Law 25: The Complete Guide for Quebec SMBs
Law 25 modernizes personal information protection in Quebec. For SMBs, compliance is no longer optional. This guide explains everything you need to know to protect your data, avoid penalties, and build customer trust.
1. What is Law 25?
Adopted in 2021, the Act to modernize legislative provisions as regards the protection of personal information (commonly known as Law 25) transforms the privacy landscape in Quebec. Highly inspired by the European GDPR, its main goal is to give citizens back control over their personal data while holding the companies that collect it accountable. It imposes a strict framework on how information is gathered, stored, shared, and destroyed, forcing businesses to move from a reactive approach to a true culture of Privacy by Design.
2. Who does it apply to?
The answer is simple: to absolutely all businesses operating in Quebec that collect, process, or communicate personal information, regardless of their size or revenue. Whether you are a freelancer with an email list, a local SMB with 15 employees, or a multinational corporation, Law 25 applies. 'Personal information' is broadly defined as any information concerning a natural person that allows them to be identified (name, personal email, address, financial info, or even an IP address).
3. Your 7 Main Obligations
Law 25 has introduced several progressive obligations since 2022. Here are the 7 central pillars:
1. Appoint an Officer: You must appoint a Privacy Officer. By default, this is the highest-ranking executive.
2. Privacy Policy: You must publish a clear and transparent policy on your website explaining your practices.
3. Incident Registry: In the event of a data breach, you must maintain a confidentiality incident registry and notify the CAI for incidents presenting a risk of serious injury.
4. Explicit Consent: Consent must be clear, free, informed, and given for specific purposes. Pre-checked boxes are no longer allowed.
5. The PIA (Privacy Impact Assessment): Mandatory for any project involving information systems or when transferring data outside Quebec.
6. Right to Erasure: Your customers can demand that you destroy their data (right to be forgotten).
7. Staff Training: Security relies primarily on humans. Regular training of your team is essential to prevent errors.
Afraid of forgetting something?
Check your obligations in less than 2 minutes with our interactive tool.
Take the free diagnostic4. The Privacy Policy: What It Must Contain
Drafting a Law 25-compliant privacy policy cannot be improvised. Simply copying and pasting a competitor's website or using a free generic generator exposes you to legal risk and blatant non-compliance. Here in detail are the substantial elements that must be included to satisfy the requirements of the Commission d'accès à l'information (CAI):
1. Identity and Contact Info of the Officer: You must clearly identify your organization's Privacy Officer (name, title, dedicated email address, phone number) so citizens can submit complaints or requests.
2. Nature of Data Collected: You must take a precise inventory of what you collect (e.g., first and last name, social insurance number, browsing data, IP address, credit card info). Omitting certain categories makes the policy invalid.
3. Purposes of Collection (Why?): Law 25 requires that collection be justified by serious and legitimate purposes. You must detail each purpose (e.g., processing orders, personalized marketing, site improvement, legal compliance). If you use the data for new purposes, new consent will be required.
4. Means of Collection (How?): How do you obtain this data? Directly via a contact form? Automatically via cookies? Indirectly via third-party partners (like Facebook or Google Analytics)?
5. Communication and Data Sharing: Who do you share this information with? You must mention the categories of third parties (web hosts, payment processors, CRMs, marketing tools) and specify if data is communicated outside Quebec (which triggers the PIA obligation).
6. User Rights: The policy must clearly explain to users how to exercise their rights to withdraw consent, access their data, request rectification, and their new right to portability, as well as rights regarding de-indexation or erasure under certain conditions.
7. Retention Period and Destruction: Indicate how long data is kept once the purpose is fulfilled and what your secure destruction methods are.
8. Security Measures: Explain the technological and administrative protections in place (encryption, restricted access, firewalls) to protect data against theft or leaks.
A Law 25 privacy policy must be written in clear and simple language, avoiding complex legal jargon, to ensure truly informed consent.
Download our free Privacy Policy Template
Compliant with Law 25. Receive it immediately by email in PDF format (.pdf) to adapt it to your business.
5. How long must you retain personal information?
The fundamental principle of Law 25 regarding data retention is limitation: you must only retain personal information for the time strictly necessary to achieve the purposes for which it was initially collected. Retaining data "just in case" is now an illegal and risky practice. Once the objective is met, the law imposes an obligation to act: the data must be either permanently and securely destroyed, or anonymized (not merely de-identified) to be kept for serious and legitimate purposes.
