This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Bill 64 is modernizing Québec privacy law – What it involves, why it matters, and what you can do to reduce the risk of non-compliance financial and administrative penalties.

Download resources

About this session

Jim Short, regional sales director for public sector at DataStealth, a Toronto software company, presents Québec's Bill 64 as the most GDPR-like privacy regime in North America and explains what it demands: mandatory breach reporting and a designated privacy officer already in force, then privacy impact assessments, documented cross-border transfers, retention and destruction rules and the right to erasure by the following September, with penalties he cites as up to 25 million dollars or four percent of revenue. Federal Bill C-27, he says, is catching up. He stresses data discovery as the real obstacle, citing a large client that thought it had eleven databases and found twenty-one, and warns that cloud identity and marketing platforms hosted in the United States put organisations out of compliance by default. The second half is a product pitch: DataStealth sits inline at the transport layer and tokenises, encrypts or redacts personal data on the fly with no application changes, agents or APIs, and is PCI level 1 certified. He asserts that encryption alone is no longer acceptable under Bill 64 and C-27. Questions cover companies leaving Québec, erasure across legacy archives, seven-year retention conflicts, GDPR clauses with cloud providers and third-party contracts.

The stringent new privacy regulations introduced in Bill 64 will require significant changes for organizations operating in Québec or engaging with Québec residents. Policies and procedure will only take you so far to avoid the serious consequences of non-compliance. DataStealth is a proven solution that helps organization discover, classify, and protect sensitive data governed by Bill 64, including obligations regarding data residency and the right to be forgotten. Meet the challenge of compliance head on, without the need for any code changes, API integrations, agent installations, or other changes to your applications or IT environment. Join us to learn about a simple way to take Bill 64 compliance from paper to an actionable plan that will improve your security and mitigate your risk (this presentation will be in English).

Key takeaways

  • Start with data discovery: inventory every database and archive holding personal information before promising erasure or running privacy impact assessments.
  • Map where cloud identity, CRM and marketing platforms actually store Québec residents' data; US-hosted services need contractual and technical safeguards to meet Bill 64's transfer rules.
  • Confirm with counsel how the right to erasure interacts with seven-year retention obligations and legacy backups; the speaker admits the answer is unsettled.
  • Reopen third-party contracts now so suppliers' practices do not make you non-compliant, and prepare for federal C-27 at the same time.
  • Treat tokenisation or redaction at the transport layer as one way to protect data in systems you cannot change, but verify the claim that encryption alone is insufficient with your own legal advisors.

Speakers

Jim Short
Jim Short
Regional Sales Director - Public Sector · Datastealth

Resources

Tags

More from GoSec 2022

Also from Jim Short

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.