Sentrix

Framework · Law 25

Law 25: PIAs, incidents, access and portability, documented

Québec's private-sector privacy law, in full force since September 2023: privacy impact assessments, confidentiality incidents, access rights and portability.

Law 25, the Act to modernize legislative provisions as regards the protection of personal information, introduced the most significant overhaul of provincial privacy legislation in Canada in decades. It has been in full force since September 2023 and the Commission d'accès à l'information (CAI) has issued its first enforcement actions. It applies to enterprises collecting personal information in Québec, and its obligations differ meaningfully from federal PIPEDA obligations.

Key facts

  • September 2023: full enforcement; all obligations, including PIAs, incident notification and portability, apply.
  • 30 days: response deadline for access and rectification requests.
  • PIA: privacy impact assessment required before any project involving personal information and before any communication outside Québec.
  • CAI: notification of confidentiality incidents presenting a risk of serious injury, with diligence, and an incident register.

What Law 25 requires

Law 25 introduced some of the most stringent privacy obligations in Canada.

  1. Designation of a person in charge of the protection of personal information, whose title and contact information are published
  2. Privacy impact assessment before any project involving personal information and before any communication outside Québec
  3. Consent: collection, use and withdrawal documented; privacy by default and collection limited to what is necessary
  4. Confidentiality incidents: notification to the CAI and affected individuals where there is a risk of serious injury, incident register
  5. Individual rights: access and rectification within 30 days, withdrawal of consent, cessation of dissemination
  6. Portability: computerized personal information collected from the individual, communicated in a structured technological format

What Sentrix provides for Law 25

Privacy impact assessment (PIA)

Sentrix provides bilingual PIA templates aligned with CAI guidance, routes assessments to the appropriate reviewers, captures sign-off, tracks remediation of identified risks and retains every assessment as audit evidence. An alert fires when a new project triggers a PIA.

Confidentiality incident response

CAI notification workflow, affected person letter templates in French and English, incident register maintained automatically and documentation stored in the format the CAI expects. Built-in severity scoring evaluates each incident against the criteria of the Act.

Data subject request management

Access, rectification, and portability requests tracked with a 30-day response deadline. Request log maintained as evidence, reminders before deadlines, response documentation archived.

Privacy by default

Sentrix monitors your data collection practices, flags integrations that collect unnecessary personal information, and documents your privacy-by-default settings.

Bilingual documentation

All PIAs, policies, incident notices and audit packages are available in French and English, as required for Québec organizations and public bodies governed by the Act.

Accountability to the CAI

The CAI has broad powers to investigate, audit, and sanction. Sentrix provides the evidence repository, audit trails, and dashboards the person in charge needs to demonstrate accountability on demand.

Crosswalks

  • PIPEDA: crosswalk between Law 25 obligations and the ten federal principles, for organizations subject to both regimes.
  • GDPR: significant overlap (consent, PIA and DPIA, incident notification, data subject rights) for organizations with EU customers.
  • TGV: TGV's PRP domain shares Law 25 requirements for health network suppliers.
  • HIPAA: incident classification for healthcare organizations operating in Québec and the United States.
  • ISO 27001: many Annex A controls address the personal information protection outcomes of the Act.

Further reading

Article: Law 25, the review. Public body or municipality: public sector solution.

See your Law 25 compliance posture in real time.

Contact us

Frequently asked questions

What is Law 25?
Law 25, the Act to modernize legislative provisions as regards the protection of personal information, reformed Québec's private-sector privacy law. In full force since September 2023, it requires a designated person in charge, privacy impact assessments, confidentiality incident management, privacy by default and new rights for individuals, under the oversight of the Commission d'accès à l'information (CAI).
When is a privacy impact assessment required?
A PIA is required before any project to acquire, develop or redesign a system involving personal information, and before any communication of personal information outside Québec. Sentrix provides bilingual PIA templates aligned with CAI guidance, routes assessments to the right reviewers, records sign-off and keeps every assessment as audit evidence.
What must be done after a confidentiality incident?
When a confidentiality incident presents a risk of serious injury, the organization must notify the CAI and the affected individuals with diligence, and keep a register of all incidents. Sentrix automates the workflow from detection through risk assessment, notice drafting and communication to affected individuals, with letter templates in French and English and a register maintained automatically.

Let's talk about your compliance program.

Last updated: 2026-09-17