Skip to content
Proudly made in Quebec

From consent to verifiable proof. The complete Law 25 platform.

Consent requested purpose by purpose, as article 14 requires, accountability registers, individual rights and independently verifiable proof. Built for both acts it modernized: P-39.1 private sector and A-2.1 public bodies, under the CAI's actual regime, not a foreign standard.

Agreely dashboard: Law 25 actions to handle by article, the consent-verification trend, and compliance posture, at a glance

Collecting consent is easy. Proving it is the hard part.

Quebec's Law 25 turned consent into an obligation you must defend. In practice, an organization must be able to show, after the fact, that consent was given for a specific (category, purpose), that it was honored while active, and that it stopped the moment it was withdrawn. A checkbox in a database cannot prove any of that.

01

Prove it on demand

A regulator or auditor can demand proof of valid consent for any (category, purpose) at any time. Logs you could have edited prove nothing.

02

The gap is structural

Consent lives as a boolean in an app database: easy to overwrite, impossible to prove untouched, and disconnected from the code that touches the data.

03

Revoke and erasure are binding

Withdrawal of consent has to take effect on the very next use, and Law 25's erasure duty (art. 23) has to actually destroy the readable claim, not just promise to.

04

A blanket yes is worthless

Law 25 requires consent asked for each purpose, presented distinctly from any other information. A single "I accept all" is without effect, and proving otherwise is on you.

05

The access right runs against the clock

An individual concerned can ask for access to their information, a copy, and its release in a structured, commonly used technological format. You have 30 days to answer, after which the request is deemed refused.

06

One incident, and you reconstruct everything

Faced with a confidentiality incident, you must assess the risk of serious injury, notify the Commission and the individuals concerned with diligence, and keep a register. Without a reliable record of who consented to what, scoping it is guesswork.

07

An obligation with a name on it

Law 25 places personal-information protection in the hands of a named person in charge, whose contact details are public. In practice, the enterprise must be able to demonstrate valid consent, notably under art. 14 (non-compliant consent is without effect) and art. 3.1 (accountability rests with the person in charge). Accountability is not a promise: it is a person who must answer, article in hand.

The full platform

Enter the Law 25 platform.

Agreely is the proof and accountability layer, not a new data store. Your information stays with you.

Quebec's Law 25 modernized two statutes
P-39.1 Private sector A-2.1 Public bodies

Agreely covers both regimes.

From collection to erasure, every step covered.

Agreely covers every step of an information's life cycle: disclosure at collection (art. 8), consent asked for each purpose (art. 14), proof on demand, withdrawal and erasure (art. 23), governance through the responsable and the register, then audit through a tamper-evident access log.

The whole life cycle

Every step documented

Every step leaves proof bound to the article it documents.

Consent documents

Versioned, signed documents carry the purposes, means, rights, and withdrawal.

Law 25 art. 8 / 14

Granular consent

Consent is asked for each purpose, separately.

Law 25 art. 14

Consent withdrawal

Withdrawal is honored on the very next check.

Law 25 art. 8 al. 1 (4)

Tamper-evident access log

Disclosures covered by art. 18 al. 2 are recorded; the log goes further, covering all accesses, anchored and verifiable.

Law 25 art. 18 al. 2 / 27

Crypto-shred erasure

Erasure destroys the key that makes the claim readable.

Law 25 art. 23

Accountability receipts

Signed receipts show, after the fact, who consented to what, when, and under which disclosure.

Law 25 art. 3.1

Proof and governance, beyond consent.

Agreely documents every step of Law 25, article in hand: a tamper-evident access log, versioned consent documents, attested offline consent, and a complete governance suite.

Named responsable, confidentiality-incident register, and privacy policy, in one suite. Proof, audit, and accountability; Agreely does not become a new store of your personal information.

Agreely's Compliance Center: named responsable (art. 3.1), policies, retention, out-of-Quebec transfers, incident register, and individual rights, in one suite.

From a question to a proof, in four moves.

Agreely turns a yes-or-no consent question into a signed, anchored proof anyone can check later. The synchronous check stays off-chain; the chain only ever carries the proof.

01

Declare the grid

Define the (category, purpose) cells your product needs consent for.

02

Issue a signed request

Ask the citizen for exactly those cells with a request your company key signs.

03

Approve with a passkey

The citizen consents on their own device, producing a signed receipt.

04

Anchor on-chain

The commitment is anchored so any alteration to the record becomes detectable.

One call.

