Offers · Audit

Law 25 / GDPR audit

Law 25 is fully in force, PIPEDA still applies, and European clients add the GDPR to their contracts.
Meanwhile the compliance declared in a policy and the reality of a system often diverge: fields collected beyond need, retention periods never enforced, processors missing from the record.
The audit measures that gap precisely, because the gap is what costs money in an inspection, a complaint or an incident.

15 business days from CA$12,500 Action plan ranked by risk
Our approach

The system is the evidence

Verified in the code

Policies and records are read, then checked against the code and the databases: what is actually collected, kept, shared and deleted. Gaps are documented with their exact location.

All regimes in one pass

Law 25 and PIPEDA, plus the GDPR, UK GDPR or CCPA if your users trigger them. A single architecture covers the whole, without redundant or contradictory measures.

A deliberate ranking

Not everything is urgent. The plan separates what exposes you to a sanction or a lost contract from what can wait a cycle, and the trade-off is reasoned in writing.

How it runs

Fifteen business days, four steps

01

Map

The real map of your processing, built from the systems: data, flows, processors, jurisdictions.

02

Compare

Each processing activity examined against its requirements: legal basis or consent, notice, retention, security, individual rights, transfers, PIAs where required.

03

Verify

The code and the infrastructure are checked to confirm the system does what the policy announces.

04

Correct

Delivery of the ranked action plan, the corrected records and policies, and the evidence organised for the CAI, a client or an auditor.

Deliverables

The deliverables

Documents your teams can act on, your advisers can confirm and your clients can sign against.

  • Processing and flow map: data, purposes, processors, jurisdictions, retention.
  • Law 25 records and policies: created or corrected, ready to present.
  • Gap analysis: the finding, its location in the system, the risk and the proposed fix.
  • PIAs where required: documented, dated and reasoned.
  • Ranked action plan: dated and costed, executable by your teams or by ours.
  • Incident and rights procedures: notification, registers and deadlines, tested with your teams.

Pricing. The audit is quoted in detail, from CA$12,500 depending on the number of processing activities and applicable regimes. A written preliminary assessment opens the engagement (CA$2,200 (plus taxes), delivered within five business days); its price is credited against the audit.

Have your processing verified

Describe your situation in a few lines. The preliminary assessment identifies the gaps that expose you most.

Contact us