Skip to content
../services/security

ARSENAL 02

Law 25 compliance

Get compliant progressively, without paralysing the business.

Quebec’s Law 25 applies to any business operating in Quebec that holds personal information, whatever its size. We establish what you must have, what you are missing, and in which order to address it. The goal is a file you can show a client, an insurer or the access-to-information commission — not a binder gathering dust.

Who it is for

  • Quebec businesses holding client, employee or supplier data
  • Organisations asked by a client to document their practices before signing
  • SMBs that have appointed nobody as privacy officer
  • Companies using cloud tools hosted outside Quebec

What you live with today

  • Nobody knows exactly what personal data you hold or where it sits
  • Your privacy policy was copied from another website years ago
  • No procedure exists for reacting to a confidentiality incident
  • Access or deletion requests are handled case by case, with no record

What it gets you

Appointed

Privacy officer

The person responsible for protecting personal information is named and published, as the law requires.

Maintained

Register

An incident register and a processing inventory you can produce on request.

Written

Procedure

Who does what in the first hours of an incident, through to notification where it is required.

What is included

  • Mapping of personal information: nature, location, retention period
  • A privacy policy written for your actual processing, in plain language
  • An incident register and the associated handling procedure
  • Privacy impact assessments for the projects that require one
  • Consent management and handling of access, correction and withdrawal requests
  • A training session for the people who handle personal data

How it runs

01

Gap assessment

2 to 3 weeks

We compare your current practices to the obligations that genuinely apply to you, and rank the gaps by risk level.

02

Priority workstreams

3 to 5 weeks

Appointing the officer, the incident procedure and the privacy policy: what exposes you most if nothing is done.

03

Full documentation

4 to 6 weeks

Register, processing inventory, consents, supplier agreements and assessments where the project calls for them.

04

Upkeep

Annual review

Compliance goes stale: new tools, new processing, new suppliers. We plan a periodic review.

Indicative timelines for an SMB. A large data volume or several legacy systems lengthen the assessment.

The questions you are asking

Does this apply to us with five employees?

Yes. Law 25 has no headcount threshold: it covers any business operating in Quebec that holds personal information. Some obligations, such as privacy impact assessments, only trigger in specific cases, but the baseline applies to everyone.

Our data is hosted in the United States. Is that a problem?

It is not forbidden, but communicating personal information outside Quebec requires a prior assessment and, often, appropriate contractual clauses. It is one of the points the assessment addresses first.

What are the real penalties?

The law provides for administrative monetary penalties and criminal fines with high ceilings. In practice, the most immediate risk for an SMB remains losing a contract because a client demands guarantees you cannot provide.

We already comply with GDPR. Is that enough?

It is a very good base and much of the work transfers, but the two regimes differ on several points, notably officer designation and rules on transfers outside Quebec. The assessment pinpoints the remaining gap.

Compliance is not a project, it is a state to maintain.

We start with a gap assessment that tells you exactly where you stand and what to tackle first.

The rest of the arsenal