Your org chart is personal information.

That sentence does more work than it looks like. Names, work emails, job titles, who reports to whom, often salary bands, sometimes home city or employee number. Under Québec's Law 25, that is a file of personal information about your staff, and you are accountable for it.

Most companies never think of the org chart that way. It feels like a diagram, not a database. So it gets built in whatever tool was closest, shared as a link or a PDF, and quietly copied into a vendor's servers somewhere else.

Here is the part that surprises Québec companies: for most org chart tools, "somewhere else" means the United States.

This post is about that narrow question. What Law 25 actually asks of an org chart, why hosting location matters, and the five questions worth asking any HR tool before you upload your staff list into it. We make one of these tools, so read the last section with that in mind. The five questions work on us too.

(For the other Québec question, the language your software speaks, see a French org chart for Québec. That one covers Bill 96 and the OQLF. This one is about privacy.)

Why Law 25 touches the org chart at all

Law 25 (formerly Bill 64) was adopted in 2021 and phased in over the three years that followed, reshaping how Québec businesses handle personal information. Three of its ideas land directly on an org chart.

It is personal information. Law 25 covers information that relates to an identifiable person. An org chart identifies people by name, role, and reporting line. It qualifies. So do the exports and share links you make from it.

You stay accountable when you hand it to a vendor. Putting your roster into a piece of software does not transfer responsibility for it. Your company remains accountable, and you are expected to know what the vendor does with it.

Sending it outside Québec requires work first. Since September 2023, before communicating personal information outside the province, an organization must carry out a privacy impact assessment (an évaluation des facteurs relatifs à la vie privée, or EFVP) weighing the sensitivity of the information, how it will be used, and the legal framework where it lands. The transfer also has to be covered by a written agreement. That is a real piece of work. It is also the step that quietly gets skipped when someone signs up for a tool with a credit card.

None of this makes an org chart forbidden or dangerous. It makes it a file you should be able to account for.

The residency question

So where does your org chart actually live?

For most of the well-known tools, the answer is a US data centre. ChartHop's own security statement says it plainly: hosted on Amazon Web Services in us-east-1, the Virginia region, with its production databases in the same region. Pingboard, now sold as part of Workleap, and Lucidchart are likewise US-hosted platforms.

This is not a scandal, and it is not carelessness. It is simply where most SaaS infrastructure was built. Plenty of Québec companies use US-hosted software every day and handle it properly.

But it does have a cost, and the cost is paperwork. When the tool holding your staff list is in Virginia, that is a communication outside Québec, so the EFVP and the written agreement apply. You document the transfer, look at the protections that apply where it lands, and stay ready to explain the decision if anyone asks. Multiply that across every tool in your stack and you understand why privacy officers at 40-person companies look tired.

The shortcut is not a better legal argument. It is choosing, where you reasonably can, tools that keep the data in Canada in the first place. Fewer transfers, shorter assessments.

The five questions to ask any HR tool

Whatever you end up using, these are the questions worth asking before your staff list goes in. They are vendor-neutral. Ask them of us, ask them of everyone.

  1. Where is the data physically stored? Not "where is the company headquartered", which is a different question with a different answer. Ask for the region. A straight answer sounds like "Canada, Montréal region" or "United States, us-east-1". A vendor who cannot tell you quickly is telling you something.
  2. Who can see the sensitive fields? Salary is the obvious one. If salary sits in your roster file, ask whether it can be hidden from people who should not see it, and whether it is hidden on the server or merely hidden in the interface. Those are very different things. Data minimization is a Law 25 idea: people should see what their role requires, not everything in the file.
  3. What is reachable without a login? Public share links are enormously useful and are also the easiest way to leak a staff directory. Ask what a share link exposes. Does it include email addresses? Salary? Can it be turned off? A link that quietly carries every field is a problem waiting for a screenshot.
  4. How is access scoped between organizations and between users? In a multi-tenant product, every customer's data sits in shared infrastructure. Ask how one company's data is kept from another's, and how one employee's access is kept from another's. The good answer is enforced at the database layer, not just in the application code.
  5. What happens on export and on deletion? Exports leave the system. A PDF of the full chart with salaries in it is now a file on someone's laptop and outside every control you just asked about. And when you leave the vendor, ask what deletion actually means and how long it takes.

Save this list. It is more useful than a vendor's compliance page, because it makes them answer in specifics.

How OrgPlease answers them

Straight answers to our own five questions.

Where the data is stored. OrgPlease's primary datastore runs in Montréal, in the AWS Canadian region. Your roster data is stored in Canada, encrypted in transit and at rest. We moved it there deliberately, because "the data stays in Canada" is a materially easier sentence for a Québec company to work with than "the data is in Virginia and here is our transfer analysis".

Sensitive fields. Salary and other sensitive columns can be hidden, and they are filtered out on the server before the chart is sent, not just styled out of view in the browser. A viewer without permission does not receive the number at all.

What is public. A share link shows a live, read-only chart with sensitive fields removed, and it never exposes email addresses. You can turn a link off. It exists so you can send the chart to the whole company or a board without giving anyone a login, and without handing over the underlying file.

Access scoping. Every organization's data is scoped to its own members with row-level security enforced in the database, so the isolation does not depend on the application remembering to check.

Exports and the honest caveat. Exports are real files: a vector PDF, an editable PowerPoint, an Excel roster. Once exported they live wherever you put them, which is true of every tool and worth saying out loud. And our data model is re-upload based: the chart is as current as your last upload plus any edits you make in the app. We do not have live HRIS sync, and we would rather tell you that than let you assume it.

What this does, and what it does not do

Here is the part where a lot of vendor pages overreach, so let me be exact.

Using OrgPlease does not make your company compliant with Law 25. No software can do that, and any vendor who tells you otherwise is selling you a feeling. Compliance is a company-wide posture: your policies, your privacy officer, your inventory of personal information, your assessments, your retention practices, your breach procedures. A single tool is one line item inside that.

What Canadian hosting and field-level privacy actually buy you is a shorter conversation. When your privacy officer asks where the staff list lives, "Montréal" ends the question instead of starting a transfer assessment. When someone asks who can see salaries, you have a specific answer. That is not compliance. It is one fewer exception to explain, on one of the few documents in the company that everybody sees.

If your privacy officer wants details for an assessment, ask us. We keep documentation for exactly that purpose.

Bottom line

Two Québec laws quietly turned the org chart into a document with obligations attached. Bill 96 cares what language it speaks. Law 25 cares where it lives and who can see what is in it.

The practical move is not to panic about a diagram. It is to ask the five questions of whatever tool you use, write down the answers, and prefer Canadian hosting when a good option exists. For a 25 to 200 person Québec company, that is a short afternoon of work that makes a future assessment far easier.

This post is general information, not legal advice. For your obligations under Law 25, talk to your legal counsel or consult the Commission d'accès à l'information du Québec directly.


Try it, free up to 25 employees. Bilingual interface, data in Montréal, no credit card. Start your free org chart

Related reading: Lire cet article en français · A French org chart for Québec (Bill 96) · The 8 best org chart software tools in 2026