Logo AgtechnoAGTECHNOManaged IT services — Montreal

Law 25: the six obligations almost no SMB has in place

Law 25 compliance · 6 min read

If your business holds the contact details of even one client, employee or supplier, you are subject to Law 25. Not "eventually". Since 2023.

Most SMB owners we meet believe this law targets banks and large technology companies. It doesn't. Law 25 applies to every business operating in Quebec, with no size or revenue threshold.

A twelve-person accounting firm is subject to it. So is a dental clinic. So is a surveying firm. Here is what the law actually requires.

1. Appoint a privacy officer

You must designate a person responsible for the protection of personal information and publish their contact details, usually on your website. Absent an explicit appointment, the law automatically designates the person with the highest authority — the president or owner.

In other words: if you have done nothing, it's you. With every responsibility that comes with it.

2. Write and publish a privacy policy

Not a paragraph copied from another site. A policy that actually describes what information you collect, why, how long you keep it and who you share it with. It must be written in plain language and made public.

3. Maintain a confidentiality incident log

This is the most neglected obligation — and the most telling in an audit. Every confidentiality incident must be recorded: date, nature, information affected, people concerned, measures taken.

An incident isn't only a cyberattack. An email sent to the wrong recipient with client data attached is an incident. A laptop left in a taxi is an incident.

And when an incident presents a risk of serious injury, you must report it to the Commission d'accès à l'information and notify the individuals concerned.

4. Obtain clear consent

Consent must be manifest, free, informed and given for specific purposes. Pre-ticked boxes and vague wording such as "by submitting this form you accept our terms" no longer suffice.

5. Destroy or anonymize information you no longer need

You can no longer keep data indefinitely. Once the purpose is fulfilled, information must be destroyed or anonymized — and you need a written procedure that says so.

In practice, that means knowing where your data lives. How many old mailboxes from former employees are still sitting in your Microsoft 365?

6. Put reasonable security measures in place

The law doesn't provide a technical checklist. It requires measures "appropriate to ensure the protection of personal information" and proportionate to its sensitivity.

In practice, a court or the Commission will look at: do you have multi-factor authentication? Access restricted to what's strictly necessary? Logging? Tested backups? Ransomware protection?

Your good faith isn't what counts. What counts is your ability to demonstrate what you had in place on the day of the incident.

What happens if you do nothing

The penalties in the law are substantial — they can reach millions of dollars or a percentage of worldwide revenue. But honestly, that isn't the most likely risk for an SMB.

The real risk is elsewhere, and it's already materializing:

Where to start

The good news: compliance is operated, not "projected". A 25-seat SMB doesn't need a $25,000 legal mandate. It needs six things written down, maintained and provable.

The bad news: it isn't a one-time fix. An incident log you don't keep up to date is worthless. So is a policy written in 2023 and never reviewed.

Start by knowing where you stand. Our Law 25 compliance test takes five minutes and requires no sign-up. If the result concerns you — and it concerns most owners who answer honestly — the full assessment gives you the point-by-point scorecard and a costed action plan.

This article is a plain-language summary for SMB owners and does not constitute legal advice. For interpretation of your specific obligations, consult legal counsel.

‹ Back to the blog

Are you compliant? Check in 5 minutes.

Free test, instant result, no sign-up.

Take the Law 25 test