Managing the data lifecycle requires the development of an official retention schedule (retention policy). This essential internal document dictates the exact retention period and the method of final disposition for each category of information. It protects your business in the event of a CAI audit and limits your attack surface during a cyberattack (hackers cannot steal what you no longer possess).
Here are practical guidelines and typical timeframes by data type to guide your policy:
1. Employee files: Information relating to employees (payroll, taxes, contracts) must generally be kept for a period of 6 years after the end of employment to meet the requirements of Revenu Québec and the Canada Revenue Agency. Disciplinary or medical records might have different rules depending on your sector.
2. Client files and billing: The retention period generally corresponds to the duration of the business relationship or service provision, plus the legal limitation period (often 3 years in Quebec for civil recourses) and tax requirements (generally 6 years for transaction records and invoices).
3. Unsuccessful candidate resumes: This is a common mistake. Without the explicit consent of the candidate to keep their resume for future opportunities, this document must be destroyed shortly after the hiring process ends (e.g., 3 to 6 months), just long enough to close the file.
4. Marketing data and email lists: As soon as a user unsubscribes from your newsletter or withdraws their consent, their data must be removed from your active lists. If no transaction has occurred for several years (e.g., 2 to 3 years), it is recommended to purge these inactive contacts.
Destruction of Physical and Digital Media
The destruction obligation under Law 25 implies irretrievable erasure. Moving a file to your computer's recycle bin or formatting a hard drive with standard tools is not enough. For your old servers, laptops, or hard drives, you must guarantee media sanitization aligned with industry standards (such as the NIST SP 800-88 Rev. 2 guidelines) or proceed with physical destruction by shredding. Using a
secure data destruction and ITAD service in Montreal helps document how storage media are handled, including through an intervention report or destruction certificate when applicable.
6. The PIA: What is it and when is it mandatory?
The Privacy Impact Assessment (PIA) is a mandatory preventive process. It aims to identify and minimize privacy risks when developing new projects or systems. The Law notably requires a PIA for any project involving the acquisition, development, or redesign of an information system or electronic service delivery system involving personal information, as well as before communicating information outside Quebec or for research purposes. If this process seems overwhelming, our experts can guide you.
Discover our PIA and global compliance service →
7. The Penalties
The penalties provided by Law 25 are among the most severe in the world. For a company, administrative fines can reach $10 million or 2% of worldwide turnover. In the case of penal prosecution, the fine can go up to $25 million or 4% of turnover. Beyond the financial impact, it is the company's reputation that is at stake: the loss of customer trust following a poorly managed data breach is often devastating.
8. Where to start?
The path to compliance can seem daunting, but it is done step by step. Start by appointing your Privacy Officer. Next, map your data: what do you have and where is it? Update your privacy policy and ensure you have a ready-to-use incident registry. If you use old IT equipment, make sure it is destroyed by certified professionals.
Discover our approach →
9. Law 25 FAQ
What is Law 25 in summary?
It is a Quebec law that protects citizens' privacy by requiring companies to be transparent about the collection, use, and destruction of personal data, under penalty of heavy fines.
What are the Law 25 obligations for a business?
Main obligations include: appointing an officer, publishing a clear privacy policy, maintaining a breach registry, obtaining explicit consent, and conducting privacy impact assessments (PIAs).
Is consent always mandatory?
The Law distinguishes between implicit consent for standard uses and explicit consent for sensitive information. Exceptions to obtaining consent exist for specific cases provided by law.
Is a PIA mandatory for everyone?
Yes, if you launch a new technological project involving data or if you transfer data outside Quebec (for example, by using American servers or foreign SaaS).
Who is responsible for Law 25 in a small business?
By default, it is the person with the highest authority (President or CEO). This role can be delegated internally, but the delegation must be in writing.
What to do in case of a data breach?
You must record the incident in your confidentiality incident registry. If the breach presents a risk of serious injury, you must notify the Commission d'accès à l'information (CAI) and the individuals concerned.
Does Law 25 apply to NPOs and freelancers?
Yes. As soon as you collect personal information as part of your professional activities in Quebec, you are subject to it.
How to securely destroy data?
Digital data must be wiped through an erasure process adapted to the media and aligned with applicable guidelines, notably NIST SP 800-88 Rev. 2 or the hardware must be physically destroyed. A simple formatting is not sufficient under Law 25.
Afraid of forgetting something?
Check your obligations in less than 2 minutes with our interactive tool.
Take the free diagnostic