Quebec Law 25: which business practices should you review?
Connect policies, responsibilities and everyday actions: prepare a Quebec Law 25 work plan grounded in your business activities.
Loupe Technologies helps organizations improve their processes, develop their tools and protect their data.
Five areas of expertise to move your organization forward.
Review your privacy practices, responsibilities and the actions to prioritize in your organization.
Clarify the issues in your healthcare project: the information involved, access, sharing and providers. The applicable framework depends on your role and activities.
Examine privacy risks when preparing a project. Connect the information being processed, the providers involved and the safeguards to plan.
Do your activities extend beyond Quebec? Scope the questions to examine about PIPEDA and provincial laws based on your activities and the information you process.
This is how we propose to work: examine how things actually operate, then connect technical choices, responsibilities and data protection.
Your organization
Responsibilities
Technical choices
Protection
The need and the data are identified.
Responsibilities are defined.
Tools are connected and access is controlled.
The operation can be verified.

Connect policies, responsibilities and everyday actions: prepare a Quebec Law 25 work plan grounded in your business activities.

Prepare a Copilot pilot with a defined use case, reviewed access, quality criteria and a practical decision worksheet for your team.

Prepare an authorization worksheet for your AI agent: task, data, permitted actions, human decisions and scenarios to check before a trial.
Answers to clarify your needs and consider the next steps.
Start with a specific situation: a task that takes too long, access that is difficult to control or a requirement you need to understand. We propose clarifying the context, the people involved and the intended outcome before defining the scope of the work.
Not necessarily. The first step is to examine the workflow, repeated data entry, decision rules and features already available in your tools. This helps assess whether clarifying the process, changing a configuration or integrating systems would meet the need. A software change can then be considered in light of the project’s constraints.
Law 25 amended Quebec’s personal information protection laws. Law 5 refers here to the specific framework for health and social services information. The framework to examine depends in part on the organization, its activities and the information involved. Our Law 5 support helps clarify a need related to the health sector.
A privacy impact assessment (PIA, or EFVP in French) examines how a project affects personal information and the privacy risks for individuals. It helps identify safeguards to build in from the design stage and review as the project develops. The law makes this assessment mandatory in certain circumstances.
Start with file permissions and sharing. Microsoft 365 Copilot draws on information the user already has access to, so overly broad permissions still need to be addressed. Preparation also includes choosing use cases, establishing data governance and explaining the rules to your teams.
First define the task, the data required and the tools involved. We then propose examining permitted actions, human approvals, traceability and stopping conditions. This groundwork helps determine what to test and which safeguards to put in place before the system goes into use.