Overseeing suppliers and subprocessors
Entrusting personal information to a supplier (cloud, payroll, email, analytics, AI) does not transfer responsibility: it remains yours.
The contract
When a supplier receives information to carry out a mandate, a written contract must notably provide for (s. 18.3):
- the required protection measures;
- use limited to the purposes of the mandate;
- no retention after the mandate ends;
- notice without delay of any incident or attempted breach;
- your ability to carry out verifications.
Check before signing
Security questionnaire, independent attestations (SOC 2 Type II, ISO 27001), data location, list of further subprocessors, exit plan (data return and deletion).
Outside Québec
Before disclosing information outside Québec, a PIA concludes whether protection would be adequate (s. 17), and a written agreement frames the transfer. The hosting region (Canada vs United States) therefore matters in purchasing decisions.
Audit rights
Provide for the right to obtain third-party audit reports and, where needed, to carry out a reasonable verification.
Detailed legal framework: see the reference guide — Disclosure outside Québec and suppliers.