Skip to content

“Are we actually PIPEDA compliant, or did someone just say so?”

Privacy law asks a business question. Microsoft 365 answers with settings.

Growing Canadian teams already trust the desk with Canadian-dollar pricing. This page translates PIPEDA and Quebec’s Law 25 into the specific, checkable Microsoft 365 settings that typically support them—not a legal opinion, and not a substitute for your own counsel.

Turn the law into settings

Five privacy themes, and where each one actually lives in Microsoft 365.

This is a practical checklist to work through with your tenant owner, not a legal opinion on what your business is required to do.

Privacy themePractical Microsoft 365 settingWho owns the decision
Limiting who can see whatGuest access defaults, sharing-link expiry, and licence-based access reviews.Your business decides the policy; the desk applies an approved change.
Safeguards proportionate to sensitivityMulti-factor authentication and sign-in risk policies across the tenant—see Conditional Access and MFA policy setup → for the practical side.The desk can check the current state and flag gaps; enabling tenant-wide security defaults is a tenant-owner decision.
Being able to show accountabilitySign-in and audit logs, and a current list of who holds elevated admin access.Reviewed with your tenant owner; a written policy is a business and, where needed, legal decision.
Keeping data only as long as neededMailbox, OneDrive, and Teams retention policies, and offboarding data handling—see backup and recovery planning → for the practical side.Retention periods are a business and legal decision; the desk applies the configuration once set.
Knowing where data actually sitsMicrosoft’s published data-residency and datacentre documentation for your tenant region.Confirm directly against Microsoft’s current documentation and your own legal counsel—never assumed.

Before you rely on this page

What this is—and is not.

Is this legal advice?
No. It names common, practical Microsoft 365 settings. Your specific PIPEDA and Law 25 obligations depend on facts this page cannot know—confirm them with qualified legal counsel.
Does Plus include a compliance audit?
No. Light security-baseline support is not a focused review, hardening engagement, or investigation—the same boundary published on the pricing page.
Does the desk decide our retention or sharing policy?
No. Those stay business and, where needed, legal decisions. The desk can apply an approved setting once your business decides it.
Who keeps ownership of the data itself?
You do. Your tenant, your licensing, and your data stay yours—the desk supports the Microsoft 365 side of using them well.

Common questions

What a checklist can and cannot answer.

Is M365 Desk a compliance or legal service?

No. It is Microsoft 365 user support. This page is a practical starting checklist; your actual compliance obligations should be confirmed with qualified legal counsel.

Can the desk turn on MFA and sign-in risk policies for us?

Applying an approved security setting is routine desk work once your business decides the policy. Deciding how strict that policy should be is a business decision, sometimes made alongside legal counsel.

Does this apply outside Quebec?

PIPEDA applies federally; Law 25 adds Quebec-specific obligations on top of it. The Microsoft 365 settings below are relevant either way—confirm which specific obligations apply to your business and where it operates.

Related guides

Sharing and sign-in risk both touch this checklist.

Guest access and external sharing →Proactive tenant monitoring →