Guide · Law 25

Law 25: what a small office needs on the IT side.

Law 25 is Quebec’s privacy law. Here is what is already in force, what is handled on the IT side, and what needs a lawyer.

General information, not legal advice. I am an IT professional, not a lawyer. This guide summarizes what Quebec’s privacy regulator, the Commission d’accès à l’information (CAI), says and explains the technical part. For the wording of your policies and your exact obligations, talk to a lawyer.

What is already in force

  • Since September 22, 2022: a person in charge of personal information whose title and contact details are published on the company website, a register of confidentiality incidents, and a duty to notify the CAI and the people affected when an incident carries a risk of serious harm.
  • Since September 22, 2023: governance policies, a privacy impact assessment when the law requires one (for example before sharing personal information outside Quebec), and rules on consent, destruction, and privacy by default.
  • Since September 22, 2024: the right to data portability.
  • Website: if you collect personal information through your website, a privacy policy written in plain, clear terms must be published on it.

Source: the CAI’s guide to businesses’ responsibilities (cai.gouv.qc.ca), February 2023. The law is not reserved for large companies.

What is handled on the IT side

  • The website: a clear privacy page, the privacy officer’s title and email visible, and an inventory of the tracking tools (Google Analytics, Facebook pixel) it loads.
  • A dedicated email address for the privacy officer (for example privacy@yourdomain.com) that does not depend on one person.
  • The incident register and a short procedure: who to call, what to note, who to notify.
  • Access: who sees which files, two-step login turned on, former employees’ accounts closed.
  • Email: SPF, DKIM, and DMARC reduce spoofing of your domain (see the SPF, DKIM, and DMARC guide).
  • Backups and retention: where the data lives, how long you keep it, how you destroy it.
  • An inventory of the tools that hold personal information (Microsoft 365, case software, forms) and where they host the data.

What needs a lawyer

The CAI recommends consulting a lawyer who specializes in privacy and an information security specialist. I am the second: I put the technical controls in place. The wording of your policies, your consent forms, the privacy impact assessment, and your contracts with suppliers belong to a lawyer.

What doing nothing can cost

According to the Quebec government, penalties can reach CAD 10 million or 2% of worldwide revenue for administrative penalties, and CAD 25 million or 4% for penal ones. For a small office, the practical risk is an unmanaged incident: an email sent to the wrong person, a lost laptop, a hacked account.

Where to start

  1. Name a privacy officer and publish the title and email on your website.
  2. Publish a clear privacy policy (written or checked by a lawyer).
  3. Open an incident register, even if it is empty.
  4. List the tools and places where personal information lives.
  5. Turn on two-step login, check your backups, and set up SPF, DKIM, and DMARC.

IT health check

See where you stand in one day.

The IT health check covers the technical points in this guide and gives you a written report with priorities. CAD 500, credited toward any project decided within 30 days.