Current-state review
Look at policies, forms, systems, vendor usage, access patterns, and incident handling as they exist today.
Law 25 Gap Analysis Quebec • Privacy Review • Priorities
This page is for organizations that know Law 25 matters, but need a clearer view of what is already in place, what is missing, and which privacy or technical gaps actually deserve attention first.
Current-state review • Control gaps • Priority next steps
Why business owners land here
The goal of a gap analysis is not to produce a heavy document nobody uses. The goal is to identify where governance, systems, vendors, and day-to-day handling still fall short so the business can act in sequence.
Look at policies, forms, systems, vendor usage, access patterns, and incident handling as they exist today.
Pinpoint which privacy and operational controls are weak, missing, informal, or inconsistent.
Turn the findings into a realistic action order instead of a pile of disconnected recommendations.
What the review usually covers
The most important issues are rarely in one place. They usually sit across websites, forms, Microsoft 365, user access, vendor relationships, and the business processes that move personal information every day.
Review how personal information is requested, explained, stored, and routed from the public-facing side of the business.
Assess identity, sharing, access rights, and common operational patterns that affect privacy exposure.
Look at the software and service relationships that influence how personal information is processed.
Check whether the business can recognize, route, and document a confidentiality incident cleanly.
What usually forces action
The strongest fit is a team that wants to improve Law 25 readiness but still lacks a clear picture of what the current environment actually looks like.
Some policies exist, some controls exist, but the organization cannot yet explain the full operating picture clearly.
Privacy handling is spread across websites, SaaS tools, IT systems, and outside providers.
The business wants to know what to fix first instead of reacting to the loudest opinion.
A gap analysis helps decide whether the next move is a PIA workflow, incident process, site update, or technical control change.
FAQ
No. It is an operational and technical review that helps the business understand where privacy obligations intersect with systems, workflows, and controls.
The useful outcome is a clearer map of the current environment, the major control gaps, and the next actions that should be prioritized.
Yes. Public data-collection points are often part of the privacy handling picture and should be reviewed along with internal systems.
Often yes. Access, Microsoft 365 configuration, security controls, retention handling, and incident procedures frequently need follow-through after the review.
Related pages
Start with the parent page when the team still needs to choose between a gap analysis, privacy assessments, breach response planning, or broader Law 25 implementation.
Browse the full resource library when you want a deeper page under the core services.
A repeatable Law 25 privacy impact workflow for Quebec teams that need cleaner review around new tools, vendors, and data-handling changes.
Law 25 confidentiality-incident workflow support for Quebec teams that need cleaner coordination between privacy obligations and technical response.
Next step
We can review the environment, identify the biggest privacy-handling gaps, and turn them into a workable sequence of next steps.