Coworking for Confidential Work: Privacy, Security and Quebec's Law 25

A practical Quebec guide to Law 25, confidential calls, documents, Wi-Fi, incidents and choosing a coworking setup for sensitive work.

2727 Coworking - workspace

Executive Summary

Coworking is not prohibited by Quebec privacy law. The amended private-sector privacy law applies because an enterprise collects, holds, uses or communicates personal information. It does not select one legal office format over another. The practical question is whether the organization can apply safeguards that are reasonable for the sensitivity, purpose, quantity, distribution and medium of the information it handles. That conclusion is an inference from the law and regulator guidance, not a coworking exemption. [1] [7] [11]

For a business that handles confidential client work, the workspace decision should follow the information and the activity:

  • An open desk may suit ordinary administrative work that exposes no confidential content.
  • A dedicated desk gives continuity, but it does not create an acoustic or visual boundary.
  • A phone booth can reduce disruption, but the word "booth" does not prove sound isolation, access control or suitability for professional secrecy.
  • A meeting room can support a planned client meeting if its actual speech, visual, access and technology conditions are assessed.
  • A lockable private office gives the strongest physical starting point among common coworking products, but a door alone does not secure devices, cloud services, paper, printing, visitors or conversations that carry through walls.

The enterprise remains accountable for its information. A coworking agreement, a password on Wi-Fi, a VPN or a provider's marketing statement does not transfer that responsibility or certify compliance. Quebec organizations should have a privacy lead, policies and practices, an information inventory, access controls, retention rules, an incident process and proof that those controls work. [2] Federal PIPEDA rules may also apply to federally regulated businesses and to personal information that crosses provincial or national borders in commercial activity. [21]

A privacy impact assessment is not automatically required simply because a business rents coworking space. The Quebec trigger relevant to most small businesses concerns a project to acquire, develop or redesign an information system or electronic service involving personal information. An assessment is also required before communicating personal information outside Quebec or entrusting its collection, use, communication or retention to a person or body outside Quebec. [8] [11]

If a confidentiality incident occurs, record it. If it presents a risk of serious harm, notify the Commission d'accès à l'information du Québec, or CAI, and affected people diligently. Quebec's rule does not create a universal 72-hour deadline. The incident register must cover all confidentiality incidents and the CAI says its information must be kept for at least five years after the date or period when the organization learned of the incident. [11] [7] [12]

This guide is current as of October 3, 2026. It provides general information and a practical evaluation method. A lawyer, professional order, insurer, privacy specialist or client may impose requirements beyond this guide.

"Law 25" is the familiar name of the amending statute. Day-to-day duties now appear in Quebec's amended Act respecting the protection of personal information in the private sector. The official text covers accountability, governance, collection, consent, use, communication, retention, security, incidents, access and portability. [11]

The amendments arrived in stages. The dates explain why an older policy or article may describe only part of the current regime:

Effective date Principal changes relevant here
September 22, 2022 Privacy-officer responsibility and confidentiality-incident duties began.
September 22, 2023 The main governance, consent, transparency and privacy-impact-assessment changes took effect.
September 22, 2024 The portability provisions took effect.

The principal changes in these three stages are now in force. Article 175 of the amending statute supplies the precise commencement dates. [38] A current workplace process should be assessed against the completed regime rather than the rules that applied when the phase-in began. [8]

The office format is therefore the wrong first classification. Begin with four questions:

  1. Which law and professional rules apply? A private enterprise, public body, covered health organization and regulated professional may have different or overlapping duties.
  2. What information is involved? Names and work coordinates are different from health records, account details, identity documents, legal strategy or disciplinary files.
  3. What will happen in the space? Quiet writing, a client call, printing, an in-person meeting, overnight storage and remote access create different exposure paths.
  4. What consequence could follow an exposure? Embarrassment, financial loss, identity theft, professional prejudice, loss of privilege or physical risk do not call for the same controls.

Quebec also protects privacy through broader civil rights. The Civil Code recognizes a right to reputation and privacy and identifies interception or use of a private communication as a possible invasion of privacy. [14] The Quebec Charter also protects privacy and separately protects professional secrecy. [15] These rules matter when a conversation is overheard or a screen is visible even if the operator never receives a database.

Private-sector, federal, public and health rules are distinct

For most Quebec businesses, the private-sector law is the central provincial regime. Quebec's law is recognized as substantially similar to PIPEDA. [21] PIPEDA still applies to federal works, undertakings and businesses, and to personal information crossing provincial or national borders in commercial activity. More than one law can apply to the same organization or flow. [22]

Public bodies fall under Quebec's public-sector access and privacy statute. The CAI says close to 3,000 public bodies are subject to that regime. [9] A government employee or contractor should follow the responsible body's approved workplace, device, records and contracting rules rather than assume this private-enterprise guide is sufficient.

Covered health and social-services organizations now have a dedicated Quebec statute for health and social-services information. The CAI confirms that the law came into force on July 1, 2024. [36] The CAI's current scope guidance says those organizations' obligations are mainly found in that health-sector law, while the private or public regime can continue to govern other information they hold. [20] A clinic, professional or supplier should identify its status before using a general coworking checklist.

Business contact information is not a blanket exemption

Quebec article 1 contains a limited exclusion from sections II and III for specified information concerning a person's function within an enterprise, including the person's name, title, work address, work email and work telephone number. It does not remove every fact about a professional from the law. Client communications, a case description, financial history, health information, credentials and meeting notes do not become ordinary business coordinates because one participant works for a company. [11]

PIPEDA uses a different, purpose-based exclusion. The current federal statute excludes business contact information only when it is collected, used or disclosed solely to communicate or facilitate communication with a person about their employment, business or profession. [37] Keep the provincial and federal tests separate in policies and training.

Build an Information and Activity Inventory Before Choosing a Seat

The fastest way to choose badly is to ask whether a space is "private" without defining the work. Build a short inventory before touring or buying a pass. It can be a spreadsheet, provided it is controlled and does not itself expose unnecessary personal information.

