Law 25 checklist: the 12 obligations a Quebec business has to tick off
The 12 obligations under Law 25, one by one: what each one means, the trap people fall into, and a 10-minute test to see where your business actually stands.

A law with no threshold: why your business is caught
Law 25 (formally the Act to modernize legislative provisions as regards the protection of personal information, CQLR c. P-39.1) applies to every business that holds personal information in Quebec. A name, an email address, an employee file or a prospect list is enough. There is no size or revenue threshold: the metal fabrication shop in Granby with its twelve employees is caught just as much as the multinational.
Every phase has been in force since September 22, 2024, and the anonymization regulation has applied since May 30, 2024. Since 2026, the first monetary penalties from the Commission d’accès à l’information (CAI) have been public: the risk is no longer theoretical. The CAI can impose up to $10M or 2% of worldwide revenue directly; the courts can impose penal fines of $15,000 to $25M or 4%; and the private right of action carries punitive damages of at least $1,000 per person where the fault was intentional or gross. For a single breach, all three can stack.
This checklist goes through the 12 obligations one at a time. For each one: what it means, the trap we see most often in the field, and a 10-minute test you can run yourself, without a lawyer. To understand the why behind each part, our complete guide to Law 25 remains the reference; this piece is about the how.
$10M
maximum administrative penalty the CAI can impose directly (or 2% of worldwide revenue)
$25M
ceiling on penal fines before the courts (or 4% of worldwide revenue)
5 years
minimum retention period for the register of confidentiality incidents (ss. 3.5 to 3.8)
Obligations 1 to 4: the foundations of governance
1. Appoint a privacy officer (s. 3.1). By default the Act assigns this role to the person with the highest authority in the business, who may delegate it in writing. The officer’s title and contact details must be published on your website. The trap: believing you have to hire a lawyer; what matters is a named person, reachable and empowered to act. The test: open your website and look for the officer’s title and a way to reach them. If they are not there, that is your first job, and it takes a day.
2. Publish a privacy policy that matches reality (s. 3.2). The policy has to describe what you collect, why, how long you keep it and who you share it with, in simple, clear terms. The trap: the template copied from another site, promising practices you do not have. Promising what you do not do is an exploitable fault if a complaint is filed. The test: read your policy and check that every sentence matches what your teams actually do this week.
3. Maintain a personal information register (a requirement flowing from the governance policies, s. 3.2). You have to know what data you hold, where it sits, why, for how long and who has access. Without that map, none of the other obligations can be verified. The trap: assuming the information lives “in the controller’s head.” The test: ask two people separately where employee files are stored and who can consult them. If the answers differ, your register still has to be built.
4. Carry out a privacy impact assessment before any project touching personal information (s. 3.3). The assessment is mandatory before acquiring, developing or redesigning a system that processes personal information. Any AI deployment touching employee or client data is caught. The trap: doing the assessment after go-live, or skipping it for the “free” cloud tools a team adopted without telling IT. The test: list the software adopted in the last 12 months and check whether a documented assessment exists for each one. Our practical guide to the privacy impact assessment sets out the method.
Obligations 5 to 8: the information lifecycle
5. Govern consent (s. 14). Consent must be manifest, free, informed, given for specific purposes and requested separately from any other condition. The trap: the pre-ticked box and the catch-all consent covering “any future use.” The test: fill in your own newsletter form. If you cannot say precisely what you just consented to, neither can your clients.
6. Handle confidentiality incidents (ss. 3.5 to 3.8). Where an incident presents a risk of serious injury, you have to notify the CAI and the people concerned “promptly,” and keep an incident register for at least five years. Unlike the GDPR, there is no fixed 72-hour deadline; “promptly” means without undue delay. The trap: discovering on the morning of the incident that no process exists and no register was ever opened. The test: ask who would notify the CAI tomorrow morning and where the register is. A long silence is your answer.
