Quebec Law 25 Transfer Assessments: What Your Offshore Vendor Should Provide
Founder & Lead Engineer, RAITHub
Before a Québec business communicates personal information outside Québec, including to an offshore developer, Law 25 requires a privacy impact assessment and a written agreement; this obligation took effect in September 2023. The vendor cannot do the assessment for you, but it should hand over what the assessment needs: a data map, a sub-processor list and a description of its security measures.
This post is for Québec founders, operators and privacy leads who are about to hire a software vendor outside the province, whether in another Canadian province or overseas. RAITHub is one such vendor, based in Dhaka, Bangladesh. This is general information, not legal advice. RAITHub has no legal expertise; confirm every point with your adviser and read the current text of the law. The regulator is the Commission d'accès à l'information du Québec (CAI).
What does Law 25 require before personal information leaves Québec?
A privacy impact assessment first, then a written agreement. The CAI's guidance for private businesses says an organization must carry out an assessment of privacy-related factors (in French, an évaluation des facteurs relatifs à la vie privée, or EFVP) before communicating personal information outside Québec, and that the communication "doit toujours faire l'objet d'une entente écrite": it must always be covered by a written agreement (CAI: use and communication of personal information).
According to the CAI, the assessment considers the sensitivity of the information, the purpose of its use, its quantity, its distribution and the medium it is held on. The communication can go ahead if the assessment shows the information would receive adequate protection, in particular with regard to generally recognized principles of personal information protection. The CAI's summary of the main changes dates this obligation to September 2023 (CAI: main changes under Law 25).
Law 25 amended the Act respecting the protection of personal information in the private sector (CQLR c P-39.1). The outside-Québec rule is commonly cited as section 17 of that Act. Read the current wording, including the full list of factors, on LégisQuébec, and confirm the section and how it applies to you with your adviser.
Does hiring an offshore developer count as communicating information outside Québec?
If the vendor's people can see personal information from outside the province, plan as if it does. The rule, as the CAI describes it, is about communication outside Québec, which reads as covering other provinces as well as other countries. Whether remote access to data hosted in Québec counts is a question for your adviser; the safer engineering assumption is that it does.
That assumption changes the design question from "can we send data abroad?" to "does the vendor need to see personal information at all?". For most of a software build, it does not. Engineers can write and test code against synthetic data, and only a small number of tasks, such as diagnosing a production incident, need controlled access to real records.
Is there a second assessment for the software project itself?
Often, yes. The CAI states that an EFVP is required for any project involving an information system or electronic service delivery that involves personal information (CAI: the person in charge of the protection of personal information). So a new customer portal or booking platform may need an assessment as a project, and a separate look at the outside-Québec communication if an offshore vendor is involved. Ask your adviser whether one document can cover both in your case.
The same CAI page says the person with the highest authority in the business, such as its chief executive, is by default the person in charge of the protection of personal information, and that this person's title and contact details must be published on the website. The vendor cannot take that role.
What should the service provider contract say?
The CAI lists three things. Personal information can be communicated to a service provider without consent when it is necessary to carry out a mandate or a service contract, but the mandate or contract must be in writing and must specify the measures the provider takes to ensure (CAI):
- that the information stays confidential,
- that it is used only to carry out the mandate or contract, and
- that it is not kept after the mandate or contract ends.
Those are the floor. Contracts commonly add the points your own obligations depend on: how quickly the vendor tells you about an incident, your right to check its safeguards, approval before new sub-processors, and how data is returned or destroyed at the end. Your adviser decides the wording; the offshore IP checklist covers the ownership side of the same contract.
What should an offshore vendor hand over for your assessment?
