“Are we actually PIPEDA compliant, or did someone just say so?”
Privacy law asks a business question. Microsoft 365 answers with settings.
Growing Canadian teams already trust the desk with Canadian-dollar pricing. This page translates PIPEDA and Quebec’s Law 25 into the specific, checkable Microsoft 365 settings that typically support them—not a legal opinion, and not a substitute for your own counsel.
Turn the law into settings
Five privacy themes, and where each one actually lives in Microsoft 365.
This is a practical checklist to work through with your tenant owner, not a legal opinion on what your business is required to do.
| Privacy theme | Practical Microsoft 365 setting | Who owns the decision |
|---|---|---|
| Limiting who can see what | Guest access defaults, sharing-link expiry, and licence-based access reviews. | Your business decides the policy; the desk applies an approved change. |
| Safeguards proportionate to sensitivity | Multi-factor authentication and sign-in risk policies across the tenant—see Conditional Access and MFA policy setup → for the practical side. | The desk can check the current state and flag gaps; enabling tenant-wide security defaults is a tenant-owner decision. |
| Being able to show accountability | Sign-in and audit logs, and a current list of who holds elevated admin access. | Reviewed with your tenant owner; a written policy is a business and, where needed, legal decision. |
| Keeping data only as long as needed | Mailbox, OneDrive, and Teams retention policies, and offboarding data handling—see backup and recovery planning → for the practical side. | Retention periods are a business and legal decision; the desk applies the configuration once set. |
| Knowing where data actually sits | Microsoft’s published data-residency and datacentre documentation for your tenant region. | Confirm directly against Microsoft’s current documentation and your own legal counsel—never assumed. |
Before you rely on this page
What this is—and is not.
- Is this legal advice?
- No. It names common, practical Microsoft 365 settings. Your specific PIPEDA and Law 25 obligations depend on facts this page cannot know—confirm them with qualified legal counsel.
- Does Plus include a compliance audit?
- No. Light security-baseline support is not a focused review, hardening engagement, or investigation—the same boundary published on the pricing page.
- Does the desk decide our retention or sharing policy?
- No. Those stay business and, where needed, legal decisions. The desk can apply an approved setting once your business decides it.
- Who keeps ownership of the data itself?
- You do. Your tenant, your licensing, and your data stay yours—the desk supports the Microsoft 365 side of using them well.
Common questions
What a checklist can and cannot answer.
Is M365 Desk a compliance or legal service?
No. It is Microsoft 365 user support. This page is a practical starting checklist; your actual compliance obligations should be confirmed with qualified legal counsel.
Can the desk turn on MFA and sign-in risk policies for us?
Applying an approved security setting is routine desk work once your business decides the policy. Deciding how strict that policy should be is a business decision, sometimes made alongside legal counsel.
Does this apply outside Quebec?
PIPEDA applies federally; Law 25 adds Quebec-specific obligations on top of it. The Microsoft 365 settings below are relevant either way—confirm which specific obligations apply to your business and where it operates.