Business Continuity Plan Template: Quebec Law 25 + PIPEDA (2026)
Decide what 'recovered' means
Set a recovery time objective (how long you can be down) and a recovery point objective (how much data you can lose) for each critical system. These two numbers drive every other decision in the plan.
Order your recovery
List systems by how fast the business needs them back — payments and email usually first, archives last. Document who restores what, from which backup, and how you verify it worked.
Fold in Law 25 / PIPEDA
If the disruption involves a privacy breach, your continuity plan must trigger the reporting duties under Law 25 and PIPEDA. Linking the two means you don't recover systems while quietly missing a legal deadline. IT Cares can build and test the backup and recovery side.
Action checklist
- ✅ Set an RTO and RPO for each critical system
- ✅ Rank systems by recovery priority
- ✅ Document who restores what, and from where
- ✅ Keep at least one offline/immutable backup
- ✅ Add the Law 25 / PIPEDA breach-reporting trigger
- ✅ Test a full restore at least once a year
FAQ
What is the difference between a backup and a continuity plan?
A backup is a copy of your data; a continuity plan is the documented process for getting the business running again — recovery priorities, RTO/RPO, roles, and communications. You need both.
Should a continuity plan include privacy breach steps?
Yes, in Canada it should. If an outage involves a data breach, Law 25 and PIPEDA may require you to notify regulators and individuals. Building that into the plan prevents missed legal deadlines during recovery.
Get a free assessment
Tell us where you are — we send back a clear, no-pressure plan. Leads only, no payment.