Since September 2022, every Quebec business must designate and publish a privacy officer. What the role actually involves at SMB scale.

Of all the obligations in Quebec's Law 25, this is the oldest and the easiest to check. Since September 22, 2022, every business operating in Quebec must have a person in charge of the protection of personal information, commonly called a privacy officer, and must publish that person's title and contact information. Not since 2023 or 2024: 2022. It was the very first wave of the reform, in force a full year before the bulk of the obligations we summarized here. Almost four years later, a large share of Quebec SMBs still haven't done it.
The paradox is that this is also the cheapest obligation in the entire law. No software to buy, no mandatory consultant, no report to file. One decision, one sentence on your website. This article explains what the law actually says, how the role works, what the job looks like in a company of 5 to 50 people, and what the new officer should do first.
Since September 22, 2022, every business operating in Quebec must have a person in charge of the protection of personal information, with no size exemption. By default, the law assigns the function to the person with the highest authority in the business, meaning the owner or top executive; that person can delegate it, in writing, in whole or in part, to anyone. The officer's title and contact information must be published on the company's website or, if there is no website, made accessible by other appropriate means. No registration with the Commission d'accès à l'information is required. The role involves approving privacy governance policies, answering access and rectification requests within 30 days, taking part in privacy impact assessments, and being consulted when a confidentiality incident occurs. In an SMB, this amounts to a few hours per quarter, not a hire.
Section 3.1 of Quebec's Act respecting the protection of personal information in the private sector fits in three sentences. The first states the principle: every person carrying on an enterprise is responsible for the personal information it holds. The second gives the principle a face: within the enterprise, the person with the highest authority ensures the Act is complied with, and exercises the function of person in charge of the protection of personal information.
Read the mechanism carefully, because it is clever. The legislator did not write "the business must appoint an officer", which would have left the eternal excuse open: nobody has been appointed yet. It wrote that the function is exercised by default. The day the provision came into force, every business owner in Quebec became their company's privacy officer, whether they knew it or not. There is no such thing as a vacant seat; there are only owners who don't know they're sitting in it.
And the obligation has no size threshold. The solo consultant with a contact form, the three-person firm, the forty-employee shop: same rule. What varies is the amount of work, not the existence of the function.
The third sentence of section 3.1 is the one that can be checked from the outside: the title and contact information of the privacy officer must be published on the company's website or, if it has no website, made accessible by any other appropriate means.
Run the test right now: open your own site and look for who your privacy officer is. If the answer isn't there, you are in breach of a four-year-old obligation, and you are far from alone. In February 2024, Le Devoir reported, based on data from a consent-management vendor, that barely 3% of Quebec businesses had adapted to the law and that 60% of SMBs had no plans to. The numbers come from a company selling compliance tools, so apply the usual discount; the underlying trend is easy to confirm by browsing ten SMB websites in your area.
Why does this publication matter so much? Because it is the visible part of your compliance. An unhappy client, a rejected job candidate, a former employee considering a complaint to the Commission d'accès à l'information: the first thing that person, or the investigator who follows, will look for is the officer listed on your site. Its absence proves little in law, but it sets the tone of the file: a business that hasn't done the simplest thing in the Act probably hasn't done the rest either.
In practice, all it takes is a block in your privacy policy, repeated or linked in the footer: the person's title (not necessarily their name, but the title and a way to reach them) and an email address someone actually reads. That is all the law requires.
By default, then, it's you. The law allows the function to be delegated in writing, in whole or in part, to anyone. The text imposes no restriction: a member of management, an office administrator, an outside consultant. The Commission d'accès à l'information spells out the spirit of it, though: the delegate should be competent in the matter and hold real decision-making power, and the person with the highest authority remains accountable for implementing the Act. You can delegate the function; you cannot delegate the responsibility. The CAI adds that leadership must give the officer the human, technical and financial resources the job needs.
At SMB scale, the choice is simple. In a company of fewer than ten people, the owner usually keeps the function: delegating it would create more friction than value. Between ten and fifty, it typically goes to whoever already runs administration or operations, the person who knows where the data lives. The delegation itself fits on one page: who, what, since when, signed by the owner. You don't need a twenty-page contract; you need something in writing.
Be wary, on the other hand, of outsourcing the function to a turnkey compliance service billed monthly. Nothing forbids it, but a useful officer has to know your actual processes, and a provider managing four hundred SMBs remotely does not. You end up paying for a name on your website, not a function being exercised.
What does the officer actually do once designated? The Act and the CAI's guidance describe a precise job. They approve the company's privacy governance policies, starting with the privacy policy displayed on your site. They receive and handle access and rectification requests, with 30 days to respond. They take part in privacy impact assessments when the company acquires a new system or sends data outside Quebec. They are consulted during a confidentiality incident to assess the risk of harm. And they are the person your vendors must notify without delay if confidentiality is breached on their side.
On paper, the list looks heavy. In the reality of a fifteen-person company, the volume is low: access requests come a few times a year, not a few times a week, and incidents, if you have any, are rare. The officer's real job is to be reachable, to know the procedure before it's needed, and to ask one reflex question every time the company adopts a tool or launches a form: what personal information, for what purpose, stored where? A few hours per quarter at cruising speed. Not a hire, not even a half-day a week; a responsibility attached to someone who already does something else.
If you have just discovered the function belongs to you, here is the realistic sequence, without drowning in it. The first month is for seeing clearly: inventory the places where personal information lives in your company. The CRM, the email inboxes, the website forms, payroll, the pile of résumés received. A one-page list is enough, and the exercise almost always surfaces data nothing justifies keeping anymore.
The second month makes compliance visible: publish your title and contact information on the site, put up a privacy policy in plain language, and check that your forms collect valid consent rather than a pre-checked box inherited from a US template.
The third month prepares for the day something goes wrong: create the confidentiality incident registry, even empty, and agree on who does what if an email goes to the wrong recipient or a laptop disappears. After that, the role shrinks to a maintenance reflex: every new tool, form or vendor goes through the officer's question before it enters the company.
The minimal move happens this week: decide who carries the function, put the delegation in writing if it isn't you, and publish the title and contact information on your site. One hour of work to leave the group of companies that have done nothing.
And if your site has neither an officer block nor a policy worth the name, that is exactly the kind of thing we build in by default with a website subscription: visible compliance is part of the product, not an add-on.
This article explains a legal obligation to help an SMB take action; it is not legal advice. Your exact obligations depend on your situation: for edge cases (sensitive data, biometrics, complex corporate structures), consult a specialized lawyer. The text of the Act and the guidance of the Commission d'accès à l'information prevail.
Written by