Activity Possible information Common exposure in coworking Better starting arrangement
Email, scheduling and ordinary research Business coordinates, public material Screen visibility, notifications, unattended device Open or dedicated desk with screen discipline
Sales call without sensitive details Contact details, commercial interests Being overheard, names on screen Booth or assessed room if names or pricing are sensitive
Legal, HR, health or financial call Professional secrets, identity, health, discipline, account data Intelligible speech, recording, unauthorized entry Assessed private office or meeting room, possibly another controlled site
Drafting or reviewing a client file Case facts, identifiers, evidence Shoulder surfing, cloud sync, unattended papers Private office, privacy filter, controlled device and storage
Printing or scanning Full document contents and metadata Wrong printer, abandoned output, retained copies Controlled output device and immediate collection
In-person client meeting Identity, presence, spoken and displayed information Visitor visibility, hallway speech, calendar labels Reserved room or private office with an arrival plan
Overnight equipment or files Devices, tokens, original records Theft, cleaning access, emergency access Lockable room plus device encryption and separately arranged file controls
Video conference Voice, image, screen share, participant data Wrong attendee, weak link controls, visible background Assessed room, configured platform and participant checks

Quebec requires enterprises to collect only personal information that is necessary for identified purposes. [3] That rule is an operational advantage. If a client appointment can be scheduled with a name, contact method and neutral label, do not put a diagnosis, allegation, legal issue or account number in the coworking calendar. If a visitor list needs only a name and arrival time, do not add a case summary.

For each activity, record:

  • the purpose and lawful basis for handling the information;
  • the people or systems that may access it;
  • sensitivity and likely harm if it is exposed;
  • where the authoritative copy and backups live;
  • how long it should be kept;
  • whether it will leave Quebec or Canada;
  • the room, device, printing and visitor controls needed;
  • the person who can stop the activity if conditions change.

Do not send real client names, records or matter details to a coworking operator merely to ask whether a room is suitable. Describe the control need instead, such as "four-person meeting, no recording, controlled entry, speech check required."

Accountability Does Not Transfer to the Coworking Operator

The person with the highest authority in a Quebec enterprise is the privacy officer by default. The role may be delegated in writing, in whole or in part, but the highest authority remains accountable. The title and contact information of the person exercising the role must be published on the enterprise's website or otherwise made public if there is no website. [2] A solo practitioner will commonly hold the role personally.

An enterprise also needs governance practices that people can actually follow. At a minimum, the operating package for confidential coworking should identify:

  • who approves workspace types for each information class;
  • which devices and accounts may be used;
  • where confidential calls and meetings may occur;
  • how visitors, printing, paper and removable media are handled;
  • how access is changed when staff join, change roles or leave;
  • who receives a suspected-incident report at any hour;
  • retention and secure-destruction rules;
  • how service providers and foreign processing are reviewed;
  • how compliance is checked and corrected.

The federal accountability principle leads to the same practical conclusion. The Office of the Privacy Commissioner of Canada recommends a privacy-management program with assigned responsibility, risk assessment, training, service-provider oversight and evidence that the program operates. [27] The OPC's business guide organizes PIPEDA compliance around ten fair-information principles, including accountability, limiting collection, safeguards, openness and individual access. [26]

Valid Quebec consent must meet several conditions, including being manifest, free, informed, specific, time-limited, granular and understandable. A written request for consent must be presented separately from other information. Express consent is generally required for sensitive information, subject to the law's exceptions. [4]

Workspace controls do not cure a collection that was unnecessary or a consent that was invalid. Before recording a meeting, enabling an AI transcript, photographing identification, adding a guest to an operator system or displaying a client name on a room screen, ask whether the step is necessary, disclosed and authorized. Platform defaults can activate recording, transcription, participant analytics or cloud retention. Review them before the meeting begins.

People also have access and rectification rights. Quebec's portability right is narrower than a universal export guarantee. It applies in the conditions set by law to computerized personal information collected from the person, and does not require transfer of information created or inferred from that information or obtained from third parties. The duty to provide those data in a structured, commonly used technological format does not apply when doing so raises serious practical difficulties; the underlying access right remains. Do not promise that every case note, risk score, legal opinion or mixed record can be exported automatically. [2]

Use a Risk-Based Safeguards Test

Quebec's security standard is contextual. Measures must be reasonable in light of sensitivity, purpose, quantity, distribution and medium. The CAI groups useful controls across administrative, physical and technical measures and includes restricted premises, locked files, access management, encryption, secure destruction, training and an incident plan. [7]

This does not mean every organization must buy every security product. It means the decision should be explainable. A useful assessment records:

Factor Questions Evidence to keep
Sensitivity Could exposure affect health, finances, reputation, employment, legal rights or safety? Classification and rationale
Purpose Is this information needed for the task happening in this space? Purpose statement and minimized fields
Quantity Is one record visible, or a whole client database? Data inventory and access scope
Distribution Which staff, guests, operators, cleaners, vendors and remote participants can encounter it? Access list and provider review
Medium Is it spoken, on paper, on a screen, in a cloud service or on removable media? Control map for each medium
Duration Is exposure momentary, or will devices and files remain overnight? Booking and retention plan
Consequence What harm could realistically follow? Risk rating and escalation decision

The CAI's prevention checklist emphasizes collecting less, controlling access, storing information securely, training personnel and preparing for incidents. [10] Apply those controls before asking whether a particular chair is acceptable.

Compare Coworking Arrangements by Control, Not Label

Marketing labels are inconsistent. "Private," "quiet," "secure," "professional" and "soundproof" can describe different facts. Inspect the exact room and operating process.

