{"id":2406,"date":"2024-08-23T10:04:28","date_gmt":"2024-08-23T14:04:28","guid":{"rendered":"https:\/\/solulan.com\/?p=2406"},"modified":"2024-11-15T10:36:07","modified_gmt":"2024-11-15T14:36:07","slug":"quebecs-law-25-how-to-upgrade-your-business-up-to-standard","status":"publish","type":"post","link":"https:\/\/solulan.com\/en\/quebecs-law-25-how-to-upgrade-your-business-up-to-standard\/","title":{"rendered":"Quebec's Law 25: How to upgrade your business up to standard?"},"content":{"rendered":"<p><span style=\"font-weight: 400;\">The protection of personal information has become an absolute priority for Quebec businesses. <\/span><b>Law 25<\/b><span style=\"font-weight: 400;\"> is a law modernizing legislative provisions on the protection of personal information. Coming into force on <\/span><b>September 22, 2022<\/b><span style=\"font-weight: 400;\">, it marks a major turning point in the way organizations must manage and protect sensitive data.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Solulan, your trusted IT services and cybersecurity partner, supports you in this crucial transition to <\/span><b>Law 25 compliance<\/b><span style=\"font-weight: 400;\">. Discover our complete guide to understanding the challenges of this law and implementing the necessary measures to ensure the protection of personal information within your organization.<\/span><\/p>\n<p>&nbsp;<\/p>\n<h2><span style=\"font-weight: 400;\">What is Law 25 in Quebec?<\/span><\/h2>\n<p><span style=\"font-weight: 400;\">Law 25 aims to strengthen the <\/span><b>protection of personal information in Quebec<\/b><span style=\"font-weight: 400;\"> by introducing stricter provisions and extending the rights of individuals.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">It applies to <\/span><b>all private companies and public bodies<\/b><span style=\"font-weight: 400;\"> that collect, use or communicate personal information. Specific new obligations are imposed to ensure compliance with Law 25, guaranteeing that companies and public bodies adequately protect the personal data they manage. This enables more secure and transparent management of sensitive information, while complying with the new legal requirements for the protection of personal information.<\/span><\/p>\n<p>&nbsp;<\/p>\n<h3><span style=\"font-weight: 400;\">Informed consent and greater rights<\/span><\/h3>\n<p><span style=\"font-weight: 400;\">One of the major changes concerns consent. Companies must now obtain explicit, <\/span><b>informed consent before collecting<\/b><span style=\"font-weight: 400;\">, using or disclosing personal information. In addition, Law 25 grants individuals new rights, such as the right to data portability and, in certain circumstances, the right to forget or <\/span><b>destroy personal information<\/b><span style=\"font-weight: 400;\">.<\/span><\/p>\n<p>&nbsp;<\/p>\n<h3><span style=\"font-weight: 400;\">Mandatory notification of security breaches<\/span><\/h3>\n<p><span style=\"font-weight: 400;\">Law 25 also requires companies to notify the <\/span><a href=\"https:\/\/www.cai.gouv.qc.ca\/english\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">Commission d'acc\u00e8s \u00e0 l'information<\/span><\/a><span style=\"font-weight: 400;\"> (CAI) and the individuals concerned in the event of a confidentiality incident <\/span><b>involving personal information<\/b><span style=\"font-weight: 400;\">. This measure is designed to ensure greater transparency and enable individuals to take the necessary action to protect their interests.<\/span><\/p>\n<p>&nbsp;<\/p>\n<h3><span style=\"font-weight: 400;\">Tougher penalties<\/span><\/h3>\n<p><span style=\"font-weight: 400;\">Failure to comply with Law 25 can result in <\/span><b>significant financial penalties<\/b><span style=\"font-weight: 400;\">, up to $10 million or 2% of worldwide sales, whichever is greater. These enhanced penalties underline the importance of compliance and encourage companies to take data protection seriously.