Compliance

Compliance, treated as engineering.

The texts that govern your activity translate into technical requirements: retention periods, encryption, logs, procedures.
We implement them in the system itself and keep the documentation that attests to it up to date.

Law 25 PIPEDA CCPA PCI DSS FINTRAC GDPR +65 more
Our conviction

A property of the whole system

Compliance depends on the architecture, the code, the infrastructure, the processes and the documentation. It is, from end to end, engineering work.

A cross-cutting requirement

Data protection, payment and sector constraints overlap. Handling them within one architecture avoids redundant or contradictory measures.

A competitive advantage

A solid compliance file speeds up everything else: bank onboarding, payment providers, tenders, client audits. Documentary disorder, on the other hand, closes doors.

A matter of evidence

A regulator, an auditor or a partner will not settle for an assertion. The system therefore keeps, for any requirement, written and dated evidence of what it does.

Practice areas

Six regulatory terrains we know from the inside

Our compliance practice was built on real systems, in contact with industries where documentary error carries a real cost.

Personal data and privacy

Law 25 (Québec), PIPEDA, GDPR and ePrivacy: processing registers, privacy impact assessments, incident management, individual rights, cross-border transfers.

Payments and card networks

Onboarding files for payment providers, card network requirements, PCI DSS scoping, descriptors, dispute and chargeback handling, mandatory contractual pages.

Regulated online platforms

Age and identity verification, moderation and reporting channels, content traceability, takedown obligations, record-keeping required by partners and regulators.

Financial services

Systems in contact with financial players: anti-money laundering and anti-terrorist financing requirements, separation of duties, audit logs, access governance.

Health and life sciences

Health data and demanding environments inherited from pharma: documentary traceability, system qualification, regulated information, strict isolation of sensitive data.

International trade

Practice acquired in import-export: export controls, sanctions regimes, customs documentation, traceability of supply chains and cross-border data flows.

Catalogue

More than 70 regulatory perimeters in our catalogue

The method stays the same from one framework to the next.
The catalogue below lists those we have already instrumented or know how to instrument.

Privacy and personal data

Personal information protection, across regimes.

Law 25 Quebec Personal information
PIPEDA Canada Federal privacy
GDPR European Union Data protection
UK GDPR United Kingdom Data protection
ePrivacy European Union Cookies and communications
CCPA United States California privacy
LGPD Brazil Data protection
nFADP Switzerland Data protection
SCCs European Union International transfers

Payments and card processing

Acquirer, network and regulator requirements.

PCI DSS Card data security
PSD2 European Union Payment services
SCA · 3DS European Union Strong authentication
Visa · MC Network rules
SEPA European Union European payments
VAMP Monitoring programs
Disputes Chargebacks and evidence

Anti-money laundering and sanctions

AML/CFT obligations and international sanctions regimes.

FINTRAC Canada AML/CFT reporting
AMLD European Union Anti-money laundering directives
FATF Recommendations
KYC · KYB Customer due diligence
OFAC United States US sanctions
EU · UN Sanctions regimes

Platforms and content

Obligations of online services and marketplaces.

DSA European Union Digital services
OSA United Kingdom Online safety
COPPA United States Protection of minors
§ 2257 United States Record keeping
18+ Age verification
Takedown Removal obligations
Bill 96 Quebec Charter of the French language

Information security

Security, audit and hardening frameworks.

ISO 27001 Security management
ISO 27017/18 Cloud security
ISO 27701 Privacy management
SOC 2 United States Trust services criteria
NIST CSF United States Cybersecurity framework
CIS System hardening
ASVS Application security
Top 10 OWASP risks

Artificial intelligence

Governance of AI systems and automated decisions.

AI Act European Union AI systems
ISO 42001 AI management
AI RMF United States NIST risk management
ADM Canada Automated decisions directive

Marketing and consumer law

Commercial communications and consumer rights.

CASL Canada Anti-spam
CAN-SPAM United States Commercial email
CPA Quebec Consumer protection
CRTC Canada Telecommunications
Omnibus European Union Consumer rights

Tax and invoicing

Tax obligations of digital and cross-border sales.

GST · QST Quebec Sales taxes
OSS · IOSS European Union European VAT
DAC7 European Union Digital platforms
e-Invoicing European Union Electronic invoicing
Nexus United States US sales tax

Health and life sciences

Health data and qualified environments.

HIPAA United States Health data
21 CFR 11 United States Electronic records
Annex 11 European Union Computerised systems
GAMP 5 System validation
GxP Good practices
HDS France Health data hosting

International trade

Export controls and customs discipline.

EAR United States Export controls
ITAR United States Defence articles
Dual-use European Union Sensitive goods
Incoterms Trade terms
AEO Authorised operator
Customs Documentation and origin

Resilience and continuity

Business continuity and critical infrastructure security.

DORA European Union Financial resilience
NIS 2 European Union Critical infrastructure
ISO 22301 Business continuity
C-26 Canada Federal cybersecurity

Accessibility

Digital services accessible to every audience.

WCAG 2.2 Web accessibility
EN 301 549 European Union European standard
RGAA France French framework
ADA United States US accessibility

From text to system: each perimeter in the catalogue is a text or standard we read at the source, translate into technical requirements and instrument in the system. For audited frameworks, such as ISO 27001, SOC 2 or PCI DSS, we prepare your systems, your processes and your evidence for the auditor.

Method

From obligation to evidence, in four steps

The treatment is identical whatever the text. The obligation is converted into a technical requirement, the requirement is implemented, and the system keeps track of what it does.

01

Map

Identify the texts that actually apply to your activity, your data, your flows and your jurisdictions.

02

Translate

Convert each obligation into a measurable technical requirement: retention, encryption, consent, logging, procedures.

03

Implement

Build the requirements into the code, the infrastructure and the processes, at the system's design stage.

04

Prove

Produce and maintain the evidence: registers, logs, audit trails and dated documentation, available on request.

Deliverables

The deliverables

Written, dated documents that your teams and your advisers can use. They describe the gap found, its correction and the corresponding evidence.

  • Gap audit: current state against the applicable texts, action plan prioritized by risk.
  • Registers and policies: processing register, privacy policy, incident and notification procedures.
  • Privacy assessments: PIAs for projects and transfers outside Québec, documented and dated.
  • Payment provider files: complete onboarding file, contractual pages, compliant payment flows.
  • Data flow mapping: data, processors, jurisdictions, legal bases, retention periods.
  • Logging and audit trails: implemented in the system, with evidence available on demand.
Field experience

The industries we come from

Our practice comes from four industries where compliance is a condition of doing business.

01

Finance

Environments subject to anti-money laundering requirements, transaction traceability and access governance.

02

Pharma and health

A culture of documentary traceability and system qualification, inherited from pharmaceutical environments.

03

Import-export

Export controls, sanctions, customs documentation: the discipline of international supply chains.

04

Online platforms

Age verification, records, notice handling: the discipline of operating under continuous obligations.

The field first. One regulatory file follows another, payments, data, platforms, on our own systems and on our clients'. The catalogue above is that practice, kept alive in production.

Unsure about your compliance?

Write to us. We reply within two business days, with a frank first read of your most urgent gaps.

Contact us