OKTO Solutions

Since September 2023, Quebec’s Law 25 has placed concrete obligations on every business that collects personal information. Yet many SMBs in Trois-Rivieres and the Mauricie region still don’t know whether they’re compliant. Fines can reach $25 million or 4% of worldwide revenue, which is reason enough to act now.

At OKTO Solutions, we help Quebec SMBs understand their obligations and put the right technical measures in place. This guide covers what the law actually requires, walks through seven steps to reach compliance, and shows how Microsoft 365 makes the process easier.

Quebec Law 25 SMB compliance personal data protection OKTO Solutions Trois-Rivieres

Quick answer: Law 25 requires Quebec SMBs to protect personal information by naming a privacy officer, obtaining clear consent, securing data, and reporting incidents. Fines can reach $25 million.

1. What is Quebec Law 25 and who does it apply to?

Quebec’s Law 25, officially the Act to modernize legislative provisions respecting the protection of personal information, replaces the province’s former private sector privacy law. It applies to any business that collects, uses, discloses, or retains personal information about individuals, whether those are customers, employees, or suppliers.

In other words, if your SMB has a customer list, employee records, or an online contact form, this law applies to you. That said, the specific obligations depend on your organization’s size and the type of data you handle.

Key dates to remember:
September 2022: first individual rights took effect
September 2023: governance, incident reporting, and privacy impact assessments became mandatory
September 2024: data portability and de-indexing rights took effect
Fines: up to $25 million or 4% of worldwide revenue for serious violations.

2. Law 25’s 5 core obligations for your SMB

Quebec’s Law 25 introduces several concrete obligations. Here are the five that matter most for a Mauricie SMB.

1. Name a privacy officer

Every business must designate someone responsible for compliance, and that person’s name and contact information must appear on your website. In most SMBs, this ends up being the owner or an HR manager.

2. Take inventory of your personal information

You need to know exactly what information you collect, where it’s stored, who can access it, and how long you keep it. A personal information register is now mandatory, and it’s the foundation of any compliance effort under Law 25.

3. Report confidentiality incidents

If your data is compromised, lost, or accessed without authorization, you’re required to assess the risk and report it to Quebec’s Commission d’acces a l’information (CAI). An incident management plan is essential here. Our article on disaster recovery planning for SMBs covers this in more detail.

4. Get explicit consent

Collecting personal information now requires clear, specific consent. Vague forms or pre-checked boxes no longer cut it. You need to explain why you’re collecting each piece of information and get informed agreement.

5. Conduct a privacy impact assessment (PIA)

Before launching any project involving personal information, your SMB needs to assess the privacy risks. That includes adopting new software, rolling out a CRM, or starting an email marketing campaign.

Quebec Law 25 SMB compliance plan OKTO Solutions Mauricie

3. Quebec Law 25: 7 steps to reach compliance

Compliance with Law 25 isn’t a one-time project, it’s an ongoing process. Here are the seven concrete steps to get started.

Step 1: designate your privacy officer

Start by choosing who will own compliance in your organization, then publish their name on your website, ideally within your privacy policy.

Step 2: inventory your data

List every source of personal information: web forms, CRM software, HR files, customer lists, emails. For each source, document the type of data, where it lives, how long you keep it, and who’s authorized to access it.

Step 3: update your privacy policy

Your policy now needs to cover individual rights, the types of information you collect, the purposes behind that collection, and your privacy officer’s contact details. It should also be written in clear, accessible language.

Step 4: secure your IT systems

Quebec’s Law 25 requires security measures proportional to how sensitive the data is. That includes data encryption, role-based access controls, multi-factor authentication, and regular backups. This is where OKTO Solutions can make a real difference, since Microsoft 365 already includes many of these tools natively.

Step 5: set up an incident management process

Define who does what when an incident happens. Specifically, set your reporting timeline (72 hours for serious cases), identify who needs to be contacted, and establish how the incident gets documented.

Step 6: train your employees

Your employees are your first line of defense. Training on how to handle personal information, spot phishing attempts, and follow incident procedures is essential. Check out our guide on AI-driven cyberattacks targeting SMBs in 2026 to understand the current threats.

Step 7: review and update regularly

Compliance with Quebec’s Law 25 isn’t something you do once and forget. It’s an ongoing practice. Review your register and your measures at least once a year, or whenever something significant changes in your operations.

Law 25 Quebec SMB compliance support personal data Trois-Rivieres

4. How Microsoft 365 helps your SMB meet Law 25

The good news is that several Microsoft 365 tools already address Quebec Law 25 requirements directly. If your SMB is already on the Microsoft suite, you likely have access to compliance features you haven’t turned on yet.

  • Microsoft Purview: classifies and protects sensitive data, prevents leaks (DLP), and tracks access to personal information.
  • Azure Active Directory: granular access management, multi-factor authentication, and audit logs to show who has access to what.
  • Microsoft Defender: detects security incidents and automatically alerts on abnormal access to personal data.
  • Retention policies: automatically delete data once its retention period expires, reducing your exposure.

To learn more about these tools, see the official Microsoft documentation on information protection and the resources from Quebec’s Commission d’acces a l’information.

Frequently asked questions about Quebec Law 25

My business is small. Does Law 25 still apply?

Yes. The law applies to any business that collects personal information, regardless of size. That said, obligations scale with your organization. A 5-employee SMB has lighter obligations than a 200-person company, but the fundamentals are the same.

What are the penalties for non-compliance?

The Commission d’acces a l’information can impose administrative monetary penalties of up to $10 million. On top of that, the courts can impose penal fines of up to $25 million or 4% of worldwide revenue for serious violations.

Where do we start if we haven’t done anything yet?

Start with a data inventory and by naming a privacy officer. Those are the two most important steps. From there, reach out to OKTO Solutions for an audit of your IT environment. We’ll assess your current technical measures and put together an action plan suited to your SMB’s reality here in Mauricie.

OKTO Solutions supports your Law 25 compliance journey

Compliance with Quebec Law 25 can feel overwhelming. But with the right technology partner, it becomes a structured, manageable process. At OKTO Solutions, we assess your environment, identify the gaps, and put the necessary technical measures in place across Microsoft 365 and beyond.

Contact our team for a free Law 25 compliance assessment, or discover our cybersecurity and compliance services for Quebec SMBs.

Leave a Reply

Your email address will not be published.Required fields are marked *

Gravatar profile