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: center;\"><a href=\"https:\/\/solulan.com\/en\/cybersecurity\/security-audits\/\"><span style=\"font-weight: 400;\">Request a security audit<\/span><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<h2><span style=\"font-weight: 400;\">Key steps for compliance with Law 25 in Quebec<\/span><\/h2>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-2403\" src=\"https:\/\/solulan.com\/wp-content\/uploads\/s5ryfkgb-300x171.jpg\" alt=\"\" width=\"1116\" height=\"636\" srcset=\"https:\/\/solulan.com\/wp-content\/uploads\/s5ryfkgb-300x171.jpg 300w, https:\/\/solulan.com\/wp-content\/uploads\/s5ryfkgb-1024x585.jpg 1024w, https:\/\/solulan.com\/wp-content\/uploads\/s5ryfkgb-768x439.jpg 768w, https:\/\/solulan.com\/wp-content\/uploads\/s5ryfkgb-1536x877.jpg 1536w, https:\/\/solulan.com\/wp-content\/uploads\/s5ryfkgb-480x274.jpg 480w, https:\/\/solulan.com\/wp-content\/uploads\/s5ryfkgb-640x366.jpg 640w, https:\/\/solulan.com\/wp-content\/uploads\/s5ryfkgb-720x411.jpg 720w, https:\/\/solulan.com\/wp-content\/uploads\/s5ryfkgb-960x548.jpg 960w, https:\/\/solulan.com\/wp-content\/uploads\/s5ryfkgb-1168x667.jpg 1168w, https:\/\/solulan.com\/wp-content\/uploads\/s5ryfkgb-1440x822.jpg 1440w, https:\/\/solulan.com\/wp-content\/uploads\/s5ryfkgb-scaled.jpg 2560w\" sizes=\"auto, (max-width: 1116px) 100vw, 1116px\" \/><\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"font-weight: 400;\">Compliance with Law 25 is a process that requires <\/span><b>careful planning<\/b><span style=\"font-weight: 400;\"> and a proactive approach.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">As a reminder, here are the <\/span><b>key dates<\/b><span style=\"font-weight: 400;\"> for compliance with Law 25:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>September 22, 2022<\/b><span style=\"font-weight: 400;\">: Law 25 comes into force.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>September 22, 2023<\/b><span style=\"font-weight: 400;\">: Deadline for implementation of initial compliance measures.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>September 22, 2024<\/b><span style=\"font-weight: 400;\">: Deadline for full compliance.<\/span><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<h3><span style=\"font-weight: 400;\">Appointment of a data controller and data mapping<\/span><\/h3>\n<p><span style=\"font-weight: 400;\">The first step is to appoint a <\/span><b>Chief Privacy Officer (CPO)<\/b><span style=\"font-weight: 400;\">. This person will be responsible for overseeing the implementation of and compliance with Law 25 within your company. In particular, the RPRP will have to carry out a <\/span><b>privacy impact assessment<\/b><span style=\"font-weight: 400;\"> for any communication of personal information outside Quebec.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Next, it's essential to map data flows, i.e. to <\/span><b>identify all the personal information you collect<\/b><span style=\"font-weight: 400;\">, use and communicate, as well as the reasons why you do so.<\/span><\/p>\n<p>&nbsp;<\/p>\n<h3><span style=\"font-weight: 400;\">Updating policies and procedures<\/span><\/h3>\n<p><span style=\"font-weight: 400;\">Once your data flows have been mapped, it's time to <\/span><b>update your internal policies<\/b><span style=\"font-weight: 400;\"> and procedures. Your privacy policies, consent forms and data management procedures must <\/span><b>comply with the law<\/b><span style=\"font-weight: 400;\"> and the new requirements of Law 25.<\/span><\/p>\n<p>&nbsp;<\/p>\n<h3><span style=\"font-weight: 400;\">Data security and staff training about Law 25<\/span><\/h3>\n<p><span style=\"font-weight: 400;\">Protecting personal information involves implementing appropriate <\/span><a href=\"https:\/\/solulan.com\/en\/cybersecurity-excellence\/\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">cybersecurity measures<\/span><\/a><span style=\"font-weight: 400;\">. It is essential to protect data against unauthorized access, use, disclosure, loss or theft.