7. Set retention periods and destroy (s. 23). Once the purpose is fulfilled, the information has to be destroyed or anonymized. Since May 30, 2024, the anonymization regulation has set the bar very high: data is only anonymized if it can no longer be used, irreversibly, to identify the person. The trap: keeping everything “just in case,” from résumés dating to 2015 to the files of clients long gone. The test: find the oldest résumé still sitting in the HR inbox and ask yourself what purpose justifies its still being there.
8. Process individual requests (s. 27 and following). Anyone can ask for access to their information, its correction, the withdrawal of their consent, de-indexing, portability, or human review of an automated decision. The Act provides for a response within 30 days (s. 32). The trap: no defined front door, so the request sits in an info@ inbox nobody checks. The test: send yourself a fictitious access request from a personal address and time its journey. Who receives it, who handles it, who answers?
Obligations 9 to 12: suppliers, minimization and AI
9. Govern suppliers and transfers outside Quebec (ss. 18.3 and 17). Entrusting information to a processor requires a written contract setting out the protective measures and the incident notices (s. 18.3). Any disclosure outside Quebec requires a prior assessment demonstrating adequate protection (s. 17). The trap: the SaaS tool or AI assistant hosted in the United States, adopted with no assessment. Under the US CLOUD Act, the physical location of the servers is no protection: what counts is the owner’s jurisdiction, as our article on the CLOUD Act and data sovereignty explains. The test: list your five main tools (CRM, accounting, email, AI, backup) and note, for each, the hosting country and the supplier’s jurisdiction.
10. Minimize collection (s. 5). You may only collect the information necessary for the stated purpose. The trap: legacy forms demanding date of birth, marital status or a social insurance number “just in case.” Every superfluous field is a liability. The test: open your quote form or your hiring form and justify each field in one sentence. Whatever you cannot justify, delete.
11. Enable portability (s. 27). Since September 22, 2024, anyone can obtain their computerized personal information in a structured, commonly used technological format. The trap: assuming this only concerns banks and telecoms. A client, an employee or a candidate can ask you today. The test: ask your IT team to export a client’s complete file. If the exercise takes a week, it will take just as long when the request is real.
12. Disclose automated decisions (s. 12.1). If a decision is based exclusively on automated processing, you must inform the person no later than at the time of the decision, tell them what information was used and what the main factors were, then let them make submissions and ask for a review. The trap: automated résumé screening installed “to save time,” with no disclosure. A simple design rule: keep a human able to review before any action. The decision is then no longer exclusively automated, which simplifies compliance. Your AI acceptable use policy should record that rule in black and white.
The summary table: obligation, section, first move
Print this table and tick as you go. The sections refer to the private sector Act (CQLR c. P-39.1), as amended by Law 25.
| Obligation | Section (P-39.1) | First move |
|---|---|---|
| 1. Privacy officer | s. 3.1 | Publish their title and contact details on the website |
| 2. Privacy policy | s. 3.2 | Compare every promise against actual practice |
| 3. Personal information register | flows from s. 3.2 (governance) | Map the data in three key processes |
| 4. Assessment before any project | s. 3.3 | Inventory the systems adopted in the last 12 months |
| 5. Governed consent | s. 14 | Test your own forms |
| 6. Incident handling | ss. 3.5 to 3.8 | Open the register and name who notifies the CAI |
| 7. Retention and destruction | s. 23 | Set a period for each category of data |
| 8. Individual requests | s. 27 and following | Create a single front door (a dedicated inbox) |
| 9. Suppliers and transfers | ss. 18.3 and 17 | Note the hosting country of every tool |
| 10. Minimizing collection | s. 5 | Delete the unjustified fields from your forms |
| 11. Portability | s. 27 | Test a full export of one client’s file |
| 12. Automated decisions | s. 12.1 | Find where software decides alone and add human review |
The three failures we see most often
First failure: no officer appointed. Many executives have no idea the role has fallen to them by default since September 2022, so their contact details are never published. Second failure: tools hosted in the United States with no transfer assessment. The AI assistant your sales team has been using for six months may be processing your quotes on servers subject to US law, without the assessment section 17 requires. Third failure: a privacy policy disconnected from reality, often copied from a competitor, which becomes evidence against the business the day a complaint is filed.
