An access request rarely arrives at a convenient time. It shows up by email, often from a former employee or an unhappy client, and it starts a 30-day clock the law won’t pause because the right person was on vacation.
This page covers the rights Law 25 grants to individuals, the deadlines that bind you, and the technical groundwork that determines whether you can respond on time.
Quick answer: Law 25 gives individuals a right of access, a right of correction, a right to portability, a right to stop distribution and to de-indexing, and specific rights regarding automated decisions. The person responsible must respond in writing within 30 days of receiving the request. After that deadline, the organization is deemed to have refused, which opens the door to a complaint before the Commission d’accès à l’information.
1. The Right of Access
Section 27 requires the organization, at the request of the individual concerned, to confirm that personal information about them exists, disclose it to them, and allow them to obtain a copy.
Computerized information must, upon request, be provided in the form of a written, intelligible transcription. When the individual has a disability, reasonable accommodation measures must be taken upon request.
Access is free under Section 33. Reasonable fees may be charged for transcription, reproduction, or transmission, and the individual must be informed of the approximate amount before any costs are incurred.

2. The 30-Day Deadline and the Consequence of Silence
Section 32 requires the person responsible for the protection of personal information to respond in writing to an access or correction request promptly, and no later than 30 days after the date the request is received.
The same section adds a consequence for silence: failing to respond within 30 days means the organization is deemed to have refused the request. That deemed refusal opens the door to a complaint before the Commission d’accès à l’information. Three practical consequences follow.
- You need a known, monitored receiving address. That’s the responsible person’s contact, published on your website.
- You need to timestamp receipt. The clock starts from when the request was received, not from when the right person found the email.
- You need to be able to extract the data in under 30 days. That’s the technical challenge, and it’s where most small businesses get stuck.
Tracking down everything your organization holds on a person across your file server, cloud office suite, CRM, payroll system, and email archives takes time if nothing has been set up in advance. A properly tooled search across your entire environment, built proactively, turns a three-week exercise into a few hours of work.
3. Correction and Portability
Section 28 allows any individual to demand the correction of information that is inaccurate, incomplete, or ambiguous, or whose collection, disclosure, or retention is not authorized by law. The same 30-day deadline applies.
The right to portability was the last provision to take effect, on September 22, 2024. Section 27 provides that computerized personal information collected from the individual must, upon request, be communicated in a structured, commonly used technological format. That information must also be transmitted, upon request, to any person or body authorized by law to collect it.
The right has two limits written into the text. It does not cover information created or inferred from information about the individual: the score you calculated, the performance rating you assigned, or the marketing segment you derived are not portable. And it does not apply if doing so would raise serious practical difficulties. That’s a safety valve, not an escape hatch. Invoking it because the export is tedious won’t hold up; invoking it because the data is locked in a legacy system with no export mechanism is more defensible.
In practice, a clean CSV or JSON file satisfies the requirement for a structured, commonly used format. A 40-page image document does not.

4. Stopping Distribution and De-indexing
Section 28.1 creates two remedies.
The first is straightforward: the individual can demand that the organization stop distributing a piece of information, or that any hyperlink connected to their name that gives access to it be de-indexed, when the distribution violates the law or a court order.
The second involves a three-part cumulative test. The distribution causes the individual serious harm to their reputation or privacy. That harm clearly outweighs the public interest in knowing the information or anyone’s interest in free expression. And the measure requested does not go beyond what is necessary to prevent the harm from continuing.
The assessment takes into account, among other things, whether the person is a public figure, whether the information relates to them from when they were a minor, and whether the information is current and accurate.
For a small business, the real-world scenario is almost always the same: a former employee asks for their name and photo to be removed from a team page, a press release, or a social media post.
5. Automated Decisions
Section 12.1 applies to organizations that use personal information to render a decision based exclusively on automated processing. Three obligations follow.
- Inform the individual that the decision is automated, no later than when they are notified of the decision.
- Upon request, inform them of the personal information used, the reasons, and the main factors and parameters that led to the decision, along with their right to have that information corrected.
- Give them the opportunity to present their observations to a staff member capable of reviewing the decision.
The word “exclusively” is the key. If a human reviews the file and makes the call, the section does not apply. If the system decides on its own and the human simply passes along the result, it does.
This obligation becomes more pressing as small businesses connect AI tools to their candidate screening, credit approval, or pricing processes. The law requires the ability to explain the main factors. A tool that provides no explanation puts you in non-compliance by design.
Frequently Asked Questions
What is the deadline to respond to an access request under Law 25?
Thirty days from receipt of the request, with a written response from the responsible person. Failing to respond within that timeframe means the organization is deemed to have refused, which opens the door to a complaint before the Commission d’accès à l’information.
Can you charge a fee for a personal information access request?
Access itself is free. Reasonable fees may be charged for transcription, reproduction, or transmission, and the approximate amount must be communicated to the individual before being incurred.
Can a former employee demand the removal of their photo from the company website?
Often yes, through the right to stop distribution or de-indexing under Section 28.1, depending on whether the distribution violates the law or causes serious harm that outweighs the public interest. In practice, most organizations remove the photo without any argument.
Actually Being Able to Respond in 30 Days
Access rights compliance is won or lost on technical preparation: knowing where the data lives, being able to search everywhere at once, and keeping a record of what was searched. Our managed IT services equip small businesses in Trois-Rivières and Quebec so that search takes hours rather than weeks. To assess your ability to respond on time, use our contact form or call 450-231-3836.
This guide provides a plain-language overview of legal obligations. It is not legal advice and does not replace reading the actual legislation or consulting a legal professional. Legal references refer to the Act Respecting the Protection of Personal Information in the Private Sector (CQLR, chapter P-39.1), as amended by Law 25.