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">In addition, it is essential that your staff receive <\/span><b>training on Law 25<\/b><span style=\"font-weight: 400;\"> throughout their careers. Your employees involved in <\/span><b>electronic service delivery<\/b><span style=\"font-weight: 400;\">, must be made aware of the importance of protecting personal information and the new obligations of Law 25.<\/span><\/p>\n<p>&nbsp;<\/p>\n<h2><span style=\"font-weight: 400;\">Quebec\u2019s Law 25 and cybersecurity: An integrated approach<\/span><\/h2>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-2405\" src=\"https:\/\/solulan.com\/wp-content\/uploads\/745eytg-300x200.jpg\" alt=\"\" width=\"1122\" height=\"748\" srcset=\"https:\/\/solulan.com\/wp-content\/uploads\/745eytg-300x200.jpg 300w, https:\/\/solulan.com\/wp-content\/uploads\/745eytg-1024x683.jpg 1024w, https:\/\/solulan.com\/wp-content\/uploads\/745eytg-768x512.jpg 768w, https:\/\/solulan.com\/wp-content\/uploads\/745eytg-1536x1024.jpg 1536w, https:\/\/solulan.com\/wp-content\/uploads\/745eytg-2048x1365.jpg 2048w, https:\/\/solulan.com\/wp-content\/uploads\/745eytg-480x320.jpg 480w, https:\/\/solulan.com\/wp-content\/uploads\/745eytg-640x427.jpg 640w, https:\/\/solulan.com\/wp-content\/uploads\/745eytg-720x480.jpg 720w, https:\/\/solulan.com\/wp-content\/uploads\/745eytg-960x640.jpg 960w, https:\/\/solulan.com\/wp-content\/uploads\/745eytg-1168x779.jpg 1168w, https:\/\/solulan.com\/wp-content\/uploads\/745eytg-1440x960.jpg 1440w, https:\/\/solulan.com\/wp-content\/uploads\/745eytg-1920x1280.jpg 1920w, https:\/\/solulan.com\/wp-content\/uploads\/745eytg-scaled.jpg 2560w\" sizes=\"auto, (max-width: 1122px) 100vw, 1122px\" \/><\/p>\n<p>&nbsp;<\/p>\n<p><b>Law 25 and cybersecurity<\/b><span style=\"font-weight: 400;\"> are intrinsically linked. Personal information cannot be protected without robust cybersecurity. An integrated approach is essential to ensure that all the necessary security measures are in place to protect sensitive data.<\/span><\/p>\n<p>&nbsp;<\/p>\n<h3><span style=\"font-weight: 400;\">Risk assessment and incident response plan<\/span><\/h3>\n<p><span style=\"font-weight: 400;\">A <\/span><b>risk assessment<\/b><span style=\"font-weight: 400;\"> is a crucial step in identifying potential vulnerabilities within your systems. This assessment identifies weak points that could be exploited in a cyberattack. Once these vulnerabilities have been identified, you can implement corrective measures to strengthen the security of your company's data.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">An <\/span><b>incident response plan<\/b><span style=\"font-weight: 400;\"> is equally important. This plan must include clear procedures for reacting quickly and effectively in the event of a security breach. It should define the steps to be taken to contain the incident, <\/span><b>minimize damage<\/b><span style=\"font-weight: 400;\"> and restore affected systems. In addition, the plan must provide for communications with internal and external stakeholders, including notification to the Information Access Commission and affected individuals.<\/span><\/p>\n<p>&nbsp;<\/p>\n<h3><span style=\"font-weight: 400;\">Cybersecurity awareness<\/span><\/h3>\n<p><span style=\"font-weight: 400;\">Raising awareness and training your employees is essential to maintaining a high level of IT security. It's vital that employees receive <\/span><b>training in Law 25<\/b><span style=\"font-weight: 400;\"> in addition to cybersecurity best practices, and are made aware of the risks associated with hacking. Regular training ensures that all staff members understand the importance of protecting personal information and know how to react in the event of an attempted cyber-attack.