What is Bill 25?
Bill 25, formerly known as Bill 64, is Quebec's law modernizing legislative provisions respecting the protection of personal information. It applies to every private-sector business operating in Quebec that collects, uses, or holds personal information, regardless of size. Whether you have three employees or three hundred, if you hold data on clients, patients, or employees, this law applies to you.
This guide covers your obligations, the rights the law grants to individuals, and the penalties for non-compliance.
Your obligations as a business
1. Appoint a privacy officer
Every business must designate a person responsible for the protection of personal information. By default, this role falls to the person with the highest authority in the business, but it can be delegated in writing. This person's contact information must be published on your website.
2. Publish a privacy policy
Your policy must be written in plain, clear language and remain accessible on your website. It should explain what information you collect, for what purposes, who you share it with, how long you retain it, and how a person can exercise their rights.
3. Be transparent at the point of collection
This is a separate obligation from the policy itself. At the exact moment you collect a piece of information, you must inform the person of the purpose, the means used, their rights, any third parties the information might be shared with, the possibility that it may be transferred outside Quebec, the retention period, and who to contact. Many businesses have a general policy but neglect this point-of-collection notice.
4. Obtain valid consent
Consent must be clear, freely given, and informed, and requested separately for each purpose. For sensitive information (health, financial data, biometrics), consent must be express, meaning explicitly given rather than assumed.
5. Offer privacy by default
Since September 2023, any technology product or service you offer to the public must, by default, apply the settings that provide the highest level of privacy. A person shouldn't have to dig through settings to protect themselves. Only cookies are exempt from this rule.
6. Govern automated decisions and profiling
If you make a decision based exclusively on automated processing of personal information, you must inform the person and allow them to submit their comments. And if your site or application uses technology that identifies, locates, or profiles a user, you must notify them and explain how to disable it. This point is gaining importance with the growing use of AI.
7. Conduct a privacy impact assessment
Certain projects require an assessment before moving forward, particularly any project to acquire or develop an information system that processes personal information, and especially before any transfer of information outside Quebec.
8. Oversee your vendors and cross-border transfers
When you entrust information to a vendor (cloud hosting, payroll service, marketing tool), your contract must include protection clauses. And before transferring information outside Quebec, you must assess whether it will receive adequate protection there. For an SMB using cloud services often hosted abroad, this is a point not to be underestimated.
9. Retain and destroy information responsibly
You cannot keep personal information indefinitely "just in case." Once the purpose has been fulfilled, you must destroy or anonymize it according to the applicable rules.
10. Manage confidentiality incidents
You must log all incidents in a register, kept for at least five years. When an incident presents a risk of serious harm, you must notify the Commission d'accès à l'information (CAI) and the affected individuals diligently, meaning within a reasonable time that allows them to protect themselves. An incident without serious risk must still be logged in the register.
11. Keep your registers up to date
In practice, the law requires you to maintain four registers: confidentiality incidents, cross-border data transfers, access requests, and privacy impact assessments. These serve as your proof of compliance if the CAI asks for an account.
Individual rights
La Loi 25 renforce ce qu'une personne peut exiger au sujet de ses propres renseignements. Vos processus doivent permettre d'y répondre.
Bill 25 strengthens what a person can demand regarding their own information. Your processes must be able to respond to these requests.
Right of access: to know what information you hold about them and obtain a copy.
Right of rectification: to have inaccurate, incomplete, or ambiguous information corrected.
Right to withdraw consent: at any time, as easily as it was given.
Right to portability: to obtain the computerized information they provided to you, in a structured, commonly used technological format, or to have it transferred to a third party.
Right to de-indexing: to request that the dissemination of information cease, or that related search results be de-indexed, under certain conditions.
Right to be informed of an automated decision: and to submit comments.
Penalties for non-compliance
Since 2023, the penalty regime has been fully in force, and the CAI is using it. Three types of risk apply.
First, administrative monetary penalties, imposed directly by the CAI without going through the courts, which can reach up to $10 million or 2% of worldwide turnover, whichever is greater.
Second, penal sanctions, in the event of prosecution, which can climb up to $25 million or 4% of worldwide turnover, and which double for repeat offenses.
Finally, the private right of action: an individual can sue the business in court, either individually or through a class action. When the breach is intentional or results from gross negligence, the law sets punitive damages of at least $1,000 per person, in addition to compensation for actual harm.
Implementation timeline
Compliance is not a finish line
One last point, and it matters: Bill 25 is not set in stone. The text, its interpretation by the CAI, and case law continue to evolve, and new technologies like AI constantly raise questions the law hadn't anticipated. Becoming compliant once is not enough. You need to stay attentive to regulatory updates, review your practices periodically, and adapt your processes as your business and the legal framework change. Compliance is a state to maintain, not a box to check once and for all.
How AIKI Secure can help you with:
To assess where your business stands, contact us or call 514-939-3222.


