CapGRC
CapGRC
All solutions
Law 25

Quebec Law 25 — CapGRC guides you from assessment to compliance

Structure your Law 25 program with dedicated tools: PIAs, incident register, privacy policy and data subject rights.

What Law 25 requires

Law 25 (An Act to modernize legislative provisions as regards the protection of personal information) imposes new obligations on Quebec organizations. CapGRC structures and automates your compliance.

01

Privacy Impact Assessments (PIA)

Conduct a PIA before any project involving personal information.

02

Privacy incident register

Document any privacy incident and notify the CAI if necessary.

03

Privacy policy

Publish a clear and accessible privacy policy.

04

Privacy officer

Designate a privacy officer and publish their contact information.

05

Data subject rights

Implement mechanisms to handle access, rectification and deletion requests.

06

Consent

Obtain free, informed and specific consent for the collection and use of personal information.

How CapGRC responds

RequirementCapGRC feature
PIAProject Security module — Integrated PIAs
Incident registerCompliance module — Incident register
Privacy policyAuthoritative Refs & Docs module — Policy management
Data subject rightsCompliance module — Request management
ConsentCompliance module — Consent tracking

Compliance timeline

September 2022

Officer designation, committee creation

September 2023

PIAs, incident register, new consent rules

September 2024

Right to portability, de-indexing, full enforcement

Recommended modules

Ready to ensure your Law 25 compliance?

Request a free consultation and discover how CapGRC can structure your compliance program.