Arrangement Useful for Material limits Questions before use
Open hot desk Public information and ordinary low-risk work Changing neighbours, visual exposure, calls audible nearby, no assured storage Are calls allowed? What can be seen behind and beside the screen?
Dedicated desk Repeated setup and equipment continuity Still open, no acoustic boundary, equipment may remain exposed Who enters the area after hours? Can the screen and documents be cleared?
Phone booth Short calls with less disruption Unknown speech isolation, availability, entry and ventilation; a booth may not suit documents or several people Can words be understood outside? Who can enter? Is recording present?
Meeting room Planned meetings and calls Shared calendar, turnover, glass, hallway speech, service access and remote-platform risks Is the booking title neutral? Can entry and speech be tested?
Private office Repeated sensitive work and controlled client meetings A lock does not prove sound isolation, exclusive keys, secure storage or network design Who has access, when, and why? What happens during cleaning or emergencies?

A closed door improves occupancy control, but it does not establish legal compliance or professional secrecy. A room can be visually private and acoustically weak. It can be acoustically acceptable while a glass wall exposes a screen. It can perform well at noon and poorly in a quiet corridor after hours.

Use the site's dedicated research instead of duplicating the full technical tests here. The private-office privacy and video-call guide explains how to test sightlines, speech and simultaneous calls. The meeting-room privacy and acoustics guide covers doors, partitions, corridors and meeting workflows. For a one-day booking, the confidential video-call workspace guide compares open desks, booths and rooms.

A simple speech and sightline test

Before sensitive work, use representative but fictional content:

  1. Put one person in the normal speaking position and one at each plausible listening point outside.
  2. Close the door as it will be used. Test ordinary speech and the loudest expected participant.
  3. Check the threshold, adjacent wall, glass, ventilation path and corridor.
  4. Sit where a visitor or passerby might be and inspect screens, whiteboards and paper.
  5. Repeat when surrounding activity is quiet, since background sound can otherwise hide leakage.
  6. Record the result as a limited observation for that room and setup, not a permanent soundproofing certificate.

If intelligible sensitive speech reaches an uncontrolled area, stop the discussion, reduce the information, move or use another channel. Headphones prevent nearby people from hearing the remote participant. They do not stop nearby people from hearing the local speaker.

Treat Digital Security as an Organization Control

Law 25 requires reasonable safeguards, but it does not state that every coworker must use a VPN, a particular encryption product or a certified coworking network. The Canadian Centre for Cyber Security sources in this section are practical recommendations. They help build a defensible baseline, but no single tool proves legal compliance.

Network choices

The Cyber Centre recommends that sensitive information not be transmitted over open networks without additional encryption controls. Its Wi-Fi guidance discusses encryption, corporate VPNs, patching and separation of guest, staff and device networks. [28] This is a reason to ask an operator precise questions. It is not evidence that any particular coworking space provides segmentation.

For shared or public-area Wi-Fi, the Cyber Centre recommends avoiding it for business where possible, using a VPN according to organizational policy, watching for shoulder surfing, disabling automatic connection, keeping devices updated and signing out when finished. [31] A mobile hotspot can reduce reliance on venue Wi-Fi, but it still needs a controlled device, strong account security and adequate signal.

Ask the operator:

  • Is the network open, shared with one password, segmented by role or separately provisioned?
  • Are wired connections available, and what network do they reach?
  • Can members discover one another's devices?
  • How are router, access-point and firewall updates managed?
  • What logs exist, who can access them and how long are they kept?
  • How are guest, staff, building-device and member networks separated?
  • What happens when a member reports a suspected network event?

If the operator cannot answer, do not invent the answer from a network name or a lock icon. Reduce the information used there or choose a connection your organization controls.

Devices, accounts and remote work

The Cyber Centre's baseline for small and medium organizations recommends encrypted mobile storage, secure remote access, network controls, backups and assessment of cloud providers. [30] Its BYOD guidance warns that poorly configured end-user devices create organizational risk and recommends policy, classification, encryption, network rules, incident handling and training. [32]

A practical device baseline for confidential coworking is:

  • organization-managed or formally approved devices;
  • full-device encryption and prompt security updates;
  • automatic screen lock with a short timeout;
  • separate user accounts and least-privilege access;
  • no confidential local copies unless needed and protected;
  • controlled backup and tested recovery;
  • remote lock or wipe where appropriate;
  • notification previews hidden on lock screens;
  • Bluetooth, file sharing and automatic network connection disabled when unnecessary;
  • an immediate process for loss, theft or suspected compromise.

Use strong multi-factor authentication for sensitive systems. The Cyber Centre recommends MFA for accounts and devices, with authenticator applications, security keys or smartcards preferred over weaker methods for higher-risk use. [33] Also train people to verify unexpected login prompts and requests through an independent channel. Phishing controls work better when staff know how to recognize, report and rehearse them. [34]

Video calls and collaboration platforms

Video conferencing adds participant, recording, link-sharing, screen-sharing and cloud-processing risks. The Cyber Centre recommends assessing vendors, encryption, access controls, passwords, waiting rooms, software updates and the sensitivity of the discussion. It advises against using video teleconferencing for highly sensitive discussions. [29]

Before a confidential call:

  1. Use a neutral meeting title and a controlled invitation list.
  2. Confirm the platform, account and data-location rules approved by the organization.
  3. Use a waiting room or equivalent and admit known participants.
  4. Disable recording, transcription and assistants unless specifically authorized.
  5. Close unrelated applications and notification previews.
  6. Share one window rather than the whole desktop when possible.
  7. Confirm every participant and any person physically present.
  8. State the recording rule and stop if an unknown participant joins.
  9. Clear whiteboards, downloads, chats and temporary files according to policy afterward.

Control Paper, Printing and Storage

Paper is easy to overlook because it does not generate a login alert. A shared printer can retain a job, release it to the wrong tray or expose pages while the sender walks across the floor. A scanner may email to a default address or store a copy. A cleaner, visitor or neighbouring member may see papers left face up.

Government security guidance on protecting specified information treats physical control of output devices, privacy screens and headphones as useful controls. [35] Use that as a practical reference, not as a claim that the same federal security profile is mandatory for every Quebec small business.

