General information, not legal advice. I am an IT professional, not a lawyer. This guide summarizes what Quebec’s privacy regulator, the Commission d’accès à l’information (CAI), says and explains the technical part. For the wording of your policies and your exact obligations, talk to a lawyer.
What is already in force
- Since September 22, 2022: a person in charge of personal information whose title and contact details are published on the company website, a register of confidentiality incidents, and a duty to notify the CAI and the people affected when an incident carries a risk of serious harm.
- Since September 22, 2023: governance policies, a privacy impact assessment when the law requires one (for example before sharing personal information outside Quebec), and rules on consent, destruction, and privacy by default.
- Since September 22, 2024: the right to data portability.
- Website: if you collect personal information through your website, a privacy policy written in plain, clear terms must be published on it.
Source: the CAI’s guide to businesses’ responsibilities (cai.gouv.qc.ca), February 2023. The law is not reserved for large companies.
What is handled on the IT side
- The website: a clear privacy page, the privacy officer’s title and email visible, and an inventory of the tracking tools (Google Analytics, Facebook pixel) it loads.
- A dedicated email address for the privacy officer (for example
privacy@yourdomain.com) that does not depend on one person. - The incident register and a short procedure: who to call, what to note, who to notify.
- Access: who sees which files, two-step login turned on, former employees’ accounts closed.
- Email: SPF, DKIM, and DMARC reduce spoofing of your domain (see the SPF, DKIM, and DMARC guide).
- Backups and retention: where the data lives, how long you keep it, how you destroy it.
- An inventory of the tools that hold personal information (Microsoft 365, case software, forms) and where they host the data.
What needs a lawyer
The CAI recommends consulting a lawyer who specializes in privacy and an information security specialist. I am the second: I put the technical controls in place. The wording of your policies, your consent forms, the privacy impact assessment, and your contracts with suppliers belong to a lawyer.
What doing nothing can cost
According to the Quebec government, penalties can reach CAD 10 million or 2% of worldwide revenue for administrative penalties, and CAD 25 million or 4% for penal ones. For a small office, the practical risk is an unmanaged incident: an email sent to the wrong person, a lost laptop, a hacked account.
Where to start
- Name a privacy officer and publish the title and email on your website.
- Publish a clear privacy policy (written or checked by a lawyer).
- Open an incident register, even if it is empty.
- List the tools and places where personal information lives.
- Turn on two-step login, check your backups, and set up SPF, DKIM, and DMARC.