Quebec Law 25 (Act respecting the protection of personal information in the private sector) free register: one record per processing activity with purpose, categories of personal information, categories of data subjects, recipients, retention period and legal basis; a confidentiality incident register holding the seven mandatory elements, with the date the organisation BECAME AWARE kept separate from the date of the incident, and logging every incident including those with no risk of serious injury; the designated privacy officer with the written delegation and the publication of title and contact details; and a tamper-proof event log. Every legal figure ships as a dated record carrying its primary source URL. LGPL-3.
Overview
Loi 25 — the two registers the law requires, kept in Odoo
The Act to modernize legislative provisions as regards the protection of personal information — “Law 25” — requires every business operating in Québec to keep two things in writing, and to have a designated person.
This module keeps them. It does nothing else, and it says so.
The record of processing activities
One record per activity — payroll, the newsletter, client files, CCTV in the warehouse. Six headings, which are the six questions you will be asked: why (the purpose), what (the categories of personal information), about whom (the categories of individuals concerned), for whom (the recipients, internal and external), how long (the retention period and what justifies it), and on what grounds (the legal basis).
The legal basis is a free-text field, and that is deliberate. The source consulted on September 14, 2026 publishes no closed list of accepted grounds in the Québec private sector. A drop-down list would amount to inventing a taxonomy and passing it off as the law.
The register of confidentiality incidents
All incidents are recorded there, including those that do not present a real risk of significant harm. This is the point spreadsheets miss: only what caused a stir gets written down, and the register ends up proving the opposite of what it was meant to show.
The seven elements required by the source are all there, one by one: the information concerned or the reason it cannot be described, the circumstances, the date or period of the incident, the date or period when it came to the organization's attention, the number of individuals affected or an estimate, the factors leading to the conclusion that there is or is not a risk of serious injury, and finally the dates of the notices and the measures taken.
The date of discovery is a separate field, and the module refuses to let it precede the incident. This is not a matter of fussiness: the register's retention period is counted from it, and it is what starts the notification obligations running.
The designated person in charge
Without a written delegation, the function falls by default to the person with the highest authority: it is never “nobody”. Delegation is made in writing, in whole or in part, and the module refuses a delegation whose written document is neither attached nor described. The title and contact details are published on the company's website, or by any other appropriate means if there is no website.
And the Commission does not need to be notified of this designation. It is stated on screen, because many people believe otherwise and waste time looking for a procedure that does not exist.
The log cannot be rewritten
Registering a processing activity, changing a purpose, logging an incident, assessing the risk, notices sent, measures taken: every action leaves a dated, signed line. A record rule denies modification and deletion to everyone, including the controller.
An incident register that can be corrected after the fact — backdating the date an incident became known, erasing an inconvenient incident — proves nothing to the Commission d'accès à l'information (Québec's access to information and privacy commission). It even proves the opposite: that it could be done.
The module records findings; it does not draw conclusions
It says that an incident has not yet been the subject of a recorded assessment. It does not say that the risk of harm is significant, or that the company is in default. These two judgments are not calculations: they are assessed, with advice, and they are entered by the user, dated and signed.
No regulatory value is hard-coded
Deadlines, durations and penalty amounts are shipped as dated records carrying the URL of their primary source and the date it was consulted. They can be corrected on screen, without a code release.
The deadline for notifying the Commission ships marked “value not found”, with its written caveat: the source says “promptly” and gives no figure. The module therefore gives no figure and calculates no deadline for this notice. A false confirmation is worse than nothing: it switches off vigilance.
What this module does not do
No privacy impact assessment, no notice generation, no tracking of access requests and their deadlines, no retention alerts, no filing with the Commission. These features are grouped in dyo_loi25_qc, the full edition.
Also searched as: Loi 25 Odoo, Law 25 Quebec Odoo, confidentiality incident register, Quebec register of processing activities, person in charge of the protection of personal information, CAI Québec, Quebec private sector privacy act.
Specifications
| Price | Free |
|---|---|
| License | LGPL-3 |
| Odoo series | 19.0: published on the Odoo Apps Store; 20.0: published on the Odoo Apps Store |
| Version | 1.0.0 |
| Edition | Odoo Community / on-premise |
| Technical name | dyo_loi25_qc_lite |
| Domain | Industries and services |
| Premium version | dyo_loi25_qc |
Price excluding VAT as displayed on the Odoo Apps Store; purchase and installation are done on the Store or through your Omnifloo instance.