AIKI Secure, services TI gérés et cybersécurité à Montréal
Complete Guide to Law 25 Compliance for Quebec SMEs
Back to blog
compliance

Complete Guide to Law 25 Compliance for Quebec SMEs

Everything you need to know to bring your business into compliance with Quebec's new personal information protection law.

AIKI Secure
July 21, 2026
6 min read
Complete Guide to Law 25 Compliance for Quebec SMEs

What is Bill 25?

Bill 25, formerly known as Bill 64, is Quebec's law modernizing legislative provisions respecting the protection of personal information. It applies to every private-sector business operating in Quebec that collects, uses, or holds personal information, regardless of size. Whether you have three employees or three hundred, if you hold data on clients, patients, or employees, this law applies to you.

This guide covers your obligations, the rights the law grants to individuals, and the penalties for non-compliance.

Your obligations as a business

1. Appoint a privacy officer


Every business must designate a person responsible for the protection of personal information. By default, this role falls to the person with the highest authority in the business, but it can be delegated in writing. This person's contact information must be published on your website.

2. Publish a privacy policy


Your policy must be written in plain, clear language and remain accessible on your website. It should explain what information you collect, for what purposes, who you share it with, how long you retain it, and how a person can exercise their rights.

3. Be transparent at the point of collection


This is a separate obligation from the policy itself. At the exact moment you collect a piece of information, you must inform the person of the purpose, the means used, their rights, any third parties the information might be shared with, the possibility that it may be transferred outside Quebec, the retention period, and who to contact. Many businesses have a general policy but neglect this point-of-collection notice.

4. Obtain valid consent


Consent must be clear, freely given, and informed, and requested separately for each purpose. For sensitive information (health, financial data, biometrics), consent must be express, meaning explicitly given rather than assumed.

5. Offer privacy by default


Since September 2023, any technology product or service you offer to the public must, by default, apply the settings that provide the highest level of privacy. A person shouldn't have to dig through settings to protect themselves. Only cookies are exempt from this rule.

6. Govern automated decisions and profiling


If you make a decision based exclusively on automated processing of personal information, you must inform the person and allow them to submit their comments. And if your site or application uses technology that identifies, locates, or profiles a user, you must notify them and explain how to disable it. This point is gaining importance with the growing use of AI.

7. Conduct a privacy impact assessment


Certain projects require an assessment before moving forward, particularly any project to acquire or develop an information system that processes personal information, and especially before any transfer of information outside Quebec.

8. Oversee your vendors and cross-border transfers


When you entrust information to a vendor (cloud hosting, payroll service, marketing tool), your contract must include protection clauses. And before transferring information outside Quebec, you must assess whether it will receive adequate protection there. For an SMB using cloud services often hosted abroad, this is a point not to be underestimated.

9. Retain and destroy information responsibly


You cannot keep personal information indefinitely "just in case." Once the purpose has been fulfilled, you must destroy or anonymize it according to the applicable rules.

10. Manage confidentiality incidents


You must log all incidents in a register, kept for at least five years. When an incident presents a risk of serious harm, you must notify the Commission d'accès à l'information (CAI) and the affected individuals diligently, meaning within a reasonable time that allows them to protect themselves. An incident without serious risk must still be logged in the register.

11. Keep your registers up to date


In practice, the law requires you to maintain four registers: confidentiality incidents, cross-border data transfers, access requests, and privacy impact assessments. These serve as your proof of compliance if the CAI asks for an account.

Individual rights

La Loi 25 renforce ce qu'une personne peut exiger au sujet de ses propres renseignements. Vos processus doivent permettre d'y répondre.

Bill 25 strengthens what a person can demand regarding their own information. Your processes must be able to respond to these requests.

Right of access: to know what information you hold about them and obtain a copy.
Right of rectification: to have inaccurate, incomplete, or ambiguous information corrected.
Right to withdraw consent: at any time, as easily as it was given.
Right to portability: to obtain the computerized information they provided to you, in a structured, commonly used technological format, or to have it transferred to a third party.
Right to de-indexing: to request that the dissemination of information cease, or that related search results be de-indexed, under certain conditions.
Right to be informed of an automated decision: and to submit comments.

Penalties for non-compliance

Since 2023, the penalty regime has been fully in force, and the CAI is using it. Three types of risk apply.

First, administrative monetary penalties, imposed directly by the CAI without going through the courts, which can reach up to $10 million or 2% of worldwide turnover, whichever is greater.

Second, penal sanctions, in the event of prosecution, which can climb up to $25 million or 4% of worldwide turnover, and which double for repeat offenses.

Finally, the private right of action: an individual can sue the business in court, either individually or through a class action. When the breach is intentional or results from gross negligence, the law sets punitive damages of at least $1,000 per person, in addition to compensation for actual harm.

Implementation timeline

  • September 2022: first provisions (appointment of the privacy officer, obligations related to confidentiality incidents).

  • September 2023: core of the law (privacy policy, consent regime, transparency, privacy by default, PIA).

  • September 2024: final provisions (right to portability, right to de-indexing).
  • Compliance is not a finish line

    One last point, and it matters: Bill 25 is not set in stone. The text, its interpretation by the CAI, and case law continue to evolve, and new technologies like AI constantly raise questions the law hadn't anticipated. Becoming compliant once is not enough. You need to stay attentive to regulatory updates, review your practices periodically, and adapt your processes as your business and the legal framework change. Compliance is a state to maintain, not a box to check once and for all.

    How AIKI Secure can help you with:

  • auditing your current practices and taking inventory of the information you hold;

  • drafting your policies and setting up your registers;

  • implementing the required security measures (access control, encryption, backups, multi-factor authentication);

  • overseeing your vendors and your cross-border transfers;

  • ongoing staff training.
  • To assess where your business stands, contact us or call 514-939-3222.

    Free resourceLaw 25 Compliance GuideDownload our free step-by-step guide to take action.Get the free guide
    Share
    Équipe AIKI Secure prête à sécuriser votre PME

    Need help with your cybersecurity?

    Our experts are here to help you protect your business.