Since September 2024, Law 25 has been fully in force in Quebec. The implicit grace period that followed its phased rollout is behind us.
Key points
- Law 25 applies with no threshold for headcount or revenue.
- If you have customers, employees, or job applicants, you handle personal information.
- Penalties accumulate across three distinct regimes, including a private right of action.
- Most notifiable incidents have a technical cause, not a documentation gap.
Who does Law 25 apply to?
Any organization that collects, holds, uses, or discloses personal information in Quebec: private businesses, non-profits, professional orders, self-employed workers with a client list. There is no minimum revenue or employee threshold.
The law, officially the Act to modernize legislative provisions as regards the protection of personal information, passed in September 2021, does not provide a lighter regime for small organizations. A five-person accounting firm carries the same substantive obligations as a financial institution; only the proportionality of the measures differs. Businesses outside Quebec that serve Quebec customers are also covered.
A piece of personal information is anything that can identify a natural person: name, email, phone number, IP address, billing data, employee file, a resume you received, purchase history. In other words: if you have customers, employees, or job applicants, you handle personal information.
What obligations are actually in force?
Five areas, all in effect since September 2024: governance and the designation of a person in charge, confidentiality incident management, consent and transparency, the information lifecycle, and contractual oversight of service providers.
1. Governance and accountability
- Designate a person in charge of the protection of personal information. By default, this is the person with the highest authority in the organization. The role can be delegated in writing to an employee or an external consultant. Their title and contact information must be published on your website.
- Establish governance policies and practices covering personal information: roles and responsibilities, retention, destruction, and complaint handling. Detailed information must be communicated in plain, clear language, generally through the website’s privacy policy.
2. Confidentiality incident management
- Keep a register of confidentiality incidents: any unauthorized access, use, or disclosure, as well as any loss or theft, must be logged, even minor ones.
- Assess the risk of serious harm for each incident: sensitivity of the information, foreseeable consequences, likelihood of malicious use.
- Notify the Commission d’accès à l’information (Quebec’s access to information commission) and the affected individuals without delay when that risk exists, and take reasonable steps to reduce it.
This is where compliance and cybersecurity meet: ransomware, a compromised email account, or a stolen unencrypted laptop are confidentiality incidents under the law.
3. Consent and transparency
- Obtain clear, free, and informed consent, requested for specific purposes and separately from any other information. Sensitive information requires express consent.
- Set privacy settings to the highest level by default for technology products and services offered to the public. Non-compliant cookie banners remain one of the easiest gaps to spot from the outside.
- Inform individuals when decisions are based exclusively on automated processing and allow them to submit comments.
- Declare any biometric system at least sixty days before it goes into service.
4. Information lifecycle
- Carry out a privacy impact assessment for any project to acquire, develop, or overhaul a system involving personal information. Switching customer relationship management software falls into this category.
- Conduct one before any disclosure outside Quebec and confirm that the destination jurisdiction offers adequate protection. Hosting your customer data with a foreign provider without documented analysis is a violation.
- Destroy or anonymize information once the purposes for which it was collected have been fulfilled.
- Ensure portability: any individual can request to receive their information in a structured, commonly used format.
5. Oversight of service providers
Any disclosure of personal information to a supplier, whether a host, an agency, an IT provider, or a payroll service, must be governed by a written contract specifying the protection measures, use restrictions, destruction at the end of the contract, and the obligation to notify you of any incident. This is one of the most frequently overlooked obligations, and one of the easiest for an inspector to verify.
What are the actual risks?
Three penalty regimes accumulate: administrative penalties the Commission imposes directly, criminal prosecution, and a private right of action open to every individual whose information was compromised. On top of that come costs that hit even without a final penalty.
1. Administrative monetary penalties. The Commission can impose these without going through the courts: up to $10M or 2% of worldwide revenue from the prior fiscal year, whichever is higher. For a business with $2M in revenue, the theoretical 2% cap already amounts to $40,000, before any corrective orders.
2. Criminal penalties. For serious offences, from $15,000 to $25M or 4% of worldwide revenue, whichever is higher. Individuals, including executives, face fines of $5,000 to $100,000. Fines double for repeat offences.
3. Private right of action. Anyone whose information was compromised can claim damages, with punitive damages of at least $1,000 per person in cases of unlawful and intentional infringement or gross negligence. A breach affecting 5,000 customers sets a theoretical floor of $5M in a class action, before legal fees.
