Reference
Glossary
Abbreviations, laws, attestations, and compliance programs used on .
- PIA
- Privacy impact assessment. Required written document before sending personal information outside Canada (Bill 25, art. 17).
- Privacy Officer
- Person responsible for protecting personal information in your workspace. Your official Bill 25 contact — usually a senior leader or delegate (art. 3.1).
- Bill 25
- Quebec law on private-sector personal information protection (RLRQ, c. P-39.1). Formerly Bill 64.
- CAI
- Commission d'accès à l'information du Québec. The regulator that investigates and sanctions Bill 25 violations.
- CLOUD Act
- US law (2018) that lets American authorities compel data from US-headquartered companies — even when the data is stored in Canada.
- Bill 96
- Quebec French-language law (Charter of the French Language). Requires services and products to be available in French.
- PIPEDA
- Canada's federal Personal Information Protection and Electronic Documents Act. Applies to businesses in Canada outside Quebec.
- GDPR
- General Data Protection Regulation. European Union privacy law — the EU equivalent of Bill 25.
- SOC 2
- Independent CPA attestation (AICPA) on a service’s controls. Type I = design at a point in time; Type II = operating effectiveness over a period. At : Security, Availability, Confidentiality — Type II in progress, no Type I report first.
- ISO 27001
- International standard for managing information security. At : program approved, in preparation. Not certified until the certificate exists.
- DPA
- Data Processing Agreement. Contract between you and a vendor that processes personal information on your behalf.
- HIPAA
- US law protecting health information; requires a signed agreement (BAA) before a vendor can touch it.
- GLBA
- US financial-institutions law; its Safeguards Rule requires a security contract with every vendor.
- US state privacy laws
- Twenty US state laws requiring consent before processing sensitive data (health, ethnicity, biometrics).
- EU AI Act
- EU law governing risk-tiered AI systems; obligations for general-purpose models are already in force.
- ISO 42001
- International standard for AI management systems — bias, explainability, human oversight. In progress at , Q4 2026 audit target.