Wrap any data use in a single check(). It resolves one (customer, category, purpose) to a synchronous allow or deny, reading a single indexed record. First-party SDKs for TypeScript and PHP, plus a CLI.

import { Agreely } from "@agreely/sdk";

const agreely = new Agreely({ apiKey: process.env.AGREELY_API_KEY! });

// One call. Fail-closed by default.
const ok = await agreely.check("cust_8812", "Phone number", "Billing");

Fail-closed by default

If Agreely cannot be reached, the answer is deny. A revoked, expired, erased, or never-granted cell is always false.

Agent-native CLI

One env var and --json gives pure JSON on stdout with stable exit codes that separate an outage from a denial.

Read the SDK docs

One synchronous read of a single indexed cell. Fail-closed with stable exit codes.

The key Law 25 obligations, and how Agreely equips you.

Show, don't ask to be trusted. Law 25 modernized two acts: P-39.1 (private sector) and A-2.1 (public bodies). Agreely is designed around both CAI regimes, article by article. Per-purpose consent (art. 14/53.1), tamper-evident registers: not a foreign consent tool retrofitted after the fact. Pick your sector: each obligation appears with the article that governs you.

Your sector

Act respecting the protection of personal information in the private sector (CQLR, c. P-39.1) Act respecting access to documents held by public bodies and the protection of personal information (CQLR, c. A-2.1)

See the article-by-article mapping (Law 25)

Consent

art. 14 art. 53.1
Obligation Manifest, free and informed consent, asked for each purpose.
Agreely (category, purpose) catalog with per-cell consent.
art. 8 art. 65
Obligation Mandatory disclosure list at collection, in plain and clear terms.
Agreely Versioned, signed consent documents.
art. 8 al. 1 (4°) art. 65 (5°)
Obligation Right to withdraw consent. Withdrawal of consent to the use or release of information provided under an optional request; the consequences are disclosed beforehand.
Agreely Withdrawal honored on the very next check.
art. 4.1 art. 64.1
Obligation Minor under 14: consent by the holder of parental authority.
Agreely Parental consent flow.
art. 8.1 art. 65.0.1
Obligation Technology that can identify, locate or profile a person: inform beforehand of its use and of the means offered to activate those functions.
Agreely Catalog profiling flag, prior disclosure carried into documents and the policy.
art. 12 al. 2 art. 65.1
Obligation Use for another purpose without consent in five cases only; a compatible purpose requires a relevant and direct link and excludes prospecting. Use for another purpose without consent in four cases only; a compatible purpose requires a relevant and direct link; the first three cases are entered in the article 67.3 register.
Agreely Secondary-use register: invoked exception, original purpose and justification attested.
art. 12.1 art. 65.2
Obligation Decision based exclusively on automated processing: disclosure and observations.
Agreely Automated-decision notice and tracking log (art. 12.1).

Rights of the individual concerned

art. 27 art. 83
Obligation Right of access: confirm holding and hand over a copy.
Agreely Access export on request.
art. 27 al. 3 art. 84 al. 3
Obligation Delivery in a structured, commonly used technological format.
Agreely Structured export of information collected from the person.
art. 32 art. 98
Obligation Respond to the access request within 30 days; silence counts as a deemed refusal. Respond with diligence within 20 days; a single 10-day extension, with written notice before the deadline.
Agreely Rights clock: each request's deadline is computed for the applicable regime.
art. 23 art. 73
Obligation Destruction or anonymization once the purposes are accomplished.
Agreely Crypto-shred erasure and a destruction schedule.
art. 11 al. 2 P-39.1 only
Obligation Information used for a decision kept at least one year.
Agreely Retention floor applied to the schedule.

Accountability and logging

art. 3.1 art. 52.2 / 8
Obligation Person in charge of personal information protection.
Agreely Named responsable, published contact, signed receipts.
art. 18 al. 2 art. 67.3
Obligation Record certain disclosures to a third party.
Agreely Tamper-evident access log, anchored, citizen unlinkable.
art. 18.3 art. 67.2
Obligation Disclosure without consent to a mandatary or service provider: the mandate given in writing, stating the required protective measures.
Agreely Mandatary register: written contract and required clauses attested, gaps flagged.
art. 3.2 / 8.2 art. 63.3 / 63.4
Obligation Governance policies and a public privacy policy.
Agreely Governance suite and a published policy.

