Compliance

Law 25 penalties: the real risk for an SMB

August 18, 2026
Xavier PeichBy Xavier Peich

Everyone quotes the $10M and $25M ceilings. The framework the Commission published starts at $1,000 to $15,000. The real risk sits elsewhere.

Law 25 penalties: the real risk for an SMB

There is a small fear industry around Law 25, and it runs on two numbers: $10 million and $25 million. Both are real, both are in the statute, and neither has much to do with what a Quebec SMB actually risks. For the tour of the obligations themselves, we wrote that one here: what Law 25 asks of an SMB. This article is about the price.

In May 2023 the Commission d'accès à l'information published the framework it uses to decide whether to impose a penalty and how much. That six-page public document contains a table of starting amounts almost nobody quotes, and those amounts are four digits long.

What follows works from that framework, the text of the statute, and the Commission's own published numbers, to rank the risks in the order they actually cost money to a company of 10 to 50 people. The fine is not at the top of the list, and that is not reassuring: what sits above it is harder to insure.

The short answer, for the busy

Law 25 has two penalty regimes. The Commission d'accès à l'information can impose an administrative monetary penalty, capped for a company at $10 million or 2% of worldwide turnover (section 90.12). A penal prosecution before a judge can lead to a fine of $15,000 to $25 million or 4% (section 91). Those are ceilings, not price tags. The framework the Commission published in May 2023 sets the actual starting point: a base amount of $1,000, $4,000, $8,000 or $15,000 for a company depending on the severity of the breach, then adjusted for cooperation, corrective measures and ability to pay. The Commission must first serve a notice of non-compliance, and a company that gives an undertaking the Commission accepts, and honours it, cannot be penalized for those same acts. For an SMB, the cost of the incident, civil liability and lost contracts all outweigh the fine.

The ceilings everyone quotes

The exact figures first, because they are often reported wrong. Section 90.12 of the Act respecting the protection of personal information in the private sector caps an administrative monetary penalty at $50,000 for an individual and, in other cases, at $10 million or 2% of worldwide turnover for the preceding fiscal year, whichever is higher.

Section 91 is a separate, penal regime: the Commission brings a prosecution, a judge rules, and the fine runs from $5,000 to $100,000 for an individual and $15,000 to $25 million or 4% for a company. Those fines double on a repeat offence (section 92.1), and a director who ordered or authorized the act is a party to the offence (section 93).

A ceiling is not a forecast. Nobody prices a speeding ticket at the maximum in the Highway Safety Code, yet that is exactly the shape of the argument when someone sells you compliance by waving $25 million around.

The number nobody quotes: the base amount

Section 90.2 requires the Commission to publish a general framework for applying administrative monetary penalties. It did so on 11 May 2023, and section 5 of that document lays out a two-step method.

First, the designated officer sorts the breach into one of four categories: A for a minor, largely administrative breach, B for a moderate one, C for a serious one, D for a very serious one. The category yields a base amount. For a company: $1,000 in A, $4,000 in B, $8,000 in C, $15,000 in D. For an individual: $500, $1,500, $3,000 and $5,000.

Second, that amount moves up or down on factors the framework lists: the duration and repetition of the breach, the sensitivity of the information, the number of people affected, the corrective steps taken, the degree of cooperation with the Commission, any compensation offered to the people affected, and ability to pay.

Nothing stops a penalty from reaching the ceiling. But a regime that starts at $1,000 and explicitly weighs ability to pay was not designed to sink a 20-person company. It was designed to make it fix things quickly.

The Commission has to warn you first

This is the least known and most useful part. Section 90.4 is categorical: before imposing a penalty, the designated officer must have served a notice of non-compliance and given the company a chance to make representations. No surprise penalty in the mail.

Better still, section 90.1 lets a company, at any time after a breach, undertake to the Commission to take the steps needed to remedy it. If the undertaking is accepted and honoured, no penalty can be imposed for the acts it covers. The statute gives an exit to whoever fixes the problem.

Two deadlines worth remembering: a penalty is prescribed two years after the breach (section 90.10), and the company has 30 days after the notice of claim to request an internal review, then 30 days to contest before the Court of Québec.

