Govern customer and employee data
Know which data exists, why, and how long it is kept.
Law 25 is Quebec's statute that modernizes personal information protection rules in the private and public sectors. Passed in 2021 (from Bill 64), it strengthens organizational duties: data governance, consent, privacy notices, privacy impact assessments, and confidentiality-incident management. The Commission d'accès à l'information du Québec (CAI) oversees enforcement; the private-sector framework appears notably in the Act respecting the protection of personal information in the private sector (P-39.1).
In one sentence
Law 25 modernizes personal-data protection in Quebec and creates concrete duties for businesses.
Key points
Term at a glance
Quebec already had privacy statutes before the reform, but several mechanisms—documented governance, incident registers, clearer tech-vendor duties—were less explicit. Law 25 updated that framework toward modern expectations of transparency and accountability.
For a private business this typically means: appointing someone responsible for personal information protection, publishing clear policies, obtaining valid consent when required, limiting collection to what is necessary, and assessing privacy risks on high-impact projects (new systems, transfers, sensitive tech).
When a confidentiality incident presents a risk of serious injury, the organization must notify affected individuals and the CAI as required, and keep an incident register. On websites and digital products, that often means consent banners, retention rules, vendor clauses, and proportionate security (encryption, least privilege, logging).
Identify what you collect (forms, CRM, analytics, HR), where it lives, who accesses it, and for which purposes.
Name the person responsible and write policies and procedures (access, retention, destruction, vendors).
Refresh privacy notices, consent mechanisms, and marketing / analytics tool settings.
Define detection, serious-injury risk assessment, CAI / individual notifications, and the incident register.
A private clinic in Quebec City finds an Excel appointment file emailed to the wrong recipient. The team assesses harm risk, logs the incident, notifies affected people when required, then tightens controls (encryption, distribution lists, training). Without a Law 25 process, they might have sent only a corrective email—with no register or corrective measures.
Know which data exists, why, and how long it is kept.
Align cookies, CRM, and campaigns with clear consent and purposes.
Contract confidentiality duties and incident notice expectations.
Assess, document, and notify per CAI requirements instead of improvising.
| Law 25 | PIPEDA (federal) | |
|---|---|---|
| Geographic scope | Quebec law; applies to businesses under the provincial private-sector framework | Canadian federal private-sector privacy law in federal jurisdiction |
| Oversight body | Commission d'accès à l'information du Québec (CAI) | Office of the Privacy Commissioner of Canada |
| SME focus in QC | Recent reform highly visible for sites, HR, and incidents in Quebec | National framework that may still apply depending on the organization |
| Takeaway | Start with provincial duties (modernized P-39.1) | May coexist for interprovincial / federal activities |
In Quebec, almost every SME collects personal information—customers, leads, employees, patients, or users. Law 25 turns privacy from a distant legal topic into operational duties: policies, consent, vendors, incidents. Compliance lowers sanction and trust risk; more importantly, it stops you from discovering too late where your data actually flows.
No. In Quebec privacy context, “Law 25” means the personal information protection reform—not a geography statute.
When a business collects, uses, or discloses personal information in the course of its Quebec activities, the private-sector framework (P-39.1) generally applies. Check CAI guidance for precise scope.
Legal advice helps on grey areas, but many actions are operational: data inventory, policies, tool configuration, incident procedure.
Contain, assess risk of serious injury, log it, and notify the CAI and individuals when the law requires. CAI guides detail the steps.
Need clarity on Law 25 duties for your site, CRM, or vendors?
Talk about privacy compliance