For confidential output:

  • avoid printing unless the task requires paper;
  • confirm the selected printer and destination before sending;
  • use secure release if it is actually available and tested;
  • collect every page immediately and check the page count;
  • do not use a shared recycling bin for confidential drafts;
  • arrange secure destruction through an assessed process;
  • do not leave originals in a meeting room, booth, printer or scanner;
  • keep a chain of custody for identity, legal, financial or signed originals.

Quebec requires secure destruction when information is no longer needed, subject to any retention law. Anonymization for serious and legitimate purposes is a tightly regulated alternative, not the same thing as deleting names from a document. [6] Quebec's anonymization regulation requires a documented process and analysis of reidentification risk. [13]

Federal best practices also connect retention to purpose and secure disposal, including copies, backups, moves, closures and due diligence when a destruction contractor is used. [24] A locked private office does not replace a retention schedule or a verified destruction process.

Plan Visitors and Client Meetings

A client meeting begins before the door closes. The booking name, building entry, waiting place, greeting, room display and departure can reveal a relationship. Professional-services work may also involve interpreters, support people, witnesses or family members whose authority and role must be clear.

Use a client-arrival plan:

  1. Give the client exact arrival instructions through an approved channel.
  2. Use a neutral calendar and room label.
  3. Decide who will greet the visitor and where they may wait.
  4. Avoid asking for the matter, diagnosis or service type in a common area.
  5. Prevent overlapping appointments from exposing identities to one another when that matters.
  6. Confirm who is attending and why before discussing the file.
  7. Keep hallway and doorway conversation generic.
  8. At the end, collect documents, clear displays and escort the visitor according to the operator's rules.

For a broader professional-client workflow, see the client-facing offices guide. It covers arrival, interpreters, printing, record handling and professional-order questions without treating a closed office as a compliance certificate.

Professional liability, commercial general liability, cyber coverage and property coverage answer different risks. The coworking business insurance guide provides a separate starting point. Confirm actual policy terms with the insurer or broker. Do not infer coverage from the coworking operator's insurance.

Know When a Privacy Impact Assessment Is Required

A privacy impact assessment, often called a PIA or EFVP in French materials, is a structured review of a project and its privacy risks. It is useful voluntarily in many situations, but the Quebec private-sector statute creates specific triggers.

For most small organizations considering coworking, distinguish three decisions:

Decision Automatic Quebec PIA trigger? Sensible review
Rent a desk, room or private office Renting alone is not listed as a trigger Document the workspace risk and controls
Acquire, develop or redesign an information system or electronic service involving personal information Yes, this is the statutory project trigger Begin the PIA early enough to influence design
Communicate personal information outside Quebec, or entrust its collection, use, communication or retention to a person or body outside Quebec An assessment is required beforehand under article 17 Map location, sensitivity, the applicable legal regime, protections and contract

The law requires the privacy officer to be consulted at the beginning of a qualifying system or electronic-service project. [11] Do not wait until a platform is configured and data has moved. A voluntary short assessment can still be wise when an office move changes access, printing, visitor or storage conditions, even though the lease itself is not an automatic trigger. [8]

Ask these questions for a new coworking-related system:

  • Will the operator receive member, visitor, access-log, camera or payment information?
  • Will a room-booking tool reveal client or matter names?
  • Will an access app connect identity, device and arrival data?
  • Which vendors and subprocessors receive information?
  • Where is each service hosted and supported?
  • What settings reduce collection and retention?
  • How are access, correction, deletion and incident requests handled?
  • Can the organization leave the provider without losing or exposing records?

Review Service Providers and Cross-Border Processing

Quebec permits some communication to service providers without consent when communication is necessary for the mandate or service contract and the statutory conditions are met. Article 18.3 normally requires a written mandate or contract and confidentiality safeguards, with a specific exception to the safeguard-clause requirement for a recipient who is a public body covered by the public-sector access statute or a member of a professional order. The enterprise remains responsible for the information. Under article 17, assess the transfer or outsourced processing before it begins, including the applicable foreign legal regime. It may proceed only if the assessment demonstrates adequate protection, and a written agreement must reflect the assessment and any agreed risk-reduction measures. [11] [5]

Do not limit the review to the building operator. The relevant providers can include:

  • access-control and visitor applications;
  • room-booking and payment platforms;
  • email, file storage and collaboration suites;
  • video-conference and transcription services;
  • managed IT, support and device-management vendors;
  • printers, scanners and destruction contractors;
  • backup, identity and security-monitoring providers.

The OPC likewise says outsourcing does not transfer accountability. Organizations subject to PIPEDA should review third-party policies, training, safeguards and foreign processing, and explain foreign processing and potential access by foreign authorities. Contractual or other measures must provide protection comparable to PIPEDA. [26] [23]

Keep a provider record containing the service, information categories, purpose, location, authorized people, subprocessors, retention, return or deletion terms, incident route and contract owner. A list of vendors without their data flows is not enough.

Prepare for Confidentiality Incidents

A confidentiality incident involves personal information: unauthorized access, use or communication, loss, or another breach of its protection. Possible events to investigate in coworking include a laptop left in a room, a file sent to the wrong printer, an unintended recording, intelligible hallway speech, a visitor entering the wrong office, exposed credentials or an access fob that remains active after departure. An active fob or an unattended laptop is a warning sign, not automatically a confidentiality incident; determine whether personal information was lost or its protection breached. [7]

Use this response sequence:

  1. Stop and contain. End the discussion, retrieve output, lock or isolate a device, revoke a link or access credential and preserve relevant evidence.
  2. Notify the internal lead. Staff should know one route that works promptly, including outside ordinary hours.
  3. Establish facts. Identify the information, people, time, systems, recipients, copies and containment status. Do not put extra personal information into an insecure incident channel.
  4. Reduce harm. Recover documents, reset credentials, contact unintended recipients and take other lawful steps.
  5. Assess serious harm. Consider sensitivity, anticipated consequences and likelihood of harmful use.
  6. Notify when required. If serious harm risk exists, notify the CAI and affected people diligently. The enterprise may notify a person or body able to reduce that risk, communicating only necessary personal information; the privacy officer must record that communication. [11]
  7. Record every incident. Include incidents that do not meet the serious-harm threshold and keep the register information updated and retain it for at least five years after the date or period when the organization learned of the incident. [7] [12]
  8. Correct the system. Update room rules, training, technology, vendor terms or access so the same path is less likely to recur.