Those three failures have one thing in common: they are visible from the outside. A complainant, a competitor or the CAI can spot them without ever setting foot in your building, simply by visiting your site and looking at your forms. They are therefore the easy targets in an audit, and the best use of your first two hours.
The CAI does not need an incident to act: no published officer, or a policy contradicted by your practices, is enough to open a case.
Where to start this week
If your twelve tests turn up holes, do not try to fix everything at once. Start with obligations 1, 2 and 9: appoint and publish the officer, align the policy with reality, inventory the suppliers and their jurisdictions. Those three moves cover the most visible failures and structure everything else. The register (obligation 3) comes next, because it feeds the assessments, the retention periods and the access requests.
An SME of 50 people can reasonably clear those steps in a few weeks with one accountable person and a clear mandate from management. Where it gets harder is when AI enters the picture: assessment before deployment, transfers outside Quebec, automated decisions, access logging. That is our ground. Our approach starts with a diagnostic that works through these 12 obligations with evidence in hand; stream 1B of Investissement Québec’s ESSOR program may cover part of it, subject to confirmation of eligibility. If you would rather go it alone, the complete guide goes deeper into each obligation; otherwise, write to us: the first conversation is there precisely to place your business on this checklist.
Frequently asked questions
Does Law 25 apply to a business with five employees?
Yes. The Act sets no size or revenue threshold: it covers every business that holds personal information in Quebec, about its clients as much as its employees, suppliers or prospects. A self-employed worker who keeps client emails is caught, even though the measures required stay proportionate to the size and sensitivity of the data.
How long do we have to notify the CAI after a confidentiality incident?
Law 25 requires notice “promptly” as soon as an incident presents a risk of serious injury, without setting a numerical deadline, unlike the GDPR and its 72 hours. In practice: act without undue delay from the moment you find out. You also have to record every incident in a register kept for at least five years, including the ones that require no notice.
What does an SME actually risk by being non-compliant?
Three regimes can stack. The CAI can impose administrative monetary penalties directly, up to $10M or 2% of worldwide revenue. The courts can impose penal fines from $15,000 to $25M or 4% of the same figure. And the people harmed have a private right of action, with punitive damages of at least $1,000 per person where the fault was intentional or gross; the first penalties published by the CAI in 2026 confirm the regime is being applied.
Do we need a privacy impact assessment to deploy an internal AI tool?
Yes, as soon as the system processes personal information. Section 3.3 requires an assessment before the acquisition, development or redesign of any information system involving such information. An AI assistant that reads emails, employee files or client data falls into that category. If the tool is hosted outside Quebec, the transfer assessment under section 17 applies on top.
Does the privacy officer have to be an employee?
No. By default the Act gives the role to the person with the highest authority, who may delegate it in writing to a member of staff or to an external provider. What matters: a clearly designated person, the authority to act, and a title and contact details published on the website.
Sources and references
- Légis Québec, Act respecting the protection of personal information in the private sector (CQLR c. P-39.1)
- Commission d’accès à l’information du Québec, business obligations and incident reporting
- Regulation respecting the anonymization of personal information, in force since May 30, 2024 (Légis Québec)
This article is a plain-language summary, accurate as of the date shown. It is not legal advice: for your own situation, consult a legal adviser or contact the Commission d’accès à l’information.
Read next
Compliance
Law 25: the complete compliance guide for Quebec businesses
Read →
Compliance
The privacy impact assessment, demystified: how to assess an AI project before you deploy it
Read →
Sovereignty
CLOUD Act: why a server in Montreal is not always sovereign
Read →
A question about your own compliance?
The discovery call is free and takes half an hour. You leave with an honest read on your situation.
Let’s talk