October 2022

Your company is responsible for personal information records. Beware of fines!

Legislation that went into effect this fall calls for hefty fines for businesses of all sizes that fail to adequately protect themselves from personal data leaks.

On Sept. 22, 2022, the Privacy Act 25 expands with a series of mandatory rules for businesses of all sizes.

Your company is responsible for personal information records. Beware of fines!

Some of the new rules are as follows

- Designate a person in charge of the protection of personal information, as well as the formation of a committee

- Notify the Commission and the persons concerned of any confidentiality incident involving personal information in their possession and presenting a risk of serious injury.

 

Bill 25, "Privacy Modernization Act", is becoming a headache for businesses of all sizes, as it has been growing since Sept. 22, 2022 and will continue to do so through 2023 and 2024

Bill 25 modernizes privacy legislation

What is personal information? Any information about an individual that directly or indirectly identifies the individual

Now, if your company stores any of this data, whether in the cloud or elsewhere, it becomes legally responsible for protecting that data.

If a privacy incident, a "hack" as we say, occurs, the victim company could be penalized if it did not have the systems in place required by law.

As of September 22, 2023, the Commission will have the authority to impose administrative monetary penalties. For example, administrative penalties could be as high as 2% of worldwide turnover or $10 million.

Section 68..8. item 4 of Act 64 states that a "privacy incident may be;

 (4) the loss of personal information or any other breach of the protection of such information.

While beneficial to the public, ensuring the safe and secure management of valuable personal data, this legislation will force companies of all sizes to invest in and secure their IT infrastructures and strengthen the protections in place.

Fortunately, the protection products currently available can assure the entrepreneur that his data and that of his clients are safe. Natrix, for instance, offers several levels of support for a business' IT environment and offers services that can be adapted to the needs of any size.

It becomes clear that in the long run, this kind of initiative will result in time and money saved and will reduce crisis handling needs. Contact us for an in-depth analysis of your needs and available solutions.

Back