The statute allows notice to an affected person to be delayed only while it could impede an investigation by a legally responsible crime or offence investigator. This exception does not suspend notice to the CAI. [11]

There is no general Quebec 72-hour rule in the private-sector incident provisions or regulation. [7] [12] PIPEDA has its own current breach-reporting duties, which should be assessed separately when the federal statute applies. [26]

The operator may hold useful access, booking or building information, but the enterprise should not wait for the operator to decide its legal duties. The incident plan should state who contacts the operator, who preserves evidence, who makes the legal assessment and who communicates externally.

Professional Secrecy Can Require More Than General Privacy Compliance

Quebec's Professional Code requires a professional to respect the secrecy of confidential information learned in professional practice, subject to narrow lawful or client-authorized exceptions. [16] General privacy compliance therefore does not answer every question for a regulated professional.

The Barreau du Québec states that a lawyer's duty applies at all times and covers client exchanges. [17] The lawyers' code also requires confidentiality of information about a client's affairs and reasonable measures concerning collaborators and the lawyer's organization. [19] The CPA code requires reasonable measures throughout preparation, retention and transmission of confidential information. [18]

These sources directly support lawyers and CPAs. They should not be used to invent the wording of another profession's code. A physician, psychologist, notary, financial professional or other regulated practitioner should review the current rule of their own order, client contracts and insurer requirements.

For professional work, add these questions:

  • Does professional secrecy protect the fact of the relationship as well as the content?
  • Does privilege depend on who is present or how a third party is used?
  • May assistants, interpreters or vendors receive the information?
  • Does the client contract require a location, certification or prior approval?
  • Does the insurer require specific physical or cybersecurity controls?
  • Must original records remain in a particular place or system?
  • What evidence would the professional need to show the order after a complaint?

If the room or process cannot meet the answer, choose another environment. The correct result can be to postpone or relocate the activity.

A Practical Operating Workflow

Before joining a coworking space

  1. Inventory the information and activities that will occur there.
  2. Identify applicable Quebec, federal, health, public-sector, professional, contractual and insurance requirements.
  3. Classify each activity by sensitivity and consequence.
  4. Tour the exact desk, room or office at realistic times.
  5. Test speech and sightlines with fictional content.
  6. Ask written questions about access, guests, cleaning, emergencies, networks, printers, storage and incidents.
  7. Review the agreement, privacy notice, access app and related vendors.
  8. Decide which activities are approved, conditional or prohibited.
  9. Prepare devices, accounts, retention and incident processes.
  10. Train every person who will use the space and keep the decision record.

At the start of each workday

  • Check that the assigned room and access conditions have not changed.
  • Position the screen away from circulation and use a privacy filter when appropriate.
  • Connect only through an approved network method.
  • Confirm updates, encryption, MFA and screen lock are functioning.
  • Keep only the files and paper needed for the day's tasks.
  • Review meeting names, participants, recording settings and visitor arrivals.
  • Know where to move if a private space becomes unavailable.

Before a sensitive call or meeting

  • Reassess the information. Remove unnecessary names, files and examples.
  • Confirm the room is reserved and clear of earlier users' material.
  • Test speech and visual exposure if conditions have changed.
  • Admit only authorized people and confirm remote participants.
  • Disable unapproved recording, transcription and assistants.
  • Close unrelated applications and hide notifications.
  • State confidentiality, recording and document-handling expectations.
  • Stop if the door, platform, audience or surrounding conditions change.

Before leaving

  • Collect every page, note, token, key and device.
  • Clear whiteboards and room displays.
  • Sign out of shared equipment and remove downloads.
  • Close and lock approved storage.
  • Report misplaced material or unusual access immediately.
  • Do not postpone a suspected incident until the next business day merely because the booking has ended.

When a worker or the organization leaves

  • Revoke app, fob, key, network and room-booking access.
  • Remove equipment and records under a documented inventory.
  • Verify return or deletion by relevant providers.
  • Update the public privacy contact and any address records if needed.
  • Redirect clients and vendors without revealing confidential matters.
  • Retain contracts, assessments and incident records for their applicable periods.
  • Test that former users can no longer enter systems or premises.

Apply the Method to Common Work Patterns

The same coworking product can be suitable for one task and unsuitable for the next. Approval should therefore attach to a defined activity and control set, not to the member or address in the abstract. The following scenarios show how to turn the legal and practical principles into a workable decision.

Routine solo work with occasional calls

A consultant who spends most of the day reading public material, preparing a generic presentation and answering routine messages may be able to use an open desk. The approved setup could require a privacy filter, hidden notification previews, an organization-managed device, MFA and a rule that client-specific calls move to an assessed booth or room.

The critical control is the transition. People often begin with an ordinary call and then receive a question that requires identity, pricing, account, legal or health details. The worker needs permission to say, "I need to move before we discuss that," and a practical place to go. If no suitable room is available, the sensitive part waits. A day pass should not create pressure to continue a confidential conversation at the desk.

A professional who takes calls throughout the day

A lawyer, accountant, recruiter, financial professional or adviser with repeated client calls should not build the day around uncertain booth availability. A private office may provide a better starting boundary, but the professional must still test speech, orient the screen, control paper and understand who can enter. If calls overlap with cleaning, maintenance or client arrivals, schedule and access procedures matter as much as the lock.

Write a fallback rule before the first call. For example: if speech is intelligible outside, if an unauthorized person enters, if the network method fails or if the video platform activates an unapproved feature, stop and move. This avoids making a high-pressure decision while confidential information is already being disclosed.

