OKTO Solutions

Law 25: The Eight Compliance Items Every Quebec SMB Needs to Handle

Law 25 is not a compliance project reserved for large organizations. A four-person business in Trois-Rivières is subject to the exact same rules as one with four hundred employees. The obligations came into force in stages, on September 22, 2022, September 22, 2023, and September 22, 2024. All of them are in effect today.

This guide breaks down what a Quebec SMB needs to address, in what order, and where the line falls between documentation work and technical work. It’s written for the business owner who wants to know where to start, not the lawyer looking for an article-by-article legal analysis.

Quick answer: Law 25 amends the Act Respecting the Protection of Personal Information in the Private Sector and applies to every Quebec business, regardless of size. There are eight items to address: data scope, consent, individual rights, designated officer, incidents, out-of-Quebec transfers, penalties, and documentation. An SMB that hasn’t done anything isn’t just behind schedule anymore; it’s in breach.

1. What We’re Actually Talking About

“Law 25” is the nickname for a statute passed in 2021, the Act to Modernize Legislative Provisions as Regards the Protection of Personal Information. It was known as “Bill 64” during its passage through the National Assembly.

That law doesn’t stand alone as a self-contained set of rules. It amended other existing laws. For a private business, the one that matters is the Act Respecting the Protection of Personal Information in the Private Sector, CQLR chapter P-39.1. That’s the text where the articles cited throughout this guide actually appear. Looking for a document titled “Law 25” to read your obligations is a dead end.

2. Who It Applies to, and Why There Are No Exemptions

Section 1 applies to “any person carrying on an enterprise.” The word enterprise refers to the concept in article 1525 of the Civil Code of Quebec, meaning the organized exercise of an economic activity. Three practical consequences follow.

  • No size threshold. Employee count, revenue, and industry have no bearing on whether the law applies.
  • No exemption for employee data. Personnel files, job applications, payroll records, and group insurance files all contain personal information.
  • No exemption because data is with a vendor. If your IT provider, payroll firm, or hosting company holds personal information on your behalf, the responsibility remains yours.

That third point catches a lot of people off guard. Outsourcing the processing doesn’t transfer the obligation. It adds a layer you need to document.

Signed contract document, illustrating the written obligations under Law 25

3. The Eight Items to Address

The work breaks down into eight blocks. Each has its own pitfalls, and each gets its own section in this guide.

  1. Scope and definitions. What counts as personal information, what’s sensitive, what isn’t, and the obligation to destroy or anonymize.
  2. Consent. The five conditions under section 14, the required disclosures at collection, minors, geolocation, and profiling.
  3. Individual rights. Access, correction, portability, cessation of disclosure, de-indexing, automated decisions, and the 30-day deadline.
  4. Privacy officer. Who holds that role by default, how to delegate it in writing, and what needs to be published.
  5. Confidentiality incident. What qualifies as an incident, the register, the serious harm assessment, and notifying the Commission.
  6. Out-of-Quebec transfers. The privacy impact assessment and written agreement required under section 17.
  7. Penalties. The three enforcement regimes, the amounts set out in the law, and who imposes them.
  8. Templates. The documents you need to fill out so everything else holds together.

4. The Bare Minimum, in Order

If you’re starting from scratch, do them in this order. The first four are what a client, insurer, or the Commission d’accès à l’information asks to see first.

  1. Appoint the privacy officer and publish their title and contact information.
  2. Write and publish the governance policy and the privacy policy.
  3. Open the confidentiality incident register, even if it’s empty.
  4. Write the access request procedure, including the 30-day deadline.
  5. Inventory the personal information you hold and the vendors who touch it.
  6. Complete the privacy impact assessment for any out-of-Quebec transfers.
  7. Set your retention periods and your destruction process.
  8. Update your collection forms to include all required disclosures.

The first four can be sorted out in a matter of weeks for most SMBs. The last four require a technical inventory, which means time from your IT provider or internal team.

Law 25 compliance plan presentation at a management meeting

5. What Law 25 Is Not

Three misconceptions come up constantly, and each one costs money.

It’s not a cybersecurity standard. The law requires reasonable security measures under section 10, without specifying which ones. A firewall doesn’t make you compliant. A well-written policy doesn’t protect you from a breach.

It’s not a certification. No one issues an official Law 25 compliance certificate. A vendor selling “Law 25 certification” is selling their own stamp of approval.

It’s not the European GDPR. The two frameworks look similar on consent and individual rights. They differ on transfers, timelines, and penalty amounts. A privacy policy translated from a European template almost always includes references that make no sense here, starting with the well-known 72-hour rule, which doesn’t appear in Quebec’s law.

6. The Documentation Side and the Technical Side

Compliance happens on two fronts. The documentation front is legal and administrative: policies, procedures, registers, agreements. It falls to your designated officer and your legal counsel.

The technical front belongs to a managed IT services provider. It covers access management, logging, encryption, endpoint protection, verified backups and offsite immutable copies, incident detection and response, data hosting, and documentation for all of it. The IT provider is also the one who produces the inventory that feeds your documents: where data lives, who accesses it, which vendor holds it, and in what country. Our managed IT services cover this side of things for SMBs in Mauricie and across Quebec.

The line is simple to remember. No one can write your governance policy for you, and no one can prove your access controls for you either.

Frequently Asked Questions

Does Law 25 apply to a business with fewer than 10 employees?

Yes. The law sets no size threshold. Any person carrying on an enterprise within the meaning of article 1525 of the Civil Code is covered, including a self-employed person who has incorporated. The obligations are proportionate to the activities involved, not to whether the law applies.

Do you need a lawyer to comply with Law 25?

Not for everything, but for reviewing policies and handling edge cases, yes. An SMB can build its inventory, incident register, and access procedure internally, then have them reviewed. The technical side gets delegated to an IT provider.

Is there an official Law 25 compliance certification?

No. No public body issues a compliance certificate. What exists is evidence: published policies, a maintained register, documented assessments, retained logs. That’s what a client or insurer asks to see.

Where to Start as a Quebec SMB

The most practical starting point is the inventory: what personal data you hold, in which systems, with which vendors, and in which countries. Everything else follows from that, from the incident register to the transfer assessment. Our Trois-Rivières team builds that inventory and puts the associated technical measures in place through our managed cybersecurity and cloud services. To talk through your situation, reach us through the contact form or call 450-231-3836.

This guide simplifies legal obligations for practical purposes. It is not legal advice and does not replace reading the statute or consulting a legal advisor. All legal references point to the Act Respecting the Protection of Personal Information in the Private Sector (CQLR, chapter P-39.1), as amended by Law 25.