What IT can actually do
Five mechanics behind a privacy obligation.
Access logging
Microsoft 365 and most business systems can record who accessed or changed a file or record, and for how long that log is kept. IT can turn this on and keep it running - it cannot decide what your specific obligation requires you to log.
Retention settings
Mailbox, file, and record retention can be configured to match a period you specify. IT applies the setting; your organization, with counsel, sets the number.
Breach-notification mechanics
If an incident happens, IT can help establish what was accessed, when, and by which account - the technical facts a notification needs. Whether an event legally qualifies as a reportable breach, and what the notice must say, is a legal determination.
Access control and least privilege
Restricting who can open which records, and removing access promptly when someone leaves or changes roles, is an ordinary access task IT already performs - and one a privacy obligation makes more consequential.
Vendor and sub-processor visibility
Keeping a current list of which cloud vendors and applications hold personal information supports a privacy assessment. It does not replace one.
An honest boundary
Configuring a control is not the same as interpreting an obligation.
What IT operationalizes
Access logging, retention configuration, access control and offboarding, the technical facts behind a breach, and an inventory of vendors holding personal information.
What stays with your own counsel
Whether PIPEDA, Law 25, or another statute applies to your organization, what counts as personal or sensitive information in your context, breach-notification thresholds and deadlines, and any required privacy-officer designation or impact assessment.
Honest limit: this page is not legal advice and does not interpret PIPEDA, Law 25, or any other privacy statute for your organization. A privacy lawyer or compliance professional should confirm what applies to you; IT then configures the systems to match that decision.
- To counsel: does PIPEDA, Law 25, or a provincial equivalent apply to what we collect and where our clients or employees are located?
- To counsel: what is our breach-notification deadline and threshold once a decision-maker has been informed?
- To IT: can our current systems actually produce an access log for a specific record on request?
- To IT: what is our real retention setting today, on the systems that matter - not what we assume it is?
Connect the work
See the baseline these controls build on.