Back to Blog
Law 25 August 27, 2026 7 min read

Quebec Law 25 for Small Business: What You Actually Have to Do

Quebec's Law 25 reads like it was written for a bank. Most of it wasn't meant for your five-person shop. Here's the short list of what a small business genuinely has to do.

By Valdra Team

Quebec Law 25 for Small Business: What You Actually Have to Do

A landscaping company outside Sherbrooke got a letter from the Commission d'accès à l'information last year. Someone had complained that the business kept a spreadsheet of client addresses, gate codes, and alarm details, then emailed it around to seasonal staff with no controls at all. The owner had four employees and had never heard the words "Law 25." That spreadsheet, harmless as it felt, was exactly the kind of thing the law was written to catch.

Here is the part nobody tells small Quebec businesses. Most of the 200-plus pages of analysis you'll find online were written with Desjardins and the big banks in mind. The version of the law that applies to a five-person company is far shorter than the consultants would like you to believe. You don't need a $40,000 gap assessment. You need to do about six things properly and keep doing them.

What Law 25 actually is, in one breath

Law 25 (formally *An Act to modernize legislative provisions as regards the protection of personal information*, which is why everyone just shortens it to Loi 25 or Law 25) overhauled Quebec's private-sector privacy act in three waves: September 2022, September 2023, and the data-portability right that arrived in September 2024. It's enforced by the CAI (Commission d'accès à l'information du Québec), not the federal OPC. If you operate in Quebec and hold personal information about Quebec residents, your own employees included, you're in scope. There's no headcount exemption. A dépanneur with a loyalty list is covered the same way a bank is.

What changed for everyone is the teeth. The CAI can now impose administrative monetary penalties up to $10 million or 2% of worldwide turnover, whichever is greater, and the separate penal fines run up to $25 million or 4%. Those ceilings exist to make boardrooms at large firms sweat. The CAI's own framework on penalties points toward proportionality, and the agency has shown more interest in whether you made a genuine effort than in trapping a small operator on a technicality. That distinction should shape how you spend your time.

Name a person, and write it down

The single most important obligation, and the one small businesses skip most often, is naming someone responsible for the protection of personal information. By default that's the person with the highest authority in the company, which in a five-person shop is you, the owner. You can delegate the role in writing to someone else, but somebody's name has to exist.

This is not a ceremonial title. That person's name and contact details have to be published, usually on your website. When the CAI looks at a small business, the first thing it checks is whether a responsible person is identified and reachable. The task costs nothing and takes ten minutes, and its absence is the clearest possible signal that you've done nothing at all. Start here.

Know what you hold and why

You can't protect information you can't describe. Law 25 expects you to state, in plain terms, what personal information you collect, why you collect it, where it lives, who can see it, and how long you keep it. The fancy name is a "record of processing activities." For a small business it's a one-page table.

The landscaping company's problem wasn't that it had client addresses. Of course it did. The problem was that nobody could answer the basic questions. Why are gate codes sitting in the same file as marketing emails? Who has the spreadsheet? When does old client data get deleted? "Never" is not an acceptable retention period under Law 25, and indefinite retention is one of the easiest violations for the CAI to spot.

Sit down for an afternoon and list it out: customer data, employee data, anything from a contact form, payroll, your point-of-sale system. For each one, write the purpose and a retention period you can actually defend. That document does more real compliance work than any policy you'll buy.

Tell people what you're doing

Quebec residents have a right to know how their information is used, and Law 25 raised the bar on transparency. You need a privacy notice written for humans, not lawyers, and it has to be available in French (the Charter of the French Language is not optional, and a French-first business that posts an English-only privacy policy is asking for a complaint).

If you collect information through technology that profiles, locates, or identifies people, you have to tell them and give them the means to switch that profiling off. For a small business this is mostly about the cookies and analytics on your website. Quebec went further than the rest of Canada on this point. Any function that identifies, locates, or profiles a user must default to the highest level of privacy out of the box, without the person lifting a finger. That's a genuine break from PIPEDA, and it trips up businesses that simply copied an Ontario competitor's banner.

Default to the highest privacy setting. In Quebec, opt-out is the starting point, not a buried checkbox.

Have a plan for the day something goes wrong

Breaches are when small businesses find out whether they're compliant or just hopeful. If you suffer a "confidentiality incident," a stolen laptop, a misdirected email carrying personal data, ransomware, and it poses a risk of serious injury, you have to notify both the CAI and the affected individuals promptly. You also have to keep a register of every incident, including the minor ones you decided not to report.

I tell every small client the same thing. You will not write a good breach-response plan at 11 p.m. on the night of the breach. Write a half-page now: who you call, what you assess, when the CAI gets notified, where the register lives. The CAI can ask to see that register, so logging incidents, even the small ones, is part of the obligation, not just good hygiene.

The privacy impact assessment, demystified

You've probably seen the phrase "Évaluation des facteurs relatifs à la vie privée," or PIA, and assumed it's a big-company chore. Mostly it is. A formal assessment is required before you launch a new system involving personal information, and before you transfer personal data outside Quebec. For most five-person businesses, the second trigger is the one that bites. If you use a US-based cloud tool, a mailing platform, a CRM, a payment processor, you're sending Quebec personal information out of the province, and the law expects you to have assessed that move.

The honest answer for a small shop is that this is usually a short, structured note confirming the provider gives adequate protection, not a 30-page report. But the assessment has to exist. "We use Mailchimp and never thought about it" is precisely the gap the CAI flags.

Quebec Law 25 for small business: the realistic short list

Strip away the enterprise noise and Quebec Law 25 for small business comes down to this:

  • Name a person responsible for privacy and publish their contact details.
  • Map what personal information you hold, why, and how long you keep it.
  • Publish a plain-language privacy notice, in French, with privacy-by-default settings.
  • Keep an incident register and a half-page breach plan.
  • Run a light assessment before sending Quebec data to out-of-province tools.

That's the genuine core. Everything else is refinement. The businesses that get in trouble aren't the ones with imperfect documentation; they're the ones with nothing. No named person, no map, no French notice. They look like they never tried.

The catch is that doing those six things by hand, then keeping them current as you add a tool or hire someone, eats time a small owner doesn't have. That's the real reason Quebec Law 25 for small business compliance feels heavier than it should: the obligations are modest, but the upkeep never stops. If you want to see exactly where you stand without paying for a consultant's gap assessment, you can run a free Law 25 assessment built for small businesses and get a plain-language picture of what's done and what's missing.

Quebec Law 25 for small businessLaw 25 compliance QuebecLoi 25 petite entrepriseprivacy officer QuebecLaw 25 privacy policyCAI Quebec compliance

AI governance and privacy compliance, simplified.

Valdra helps Canadian companies govern AI and meet PIPEDA and Law 25 — hosted in Canada.

Try Valdra

Our own compliance

We run our own compliance programme inside Valdra — the product we sell. Our SOC 2, ISO 27001 and ISO 42001 programmes are actively in progress; we do not claim certifications we do not yet hold.

Valdra compliance badge — click to verify
  • PIPEDA
  • Law 25 (Quebec)
  • CASL
  • Data hosted in Canada 🇨🇦
  • AI governance
View our Trust Centre

Self-declared, not audited by a third party. Click the badge to verify it is genuine and see what it covers.

Quebec Law 25 for Small Business | Valdra