What to do next
Map what data you hold and why
You cannot comply with obligations you cannot describe. Inventory what personal data you collect, where it lives, who can access it, which vendors process it, and how long you keep it.
Fix the documents and the vendor chain
Update your privacy notice to reflect reality, put processing agreements in place with vendors, and confirm any cross-border transfers are handled properly. Quebec's Law 25 and the GDPR both impose specific transfer and transparency requirements.
Prepare for rights requests and breaches
Have a process for access, correction and deletion requests, and a written breach-response plan. Breach notification deadlines are short and start running the moment you become aware.
Frequently asked questions
Does the GDPR apply to a company outside the EU?
It can, where you offer goods or services to people in the EU or monitor their behaviour. Location of the business is not determinative.
What applies in Canada?
Federal private-sector privacy legislation applies broadly, and Quebec's Law 25 imposes additional and in some respects stricter requirements. Some provinces have their own regimes.
Do we need consent for everything?
Not always — lawful bases vary by regime. But transparency is universal: people must be told clearly what you do with their data.
How fast must we report a breach?
Notification windows are short and differ by regime. Treat a suspected breach as urgent and get advice immediately.
This is general information, not legal advice. Laws vary by location and every situation is different — speak with a qualified lawyer about your specific circumstances.