ComplianceBy Xavier Peich

Quebec Law 25: a summary of what an SMB actually has to do (2026)

Quebec Law 25 summarized for an SMB: every obligation turned into a concrete move, the three phases, the official text and what the CAI enforces.

Quebec Law 25: a summary of what an SMB actually has to do (2026)

What people call Quebec's Law 25 on the protection of personal information has a longer official name: An Act to modernize legislative provisions as regards the protection of personal information. Introduced as Bill 64, passed by the National Assembly on September 21, 2021 and assented to the next day, it gets its nickname from its place in the 2021 statute book: chapter 25. People often search for it as "Bill 25", though the bill itself was number 64. You do not read it on its own. It amends the Act respecting the protection of personal information in the private sector, the statute that governs your business, along with the act covering public bodies. "Complying with Law 25" means complying with that private-sector act as the reform rewrote it.

The summaries you find online come in two kinds: law firm analyses, accurate but written for other lawyers, and compliance vendor pages waving the $25 million fine to sell you a package. In between, the owner of a 5-50 person business is left with the practical question: what do I actually have to do?

This page answers in order: what the law is, its three phases, every obligation turned into a concrete move, what the Commission d'accès à l'information (CAI) actually enforces, and where to read the official text. Each obligation links to an article that covers it in depth, for your website as much as for your AI agent projects.

The short answer, for the busy

Quebec Law 25 (Bill 64, passed in 2021) is Quebec's overhaul of its private-sector privacy regime, phased in between September 2022 and September 2024 and now fully in force. It applies to every business that collects personal information in Quebec, with no size exemption. For an SMB, the credible minimum comes down to five moves: designate a privacy officer (by default, the person with the highest authority in the company) and publish their contact information; post a privacy policy in plain language; collect only the information you actually need; keep a register of confidentiality incidents and report those creating a risk of serious injury to the Commission d'accès à l'information; and run a privacy impact assessment before any new information system or any transfer of personal data outside Quebec. Maximum administrative penalties reach $10 million or 2% of worldwide turnover, but actual enforcement so far has targeted biometrics and excessive collection.

What is Law 25, and who does it apply to?

Law 25 takes an act that has been in force since 1994 and tightens it on four fronts (governance, transparency, consent and individual rights), adding what the original regime lacked: penalties with teeth.

Personal information is any information that relates to a natural person and allows that person to be identified, directly or indirectly (section 2). A client's name and email address qualify. Sensitive information, meaning information that by its medical, biometric or otherwise intimate nature, or by its context, carries a high level of reasonable expectation of privacy (section 12), requires express consent.

First point most summaries skip: the law covers anyone carrying on an enterprise, with no size threshold. A freelancer with a contact form is covered, just like a multinational. Nonprofits are not automatically exempt either: their case is covered here. What varies is proportionality, and the law says so itself: policies must be proportionate to the nature and scope of the business's activities (section 3.2). Nobody expects an eight-person company to run a bank's governance program. And if you also sell in Europe, Law 25 does not exempt you from the GDPR, or the reverse: here is the comparison.

The three phases of Law 25: 2022, 2023, 2024

The reform came into force in stages, each time on September 22, following the schedule set in section 175 of the act.

September 22, 2022. The foundations: designating a privacy officer, managing confidentiality incidents (mitigation, notice to the CAI and to affected individuals, the register) and disclosing information without consent to complete a commercial transaction, such as selling the business.

September 22, 2023. The bulk of the reform: governance policies, the privacy policy, transparency and consent rules, privacy impact assessments, transfers outside Quebec, automated decisions, profiling technologies, destruction or anonymization, de-indexing, and the penalty regime.

September 22, 2024. The right to data portability: getting your computerized personal information in a structured, commonly used technological format, or having it sent to another organization.

Since then, the law has been fully in force. There is no grace period left.

Law 25 obligations, one by one

Each obligation, the section that carries it and the move that answers it. Several can be handled in the same afternoon.

1. A privacy officer, published on your site. The person with the highest authority in the company is the person in charge of protecting personal information by default, and can delegate the role in writing, in whole or in part (section 3.1). Their title and contact information must be published on your website. Move: one line in your privacy policy, plus a written delegation if it is not you. The role in an SMB, in detail.

