Sentrix

Breakdown · Law 25

Law 25: when the PIA is mandatory and how to document it

The privacy impact assessment is required by Quebec's Law 25 in specific cases. What the Commission d'accès à l'information says about its content and form.

By Sentrix · Published 2026-09-20

A new CRM, a cloud payroll module hosted in the United States, an artificial intelligence tool connected to customer files: each of these projects triggers, in Quebec, a legal obligation that many enterprises discover after the fact. The privacy impact assessment, or PIA (EFVP in French), is not an optional good practice. In specific cases, it is the law.

What the Commission d'accès à l'information says

The Commission d'accès à l'information (CAI) describes the PIA as a preventive and evolving approach aimed at better protecting and respecting the right to privacy, from the start of any project involving personal information. Its guide "Réaliser une évaluation des facteurs relatifs à la vie privée", in its version 3.1 of April 2024, lists five situations in which the Act respecting access and the private sector Act make the PIA mandatory. Two of them concern private enterprises.

The first, set out in section 3.3 of the private sector Act and in force since September 22, 2023: any project to acquire, develop or overhaul an information system or electronic service delivery system involving the collection, use, communication, retention or destruction of personal information. The guide gives concrete examples of such systems: videoconferencing or collaboration software, biometric system, artificial intelligence system, payroll management system, member area of a website, mobile application.

The second, set out in section 17 of the same Act and in force on the same date: any communication of personal information outside Quebec, or entrusting a person or body outside Quebec with the task of collecting, using, communicating or retaining that information on your behalf. The PIA must then take into account the sensitivity of the information, the purposes for which it is used, the protection measures, including contractual ones, and the legal regime of the destination State. If it shows that the information would not receive adequate protection, you must refuse the communication. If it allows it, the communication is the subject of a written agreement that takes the results of the assessment into account.

In both cases, the Act provides that the PIA is proportionate to the sensitivity of the information concerned, the purposes for which it is used, its quantity, its distribution and its medium. And the enterprise must consult, from the start of the project, its person in charge of the protection of personal information: by default the person with the highest authority in the enterprise, who may delegate the function in writing, and whose title and contact information must be published on the enterprise's website.

Why it matters

The most frequent mistake we see is not the absence of a PIA, it is the PIA written after the contract is signed, for the file. The CAI guide is clear: the assessment takes place before the project and during its evolution, and a project that is not necessary and proportionate is not legal. A PIA done after the fact can no longer influence the choice of tool, the configuration of privacy settings or the contract clauses.

The second mistake is to believe that the obligation only concerns large projects. A subscription to a SaaS tool hosted outside Quebec that receives names, emails and purchase histories is a communication outside Quebec within the meaning of section 17. Proportionality allows you to keep it short; it does not allow you to do nothing.

The third is to treat the PIA as an isolated legal document. Its inputs (inventory of information, data flows, security measures, subcontractors) are exactly those of an information security program. An organization that already keeps an asset and supplier register for ISO 27001 or SOC 2 has done half the work.

What we think at Sentrix

The PIA becomes light when it relies on registers that already exist, and painful when it is restarted from scratch for every project.

  1. Name and publish the person in charge of the protection of personal information, with a written delegation if it is not the chief executive, and put that person in the approval process for projects and purchases.
  2. Add a trigger to project intake: any request to acquire, develop or overhaul a system and any new supplier outside Quebec opens a PIA, whose scale is decided according to the five criteria of the Act and documented.
  3. Reuse the information inventory and data flows of the security program (ISO 27001:2022, controls 5.9, 5.12 and 5.34; SOC 2, privacy criteria) rather than redrawing them in each PIA.
  4. Structure the report on the CAI's generic template: legal situation, project description, roles and consultations, inventory and scale, compliance with obligations, risks and mitigation measures, approval by senior management, appendices (policies, penetration tests, certifications, communication agreement).
  5. Link the outside-Quebec PIA to the supplier file: the analysis of the legal regime and of the contractual measures is kept there, with the written agreement, and reviewed when the supplier changes subcontractor or hosting region. The Sentrix platform connects these files to the third-party risk module.
  6. Update rather than redo: every change to the project triggers a revision of the existing PIA, as the guide requires.

The next step

List your system projects launched since September 2023 and your suppliers that process personal information outside Quebec. For each, look for the PIA. The empty boxes are your work plan, and our Law 25 page gives the rest of the framework. To discuss it, write to us.

Sources

Frequently asked questions

In which cases must a private enterprise carry out a PIA?
In two situations, according to the guide of the Commission d'accès à l'information: any project to acquire, develop or overhaul an information system or electronic service delivery system involving personal information, and any communication of personal information outside Quebec, including when a third party outside Quebec stores or processes it on your behalf. Both obligations have been in force since September 22, 2023.
Must the PIA be sent to the Commission d'accès à l'information?
Not in the two situations that concern enterprises, according to the Commission's guide: transmission is expected only when the PIA precedes the signing of an agreement to communicate information without consent. In the other cases, it is not necessary to send it proactively, but the Commission may ask to see it in its oversight activities. The report must therefore exist, be approved by senior management and remain available.
Must a project launched before September 2023 be reassessed?
No if the project was already finalized when the obligation came into force, for example a system already deployed or a communication outside Quebec already completed, according to the Commission's guide. Yes as soon as you change it: system overhaul, new purpose, new recipient. The Commission also recommends carrying out a PIA even when it is not mandatory, as soon as a project involves personal information.

Let's talk about your compliance program.

Last updated: 2026-09-20