Know your information.
Organize categories and purposes. Identify sensitive information and uses involving automated decisions.
P-39.1 · art. 14, 12.1A-2.1 · art. 53.1, 65.2
Your practices become policies. Your policies get a public home. Requests reach the right place. Your Law 25 work, together in one workspace.
30-day trial, no card, no commitment. One trial per business.
The information you collect, the policies you publish and the requests you receive. Follow the same thread from everyday work to your accountability dossier.
A catalog of information and purposes that informs policies for each product and your whole organization.
02Publish policies on your public page and record the methods you used to distribute them.
03Rights requests, incidents and registers share the same workspace as your policies.
Categories, purposes and retention periods: describe your information and connect it to your products or services. This foundation informs policies that reflect your activities.
Generate an organization-wide or product-specific privacy policy from your catalog. Review the text, then publish a version you can refer back to.
Agreely hosts your policies at a public address. Link to it from your website, then record the channels and distribution methods you used.
Your public page’s form routes rights requests to Agreely. Once the email is confirmed, requests enter your register for your team to track and handle.
When a purpose requires consent, send a dedicated request. The person reviews the purposes on their device and confirms their choice with a passkey. Their decision produces a signed receipt they can return to.
From the first information collected to your auditor’s dossier. Find tools for every step in one workspace.
Organize categories and purposes. Identify sensitive information and uses involving automated decisions.
P-39.1 · art. 14, 12.1Generate organization-wide or product-specific privacy policies from your catalog. Review, publish and retain each version.
P-39.1 · art. 8.2Your public page’s form feeds the register after email confirmation. Track requests and their deadlines.
P-39.1 · art. 27, 32Identify your privacy officer and publish governance and privacy policies, with their history.
P-39.1 · art. 3.1, 3.2, 8.2Record the facts, risk assessment, actions taken and notices in one register.
P-39.1 · art. 3.5 to 3.8Associate categories with retention rules and document destruction obligations and attestations.
P-39.1 · art. 23Document project and cross-border privacy assessments, chosen safeguards and your conclusions.
P-39.1 · art. 3.3, 3.4, 17Maintain provider and secondary-use registers, together with the agreements and reasons supporting them.
P-39.1 · art. 18.3, 12Collect separate decisions, with dedicated handling for parental and express consent.
P-39.1 · art. 14, 4.1Your systems can check consent before using information. A withdrawal takes effect at the next check.
P-39.1 · art. 8, 14With Témoins, block non-essential trackers before consent and retain evidence of each decision. Billed separately.
P-39.1 · art. 8.1, 14Review the access log, export your dossier and give your auditor temporary access.
P-39.1 · art. 3.1Law firms and advisory teams: move between businesses and public bodies with the same Agreely account.
For firms and advisorsAPI, TypeScript and PHP SDKs, CLI: connect your Agreely workflows to your ERP or internal tools.
Explore integrationsA real access-log event, drawn from the demo tenant Assurance Boreale and anchored on the public Base chain. The math is redone right here, in your browser, from the artifacts alone.
The company's registered DID key, hosted by Agreely, verifies the signature placed over the epoch root. Defense in depth, not non-repudiation.
0x5b0cd3ecafd1850fc2dd12c548ca140095636032339c0dd86f6be0fc3da5fbfa
pending
The math was redone right here, in your browser, from the artifacts alone. This receipt would still verify even if Agreely disappeared.
This demonstrates the integrity and traceability of the access event, recorded and unaltered in the tenant's log. It is never proof of compliance.
The math was redone right here, in your browser, from the artifacts alone. This receipt would still verify even if Agreely disappeared.
Your browser does not verify Ed25519 signatures: check the signature on the full verifier.
This demonstrates the integrity and traceability of the access event, recorded and unaltered in the tenant's log. It is never proof of compliance.
This is exactly what verification would reveal if the record had been altered after the fact.
The receipt could not be loaded here. Verify it directly on the full verifier:
compute, your browser 0 ms
For uses that require it, a dedicated flow lets people decide on their own device. They can then find their choices, withdraw them and view their receipt in their citizen space.
Every consent is signed and verified with the passkey on your device, in an app on your home screen.
A withdrawal, by passkey (Face ID or Touch ID), is honored from the very next check.
Confirm a receipt is authentic and untampered, without having to trust Agreely or anyone else.
Your registers tell the story of what you have done. Agreely brings them together in a view your auditor can review, article by article.
Consent, requests, incidents and retention. Find the registers and documented information from your workspace.
Explore the obligations
Connect your ERP, CRM or internal tools to Agreely. Check access, create a consent request or report the end of a customer relationship from your own workflows.
One example: ending a customer relationship
The customer relationship ends.
An API call records the end and its reason.
That date anchors the retention periods you have defined.
Deadlines are calculated from your applicable rules. Data destruction remains under your control.
Support several businesses or public bodies with their Law 25 work. Switch organizations with your Agreely account to find each client’s policies, requests and registers.
Let’s talk about your firmLaw 25 modernized two acts: P-39.1 for the private sector, A-2.1 for public bodies. Pick your sector: each obligation appears with the section that governs you.
Citations now shown for the private sector (P-39.1). Citations now shown for the public sector (A-2.1).
