Digital Performance
Law 25 Operational Audit
In 10 days: full personal-data inventory, quantified gaps vs Law 25, prioritized compliance plan and publish-ready templates.
Is this offer right for you?
For you if…
- You collect personal information — forms, CRM, newsletter — without an up-to-date register or policy.
- A client, partner or insurer is asking for proof of compliance.
- You want to know your actual gaps and their risk level before investing in fixes.
- No one internally owns the file and you need a concrete starting point.
Not for you if…
- You need a formal legal opinion — we document the gaps and work with your counsel as needed.
- Your organization exceeds the SMB frame — multiple entities, sites or jurisdictions: the 10-day format needs rescoping before committing.
- You only want a cookie banner installed, without looking at the rest — that would be surface-level compliance.
What the mandate covers
Included in the mandate
- 1Inventory of personal information collected: site, CRM, tools
- 2Cookie, consent and banner audit
- 3Third-party and processor review: contracts, transfers outside Quebec
- 4Gap analysis vs Law 25 obligations
- 5Prioritized compliance plan
- 6Templates: privacy policy, register, incident response
Not included
- A formal legal opinion (we work with your counsel as needed)
- Technical implementation of fixes (quotable afterward)
- Full European GDPR compliance
Concrete deliverables
- Audit report with risk level per gap
- Compliance plan: actions, priorities, owners
- Pre-filled processing register
- Compliant privacy policy and banner
- 90-minute readout session
How the mandate unfolds
- 1
Days 1-3 — Inventory and collection
Data, tool and flow mapping; contract access.
- 2
Days 4-7 — Gap analysis
Gaps vs obligations, risk level, prioritization.
- 3
Days 8-10 — Plan and readout
Compliance plan, templates delivered, 90-min session.
Delivery guarantee
Scope, deliverables and schedule are fixed in the contract before kickoff. If a deliverable slips because of us, we complete it at no extra charge — no open-ended billing.
Risks and mitigations
No mandate is risk-free. Here are the most common ones for this type of mandate, and how the process addresses them.
The compliance plan goes nowhere after the readout.
Each action ships with a priority, a proposed owner and, where relevant, a publish-ready template; the readout session closes on the first actions to take.
The inventory misses tools or data flows.
Collection cross-references three sources — interviews, tool review, contract review — and uncovered areas are named in the report rather than left unsaid.
Who does the work
The audit is led by the founder. Depending on the file, an experienced privacy advisor joins the analysis; their participation is confirmed at framing. We do not replace your legal counsel.
Ready to start?
30 minutes to confirm whether this offer fits your situation. No commitment.
Book my call (new tab)Frequently asked questions
Does Law 25 really apply to us?+
Any business collecting personal information in Quebec is subject to it — a simple contact form qualifies. Penalties can reach $25M or 4% of worldwide revenue.
10 days, really?+
Yes, for an SMB with one site, one CRM and under 20 SaaS tools. Beyond that, we adjust scope before starting.
What happens after the audit?+
You execute the plan internally, or we quote the implementation of the priority fixes.