Law 25 for Quebec SMBs: The Complete 2026 Compliance Guide
Since September 22, 2023, most of Quebec’s Law 25 has placed concrete obligations on every business that collects personal information, and the duty to report confidentiality incidents has applied since September 22, 2022. Many SMBs in Trois-Rivières and the Mauricie still do not know whether they comply. Fines can reach 25 million dollars or 4% of worldwide revenue, so acting now remains the best decision.
At OKTO Solutions, we help Quebec SMBs understand their obligations and put the necessary technical measures in place. In this guide, we first explain what the law requires in practice. We then set out the 7 steps to compliance. Finally, we show how Microsoft 365 technology simplifies the work.

Quick answer: Law 25 requires Quebec SMBs to protect personal information: appoint a privacy officer, obtain clear consent, secure the data and report incidents. Fines can reach 25 million dollars.
1. What is Law 25 for Quebec SMBs, and who does it cover?
Law 25 for Quebec SMBs, officially the Act to modernize legislative provisions as regards the protection of personal information, replaces the former act on the protection of personal information in the private sector. It applies to any business that collects, uses, discloses or stores personal information about individuals, whether they are clients, employees or suppliers.
Put another way, if your SMB keeps a client list, employee files or an online contact form, the law concerns you directly. The obligations do vary with the size of your organization and the type of data you handle.
Key dates to remember:September 2022: the first rights for individuals come into force
September 2023: governance, incidents and privacy impact assessments become mandatory
September 2024: the rights to portability and de-indexing come into force
The fines: up to 25 million dollars or 4% of worldwide revenue for serious violations.
2. The 5 main Law 25 obligations for your SMB
Law 25 for Quebec SMBs introduces several concrete obligations. Here are the five that matter most to an SMB in the Mauricie.
1. Appoint a person in charge of protecting personal information
Every business has to designate someone responsible for overseeing compliance. That person’s name and contact details also have to be published on your website. In an SMB, the owner or the human resources lead usually takes on the role.
2. Take inventory of your personal information
You have to know exactly what information you collect, where it is stored, who has access to it and how long you keep it. A register of personal information therefore becomes mandatory. It is the foundation of all compliance with Law 25 for Quebec SMBs.
3. Report confidentiality incidents
If your data is compromised, lost or accessed without authorization, you are required to assess the risk and report it to the Commission d’accès à l’information (CAI), Quebec’s privacy regulator. An incident management plan therefore becomes essential. Our article on the disaster recovery plan for SMBs covers this in detail.
4. Obtain explicit consent
Collecting personal information has to rest on clear, specific consent. Vague forms and pre-checked boxes are no longer acceptable. You have to explain why you are collecting each piece of information and obtain informed agreement.
5. Carry out a privacy impact assessment (PIA)
Before any new project involving personal information, your SMB has to assess the risks to privacy. That includes adopting new software, rolling out a CRM or launching an email marketing campaign.

3. Law 25 for Quebec SMBs: the 7 steps to compliance
Compliance with Law 25 for Quebec SMBs is not a one-time project. It is a continuous process. Here are the seven concrete steps to get started efficiently.
Step 1: designate your privacy officer
Start by choosing the person responsible for compliance in your organization. Then publish their name on your website, ideally in your privacy policy.
Step 2: draw up an inventory of your data
List every source of personal information: web forms, CRM software, HR files, client lists, email. For each source, document the type of data, where it sits, how long it is kept and who is allowed to access it.
Step 3: update your privacy policy
Your policy now has to include the rights of individuals, the list of information collected, the purposes of the collection and the contact details of your privacy officer. It also has to be written in clear, accessible language.
Step 4: secure your IT systems
Law 25 for Quebec SMBs calls for security measures proportional to how sensitive the data is. That includes data encryption, role-based access control, multi-factor authentication and regular backups. This is where OKTO Solutions can give you concrete help. Microsoft 365 already includes several of these tools natively.
Step 5: set up an incident management process
Define who does what when an incident happens. Quebec law requires you to notify the Commission d’accès à l’information "with diligence" as soon as an incident carries a risk of serious injury (section 3.5 of the Act respecting the protection of personal information in the private sector). It sets no deadline in hours: the 72-hour figure people often quote comes from the European GDPR. So spell out who notifies the Commission, the people to contact and the way the incident is documented in your register.
Step 6: train your employees
Your employees are your first line of defence. Training on handling personal information, recognizing phishing attempts and following the procedures when an incident happens is therefore essential. Read our guide on the AI-driven cyberattacks that target SMBs in 2026 to understand the risks in play today.
Step 7: review and update regularly
Compliance with Law 25 for Quebec SMBs is not a project you do once. It is a continuing practice. Review your register and your measures at least once a year, or whenever something important changes in your operations.

4. How Microsoft 365 helps your SMB meet Law 25
The good news is that several Microsoft 365 tools answer the requirements of Law 25 for Quebec SMBs directly. If your SMB already uses the Microsoft suite, you most likely have access to compliance features you are not using yet.
- Microsoft Purview: classification and protection of sensitive data, data loss prevention (DLP) and tracking of access to personal information.
- Azure Active Directory: granular access management, multi-factor authentication and audit logs to show who has access to what.
- Microsoft Defender: detection of security incidents and automatic alerts when personal data is accessed abnormally.
- Retention policy: automatic deletion of data once its defined retention period is over, which reduces your exposure.
To learn more about these tools, see the official Microsoft documentation on information protection and the resources from the Commission d’accès à l’information du Québec.
Frequently asked questions about Law 25 for Quebec SMBs
My business is small. Does Law 25 for Quebec SMBs still apply?
Yes. The law applies to every business that collects personal information, whatever its size. The obligations are proportional, though. An SMB with 5 employees carries a lighter load than a company of 200 people, but the basics are the same.
What are the penalties for non-compliance?
The Commission d’accès à l’information can impose administrative monetary penalties of up to 10 million dollars. A court can also impose penal fines of up to 25 million dollars or 4% of worldwide revenue for serious violations.
Where do you start if nothing has been done yet?
Start with the inventory of your data and the appointment of a privacy officer. Those are the two most important steps. Then contact OKTO Solutions for an audit of your IT environment. We will assess your current technical measures and propose an action plan suited to the reality of an SMB in the Mauricie.
OKTO Solutions supports you through Law 25 compliance
Compliance with Law 25 for Quebec SMBs can look complex. With the right technology partner, it becomes a structured, workable process. At OKTO Solutions, we assess your environment, identify the gaps and put the necessary technical measures in place in Microsoft 365 and beyond.
Contact our team for a no-obligation assessment of your Law 25 compliance, or discover our cybersecurity and compliance services for SMBs in Quebec.
Full guide: Law 25 for Quebec SMBs
The obligations by deadline, the official sources, the fines set out in the law and the frequently asked questions, all on a single page kept up to date.
Sources:
Commission d’accès à l’information du Québec: Law 25
LegisQuebec: Act respecting the protection of personal information in the private sector
Microsoft Learn: Microsoft 365 information protection
An article sets out the principle. Putting it in place happens one workstation at a time: our managed cybersecurity service, backup and disaster recovery and our IT services in Montreal.