FR EN

Compliance

The compliance hub gathers your Law 25 obligations into distinct pages, each with its own route. Every page carries a clear notice: this is a guide, not legal advice. Agreely gives you the tools to keep and demonstrate your compliance; it does not stand in for the judgment of a legal advisor.

Two regimes, one hub

Agreely covers both acts Law 25 amended: P-39.1 (the private-sector act) and A-2.1 (the public-bodies access act), according to the sector your organization declares. Article citations, vocabulary and the registers on offer change accordingly: the two acts reuse the same article numbers for different things, so a citation is resolved per regime and never obtained by substituting a number from one act into the other. A public body sees its access and protection committee and its article 67.3 register; a private enterprise sees its secondary-use register. Health law (R-22.1, "Loi 5") is out of scope for Agreely.

Guide, not legal advice

Every section of this hub is an implementation tool. The content you enter, and how you apply it, are your responsibility. Agreely gives no legal advice and certifies no compliance.

Privacy officer, article 3.1

Declare the person responsible for the protection of personal information: their name, their title, and at least one way to reach them, either an email or a phone number. This is the person Law 25 charges with overseeing the protection of personal information within the company.

Policies

Publish and version your policies:

  • the personal-information governance policy, article 3.2;
  • the privacy policy, article 8.2.

Each policy carries a bilingual title and body. On publication, a policy is versioned and immutable: a published version is never edited, a new one is published instead. The history stays a faithful record of what was in force on each date.

The statutory registers

Each register has its own page, its per-entry record and its export. Writes are restricted to the owner and the admin, and a write carries the signature of the person who made it: in a register, the write is the declaration.

Register What it keeps
Retention and destruction Your retention rules: a label, a period in months, a trigger (by default the purpose being achieved), an action (by default destruction) and notes, with the one-year floor on data used to make a decision.
Security measures The measures you have put in place, in your words: Agreely prefills nothing here, because the obligation is about your own systems.
Anonymization The anonymization processes and their re-evaluation.
Cross-border communications and PIAs Communications of personal information outside Quebec and the privacy impact assessments that go with them: a title, the sensitivity, the purpose, the protection measures, the legal regime of the destination, and a conclusion.
Project PIAs The assessment of a project to acquire, develop or overhaul a system. A late consultation is surfaced, never blocked.
Processors and mandataries The third parties you entrust with personal information, and the agreement governing each.
Secondary uses (private enterprise) Uses without consent, with the ground relied on.
Confidentiality incidents The discovery date and the occurrence date, a description, the categories involved, the number of people affected, the risk assessment with its risk of serious injury flag, the measures taken, notice to the Commission d'accès à l'information, notice to the people concerned, and the status. An incident is archived, never deleted.
Rights requests The full workflow, with the statutory 30-day clock and an overdue counter.
Erasure obligations The concrete obligation born of an erasure, and your disposition attestation.
Minors The handling of a minor's information and your process attestation.

The retention register is declarative

Agreely does not hold the underlying information. A retention rule is therefore a declared policy, never a per-record destruction date computed for you. You document the rule; execution stays in your systems.

Confidentiality incident register, articles 3.5 to 3.8

Keep the confidentiality incident register. Each entry records:

  • the date the incident was discovered and the date it occurred;
  • a description;
  • the categories of information involved;
  • the number of persons affected;
  • a risk assessment, with a serious-risk-of-injury flag;
  • the measures taken;
  • whether the Commission d'accès à l'information was notified, and whether the affected persons were;
  • the incident status.

The register supports the obligation to keep, and where required demonstrate, the handling of confidentiality incidents.

Rights requests

Handle requests from data subjects in a workflow: received → in progress → responded or refused. Each request carries the article 32 30-day clock, and an overdue count highlights the ones past their deadline.

The request types covered are:

  • access, article 27;
  • rectification, article 28;
  • de-indexing, article 28.1.

Requests and their handling export in JSON or CSV.

Erasure obligations, article 23

When a citizen exercises erasure, your company receives an actionable erasure obligation: destroy or anonymize the underlying data you still hold in your own systems. You attest a disposition from among:

  • destroyed;
  • anonymized;
  • retained under a legal period.

You attach a note to the attestation.

Attesting is not proof of compliance

Agreely proves the consent ended and signals the obligation to act. You, the company, attest that you acted. That attestation is your statement, not cryptographic proof that the data was in fact destroyed or anonymized in your systems. And an erasure obligation is not a confidentiality incident and is not handled as one.

What stays, and what you can delete

One rule runs through the whole hub: a statement you made stays; a working document you produced is yours to remove.

Kept on the record, permanently:

  • your attestations (security measures, retention schedule, the process applied to minors, legal review), together with the date each one stopped covering anything;
  • your disposition attestation on an erasure obligation;
  • the destruction runs recorded in the retention journal;
  • every published policy, and an incident entered in the register, which is archived;
  • the attestation delivered to a person following a rights request, frozen at the moment it was delivered.

Deletable, with no justification owed:

  • a cross-border PIA: that is your own analysis;
  • an anonymization process and its re-evaluations;
  • a policy draft, for as long as it stays unpublished.

Why the difference. An attestation is a statement about what happened; a PIA is a document you wrote. If an attestation could disappear, the ones that disappeared would be exactly the ones that turned out to be wrong, and the register would then prove nothing to anyone. No provision of either act requires these attestations. You make them because they demonstrate your accountability, and it is precisely because they cannot be quietly withdrawn that they carry weight with an auditor or with the Commission.

Correct it, do not erase it. An attestation that has become inaccurate is not deleted: you record a new one, and the previous one is marked as superseded, at its date. The record then shows the correction, which serves you better than a hole in the history. It is the same reason a published policy is never edited: a new version is published instead. A draft stays a draft, and a draft can be thrown away.

Permanent does not mean certified

An attestation being permanent says nothing about whether it is accurate: it only guarantees that its date, its author and its content will not change after the fact. Agreely documents and demonstrates; it does not inspect your systems and it certifies no compliance.

The access log and the accountability dossier

Two surfaces turn this hub into proof rather than mere documentation:

  • The access log, the hash-chained register whose epochs are anchored on-chain, exportable and re-verifiable offline;
  • the accountability dossier, the single evidence file, opening on an article-by-article coverage index, that an auditor can take away. It downloads from the hub, and from auditor access.

Compliance guide

The compliance guide is a static, article-by-article map of how Agreely helps address each relevant Law 25 article. It carries the same notice as the rest of the hub: it is a guide, not legal advice.

Next