Training by theme
Confidentiality and compliance
Law 25, purpose, anonymization, transfers outside Québec: the path that protects the personal information entrusted to AI, day to day and at every tool choice.
Why this path
What enters a public AI can come back out.
Masking a name is not enough: indirect clues allow re-identification, and reusing data for a new objective requires new consent. This path makes purpose, minimization and anonymization concrete, and clarifies what Law 25 actually requires.
The modules in this path
Law 25 in plain terms for employees
M07
Apply purpose, minimization and informed consent day to day.
Minimize the information given to AI and respect the purpose of collection. Reusing data for a new objective requires new consent.
RegisterAnonymization vs pseudonymization
M08
Distinguish reversible masking from legal, irreversible anonymization.
Masking a name is not enough: indirect clues (postal code, role, unique detail) allow re-identification. Legal anonymization is irreversible.
RegisterReusing existing data
M09
Assess whether a new use is compatible with the original purpose.
Holding data does not grant unlimited usage rights. A compatible use is allowed; a different, incompatible objective requires new consent.
RegisterChoosing a tool and managing transfers outside Québec
M10
Require contractual guarantees and conduct a PIA.
Require non-reuse, encryption and transfer compliance. A privacy impact assessment precedes any transfer outside Québec, and GDPR compliance does not equal Law 25 compliance.
RegisterConfidential data: the basic reflexes
M04
Sort your data and de-identify rigorously before every prompt.
Anything entered into a public AI can be retained and reused. Never client names, salaries or API keys; removing just the name is not enough.
RegisterReady to equip your team?
Enroll your teams in our AI-literacy and governance training paths, from the common core to function-specific use cases.
Immediate access · 100% online · at your own pace