Guide G8 Compliance & governance
“We need to be compliant” is not a scope. Name the framework and the artifact.
Quebec's Law 25 and the federal PIPEDA create specific, real obligations: a privacy policy, a breach process, a personal-information inventory, and vendor agreements, among others. A vague compliance worry is not yet a scope. This guide separates an active incident from a planned assessment or an ongoing privacy program.
G8 · Entry 01 Three different compliance jobs
Start with what actually triggered the question.
There's an active incident or complaint
A breach, client complaint, or regulator letter needs an existing incident, legal, or insurer process - not a general directory.
No one has inventoried personal information
A bounded review can map what personal data exists, where it lives, and what documents are missing.
Policies exist but nobody keeps them current
Ongoing ownership matters when a privacy policy, training, and vendor list need a dependable review cadence.
G8 · Entry 02 Decision matrix
Match the situation to the right first route.
| Observed need | Best first route | Useful evidence | Boundary |
|---|---|---|---|
| A regulator, client, or insurer named a specific incident | Existing incident or legal process first | Incident timeline, affected data, notifications made | A directory does not replace legal counsel |
| Personal data has never been inventoried | Bounded specialist review | Systems list, data types, retention practice | Not a certification |
| A privacy policy or breach process needs to be built | Bounded specialist review | Business description, jurisdiction, current documents | Not a guaranteed audit pass |
| Existing policies are stale and unreviewed | Managed IT / ongoing ownership | Policy owner, review cadence, training record | Not a substitute for legal review |
G8 · Entry 03 Prepare the brief
Bring these facts to a compliance conversation.
- Which jurisdiction(s) apply: Quebec's Law 25, federal PIPEDA, or sector rules.
- What personal information is collected, and from whom.
- Whether a privacy policy or breach process already exists.
- Any client, insurer, or vendor contract naming a specific control.
- Whether the request follows an actual incident or complaint.
- The artifact needed: an inventory, a policy set, or ongoing oversight.
G8 · Entry 04 What this covers
What this guide covers, and what it does not.
- In scope
- Separating an active incident from a planned assessment or an ongoing program, and the evidence a reviewer should ask for.
- Out of scope
- Legal advice, regulatory representation, and incident-response execution. NexDefend does not perform the review itself.
- Possible next decision
- A bounded assessment, a build-the-artifacts project, or ongoing privacy-program ownership.
G8 Next
Scope the question before scoping the provider.
Compare specialist review routes, or read the fuller advisory guide for how a bounded engagement should be framed.