ISO 27001 · ISO 42001 · GDPR · PCI DSS · Loi 25

data-privacy

  • PIPEDA: Consent and Purpose — The Two Principles SMBs Get Wrong

    8 min read

    PIPEDA’s Principles 2 and 3 — Identifying Purposes and Consent — are the two rules SMB IT teams break most. A grounded deep-dive into the statute text: purpose identification at collection, the no-condition rule, express vs implied consent, withdrawal, and the reasonable-person test for appropriate purposes.

    Read →

  • PIPEDA vs Loi 25 vs GDPR: The Cross-Border SMB Compliance Map

    8 min read

    A Canadian SMB that also serves EU or Quebec customers can trigger all three regimes at once. Side-by-side map of PIPEDA, Loi 25, and GDPR — scope, authority, officer, breach clock, access response, impact assessment, portability, transfers, and enforcement — grounded in the statute and regulation text.

    Read →

  • GDPR for SMBs: Why You Are Subject

    8 min read

    A pragmatic intro to the GDPR for solo and small-team IT admins — Article 3 territorial scope, the seven principles and six lawful bases, data-subject rights, the 72-hour breach rule, and a 90-day roadmap.

    Read →