Privacy law tells you what outcome is required. It does not tell you which system to change, who signs off, what your intake form has to say, or what happens at 4pm on a Friday when someone emails asking for a copy of their data. Cyberwall turns the rules that actually bind you, PIPEDA and Quebec Law 25 in Canada, HIPAA and state privacy law in the United States, California's CCPA and CPRA chief among them, provincial and state breach notification duties, and standards such as ISO/IEC 27701, into a documented program your team can run, before a breach or a regulator forces the question.
Thirty minutes, no cost, and you leave knowing which privacy laws apply to you and where your exposure sits.
Privacy consulting is the work of establishing, documenting and maintaining your accountability for the personal information you hold, and being able to prove that accountability to a regulator, a customer, a partner or the individual who asks. Every modern privacy law in Canada, the United States and Europe is built on the same handful of ideas, whatever the statute calls them:
Cyberwall builds each of those into documented, operating practice, and stays on as the privacy function for organizations that do not have one.
Cybersecurity asks whether the data is protected. Privacy asks whether you should have collected it, whether you told people, whether you are still allowed to use it, and what happens when they ask for it back. Most providers only do the first. Cyberwall is an MSSP with a privacy practice, so the safeguards a privacy assessment recommends get technically validated and implemented rather than just written down.
In Canada, Quebec Law 25 is fully in force: a designated privacy officer, published policies, mandatory privacy impact assessments for information system projects and cross-border transfers, incident reporting to the Commission d'accès à l'information, and data portability. Alberta and British Columbia maintain their own private-sector regimes, and PHIPA governs anyone touching health information in Ontario. Federal reform is moving again: Bill C-36, introduced in June 2026, would replace PIPEDA's privacy provisions with the Protecting Privacy and Consumer Data Act, adding deletion and portability rights, a legitimate interest basis conditional on completing a privacy impact assessment, mandatory assessments before cross-border transfers, automated decision-making disclosure, and a regulator with order-making and audit powers.
In the United States, California set the template with CCPA and CPRA, and it remains the most actively enforced consumer privacy regime in the country, with a dedicated regulator and a private right of action for certain breaches. Roughly twenty states have followed with comprehensive privacy laws now in effect and more phasing in, each carrying its own thresholds, opt-out mechanics and assessment duties. Anyone touching protected health information answers to HIPAA, business associates included. Every state imposes breach notification duties on different triggers and deadlines, and the GLBA Safeguards Rule now requires notification to the FTC for larger incidents.
On both sides of the border, customer questionnaires ask where data is stored, whether sub-processors are disclosed and how access requests are handled. And AI changed the exposure, because feeding personal information into an AI system creates a new purpose, a new disclosure, often a new cross-border transfer and sometimes an automated decision affecting an individual.
Organizations that build the documentation now are not scrambling later. The ones that wait discover, mid-incident, that they do not have a data inventory. See our breach notification reference for how the obligations differ by jurisdiction.
Scaled to your size and the obligation you have to meet.
| Phase | What happens |
|---|---|
| 1. Scope | We establish which laws apply to you, what is driving the work, and what a successful outcome looks like. No cost, and it produces a scoped proposal rather than a generic quote. |
| 2. Discover | Structured interviews and workshops with the business units that actually touch personal information, review of policies, contracts and notices, and a walk through the systems involved. Where relevant our security practice validates the technical safeguards rather than taking them on faith. |
| 3. Assess | Findings assessed against the applicable legal requirements and recognized privacy frameworks, with each risk rated for likelihood and impact on individuals as well as on the organization. |
| 4. Remediate | We implement alongside you: policies, procedures, data maps, registers, training and governance structures. Most clients want the program stood up, not just described. |
| 5. Sustain | Fractional privacy officer support, recurring compliance reviews, annual assessment refreshes, training cycles and regulator-ready reporting. |
Every engagement produces the same deliverable set: an executive summary of your privacy exposure and what leadership must decide, a privacy assessment report with findings against each applicable requirement, a personal information inventory and data flow maps, a rated privacy risk register, a sequenced remediation roadmap with owners and target dates, the policy and procedure set, and a walkthrough session for leadership or a privacy committee.
