OKTO Solutions

Law 25: What Non-Compliance Actually Costs

The question comes up at every meeting: what do we actually risk? The answer has two parts. What the law says, and what actually happens to a small Quebec business. Both are worth knowing, because they don’t point in the same direction.

This page covers the three penalty regimes created by Law 25, then the concrete risk, the one that shows up long before any fine is imposed.

Quick answer: Law 25 created three distinct paths: administrative monetary penalties imposed by the Commission d’accès à l’information, criminal fines obtained through prosecution, and punitive damages awarded by a civil court. In practice, the most common risk for a small business isn’t the fine; it’s the complaint, the investigation, and the contract lost because you couldn’t answer a compliance questionnaire.

1. Three Distinct Regimes

Law 25 created three paths that can hit the same company for the same incident.

  • The administrative monetary penalties, imposed by the Commission d’accès à l’information without going through a court.
  • The criminal fines, obtained through criminal prosecution.
  • The punitive damages, awarded by a civil court at the request of an affected individual.

They’re not mutually exclusive. A poorly handled data breach can trigger a Commission order, a criminal prosecution, and a civil lawsuit.

2. Administrative Monetary Penalties

Section 90.12 sets the maximums: $50,000 for an individual, and in all other cases, $10,000,000 or an amount equal to 2% of worldwide revenue from the previous fiscal year, whichever is higher.

For a small Quebec business, the relevant cap is $10 million. The percentage only exceeds that figure for companies with worldwide revenue above $500 million.

These are maximums, not expected amounts. There’s no public scale that guarantees a specific penalty for a given violation.

Unexpected invoice after an incident, illustrating the real cost of non-compliance

3. Criminal Fines

Section 91 sets fines ranging from $5,000 to $100,000 for individuals, and for all other cases, from $15,000 to $25,000,000 or 4% of worldwide revenue from the previous fiscal year, whichever is higher.

The offenses covered are listed in the same section. The ones most relevant to a small business:

  • collecting, using, disclosing, retaining, or destroying personal information in violation of the law;
  • failing to report a confidentiality incident to the Commission or to affected individuals when required to do so;
  • failing to implement the security measures required to protect personal information as set out in section 10;
  • identifying or attempting to identify a person from de-identified information without authorization, or from anonymized information;
  • obstructing a Commission investigation or inspection, including by providing false or inaccurate information;
  • violating a Commission order.

The floor is worth noting. For a business, the minimum fine is $15,000. There’s no symbolic slap on the wrist. Section 92.1 doubles fines for repeat offenses, and section 92.2 sets a five-year limitation period from the date of the offense.

4. Punitive Damages

Section 93.1 provides that when an unlawful infringement of a right granted by the law or by sections 35 to 40 of the Civil Code causes harm, and that infringement is intentional or results from gross fault, the court awards punitive damages of at least $1,000.

Two words matter here. “Awards”: this isn’t discretionary; it’s mandatory once the conditions are met. “At least”: that’s a floor, not a ceiling.

That per-person floor changes the economics of class actions. A breach affecting 20,000 records represents a substantial theoretical minimum, even before compensatory damages are added.

5. The Real Risk for a Small Business

The fine amount is neither the biggest cost nor the most common outcome.

What actually happens: a complaint from a former employee or client to the Commission, an information request, document production, an order to remediate. The cost comes in management time, legal fees, and disruption.

What’s also happening, with increasing frequency: compliance questionnaires from clients. Large buyers, insurers, and public agencies are now asking the questions. Who’s your designated contact? Where is your data? Do you have an incident log? Are your backups tested? A small business without answers loses contracts long before it ever sees a fine.

That’s the most honest argument you can make to a business owner. Compliance pays for itself mainly as a condition of access to clients.

Document review during a compliance audit

6. What Actually Reduces Your Exposure

Three gaps show up repeatedly in cases that go badly: no reachable designated contact, no incident log, and no way to show what data left the organization because logs weren’t kept. All three can be fixed without a major project.

The first two are administrative and can be handled in a few hours. The third is technical: it means enabling, retaining, and monitoring audit logs, securing endpoints, and testing backups. That’s the core of our managed IT services, and it’s also what lets you answer a client questionnaire without scrambling.

Frequently Asked Questions

What fines does Law 25 set for a small business?

The law sets administrative penalties up to $10,000,000 or 2% of worldwide revenue, and criminal fines from $15,000 to $25,000,000 or 4% of worldwide revenue for a business. These are maximums, not expected amounts.

Who enforces Law 25 penalties?

The Commission d’accès à l’information imposes administrative monetary penalties without going through a court. Criminal fines go through prosecution, and punitive damages are awarded by a civil court at the request of an affected individual.

Can a small business be sued by an employee for a violation?

Yes. Section 93.1 provides for punitive damages of at least $1,000 when an intentional or grossly negligent unlawful infringement causes harm. An employee or a client can bring that claim.

Reducing Risk Instead of Calculating It, in Mauricie

No small business should build its plan around the size of the fines. The real calculation is simpler: how long would it take to answer a client questionnaire, and can you show what happened after an incident? Our managed IT services put the technical proof in place that both questions require, for businesses in Trois-Rivières and across Quebec. To talk it over, use the contact form or call 450-231-3836.

This guide simplifies legal obligations for a general audience. It is not legal advice and does not replace reading the legislation or consulting a legal advisor. Legal references point to the Act respecting the protection of personal information in the private sector (CQLR, chapter P-39.1), as amended by Law 25.