Skip to Content

Law 25, four years on: what really changed for SMBs

Past the launch buzz, where do Quebec SMBs and non-profits actually stand with Law 25?



In this article

The major obligations of Law 25 came into effect in stages, on precise dates: September 22, 2022, then 2023, then 2024. Four years have passed since the first deadline, two since the last. That is enough perspective for an honest assessment, well past the rush of the opening months: what has truly changed on the ground, in SMBs and non-profits here?

A recap of the key obligations

Law 25 requires, among other things, designating a person responsible for the protection of personal information, keeping a register of confidentiality incidents and reporting them, adopting a governance policy, obtaining clear consent, and respecting new rights for citizens (access, rectification, portability). Privacy impact assessments are required for certain projects and certain data transfers. The detailed calendar: the responsible officer designation and the incident regime have applied since September 22, 2022; the rules on consent, automated decisions and transfers outside Quebec since September 22, 2023; and the right to portability since September 22, 2024.

One point about portability, because it is regularly misunderstood: it only covers computerized information collected from the person themselves, not information the organization created or inferred about them. The purchase history a customer generated themselves is portable; the risk score calculated from that history is not. The distinction is written into section 27 of the private-sector act, and it changes a great deal once you have to build a process for handling such a request.

Another point that stayed unresolved for a long time: anonymization. Law 25 introduced it as an alternative to destruction, but it only became workable once the criteria were set by regulation. The Regulation respecting the anonymization of personal information has been in force since May 30, 2024. Organizations that wrote "we will anonymize" into their retention policy back in 2022 now have a precise framework to follow, and a method to document. One calendar nuance comes with it: the obligation to record the prescribed information in an anonymization register has only been in force since January 1, 2025.

What has shifted in SMBs

The most visible first: many organizations appointed an officer, published a privacy policy and added consent banners to their site. Sensitivity to the topic has clearly risen; "personal information" and "confidentiality incident" have entered everyday vocabulary. That's real progress over the indifference of before.

The Commission d'accès à l'information's own figures give a more reliable measure than impressions do. In its 2024-2025 annual report, it says it received 514 confidentiality incident reports, up 16% over the previous year and up 559% over three years. Of those 514 reports, 80% came from the private sector, 16% from the public sector and 4% from health and social services. Complaints follow the same curve: 549 received during the year, 364 of them aimed at businesses, and a 227% rise since 2021-2022.

What those reports contain is instructive. Unauthorized access to information dominates by a wide margin with 251 cases, ahead of unauthorized communication (116), loss or another breach of protection (59) and unauthorized use (9). Fifteen percent of the reports tick more than one category for a single incident. The most frequent causes are cyberattacks, human error and ransomware.

That rise deserves to be read for what it is. It does not say leaks multiplied sixfold in three years. It mostly says the duty to report has entered common practice, and that some of what used to be settled quietly now reaches the regulator. That is the sign of a regime taking hold, not of an epidemic.

What still drags

The catch is that many treated Law 25 as a one-time project: tick the box, file it, move on. The result is incident registers that stay empty templates, impact assessments never carried out, vendors never reviewed, and policies that aren't re-read. Paper compliance exists; lived compliance, much less.

What has changed on the Commission's side

The assessment would be incomplete if it only looked at businesses. The authority charged with enforcing the act has changed too, and not only in volume.

Its means have grown, more slowly than its workload. In 2021-2022, before Law 25 was adopted, the Commission had an annual budget of $8.3 million and 73 full-time equivalents. In 2026-2027, it has $12.2 million and 92 authorized positions. In its five-year report, it writes itself that this increase has not matched the expansion of its functions, and that no new money accompanied the responsibilities handed to it by the health and social services information act.

One reference point has also disappeared. Since 2022, the Commission had been publishing the list of organizations that reported an incident. It ended that practice on May 27, 2025, to avoid exposing IT vulnerabilities, hindering the handling of ongoing incidents and compromising its own investigations. It still publishes aggregate statistics, but the names of the organizations affected are no longer made public. For an SMB that used to check its vendors against that list, it is one means of verification fewer.