Governance and risk

art. 10 art. 63.1
Obligation Reasonable security measures given sensitivity, purpose, quantity, distribution and medium, from collection through destruction.
Agreely Declarative register of security measures, covering sensitive information and destruction.
art. 3.5-3.8 art. 63.8-63.11
Obligation Measures, notification, and a confidentiality-incident register.
Agreely Confidentiality-incident register.
art. 17 art. 70.1
Obligation Communication outside Quebec and a privacy impact assessment.
Agreely Transfer register and privacy impact assessment (EFVP).
art. 17 al. 2-3 art. 70.1
Obligation Outside Quebec: adequate protection shown by the assessment and a written agreement, including for a mandate or contract entrusted outside.
Agreely Written-agreement block and linked assessment on every recorded transfer or mandate.

Citations verified against the official texts of the two acts modernized by Law 25: the Act respecting the protection of personal information in the private sector (P-39.1) and the Act respecting access to documents held by public bodies and the protection of personal information (A-2.1). The two acts sometimes reuse the same article numbers for different obligations; the mapping shown here is built obligation by obligation, never by substituting numbers, and obligations with no direct equivalent in the other act are marked as such. For information only, not legal advice.

Built on the statute, not translated to it.

OneTrust, Transcend, Didomi, Osano, Ethyca: strong GDPR-first suites. None is built on Quebec's two statutes, and none hands over proof a third party can verify without trusting the vendor.

Criterion Agreely The GDPR-first suites OneTrust · Transcend · Didomi · Osano · Ethyca
Independently verifiable proof Yes · Anchored on Base, public verifier No · Private audit logs, verifiable only with the vendor
Both Quebec regimes, private and public Yes · P-39.1 and A-2.1, by sector No · GDPR first, Law 25 as a simple mapping
Article-by-article depth Yes · Every capability cites its article Partial · Templates and add-on modules
French first Yes · Quebec French by design Partial · Translated interface, admin defaults to English
Data residency Yes · Hosted in Canada Partial · US or European cloud by default

A general characterization of the GDPR-first suites (OneTrust, Transcend, Didomi, Osano, Ethyca), based on their usual public characteristics, to the best of our knowledge and as of August 2026. Every product evolves: always check up-to-date spec sheets. And a reminder: our proof covers the integrity of recorded decisions, never your compliance itself.

Simple plans, banner priced on its own.

Four tiers in Canadian dollars, billed annually. Every plan covers the Law 25 core: on-chain anchoring, verifiable receipts and your data hosted in Canada. You move up by active records and seats, never by traffic. The cookie banner is a capability of the same platform, billed separately.

Priced on your accountability surface, not your traffic. You are billed on active consent records and seats, never on how often you verify. Check as often as you need.

Starter

$99 CAD / mo
billed annually
  • Active consent records 2,500
  • Consent requests / mo 1,000
  • Cookie banner Capability available, billed separately
  • API keys 2
  • Custom domain No
  • Seats 3
  • Support Email
Get started (new tab)

Business

$999 CAD / mo
billed annually
  • Active consent records 150,000
  • Consent requests / mo Unlimited
  • Cookie banner Capability available, billed separately
  • API keys Unlimited
  • Custom domain Yes
  • Seats Unlimited
  • Support Priority + target uptime
Get started (new tab)

Enterprise

Custom

For high volumes and contractual requirements. Dedicated stack and a negotiable SLA.

  • Active consent recordsCustom
  • Cookie bannerCapability available, billed separately
  • IsolationDedicated database and stack
  • SeatsUnlimited
  • SupportCustom contract (negotiable SLA)
Contact us
Annual billing, in Canadian dollars, shown as a monthly equivalent. You move up by active records and seats. The cookie banner is a capability of the same platform, billed separately: free on one site in Agreely's branding (5,000 loads per month), then $15 per month per site in your own brand (100,000 loads per month per site). A plan does not unlock banner sites.

The cost of a monthly subscription, against sanctions that can reach $25 M or 4% of worldwide turnover.

For citizens

Your consent, on your device.

Agreely's citizen app hands you every consent as a signed receipt, kept on your own device. See what you agreed to, withdraw it whenever you want, and check that a receipt is genuine yourself. No passwords.

  • Your receipt goes with you

    Every consent becomes a cryptographic receipt kept on your device. The app installs to your home screen like any app.

  • Withdraw with a tap

    Withdraw a consent with your passkey (Face ID or Touch ID). The withdrawal is honored from the very next check.

  • Verify it yourself

    Confirm a receipt is authentic and untampered, without having to trust Agreely or anyone else.

  • No passwords, pseudonymous

    Your identity is a passkey tied to an opaque identifier. Nothing in Agreely allows correlating you from one company to another.

Learn more

The citizen app lives at my.agreely.ca and installs to your home screen like an app (PWA).

The Agreely citizen app on a phone: the consent review screen, where each purpose is shown separately and approved with a passkey.