A client meeting with documents and a remote participant

This meeting has at least four boundaries: the building, the room, the documents and the video platform. The organizer should use a neutral booking title, give the client controlled arrival instructions, verify every in-person and remote participant, limit the papers brought into the room and decide who owns each original at the end.

The remote participant creates a second physical environment that the coworking operator cannot assess. Ask them to confirm who is present, whether they are using headphones, whether recording or transcription is active and whether their location is suitable. Share the smallest necessary window. If the group needs to compare several files, prepare a controlled workspace rather than opening an email inbox or general client directory on screen.

A small team in a private office

A private office does not mean that every team member should have access to every client file. Apply role-based access inside the team. Keep matter names out of shared calendars when unnecessary. Decide whether calls can occur simultaneously, whether visitors can see another worker's screen and where printouts go. If people share one membership, key or account contrary to provider terms, both operational control and accountability become harder. Use individual identities and authorized access.

For a team that is choosing among plans, the hot desk, dedicated desk and private office guide explains the product trade-offs. The privacy decision in this guide should then be applied to the selected plan and exact room.

Paper-heavy or original-document work

A task involving tax slips, identity documents, signed instruments, evidence or medical forms deserves its own chain of custody. Count originals on arrival and departure. Do not rely on a general promise of "storage" without confirming the exact container, keys, access list and retrieval process. If the space has no verified storage or destruction process, bring only what can remain under the responsible person's control and remove it at the end.

Scanning does not automatically solve the problem. Confirm the scanner destination, stored history, address book, local cache and deletion procedure. Review the resulting file before destroying a paper source, and do not destroy an original that must be preserved under another law, professional rule, contract or litigation hold.

A one-day visitor or urgent booking

Time pressure increases the chance of assumptions. A visitor should not infer that a day pass includes a private office, booth, printer procedure or staff support. Before paying, confirm the product, hours, entry method, call options and cancellation terms. Bring a connection and device setup that already meets organizational policy. Avoid making the first test of a security control during a live client call.

If the work requires a closed room for only part of the day, compare the available meeting-room product with the sensitivity and schedule. Do not use an open desk for the sensitive part merely because a private product is sold only by the day. Reschedule, reduce the information or choose another venue.

A growing practice that changes systems

Moving from a solo laptop to a client portal, shared case system, booking workflow or AI assistant changes more than the furniture. The system project may trigger a Quebec PIA, and vendor or cross-border rules may apply. Begin with a data-flow map and privacy-officer involvement. Keep the workspace assessment as one component of the wider project rather than treating the office lock as an answer to software risks.

Keep a Small Evidence File

A useful compliance record can be concise. Keep the workspace assessment, date and assessor; the information and activity classes approved there; operator answers and applicable contract terms; speech and sightline test notes; the chosen device, network, visitor, paper and incident controls; training completion; and the next review date.

Reassess after a renovation, office move, provider change, network change, new printer, new access app, team expansion, new professional service, new client requirement or incident. Also review after a test no longer produces the same result. The aim is not to create paperwork for its own sake. It is to preserve the facts and judgment that made the decision reasonable, then update them when the facts change.

Plan for Disruption and Continuity

A confidential practice needs a fallback before the preferred room, connection or system fails. List the events that would stop approved work: loss of the private office, an access-app outage, an unavailable booth, a network incident, a fire alarm, a printer failure, a stolen device or unexpected people in the room. Assign a response to each event.

The fallback may be to use an approved mobile connection, move to another previously assessed room, switch to a controlled paper-free task, contact the client through a neutral message or postpone. It should not be to disclose the same information at an open desk because the reservation failed. Keep the fallback instructions accessible without exposing the client file.

Also decide how urgent work continues after a device is isolated or access is revoked. Identify the authorized backup device, recovery contact, secure copy and method for verifying the client before resuming. Test recovery with fictional information. A backup that has never been restored is an assumption, and a personal laptop borrowed during an incident may create a second uncontrolled copy.

For a planned move or cancellation, set a cutover date. Remove equipment and paper, revoke every physical and digital credential, obtain any provider confirmation required by contract, update client directions and test that the former location no longer appears in calendars or templates. Keep a neutral contact path active so a client can reach the practice without sending confidential details to an abandoned mailbox or booking account.

Questions to Ask the Operator and Verify Yourself

Ask factual questions rather than asking whether the space is "Law 25 compliant." The operator cannot decide your purposes, information sensitivity, professional secrecy or complete control environment.

Physical and access questions

  • Does the exact office lock, and who can open it?
  • What access do staff, cleaners, maintenance workers and emergency personnel have?
  • How are lost credentials disabled?
  • How do visitors enter, wait and reach the member?
  • Are access events logged, and for how long?
  • Can a member reserve a room without displaying a sensitive title?
  • Is any camera or recording device present near the workspace?
  • What storage exists, and is it separately controlled?

Speech and visual questions

  • Can ordinary speech be understood in the corridor or adjacent room?
  • Can screens or whiteboards be seen through glass or from circulation paths?
  • Are booths reserved, first come first served or time-limited?
  • What happens if the private room is unavailable during a scheduled call?
  • May the member conduct a realistic speech and sightline test?

Technology and records questions

  • What Wi-Fi and wired-network arrangements are actually provided?
  • Are printers or scanners shared, and do they support secure release?
  • Does equipment retain jobs, scans or address books?
  • Which provider operates access, booking, payments and visitor systems?
  • Where is operator-held member and visitor information processed?
  • What incident route is available after hours?
  • How are information and access deleted when membership ends?

Treat unanswered or unverifiable questions as uncertainty in the risk assessment. Do not convert silence into a favorable fact.

How 2727 Coworking Fits

2727 Coworking is at 2727 Rue Saint-Patrick, Suite 109, in Montreal. Every private office has a lockable door and a window. Private-office and dedicated-desk members have 24/7 access through Kisi by phone app or fob. Hot desks and day passes run Monday to Friday from 8:00 to 18:00, excluding weekends and holidays. The service includes gigabit fibre internet, with wired Ethernet available in offices, printer access, phone booths available first come first served and free conference-room use for office and desk members, booked as available. These product features do not establish soundproofing, network segmentation, secure file storage, cybersecurity certification or compliance with a professional rule.

