ISO 27001 · ISO 42001 · GDPR · PCI DSS · Loi 25

it-operations

  • How to Run Your First Tabletop Exercise: An SMB Walkthrough

    6 min read

    ISO 27001:2022 controls A.5.24 to A.5.27 require planned, practiced incident response. A tabletop exercise is the cheapest way to test it. Here is how a small IT team runs its first one in 90 minutes, with a ready-to-use scenario.

    Read →

  • CPPA Reform 2025 Readiness: What Canadian SMBs Do While Bill C-27 Finishes

    6 min read

    Bill C-27 replaces PIPEDA with the Consumer Privacy Protection Act, adds a data-protection tribunal, and introduces the Artificial Intelligence and Data Act. The exact penalty ceilings and final provisions will be set by the enacted bill — but seven readiness actions are PIPEDA-good today and CPPA-ready tomorrow. A grounded getting-started guide for SMB IT.

    Read →

  • PIPEDA: Consent and Purpose — The Two Principles SMBs Get Wrong

    6 min read

    PIPEDA’s Principles 2 and 3 — Identifying Purposes and Consent — are the two rules SMB IT teams break most. A grounded deep-dive into the statute text: purpose identification at collection, the no-condition rule, express vs implied consent, withdrawal, and the reasonable-person test for appropriate purposes.

    Read →

  • Law 25: SMB Getting-Started Checklist (30-60-90 Days)

    6 min read

    Law 25 imposes twelve obligations across three phases (2022, 2023, 2024). For an SMB starting out, order matters: appoint the officer, stand up the incident register, then build governance. Here is a 30-60-90-day checklist by phase.

    Read →

  • Quebec Law 25: Appointing the Personal-Information Officer

    6 min read

    Law 25 (Article 3.1) requires every private-sector organisation to appoint a personal-information officer and publish their contact details. It is the first obligation, in force since 22 September 2022. Here is the role, the delegation, and how an SMB stands it up.

    Read →

  • Quebec Law 25: Confidentiality Incidents, Register, and Notice Deadline

    6 min read

    Law 25 (Articles 3.5–3.8) requires a register of every confidentiality incident and notice to the CAI and affected individuals when there is a risk of serious prejudice. Unlike GDPR, there is no 72-hour clock — notice is ‘as soon as possible.’ Here is what the Law requires.

    Read →

  • PIPEDA vs Loi 25 vs GDPR: The Cross-Border SMB Compliance Map

    6 min read

    A Canadian SMB that also serves EU or Quebec customers can trigger all three regimes at once. Side-by-side map of PIPEDA, Loi 25, and GDPR — scope, authority, officer, breach clock, access response, impact assessment, portability, transfers, and enforcement — grounded in the statute and regulation text.

    Read →

  • Law 25 and GDPR: Parallelism and a Joint Programme for an SMB

    6 min read

    Law 25 transposes several GDPR elements into Quebec’s private sector: an officer, a PIA, an incident register, portability. An SMB subject to both can fuse the artifacts and run one programme. Here is the correspondence and the divergences.

    Read →

  • GDPR DPIA Template: A Data Protection Impact Assessment an SMB Can Fill

    6 min read

    GDPR Article 35 requires a DPIA for high-risk processing — profiling, large-scale special-category data, systematic monitoring, new-technology employee tracking. Here is what the assessment must contain, a fill-in template, and a worked SMB example.

    Read →

  • GDPR Data Subject Rights and the 72-Hour Breach Clock

    6 min read

    GDPR gives data subjects eight rights, and it gives you one month to answer them — and 72 hours to report a breach. Here is what each right requires, the response clock, and the breach-notification contents an SMB must assemble in three days.

    Read →