What the Commission actually handles

Its 2024-2025 annual report gives the sense of volume: 549 oversight complaints received, up 98% in one year and 227% since 2021-2022, and 514 confidentiality incident notices, 80% of them from the private sector. The most frequent causes were cyberattack (160 notices), human error (110) and ransomware (106).

That report publishes no amount for any administrative monetary penalty imposed. And in its five-year report tabled in May 2026, the Commission still describes the regime as recently implemented and recommends reworking it, because some of the breaches it covers rest on subjective criteria poorly suited to a fast penalty.

That five-year report also holds a detail compliance vendors leave out. Several obligations sold to you as ticking bombs currently cannot trigger any administrative monetary penalty at all: publishing the title and contact details of the person in charge of protecting personal information (section 3.1), publishing your governance policies (section 3.2), running a privacy impact assessment (section 3.3), and keeping a confidentiality incident registry (section 3.8). The Commission recommends adding them, which tells you where this is heading. Do them anyway: they are cheap and they protect you elsewhere.

The honest risk ranking

Here is the order in which a Quebec SMB actually loses money under Law 25.

First: the incident itself. Ransomware on a Friday night means a team that cannot work, an emergency vendor to pay, and clients to call one by one. The 514 notices the Commission received came from organizations that lived through that week. The bill lands before any regulator has opened your file.

Second: civil liability. Section 93.1 requires a court to award punitive damages of at least $1,000 where an unlawful infringement of a right under the Act causes injury and is intentional or results from gross fault. A thousand dollars per person, across 5,000 customers, stops being a thousand dollars. The Desjardins settlement approved in 2022, roughly $200 million for a breach affecting millions of members, shows the scale once the headcount is large.

Quebec case law is not a payout machine, though. In Lamoureux, an unencrypted laptop holding the records of more than 50,000 investors was lost on a train; the class action was dismissed on the merits in 2021 and the dismissal upheld by the Court of Appeal in 2022. The court held that anxiety and having to watch your own accounts must reach a certain severity to be compensable, and it refused punitive damages because the organization had followed best practices afterwards: notify the Commission, tell affected people quickly, retain experts, provide credit monitoring. What protected the defendant was its conduct.

Third: your contracts. The most underrated risk. Large buyers, financial institutions and the public sector push their obligations down to suppliers by contract, with security questionnaires and termination clauses. Losing a $60,000-a-year recurring contract because you cannot fill in a compliance annex happens more often than a penalty from the Commission. It is also the only risk on this list that flips into an advantage when your competitor is not ready.

Fourth: reputation. A decision of the Commission is public, and notices to affected people travel fast.

Fifth, and only then: the regulatory penalty. Preceded by a notice, defusable by undertaking, calculated from $1,000, weighted by your cooperation.

What actually changes your exposure

Almost everything that protects you happens before and after the incident, not in front of the regulator. Knowing what data you hold and being able to delete it. Encrypting what leaves the office. Having written down, on one page, who calls whom in the hours after a discovery. Keeping the registry. Documenting your decisions, including the ones about your security cameras.

This is the work we do when we rebuild a client's site and forms: line up what you collect, what you keep and what you display, while we are in there rather than after a complaint. Our position on services hasn't moved on this: compliance that holds is built into the product, not filed in a binder.

The good reason to deal with Law 25 was never the fine. It is that a company that knows where its data lives reacts better the day something breaks, and signs contracts others cannot. If someone sells you compliance starting at $25 million, ask for the Commission's table.

→ Let's talk about your real exposure, no commitment

This article explains the Law 25 penalty regime to help an SMB place its own risk; it is not legal advice. The amounts, deadlines and remedies cited come from the Act respecting the protection of personal information in the private sector (P-39.1) and the general framework published by the Commission d'accès à l'information, but how they apply depends on the facts of each file. Validate your situation with legal counsel before deciding anything, especially if an incident has already occurred.

Xavier Peich

Written by

Xavier Peich

Law 25 penalties: the real risk for an SMB | Blog PEICH | PEICH