Skip to content
NexDefend IT services directory
14 destinations · EN + FR contact@nexdefend.com How listings work
Menu

Guide G8 Compliance & governance

“We need to be compliant” is not a scope. Name the framework and the artifact.

Quebec's Law 25 and the federal PIPEDA create specific, real obligations: a privacy policy, a breach process, a personal-information inventory, and vendor agreements, among others. A vague compliance worry is not yet a scope. This guide separates an active incident from a planned assessment or an ongoing privacy program.

G8 · Entry 01 Three different compliance jobs

Start with what actually triggered the question.

There's an active incident or complaint

A breach, client complaint, or regulator letter needs an existing incident, legal, or insurer process - not a general directory.

No one has inventoried personal information

A bounded review can map what personal data exists, where it lives, and what documents are missing.

Policies exist but nobody keeps them current

Ongoing ownership matters when a privacy policy, training, and vendor list need a dependable review cadence.

G8 · Entry 02 Decision matrix

Match the situation to the right first route.

Observed need Best first route Useful evidence Boundary
A regulator, client, or insurer named a specific incident Existing incident or legal process first Incident timeline, affected data, notifications made A directory does not replace legal counsel
Personal data has never been inventoried Bounded specialist review Systems list, data types, retention practice Not a certification
A privacy policy or breach process needs to be built Bounded specialist review Business description, jurisdiction, current documents Not a guaranteed audit pass
Existing policies are stale and unreviewed Managed IT / ongoing ownership Policy owner, review cadence, training record Not a substitute for legal review

G8 · Entry 03 Prepare the brief

Bring these facts to a compliance conversation.

  • Which jurisdiction(s) apply: Quebec's Law 25, federal PIPEDA, or sector rules.
  • What personal information is collected, and from whom.
  • Whether a privacy policy or breach process already exists.
  • Any client, insurer, or vendor contract naming a specific control.
  • Whether the request follows an actual incident or complaint.
  • The artifact needed: an inventory, a policy set, or ongoing oversight.

G8 · Entry 04 What this covers

What this guide covers, and what it does not.

In scope
Separating an active incident from a planned assessment or an ongoing program, and the evidence a reviewer should ask for.
Out of scope
Legal advice, regulatory representation, and incident-response execution. NexDefend does not perform the review itself.
Possible next decision
A bounded assessment, a build-the-artifacts project, or ongoing privacy-program ownership.

G8 Next

Scope the question before scoping the provider.

Compare specialist review routes, or read the fuller advisory guide for how a bounded engagement should be framed.

Compare specialist review routes Read the IT advisory guide →