Everything the assessment asks about that only the vendor knows: what data it will touch, where, through which third parties, and how it is protected. A vendor that cannot produce this in writing is telling you something.
| # | What the vendor hands over | What it shows your assessment |
|---|---|---|
| 1 | A data map: each category of personal information the vendor could access, the fields, the purpose and the system it lives in | Sensitivity, purpose and quantity |
| 2 | Where data is stored and where people access it from, by country | Distribution and medium |
| 3 | A sub-processor list: every third party that could receive data (hosting, email, error tracking, AI APIs), with its location | Distribution, and who else is involved |
| 4 | The access model: named roles, least privilege, multi-factor sign-in, access only through accounts you own | Security measures |
| 5 | A written description of security measures: encryption, secrets handling, logging, backups, device rules | Whether protection would be adequate |
| 6 | A production-data policy: synthetic data for development, and when real data is touched, by whom, with what record | Quantity actually communicated |
| 7 | Incident terms: how fast the vendor tells you, and what it tells you | Your incident register and notices |
| 8 | An exit plan: return or deletion of data and credentials when the contract ends | The "not kept after the contract" term |
| 9 | Signed contract terms: confidentiality, use only for the mandate, no retention after the end | The written agreement and contract the CAI requires |
| 10 | A plain statement of which data protection law applies in the vendor's country, as the vendor understands it | Input for your adviser, not a legal opinion |
Row 10 needs care. A vendor can tell you where it operates and which rules it believes apply, but assessing a foreign legal framework is your adviser's job, not the vendor's.
What does a useful data map look like?
One entry per category of personal information, precise enough that your adviser can judge sensitivity and your engineers can enforce it. Keeping it in the repository, as typed data, means it is reviewed with every change that adds a field. A minimal shape, as engineering guidance:
type VendorAccess = 'none' | 'synthetic-only' | 'break-glass'
interface DataMapEntry {
category: string
fields: string[]
purpose: string
storedIn: string // system and hosting region
accessedFrom: string[] // countries where people can see it
vendorAccess: VendorAccess
subProcessors: string[]
retention: string
}
export const dataMap: DataMapEntry[] = [
{
category: 'Customer contact details',
fields: ['full_name', 'email', 'phone'],
purpose: 'Account sign-in and service notices',
storedIn: 'Postgres, client-owned account, Canadian region',
accessedFrom: ['Canada'],
vendorAccess: 'synthetic-only',
subProcessors: ['Hosting provider', 'Transactional email provider'],
retention: 'Life of the account, then deleted',
},
{
category: 'Payment references',
fields: ['processor_customer_id', 'last4'],
purpose: 'Reconciling payments',
storedIn: 'Postgres, client-owned account, Canadian region',
accessedFrom: ['Canada', 'Bangladesh'],
vendorAccess: 'break-glass',
subProcessors: ['Payment processor'],
retention: 'As your accounting retention rules require',
},
]
The second entry is the one your assessment will spend time on, because it records access from outside Québec. The honest version of this map is what makes the assessment possible, and it often shows that very little needs to leave the province.
How do you keep personal information from leaving Québec during the build?
Design the engagement so the vendor rarely needs it. Four habits cover most of it:
- Host in accounts you own, in the region your assessment prefers, with the vendor as a removable member rather than the account owner.
- Develop on synthetic data. Seed scripts that generate realistic fake records mean engineers never need a copy of production.
- Make production access an event. Access to real data for an incident is granted for a named person and a limited time, and recorded. An audit log is the record.
- Scope data inside the database, not only in the application, so a bug in one screen cannot expose another customer's records. The Postgres row-level security guide shows how.
None of this replaces the assessment. It changes what the assessment has to weigh.
What happens if there is a confidentiality incident at the vendor?
You stay responsible. The CAI says businesses remain responsible for their obligations when a service provider holds the information, including mitigation, the incident register and the required notices. Incidents that present a risk of serious injury must be reported to the CAI and to the people concerned, and every incident goes in the register (CAI: confidentiality incidents and security measures). The CAI also notes administrative monetary penalties of up to $10 million or 2% of worldwide turnover.
That is why row 7 of the checklist matters: your register can only be as good as what the vendor tells you, and how fast.
How does PIPEDA fit alongside Law 25?
