Compliance

Training your employees on Law 25 without buying a $3,000 course

September 7, 2026
Xavier PeichBy Xavier Peich

The word "training" is not in section 3.2. What Law 25 expects of your staff fits in one page, 45 minutes and three habits.

Training your employees on Law 25 without buying a $3,000 course

There is a market for Law 25 training, and what it mostly sells is relief. You read somewhere that the law requires your staff to be trained, a vendor offers a session per employee, and the quote lands in four figures for a team of twenty. Before signing, reread what the law actually asks. We covered what Law 25 asks of an SMB elsewhere; this article is about your people.

Two things are true at once, which is what makes the subject confusing. The word "training" appears nowhere in the section that imposes your governance policies. And the Commission d'accès à l'information, in its January 2026 guide, prints "train and raise awareness among staff" in bold, in a list where bold marks the obligations the law imposes. The two reconcile easily, and the reconciliation points to something an SMB can deliver on a Tuesday afternoon.

The short answer, for the busy

Law 25 nowhere requires a Quebec company to buy a training course. Section 3.2 of the Act respecting the protection of personal information in the private sector requires governance policies that set out "the roles and responsibilities of the members of its personnel throughout the life cycle" of the information, approved by your privacy officer and summarized publicly on your website. The word "training" is not there: the legislature wrote it for public bodies, in section 63.3 of the Access Act, and left it out for businesses. But in the incident-prevention guide it published in January 2026, the Commission d'accès à l'information puts "train and raise awareness among staff" in bold, meaning among the obligations flowing from section 10 on security measures. What an SMB owes is modest: a one-page policy, a short session, and a written record of who attended.

What the law asks, and the word that isn't in it

Section 3.2 runs to a single paragraph. Every business must establish and implement policies governing its handling of personal information. Those policies must cover retention and destruction, set out "the roles and responsibilities of the members of its personnel throughout the life cycle of that information", and provide a complaint process. They must be proportionate to your activities, approved by your privacy officer, and summarized on your website.

Read the wording: roles and responsibilities, not classroom hours. The legislature knew perfectly well how to write the other version, because it wrote it elsewhere. Section 63.3 of the Access Act, which covers public bodies, repeats the staff roles and responsibilities word for word, then adds a sentence the private sector does not get: those rules "include a description of the training and awareness activities the body offers its personnel". A government department has to publish a description of its training program. Your company does not.

The Commission, for its part, puts training in bold

Do not conclude from that that your employees have nothing to know. In January 2026 the Commission published two free documents for businesses: the guide "Prévenir les incidents de confidentialité" and its companion checklist. The guide lays out seven steps for implementing section 10, the reasonable-security-measures obligation, and notes at step 4 that "the items in bold are obligations provided for in the law".

Among the tactical measures, exactly one is bold: "train and raise awareness among staff". So the regulator treats staff awareness as one of the security measures section 10 already requires of you. The scope it has in mind follows in ordinary type, in brackets: strong passwords, malware and social-engineering risks, clean-desk principles. Not a law seminar.

The distinction changes your exposure. Section 90.1 lists the breaches that can draw an administrative monetary penalty: failing to take security measures under section 10 is on that list, section 3.2 is not. You will not be penalized for lacking a training program; you can be penalized for what an unaware team eventually does. We covered that regime in the article on Law 25 penalties.

What breaks is human, and ordinary

The Commission's 2024-2025 annual report gives the texture of the problem: it received 514 confidentiality incident notices, 80% of them from the private sector. The breakdown by cause, which counts incidents with several causes and therefore does not add up cleanly, puts cyberattack first at 160 notices, human error right behind at 110, ransomware at 106 and accidental disclosure at 100. The direction is clear, and it does not point at your firewall.

The guide is more concrete still. Its list of example incidents includes sending a communication to the wrong person, and disclosing personal information "through gossip inside or outside the workplace (for example on the bus)". That is the real curriculum for your session. Nobody needs section 90.12 memorized. Somebody needs to know that recounting a client's file on the northbound 55 is a confidentiality incident within the meaning of the Act.

