If your business operates in Quebec and handles the personal information of clients, employees or suppliers, Quebec's Law 25 applies to you. It does not matter whether you are a large company or a single self-employed professional: there is no exemption based on size. Since September 2024, all provisions of the law are fully in force, and businesses are expected to be compliant. Understanding what the law requires, and where the technical responsibilities lie, is now part of operating responsibly in Quebec.
What this article covers
This article explains, in plain language, what Law 25 is, who it applies to, and the practical steps a business can take to move toward compliance. It focuses in particular on the technical side of protecting personal information, the area where Computer Repair MTL supports Montreal businesses. It is intended as general information, not legal advice; for the legal interpretation of your specific obligations, consult a qualified professional.
In this article you will learn:
- What Law 25 is and who it applies to, including why company size makes no difference.
- The main obligations it introduced, from appointing a privacy officer to reporting incidents.
- How the law was phased in between 2022 and 2024, and what is now fully in force.
- Where the technical work of compliance lies, and how it connects to everyday IT security.
- Practical first steps a business can take to reduce its exposure.
What is Law 25 and who does it apply to?
Law 25, originally introduced as Bill 64, modernized Quebec's rules on the protection of personal information in the private sector. It applies to every business that operates in Quebec and collects, uses, communicates or stores personal information about Quebec residents. Personal information means any information that identifies a person, directly or indirectly: names, email addresses, phone numbers, client records, employee files and more.
The most important thing to understand is that there is no exemption based on the size of the business. A large corporation and a self-employed professional who keeps a list of client emails are both subject to the law. This is why Law 25 affects nearly every business in the province, including small and medium businesses that may not have considered themselves concerned.
The main obligations introduced by Law 25
The law was rolled out in three phases so that businesses had time to prepare. The table below summarizes when each set of obligations came into force and what it involves.
| Phase | In force since | Key obligations |
|---|---|---|
| Phase 1 | September 2022 | Appoint a person responsible for the protection of personal information, report confidentiality incidents, and keep an incident register. |
| Phase 2 | September 2023 | Adopt governance policies, conduct privacy impact assessments, apply new consent rules, and face new administrative monetary penalties. |
| Phase 3 | September 2024 | Honour the right to data portability and the right to have personal information deleted. All provisions now fully in force. |
Non-compliance carries significant consequences. Penal fines can reach up to 25 million dollars or 4% of worldwide turnover, whichever is higher, and administrative monetary penalties can reach up to 10 million dollars or 2%. That said, the Commission d'accès à l'information, which oversees the law, takes good faith and proactivity into account: a business that has taken concrete steps toward compliance is in a much better position than one that has done nothing.
Where compliance becomes a technical matter
Much of Law 25 is legal and organizational, but a significant part of it is technical, and this is where an IT partner becomes essential. The law requires businesses to protect personal information with security measures appropriate to its sensitivity. In practice, that means the everyday IT security work that reduces the risk of a data breach in the first place.
Protecting the systems where personal data lives depends on well-maintained infrastructure, which is part of ongoing server administration. Controlling who can access that data, and keeping intruders out, depends on properly configured network administration. And because the law requires you to report confidentiality incidents, being able to detect and respond to a breach quickly is not optional.
There is also a direct link to data retention and recovery. Law 25 introduced a right to have personal information deleted, which means a business must know where its data is stored and be able to remove it. At the same time, protecting against accidental loss requires reliable backups. Getting both right often depends on modern, well-configured systems, which is where a timely server upgrade or migration can make compliance far easier to achieve.
Practical first steps toward compliance
Reaching full compliance is a process, but a business can reduce its exposure quickly with a few concrete actions.
- Appoint a person responsible for personal information. By default this is the person with the highest authority in the business, but the role can be delegated in writing. Their contact details should be published, typically on your website.
- Map the personal data you hold. Identify what you collect, where it is stored, who has access, and why you keep it. You cannot protect or delete what you have not located.
- Strengthen your technical safeguards. Ensure access to personal data is limited, systems are updated, and backups are working, so a breach is less likely and recovery is possible.
- Prepare an incident response process. Know in advance how you would detect, contain and report a confidentiality incident, since reporting is now a legal obligation.
- Publish a clear privacy policy. Make it simple, accessible and available on your website, as the law requires.
Ongoing technical support for businesses keeps these safeguards current as your systems and data evolve, so compliance does not become a one-time effort that quietly lapses.
Compliance is an ongoing commitment
Law 25 is now fully in force, and it is not a one-time task to check off. It is an ongoing commitment to handling personal information responsibly. The businesses best positioned are those that treat data protection as a normal part of operations rather than a crisis to manage after an incident.
At Computer Repair MTL we help Montreal businesses put in place the technical safeguards that support Law 25 compliance: securing the systems where personal data lives, controlling access, maintaining reliable backups, and being ready to respond to an incident. If you would like to understand how well your current systems protect the personal information you hold, a technical assessment is the place to start.
This article is provided for general information only and does not constitute legal advice. For guidance on your specific obligations under Law 25, consult a qualified legal professional.
Frequently asked questions about Law 25
Yes. There is no exemption based on the size of the business. Any business that operates in Quebec and handles the personal information of Quebec residents is subject to Law 25, including small businesses and even self-employed professionals who keep client names and emails.
Yes. The law was phased in over September 2022, September 2023 and September 2024. Since September 2024, all of its provisions are in force, including the right to data portability and the right to have personal information deleted.
Penal fines can reach up to 25 million dollars or 4% of worldwide turnover, whichever is higher, and administrative monetary penalties can reach up to 10 million dollars or 2%. However, the Commission d'accès à l'information considers good faith and proactive steps toward compliance, which can reduce the consequences.
Yes. Every business must have a person responsible for the protection of personal information. By default it is the person with the highest authority in the organization, but the role can be delegated in writing. Their contact information should be easily accessible, usually on the company website.
Law 25 requires businesses to protect personal information with appropriate security measures. In practice this means everyday IT security: limiting access to data, keeping systems updated, maintaining reliable backups, and being able to detect and report a breach. Strong technical safeguards are a core part of meeting the law's requirements.