Quebec Law 25: What SMBs Need to Know in 2026
This article provides general information and does not constitute legal advice. The applicable requirements depend on the organization's activities and circumstances.
Key Takeaways
- Law 25 modernized Quebec's personal-information protection framework.
- Organizations must establish responsibility for personal-information protection and publish the responsible person's title and contact information.
- Requirements address governance, transparency, consent, privacy incidents, privacy impact assessments, retention, destruction, and security safeguards.
- Privacy compliance and cybersecurity are connected because organizations must protect the personal information they hold.
- A generic policy copied from another organization is not a substitute for practices that reflect the business's actual activities.
Law 25 came into force in stages beginning in September 2022. Its final scheduled phase came into force in September 2024.
In 2026, organizations should no longer treat the legislation as a future requirement. The practical challenge is to understand what applies, identify the current gaps, and organize the work.
What Law 25 Changed for Quebec Businesses
Legislative Context and Timeline
Law 25 - formally the Act to modernize legislative provisions as regards the protection of personal information, SQ 2021, c. 25 - was adopted by Quebec's National Assembly in September 2021.
It amended several statutes, including the Act respecting the protection of personal information in the private sector and the Act respecting Access to documents held by public bodies and the Protection of personal information.
The scheduled implementation occurred in three principal stages:
- September 2022: first obligations;
- September 2023: major additional obligations; and
- September 2024: final scheduled provisions, including the right to data portability.
Which Businesses Are Covered?
Quebec's private-sector privacy legislation applies to enterprises that collect, hold, use, or disclose personal information in the course of their activities in Quebec, subject to applicable rules and exceptions.
Personal information may include customer and employee names, contact details, account information, identifiers, financial information, and other information about an identifiable individual.
Business size alone does not create a general SMB exemption.
Practical Obligations for an SMB
Establish Responsibility for Personal-Information Protection
By default, the person exercising the highest authority within the enterprise is responsible for ensuring compliance with the private-sector Act. All or part of that function may be delegated in writing.
The title and contact information of the person responsible must be published on the organization's website or otherwise made available by an appropriate means.
The precise governance and delegation arrangement should reflect the legal requirements and the organization's actual decision-making authority.
Publish Clear Privacy Information
Depending on the organization's activities and collection methods, privacy information must clearly explain relevant practices such as what personal information is collected, the purposes, means of collection, rights, and contact process.
The content must reflect actual practices. A policy cannot correct undisclosed or poorly governed processing on its own.
Maintain a Privacy Incident Register
The organization must keep a register of privacy incidents. Under the applicable regulation, the information in the register must be retained for the required period after the organization becomes aware of the incident.
Notify When an Incident Presents a Risk of Serious Injury
When a privacy incident presents a risk of serious injury, the organization must notify the Commission d'accès à l'information and the individuals concerned. It must also take reasonable measures to reduce the risk of injury and prevent similar incidents.
The assessment considers factors set out in the legislation, including the sensitivity of the information, anticipated consequences, and likelihood that the information will be used for harmful purposes.
Conduct Privacy Impact Assessments Where Required
A privacy impact assessment may be required for projects involving the acquisition, development, or redesign of an information system or electronic service that involves personal information. It is also required before certain disclosures of personal information outside Quebec.
The assessment must be proportionate to the sensitivity, purpose, quantity, distribution, and format of the information.
Obtain Valid Consent Where Consent Is the Applicable Basis
Consent requirements depend on the context and legal basis. Where consent is required, it must meet the conditions established by the legislation, including being clear, free, and informed, and requested for specific purposes.
The organization should obtain legal advice for its particular collection and use practices.
What the Law Does Not Mean
"We Are Small, So the Law Does Not Apply"
Company size alone is not a general exemption. The analysis depends on the enterprise's activities and the personal information it processes.
"We Need Specialized Software Before We Can Begin"
Technology may support a mature privacy program, but many initial steps are organizational: identify responsibility, inventory personal information and purposes, document suppliers and systems, establish incident handling, review retention, and align public notices with actual practices.
"Good Faith Makes Non-Compliance Acceptable"
Good faith does not replace the organization's legal obligations. Documented diligence, proportional safeguards, and corrective action may be relevant to the facts of a matter, but they do not prevent enforcement or penalties on their own.
How Law 25 and Cybersecurity Connect
Quebec's private-sector legislation requires reasonable security measures that take into account factors such as the purpose, quantity, distribution, medium, and sensitivity of the information.
The law does not prescribe one universal technical checklist for every business. Appropriate safeguards depend on context.
A properly scoped audit or vulnerability assessment can provide evidence about selected safeguards and gaps. It does not, by itself, prove complete legal compliance. Privacy compliance also involves governance, purposes, transparency, rights, retention, contracts, and legal interpretation.
Common Mistakes
Copying a Generic Privacy Policy
A policy copied from the internet may describe practices the organization does not follow and omit practices it does follow. Public statements should be based on an accurate data and process inventory.
Assuming Small Businesses Are Exempt
The relevant question is not employee count alone. It is whether the enterprise processes personal information in activities governed by the legislation.
Treating GDPR and Law 25 as Identical
The European Union's General Data Protection Regulation and Quebec Law 25 share concepts but are distinct legal regimes with different texts, authorities, territorial rules, and enforcement mechanisms. Compliance with one does not automatically establish compliance with the other.
What to Do Now
- Confirm who is responsible for personal-information protection and whether any delegation is properly documented.
- Map the personal information held, purposes, systems, access, suppliers, transfers, retention, and destruction.
- Compare public privacy information with actual practices.
- Establish or review the privacy-incident register and escalation process.
- Identify projects or disclosures that may require a privacy impact assessment.
- Obtain qualified legal advice where interpretation is required.
Frequently Asked Questions
What penalties are possible?
The Commission d'accès à l'information may impose administrative monetary penalties or initiate penal proceedings depending on the violation.
An administrative monetary penalty may reach $10 million or 2% of worldwide turnover. Certain penal fines may reach $25 million or 4% of worldwide turnover. The applicable regime and amount depend on the nature of the violation and the circumstances.
Is Law 25 the same as the GDPR?
No. They are separate legal regimes. They share some concepts, but their specific requirements, territorial application, regulators, and enforcement mechanisms differ.
We have done nothing so far. Is it too late?
The obligations are already in force. Starting a structured effort now is preferable to waiting for an incident, complaint, customer request, or transaction. Begin with accountability, an inventory of actual practices, incident readiness, and prioritized gaps.