Act respecting the protection of personal information in the private sector (CQLR, c. P-39.1) Act respecting access to documents held by public bodies and the protection of personal information (CQLR, c. A-2.1)
(category, purpose) catalog with per-cell consent.
Versioned, signed consent documents.
Withdrawal honored on the very next check.
Parental consent flow.
Catalog profiling flag, prior disclosure carried into documents and the policy.
Secondary-use register: invoked exception, original purpose and justification attested.
Automated-decision flag in the catalog, its disclosure carried into your documents, and the review request as a rights type.
Access export on request.
Structured export, in JSON or CSV, of the consent records held for the person.
Rights clock: each request's deadline is computed for the applicable regime.
Crypto-shred erasure and a destruction schedule.
Retention floor applied to the schedule.
Named responsable, published contact, signed receipts.
Register of communications without consent (ground relied on, recipient, categories), plus the anchored access log for every consent decision.
Mandatary register: written contract and required clauses attested, gaps flagged.
Governance suite and a published policy.
Declarative register of security measures, covering sensitive information and destruction.
Confidentiality-incident register.
Transfer register and privacy impact assessment (EFVP).
Written-agreement block and linked assessment on every recorded transfer or mandate.
Citations verified against the official texts of the two acts modernized by Law 25: the Act respecting the protection of personal information in the private sector (P-39.1) and the Act respecting access to documents held by public bodies and the protection of personal information (A-2.1). The two acts sometimes reuse the same article numbers for different obligations; the mapping shown here is built obligation by obligation, never by substituting numbers, and obligations with no direct equivalent in the other act are marked as such. For information only, not legal advice.
Global suites serve many markets. Agreely brings Québec’s requirements and everyday tools together. Here are a few practical points to compare.
| Your needs | Agreely | Elsewhere in the market Documented examples by vendor |
|---|---|---|
| Law 25 guidance | P-39.1 and A-2.1, with article references for your sector’s obligations. | OneTrustAssessments, data mapping and rights workflows supporting Law 25. |
| Rights requests | A form on your public page. After email confirmation, requests enter your register. | TranscendA self-service Privacy Center for exercising data rights. |
| Consent integrity | Receipts anchored on Base, with integrity checks through a public verifier. | OsanoEncrypted, immutable cookie-consent records accessible within Osano. |
| Data residency | Data at rest hosted in Canada. | OneTrustCanada is among the available hosting regions. |
Official sources reviewed September 21, 2026. Each example refers only to the named vendor and capability, depending on modules and plans.
Plans based on clients in your register, published products or services, and your team. Prices in Canadian dollars, billed annually. A thirty-day trial, no card or commitment.
$99/ mo
CAD, billed annually
$349/ mo
CAD, billed annually
$999/ mo
CAD, billed annually
For information only, not legal advice. Articles cited here are those of P-39.1 (private sector).
Yes. Art. 14 requires clear, free and informed consent, given for specific purposes and “requested for each such purpose”. Bundled consent, not requested separately for each purpose, is without effect (art. 14). An “accept all” button placed after each purpose has been presented separately is a convenience, not a shortcut. When the request is made in writing, it must also be presented distinctly from any other information given to the individual concerned.
In practice, it is for the enterprise to demonstrate valid consent: non-compliant consent is without effect (art. 14) and the enterprise is accountable for the information it holds (art. 3.1). Collecting consent is easy, but being able to demonstrate it after the fact is what counts. A checkbox in a database you could have edited proves neither when consent was given, nor for which purpose, nor that it was honored until withdrawal. Consent proof is a verifiable record, bound to the specific purpose (art. 8 and 14), that a regulator or auditor can check on demand.
Art. 8 requires that, at collection and in clear and simple language, you inform the individual concerned of the purposes, the means used, their rights of access and rectification, and their right to withdraw consent. Where applicable, you must also name the third party on whose behalf collection is made, the categories of recipients, and the possibility of a communication outside Quebec. On request, you add the categories of persons with internal access, the retention period, and the contact details of the person in charge of the protection of personal information.
The individual concerned can ask for access to their information and a copy (art. 27), ask to rectify inaccurate information (art. 28), and withdraw consent at any time (art. 8 al. 1 (4)). Computerized information collected from them must, on request, be released in a structured, commonly used technological format (art. 27 al. 3). The person in charge must answer in writing, with diligence and within 30 days at the latest; failing that, the request is deemed refused (art. 32).
Yes. Article 3.1 places personal-information protection in the hands of a person in charge ; by default this is the person with the highest authority in the enterprise, who may delegate the function in writing. That person's title and contact details must be published, notably on the enterprise's website. The named person answers access requests and carries accountability, article in hand (the statutory term is “responsable de la protection des renseignements personnels”, not “DPO”).
Once the purposes of collection are accomplished, art. 23 requires the enterprise to destroy the personal information or anonymize it according to best practices, subject to any retention period set by law. In Quebec, “anonymized” sets a strict bar: the process must be irreversible, which is distinct from mere de-identification. Cessation of dissemination and de-indexing (art. 28.1) cover what the public often calls the “right to be forgotten”, but that is not the statutory term.
Thirty minutes to see if Agreely fits, or write to us directly. Agreely is built by Ophelios Studio. No form, no queue.