Law 25 coverage
Conformaze maps every Law 25 obligation, article by article. For each one: what the law requires, the feature that covers it, and the proof produced — all in one place, so nothing slips between two Excel files.
Why tracking Law 25 in Excel/SharePoint lets obligations slip — even with a serious team.
Each team keeps its share — legal, IT, HR, operations. The day the regulator or a client asks for a complete view, you chase scattered files.
You approved an activity, signed a DPA, validated a PIA. Reconstructing the chain six months later is archaeology.
A policy adopted in 2023, a processor added last year, a transfer left open — nothing warns you it needs reviewing.
When leadership or the regulator asks 'where are we on Law 25?', no one can answer in five minutes with a reliable number.
Everything Law 25-related — decisions, proof, deadlines — in one place, linked and traced.
Everything Law 25 asks you to demonstrate — register, PIA, DPAs, transfers, DSARs, incidents — in one place, linked to each other.
Every creation, change and approval is timestamped and attributed. Proof builds itself as your team works.
See what is covered, what is in progress, what is missing — by obligation and by owner.
A consolidated, signed and defensible export. For the regulator, for leadership, for a client demanding compliance proof.
Article by article
For each article: the obligation in plain language, the feature(s) that cover it, and the proof produced by the platform.
The person with the highest authority in the business exercises the function of privacy officer by operation of law; they may delegate it in writing, in whole or in part. Publish the officer's title and contact details on the company's website or, if it has none, make them available by any other appropriate means.
Establish and implement policies and practices governing personal information and apt to ensure its protection. They must provide, among other things, for the framework applicable to retention and destruction, the roles and responsibilities of staff throughout the information life cycle, and a process for handling complaints. They must be proportionate to the nature and scope of the business’s activities, and approved by the privacy officer.
Conduct a privacy impact assessment for any project to acquire, develop or redesign an information system or electronic service delivery system that involves collecting, using, disclosing, keeping or destroying personal information. Consult the privacy officer from the outset of the project, and ensure the project allows computerized information collected from the individual to be communicated to them in a structured, commonly used technological format. The assessment must be proportionate to the sensitivity of the information, the purpose of its use, its quantity, distribution and medium.
Publish detailed information about those policies and practices, in clear and simple language, on the company's website or make it available by any other appropriate means — in particular about the content required by the first paragraph (framework for retention and destruction, staff roles, complaint handling).
As soon as there are grounds to believe a confidentiality incident has occurred, take reasonable measures to reduce the risk of harm and to prevent further incidents of the same nature. If the incident presents a risk of serious harm, promptly notify the Commission d’accès à l’information and every individual concerned. Maintain a register of confidentiality incidents.
Determine the purposes of processing before collecting personal information.
Inform the individual at the time of collection, and thereafter on request: of the purposes and means of collection, of their rights of access and rectification, and of their right to withdraw consent to disclosure or use. Where applicable, also of the third party for whom the collection is made, the third parties or categories of third parties the information will be disclosed to, and any disclosure outside Quebec. On request: the information collected from them, the categories of persons with access to it within the business, the retention period, and the privacy officer's contact details. All in plain and clear language.
Where personal information is collected by technological means, publish on the company's website, if it has one, and circulate by any means suited to reaching the individuals concerned, a privacy policy drafted in clear and simple language; do the same for the notice required for any amendment to that policy.
Where collection uses technology that includes functions allowing the individual to be identified, located or profiled, inform them beforehand of the use of such technology and of the means available to activate those functions. This is in addition to the collection notice, not a replacement for it.
Where the company collects personal information by offering a technological product or service to the public that has privacy settings, ensure those settings provide the highest level of confidentiality by default, without any action by the individual concerned. The privacy settings of a connection cookie are not covered.
Obtain consent that is manifest, free and informed and given for specific purposes, requested for each of those purposes in clear and simple language and, where requested in writing, presented separately from any other information. Consent must be express where the information is sensitive, and is valid only for the time needed to achieve the purposes for which it was requested. Consent for a minor under 14 is given by the person having parental authority or by the tutor. Consent that is not given in accordance with the Act is without effect.
Law 25 names no record of processing activities. Documenting each activity is the strongest way to demonstrate the governance required by Art. 3.2.
Once the purposes are achieved, destroy the personal information or anonymize it in order to use it for serious and legitimate purposes, subject to any retention period provided by an Act. Information is anonymized only where it is reasonable to expect at all times that it irreversibly no longer allows the person to be identified, according to generally accepted best practices and the criteria set by regulation.
Entrust in writing any mandate or contract involving the communication of personal information, and set out in it the measures the mandatary must take to protect confidentiality, to use the information only in performing the mandate, and not to keep it after the mandate expires. The mandatary must notify the privacy officer without delay of any violation or attempted violation, and allow the officer to carry out any verification relating to that confidentiality.