Private offices are month to month with no minimum term and 30 days' notice. They include furniture, Wi-Fi, coffee, cleaning, printer access, phone booths and use of the address with mail reception. Private offices are priced from $700 per month before taxes, as of October 2026. Online checkout adds a setup fee equal to one month’s rent. All quoted amounts are in Canadian dollars. Inventory changes, so check the live booking page for current rates and availability.

Visitors may meet a member in the member's private office or in the conference room, not in the coworking area. There is no reception. Visitors use the intercom and the member greets them. There are no lockers or general storage. Private-office tenants must carry at least $1,000,000 in civil liability insurance. Those operational facts should be included in the organization's assessment rather than presented as privacy guarantees.

To inspect the space, book a tour. Published tours run Monday to Friday from 8:00 to 11:30, with weekday afternoons by arrangement. There are no weekend tours or walk-ins. Ask to inspect the exact office, calling location and client route that you plan to use. Current products and pricing are also described on the private-office page, day-pass and desks page and conference-room page.

Frequently Asked Questions

Does Quebec's Law 25 prohibit coworking for confidential work?

No. The private-sector law regulates how an enterprise handles personal information. It does not name coworking as a prohibited office format. The enterprise must choose reasonable safeguards for its information and circumstances. Some activities may be appropriate at an open desk, while professional secrets or highly sensitive records may require a tested private room, stronger controls or another location.

Is a coworking operator responsible for my Law 25 compliance?

The operator is responsible for its own handling of personal information. Your enterprise remains responsible for its purposes, collection, access, devices, client records, vendors, retention and incidents. A contract should allocate services and incident cooperation clearly, but it does not transfer the enterprise's statutory accountability.

Is a privacy impact assessment required before I rent a coworking office?

Renting the space alone is not listed as an automatic trigger. A PIA is required for a qualifying project to acquire, develop or redesign an information system or electronic service involving personal information. An assessment is also required before communicating personal information outside Quebec or entrusting its collection, use, communication or retention to a person or body outside Quebec. A short voluntary workspace risk assessment is still useful. [11]

Does a private office automatically make confidential work compliant?

No. A lockable office improves physical control, but you must still assess sound transmission, screen visibility, authorized access, cleaning, emergencies, networks, devices, cloud services, visitors, printing, storage, retention and incidents. Compliance belongs to the full process.

Can I handle confidential files from a dedicated desk?

Only if the information and controls make that reasonable. A dedicated desk remains in an open area. It may work for low-risk administration on a controlled device. Regular professional-secret calls, visible identity records or paper files usually point toward an assessed private room or another controlled environment.

Can I take ordinary calls at an open coworking desk?

Follow the operator's call rules and your organization's classification. An ordinary operational call may be acceptable with a headset and careful language. Move if the call involves client identity, HR, health, financial, legal, security or other confidential details. A headset does not stop others from hearing your voice.

Is a phone booth confidential or soundproof?

The label alone proves neither. Test whether representative speech can be understood outside, who can enter, whether glass exposes a screen and whether a platform or device records. Use fictional content for the test. Do not use a booth for sensitive material if the result is uncertain.

Is a meeting room suitable for client meetings?

It can be if the room and process match the information. Check booking labels, visitor arrival, speech, sightlines, entry, displays, paper cleanup and remote participants. A room described as private may mean exclusive occupancy, not verified acoustic isolation.

Does shared Wi-Fi violate Law 25?

Not automatically. Quebec requires reasonable safeguards rather than naming one network design. Assess encryption, device isolation, authentication, logging, updates and the information being transmitted. Use approved additional controls or another connection when the shared service does not meet the organization's risk decision.

Is a VPN legally mandatory in coworking?

Law 25 does not prescribe a universal VPN requirement. A VPN is a Cyber Centre recommendation for some shared-network situations and may be required by an employer, client or security policy. It protects a data path, not a visible screen, an overheard call, a compromised device or an unsafe cloud account.

Must the coworking space hold a cybersecurity certification?

No universal certification requirement appears in the cited Quebec private-sector rules. A client contract or sector policy may require one. Ask for factual controls and independent evidence relevant to the risk, then document any gap. Do not treat a certification name as proof of every physical and operational control.

Can I print confidential documents on a shared printer?

Use a shared printer only under an approved process. Confirm the destination, use tested secure release if available, collect every page immediately and arrange secure destruction for drafts. If the device stores jobs or output can be collected by others, use another method.

Can I leave paper files in a private office overnight?

Only if approved storage and access conditions support it. A lockable office is not necessarily a locked file cabinet, and staff or emergency personnel may have access. 2727 provides no lockers or general storage, so ask before adding any cabinet and otherwise remove the files.

Is it safe to leave my laptop overnight?

The decision belongs to the organization's risk policy and insurance terms. At minimum, use encryption, strong authentication, screen lock, controlled backups and a rapid lost-device process. Physical possession of a locked room does not protect an unencrypted device or active session.

Can clients visit me in coworking without exposing confidentiality?

Plan the full visit. Use neutral invitations and room labels, control waiting and greeting, avoid discussing the matter in common areas, confirm attendees and clear the room afterward. At 2727, visitors may meet in the member's office or conference room and are greeted by the member because there is no reception.

Not by itself. It changes the operating workflow. Decide how clients enter, who greets them, where they wait and what happens if they arrive early. A confidential practice should not rely on an unverified assumption that staff will receive or screen visitors.

Does professional secrecy apply in coworking?

Yes. The duty follows the professional relationship and information, not the lease. Quebec's Professional Code establishes a general secrecy duty for regulated professionals, while each profession's code and facts supply further detail. The professional should review the applicable order's current rules.

Can a lawyer work from a coworking space?

