Regulatory Compliance

Quebec Law 25 Compliance for SMEs

Quebec's Law 25 fundamentally changes how SMEs handle personal data. This comprehensive guide breaks down obligations, penalties, and implementation strategies to keep your business compliant and customer data secure.

Editorial review

Reviewed August 25, 2026 • Reading time: 12 minutes

Legal Disclaimer

This content is informational only and does not constitute legal advice. Law 25 compliance requirements are complex and fact-specific. We strongly recommend consulting with a qualified privacy lawyer or compliance professional to ensure your organization meets all obligations. CyberNow is not liable for interpretations or implementation decisions based on this guide.

1. Law 25 Fundamentals: What You Need to Know

Law 25, enacted in 2021 and effective since December 2024, modernizes Quebec's privacy legislation. It applies to all organizations—for-profit or non-profit—that collect, use, or store personal data of Quebec residents, regardless of where your company operates.

Who Must Comply?

Any SME collecting personal data from Quebec residents must comply. This includes data collected online (website forms, cookies), in-store, by phone, or through partners. Even microenterprises with limited data operations are subject to Law 25.

What is 'Personal Data'?

Personal data is any information that identifies a person: names, emails, phone numbers, IP addresses, cookies, transaction history, job titles, and biometric data. Under Law 25, the scope has expanded to include inferred data and sensitive categories.

Key Timeline

Law 25 has been in effect since December 2024. Organizations should implement core consent and governance mechanisms as part of their compliance program. Enforcement depends on the regulator and the facts of each case.

2. Four Core Obligations Under Law 25

Law 25 establishes four mandatory obligations that form the foundation of compliance. These pillars apply to all organizations and must be implemented proactively.

Obligation 1: Explicit Consent

You must obtain explicit, prior consent before collecting personal data. Consent must be informed, specific, and freely given. Pre-checked boxes are prohibited. You must inform individuals:

  • What data is collected and why
  • How long data is retained
  • Who has access to their data
  • Their rights (access, correction, deletion)
  • How to withdraw consent

Obligation 2: Data Security

Organizations must implement reasonable security measures proportionate to data sensitivity:

  • Encryption (in-transit and at-rest)
  • Access controls and authentication
  • Regular security assessments
  • Notify breaches with diligence when the risk threshold is met, based on risk and impact assessment
  • Data minimization (collect only necessary data)
  • Employee training on data handling

Obligation 3: Individual Rights

Quebec residents have four fundamental rights under Law 25. Organizations must have processes to respond within 45 calendar days:

  • Right to Access: Request copies of their personal data
  • Right to Correction: Update inaccurate information
  • Right to Deletion: Remove data (with limited exceptions)
  • Right to Data Portability: Export data in machine-readable format

Obligation 4: Privacy Impact Assessment (PIA)

For high-risk processing (AI systems, large-scale profiling, biometric data, automated decision-making), complete a PIA before implementation. PIA documents:

  • Data collection and processing purposes
  • Risks to individual privacy
  • Security and technical safeguards
  • Mitigation measures
  • Consultation with stakeholders

3. Penalties & Enforcement

Non-compliance is costly. Quebec's CAIQ has authority to investigate, audit, and impose administrative penalties:

Financial Penalties

Potential administrative penalties can be significant for serious breaches

Investigation Costs

CAIQ can audit your operations and charge investigation costs back to your organization

Data Breach Impact

Public notification, reputational damage, and lawsuits from affected individuals

Injunctions

Courts can order immediate cessation of non-compliant data practices

Real-World Penalty Examples

  • Collecting data without explicit consent: Up to 25M CAD or 4% annual revenue
  • Failing to notify a breach with diligence when required: penalties may apply depending on the circumstances
  • Refusing access requests: Up to 6.25M CAD or 1% annual revenue
  • Inadequate security measures leading to breach: Up to 25M CAD + individual lawsuits

4. Implementation Roadmap: Four-Phase Approach

Compliance is a journey. Implement Law 25 using this practical, four-phase roadmap designed for SMEs:

Weeks 1-2

Phase 1: Assess (Weeks 1-2)

Understand your current data practices and identify gaps:

  • Data Inventory: List all data collected, stored, and processed
  • Audit Current Consent: Review whether consent is explicit and informed
  • Identify High-Risk Processing: Catalog any AI, profiling, or automated decisions
  • Security Review: Evaluate encryption, access controls, and breach response plans
Weeks 3-4

Phase 2: Design (Weeks 3-4)

Build compliance processes into your operations:

  • Consent Framework: Update forms and privacy notices
  • Data Handling Policies: Document retention, access, and sharing rules
  • Privacy Impact Assessment: Complete PIA for high-risk projects
  • Breach Response Plan: Create incident response procedures
Weeks 5-8

Phase 3: Implement (Weeks 5-8)

Roll out compliance controls across your organization:

  • Update Technology: Deploy consent management, encryption, access controls
  • Train Staff: Ensure employees understand data handling obligations
  • Test Processes: Run dry runs of data access/deletion requests
  • Vendor Management: Ensure vendors meet Law 25 standards (Data Processing Agreements)
Ongoing

Phase 4: Monitor & Improve (Ongoing)

Maintain compliance and continuously improve:

  • Monthly Audits: Check consent records and access logs
  • Incident Tracking: Log all data requests and breaches
  • Annual Review: Update policies and privacy notices
  • Staff Refresher Training: Keep team informed of updates

5. AI Tools Under Law 25: ChatGPT, Copilot & Internal LLMs

AI tools like ChatGPT, Microsoft Copilot, and internal language models pose unique Law 25 risks. Personal data (customer names, medical info, financial data) sent to external AI tools may be processed outside Quebec, creating liability.

Risk: External AI Services

When you input data into ChatGPT or similar tools, that data is transmitted to external servers. OpenAI and other providers may use this data for model training. Result: potential unauthorized processing, no consent, Law 25 violation.

Solution: Governance Framework

Implement an AI Governance Policy that requires: (1) Privacy impact assessment before any AI tool use, (2) No personal data in public AI tools, (3) Data anonymization before AI processing, (4) Use of enterprise LLMs or dedicated models with your own hardware/cloud, (5) Data Processing Agreements with AI vendors.

Internal LLMs: Best Practice

Deploy internal language models using frameworks like LLaMA, Ollama, or enterprise OpenAI instances. This ensures data stays within your infrastructure and remains under your control, fully compliant with Law 25.

FAQ: Common Law 25 Questions

Frequently asked questions

Everything you need to know about our cybersecurity services

Have other questions?

Resources & Next Steps

Compliance is ongoing. Here are official resources and recommended next steps for your organization:

Your Implementation Checklist

  • Schedule an assessment with CyberNow to review your current privacy practices
  • Complete your data inventory and identify high-risk processing
  • Update privacy notices and consent forms using Law 25 templates
  • Implement secure data handling practices and breach response procedures
  • Train your team on Law 25 obligations and data responsibilities

Ready to Ensure Law 25 Compliance?

Our compliance experts will audit your current practices, identify gaps, and guide implementation.

Related resources

Continue with the most relevant pages on Law 25 and data protection.