Protection of personal information
Law 25 and data hosting: what a Quebec law firm needs to verify
A Canadian server is a useful starting point, but it does not complete the analysis. A firm must follow the information, access paths, and subprocessors, then document the risks before launch.
Legal review to be completed before definitive publication

Key points
- Section 17 requires a PIA before disclosing personal information outside Quebec or entrusting its storage there.
- The assessment considers sensitivity, purpose, safeguards, and the legal framework applicable in the relevant jurisdiction.
- Disclosure should occur only where the assessment finds adequate protection, and it must be governed by a written agreement.
- Server location is not enough: support access, backups, subprocessors, and the laws binding the provider also matter.
What section 17 actually requires
Before disclosing personal information outside Quebec, an enterprise must conduct a privacy impact assessment. The same requirement applies where it entrusts a person or body outside Quebec with collecting, using, communicating, or keeping that information on its behalf.
The assessment must consider the sensitivity of the information, the purpose for which it is used, the protection measures, including contractual measures, and the legal framework applicable in the jurisdiction where the information would be disclosed. The statute also requires a written agreement.
For a law firm, the assessment should also address solicitor-client privilege, professional confidentiality, the nature of the matters, and the concrete effects of improper access to a document, note, or calendar entry.
Why “hosted in Canada” is not enough
Data residency answers where the primary copy is located. It does not necessarily tell you where technical support can connect from, where backups are copied, which subprocessors participate, or which laws bind the company operating the service.
A Canadian provider can rely on a foreign subprocessor. A foreign company can operate a Canadian region. An external calendar can receive a client name even while the main matter remains in Montreal. A useful PIA describes those real flows instead of stopping at a data-centre address.
Questions to ask a provider
Ask for written answers and connect each one to the contract, a security schedule, or technical evidence.
Swipe the table horizontally to view every column.
| Question | Evidence to obtain | Why it matters |
|---|---|---|
| Where are the database, files, backups, and logs? | Region list and architecture diagram | A single service can involve several processing locations. |
| Who can access the data from outside Quebec? | Support process, roles, and access logs | Administrative access is also a flow to assess. |
| Which subprocessors are used and how are changes announced? | Contractual list and notification mechanism | Risk can change without a visible product change. |
| How is the information exported and deleted? | Export format, timing, deletion evidence, and backup scope | Contract termination must be practical and verifiable. |
| What happens after an incident or government request? | Notice, cooperation, timing, and transparency clauses | The firm needs enough information to assess and manage the consequences. |
| Which controls protect accounts and privileged access? | MFA, roles, encryption, audit logs, and recovery testing | Paper compliance must match operational controls. |
A PIA method in five decisions
- 01
Define the purpose
Identify the need, the people concerned, the required information, and less intrusive options.
- 02
Map the flows
Include source systems, copies, support, backups, integrations, and data exit paths.
- 03
Assess compliance and risk
Measure likelihood and severity, then assess the applicable legal framework and contractual commitments.
- 04
Require safeguards
Assign an owner, deadline, and evidence to every technical, contractual, or organizational measure.
- 05
Decide and monitor
Document approval, conditions, the review date, and changes that will trigger a new assessment.
PIA checklist for Quebec law firms
An 8-page worksheet to define the project, map the flows, assess the contract, record risks, and document the decision. It includes a separate field for legal review.
PDF, 8 pages, working version dated August 20, 2026
Frequently asked questions
Is a PIA required when servers are in Canada?
Not automatically just because the server is in Canada. The project and its flows must be assessed. A PIA is specifically required before a disclosure or storage outside Quebec within the meaning of section 17.
Does a security certification replace a PIA?
No. A certification can be useful evidence, but the PIA still needs to address the information, purposes, jurisdictions, risks, and operating context of the firm.
Must a PIA be redone every year?
The statute does not turn every PIA into a uniform annual exercise. It should still be kept current and reviewed when a material change affects the project, flows, subprocessors, locations, or risks.
Official sources
Sources consulted on August 20, 2026
- 01LégisQuébec
- 02Commission d’accès à l’information du Québec
- 03Commission d’accès à l’information du Québec
General information only. This guide and checklist are not legal advice and must be adapted to the context of your firm.