PIA under Law 25: when and how
In Quebec, an EFVP (privacy impact assessment) documents risks before projects that handle sensitive or large-scale personal informationâincluding invasive web tracking or new data-heavy features.
When to start
- Surveillance, geolocation, or biometrics.
- Automated decisions with significant impact.
- Sensitive sharing or transfers outside Quebec.
- Large-scale collection or merged databases.
Typical steps
- Scope the project and data flows.
- Assess necessity and risks to individuals.
- Define mitigations (security, contracts, policy updates).
- Approve, monitor, and revisit.
After changes, verify the live site matches decisionsâpolicy, cookies.