If your business holds the contact details of even one client, employee or supplier, you are subject to Law 25. Not "eventually". Since 2023.
Most SMB owners we meet believe this law targets banks and large technology companies. It doesn't. Law 25 applies to every business operating in Quebec, with no size or revenue threshold.
A twelve-person accounting firm is subject to it. So is a dental clinic. So is a surveying firm. Here is what the law actually requires.
1. Appoint a privacy officer
You must designate a person responsible for the protection of personal information and publish their contact details, usually on your website. Absent an explicit appointment, the law automatically designates the person with the highest authority — the president or owner.
In other words: if you have done nothing, it's you. With every responsibility that comes with it.
2. Write and publish a privacy policy
Not a paragraph copied from another site. A policy that actually describes what information you collect, why, how long you keep it and who you share it with. It must be written in plain language and made public.
3. Maintain a confidentiality incident log
This is the most neglected obligation — and the most telling in an audit. Every confidentiality incident must be recorded: date, nature, information affected, people concerned, measures taken.
An incident isn't only a cyberattack. An email sent to the wrong recipient with client data attached is an incident. A laptop left in a taxi is an incident.
And when an incident presents a risk of serious injury, you must report it to the Commission d'accès à l'information and notify the individuals concerned.
4. Obtain clear consent
Consent must be manifest, free, informed and given for specific purposes. Pre-ticked boxes and vague wording such as "by submitting this form you accept our terms" no longer suffice.
5. Destroy or anonymize information you no longer need
You can no longer keep data indefinitely. Once the purpose is fulfilled, information must be destroyed or anonymized — and you need a written procedure that says so.
In practice, that means knowing where your data lives. How many old mailboxes from former employees are still sitting in your Microsoft 365?
6. Put reasonable security measures in place
The law doesn't provide a technical checklist. It requires measures "appropriate to ensure the protection of personal information" and proportionate to its sensitivity.
In practice, a court or the Commission will look at: do you have multi-factor authentication? Access restricted to what's strictly necessary? Logging? Tested backups? Ransomware protection?
Your good faith isn't what counts. What counts is your ability to demonstrate what you had in place on the day of the incident.
What happens if you do nothing
The penalties in the law are substantial — they can reach millions of dollars or a percentage of worldwide revenue. But honestly, that isn't the most likely risk for an SMB.
The real risk is elsewhere, and it's already materializing:
- Your major clients now require compliance attestations in their tenders. Without them, you're disqualified before you even bid.
- Your insurer asks the same questions. Denied cyber coverage or a doubled premium happens this year, not in five years.
- Your clients — especially if you're an accountant, notary or healthcare professional — trust you with their most sensitive data. A mishandled incident isn't a technical problem: it's a crisis of trust you don't always recover from.
Where to start
The good news: compliance is operated, not "projected". A 25-seat SMB doesn't need a $25,000 legal mandate. It needs six things written down, maintained and provable.
The bad news: it isn't a one-time fix. An incident log you don't keep up to date is worthless. So is a policy written in 2023 and never reviewed.
Start by knowing where you stand. Our Law 25 compliance test takes five minutes and requires no sign-up. If the result concerns you — and it concerns most owners who answer honestly — the full assessment gives you the point-by-point scorecard and a costed action plan.
This article is a plain-language summary for SMB owners and does not constitute legal advice. For interpretation of your specific obligations, consult legal counsel.
‹ Back to the blog