How ready is your business for Quebec’s Law 25?
Use this ten-question check to spot strengths and gaps in how your organization manages personal information. It takes about three minutes.
- 10 practical questions
- Immediate readiness score
- Prioritized next steps
Assess your current practices
Choose the answer that best reflects what is documented and consistently followed today—not what is merely planned.
Private by design. Your answers are evaluated only in this browser. They are not submitted to Yeevy or stored on our servers.
Your readiness result
0/20
Strong foundation
Your answers indicate that many core privacy practices are documented and operating. Focus on the remaining gaps and verify that evidence stays current as systems, vendors, and uses change.
Foundation in progress
You have some important practices in place, but inconsistent or undocumented controls can create exposure. Turn the gaps below into an owned, time-bound action plan.
Priority gaps to address
Your answers indicate several foundational gaps. Start with accountability, your information inventory, and incident readiness before expanding uses of personal information or AI.
Your recommended next steps
You reported every practice as documented and in use. Validate the answers with evidence and schedule periodic reviews so controls stay effective.
- Confirm the privacy officer, publish their title and contact details, and document any delegation of the role in writing.
- Create or update a personal-information inventory covering purposes, systems, access, recipients, locations, and retention periods.
- Document and publish the required governance framework, then assign owners and a regular review schedule.
- Review collection notices and consent requests for clear, specific information delivered at the right time.
- Adopt an EFVP/PIA trigger and review process that involves the privacy officer from the start of relevant projects and transfers.
- Inventory providers and update due diligence and written agreements to address use, safeguards, incident notice, retention, and deletion.
- Review least-privilege access and technical, administrative, and physical safeguards against the risks of each information set.
- Establish and rehearse an incident procedure, including risk assessment, escalation, notification decisions, and the incident register.
- Create a verified request workflow with identity checks, responsibilities, deadlines, decisions, and secure delivery methods.
- Inventory automated decisions and add the required transparency, correction, opportunity to submit observations, and meaningful human review.
This self-assessment is general educational information, not a legal opinion or certification of compliance. Applicability depends on your activities and circumstances; seek qualified legal advice when needed.