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">In addition to initial training, <\/span><a href=\"https:\/\/solulan.com\/en\/cybersecurity\/phishing-awareness\/\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">phishing awareness<\/span><\/a><span style=\"font-weight: 400;\"> sessions and other types of cyber attack should be organized to maintain a high level of vigilance. These sessions can include simulated attacks, updates on new threats and reminders of corporate security policies. By cultivating a culture of security, you reduce the risk of human error compromising data security.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: center;\">\u00a0<a href=\"https:\/\/solulan.com\/en\/managed-services\/managed-cybersecurity-services\/\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">Discover our cybersecurity services<\/span><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<h2><span style=\"font-weight: 400;\">Solulan: Your partner for successful compliance with Law 25 in Quebec<\/span><\/h2>\n<p><span style=\"font-weight: 400;\">Solulan, with its <\/span><b>expertise in IT and cybersecurity<\/b><span style=\"font-weight: 400;\">, is with you every step of the way to ensure compliance with Law 25. We offer personalized advice, technical expertise and <\/span><a href=\"https:\/\/solulan.com\/en\/cybersecurity\/proactive-monitoring\/\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">proactive monitoring<\/span><\/a><span style=\"font-weight: 400;\"> to help you protect your data and ensure your company's compliance.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"https:\/\/solulan.com\/en\/contact-us\/\" target=\"_blank\" rel=\"noopener\"><b>Contact us today<\/b><\/a><b> and find out how we can help you meet the challenges of Law 25 and strengthen the protection of personal information within your organization!<\/b><\/p>\n<p>&nbsp;<\/p>\n<h2><a href=\"https:\/\/www.youtube.com\/watch?v=R1a-weMiEIk&amp;t=30s\">Watch our webinar HERE !<\/a><\/h2>\n","protected":false},"excerpt":{"rendered":"<p>The protection of personal information has become an absolute priority for Quebec businesses. Law 25 is a law modernizing legislative provisions on the protection of personal information. Coming into force on September 22, 2022, it marks a major turning point in the way organizations must manage and protect sensitive data.\u00a0 Solulan, your trusted IT services [&hellip;]<\/p>\n","protected":false},"author":13,"featured_media":2401,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_seopress_robots_primary_cat":"none","_seopress_titles_title":"Quebec&#039;s Law 25: How to Upgrade your Business? | Solulan","_seopress_titles_desc":"How does Quebec&#039;s Law 25 affect your business? Solulan guides you towards compliance and safety excellence. Act now to upgrade your company!","_seopress_robots_index":"","footnotes":""},"categories":[85,90],"tags":[],"class_list":["post-2406","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-articles","category-cybersecurity"],"acf":[],"_links":{"self":[{"href":"https:\/\/solulan.com\/en\/wp-json\/wp\/v2\/posts\/2406","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/solulan.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/solulan.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/solulan.com\/en\/wp-json\/wp\/v2\/users\/13"}],"replies":[{"embeddable":true,"href":"https:\/\/solulan.com\/en\/wp-json\/wp\/v2\/comments?post=2406"}],"version-history":[{"count":0,"href":"https:\/\/solulan.com\/en\/wp-json\/wp\/v2\/posts\/2406\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/solulan.com\/en\/wp-json\/wp\/v2\/media\/2401"}],"wp:attachment":[{"href":"https:\/\/solulan.com\/en\/wp-json\/wp\/v2\/media?parent=2406"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/solulan.com\/en\/wp-json\/wp\/v2\/categories?post=2406"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/solulan.com\/en\/wp-json\/wp\/v2\/tags?post=2406"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}