CapGRC
All solutions
Law 25

Quebec Law 25, from obligation to an operable privacy program

PIAs, confidentiality incident register, consents and access rights: CapPRP structures privacy day-to-day. CapCOM strengthens compliance and evidence.

What Law 25 requires

Law 25 imposes concrete obligations on Quebec organizations. CapGRC helps you organize, track and demonstrate them, without rebuilding the program in Excel.

01

Privacy Impact Assessments (PIA)

Conduct a PIA before any project involving personal information.

02

Privacy incident register

Document any privacy incident and notify the CAI if necessary.

03

Privacy policy

Publish a clear and accessible privacy policy.

04

Privacy officer

Designate a privacy officer and publish their contact information.

05

Data subject rights

Implement mechanisms to handle access, rectification and deletion requests.

06

Consent

Obtain free, informed and specific consent for the collection and use of personal information.

How CapGRC responds

RequirementCapGRC feature
PIACapPRP module, Guided PIA / DPIA (CapPROSEC for project engagement)
Incident registerCapPRP module, Confidentiality incident register
Privacy policyAuthoritative documents, Policy management and versioning
Data subject rightsCapPRP module, Data subject rights requests
ConsentCapPRP module, Documented consent management
Law 25 postureCapCOM module, Requirement assessment and evidence

Compliance timeline

September 2022

Officer designation, committee creation

September 2023

PIAs, incident register, new consent rules

September 2024

Right to portability, de-indexing, full enforcement

Recommended modules

Ready to ensure your Law 25 compliance?

Request a free consultation and discover how CapGRC can structure your compliance program.