Overseeing suppliers and subprocessors

Entrusting personal information to a supplier (cloud, payroll, email, analytics, AI) does not transfer responsibility: it remains yours.

The contract

When a supplier receives information to carry out a mandate, a written contract must notably provide for (s. 18.3):

  • the required protection measures;
  • use limited to the purposes of the mandate;
  • no retention after the mandate ends;
  • notice without delay of any incident or attempted breach;
  • your ability to carry out verifications.

Check before signing

Security questionnaire, independent attestations (SOC 2 Type II, ISO 27001), data location, list of further subprocessors, exit plan (data return and deletion).

Outside Québec

Before disclosing information outside Québec, a PIA concludes whether protection would be adequate (s. 17), and a written agreement frames the transfer. The hosting region (Canada vs United States) therefore matters in purchasing decisions.

Audit rights

Provide for the right to obtain third-party audit reports and, where needed, to carry out a reasonable verification.

Detailed legal framework: see the reference guide — Disclosure outside Québec and suppliers.