-
Access or rectification request
- A request from a person to see, correct, erase or retrieve the information you hold about them. To be handled within 30 days.
-
Availability
- The data is accessible when you need it — no outage, loss or lockout.
-
Compliance obligation
- A legal requirement to meet (e.g. publish a policy, appoint a lead). Each obligation is documented with evidence.
-
Compliance posture
- An overall score that sums up where you stand and points to your most useful next actions.
-
Confidentiality
- The data is accessible only to authorised people.
-
Confidentiality incident register
Loi 25, art. 3.8
- The mandatory log of incidents affecting personal information. The CAI may request a copy; keep it up to date.
-
Consent
- The free and informed agreement of the individual to use their information; it must be clear and can be withdrawn at any time.
-
DICT sensitivity
Loi 25, art. 10
- A sensitivity rating of the asset on four axes — Availability, Integrity, Confidentiality, Traceability — to prioritise your protection measures.
-
Individual concerned
- The person the personal information is about (client, employee, vendor, etc.).
-
Integrity
- The data stays accurate and complete, not altered without authorisation.
-
Legal basis
- The justification that lets you process information: most often consent, or an exception provided by law.
-
Out-of-Québec disclosure
Loi 25, art. 17
- Entrusting or sending personal information outside Québec; this requires an assessment and contractual safeguards.
-
Personal information (RP)
- Any information that identifies a person, directly or indirectly (name, email, client file, IP address, etc.).
-
Portability
- The individual's right to receive their information in a structured, commonly used technological format, to reuse it elsewhere.
-
Privacy impact assessment (EFVP)
Loi 25, art. 3.3 et 17
- An assessment to run before a risky project (new technology, out-of-Québec transfer, sensitive data) to spot and reduce the risks to individuals.
-
Processor
- A vendor that processes personal information on your behalf (host, cloud software, accountant, etc.).
-
Record of processing (RoPA)
- The list of everything your organisation does with personal information: why, which data, who can access it, and where it goes.
-
Rectification
- Correcting information that is inaccurate, incomplete or ambiguous, at the request of the individual concerned.
-
Sensitive information
Loi 25, art. 59
- Information that warrants heightened protection, whether by its nature (health, biometrics) or by the context in which it is used.
-
Serious harm
Loi 25, art. 3.5
- A significant harm to the individual (financial, psychological, reputational, etc.). If it is likely after an incident, you must notify the individual AND the CAI.
-
Traceability
- You can tell who did what with the data, and when (access and action logging).