Five Privacy Compliance Suggestions for Quebec Non-Profit Organizations
What is Loi 25 and how does it apply to my organization?
Quebec adopted la Loi 25 in September 2021. The law makes wide-ranging amendments to the province’s existing law regulating private-sector personal information protection that took (and will take) effect in stages over 2022, 2023 and 2024.
In principle, not-for-profits and charities are just as bound to comply with its provisions as are for-profit businesses. Although the law’s scope is limited to regulating personal information that is collected, used, held, or disclosed “in the course of carrying on an enterprise”, the courts have interpreted this as a broad concept that encompasses any organized economic activity related to goods or services—including when performed by not-for-profits and charities. Public bodies, however, are excluded from the law’s scope.
This blog post provides information on a few key areas of the changes as they relate to not-for-profits and charities and some general best practices that work well in many situations. But it’s not a comprehensive look at the changes and, as always, this publication shouldn’t be taken as legal advice. Please consult a lawyer regarding your own specific compliance strategy.
- Designate a privacy officer
Although the law doesn’t technically require that organizations designate a privacy officer, unless they delegate the responsibility for ensuring the organization’s compliance with Loi 25 and implementation of the relevant measures in writing, then that responsibility automatically lies with the person who exercises the highest authority within the organization. Although we’re using the term “privacy officer” for ease in this blog post, the law uses the longer phrase “the person in charge of the protection of personal information”.
Best practice: Organizations should ensure that the person exercising the highest authority delegates the role of privacy officer in writing to another person in the organization, and should ensure that this person has the knowledge, training, and resources required to fulfill that role.
- Conduct a personal information inventory
It’s helpful for organizations to begin by compiling an inventory of all personal information that they hold or use, throughout the data life cycle, as well as of any existing privacy policies, practices or roles. Although the law doesn’t explicitly require you to do this, being able to refer to this type of data map is generally invaluable when working toward compliance with the law’s obligations.
Best practice: Conduct a personal information inventory that identifies the personal information that your organization uses, collects or discloses. Be thoughtful to ensure you cover everything, keeping in mind that “personal information” is a broad concept that includes information such as the IP addresses of visitors to your website, even if you don’t know the names or addresses of those people. The specific approach to compiling this inventory may vary by the organization’s size and its activities, but one approach is to go through each type of personal information collected, retained or used, make a brief note as to (1) what the information is, (2) whether it includes any sensitive data, including data of minors or health data, (3) what software or platforms are involved in its collection, retention or processing, (4) where it’s stored or hosted geographically and (5) the purposes for which the organization collects, uses and discloses it, and any other contexts in which it’s used or disclosed. This exercise should cover all of the organization’s activities, including any personal information of its members, its staff, related to its website, involved in electronic services used, or in any other context. Plan how this inventory will be updated as the organization begins to use new digital services or undertakes new activities.
- Adopt or revise privacy policies
The law requires your organization to implement personal information policies and practices that:
- ensure that personal information is protected;
- provide a framework for its retention and destruction;
- provide a process for dealing with complaints regarding the information’s protection;
- define roles and responsibilities for your personnel throughout the information life cycle;
- are proportionate to the nature and scope of your activities; and
- are approved by your privacy officer.
You must publish detailed information about these policies and practices in simple and clear language on your website (or, if you don’t have one, make it available by any other appropriate means). If you collect personal information by technological means, you must disseminate a “confidentiality policy” (and any notices of amendment to the policy) drafted in clear and simple terms by any appropriate means to reach the persons concerned.
Your public (and internal) policies can also be used to help fulfill the law’s other requirements. For example, when you collect personal information directly from the person concerned, the law requires you to communicate certain information from them at the time of collection, including the purposes for which you’re collecting any given information, the means by which it’s collected, their rights of access and rectification provided by law and their right to withdraw consent to the communication or use of the information collected. Including this information in a policy that you make accessible to them can be an efficient way to do this, and the process will of course be facilitated by having already conducted a personal information inventory.
