Most Quebec SMBs get stuck at the same point: they know what to do, but they have no idea what the document is supposed to look like. So the file stays open for months, waiting for a first draft to work from.
This page lays out the structure of the documents required under Law 25, section by section. These are starting points to adapt to your situation, then have reviewed by a legal advisor before use.
Quick answer: Six documents cover the essentials: the governance policy, the published privacy policy, the incident log, the notice to the Commission and affected individuals, the privacy impact assessment grid, and the vendor and cross-border transfer registry. A spreadsheet and two short documents are all most SMBs need.
1. The Governance Policy
Internal document, approved by the person responsible, required under section 3.2. Its structure:
- Scope and purpose: what information is covered, what formats, who is affected (clients, employees, candidates, vendors, visitors).
- Person responsible: title, contact information, reference to the written delegation and its date.
- Inventory of information held, in an appendix: by category, nature, purpose, basis for collection, location, systems involved, who has access, retention period, destruction method.
- Lifecycle and roles: collection, use, communication, retention, destruction or anonymization, including how backups and copies are handled.
- Security measures: reference to the information security policy, with a baseline (multi-factor authentication, role-based access management, periodic access reviews, encryption at rest and in transit, logging, endpoint protection, verified backups, and immutable off-site copies).
- Vendors and cross-border transfers: reference to the registry, and a rule that no new vendor handling personal information may be retained without prior assessment.
- Privacy impact assessment: triggers and grid.
- Incidents, complaints, access requests, training, and annual review.
A shorter public version, written in plain, clear language, is published on the website. It covers the scope, the person responsible, the lifecycle, vendors, incidents, complaints, and access requests, without the exploitable technical details.

2. The Website Privacy Policy
Required under section 8.2, to be published and dated. Expected sections:
- who we are, and contact information for the person responsible for privacy protection;
- what information is collected and why, in a three-column table (information, purpose, retention period), one row per purpose;
- how it is collected (form, phone call, email, cookies);
- consent and withdrawal, with the address to exercise it;
- who the information is shared with, by category of third party and purpose;
- cross-border transfers outside Quebec, where applicable;
- rights: access, correction, withdrawal of consent, portability, removal from publication or de-indexing, with a 30-day response deadline;
- automated decisions, if applicable;
- cookies, security in general terms, complaints to the Commission d’accès à l’information, and notice of changes.
3. The Privacy Incident Log
Required under section 3.8. A spreadsheet works fine, one row per incident, including those that did not result in notification. Useful columns:
- sequential number; date or period of occurrence; date discovered;
- description of circumstances, brief and factual;
- information affected, nature and categories, or the reason if unknown;
- number of individuals affected, or a reasoned estimate;
- cause: human error, external malice, internal malice, technical failure, lost equipment;
- risk of serious harm assessment under the three factors in section 3.7, and reasoned conclusion;
- person responsible consulted, with the date;
- notice to the Commission and affected individuals: yes or no, date, method of transmission;
- communications to third parties to reduce risk;
- measures taken to reduce risk and prevent recurrence, with deadline, responsible party, and closing date.
The exact content of the log and its retention period are set by the Regulation respecting privacy incidents. Check the current version of the regulatory text before finalizing your template.
4. The Two Notices After an Incident
The notice to the Commission d’accès à l’information is submitted using the form provided by the Commission. Prepare the following in advance: company and responsible person identification, a factual description of the incident, dates of occurrence and discovery, how it was discovered, categories of information affected and number of individuals, cause, grounds for the conclusion on serious harm, measures taken, status of notice to affected individuals, and the name of the vendor holding the information, where applicable.
The notice to affected individuals is written to be understood. No jargon, no defensive language. Its structure: what happened in two to four factual sentences, what information is affected, what you have done, what you recommend the person do, how to reach you, and a reminder of the recourse available before the Commission. The notice is signed by the highest authority or by the person responsible.

5. The Privacy Impact Assessment Grid
Sections 3.3 and 17. The assessment should be proportionate, so one page is enough for a typical project. The sections:
- project description and business purpose;
- information affected: categories, volume, presence of sensitive information;
- necessity of each category, with others removed;
- lifecycle: collection, use, communication, retention, destruction;
- who has access and the access control mechanism;
- data location, and hosting outside Quebec where applicable;
- planned security measures;
- portability: does the project allow the individual to receive, in a structured and commonly used format, the information collected from them;
- section 17 component: sensitivity, purpose, contractual measures, legal framework of the destination jurisdiction, conclusion, reference to the written agreement;
- residual risks, decision, conditions, and review date.
The vendor registry complements the grid: one row per service, not per vendor, with the location of data at rest and in backup, subcontractors, the deletion mechanism at end of contract, and the next review date. Filling it in requires an up-to-date technical inventory, which we produce as part of our managed IT services.
Frequently Asked Questions
What documents does an SMB need to produce for Law 25?
At minimum: an approved governance policy, a published privacy policy, an incident log, a process for handling access requests, a privacy impact assessment grid, and a vendor registry.
Does a spreadsheet work as an incident log?
Yes, as long as it includes all required fields, is kept up to date, and is retained. The format matters less than having the right fields and being able to send a copy to the Commission on request.
Can you publish your internal governance policy as-is?
You don’t have to. The law requires publishing detailed information about policies and practices, in plain, clear language. A shorter public version, without the exploitable technical details, meets the obligation.
Filling In the Templates With the Right Data, in Quebec
A template fills quickly when the inventory exists, and never when it doesn’t. The technical side of these documents, including data locations, access controls, retention periods, backups, and vendors, is exactly what our managed IT services cover for SMBs in Trois-Rivières and the Mauricie region. To get that inventory and move your documents forward, use the contact form or call 450-231-3836.
This guide is a plain-language overview of legal obligations. It is not legal advice and does not replace reading the legislation or consulting a legal advisor. Legal references refer to the Act respecting the protection of personal information in the private sector (CQLR, chapter P-39.1), as amended by Law 25.