The first question in any Law 25 file isn’t “what do we need to write,” it’s “what data are we actually talking about.” A lot of Quebec SMBs write a privacy policy before they’ve even listed the information they hold. The document ends up looking polished and being wrong.
This page covers the real scope of the law: what counts as personal information, what counts as sensitive, the difference between de-identifying and anonymizing, and the destruction obligation that almost nobody follows.
Quick answer: Personal information is any information that concerns a natural person and that makes it possible, directly or indirectly, to identify them. The word “indirectly” significantly broadens the scope: IP addresses, employee numbers, camera footage. Once the purposes of collection have been fulfilled, section 23 requires destruction or anonymization, and anonymization is a far higher bar than simply removing the “name” column.
1. What Counts as Personal Information
Section 2 of the law defines it as: any information that concerns a natural person and that makes it possible, directly or indirectly, to identify that person. Two words do most of the heavy lifting.
“Natural person” excludes legal entities. A client company’s name, its Quebec enterprise number, and its billing address are not personal information. The name, email, and cell number of your contact at that company are.
“Indirectly” significantly broadens the scope. An IP address, a device identifier, an employee number, a license plate, or a security camera image can all identify someone once cross-referenced with other data you already hold.
In a typical SMB, the list looks something like this: employee and applicant files, payroll records, client and contact lists, call recordings, camera footage, login logs, website browsing history, staff email inboxes, group insurance files, and client credit files.

2. Sensitive Information and the Weight of Context
Section 12 defines sensitive information as information that, by its nature (notably medical, biometric, or otherwise intimate), or because of the context in which it is used or communicated, warrants a high degree of reasonable expectation of privacy.
The consequence is straightforward. For sensitive information, consent must be expressed explicitly. Implied or inferred consent is not enough.
Context matters as much as the nature of the data. A list of names is not sensitive. The same list of names titled “employees on disability leave” is. That’s why an inventory that only looks at field types, without considering what the file is actually used for, misses half the risk.
3. De-identified Is Not the Same as Anonymized
The law draws a clear line between the two, and the distinction matters.
Information is de-identified when it no longer directly identifies a person. It is still considered personal information, and the law still applies. Section 12 also requires taking reasonable steps to limit the risk of re-identification.
Information is anonymized when it can reasonably be expected, at all times and under the circumstances, that it can no longer, in an irreversible manner, be used to identify a person directly or indirectly. That is the threshold set by section 23. Once crossed, it is no longer personal information.
That threshold is demanding. Removing the “name” column from a file does not anonymize anything. Section 23 specifies that anonymization must follow generally recognized best practices and the criteria and procedures set by regulation. In practice, for an SMB, the realistic path is destruction, not anonymization.
4. Destroying Data When the Purpose Is Fulfilled
Section 23 sets out the obligation: when the purposes for which information was collected or used have been fulfilled, the business must destroy it or anonymize it, subject to any retention period required by law.
This is the most widely ignored obligation in the entire framework. Most SMBs keep everything indefinitely because storage costs almost nothing. Two habits to build.
Set a retention period by data category, not by file. A single-page grid covers it: rejected applications, employee files after departure, camera recordings, access logs. The specific periods should be confirmed with your legal counsel, since some are set by tax law or labor standards legislation.
Make sure destruction reaches the copies. Data deleted from the server still lives in backups, in the cloud service’s trash, in email archives, and on the workstation of whoever exported it to a spreadsheet. This is a technical job, not a policy job, and it’s exactly the kind of verification our backup and data management services cover.

5. What the Law Does Not Cover
Journalistic, historical, or genealogical material published for legitimate public information purposes falls under a separate framework.
Public bodies, municipalities, school service centers, and health institutions fall under a different law, the Act respecting Access to documents held by public bodies and the Protection of personal information. If you supply a public body, its requirements flow down to you by contract, which amounts to the same thing in practice.
Professional orders and certain sectors have additional rules that sit on top of Law 25 without replacing it.
One point worth confirming with legal counsel: whether the law applies to non-profit organizations depends on whether they carry on an organized economic activity within the meaning of section 1525 of the Civil Code. The prevailing interpretation is that an organization that sells services, collects dues, or employs staff falls within scope.
Frequently Asked Questions
Is an IP Address Personal Information in Quebec?
It can be. The definition in section 2 covers anything that can identify a person indirectly. An IP address cross-referenced with connection logs or a customer account often identifies someone, so it should be treated as personal information.
What Is the Difference Between Anonymized and De-identified Data?
De-identified information no longer directly identifies a person but remains personal information subject to the law. Anonymized information can no longer, in an irreversible manner, be used to identify a person, and falls outside the scope of the law. The second threshold is much harder to reach.
How Long Can You Keep Former Employee Files?
The law does not set a single period. It requires destruction or anonymization once the purposes are fulfilled, subject to retention periods set by other laws, including tax law and labor standards legislation. Best practice is a retention grid by category, reviewed by legal counsel.
Inventorying Your Data, in Trois-Rivières and Beyond
No policy is stronger than the inventory it’s built on. Knowing which personal data lives in your servers, your office suite, your payroll system, and your backups is a technical job you do once and maintain from there. Our managed IT services include this data mapping for SMBs in Mauricie and Quebec. To discuss it, use the contact form or call 450-231-3836.
This guide simplifies legal obligations. It is not legal advice and does not replace reading the legislation itself or consulting a legal advisor. Legal references point to the Act Respecting the Protection of Personal Information in the Private Sector (CQLR, chapter P-39.1), as amended by Law 25.