Best practice: Develop at least one publicly accessible confidentiality policy, as well as at least one internal, non-public policy. Tailor these so that they satisfy the law’s requirements regarding policies and practices (some of which are listed above), and so that they facilitate your organization’s compliance with its other obligations under Loi 25. Publish the publicly accessible policy on your website, if you have one. Include your privacy officer’s contact information in the public policy, and make clear that this is the person to contact for the purpose of exercising the rights to access and rectification, withdrawing consent, or making a complaint. As far as the internal, non-public policy, it can be designed so as to serve as a training manual and reference for your privacy officer, including codifying in more detail how they should fulfill their obligations and carry out the organization’s privacy practices in specific situations. Because privacy compliance is an ongoing obligation that evolves along with your organization’s activities, use this internal policy as an additional safeguard to ensure that your privacy officer is aware of the various future situations that may require them to respond, even if no such situation is yet relevant to the organization. These include (1) if the organization begins using a new service that stores personal information outside of Quebec or otherwise communicates personal information outside of Quebec, (2) if a confidentiality incident occurs (and by extension, what a confidentiality incident is), (3) if the organization acquires, develops or overhauls an information system involving personal information, (4) if the organization receives notice that a person has withdrawn their consent to the use or retention of their personal information, among others. Depending on considerations that include how likely the organization believes each possible scenario to be, the internal guide can either describe in detail how the privacy officer should address the situation, or instead simply indicate that the privacy officer should promptly seek legal advice or otherwise adequately inform themself about how to appropriately respond.
- Be aware of outsourcing obligations
Platforms and online services that store information in the United States (among other foreign jurisdictions) are ubiquitous. Loi 25 recognizes that its protections would be hollow if Quebec organizations could simply transfer personal information to another country without legal protections. Loi 25 doesn’t prohibit organizations from transferring personal information outside of Quebec, but to do so they must:
- Inform individuals of that possibility when collecting their personal information from them.
- Conduct a privacy impact assessment prior to the transfer, which must establish that the information would receive adequate protection after being transferred. The law specifies some requirements about how this assessment must be conducted.
- Enter into a prior written agreement that the information is subject to that takes into account, in particular, the results of the assessment and sets out protections to mitigate the risks identified in the assessment, if applicable.
Organizations that use private, third-party services or platforms in connection with personal information without the consent of the person concerned, whether inside or outside of Quebec, must also under Loi 25 enter into a written agreement with the third party that:
- specifies the measures that the third party must take to protect the confidentiality of the personal information received;
- specifies that the third party shall use the information only for carrying out the agreement; and
- specifies that the third party shall not keep the information after the agreement expires.
Best practice: Adapt the organization’s existing outsourcing or procurement processes, or put a new one in place, to facilitate your organization’s ongoing compliance with Loi 25 whenever it begins to use a new platform or service provider.
- Be prepared to respond to requests, complaints and incidents
As mentioned, your organization can use its internal-facing policy to help its privacy officer identify and respond in a timely and appropriate way to issues that the organization may not be used to addressing and may even never have been faced with before. Adopt proportionate practices to allow your organization to be prepared, in light of foreseeable challenges like staff turnover, to issues including the following, which can unexpectedly arise at any time:
- Individual requests. You may receive requests at any time from people who want to access or correct (“rectify”) any personal information that your organization holds about them, or exercise other Loi 25 rights such as the “right to be forgotten” or the right to receive information about how the organization is processing their personal information. Although the organization is not always required to grant these requests, its privacy officer must generally respond to them within 30 days, even if only to indicate the reasons that the request is being refused. If you fail to respond, or if the person is dissatisfied with how the request was processed, they can file a request to the Commission d’accès à l’information (“CAI”) to challenge the organization’s response (or non-response) and the CAI will convene a hearing before an administrative judge with the power to order the organization to comply with the law.
- Complaints. Among the policies and practices that Loi 25 requires organizations to establish and implement is a process for dealing with complaints regarding the protection of the information. The law offers little specific guidance on how this must be done. One possible approach is to specify in policy that the privacy officer will receive and evaluate such complaints without undue delay, and will in all cases respond to the complainant in at least a preliminary way within the same 30-day deadline that applies to many individual requests, and provide a final response within that time if feasible.
- Incidents. Loi 25 defines a “confidentiality incident” to broadly encompass any access to, use of, or communication of personal information that is not authorized by law, as well as any loss of personal information or any other breach of the protection of such information. Organizations are required to keep a register of all such confidentiality incidents and must take reasonable measures to reduce the risk of injury and prevent similar future incidents. If the incident presents a “risk of serious injury”, according to criteria set out in Loi 25, the organization must also promptly report information about the incident that is specified by the law to the CAI and to the persons concerned. To be able to effectively fulfill these obligations, the organization’s privacy officer must not only be aware of them, but all relevant staff, volunteers, directors and others must be aware of the need to make the privacy officer aware of potential incidents as they arise.
The Authors
This article was written by Mark Phillips.
You can contact COCo through our usual channels, and find Mark Philips at https://www.markphillips.ca/. Nothing in this blog post is legal advice: please consult a lawyer to receive advice regarding your organization’s situation.








