Law 25 Compliance Audit
A bounded audit of your tool stack: which tools hold personal information, where that data actually lives, and what Law 25 requires you to change. Report only.
This Is Right For You If
- You operate in Quebec and use Google Analytics, Typeform, SurveyMonkey, or Google Drive on systems that handle personal information
- You've received or anticipate a CAI audit notice
- You need to know where you actually stand before committing a remediation budget
A typical Quebec municipal services provider running Google Analytics on public portals, SurveyMonkey for citizen surveys, and Google Drive for document sharing. That is the CAI audit-risk profile this service line targets.
The audit returns a written report naming each non-compliant tool, where its data actually resides, a filled EFVP checklist, and a remediation roadmap ordered by exposure. Implementing that roadmap is a separate engagement, scoped and quoted once you have the findings.
Illustrative reference scenario based on comparable industry benchmarks, not a completed TSI engagement.
Why TSI for This
- Report only, and no lock-in: the audit stands on its own and does not oblige you to buy the remediation from us
- Even a “you are already compliant” finding is a complete, valid deliverable
- Fixed price agreed before the audit starts, scope bounded in writing
- Week 1: Discovery call and scope confirmation, then a full inventory of your tools and the personal data flowing through each.
- Week 2: Technical validation of data residency and API behaviour, tool by tool.
- Weeks 2–3: Written audit report, filled EFVP checklist, and a remediation roadmap ordered by exposure.
- Implementation, if you want it, is scoped and quoted separately after the audit closes.
Delivery Phases
- Discovery Call
- Tool & Data-Flow Inventory
- Technical Validation
- Audit Report
- Remediation Roadmap
What You Receive
- Written compliance audit report
- Inventory of every tool and where its data resides
- List of non-compliant tools
- Data residency gap analysis
- EFVP checklist, filled, for your legal team
- Remediation roadmap ordered by exposure
Typical Tech Stack
- Assessed against Quebec-hosted alternatives: Matomo
- LimeSurvey
- Nextcloud
- OVHcloud BHS (Quebec)
- Single site
- Under 500 users
- Fewer than 10 tools in scope
- No formal EFVP support required
- Multi-site or multi-department
- 2,000+ users
- 20 or more tools in scope
- Formal EFVP package for your legal team
Biggest variable: Number of tools in scope × number of sites × EFVP and documentation depth