or put a new one in place, to facilitate your organization’s ongoing compliance with Loi 25 whenever it begins to use a new platform or service provider.

 

 

  1. Be prepared to respond to requests, complaints and incidents

As mentioned, your organization can use its internal-facing policy to help its privacy officer identify and respond in a timely and appropriate way to issues that the organization may not be used to addressing and may even never have been faced with before. Adopt proportionate practices to allow your organization to be prepared, in light of foreseeable challenges like staff turnover, to issues including the following, which can unexpectedly arise at any time:

  • Individual requests. You may receive requests at any time from people who want to access or correct (“rectify”) any personal information that your organization holds about them, or exercise other Loi 25 rights such as the “right to be forgotten” or the right to receive information about how the organization is processing their personal information. Although the organization is not always required to grant these requests, its privacy officer must generally respond to them within 30 days, even if only to indicate the reasons that the request is being refused. If you fail to respond, or if the person is dissatisfied with how the request was processed, they can file a request to the Commission d’accès à l’information (“CAI”) to challenge the organization’s response (or non-response) and the CAI will convene a hearing before an administrative judge with the power to order the organization to comply with the law.
  • Complaints. Among the policies and practices that Loi 25 requires organizations to establish and implement is a process for dealing with complaints regarding the protection of the information. The law offers little specific guidance on how this must be done. One possible approach is to specify in policy that the privacy officer will receive and evaluate such complaints without undue delay, and will in all cases respond to the complainant in at least a preliminary way within the same 30-day deadline that applies to many individual requests, and provide a final response within that time if feasible.
  • Incidents. Loi 25 defines a “confidentiality incident” to broadly encompass any access to, use of, or communication of personal information that is not authorized by law, as well as any loss of personal information or any other breach of the protection of such information. Organizations are required to keep a register of all such confidentiality incidents and must take reasonable measures to reduce the risk of injury and prevent similar future incidents. If the incident presents a “risk of serious injury”, according to criteria set out in Loi 25, the organization must also promptly report information about the incident that is specified by the law to the CAI and to the persons concerned. To be able to effectively fulfill these obligations, the organization’s privacy officer must not only be aware of them, but all relevant staff, volunteers, directors and others must be aware of the need to make the privacy officer aware of potential incidents as they arise.

The Authors 

This article was written by Mark Phillips. 

You can contact COCo through our usual channels, and find Mark Philips at https://www.markphillips.ca/.  Nothing in this blog post is legal advice: please consult a lawyer to receive advice regarding your organization’s situation. 

Tags: coco publication, legal information
Share this entry
  • Share on Facebook
  • Share on WhatsApp
  • Share on Pinterest
  • Share on LinkedIn
  • Share on Tumblr
  • Share on Vk
  • Share on Reddit
  • Share by Mail
https://coco-net.org/wp-content/uploads/2024/11/1.png 1080 1080 adjo https://coco-net.org/wp-content/uploads/2026/06/coco-logo-vert-green-23-300x300.png adjo2024-11-20 15:44:352024-11-20 15:44:35Five Privacy Compliance Suggestions for Quebec Non-Profit Organizations
You might also like
Sample Bylaws
Accessibility Guidelines for Organizers and Facilitators
decorative The Evolution of COCo’s Process To Being a Flat Organization
Organizational Growth: Reflections And Learnings From Atelier/C On May 28, 2024
Board Meeting Basics, Agenda and Minutes
Getting on track with the Canada Not-for-Profit Corporations Act
two people playing and laughing. Building Queer-Inclusive Workplaces Every Day
decorative Proposed Changes About Decision Making for Quebec NonProfits

Recent Posts

  • Building Queer-Inclusive Workplaces Every Day
  • 5 Ways to Make Your Workplace More Queer-Inclusive
  • Two Years Later: Diversité d’Abord and the Work Ahead
  • COCo’s New Cybersecurity Services for Community Organizations!
  • The Mechanisms of White Supremacy in Our Organizations: Understanding to Bring About Change

Archives

Contact Us

info@coco-net.org

(514) 849-5599

Privacy policy

Working Hours

Mailing Address

C.P. 19, Montreal SUCC C, QC H2L 4J7

Working Hours

Monday – Thursday 10am – 4:00pm

To get information about our services, fill out our intake form.

© Copyright - COCo - Enfold WordPress Theme by Kriesi
Link to: We’re hiring an Organizational Development and Training Coordinator replacement position. Link to: We’re hiring an Organizational Development and Training Coordinator replacement position. We’re hiring an Organizational Development and Training Coordinator replacement... Link to: Organizational Growth: Reflections And Learnings From Atelier/C On May 28, 2024 Link to: Organizational Growth: Reflections And Learnings From Atelier/C On May 28, 2024 Organizational Growth: Reflections And Learnings From Atelier/C On May 28, ...
Scroll to top Scroll to top Scroll to top

By continuing to browse this site, you accept our use of cookies to track your usage and improve your experience.

OKLearn more

Cookie and Privacy Settings



How we use cookies

We may request cookies to be set on your device. We use cookies to let us know when you visit our websites, how you interact with us, to enrich your user experience, and to customize your relationship with our website.

Click on the different category headings to find out more. You can also change some of your preferences. Note that blocking some types of cookies may impact your experience on our websites and the services we are able to offer.

Essential Website Cookies

These cookies are strictly necessary to provide you with services available through our website and to use some of its features.

Because these cookies are strictly necessary to deliver the website, refusing them will have impact how our site functions. You always can block or delete cookies by changing your browser settings and force blocking all cookies on this website. But this will always prompt you to accept/refuse cookies when revisiting our site.

We fully respect if you want to refuse cookies but to avoid asking you again and again kindly allow us to store a cookie for that. You are free to opt out any time or opt in for other cookies to get a better experience. If you refuse cookies we will remove all set cookies in our domain.

We provide you with a list of stored cookies on your computer in our domain so you can check what we stored. Due to security reasons we are not able to show or modify cookies from other domains. You can check these in your browser security settings.

Google Analytics Cookies

These cookies collect information that is used either in aggregate form to help us understand how our website is being used or how effective our marketing campaigns are, or to help us customize our website and application for you in order to enhance your experience.

If you do not want that we track your visit to our site you can disable tracking in your browser here:

Other external services

We also use different external services like Google Webfonts, Google Maps, and external Video providers. Since these providers may collect personal data like your IP address we allow you to block them here. Please be aware that this might heavily reduce the functionality and appearance of our site. Changes will take effect once you reload the page.

Google Webfont Settings:

Google Map Settings:

Google reCaptcha Settings:

Vimeo and Youtube video embeds:

Other cookies

The following cookies are also needed - You can choose if you want to allow them:

Privacy Policy

You can read about our cookies and privacy settings in detail on our Privacy Policy Page.

Privacy Policy
Accept settingsHide notification only