The core privacy deliverable, and in some jurisdictions a legal requirement. A PIA examines a specific initiative, such as a new system, a vendor, a product feature, a data-sharing arrangement or a cross-border transfer, and documents what personal information is involved, why it is needed, the legal authority or consent basis, who it is disclosed to, how long it is kept, the privacy risks created, the safeguards applied, and the residual risk leadership is accepting. Conducted before implementation or material change, it is both a risk tool and the record proving you did the analysis.
| Related assessment | When you need it |
|---|---|
| Data Protection Impact Assessment (DPIA) | The GDPR-aligned equivalent, required for processing likely to result in a high risk to individuals: large-scale sensitive data, systematic monitoring, profiling with legal or similarly significant effects, or new technologies. Structured to satisfy Article 35, including the necessity and proportionality assessment. |
| Privacy Risk Assessment (PRA) | A broader look than a single project. Identifies and rates privacy risk across the organization: over-collection, undocumented sharing, retention sprawl, shadow systems, weak consent capture and unmanaged third parties. |
| Threat Risk Assessment (TRA) | The security-side companion frequently required alongside a PIA in Canadian public sector and health contexts. Evaluates threats, vulnerabilities, impacts and safeguards affecting the systems and information in scope. |
| Privacy program maturity assessment | Benchmarks capability across governance, accountability, transparency, individual rights, data lifecycle, third-party management, incident handling and training, producing a maturity score by domain and a prioritized improvement plan. |
You cannot protect, minimize, retain or delete what you have not mapped. We build an inventory of personal information across systems, business processes and third parties: what is collected, from whom, why, where it is stored, who has access, where it moves including outside the country, how long it is kept and how it is destroyed. Retention periods are documented per data category and tied to the legal or business purpose that justifies them, with defensible disposal procedures. This single artifact underpins access requests, breach assessments, vendor reviews and every framework requirement beginning "the organization shall identify." Where GDPR applies, the same work produces the Records of Processing Activities register.
The end-to-end build: accountability structure and designated privacy officer, privacy policy framework, standard operating procedures, privacy-by-design gates in your project lifecycle, training, metrics and management reporting. Designed to fit how your organization actually works, scaled to your size, and documented well enough to show a regulator.
External privacy notices that say what you actually do, internal policies your staff can follow, consent language and capture mechanics appropriate to the jurisdiction and sensitivity, cookie and online tracking practices where applicable, and the governance to keep all of it current as the business changes.
A documented, repeatable process for receiving, verifying, scoping, fulfilling and logging individual requests for access, correction, deletion, portability and opt-out, inside the statutory clock: commonly 30 days under PIPEDA and Quebec Law 25, and 45 days with a further 45-day extension under California's CCPA and CPRA and most US state laws that follow it. Includes intake channels, identity verification standards, redaction and exemption handling, universal opt-out signal handling, which California and a growing list of states now require, response templates and a request register. Built before the requests arrive, because the deadlines are short.
A privacy breach runs on a different clock and a different assessment than a security incident. We build the privacy side of your incident process: how to assess whether a breach meets the notification threshold, who decides, and which regulators and individuals must be told in which jurisdictions and by when, whether that is the Privacy Commissioner of Canada, a provincial commissioner, a state attorney general, HHS or all of them at once. Includes notification templates, the breach register several statutes require you to maintain, and the tabletop exercise that proves the process works. Our breach notification reference sets out the obligations by jurisdiction.
Handing personal information to a processor does not transfer your accountability. We assess vendors for privacy risk, review data processing agreements, business associate agreements where HIPAA applies, and the service provider and contractor terms California's CCPA and CPRA require, mirrored in most other US state laws, confirm sub-processor disclosure and data residency, and maintain ongoing oversight of the third-party population including the SaaS tools nobody told IT about. Cross-border work covers transfer mechanisms, data residency commitments, government access exposure and the assessment obligations Quebec Law 25 already imposes.
Role-appropriate training for general staff, for teams handling personal information daily, and for executives and boards who own the accountability. Delivered live or as material your team can run, with completion records suitable as evidence.
Several statutes require a designated individual accountable for privacy, and most mid-sized organizations cannot justify a full-time hire. Cyberwall acts as or supports your designated privacy officer: handling regulator correspondence and access requests, chairing privacy governance, reviewing new initiatives, maintaining program documentation and reporting to leadership.
Recurring, independent review of whether the privacy program is operating as documented, with findings, corrective actions and follow-up. The evidence that turns a written program into a demonstrable one.
Assessment of personal information used in AI systems: purpose and consent basis, training data provenance, cross-border processing, retention inside the model and the vendor, transparency obligations, and the disclosure, explanation and opt-out requirements attaching to automated decisions and profiling that significantly affect individuals under Canadian reform proposals and US state law alike, including the automated decision-making and profiling opt-outs California has moved to regulate. Coordinated with Cyberwall's AI governance practice under ISO/IEC 42001 and NIST AI RMF where a fuller program is needed.