Finally, on June 11, 2026, the Commission tabled its seventh five-year report, titled "Transparence et vie privée : protéger la démocratie à l'ère numérique". It carries 74 recommendations. The last one takes direct aim at the penalty regime: the Commission asks that the provisions be revised so administrative monetary penalties clearly target only objective breaches, and so other breaches, objective as well, that currently escape the regime are added to it. Four years on, the sanction tool is therefore judged improvable by the very body that wields it.

Six obligations anyone can check from the outside

The most telling part of any assessment is the set of obligations a third party can verify without asking anyone for anything. Here are six, all checkable from a browser:

  • The officer's contact details. The title and contact information of the person responsible have to be published on the company's website, or made available another way if it has no site. It is the quickest check there is, and it is often the first one to fail.
  • The privacy policy. It has to be drafted in clear, simple language and published on the site as soon as you collect information by technological means. A plain contact form is enough to trigger the obligation.
  • Governance policies and practices. They do not merely have to exist: the company has to publish detailed information about them. They cover retention and destruction, staff roles across the whole life cycle of the information, and a process for handling complaints.
  • Default privacy settings. A technological product or service offered to the public has to guarantee, by default, the highest level of confidentiality, with no action required from the person concerned. Cookies are expressly excluded from this rule.
  • The information given at collection time. The purposes, the means, the rights of access and rectification, the right to withdraw consent, and the possibility that the information will be communicated outside Quebec.
  • The granularity of consent. It has to be requested for each purpose, in clear and simple terms, and presented separately from everything else when the request is in writing. A single box covering the newsletter, the analytics and the sharing with partners no longer holds.

Not one of these six needs a budget. They need the things to have been written down once, properly, and kept up to date afterwards.

What it costs when it goes wrong

Law 25 did not just add obligations, it added teeth. Three regimes coexist, and they target different acts.

Monetary administrative penalties are imposed by a person designated by the Commission, without going through a court. The maximum is $50,000 for a natural person and, in other cases, $10 million or 2% of worldwide turnover for the preceding fiscal year, whichever is higher (section 90.12).

The penal provisions target, among other things, collecting, using, communicating, keeping or destroying information in contravention of the act, and failing to report an incident when required to do so. The fine runs from $5,000 to $100,000 for a natural person and, in other cases, from $15,000 to $25 million or 4% of worldwide turnover, whichever is higher (section 91).

A civil regime comes on top. Where an unlawful infringement of a right conferred by the act causes prejudice and is intentional or results from a gross fault, the court awards punitive damages of at least $1,000 (section 93.1). That is a floor, not a ceiling, and in a class action the arithmetic adds up quickly.

A word on the distance between the text and the practice. The Commission's 2024-2025 annual report records no administrative monetary penalty imposed during the year, and its complaint-handling diagram presents the penalty as a possibility at the end of the road, after the investigation, the notice of non-compliance and the opportunity given to the business to present its observations. Several compliance sites nonetheless announce waves of fines with precise amounts. Those figures appear nowhere in the Commission's official documents.

Those numbers are impressive, and they are meant to be. In practice, the everyday risk for an SMB is not the maximum fine: it is the small incident, badly handled, unrecorded and unreported, that ends up becoming a complaint.

The blind spot: compliance isn't a project, it's a habit

That's the real lesson of these four years. Every new piece of software, every new vendor, every new data collection can introduce risk. A truly compliant organization revises, monitors and adjusts continuously. One that stopped at launch is today just as exposed as before, with the bonus of a false sense of security.

Our reading

On the technical side, compliance is won in the foundations: knowing where data lives, who has access, how it's backed up and encrypted, and being able to detect an incident. That's what we build into the infrastructures we deploy by default, because personal data protection isn't a module added at the end, it's a way of building. For the legal and organizational side, specialized partners take over.

Has your compliance stopped on launch day? Let's get it moving again.

Sources

Writing an AI usage policy for your SMB
Your employees already use AI. A clear policy turns a diffuse risk into managed use, without killing the productivity gains.