Governance & compliance
Law 25 compliance: what a Quebec business actually has to do
Obligation by obligation, what the law expects from any business holding personal information in Quebec, and where to start without an in-house legal team.
Key points
- Law 25 applies as soon as a business holds personal information. There is no headcount or revenue threshold.
- Five obligations carry the rest: designated officer, published policy, incident register, breach notification, privacy impact assessment.
- Compliance is a state to maintain, not a project to close: it is re-documented whenever a tool or a processing activity changes.
- The first useful step is mapping the personal information you hold, without that map, no obligation can be met seriously.
Who does Law 25 apply to?
Any business operating in Quebec that collects, holds, uses or discloses personal information, regardless of size. The law sets no headcount or revenue threshold: a five-person company keeping employee files falls within its scope, exactly as a large organization does.
Two groups are consistently caught off guard. Small Quebec businesses, who assume the law targets large organizations. And head offices elsewhere in Canada or in the United States, who discover that holding information about Quebec employees or customers is enough to bring them in scope.
The useful question is therefore not whether you are covered, but what you hold and where. Employee files, customer lists, prospecting email, camera recordings, payroll records: all of it is personal information under the law.
A second driver often weighs more than the law itself: enterprise customers now request compliance attestations from their suppliers. Many businesses discover their obligations inside a customer questionnaire, days before a deadline.
What are the obligations, concretely?
Five obligations carry the essentials: designate a privacy officer, publish a governance policy, keep a confidentiality incident register, notify incidents presenting a risk of serious injury, and run a privacy impact assessment before certain projects.
Order matters. The officer must exist before anyone can answer for an incident; the register must exist before an incident occurs. Starting with the published policy (the most visible item)produces surface compliance that does not survive the first real question.
- Designate a privacy officer. By default the person with the highest authority in the business. The role can be delegated in writing. The title and contact details must be published on the website.
- Publish a governance policy. Covering roles, retention, destruction, complaint handling and the use of third parties. Public, and written in plain language.
- Keep a confidentiality incident register. Every incident is recorded, notifiable or not. An empty register after several years is itself a warning sign to an investigator.
- Notify incidents presenting a risk of serious injury. To the Commission d'accès à l'information and to affected individuals, with diligence. Qualification accounts for the sensitivity of the information and the anticipated consequences.
- Run a privacy impact assessment (PIA). Before acquiring or redesigning a system that processes personal information, and before any disclosure outside Quebec.
- Honour individual rights. Access, correction, withdrawal of consent, de-indexation, and portability of computerized information.
What is the real exposure for a smaller business?
The law provides for administrative monetary penalties and penal fines, with caps set out in the text. For a smaller business, however, the most common consequence is not a fine: it is the contract lost because a customer asked for an attestation that could not be produced.
The maximum amounts are high and frequently quoted for effect. They describe a ceiling, not a practice: penalties actually imposed depend on severity, good faith and the measures taken. We do not lead with them, because waving a maximum figure is fear, not advice.
The practical risk is more mundane. A mishandled incident invites a complaint, and a complaint triggers a review of the whole arrangement, including parts unrelated to the incident. A business that documented its decisions can defend them; one that improvises discovers its gaps in front of the investigator.
Where do you start from zero?
With a map of the personal information you hold: what, where, why, who can reach it, and how long it is kept. Without that map you cannot write an accurate policy, qualify an incident, or answer an access request. Everything else follows from it.
This is done with the people who actually handle the data (payroll, sales, customer service)not from an org chart. That is where the shared spreadsheet outside the system turns up, or the mailbox used as an archive, or the vendor holding a full copy of the customer database.
Then comes the officer designation, then the documents: policy, incident procedure, register, PIA template. They are written from the map, not from a generic template: a downloaded template describes a business that is not yours, and works against you when your actual practice contradicts it.
How long it takes depends entirely on the starting point: the number of systems, how scattered the data is, and the availability of the people who know it. We do not announce a duration in advance, because announcing one would mean guessing.
Compliance and security: what is the difference?
Compliance documents what you do with personal information; security stops someone taking it. A business fully compliant on paper can be breached in an hour, and a well-protected business can be in default for never having designated an officer. Both are run together.
The law itself makes the connection: it requires security measures appropriate to the sensitivity of the information. A policy promising confidentiality without multi-factor authentication or tested backups describes an intention, not a measure.
That is why we treat compliance as one strand of an engagement rather than a standalone documentation exercise. The reverse (producing documents the technical reality does not support)manufactures an additional risk: that of an inaccurate declaration.
Frequently asked questions
No. The role falls by default to the person with the highest authority in the business, who may delegate it in writing to a staff member or rely on external support. What matters is that the role is assigned, that contact details are published, and that the designated person genuinely has the time and the information required to exercise it.
Rarely. Most published policies describe website usage, whereas the law expects a governance policy covering all the information held: retention, destruction, roles, complaint handling and use of third parties. Simple test: if the document does not say how long you keep an employee file or who decides to destroy it, it does not meet the obligation.
Record it in the register, contain it, then qualify the risk of serious injury against the sensitivity of the information and the anticipated consequences. Where that risk exists, the Commission d'accès à l'information and the affected individuals must be notified with diligence. Improvising that qualification during the incident is the main cause of late notification: it is prepared in calm conditions.
No, it sits alongside it depending on context. PIPEDA, the federal regime, covers information crossing a provincial or international border in the course of commercial activity. A Quebec business with customers elsewhere in Canada may fall under both. In practice, an arrangement built seriously for Law 25 covers most of what PIPEDA expects.
Yes. Bill 64 was the name of the bill during its passage; once adopted in September 2021 it became chapter 25 of the statutes of that year, hence "Law 25". Both names refer to the same reform, which amended the Quebec private-sector privacy act. English-language legal commentary still uses Bill 64 frequently.
Sources
- Act respecting the protection of personal information in the private sector (CQLR, c. P-39.1) · official consolidated text, Légis Québec
- Act to modernize legislative provisions as regards the protection of personal information (Law 25, formerly Bill 64) · amending act, phased into force from 2022 to 2024
- Commission d'accès à l'information du Québec · supervisory authority: guidance, incident report form and decisions
- Personal Information Protection and Electronic Documents Act (PIPEDA) · federal regime, for interprovincial commercial activity
This page provides general information for business leaders. It is not legal advice and does not replace an assessment by legal counsel in light of your particular situation.
Is your infrastructure ready for the next threat?
An initial assessment, free and without commitment, to evaluate your security posture.