← Back to Insights
Compliance Education

A privacy impact assessment costs $0 if you do it yourself. Here's the walkthrough

Quebec's Law 25 requires a privacy impact assessment before certain AI deployments. A step-by-step walkthrough for owners who cannot afford a consultant.

By Augure Newsroom·
black and gray laptop computer turned on

Quebec's Commission d'accès à l'information received more than 14,000 complaints and inquiries in the 2023-2024 fiscal year, according to its own annual report, and a rising share concern how small organizations handle personal information when they adopt new software. A privacy impact assessment, or PIA, is the document Law 25 requires before that adoption happens. It sounds like the kind of thing that needs a lawyer. Mostly, it does not.

This is a walkthrough for the office manager or owner who has to produce one before turning on a new customer database, a marketing tool, or an AI platform that stores conversations and documents. No consultant, no $4,000 invoice — just the sections a real PIA needs, in order, and the questions a business actually has to answer.

What Law 25 Requires, Not What It Sounds Like

Quebec's Act respecting the protection of personal information in the private sector — the law everyone calls Law 25 — requires a business to conduct a privacy impact assessment before any project to acquire, develop, or overhaul an information system or electronic service delivery involving personal information. It also applies before sending personal data outside Quebec.

The wording is broad enough to cover a lot: a new CRM, a scheduling app that stores client phone numbers, an AI chat tool used to draft client emails if it retains those emails. It does not cover every software purchase — a static website redesign with no data collection generally would not trigger it — but the threshold is lower than most owners assume. The CAI has published guidance confirming that what the project does, not the size of the company doing it, is what matters.

There is no prescribed template in the statute itself. The CAI's own self-assessment guide is the closest thing to an official form, and it asks for five things: a project description, an inventory of personal information involved, a risk analysis, the mitigation measures in place, and a decision, signed by someone with actual authority, on whether the project proceeds.

Building the Document Section by Section

Start with the project description: one paragraph on what the tool is, what it does, why the business is buying it. This section trips people up because they overwrite it — a PIA is not a sales pitch, it is a factual record.

The information inventory takes the longest, and it should. List every category of personal information the new system will touch — names, emails, phone numbers, payment details, employee records, health information if it applies — and for each, note where it comes from, where it is stored, and who inside the business can access it. If the vendor is a cloud provider, this section also has to note where that vendor stores and processes the information, which is the point at which most businesses discover they do not actually know the answer, because most software vendors bury it three pages into a privacy policy.

Risk analysis comes next, and it does not require actuarial tables. Three questions cover most of it: what happens if this data is breached, what happens if it is used for something other than its stated purpose, and what happens if the vendor itself gets breached or acquired. A four-person accounting firm does not need a Monte Carlo simulation. It needs an honest paragraph on each.

Mitigation measures follow directly from the risks identified — encryption in transit and at rest, access controls, staff training, a data retention schedule, a breach notification plan. Some of this the business controls directly. Some of it is inherited from the vendor, which is why vendor selection and the PIA are not separate exercises.

The final section is the decision record: who reviewed the assessment, what they decided, and the date. This is the part regulators actually look for if a complaint arrives. A PIA that was never signed by anyone is, in practice, treated as if it never happened.

Where Vendor Choice Changes the Assessment

The vendor picked for any of this — CRM, storage, AI chat — determines how long the risk-analysis section runs. A tool built by a company with an unclear sub-processor list and a privacy policy written for a US audience forces the business to guess, and guessing does not hold up well if the CAI ever asks to see the document.

Augure, a Vancouver-based AI platform built for regulated Canadian organizations, publishes its sub-processor list and stores customer data in Canada, which shortens the inventory and residency sections of a PIA compared with a vendor whose answer requires a follow-up email to legal. According to Augure's own documentation, inference runs on Canadian infrastructure for most model tiers, with vetted EU partners under zero-data-retention agreements handling certain tiers and providing failover; limited US processing still exists for payment card networks and email delivery. None of that removes the requirement to write the PIA. It means the answer to "where does this data go" fits in one paragraph instead of a support ticket that may never get a reply.

A PIA that was never signed by anyone is, in practice, treated as if it never happened.

The same logic applies under the federal Personal Information Protection and Electronic Documents Act (PIPEDA), which does not use the term "privacy impact assessment" but imposes a comparable obligation to document risk assessment for any organization handling personal information in commercial activity outside Quebec. A business in Ontario or Alberta using the same AI tool inherits the same documentation problem, even without Law 25's explicit trigger.

Cost Comparison, Plainly

A consultant-drafted PIA for a small business typically runs $1,500 to $6,000, based on rates quoted by Quebec privacy law boutiques for straightforward single-system assessments. A DIY version using the CAI's own template costs the business its own time — four to six hours for someone who has never written one, less on the second attempt.

The math gets more interesting on the software side. A small business paying US$30 a month per seat for a mainstream AI chat subscription, times five employees, is over C$2,000 a year before anyone has written a word of compliance documentation, and that subscription still requires the vendor-inventory guesswork described above. Augure's Pro tier, priced at C$20 a month per user for comparable functionality, costs less and answers the residency question on its pricing page rather than in a support queue. Neither number replaces legal advice for a company handling health records or minors' data, where the CAI has signaled it expects more rigorous assessments. For most small businesses buying ordinary productivity software, the DIY path plus a Canadian vendor is the version that gets finished before the deadline instead of sitting in an inbox for three months waiting on a consultant's availability.

The unresolved question, and the CAI has not clarified it publicly, is how it treats a PIA that predates a vendor's own compliance updates — whether a business has to redo its assessment every time a supplier changes its data-handling terms, or only when the change is material. Businesses are, for now, making that call themselves.

A

About Augure

Augure is a sovereign AI platform for regulated Canadian organizations. Chat, knowledge base, and compliance tools — all running on Canadian infrastructure.

Ready to try sovereign AI?

Start free. No credit card required.

Get Started