The federal Office of the Privacy Commissioner lists Québec as one of three provinces with a substantially similar private-sector law, and says organizations subject to those laws are generally exempt from PIPEDA for information handled within the province (OPC: PIPEDA in brief). Information that crosses provincial or national borders in the course of commercial activity can bring PIPEDA in as well. Which applies to which data flow is a question for your adviser.
Québec's French-language rules are a separate matter from Law 25 and are outside this post; the Office québécois de la langue française is the regulator.
How does the working day look with a Dhaka vendor?
Dhaka is UTC+6 with no daylight saving, so there is almost no natural overlap with Montréal. RAITHub offers a daily 2-hour window, 19:00 to 21:00 Dhaka time, which is 08:00 to 10:00 in Montréal in winter and 09:00 to 11:00 in summer. Everything else is async, with a written handoff every day, and the working week is agreed per client. For privacy work that suits the rhythm: questions about the data map arrive in writing, and the answers are written down too.
Why RAITHub for this?
- The vendor pack, in writing. RAITHub prepares the data map, sub-processor list, access model and description of security measures for your assessment, and updates them when the build changes.
- Your contract, your controls. RAITHub signs data processing terms, works to your controls and in accounts you own, and signs an NDA before detailed discussion. The client owns the IP.
- Isolation that is enforced and tested. Sundor Skin has 146 PostgreSQL tables with row-level security and 530+ tests, and its CI fails if a buyer-scoped table lacks a policy.
- Straight answers about what we are not. Not SOC 2 or ISO 27001 certified, no legal advice, English only. See how RAITHub protects your code and data, and the SaaS development service for the build itself.
When you don't need us
- You need the assessment written or signed off. That is your organization's and your adviser's work. RAITHub supplies the facts about its own side.
- Your assessment concludes no one outside Québec should access the data. Then hire a team inside the province.
- You need French-language delivery. RAITHub works in English only.
- You are a public body. Public bodies fall under a different Act, and procurement rules of their own.
- Your buyers require a certified supplier. RAITHub holds no SOC 2 or ISO 27001 certification. For a first questionnaire, see answering a security questionnaire without SOC 2.
Sources checked on 30 September 2026. General information only, not legal advice; confirm with your adviser and read the current text on LégisQuébec.
If you want an offshore build with the vendor pack ready before your assessment starts, book the free 15-minute technical audit. Bring a rough list of the personal information your product will hold.
Frequently asked questions
What does Law 25 require before sending personal information outside Québec?
According to the CAI, a privacy impact assessment that considers the sensitivity, purpose, quantity, distribution and medium of the information, and a written agreement. The CAI dates this obligation to September 2023. This is general information; confirm with your adviser.
Which section of the Act covers communication outside Québec?
It is commonly cited as section 17 of the Act respecting the protection of personal information in the private sector (CQLR c P-39.1). Read the current wording on LégisQuébec and confirm with your adviser before relying on it.
Can the offshore vendor do the privacy impact assessment for us?
No. The assessment is the Québec business's own obligation. The vendor should supply the facts about its side in writing: a data map, where data is accessed from, its sub-processors, its security measures and its incident terms.
What must a Québec service provider contract include?
The CAI says it must be in writing and specify the measures that keep the information confidential, limit its use to the mandate or contract, and ensure it is not kept after the contract ends. Your adviser may add incident, audit and sub-processor terms.
Does another Canadian province count as outside Québec?
The rule, as the CAI describes it, is about communication outside Québec, which reads as including other provinces. Confirm how it applies to your data flows with your adviser.
Who is responsible if the vendor has a data breach?
The Québec business. The CAI says businesses stay responsible for mitigation, the incident register and required notices even when a service provider holds the information, so the contract should require prompt notice from the vendor.
Does RAITHub provide a data map and sub-processor list?
Yes. RAITHub prepares both, with a written description of its access model and security measures, and signs data processing terms. RAITHub does not give legal advice or hold SOC 2 or ISO 27001 certification.
Related posts
Ready to discuss your project?
Book a free 15-minute technical audit with our engineering team.