The grace period is over
When Law 25 came fully into force, many companies took a wait-and-see approach. Eighteen months later, that strategy no longer holds. The obligations are very real, citizens now know their rights, and Quebec's privacy regulator is handling a growing volume of complaints.
The private right of action, in effect since September 2024, adds one more risk: an individual can now claim damages when there is a breach of the law.
Where SMBs get caught
No designated privacy officer
Every company must appoint a person responsible for personal information protection and publish their contact details. This is often the first thing checked, and many websites still do not display it.
Generic privacy policies
Copy-pasting a policy found online is not enough. It must reflect what your company actually collects, why, and how long you keep the data.
No incident plan
In the event of a breach that presents a serious risk, you must notify the regulator and the affected individuals, and keep a register. Without a process prepared in advance, you will not meet the deadlines.
Consent and cookies
Cookie banners that turn on tracking by default are a common problem. Consent must be clear and freely given.
Where to start
Compliance is a project, not a checkbox
Law 25 is not a form you fill out once. It is an ongoing process that touches your tools, your contracts and your habits. The good news is that a structured approach resolves most of the risk within a few weeks.
Read our Law 25 compliance guide or talk to an advisor for a review of your business.


