Law 25: Three Obligations Many organizationsThink They Meet… But Don't

Visuels Blogues 13

 

You run an SME. You've appointed someone as your privacy officer, you have a privacy policy on your website, and you've never had a major data breach. On paper, everything is in order.

The problem is that Law 25 compliance isn't measured in ticked boxes. It's measured the day the Commission d'accès à l'information (CAI) asks to see your documentation — or the day ransomware encrypts your servers and you have to prove, within hours, that you knew what to do.

Here are the three obligations Quebec SMEs most often believe they meet, and what's actually missing in each.

Law 25 in 2026: Where Do Things Stand?

All of Law 25's provisions are now in force, rolled out in three phases (2022, 2023 and 2024). The law applies to any organization that collects, uses or stores personal information in Quebec: SMEs, self-employed workers, non-profits — regardless of size or where the head office is located.

The CAI oversees enforcement and has already begun conducting audits. The penalties are not symbolic: administrative fines can reach 10 million dollars or 2% of worldwide turnover, and penal sanctions can climb to 25 million dollars or 4% of worldwide turnover.

So the question is no longer whether the law applies to you. It does. The real question is: would your compliance hold up under an audit?

Obligation 1 — The Person Responsible for the Protection of Personal Information

What many people think: "I'm the owner, so I'm the one responsible. Done."

What the law actually requires: Yes, by default, the role falls to the person with the highest authority in the organization. But appointing a privacy officer isn't enough. The law requires that this person's title and contact information be published and accessible, usually on your website. The role can also be delegated, in whole or in part, to an employee or a consultant — provided it's documented.

The most common gap isn't the absence of an officer. It's the absence of a trail: no formal designation, no published contact details, no real mandate given to the person named. An officer whose name nobody knows and who has received no resources to do the job isn't an officer in the sense of Law 25 — it's a ticked box.

The concrete test: A client wants to know who to contact about their personal information. Can they find a name and a way to reach that person in under two minutes on your website? If not, the obligation isn't met.

Obligation 2 — The Confidentiality Incident Register

What many people think: "We haven't had a major breach, so there's nothing to report or to log."

What the law actually requires: You have to separate two obligations that are almost always confused.

The first: logging. Every confidentiality incident must be recorded in a register, without exception. An email sent to the wrong recipient, a spreadsheet of client data accidentally shared with a supplier, a brief unauthorized access — all of it gets logged, even if the incident seems minor.

The second: notifying. The CAI and the affected individuals must be notified, but only when the incident presents a serious risk of injury. And even when you conclude there is no serious risk, your reasoning must be documented. The register isn't there to flag catastrophes: it's there to prove that you assess every incident methodically.

This is where the gap is most dangerous. According to the Canadian Federation of Independent Business (CFIB), a large share of Canadian SMEs suffered a cyberattack in the past year — and the majority of them had no register, no response plan, and no notification process. Three Law 25 obligations breached at once, at the worst possible moment.

The cyber link, no detours: When ransomware strikes, you deal with the technical crisis first. But the Law 25 clock starts at the same time. Without a register kept in advance and a notification procedure ready to go, the regulatory fine adds to the cost of the attack. And that cost isn't theoretical: the average cyberattack costs a Canadian SME 458,000 dollars, with 22 days of recovery after a ransomware attack. That's 22 days during which you can't afford to improvise your compliance.

Obligation 3 — Governance Policies and Practices

What many people think: "We have a privacy policy on the site. That's covered."

What the law actually requires: Since September 2023, you must have established policies and practices governing your personal information — and made them transparent. A privacy page copied from a generic template is not a governance program.

A real program means: an inventory of the personal information you actually hold, roles and responsibilities defined internally, retention periods set, deletion of data that has become unnecessary, valid and informed consent at the point of collection, and policies updated to keep pace with legal and technological change.

On top of that comes an obligation almost no one anticipates: the privacy impact assessment (PIA). You must carry it out before sharing information outside Quebec or before launching any project that involves collecting data — for example, migrating your databases to a cloud service hosted elsewhere. Many SMEs cross these thresholds without realizing it, creating a compliance gap they don't even know exists.

The concrete test: If the CAI asked you today for your data inventory, your incident register, and proof that your policies were reviewed within the past year, how many of those documents could you produce?

The Blind Spot: Law 25 and Cyber Risk Aren't Managed in Silos

Here's what these three obligations have in common. They are never tested more sharply than at the moment of a cyber incident. An attack triggers a security crisis and a legal obligation at the same time. Yet in most SMEs, these two realities are handled by different people, with different suppliers, with no coordination.

That silo is exactly what Covalen's cyber ecosystem is built to remove. Instead of selling you a policy and leaving you alone with your compliance, your broker coordinates the entire journey: assessing your real exposure through a vulnerability scan, fixing your weaknesses with a network of technology partners, strengthening your practices, preparing you for an incident, then transferring the residual risk through an exclusive cyber insurance solution. And if an incident does happen, the elucia. service supports you through the claim.

One point of entry, from diagnosis to response. Because in cybersecurity, prevention is essential, but resilience is indispensable — and Law 25 compliance is part of that resilience.

Law 25 changed the rules of the game in Quebec. A security breach is no longer just an IT problem: it's a legal liability. Your Covalen broker is there to help you assess your real exposure, close the gaps you can't see, and choose the coverage that genuinely fits your risk profile and your obligations.

Book your cyber diagnostic. It's the starting point for knowing, concretely, where your gaps are — before an audit or an attack reveals them for you.


Frequently Asked Questions — Law 25 and SMEs

Does Law 25 really apply to small businesses? Yes. Law 25 applies to any business that collects, holds or uses personal information in Quebec, regardless of size. SMEs, self-employed workers and non-profits are all covered, even if their head office is located outside Quebec.

What are the penalties for non-compliance? The CAI can impose administrative fines of up to 10 million dollars or 2% of worldwide turnover. Penal sanctions, imposed by the Court of Québec, can reach 25 million dollars or 4% of worldwide turnover.

Do I really have to publish the contact details of the person responsible for personal information? Yes. The title and contact information of the privacy officer must be accessible, usually on your website. Appointing an officer without publishing their contact details is not enough to meet the obligation.

Do I have to log a confidentiality incident even if it's minor? Yes. Every confidentiality incident must be entered in the register, without exception. Notifying the CAI and the affected individuals is only mandatory when the incident presents a serious risk of injury, but the assessment of that risk must also be documented.

Is cyber insurance enough to be compliant with Law 25? No. Cyber insurance transfers the financial risk, but it does not replace your governance, register-keeping and notification obligations. Compliance and coverage are two complementary parts of the same resilience strategy — which is why it's worth thinking about them together rather than in silos.