Glossary

Personal information (PI)

Information about a natural person that allows identifying them.

Sensitive personal information (Sensitive PI)

PI giving rise to a high reasonable expectation of privacy (medical, biometric, intimate, depending on context).

Person in charge of the protection of personal information (privacy officer) (RPRP)

Person responsible for protecting PI; by default, the organization's highest authority.

Privacy impact assessment (EFVP in French) (PIA)

Analysis of a project's privacy risks, carried out before it is implemented.

Commission d'accès à l'information (CAI)

Québec's oversight body for the law; receives incident notices and can impose administrative penalties.

Act respecting the protection of personal information in the private sector (PPIPS) (Private Sector Act)

Law applicable to Québec private enterprises, amended by Law 25.

Act respecting access to documents held by public bodies and the protection of personal information (Access Act)

Law applicable to public bodies, including school service centres and public schools.

Confidentiality incident

Unauthorized access to, use or disclosure of PI, loss of PI, or any other breach of its protection.

Risk of serious injury

Assessed by sensitivity, anticipated consequences and likelihood of harmful use; triggers notice to the CAI and individuals.

Anonymization

Irreversible process making it impossible to identify a person; use for serious and legitimate purposes.

De-identification (Pseudonymization)

Removal of direct identifiers; data remain PI because re-identification is possible.

Data Processing Agreement (DPA)

Contract framing the processing of PI by a supplier on behalf of an organization.

Subprocessor / service provider (Subprocessor)

Third party that processes PI on behalf of an organization under a written mandate.

Right to portability (Portability)

Right to obtain one's information in a structured, commonly used technological format.

Privacy by Design

Building privacy protection into a product or system from the design stage.

Privacy by Default

Default settings providing the highest level of confidentiality.

Role-based access control (RBAC)

Granting access by role, following the principle of least privilege.

Multi-tenancy

Architecture where several customers share the same application while keeping their data isolated.

Data Loss Prevention (DLP)

Tools that detect and block data leaks.

Time To Live (TTL)

Lifetime of a data item, after which it is automatically deleted.