For organizations that want their privacy program certified rather than merely documented. Gap assessment against the PIMS requirements, implementation support, internal audit and certification readiness, built as an extension of an ISO/IEC 27001 ISMS.
| Standard | What it covers and how Cyberwall helps |
|---|---|
| ISO/IEC 27701 | Privacy Information Management System, extending ISO 27001. Gap assessment, implementation support and internal audit. |
| ISO/IEC 27018 | Protection of personally identifiable information in public clouds. Cloud privacy assessment with implementation guidance. |
ISO/IEC 27001, SOC 2 and the other security management-system standards these extend are on our Compliance Services page.
Engagements are staffed by senior practitioners, not a template and a junior analyst. Certifications held across the Cyberwall team include CDPSE, CISA and CRISC (ISACA), ISO/IEC 27701 Lead Auditor (PIMS), ISO/IEC 27001 Lead Auditor, ISO/IEC 20000 Lead Auditor, ISO/IEC 27032, EC-Council Certified Security Analyst (ECSA) and Certified Cyber Threat Analyst (CCTA).
These are standards we help clients meet, not certifications Cyberwall holds. See our Compliance Services page for the frameworks we hold or help clients meet more broadly. Privacy obligations are also enforced differently than security frameworks: there's typically no single certificate to earn, just an ongoing duty to handle personal information correctly and to notify the right people, in the right timeframe, if that duty is ever breached.
It depends on where your customers and employees are, what sector you operate in, and how sensitive the information is. A Canadian organization usually starts with PIPEDA, adds Quebec Law 25 with Quebec customers or operations, and adds PHIPA or its provincial equivalent when health information is involved. A US organization starts with the state laws covering its customers, in practice California's CCPA and CPRA first because the thresholds catch the most companies and enforcement is the most active, adds HIPAA when protected health information is in play, and inherits every applicable state breach notification statute. Most of our clients sell on both sides of the border and carry both sets. Sorting this out is the first thing we do together.
In several jurisdictions yes. Quebec Law 25 requires a designated person accountable for privacy, PIPEDA requires designated accountability, and GDPR requires a Data Protection Officer in defined circumstances. US state law rarely mandates the role outright, though the assessment, opt-out and response duties California's CCPA and CPRA create need a named owner in practice, and HIPAA separately requires designated privacy and security officials. It does not have to be a full-time hire. A fractional privacy officer satisfies the accountability requirement and gives you someone senior who knows the file.
A PIA assesses the privacy implications of a specific initiative and is the standard Canadian instrument. A DPIA is the GDPR-mandated version for high-risk processing. A PRA looks across the organization rather than at one project. A TRA is the security-side assessment of threats and safeguards that frequently accompanies a PIA in Canadian public sector and health contexts. Which you need depends on the jurisdiction and the trigger, and we will tell you in the scoping call rather than selling you all four.
A published notice is one requirement out of many, and in most assessments it is also inaccurate, describing practices the organization no longer follows or omitting ones it does. The obligations carrying real regulatory and reputational risk are operational: the data inventory, the access request process, the retention schedule, the vendor reviews and the breach procedure.
It would be if the same people did both. Where Cyberwall has built or operates part of your privacy program, the compliance review of that part is staffed separately from the delivery team, and the separation is set out in the engagement letter. If you would rather the review sit entirely outside Cyberwall, we will tell you that too and work with whoever you appoint.
Yes. Cyberwall provides incident response alongside privacy support, so we can establish what happened, assess whether notification thresholds are met in each affected jurisdiction, draft the notifications, support regulator correspondence, and then fix the underlying gaps. Call the 24/7 line first if the incident is active.
No. Cyberwall is a security and privacy consultancy, not a law firm. We provide assessment, program design, documentation and operational support, and we work alongside your privacy counsel for formal legal opinions, regulator proceedings and litigation. Clients without counsel are told so directly rather than sold an opinion we are not qualified to give.
This page is informational and does not constitute legal advice. Applicability of privacy legislation, notification thresholds and statutory deadlines are validated for each engagement and each incident. Cyberwall provides advisory, assessment, implementation and readiness support; independent certification or attestation is performed by the applicable accredited certification body or licensed audit firm. Legislative references are current as at September 2026, including Bill C-36, which was introduced in June 2026 and has not been passed.
Book a privacy readiness call. Thirty minutes, no cost, and you leave knowing which privacy laws govern you, whether you need a designated privacy officer, and what a defensible program looks like at your size.