2. Governance policies and a privacy policy. Section 3.2 requires internal rules on retention and destruction, staff roles and complaint handling, approved by the privacy officer and described publicly in plain terms. Section 8.2 requires, if you collect information by technological means, a privacy policy published on your site. Move: one clear public page and an internal document of a few pages. Privacy policy structure and template; for staff roles, training employees without buying a $3,000 course.

3. Collect only what you need, and say why. You must determine your purposes before collecting, collect only what those purposes require (sections 4 and 5), and tell the person, at the time of collection, the purposes, their rights of access and rectification, and their right to withdraw consent (section 8). Move: remove every form field nothing justifies.

4. Consent that is worth something. Consent must be manifest, free, enlightened and given for specific purposes, requested for each purpose in clear and simple terms and, when in writing, presented separately from any other information (section 14). Otherwise it is without effect. Using information for a new purpose requires fresh consent, with some exceptions, and commercial prospecting is never a compatible purpose (section 12). Move: no more pre-checked boxes or all-in-one acceptance. Consent form template and examples.

5. Your website: cookies and analytics. If your site uses technology that can identify, locate or profile visitors, you must tell them beforehand and explain how to activate those functions (section 8.1). The privacy settings of a technological product offered to the public must also default to the highest level of confidentiality (section 9.1). Move: an honest banner, or tools that do not need one. Cookies, forms and analytics, and measuring traffic without cookies.

6. Confidentiality incidents and the register. Unauthorized access, use or disclosure, or the loss of personal information, is an incident (section 3.6). You must reduce the risk of injury, promptly notify the CAI and the people affected when the risk of serious injury is real (section 3.5), and log every incident, even minor ones, in a register (section 3.8) whose contents the regulation says you keep for at least five years. The CAI can demand a copy. Move: a one-page table, created before the first incident. Keeping the register without drowning in it, and the first 72 hours of a ransomware attack.

7. The privacy impact assessment (PIA). It is mandatory before any project to acquire, develop or overhaul an information system or electronic service delivery involving personal information, and must be proportionate to the information's sensitivity, volume and use (section 3.3). Move: a few serious pages before you sign with new software. The guide to privacy impact assessments for Quebec businesses, the case of an AI agent, or the document itself from our privacy impact assessment generator.

8. Retention and destruction. Once the purposes of collection are achieved, you must destroy the information or anonymize it, subject to a retention period set by another law (section 23). Anonymization follows a regulation in force since May 30, 2024. Law 25 sets no retention periods of its own. Move: a one-page retention schedule. What the law says, and does not say, about retention.

9. Transfers outside Quebec. Before communicating information outside Quebec, or entrusting a provider outside Quebec with collecting or storing it for you, a PIA is mandatory, followed by a written agreement (section 17). The threshold really is "outside Quebec", not outside Canada: a host with servers in Ontario or the United States triggers the obligation. Move: a list of your cloud providers and where they store your data. The case of AI tools on American servers, and a complete PIA for a payroll platform hosted in Ontario.

10. Automated decisions. If a decision about a person rests exclusively on automated processing, you must tell them no later than when you inform them of the decision, explain on request the main factors behind it, and let them submit observations to someone who can review it (section 12.1). Move: find your automated sorting of job applications or requests. What section 12.1 requires.

11. Individual rights. Anyone can request access to their information (section 27), rectification if it is inaccurate, incomplete or equivocal (section 28), its communication in a structured format (portability, since 2024), and that you stop disseminating it or de-index a hyperlink attached to their name when the dissemination breaks the law or, under certain conditions, causes them serious injury (section 28.1). The privacy officer must answer in writing within 30 days, failing which the request is deemed refused (section 32). Move: know which tools hold a client's data, so you can extract it in an hour.

One special case deserves a warning: biometrics. Any database of biometric characteristics must be disclosed to the CAI at least 60 days before it goes live, and identity verification by biometrics requires express consent. The fingerprint time clock bought without a second thought is the classic trap. Cameras, for their part, are held to the necessity test: what a store can actually film.

