LEGAL COUNSELNEAR ME

Technology Guide

Data Privacy and Technology Compliance for Business

9 min readUpdated January 15, 2026

The most common misconception about privacy law is that it follows your company's location. It does not — it largely follows the people whose data you hold. A ten-person business in one country can be subject to European, US state, and Canadian privacy law at the same time.

This guide explains what applies, what compliance actually requires in practice, and where the real exposure sits. It is general information; privacy regimes change frequently and enforcement is active, so get advice on your specific data flows.

Which laws apply to you

The GDPR can apply to businesses outside the EU that offer goods or services to people in the EU or monitor their behaviour. A growing number of US states have comprehensive privacy laws with their own thresholds and consumer rights. In Canada, federal private-sector legislation applies broadly, and Quebec's Law 25 adds requirements that are in some respects stricter.

Sector rules layer on top: health information, financial data, and children's data are subject to additional regimes. The practical answer is usually that more than one law applies, so build to the strictest requirement rather than tracking each separately.

What compliance actually requires

Start with a data inventory — you cannot comply with obligations you cannot describe. Know what personal data you collect, why, where it is stored, who can access it, which vendors touch it, and how long you keep it. Most compliance failures trace back to not knowing this.

Then the substantive duties: a lawful basis or valid consent for processing, a privacy notice that accurately reflects what you actually do, security appropriate to the risk, data minimization and retention limits, and a working process to honour access, correction, and deletion requests within the required timeframes.

Vendors and cross-border transfers

You remain responsible for personal data your vendors process. That means written processing agreements imposing obligations on them, and diligence on the ones handling sensitive data. Reviewing what rights a SaaS provider takes over your data — including use for model training — has become a standard part of this.

Cross-border transfers carry specific requirements under the GDPR and Quebec's Law 25, including assessments and contractual safeguards. If your data sits in another country, confirm the transfer mechanism is documented rather than assumed.

Breach response, and AI

Breach notification deadlines are short and start when you become aware, not when you finish investigating. Have a written response plan naming who decides, who notifies, and how you assess risk to affected individuals — improvising during an incident is how deadlines get missed.

Automated decision-making and AI attract specific attention: transparency where decisions materially affect people, care about the lawful basis for training on personal data, and accuracy obligations. This area is moving quickly, so treat any AI feature touching personal data as needing fresh advice rather than relying on last year's assessment.

Frequently asked questions

Does the GDPR apply if my company isn't in the EU?
It can. If you offer goods or services to people in the EU or monitor their behaviour, it may apply regardless of where your business is located.
What applies in Canada?
Federal private-sector privacy legislation applies broadly, and Quebec's Law 25 imposes additional requirements including on transfers and transparency. Some provinces have their own regimes.
Are we responsible for our vendors' handling of data?
Largely yes. You need written processing agreements and appropriate diligence — outsourcing the processing does not outsource the responsibility.
How quickly must we report a breach?
Windows are short and vary by regime, and generally start when you become aware rather than when the investigation concludes. Treat suspected breaches as urgent.
Do privacy laws affect our use of AI?
Yes, particularly around transparency for decisions affecting people, the lawful basis for training on personal data, and accuracy. It is a fast-moving area needing current advice.

This guide is general information, not legal advice. Laws, costs, and procedures vary by state, province, and your specific situation — speak with a qualified data privacy & cybersecurity lawyer about your circumstances before acting.