top of page

Quebec's Law 25: Is Your Business Compliant?

Sep 23
4 min read
Loi 25 au Québec

You've probably heard of Law 25. Maybe you told yourself, "We'll deal with it later." The problem is that "later" is already here. Since September 2024, all of the law's provisions have been in force, and the fines are very real.


The good news: understanding Law 25 isn't that complicated. Here's everything you need to know to take stock of your situation.


What Exactly Is Law 25?


Law 25, officially titled An Act to modernize legislative provisions as regards the protection of personal information, was assented to on September 22, 2021, by the Government of Quebec. Its goal: to make businesses accountable for how they collect, use, retain and destroy the personal information of their clients, employees and partners.

According to the Commission d'accès à l'information (CAI), the government body responsible for overseeing its enforcement, Law 25 "positions Quebec at the forefront of personal information protection." It was rolled out in three phases between 2022 and 2024. Today, in 2026, all of its provisions are fully applicable.


Who Does It Apply To?


Practically everyone. Law 25 applies to any business or organization that collects, uses or shares the personal information of Quebec residents, regardless of size, industry or geographic location.


In practical terms, this includes:

  • Quebec SMEs, regardless of size

  • Self-employed workers

  • Businesses outside Quebec that deal with Quebecers

  • Non-profit organizations

  • Provincial political parties


If you have a client list in an Excel file, an inbox full of contact details, or a contact form on your website: this applies to you.


Your Concrete Obligations


1. Designate a Person in Charge


Every organization must appoint a person in charge of the protection of personal information. By default, this is the CEO. According to the CAI, the title and contact information of this person must be published on your website or, if you don't have one, made available by any other appropriate means.


2. Establish Governance Policies


You must establish and implement policies governing the management of personal information within your organization, and publish detailed information about them on your website. These policies must notably define the roles of each staff member, the rules for data retention and destruction, and a complaint handling process.


3. Obtain Informed Consent


Consent to data collection must be manifest, free, informed and given for specific purposes. It must be requested in clear and simple terms, separately from any other information. No burying people in pre-checked boxes or unreadable terms and conditions.


4. Ensure Transparency at the Time of Collection


When collecting personal information, you must inform the individuals concerned of the purposes of the collection, their rights of access and rectification, and their right to withdraw their consent.


5. Manage Confidentiality Incidents


If you experience a data breach or unauthorized access, you must promptly notify the CAI and the affected individuals, and keep a register of incidents that you must be able to provide to the Commission upon request.


6. Conduct a PIA Before Sharing Data Outside Quebec


Before communicating personal information outside Quebec, for example to a supplier based elsewhere, you must conduct a Privacy Impact Assessment (PIA). The communication may only take place if the assessment shows that the information would receive adequate protection, and it must be covered by a written agreement.


7. Respect the Right to Data Portability


Since September 22, 2024, any individual can request to retrieve their computerized personal information in a structured, commonly used technological format, or require that it be transferred to another authorized provider. Your organization must be able to respond to such a request.


The Risks of Non-Compliance


This isn't a theoretical warning. The CAI has full powers to investigate, impose penalties and compel businesses to comply. Fines can reach 4% of your organization's worldwide turnover. That amount can quickly become very significant, whatever the size of your business.

And beyond the fines, your reputation is at stake. At a time when customer trust is more valuable than ever, a poorly handled data breach can cause lasting damage.


How to Become Compliant


You don't have to tackle Law 25 compliance alone. Here are the main steps to consider when structuring your approach.


The first thing to do is identify your data sources. Where is personal information stored in your organization? Excel files, emails, paper forms, online tools... A clear picture of the situation is the starting point for any serious effort.


Next comes the most critical step: implementing governance policies. This is where support from specialists, particularly law firms with expertise in personal information protection, really makes sense. The legal obligations are precise, and a policy drafted by professionals protects you far better than an improvised document.


Once the framework is in place, it becomes much easier to centralize your data. Having all personal information in a single, secure system, such as a CRM, rather than scattered across dozens of files and tools, makes it much easier to meet your obligations and significantly reduces risk.


Finally, it's about applying the governance rules day to day. A policy, however well written, is only worth something if your entire team puts it into practice.


In Summary


Law 25 is no longer new. It's the reality of Quebec's legal framework, and it applies to you right now, whatever the size of your organization.


Do you have questions about bringing your organization into compliance? Contact the Devpresso team. With the help of our partners, we support Quebec businesses in modernizing their data management.


Official Sources:

 
 

+1 (844) 878-2229

+1 (514) 418-4866

Devpresso Consulting Inc

4430 Rue Garand

Laval, QC H7L 5Z6

bottom of page