ComplianceBy Xavier Peich

Quebec's Law 25 in daycares (CPE and garderies): children's files, photos and parent portals

The childcare regulation already governs a child's education record. Law 25 covers the rest: parent portals, photos, phones. What a daycare actually owes.

Quebec's Law 25 in daycares (CPE and garderies): children's files, photos and parent portals

A CPE director who takes on Law 25 usually assumes they have to build everything from scratch. Yet a childcare service is one of the few organizations in Quebec whose most sensitive file, the child's, is already regulated line by line by a sector-specific regulation. What we wrote about Law 25 for nonprofits still applies, but part of the work is already done.

What's missing is everything the regulation never anticipated: the parent portal where years of photos and daily notes pile up, the educator's personal phone, the public Facebook post from the holiday party.

The short answer, for the busy

Yes, Law 25 applies to CPEs and garderies. A CPE is a non-profit legal person or a cooperative, a garderie can be owned by any person, and neither appears among the public bodies listed in Quebec's access-to-information act. The private-sector privacy law therefore applies, because it covers any organized economic activity, commercial or not. The Educational Childcare Regulation already governs the child's education record: limited contents, no access or disclosure without the parent's written authorization, the original handed to the parent when the child leaves, and the copy destroyed after one year. Law 25 adds the rest: a person in charge of the protection of personal information, a published policy, a register of confidentiality incidents, parental consent for any child under 14, and a privacy impact assessment before adopting a parent portal. The real risk is in that portal, not in the filing cabinet.

A CPE is not a public body, even a subsidized one

Subsidized and inspected by the ministère de la Famille, a CPE looks like it should fall under the Act respecting access to documents held by public bodies, the way a school does. The text says otherwise. The list of public bodies in section 3 of that Act doesn't mention childcare services. Section 4 adds bodies whose members are mostly appointed by the government or a minister, whose staff are appointed under the Public Service Act, or whose capital stock forms part of the domain of the State. A CPE meets none of these: under section 7 of the Educational Childcare Act, its permit is issued to a non-profit legal person or a cooperative whose board is at least two-thirds parents who use or will use the service. A garderie permit, under section 11, can go to any person who meets the conditions, including a business corporation.

That leaves the private-sector law, which covers the operation of an enterprise within the meaning of article 1525 of the Civil Code: an organized economic activity, "whether or not it is commercial in nature," including providing a service. Caring for 60 children five days a week, with staff and a budget, fits without contortion. The Conseil québécois des services éducatifs à la petite enfance, a sector association, applies the same obligations to childcare services as to businesses in its Law 25 checklist.

A practical point: when the ministère asks for information about children or their parents, section 102 of the Educational Childcare Act requires you to provide it, and the private-sector law allows that disclosure without consent (s. 18).

The regulation has already written half your policy

For the documents that matter most, the Educational Childcare Regulation is more precise than Law 25 itself.

The education record. Section 123.0.1 says it must contain "only" five items: the child's name and date of birth, the parent's name, the start date of services, the periodic portraits of the child's development and, where applicable, documents about any special support given to the child. Apart from internal use and the ministère's inspector, any access or disclosure requires the parent's prior written authorization (s. 57.1 of the Act, s. 123.0.7 of the Regulation). When the child leaves, the original goes to the parent, and the provider keeps a copy for one year, then destroys it (s. 123.0.6).

The registration card. Health, diet, emergency instructions, people authorized to pick up the child (s. 122). Signed by the parent, it is handed back when services end.

The other records. The attendance card is kept six years after services end (s. 123), the copy of the medication file three years (s. 121.3), staff documents three years after the person leaves (ss. 25 and 26).

Law 25 slots into this framework without contradicting it. Its section 23 requires destroying or anonymizing information once its purpose is fulfilled, subject to any retention period set by law. For these documents, that period already exists: your retention schedule fits on half a page, and our article on data retention under Law 25 shows how to organize it.

The parent portal, where the regulation goes quiet

The word "only" in section 123.0.1 has an effect few directors notice: anything that isn't one of the five items isn't part of the education record. Daily photos, nap and meal notes, messages between parents and educators: the regulation sets no retention period for any of it. They fall under the general rule of section 23, which says to destroy them once they've served their purpose.

Software you don't configure keeps everything. A child who spends four years in a CPE can leave thousands of photos and notes behind with a vendor, long after leaving, without anyone ever deciding to keep them.

Three sections of Law 25 govern the software choice. Section 3.3 requires a privacy impact assessment before acquiring or replacing a system that handles personal information, proportionate to how sensitive and how voluminous it is. For the health information and images of 60 children, it needs to be serious without turning into a 40-page report: our privacy impact assessment guide for private businesses shows the format. If the data is hosted outside Quebec, section 17 requires that assessment to conclude the information will be adequately protected, and a written agreement to govern the transfer. And section 18.3 requires a written contract that forbids the vendor from using the information for other purposes or keeping it after the contract ends.

One question remains open, and it belongs with your association or the ministère rather than a vendor: section 123.0.6 requires the education record to be kept "on the premises where the childcare is provided." When the periodic portraits live only in a cloud app, how that requirement applies isn't obvious.

Photos of children: one consent per use

A photo in which a child can be recognized is personal information, since the law covers any information that identifies a person (s. 2), including in visual form (s. 1). For a child under 14, consent is given by the person with parental authority or the tutor (ss. 14 and 4.1). And it must be requested for each specific purpose (s. 14). A single "I authorize photos" checkbox therefore doesn't cover the portal for parents in the group, the CPE's website and the public Facebook page all at once: those are separate uses. An honest form separates them, so a parent can say yes to the portal and no to Facebook. Our article on photo consent for employees and customers covers the wording of the clause.

The educator's phone

The most ordinary incident you can picture in a CPE involves no hacker: a personal phone left on a city bus, with 300 photos of children in its camera roll, synced to a personal cloud account. Losing personal information is a confidentiality incident (s. 3.6): you have to reduce the risk, record it in the register and, if there is a risk of serious injury, notify the Commission d'accès à l'information and the parents. Our privacy incident response plan walks through the procedure.

Prevention is cheap: devices owned by the CPE, locked, and an app that posts photos to the portal without leaving them in the camera roll. The rule fits in one sentence: no photos of children on personal devices.

The realistic minimum for a 60-child CPE

1. The person in charge. By default, it's the person with the highest authority (s. 3.1). In a CPE run by a parent board, the simplest route is a resolution delegating the role in writing to the executive director, as the law allows. Their title and contact information go on the website (see the privacy officer role in an SMB).

2. An inventory of tools. Portal, billing, email, messaging, spreadsheets: for each one, what data, hosted where, kept how long.

3. A retention setting. In the portal, an explicit retention period for photos and daily notes, applied when each child leaves.

4. The documents. A governance policy proportionate to your size (s. 3.2), a privacy policy published on the website (s. 8.2), a photo form with one consent per use, and an incident register, even an empty one.

5. An annual review. Once a year, at the board: departed employees' access, vendors, incidents. A board that is two-thirds parents is a natural ally here: it's their children in the data.

Where to start

The visible part of this compliance runs through your website: the published policy, the privacy officer's contact details, the registration form, the photo gallery. It's the kind of work we handle in our web subscriptions. If your CPE or garderie simply wants to know where it stands, write to us: the first conversation costs nothing.

This article explains a legal framework to help a childcare service ask the right questions; it is not legal advice. The texts cited are authoritative: for a specific situation, consult a lawyer or your association's legal service.

Xavier PeichWritten byXavier Peich