Coworking is not automatically barred, but the lawyer's continuing professional-secrecy and confidentiality duties remain. The lawyer must assess conversations, files, collaborators, vendors, access and client expectations. If privilege or secrecy cannot be protected in the proposed setup, the activity should move.

Can a CPA work from a coworking space?

Potentially. The CPA code requires reasonable measures throughout preparation, retention and transmission of confidential information. That calls for a controlled device, suitable room, secure records process, careful printing and reviewed service providers, not simply a professional-looking address.

How long should personal information be kept?

Keep it only as long as the purpose and applicable law require, then destroy it securely or anonymize it for serious and legitimate purposes under the prescribed conditions. A professional, tax, corporate, limitation or litigation rule may impose a longer period. Write a schedule by record class rather than keeping everything indefinitely.

What should I do if someone overhears a confidential call?

Stop the disclosure, move or end the call, identify what was heard and by whom, notify the internal privacy lead and document the facts. Assess the incident and serious-harm risk, take steps to reduce harm, notify when legally required and update the room or calling process.

Is there a 72-hour deadline to report a Quebec confidentiality incident?

The cited Quebec private-sector rules require diligent notice when an incident presents a risk of serious harm. They do not state a universal 72-hour deadline. Every confidentiality incident must still be entered in the incident register, and the register information must be kept updated and retained for at least five years after the date or period when the organization learned of the incident. [11] [12]

How much is a private office at 2727 for confidential work?

Private offices are priced from $700 per month before taxes, as of October 2026. They are month to month with 30 days' notice, and the online checkout adds a setup fee equal to one month's rent. Rates and inventory change. Review the live booking page and assess the exact office before using it for sensitive work.

Does a 2727 private office include 24/7 access and visitor access?

Private-office members have 24/7 access through Kisi by phone app or fob. Visitors use the intercom and the member lets them in. Visitors may meet in the member's office or the conference room, not in the coworking area. There is no reception, so the member should plan and perform the greeting. Day-pass and hot-desk hours are different, Monday to Friday from 8:00 to 18:00, excluding weekends and holidays.

Does 2727 require insurance for confidential professional work?

Private-office tenants must carry at least $1,000,000 in civil liability insurance. That requirement does not establish coverage for professional errors, privacy incidents, cyber events, equipment or client records. Ask an insurer or broker which policies and endorsements match the practice, contracts, equipment and information involved.

What should I verify during a 2727 tour?

Inspect the exact office, visitor route and calling locations. Test speech and sightlines with fictional content. Ask about access, cleaning, emergencies, network design, printing and your own storage needs. Private offices have lockable doors, gigabit fibre and wired Ethernet, but those verified features do not establish soundproofing, private network segmentation, secure file storage or a cybersecurity certification. Verify any control your work requires.

Does a 2727 day pass include a closed room?

No. A day pass from $55 per day before taxes, as of October 2026, is for one person in the shared hot-desk area. Day-pass users may use phone booths on a first-come, first-served basis, but the pass does not include a private office or conference-room booking. Assess the booth before a confidential call.

Is wired Ethernet available for confidential calls at 2727?

Wired Ethernet is available in private offices. That connection option does not by itself establish network separation, encryption or legal compliance. Confirm the controls required by your organization before transmitting confidential information.

Does gigabit internet mean the network is secure?

No. Gigabit describes speed, not segmentation, authentication or protection of a call. 2727 provides gigabit fibre internet, but each organization must assess its devices, connections, accounts and information.

Is conference-room use included for 2727 members?

Office and desk members may use the conference room free, booked as available. A day pass does not include the room. Reserve it separately when a sensitive call or meeting needs a controlled room.

May a guest work beside me in the coworking area?

No. Visitors may meet a member in the member's private office or in the conference room, not in the coworking area. A second person who needs their own workspace uses a day pass or their own membership.

Do all 2727 private offices have windows and locking doors?

Yes. Every private office has a window and a lockable door. Those features do not prove acoustic isolation, secure storage or suitability for a particular professional duty, so inspect and test the exact office.

Can I rent a 2727 private office for only a few weeks?

Yes. Private offices are month to month with no minimum term, and one-month or few-week stays are allowed. The setup fee equals one month's rent, so a one-month stay costs two months of rent before taxes. Leaving requires 30 days' notice.

Can two people share one 2727 membership?

No. Memberships are for one person. A second person needs a day pass or their own plan. Keep access identities and responsibility clear in your own procedures.

Does the 2727 conference room include video-conference equipment?

It includes a TV screen with HDMI and a whiteboard. It does not include a dedicated video-conference kit. Bring and test any camera, microphone, speaker or adapter that your meeting needs.

Can I try 2727 before choosing a monthly plan?

There is no free trial. You can buy a day pass from $55 per day before taxes, as of October 2026. The paid day-pass amount is credited toward a monthly plan signed within 14 days. A day pass tests the shared hot-desk experience and phone-booth availability, not a specific private office.

Conclusion

Confidential coworking is a control decision, not a label. Quebec's amended private-sector law asks the enterprise to understand its information and apply safeguards that are reasonable for the risk. Professional secrecy, PIPEDA, health-sector rules, public-sector policy, contracts and insurance can add further requirements.

Choose the workspace after classifying the activity. Test the actual room. Minimize what enters calendars, devices, calls and paper. Control access, networks, accounts, printing, visitors, retention and incidents. Keep evidence of the decision and reassess it when the room, provider, system, team or information changes.

For low-risk work, an open desk may be enough. For repeated confidential calls or files, a tested private office is often the more workable starting point. For information whose exposure would cause serious harm or violate professional obligations, the correct answer may be a different controlled environment. The organization and responsible professional must make that decision from evidence.

References

[1] [2] [3] [4] [5] [6] [7] [8] [9] [10] [11] [12] [13] [14] [15] [16] [17] [18] [19] [20] [21] [22] [23] [24] [26] [27] [28] [29] [30] [31] [32] [33] [34] [35] [36] [37] [38]

Private offices from $700/mo, plus taxesBook a tour