AGR / TRANSPARENCY
Personal information protection
Governance topics for personal information and the applicable Québec framework.
Version dated September 9, 2026A framework, not a certification
Law 25 modernized Québec’s personal information protection obligations. This page distinguishes those obligations from the site’s technical functions. It does not attest that a compliance audit or certification has been completed.
Responsibilities and practices
A business must designate a privacy officer and publish their title and contact details. It must also govern information access, retention, destruction and complaint handling.
At AGR, the officer’s designation and implementation of request deletion after no more than one month remain to be confirmed. A protected form alone is not evidence of compliance with these practices.
Projects involving personal information
Before entrusting information to an automated system, the engagement must define sources, access, purposes and human approvals. The applicable privacy impact assessment and arrangements for communication outside Québec must be examined before the processing concerned.
Presenting our method does not mean that such an assessment has already been completed for your organization.
Incident handling framework
When a confidentiality incident occurs, the law requires measures to reduce risks and prevent recurrence. If it presents a risk of serious injury, the business must promptly notify the CAI and affected individuals. It must also keep an incident register.
This description recalls applicable obligations; it does not replace an approved internal procedure. To report an issue affecting AGR, email the relevant facts.