Proof that does not ask you to trust Agreely.

Every grant produces artifacts an auditor can recompute and check on their own. The cryptography, not the company, is what makes the record stand up.

Proof you can check, not proof you have to take on trust.

What anyone can confirm
  • The commitment recomputes identically, byte for byte
  • The DID signature over the epoch root verifies offline
  • The anchor can be checked on the public Base chain
consent receipt · cookies anchored · Base verified here partly verified
Analytics granted
Functional granted
Marketing granted
identifier
a4ff4c25…d38a0667
timestamped (UTC)
2026-08-10 13:48:55
commitment
0xd0ae…33e6
epoch root · 0x0084…359a anchored · Base
A real production receipt from the Cookies module, anchored on the public Base chain. Verify it right here.
Verification · in your browser No call to Agreely: the artifacts are below and the math is redone locally, on this page.
  1. to verify computing confirmed mismatch found

    Recompute the commitment

    commitment = keccak256( JCS(claim) || salt )

    The bound claim and the revealed salt are enough to redo the hash and compare it.

    expected
    0xd0ae…33e6
    recomputed
    pending
  2. to verify computing confirmed mismatch found

    Fold the Merkle root

    row hash, then fold up to the root

    The row hash recomputes, then folds along the inclusion path up to the epoch root.

    expected
    0x0084…359a
    recomputed
    pending
  3. to verify computing confirmed check it yourself mismatch found

    Verify the DID signature

    Ed25519 · did:web:agreely.ca:c:agreely-demo

    The company's registered public key verifies the signature placed over the epoch root.

    public key
    0x3b61…e4f4
    recomputed
    pending
  4. to verify published

    Check the public anchor

    Base · 2026-08-10 14:10 UTC

    The epoch root is anchored on the public Base chain. The transaction can be checked without asking our permission.

    chain
    Base · 8453

On-chain anchoring

Consent roots, revocations, and identity commitments are anchored so the record cannot be quietly rewritten. The chain is proof, never the read path; the check never touches it.

Independently verifiable receipts

Each grant is a signed receipt built from published standards. Anyone with the artifacts can recompute and verify it offline, without trusting Agreely.

Crypto-shred erasure

Law 25's erasure duty (art. 23) is a real destruction, not a promise. Erasing a cell destroys the secret that makes its claim readable, while the surviving cells still verify.

Company and citizen unlinkability

The citizen identity is opaque and tenant-less, and never carries a company's customer reference. Agreely cannot re-identify a person across the companies they consent to.

Hand your auditor a view, not a binder.

Mint a read-only consultation link, time-boxed and revocable at any time. Your auditor opens it without an account and walks the whole accountability dossier: the article-by-article coverage index, then each of the registers.

Law 25 · s. 3.1 · Accountability

The dossier evidences what the enterprise declared in Agreely and the anchored proofs attached to it. Agreely documents the accountability set out in section 3.1; it does not certify and does not guarantee compliance.

No account for the auditor

One link is enough. The auditor opens it in a browser and reads the dossier immediately, no signup, no password.

Time-boxed and revocable

You choose when the link expires and you can revoke it at any moment; access ends right away.

Every obligation tied to its article

The coverage index lines up article, obligation, status and evidence, then opens onto the dossier's twenty or so registers: officer, catalog, retention, security, incidents, rights, access log, cookies, transfers and more.

No personal information exposed

Data subjects appear only as opaque reference codes, such as POL-2026-0027, never by name or email. Only governance contacts, including the privacy officer, are shown.

Auditor view of the accountability dossier: read-only access banner with expiry date, privacy officer, article-by-article coverage index with statuses and evidence, and navigation to the registers
The auditor's view as is: the read-only access banner with its expiry, the designated officer (s. 3.1), then the article-by-article coverage index. Each "View" row opens the matching register.

Talk to us.

A 30-minute demo, in English or French: your Law 25 context, the platform live, and straight answers to your questions.

Book a demo

Pick a 30-minute video call slot. We look at your context, then walk the platform live: consents, registers, banner and proofs.

30 minutes · video call · EN or FR

Email us

A specific question, an RFP, a partnership? Write to us: we reply in English or French, usually within one business day.

Ophelios Studio

Agreely is designed and built in Quebec by Ophelios Studio, an independent studio. You talk directly to the team building the product.

ophelios.com

Quebec's Law 25, in plain terms.

The questions we hear most about Quebec's Law 25, consent proof, and where Agreely fits.

What is Quebec's Law 25?

