Blog

Quebec's Law 25, Explained for Small Businesses

What Quebec's privacy law actually requires from a 5-to-50-person company, without the legal jargon, and where to start without losing a quarter to it.

August 12, 2026 Back to the blog

Law 25's obligations arrived in stages: the first ones (a designated officer, the incident register) as early as September 2022, the bulk in September 2023, and data portability in September 2024 (its exact scope is still framed by regulation). The Commission d'accès à l'information (CAI) can levy serious penalties. Yet most of the small businesses we meet in the Outaouais still have nothing formalized. Not out of bad faith: because everything written on the subject is written for lawyers or for enterprises.

Here is the version for you.

What the law asks, in five points

These five points are the starting line, not the whole statute. Other obligations can apply depending on your activities (for example, a privacy impact assessment before a new system that handles personal information).

1. A designated officer. Someone in your company must be officially responsible for the protection of personal information, and their title and contact information must be public (on your website if you have one, by another appropriate means if not). By default it is the person at the top. You can delegate it in writing.

2. A published privacy policy. As soon as you collect personal information (a contact form counts, but so do the phone and the front counter), you must publish a clear policy covering at minimum: what you collect, why, how, how long you keep it, who has access, who you share it with (including outside Quebec, where that applies), and how someone can request access to their information or have it corrected.

3. Consent at the right moment. Consent must be clear, free, and informed, requested for each purpose, and express for sensitive information. Concretely: one clear sentence next to your form saying who collects and why, pointing to your policy for the rest (rights, retention, recipients), not a 40-page document.

4. An incident register. If personal information is lost, stolen, or accessed without authorization, you must record it in a register, assess the risk of serious injury, and notify the CAI and the people affected when that risk exists. The register must exist even while it is empty.

5. Agreements with your vendors. Your client data flows through tools: newsletter platform, cloud accounting, CRM. The law requires proper written agreements with those vendors (use limited to the mandate, confidentiality, incident notices), and a documented assessment concluding the information will be adequately protected when it leaves Quebec. Keeping a list of your vendors is the simple habit that makes the rest possible.

What it does not ask

No certification, no mandatory external audit, no $40,000 consultant. The law requires measures proportionate to how sensitive the information is and how you use it. For a 10-person business, a well-kept set of documents (policy, register, data inventory, vendor list) covers the essential documentary obligations.

The three mistakes we see most

The copy-pasted policy. A generic policy describing practices you do not have is worse than nothing: it is a public commitment you are violating. Yours must describe what you actually do.

The chatty form. Many sites collect more than they need, then keep everything forever. The law requires the opposite: collect the minimum, destroy when the purpose has passed.

The free tool that costs a lot. Client data in a free consumer tool, with no processing agreement, is the textbook undocumented transfer. It is fixable, but it has to be inventoried first.

Where to start this week

  1. Name the officer and publish their contact on your site.
  2. Take inventory: what information, in which tools, kept how long.
  3. Publish a policy that tells the truth.
  4. Create the incident register (an empty table is fine, as long as it exists).
  5. Put an annual review date on the calendar.

We apply these rules to our own site: our privacy policy describes exactly what we collect and why, and our internal measures actually exist. If you want the same without giving up your evenings, our Law 25 compliance program starts with a fixed-price assessment. A 30-minute conversation will tell you where you stand.

Read next

Security and alerts

August 2026 Patch Tuesday: What to Patch First

On August 11, 2026, the Canadian Centre for Cyber Security posted several advisories. Here is how to rank your security patches in 30 minutes a month.

Managed IT and growth

What Does Managed IT Cost for a Small Business?

The real numbers, plan by plan, with what is included, what is not, and how to tell whether you are paying too much (or too little).

Managed IT and growth

Your First IT Provider at 10 Employees: What Changes

A composite scenario: the owner of a 10-person business has been the IT department since day one. Here is what handing that off actually looks like, and what it costs.

Ready to talk?

Not sure which tier fits?

A quick conversation will sort it out. We'll look at your team size, your tools, and what's actually breaking.

Book a call