Reference
Glossary
Abbreviations, laws, attestations, and compliance programs used on tonia.
- PIA
- Privacy impact assessment. Required written document before sending personal information outside Canada (Bill 25, art. 17).
- Privacy Officer
- Person responsible for protecting personal information in your organisation. Your official Bill 25 contact — usually a senior leader or delegate (art. 3.1).
- Bill 25
- Quebec law on private-sector personal information protection (RLRQ, c. P-39.1). Formerly Bill 64.
- CAI
- Commission d'accès à l'information du Québec. The regulator that investigates and sanctions Bill 25 violations.
- CLOUD Act
- US law (2018) that lets American authorities compel data from US-headquartered companies — even when the data is stored in Canada.
- Bill 96
- Quebec French-language law (Charter of the French Language). Requires services and products to be available in French.
- PIPEDA
- Canada's federal Personal Information Protection and Electronic Documents Act. Applies to businesses in Canada outside Quebec.
- GDPR
- General Data Protection Regulation. European Union privacy law — the EU equivalent of Bill 25.
- SOC 2
- Independent CPA attestation (AICPA) on a service’s controls. Type I = design at a point in time; Type II = operating effectiveness over a period. At tonia: Security, Availability, Confidentiality — Type I in progress, then Type II observation.
- ISO 27001
- International standard for information security management. tonia does not pursue ISO 27001 certification — security attestation is via SOC 2; AI governance is via ISO 42001.
- DPA
- Data Processing Agreement. Contract between you and a vendor that processes personal information on your behalf.
- HIPAA
- US law protecting health information; requires a signed agreement (BAA) before a vendor can touch it.
- GLBA
- US financial-institutions law; its Safeguards Rule requires a security contract with every vendor.
- US state privacy laws
- Twenty US state laws requiring consent before processing sensitive data (health, ethnicity, biometrics).
- EU AI Act
- EU law governing risk-tiered AI systems; obligations for general-purpose models are already in force.
- ISO 42001
- International standard for AI management systems — bias, explainability, human oversight. In progress at tonia, Q4 2026 audit target.