Law 25 is the common name for Quebec's overhaul of personal-information protection ; in the private sector it amends the P-39.1 act (Act respecting the protection of personal information in the private sector). Phased in between 2022 and 2024, it requires valid consent, stronger rights for the individual concerned, and documented accountability. Any person carrying on an enterprise that collects personal information in Quebec is subject to it.

Does consent have to be asked for each purpose?

Yes. Article 14 requires manifest, free and informed consent, given for specific purposes and “asked for each of those purposes”. A single “accept all” box that bundles several uses is non-compliant: consent not asked separately for each purpose is without effect. When the request is made in writing, it must also be presented distinctly from any other information given to the individual concerned.

What is consent proof, and does Law 25 require one?

In practice, it is for the enterprise to demonstrate valid consent: non-compliant consent is without effect (art. 14) and the enterprise is accountable for the information it holds (art. 3.1). Collecting consent is easy, but being able to demonstrate it after the fact is what counts. A checkbox in a database you could have edited proves neither when consent was given, nor for which purpose, nor that it was honored until withdrawal. Consent proof is a verifiable record, bound to the specific purpose (art. 8 and 14), that a regulator or auditor can check on demand.

What must you disclose when you collect personal information?

Article 8 requires that, at collection and in plain and clear terms, you inform the individual concerned of the purposes, the means used, their rights of access and rectification, and their right to withdraw consent. Where applicable, you must also name the third party on whose behalf collection is made, the categories of recipients, and the possibility of a communication outside Quebec. On request, you add the categories of persons with internal access, the retention period, and the contact details of the person in charge of personal-information protection.

What rights does an individual have under Law 25?

The individual concerned can ask for access to their information and a copy (art. 27), ask to rectify inaccurate information (art. 28), and withdraw consent at any time (art. 8, para. 4). Computerized information collected from them must, on request, be released in a structured, commonly used technological format (art. 27, al. 3). The person in charge must answer in writing, with diligence and within 30 days at the latest ; failing that, the request is deemed refused (art. 32).

Does Law 25 require a privacy officer?

Yes. Article 3.1 places personal-information protection in the hands of a person in charge ; by default this is the person with the highest authority in the enterprise, who may delegate the function in writing. That person's title and contact details must be published, notably on the enterprise's website. The named person answers access requests and carries accountability, article in hand (the statutory term is “responsable de la protection des renseignements personnels”, not “DPO”).

Is there a right to erasure in Quebec, and what does it mean?

Once the purposes of collection are accomplished, article 23 requires the enterprise to destroy the personal information or anonymize it according to best practices, subject to any retention period set by law. In Quebec, “anonymized” sets a strict bar: the process must be irreversible, which is distinct from mere de-identification. Cessation of dissemination and de-indexing (art. 28.1) cover what the public often calls the “right to be forgotten”, but that is not the statutory term.

How does Agreely help with Law 25 compliance?

Agreely is the proof and accountability layer: it asks consent for each purpose, produces a signed, verifiable receipt, and honors withdrawal and erasure on the very next check. Your information stays with you ; Agreely does not become a new store of your personal information, it helps document and demonstrate consent on demand and keeps a tamper-evident access log. Agreely does not on its own guarantee your compliance: it tools specific obligations (art. 8, 14, 23, 27, 3.1), while your policies, deadlines, and internal practices remain yours and your legal counsel's.

Is a banner enough to be compliant with Law 25 in Quebec?

No, and be wary of anyone who promises that. Compliance depends on your purposes, your practices and your documentation. Agreely helps you document and demonstrate your compliance: the cookie inventory, the decision log, the integrity proofs. The responsibility itself remains yours, and the Commission d'accès à l'information (CAI) is the body that oversees Law 25 in Quebec.

What ends up on the public chain?

No personal information. The chain only receives opaque digital fingerprints (32-byte digests) and the company's public references, like a wax seal. They prove the recorded decisions were not changed after the fact; they cannot be traced back to your visitors.

Why does this site show no cookie banner?

This site deposits zero non-essential cookies before your consent: there is nothing to consent to, and no banner is required. A consent banner is needed when a site deposits non-essential cookies or trackers on your device without your prior choice. Audience on this site is measured by a self-hosted tool that sets no cookie, stores nothing on your device and builds no advertising profile, and it never follows you from one site to another; it is described in our privacy policy, where you can also turn it off. If you want to see what your own site deposits before consent, our scan tool is available on this page (jump to the #scan section).

For information only, not legal advice.

Consent you can prove

Make consent accountable.

Start with the one-call mental model, then read the protocol that makes every grant verifiable, revocable, and anchored.

View the protocol