Compliance

Law 25 for nonprofits: obligations and exemptions

August 4, 2026
Xavier PeichBy Xavier Peich

Does Law 25 apply to nonprofits? No automatic exemption: the enterprise test, the CAI's position, and what a three-person organization should do.

Law 25 for nonprofits: obligations and exemptions

"We're a nonprofit, Law 25 doesn't apply to us." That sentence has been circulating in board meetings since 2022, and it reassures everyone: no privacy officer to appoint, no policy to publish, no register to keep. The problem is that in most cases it is wrong. If you already know the Law 25 obligations for Quebec SMBs, most of them apply to your organization too, with one aggravating factor: a nonprofit's data is often more sensitive than a retailer's.

The myth rests on a single word. The statute governing the private sector is the Act respecting the protection of personal information in the private sector, and it applies to those who carry on an "enterprise". A community organization reads that word, decides it does not recognize itself, and closes the file. But "enterprise", in this context, is a legal term whose definition does not say what everyone assumes.

This article explains the real applicability test, the position of the Commission d'accès à l'information (CAI), why your donor lists and beneficiary files are an aggravated case, and what a three-person organization should actually do.

The short answer, for the busy

No, nonprofit organizations are not exempt from Law 25. Quebec's Act respecting the protection of personal information in the private sector applies to anyone who carries on an enterprise within the meaning of article 1525 of the Civil Code of Québec, that is, an organized economic activity, "whether or not it is commercial in nature". The Commission d'accès à l'information confirms the Act can cover nonprofits and that a case-by-case analysis is required. An organization that collects membership dues, sells services, runs structured fundraising campaigns or delivers programs is very likely carrying on a covered activity. Its obligations are then the same as a business's: a person in charge of personal information protection, a published privacy policy, an incident register, and express consent for sensitive information. Administrative penalties can reach $10 million or 2% of worldwide turnover, whichever is higher.

"Enterprise" does not mean what you think

Section 1 of the Act points to article 1525 of the Civil Code of Québec, which defines carrying on an enterprise as the exercise "of an organized economic activity, whether or not it is commercial in nature, consisting of producing, administering or alienating property, or providing a service".

Read the middle clause again: "whether or not it is commercial in nature". It carries all the weight. The legislator explicitly provided that an organized economic activity does not need to seek profit to be an enterprise. An organization that delivers services to beneficiaries, collects membership dues, employs staff, manages grants and runs fundraising campaigns is carrying on an organized economic activity. The fact that surpluses go back into the mission instead of to shareholders changes nothing about the test.

The consequence is direct: nonprofit status, which is a matter of legal structure and taxation, does not answer the Law 25 question, which is a matter of activity. Two organizations with identical letters patent can get two different answers.

What the CAI and the courts say

The CAI's position is published on its page on the Act's scope of application: the Act covers persons carrying on an enterprise in Quebec "but can also cover other organizations such as nonprofit organizations", and "a case-by-case analysis must be carried out to determine whether the organization truly exercises an organized economic activity". The CAI adds that a lawyer's help may be required. In other words: no exemption in principle, and no automatic coverage either. You look at what the organization actually does.

The courts have marked both ends of the spectrum. In 2000, the Court of Québec held that a Jehovah's Witnesses congregation was not an enterprise: receiving donations and administering the property bought with them was not enough, because the principal activity remained eminently religious. At the other end, in 2021, the Superior Court concluded that student associations, textbook nonprofits, were carrying on an organized economic activity by offering health insurance coverage to their members, a decision essentially upheld on appeal in 2023. The criterion is the presence of a structured offer of goods or services, an audience receiving it, and an organization sustaining it. The status itself carries no weight.

For the large majority of active nonprofits, honesty with that test leads to an uncomfortable conclusion: a food bank, a sports club with paid registrations, a cultural organization selling tickets, a professional association collecting dues are all providing organized services. The real exemption mostly covers groups whose activity has almost nothing economic about it: the purely religious, activist or social circle that sells nothing, runs no structured program and manages no clientele.

The nonprofit paradox: small structure, heavy data

Here is what should hold a board's attention more than the applicability debate. An online store holds names, addresses and purchase histories. A community organization often holds far worse: its donors' financial situation, its beneficiaries' health or social circumstances, the background checks of volunteers working with vulnerable people.

The Act has a category for this data: "sensitive" personal information, which by its nature, "medical, biometric or otherwise intimate", commands a high reasonable expectation of privacy. The regime is stricter: consent must be express, both to use the information for another purpose and to communicate it to a third party. No implied consent, no pre-checked boxes. Our articles on compliant consent forms and on the privacy policy Law 25 requires show what this looks like in practice.

And there is a detail almost no nonprofit knows, even though it targets them directly. Section 12 of the Act lists the "compatible" purposes for which information can be reused without fresh consent, then specifies that commercial or philanthropic prospecting can never be considered a compatible purpose. Fundraising solicitation is named in the statute, on the same footing as telemarketing. Reusing an event's participant list for a fundraising campaign, or swapping donor lists with a friendly organization, requires consent given for that specific purpose.

What a three-person nonprofit should do

The Act does not ask a community organization to build a legal department. Its obligations are proportionate: the statute says policies must fit the nature and scale of your activities. Here is the realistic version, the one an executive director can carry out with a few hours and some consistency.

First, the person in charge of personal information protection. By default, it is the person with the highest authority, so your executive director or your board chair. The function can be delegated in writing, in whole or in part. The officer's title and contact information must be published on your website. It is the most visible and least costly obligation: one board resolution, one paragraph on the site.

Next, the inventory. Before any policy, answer three questions: what information do you hold (donors, members, volunteers, beneficiaries), where does it live (shared spreadsheet, newsletter tool, database, paper files), and who has access. In an organization run by rotating volunteers, the honest answer is often "too many people, for too long". That is exactly what the exercise is meant to reveal.

Then, the documents: a privacy policy published in simple, clear terms, express consent forms wherever you touch sensitive information, and a confidentiality incident register, mandatory even if it stays empty, of which the CAI can request a copy. If an incident presents a risk of serious injury, you must notify the CAI and the affected individuals promptly.

Finally, governance over time. A nonprofit's real risk is turnover: access rights that outlive mandates, the donor spreadsheet still sitting on the laptop of a volunteer who left two years ago. An annual access review, written into the board calendar, covers most of that risk.

The penalties, and the risk that actually matters

The numbers are deterrent on paper: administrative monetary penalties up to $10 million or 2% of worldwide turnover, and penal fines up to $25 million or 4%. A nonprofit has no worldwide turnover to speak of, and the CAI issues notices of non-compliance before imposing penalties. Nobody is shutting down your food bank over a missing policy.

The real risk lies elsewhere. An organization lives on the trust of three audiences: donors, beneficiaries, funders. A badly handled incident, a donor list in circulation, an exposed beneficiary file hits all three at once. And more and more funders and insurers ask for proof of compliance before signing. Law 25 compliance becomes a condition of access to funding before it is ever a question of fines.

The most visible part of that compliance runs through your website: a published policy, the officer's contact information displayed, forms that collect consent properly. That is exactly the kind of work we handle in our web subscriptions, and if your organization simply wants to know where it stands, write to us: the first conversation costs nothing.

This article explains a legal framework to help an organization ask the right questions; it is not legal advice. Whether a nonprofit is subject to the Act respecting the protection of personal information in the private sector is assessed case by case, as the CAI itself points out. For a specific situation, consult a lawyer.

Xavier Peich

Written by

Xavier Peich

Law 25 for nonprofits: obligations and exemptions | Blog PEICH | PEICH