⚠ Law 25 is in full force — penalties up to $25M or 4% of global revenue.
Law 25 Compliance

Your business is subject to Law 25.
Is your SaaS stack ready?

HarbourScan maps your SaaS tools to parent jurisdictions, flags CLOUD Act exposure, and shows you exactly which tools trigger Law 25 documentation obligations.

If your organization uses tools like Microsoft 365, Google Workspace, Slack, or Salesforce to handle Quebec personal information — Law 25 applies to you.

  • See which tools are under foreign jurisdiction
  • Identify which transfers require a TIA
  • Get a compliance gap count and severity rating
$25MMax penalty
4%Of global revenue
715Tools in database
Free Assessment
See your exposure in 10 minutes.

Map your stack in your browser. Select your tools, see your jurisdictional exposure map. No account required.

Map Your Stack — free →

Free for any Canadian organization. No credit card. No spam.

Need compliance documentation? Book a scoping call →

Quebec's landmark privacy law — with teeth.

Law 25 applies to any organization handling personal information of Quebec residents — regardless of where you're headquartered. It's in full force. Enforcement has begun.

🏛

Who It Applies To

Any organization operating in Quebec or handling data of Quebec residents — including businesses headquartered elsewhere in Canada. If you have Quebec customers, employees, or users, you're subject.

⚖️

What It Requires

Organizations must demonstrate where personal data is held, who can access it, and whether it crosses jurisdictions — including to the U.S. via your SaaS tools' parent companies or integrations.

🔍

The SaaS Problem

Most compliance teams focus on their own systems. But your SaaS stack and its integrations silently move data across borders. That's where your Law 25 exposure actually lives.

📋

Audit Readiness

Law 25 gives individuals the right to know where their data is held. If you can't answer that about your SaaS tools, you're not compliant — and you're not ready for a CAI audit.

Law 25 compliance clarity in days — not months.

01
Map Your Stack

Select your tools and see your jurisdictional exposure map in minutes. Free, in your browser, nothing stored.

02
See your Law 25 exposure

HarbourScan flags every tool under foreign jurisdiction, counts your compliance gaps, and identifies which transfers require a TIA.

03
Get the documentation

Choose the level of documentation you need — from a professional Sovereignty Snapshot ($350) to full compliance documentation with TIA guidance ($2,000).

04
Fix what's flagged

Get prioritized remediation guidance. Know exactly which tools to replace, reconfigure, or renegotiate — and in what order.

Law 25 Penalties
$25M

Or 4% of worldwide turnover — whichever is greater. Administrative penalties apply even for non-intentional violations. The time to act is before the audit.

"U.S. law requires providers to disclose data regardless of where it is stored. Data stored in Canada is still reachable via U.S. subpoena."

U.S. Department of Justice — CLOUD Act White Paper

Six things Law 25 requires you to prove.

HarbourScan addresses each of these directly — and generates documentation for all of them.

01 —

Data Inventory

Know what personal data you hold and where it lives — including across all third-party SaaS tools.

HarbourScan maps this
02 —

Cross-Border Transfers

Identify when data crosses into foreign jurisdictions — including silent data flows via SaaS integrations.

HarbourScan flags this
03 —

Vendor Risk Assessment

Evaluate third-party providers' compliance posture before onboarding — and continuously afterward.

HarbourScan scores this
04 —

Right of Access

Respond to individual requests about where their data is held and how it's used — within required timelines.

HarbourScan enables this
05 —

Privacy Impact Assessments

Assess the privacy impact of any new technology or process involving personal information.

HarbourScan supports this
06 —

Audit Documentation

Maintain records of all compliance activities — and produce them on demand for the CAI.

HarbourScan generates this

Know your Law 25 exposure.

Most organizations complete the scan in under 10 minutes. No account required. Choose the level of documentation you need after you see your results.

Jurisdictional exposure map CLOUD Act flags TIA requirement count Compliance gap analysis Remediation priorities
Map Your Stack — free → Book a scoping call →

Free scan for any Canadian organization. Professional documentation from $350.