Section 17 of Law 25, explained to a CIO
Since September 2023, any transfer of personal information outside Quebec requires a documented assessment of the legal regime in the receiving state. Most organisations have not produced it, because they believe it is a legal matter.
Section 17 of the Act respecting the protection of personal information in the private sector — RLRQ c. P-39.1, as amended by Law 25 — says something simple: before communicating personal information outside Quebec, you must carry out a privacy impact assessment, and that assessment must take into account the legal regime applicable in the state where the information will be communicated.
Put plainly: the law asks you to write down which foreign laws your data is exposed to. When the recipient is a US-incorporated company, that is a CLOUD Act risk analysis. You already owe it.
Why the document almost never exists
Because it falls between two chairs. Legal treats it as an infrastructure matter: they do not know which workload runs in which region, or who operates the underlying service. IT treats it as a compliance matter: they are waiting for a template from legal that never arrives. The file stays open, and nobody is lying — each is waiting for the other.
This is not a legal opinion. It is an architecture plan with a jurisdiction column.
What the document must contain
An inventory, a map and a decision. Nothing more, but nothing less:
- The inventory of flows. Which personal data leaves Quebec, to which service, how often, in what form. Logs and backups count, and that is where inventories turn out to be wrong.
- The actual recipient. Not the commercial name of the service, but the entity that operates it and the law it answers to. This is the line that decides the file.
- The applicable legal regime. CLOUD Act, FISA 702 where relevant, and the remedies actually open to the individual concerned.
- The measures that reduce exposure. Encryption with keys you hold, minimisation, pseudonymisation, residency, or moving the workload.
- The decision and its rationale. Including the decision to change nothing, if it is reasoned.
The residency trap
The most commonly proposed countermeasure is also the least effective: move the workload to a Canadian region. That changes nothing in the reasoning if the operator remains a US-incorporated company. The CLOUD Act follows the entity, not the building. A data centre in Quebec City operated by a US company sits in the same legal perimeter as one in Virginia.
This is the sentence that produces the longest silences in meetings, because it invalidates a project already budgeted. It forbids nothing, however: it simply forces you to write down why you accept the residual risk — which is what the law asked for in the first place.
How long it takes
For a mid-sized organisation, the flow inventory is the long part — it is fieldwork, not drafting. The legal mapping and the decision follow, and they go quickly once the inventory is right. The classic mistake is to start with the drafting: you then produce an elegant document describing a system that does not exist.
What you get beyond compliance
An accurate flow inventory stays useful long after the document is filed. It serves recovery planning, contract negotiation, supplier dependency analysis, and the next architecture decision. Organisations that do the exercise properly use it for years; those who hand it to the lowest bidder redo it two years later.
If you cannot say today which personal data leaves Quebec and who operates it, section 17 is not your most urgent problem — your inventory is.