Before communicating personal information outside Quebec, conduct a privacy impact assessment taking into account the sensitivity of the information, the purpose of its use, the protection measures it would be afforded — including contractual ones — and the legal framework of the receiving State. The communication may take place only if the assessment shows the information would receive adequate protection, and it must be the subject of a written agreement. The same applies where a person or body outside Quebec is entrusted with collecting, using, communicating or keeping such information on the business’s behalf.
Inform the individual that a decision is based exclusively on automated processing, no later than when the decision is communicated to them. On their request, inform them of the personal information used to make the decision, of the reasons and the principal factors and parameters that led to it, and of their right to have that information corrected. Give them the opportunity to submit observations to a member of staff who is in a position to review the decision.
On an individual's request, confirm the existence of the personal information held about them, communicate it to them and allow them to obtain a copy — as an intelligible written transcript if they ask, and with reasonable accommodation measures if they have a disability. The privacy officer must respond in writing promptly and no later than 30 days after receiving the request (Art. 32); failing that, the request is deemed to have been refused.
On request, correct personal information that is inaccurate, incomplete or ambiguous — or whose collection, communication or retention is not authorized by law.
On request, communicate to the individual, in a structured and commonly used technological format, the computerized personal information collected from them — excluding information created or inferred from information concerning them — unless doing so raises serious practical difficulties. That information is also communicated, on their request, to any person or body authorized by law to collect it.
Cease the dissemination of personal information or de-index the hyperlink leading to it where that dissemination contravenes the law or a court order. The individual may also require this — or require the hyperlink to be re-indexed — where the dissemination causes them serious injury to their reputation or privacy, that injury is clearly greater than the public interest in knowing the information or anyone’s interest in free expression, and the measure requested does not exceed what is necessary to prevent the injury from continuing. This conditional right is not a GDPR-style right to erasure.
Take the security measures apt to ensure the protection of personal information that is collected, used, communicated, kept or destroyed, and that are reasonable given, in particular, its sensitivity, the purpose of its use, its quantity, distribution and medium.
The person with the highest authority in the business exercises the function of privacy officer by operation of law; they may delegate it in writing, in whole or in part. Publish the officer's title and contact details on the company's website or, if it has none, make them available by any other appropriate means.
Written delegation where applicable, published title and contact details, log of the officer's decisions.
Establish and implement policies and practices governing personal information and apt to ensure its protection. They must provide, among other things, for the framework applicable to retention and destruction, the roles and responsibilities of staff throughout the information life cycle, and a process for handling complaints. They must be proportionate to the nature and scope of the business’s activities, and approved by the privacy officer.
Versioned governance framework, RACI assignments, traced approvals.
Conduct a privacy impact assessment for any project to acquire, develop or redesign an information system or electronic service delivery system that involves collecting, using, disclosing, keeping or destroying personal information. Consult the privacy officer from the outset of the project, and ensure the project allows computerized information collected from the individual to be communicated to them in a structured, commonly used technological format. The assessment must be proportionate to the sensitivity of the information, the purpose of its use, its quantity, distribution and medium.
PIA archived, timestamped, signed and linked to the corresponding processing activity.
Publish detailed information about those policies and practices, in clear and simple language, on the company's website or make it available by any other appropriate means — in particular about the content required by the first paragraph (framework for retention and destruction, staff roles, complaint handling).
Versioned, dated, approved and published policies.
As soon as there are grounds to believe a confidentiality incident has occurred, take reasonable measures to reduce the risk of harm and to prevent further incidents of the same nature. If the incident presents a risk of serious harm, promptly notify the Commission d’accès à l’information and every individual concerned. Maintain a register of confidentiality incidents.
Complete incident file, 5-year register, timestamped notifications.
Determine the purposes of processing before collecting personal information.
Purposes documented per activity in the register.
Inform the individual at the time of collection, and thereafter on request: of the purposes and means of collection, of their rights of access and rectification, and of their right to withdraw consent to disclosure or use. Where applicable, also of the third party for whom the collection is made, the third parties or categories of third parties the information will be disclosed to, and any disclosure outside Quebec. On request: the information collected from them, the categories of persons with access to it within the business, the retention period, and the privacy officer's contact details. All in plain and clear language.
Collection points carrying the notice mechanism and the transparency notice document shown to the individual.
Where personal information is collected by technological means, publish on the company's website, if it has one, and circulate by any means suited to reaching the individuals concerned, a privacy policy drafted in clear and simple language; do the same for the notice required for any amendment to that policy.
Versioned, dated privacy policy classified as public and circulated; amendment notice archived.
