By Nicolas Thiffault-Chouinard, Esq. LDB Avocats
Your shop collects information about its customers: names, addresses, phone numbers and vehicle data. Since the adoption of Bill 25, you are required to protect this information.
Personal information includes any information that can be used to identify an individual. A customer’s name, address, phone number or email address all fall into this category. As soon as you collect such information, the law applies.
Collection and Use
Personal information follows a life cycle. You first collect it for a specific purpose: repairing a vehicle, preparing an estimate, issuing an invoice or providing follow-up service. The golden rule is simple: limit collection to what is strictly necessary by asking yourself, “Why do I need this information?”
The information obtained must be used solely for that purpose. Any new use, such as marketing, requires consent. For example, you cannot use a customer’s email address to send promotions after their visit if it was originally collected to send them an invoice. Customers retain control over their information: they can access their file and request corrections.
Protecting Information Every Day
A few best practices can reduce your risks. Lock your systems, protect access with passwords and encrypt your data. Restrict access to information to employees who actually need it: a technician repairs the vehicle, while the customer’s email address is generally relevant to front-counter staff. Train your employees and securely store paper records.
You must also appoint a person responsible for the protection of personal information. By default, the law assigns this role to the person with the highest authority within the company. This individual is responsible for implementing an internal policy known to all employees, including clear guidelines for protecting personal information.
Destroying Information at the Right Time
Once the purpose for which the information was collected has been fulfilled, retaining it becomes prohibited. The law then requires you to destroy or anonymize it. First, respect any retention periods imposed by other laws, particularly tax legislation. You should also consider your warranties and contractual obligations.
Information must then be securely destroyed. Shred paper documents and reliably erase digital storage media.
If there is no longer a reason to retain information—whether because of a legal or contractual obligation—or if the customer’s consent has not been obtained for marketing purposes, the information must be destroyed.
Responding to a Data Breach
The loss or theft of data constitutes a confidentiality incident. If your shop experiences equipment theft or hackers manage to infiltrate your systems, your customers’ personal information could be at risk.
Act quickly to limit potential harm and assess the level of risk. If the risk is serious, promptly notify the Commission d’accès à l’information and the individuals affected. For example, an attempted fraud that is detected in time and prevented through best practices would be less serious than the theft of a computer containing information linking each customer to a specific vehicle.
The law requires all such incidents—whether serious or not—to be recorded in a register and kept for at least five years.
Penalties can reach $25 million or 4% of sales. Discipline is your best insurance.
Picture credit : LDB Avocats




