Compliance · 7 min read

Section 17 of Law 25, explained to a CIO

Since September 2023, any transfer of personal information outside Quebec requires a documented assessment of the legal regime in the receiving state. Most organisations have not produced it, because they believe it is a legal matter.

Section 17 of the Act respecting the protection of personal information in the private sector — RLRQ c. P-39.1, as amended by Law 25 — says something simple: before communicating personal information outside Quebec, you must carry out a privacy impact assessment, and that assessment must take into account the legal regime applicable in the state where the information will be communicated.

Put plainly: the law asks you to write down which foreign laws your data is exposed to. When the recipient is a US-incorporated company, that is a CLOUD Act risk analysis. You already owe it.

Why the document almost never exists

Because it falls between two chairs. Legal treats it as an infrastructure matter: they do not know which workload runs in which region, or who operates the underlying service. IT treats it as a compliance matter: they are waiting for a template from legal that never arrives. The file stays open, and nobody is lying — each is waiting for the other.

This is not a legal opinion. It is an architecture plan with a jurisdiction column.

What the document must contain

An inventory, a map and a decision. Nothing more, but nothing less:

The residency trap

The most commonly proposed countermeasure is also the least effective: move the workload to a Canadian region. That changes nothing in the reasoning if the operator remains a US-incorporated company. The CLOUD Act follows the entity, not the building. A data centre in Quebec City operated by a US company sits in the same legal perimeter as one in Virginia.

This is the sentence that produces the longest silences in meetings, because it invalidates a project already budgeted. It forbids nothing, however: it simply forces you to write down why you accept the residual risk — which is what the law asked for in the first place.

How long it takes

For a mid-sized organisation, the flow inventory is the long part — it is fieldwork, not drafting. The legal mapping and the decision follow, and they go quickly once the inventory is right. The classic mistake is to start with the drafting: you then produce an elegant document describing a system that does not exist.

What you get beyond compliance

An accurate flow inventory stays useful long after the document is filed. It serves recovery planning, contract negotiation, supplier dependency analysis, and the next architecture decision. Organisations that do the exercise properly use it for years; those who hand it to the lowest bidder redo it two years later.

What to take away

If you cannot say today which personal data leaves Quebec and who operates it, section 17 is not your most urgent problem — your inventory is.

Read next

All articles

Start by seeing

What the outside sees of you.

A demonstration of Klarvant Namespace Command on your own domain. No fee, no installation, no access to your systems. The report is yours.

See your external surface