Where collection uses technology that includes functions allowing the individual to be identified, located or profiled, inform them beforehand of the use of such technology and of the means available to activate those functions. This is in addition to the collection notice, not a replacement for it.
Versioned prior notice attached to the processing activity, with the date the technology went live.
Where the company collects personal information by offering a technological product or service to the public that has privacy settings, ensure those settings provide the highest level of confidentiality by default, without any action by the individual concerned. The privacy settings of a connection cookie are not covered.
Dated capture of the default settings at go-live, and a review trace for each product version change.
Obtain consent that is manifest, free and informed and given for specific purposes, requested for each of those purposes in clear and simple language and, where requested in writing, presented separately from any other information. Consent must be express where the information is sensitive, and is valid only for the time needed to achieve the purposes for which it was requested. Consent for a minor under 14 is given by the person having parental authority or by the tutor. Consent that is not given in accordance with the Act is without effect.
Inventory of consent touchpoints, timestamped proof, withdrawal log.
Law 25 names no record of processing activities. Documenting each activity is the strongest way to demonstrate the governance required by Art. 3.2.
Versioned, timestamped register, exportable as a signed PDF.
Once the purposes are achieved, destroy the personal information or anonymize it in order to use it for serious and legitimate purposes, subject to any retention period provided by an Act. Information is anonymized only where it is reasonable to expect at all times that it irreversibly no longer allows the person to be identified, according to generally accepted best practices and the criteria set by regulation.
Retention period per activity, expiration alerts, destruction traces.
Entrust in writing any mandate or contract involving the communication of personal information, and set out in it the measures the mandatary must take to protect confidentiality, to use the information only in performing the mandate, and not to keep it after the mandate expires. The mandatary must notify the privacy officer without delay of any violation or attempted violation, and allow the officer to carry out any verification relating to that confidentiality.
Centralized DPAs, status tracked, direct link to the activities concerned.
Before communicating personal information outside Quebec, conduct a privacy impact assessment taking into account the sensitivity of the information, the purpose of its use, the protection measures it would be afforded — including contractual ones — and the legal framework of the receiving State. The communication may take place only if the assessment shows the information would receive adequate protection, and it must be the subject of a written agreement. The same applies where a person or body outside Quebec is entrusted with collecting, using, communicating or keeping such information on the business’s behalf.
Per-country assessment, documented protection mechanism, link to the DPA.
Inform the individual that a decision is based exclusively on automated processing, no later than when the decision is communicated to them. On their request, inform them of the personal information used to make the decision, of the reasons and the principal factors and parameters that led to it, and of their right to have that information corrected. Give them the opportunity to submit observations to a member of staff who is in a position to review the decision.
Register of decision systems, human oversight level, log of review requests.
On an individual's request, confirm the existence of the personal information held about them, communicate it to them and allow them to obtain a copy — as an intelligible written transcript if they ask, and with reasonable accommodation measures if they have a disability. The privacy officer must respond in writing promptly and no later than 30 days after receiving the request (Art. 32); failing that, the request is deemed to have been refused.
Timestamped DSAR file, acknowledgement, response, proof of delivery.
On request, correct personal information that is inaccurate, incomplete or ambiguous — or whose collection, communication or retention is not authorized by law.
Rectification file with before/after, propagation traces.
On request, communicate to the individual, in a structured and commonly used technological format, the computerized personal information collected from them — excluding information created or inferred from information concerning them — unless doing so raises serious practical difficulties. That information is also communicated, on their request, to any person or body authorized by law to collect it.
Portability export generated, timestamped and traced in the DSAR file.
Cease the dissemination of personal information or de-index the hyperlink leading to it where that dissemination contravenes the law or a court order. The individual may also require this — or require the hyperlink to be re-indexed — where the dissemination causes them serious injury to their reputation or privacy, that injury is clearly greater than the public interest in knowing the information or anyone’s interest in free expression, and the measure requested does not exceed what is necessary to prevent the injury from continuing. This conditional right is not a GDPR-style right to erasure.
De-indexation file with reasoned decision and action trace.
Take the security measures apt to ensure the protection of personal information that is collected, used, communicated, kept or destroyed, and that are reasonable given, in particular, its sensitivity, the purpose of its use, its quantity, distribution and medium.
Documented security controls, timestamped exportable audit trail.
Indicative list of the main obligations. The Act contains other provisions; Conformaze covers the associated modules. For the full text, consult LégisQuébec.
The free Conformaze assessment asks the right questions to map your current situation against Law 25 obligations — no commitment, in a few minutes. You get a category breakdown, identified gaps and a prioritized action plan.
Take your free assessmentA platform built article by article — so every Law 25 requirement has its module, its feature and its proof.