What the CAI has actually sanctioned since 2022

The scary numbers are real, but they are ceilings. The CAI can impose administrative monetary penalties of up to $10 million or 2% of worldwide turnover, whichever is greater (section 90.12). Penal prosecutions can lead to fines for a business of $15,000 up to $25 million or 4% of worldwide turnover (section 91), doubled for repeat offences. Those ceilings were calibrated for tech giants. The real risk for an SMB is priced out here.

As of this writing (September 2026), the CAI has not publicly announced a single administrative monetary penalty against a named company. Its record since the reform consists of orders and recommendations, and it draws a very clear profile.

In September 2024, its oversight division issued a landmark decision: it ordered a printing company to stop using facial recognition to control employee access. In February 2025, it prohibited Metro Inc. from putting into service a biometric database meant to identify shoplifters, for lack of express consent. In April 2026, it found that collection necessary without lifting the ban, which Metro is challenging before the Court of Québec. In February 2026, a decision on a municipality's hiring process confirmed that systematic background checks remain subject to the necessity test. In May 2026, the joint investigation into OpenAI concluded with recommendations on consent and data retention.

Three lessons. First, biometrics is the red zone: it is where the CAI strikes hardest. Second, the necessity test is enforced for real: collecting data "just in case" is precisely what the recent decisions condemn. Third, the machine almost always starts with a complaint: an employee, a customer, a job applicant. Your real exposure is not a $10 million fine tomorrow morning; it is an investigation ending in an order that can shut down a practice you built a process on.

A detail the fear merchants leave out: the failures that can draw an administrative penalty (section 90.1) are failing to inform people, collecting, using, retaining or destroying information in breach of the law, failing to report an incident, inadequate security measures, and automated decisions. The privacy officer, the policies, the PIA and the register are not on that list. Do them anyway: they are what an investigator asks for first, and a file where none of them exist starts badly on everything else.

The credible minimum, and the order I would do it in

Eleven obligations, but not eleven projects. Starting from zero, I would follow the order of what is visible from outside and what gets sanctioned.

This week: moves 1 and 2. Publish the privacy officer and a clear privacy policy. It is the first thing a complainant or an investigator checks, and it costs almost nothing. A policy auto-generated for California does not count.

This month: moves 3 and 6. Clean up your forms and create the register. The first reduces your exposure to the test the CAI applies most; the second has to exist before the incident.

Before your next software purchase: moves 7 and 9. Do the PIA and check where the data goes. That is where most accidental transfers outside Quebec happen.

The rest comes down to adjusting existing practices. All told, a week of focused work, not a transformation program.

Where your AI tools fit in

If your SMB uses or is considering AI agents, the obligations stay the same, with two extra pressure points. The first: the tools your employees already use without telling you. A client file pasted into a consumer AI tool is exactly the kind of incident your register will have to document: that is shadow AI. The second: most AI models run on American servers, which triggers the transfer PIA (move 9), and an agent that sorts job applications falls under automated decisions (move 10).

That is why compliance is decided at design time. A website or agent built with these obligations in mind costs barely more; the same system retrofitted afterwards costs a rebuild.

Where to read the official text of Law 25 (PDF)

Anyone searching for a "Law 25 PDF" usually lands on the amending act itself: 175 sections that mostly say "replace this paragraph with that one". The text you want is the amended act, kept up to date.

The Act respecting the protection of personal information in the private sector (P-39.1) on LégisQuébec is the official consolidated version, with its regulations on incidents and anonymization. It is also available as a PDF. Law 25 as passed in 2021 is on the Publications du Québec site. Finally, the CAI publishes a summary of the main changes (in French) that helps you find your way, but the LégisQuébec text is what prevails.

Where to start

If your next project is a new website or an AI agent, the simplest path is to build compliance into the quote. That is what we do: sites and agents compliant by design, register and PIA included.

→ Tell us about your project

This article summarizes a law to help an SMB set priorities; it is not legal advice. Your exact obligations depend on your situation: for ambiguous cases (biometrics, sensitive data, international transfers), consult a specialized lawyer. The official texts and CAI decisions prevail.

Xavier PeichWritten byXavier Peich