Blog

The Law 25 Checklist: 12 Boxes for Small Businesses

The printable version of compliance: twelve concrete checks, each with the fix. Score yourself honestly. In our experience, most small businesses we meet pass fewer than half.

September 1, 2026 Back to the blog

Our "Law 25, Explained" article covers the why. This is the what: the actual list we use at the start of a compliance mandate. Run through it in fifteen minutes, pencil in hand.

Governance

1. An officer is designated. Someone officially carries responsibility for the protection of personal information. By default, it is the person at the top. Fix: decide who, write it down.

2. Their contact information is published. The officer's title and a way to reach them appear on your website (or by another appropriate means if you have none). Fix: one line in your privacy policy does it.

3. A privacy policy exists and tells the truth. It describes what you actually collect, why, how, for how long, how to reach the officer, and how to request access to information or have it corrected. Fix: start from your real practices, not a copied template.

Collection and consent

4. Every form states its purpose. One sentence next to the submit button: what this information will be used for. Fix: one line of text and a link to the policy.

5. You collect the minimum. Every form field has a justification. The "date of birth" field nobody uses is a liability, not an asset. Fix: delete the orphan fields.

6. Cookies and tracking are under control. You know which tracking tools your site runs and your policy names them. Tools that can identify, locate, or profile visitors must sit at the most private settings by default, be clearly disclosed, and get valid consent when they turn on (strictly necessary cookies do not need it). Fix: inventory your site's scripts, then remove the ones nobody looks at.

Retention and destruction

7. A retention schedule exists. For each type of information: how long you keep it, and what destroys it (an automated job, or a person with a reminder). Fix: a one-page table.

8. Destruction actually happens. Old form submissions, resumes from 2019, dead-prospect emails: something deletes them. Fix: automate where possible, following the periods in your retention schedule. Otherwise, one annual calendar appointment.

Security

9. The incident register exists. Even empty. If something happens, you know what to record (what, who, when, severity, how many people affected, measures taken, whether notices went out), and you know that a risk of serious injury means notifying the CAI and the people affected. Fix: create the table today, before the incident.

10. Access is named and reviewed. No shared "office" account. Multi-factor on email and critical tools. An employee departure triggers same-day deactivation. Fix: start with email, it is the front door to everything else.

Vendors

11. Your vendors are inventoried. Newsletter, accounting, CRM, hosting, AI tools: you know which ones touch personal information and where they process it. Fix: the list first, the agreements second.

12. Transfers outside Quebec are assessed. For every vendor processing data outside Quebec (most American tools), a written assessment exists, proportionate to how sensitive the information is and to the risks (including the legal regime of the destination country), and it concludes the information will be adequately protected, with an agreement to match. Fix: a few pages per vendor is enough for a small business, not a consultant's report.

Your score, honestly

10 to 12: you are in the lead pack. Have it all reviewed once a year. 5 to 9: the skeleton is there. The holes are probably retention and vendors, the two longest to fix alone. 0 to 4: you have plenty of company, and it is catchable in weeks, not months.

We run this exercise with clients as part of our Law 25 compliance program: a fixed-price assessment, concrete findings, and a plan you execute with us or without us. If your score made you wince, write to us or book a 30-minute call. Bring the ticked list, we will start from there.

Read next

Law 25 and privacy

Quebec's Law 25, Explained for Small Businesses

What Quebec's privacy law actually requires from a 5-to-50-person company, without the legal jargon, and where to start without losing a quarter to it.

Security and alerts

August 2026 Patch Tuesday: What to Patch First

On August 11, 2026, the Canadian Centre for Cyber Security posted several advisories. Here is how to rank your security patches in 30 minutes a month.

Managed IT and growth

What Does Managed IT Cost for a Small Business?

The real numbers, plan by plan, with what is included, what is not, and how to tell whether you are paying too much (or too little).

Ready to talk?

Not sure which tier fits?

A quick conversation will sort it out. We'll look at your team size, your tools, and what's actually breaking.

Book a call