On top of these amounts come legal support during an investigation, urgent technical remediation, management’s time, and, since the Commission’s decisions are public, the reputational impact on your customers and business partners.
Why is this primarily a cybersecurity issue?
Because most notifiable confidentiality incidents have a technical cause rather than a documentation gap: phishing, compromised credentials without multi-factor authentication, unpatched exposed equipment, failed backups. An immaculate policy protects neither your data nor your liability.
Many organizations approach Law 25 as a paperwork exercise: draft a policy, name a person in charge, check the boxes. That is necessary but not sufficient.
The evidence from the field is unambiguous: the Canadian Centre for Cyber Security confirms that all Canadian organizations are exposed to ransomware regardless of size, and that phishing and stolen credentials remain the dominant entry points.
The law requires “reasonable security measures” proportionate to the sensitivity of the information. It is the incident that triggers the investigation, and it is the actual state of your technical controls that will shape the Commission’s assessment.
How should compliance and security be addressed together?
By treating them as a single project, because that is how the Commission will assess them. Our approach runs from diagnosis to continuous improvement, and every control is mapped simultaneously against Law 25, ISO 27001, and the NIST framework.
Step 1: diagnosis and mapping. Inventory of the personal information held, mapping of data flows including disclosures outside Quebec, gap analysis, prioritization by actual risk level.
Step 2: documentation and organizational compliance. Governance and privacy policies, incident register, notification process, assessment templates, contract clauses for your service providers, support for your designated person in charge.
Step 3: technical validation. Audits and penetration testing conducted by certified professionals: review of access controls and multi-factor authentication, external exposure, backups and restoration capability, website and application security. This is the step that turns paper compliance into real protection.
Step 4: ongoing maintenance. Regulatory monitoring, incident simulation exercises, annual gap reviews, a dashboard for management.
Where should you start, in ninety days?
Start with what is visible and quick, then what requires a management decision, and finally what requires technical work. The sequence below is a priority order, not a delivery commitment: the actual timeline depends on your decision-makers’ availability.
| Timeline | Priority actions |
|---|---|
| Days 1 to 15 | Designate or delegate the person in charge and publish their contact information; begin the inventory of personal information and service providers |
| Days 16 to 45 | Publish or correct the privacy policy; set up the incident register and notification process; fix the consent banner |
| Days 46 to 75 | Put written contracts in place with critical service providers; carry out assessments for disclosures outside Quebec; enable multi-factor authentication and check backups |
| Days 76 to 90 | Have your posture validated by an external audit; set a retention and destruction schedule; plan employee training |
Law 25 is not just another administrative burden: it is the new minimum standard of trust for doing business in Quebec. Organizations that take it seriously gain a measurable advantage with customers, with business partners who require contractual guarantees, and with cyber insurers whose questionnaires map directly onto these obligations.
FAQ
Is the incident register really mandatory if we’ve never had an incident?
Yes, and it is the most common gap we see. The register must log any unauthorized access, use, or disclosure, as well as any loss, including minor incidents: an email sent to the wrong recipient, a laptop forgotten in a taxi, a misplaced paper file. Setting it up takes an hour. On the day of a serious incident, an organization without a register has to manage the crisis, reconstruct its history, and demonstrate due diligence all at once.
Do our policy templates need to be reviewed by a lawyer?
Not always. Templates adapted by a non-lawyer are sufficient in many straightforward situations. Legal review becomes worthwhile once your context includes something specific: sensitive data, activities in multiple jurisdictions, automated processing that influences decisions about individuals, or ongoing litigation. This article is general information and does not constitute legal advice.
What should we do if we find a gap in our own compliance?
Fix it and document it rather than ignore it. The Commission values due diligence, and a gap that is identified, dated, and paired with a correction plan holds up far better than one discovered by an inspector. The mistake to avoid is backdating compliance after the fact: auditors recognize this, and it turns negligence into an apparent cover-up.
Sources
- Act respecting the protection of personal information in the private sector (CQLR, c. P-39.1) · official up-to-date text, Légis Québec
- Commission d’accès à l’information du Québec · guides, incident report form, and published decisions
- Commission d’accès à l’information du Québec: penalties and prosecutions targeting businesses · applicable penalty regime
- Canadian Centre for Cyber Security: 2025-2027 ransomware threat overview · exposure and initial access vectors
- Personal Information Protection and Electronic Documents Act (PIPEDA) · federal regime, interprovincial commercial activities