Law 25 / GDPR audit
Law 25 is fully in force, PIPEDA still applies, and European clients add
the GDPR to their contracts.
Meanwhile the compliance declared in a
policy and the reality of a system often diverge: fields collected
beyond need, retention periods never enforced, processors missing from
the record.
The audit measures that gap precisely, because the gap is
what costs money in an inspection, a complaint or an incident.
The system is the evidence
Verified in the code
Policies and records are read, then checked against the code and the databases: what is actually collected, kept, shared and deleted. Gaps are documented with their exact location.
All regimes in one pass
Law 25 and PIPEDA, plus the GDPR, UK GDPR or CCPA if your users trigger them. A single architecture covers the whole, without redundant or contradictory measures.
A deliberate ranking
Not everything is urgent. The plan separates what exposes you to a sanction or a lost contract from what can wait a cycle, and the trade-off is reasoned in writing.
Fifteen business days, four steps
Map
The real map of your processing, built from the systems: data, flows, processors, jurisdictions.
Compare
Each processing activity examined against its requirements: legal basis or consent, notice, retention, security, individual rights, transfers, PIAs where required.
Verify
The code and the infrastructure are checked to confirm the system does what the policy announces.
Correct
Delivery of the ranked action plan, the corrected records and policies, and the evidence organised for the CAI, a client or an auditor.
The deliverables
Documents your teams can act on, your advisers can confirm and your clients can sign against.
- Processing and flow map: data, purposes, processors, jurisdictions, retention.
- Law 25 records and policies: created or corrected, ready to present.
- Gap analysis: the finding, its location in the system, the risk and the proposed fix.
- PIAs where required: documented, dated and reasoned.
- Ranked action plan: dated and costed, executable by your teams or by ours.
- Incident and rights procedures: notification, registers and deadlines, tested with your teams.
Pricing. The audit is quoted in detail, from CA$12,500 depending on the number of processing activities and applicable regimes. A written preliminary assessment opens the engagement (CA$2,200 (plus taxes), delivered within five business days); its price is credited against the audit.
Have your processing verified
Describe your situation in a few lines. The preliminary assessment identifies the gaps that expose you most.