← All articles

Law 25: the practical guide for SMB leaders

Every Law 25 obligation is now in force, for every business — not just the big ones. If you have customers, employees or a contact form on your website, this applies to you. Here's what actually matters, without the legalese, and where to begin.

Law 25: the practical guide for SMB leaders

Since September 2024, Law 25 has been fully in force. Every obligation, for every business — not just banks, not just the tech giants. If your company has customers, employees or even a simple contact form on its website, it holds personal information, and the Law applies. Yet in many Quebec SMBs, compliance still hovers somewhere between "we'll deal with it this fall" and "that doesn't apply to a company our size."

This guide covers what actually concerns you, without the legalese — and above all, where to start without turning it into a six-month project.

Law 25 in one minute

Law 25 modernizes Quebec's Act respecting the protection of personal information in the private sector, drawing heavily on Europe's GDPR. Personal information is any information that makes it possible to identify a person: a customer's name and email address, an employee file, a cell number sitting in your CRM, the data collected by your website form.

One key point: there is no size threshold. A company with 5 employees has the same obligations in principle as one with 5,000 — what varies is the proportionality of the means, not the existence of the obligation.

The seven obligations that apply to every SMB

1. A designated privacy officer — publicly identified. By default, this is the person with the highest authority in the organization, who may delegate the role in writing. That person's title and contact information must be published on your website. It's the simplest obligation in the entire Law, and one of the most frequently overlooked: a thirty-second check that anyone — a customer, a journalist, an inspector — can run today.

2. An incident register — and a duty to report. Every confidentiality incident (unauthorized access, use, disclosure or loss of personal information) must be recorded in a register. If the incident presents a risk of serious injury, you must report it to the Commission d'accès à l'information (CAI, Quebec's privacy regulator) and notify the individuals concerned. A compromised mailbox, a lost laptop, a ransomware attack : each can be a confidentiality incident under the Law.

3. Published policies. Personal information governance policies and practices, written in clear terms and made public — in practice, a real privacy policy on your website describing what you collect, why, and what rights individuals have.

4. An assessment before new projects. Any acquisition, development or overhaul of a system involving personal information requires a privacy impact assessment (PIA) — proportionate to the sensitivity of the data. Choosing a new CRM, adopting a cloud tool , plugging a chatbot into your customer data : each of these should trigger the reflex. Same goes before disclosing information outside Quebec.

5. Consent and transparency. Consent must be clear, free, informed and requested for specific purposes. If you use identification, location or profiling technologies, you have to tell people. And the privacy settings of your tools must offer the highest level of protection by default.

6. Minimization and retention. Collect only what you need, then destroy or anonymize the information once the purpose has been fulfilled. A word of caution: "purpose fulfilled" doesn't mean "the day after the transaction." Legal, tax and contractual obligations are part of the equation — an employee file, an invoice, a service contract each has its own legitimate retention period. The good practice is to set a retention policy (or schedule) up front that defines a duration by type of information, document it, and actually apply it. What isn't defensible is retention by default, with no end date and no justification: the 2015 prospect database gathering dust on an old network share isn't an asset, it's a liability.

7. Portability. Since September 2024, any individual can request their computerized personal information in a structured, commonly used technological format.

The penalties — and where the real exposure lies

The headline numbers: administrative monetary penalties of up to $10 million or 2% of worldwide turnover, penal fines of up to $25 million or 4% of worldwide turnover, and a private right of action with punitive damages of at least $1,000 per person.

Let's be honest: the CAI isn't handing out $10 million fines to SMBs by the dozen — its approach favours guidance and correction first. An SMB's real exposure lies elsewhere: the mishandled incident. The compromised mailbox that becomes a reportable incident, the inability to demonstrate that "reasonable security measures" were in place, the loss of customer trust when you have to announce the breach — and the insurer combing through your practices at claim time.

Law 25 is a cybersecurity law in disguise

The operational heart of the Law comes down to three words: "reasonable security measures." And those measures are exactly the fundamentals we cover throughout this series: multi-factor authentication , device encryption, least-privilege access control , tested backups , logging, revoking access when employees leave , and governing the AI tools your teams are already using.

In other words: compliance and cybersecurity aren't two parallel projects. They're the same project seen through two windows. A former employee who can still reach your client files , a fake email from the president redirecting a wire transfer that contains personal data, ransomware that exfiltrates your customer database : each is both a security incident and a confidentiality incident under the Law.

Where to start: the 30-day plan

Week 1 — The officer. Appoint the person responsible for the protection of personal information, document the delegation, publish the title and contact details on your website. One hour of work, one obligation settled.

Week 2 — The inventory. Map your personal information: what data, in which systems, who has access. The exercise overlaps directly with the access inventory we discussed in the context of employee departures — kill two birds with one stone. A security audit often does half the work for you.

Week 3 — The documents. A clear privacy policy on the site, an incident register template, and a one-page reporting procedure: who assesses, who calls the CAI, who notifies customers — including if it happens on a Saturday .

Week 4 — The measures. Validate the security fundamentals ( MFA everywhere , tested backups and an up-to-date recovery plan , laptop encryption, access revoked on departure) and build the PIA reflex into every tool purchase that touches personal data.

You don't need a full-time lawyer or a company-wide transformation: just method, templates, and an IT team that speaks both languages — compliance and security.

The bottom line

Law 25 carries a reputation as a bureaucratic mountain. In practice, most of compliance rests on things you should be doing anyway to protect your business: knowing what data you hold, limiting access to it, securing it, and knowing what to do when things go wrong. The rest is documentation.

At MMO Techno, we build Law 25 requirements directly into our managed IT services: data and access inventory, documented security measures, incident register and procedure, and support during assessments — so that compliance becomes a by-product of your security, not one more project.

If the CAI wrote to you tomorrow about an incident, could you produce your register, name your privacy officer and demonstrate your security measures — or would you have to create them first?

If the answer gives you pause, let's talk. Contact us : we'll look together at where you stand, what's missing, and what to tackle first — no commitment, and no six-month project to sell you.


This article explains the broad strokes of Law 25 for information purposes and does not constitute legal advice. For the interpretation of your specific obligations, consult a legal advisor.

An IT project or a question?

Talk to an MMO Techno expert. We'll give you a clear, fast answer.

Contact us