The same guide lists "lack of staff knowledge or training" among the potential causes of risk, alongside being "unaware" of a policy that does exist. A policy nobody has read is treated as a policy that isn't there.

Doing the math on the $3,300 course

Let's price the quote. Cégep Limoilou offers a three-hour online course, "Loi 25 : Protection des renseignements personnels", at $165, a posted public price. Multiply by twenty employees and you are at $3,300.

Now look at who it is for: "anyone responsible for applying Law 25 obligations within their company". It is built for one person, not for a shop floor. At $165 for your privacy officer, it is probably a good buy. At $3,300 for the whole team, you are paying nineteen times over for content nineteen people will never use. Subscription offers at roughly $60 per employee per year cost less, but none of them knows that your weak spot is the customer-service shared drive.

The page people actually read

Your published governance policy is a legal document, and it is not what your team will read. Write a second one beside it, a single page, in plain language, answering four questions: what counts as personal information here, who is allowed to touch it, what to do when something goes wrong, and what never leaves our tools.

That fourth line is the one that changed in the last three years. Your employees already use consumer AI tools, usually without bad intent and without telling you, and it is now the most banal leak channel in an SMB; we described the mechanism in the article on shadow AI. On your page it fits in one sentence that names examples rather than stating an abstract ban: no client list, no employee file, no document holding names and contact details gets pasted into an unapproved tool. A single page gets reread in two minutes at onboarding; a forty-page manual gets signed unopened.

The 45 minutes, and the three habits

The session runs three quarters of an hour and needs no outside trainer. Open with five minutes on what personal information means here, showing your own screens rather than a definition: the CRM, the shared HR folder, the info@ inbox where ID documents nobody asked for keep landing. Follow with fifteen minutes on ordinary incidents, using the Commission's examples plus two or three near-misses of your own: the email sent to the wrong Martin, the forgotten USB key, the colleague asking for access "just to help out".

Then give ten minutes to the one procedure everybody has to know, the report: who you tell, how fast, and above all that reporting carries no blame. That point decides everything else, because an incident hidden for three days costs far more than one flagged within the hour. Close with ten minutes on tools, consumer AI first, listing what is approved and the alternative you provide, without which the rule lasts two weeks.

Three habits come out of it, and that is all anyone has to retain: recognize personal information when you are handling it, tell a named person when something goes wrong, and paste nothing personal into an unapproved tool.

The record, and who owns the file

Keep an attendance sheet: date, topics covered, names of those present, version of the policy handed out. It looks bureaucratic and it isn't. The framework the Commission published for calculating its penalties explicitly weighs the measures taken and the degree of cooperation, and its business checklist ticks the statement "your company regularly offers its staff training and awareness sessions". The day you have to show diligence, a dated sheet beats a sincere conviction.

Rerun the session once a year and at every hire. And to measure rather than assume, the checklist itself suggests the exercise: a phishing test before and after an awareness campaign.

All of this belongs to one person, and the law already names them: the privacy officer, who has to approve your governance policies in any case. In an SMB that is the owner by default, or whoever the function was delegated to in writing, a role we covered in the article on the privacy officer in a Quebec SMB.

It is also the kind of work we do in passing when we rebuild a site and its forms: line up what you collect, what you keep and what you display, and write the page the team will read while we are in there. Our position on services hasn't moved on this. Compliance that holds lives in the tools people use, not in a framed certificate.

If a vendor sells you a mandatory Law 25 course, ask them for the section. There isn't one. Then ask for the Commission's January 2026 guide, which is free, and run the session yourself.

→ Let's talk about what your team should know, no commitment

This article explains the Law 25 obligations around governance and staff to help an SMB organize itself; it is not legal advice. The sections cited come from the Act respecting the protection of personal information in the private sector (P-39.1) and the Act respecting access to documents held by public bodies (A-2.1), and the recommendations come from guides published by the Commission d'accès à l'information, but how they apply depends on the facts of each business. Validate your situation with legal counsel before deciding anything.

Xavier Peich

Written by

Xavier Peich