← All articles

Law 25: the practical guide for SMB leaders

Every Law 25 obligation is now in force, for every business — not just the big ones. If you have customers, employees or a contact form on your website, this applies to you. Here's what actually matters, without the legalese, and where to begin.

Law 25: the practical guide for SMB leaders

Since September 2024, Law 25 has been fully in force. Every obligation, for every business — not just banks, not just the web giants. If your company has customers, employees, or even a simple contact form on its website, it holds personal information, and the Law applies. Yet in many Quebec SMBs, compliance still hovers somewhere between "we'll get to it this fall" and "that doesn't apply to a company our size."

This guide covers what actually concerns you, without the legal jargon — and above all, where to start without turning it into a six-month project.

Law 25 in one minute

Law 25 modernizes Quebec's Act respecting the protection of personal information in the private sector, drawing heavily on Europe's GDPR. Personal information is any information that allows a person to be identified: a customer's name and email, an employee file, a cell number in your CRM, the data collected by your website form.

One important point: there is no size threshold. A company with 5 employees has the same obligations in principle as one with 5,000 — what varies is the proportionality of the means, not the existence of the obligation.

The seven obligations that affect every SMB

1. A designated privacy officer — and a published one. By default, this is the person with the highest authority in the company, who may delegate the role in writing. That person's title and contact information must be published on your website. It's the simplest obligation in the entire Law, and one of the most frequently overlooked: a thirty-second check that anyone — a customer, a journalist, an inspector — can run today.

2. An incident log — and a duty to report. Every confidentiality incident (unauthorized access to, use, disclosure, or loss of personal information) must be recorded in a log. If the incident presents a risk of serious injury, you must report it to the Commission d'accès à l'information (CAI) and notify the individuals concerned. A compromised mailbox, a lost laptop, a ransomware attack: each one can be a confidentiality incident under the Law. And the moment to discover your reporting procedure is not during the first 72 hours of a ransomware attack .

3. Published policies. Governance policies and practices for personal information, written in clear terms and made public — in practice, a privacy policy worthy of the name on your website, describing what you collect, why, and what rights individuals have.

4. An assessment before new projects. Any acquisition, development, or redesign of a system involving personal information requires a privacy impact assessment (PIA) — proportionate to the sensitivity of the data. Choosing a new CRM, adopting a cloud tool, connecting an AI assistant to your customer data : each of these should trigger the reflex. Same thing before transferring information outside Quebec.

5. Consent and transparency. Consent must be clear, free, informed, and requested for specific purposes. If you use identification, location, or profiling technologies, you have to tell people. And the privacy settings in your tools must offer the highest level of protection by default.

6. Minimization, retention, and destruction. Collect only what you need — and don't keep it forever. The Law requires you to destroy or anonymize personal information once the purpose has been fulfilled, but "purpose fulfilled" does not mean "the day after the last invoice."

In practice, this translates into a retention schedule: a period set in advance by your company, for each category of information, that accounts for your other obligations — tax, accounting, contractual, employment — and your legitimate archiving needs. Seven years for supporting financial records, a defined period for employee files after a departure, a few months for unsuccessful job applications, a clear window for camera footage. The exact number matters less than the fact that it exists, that it can be justified, and that it is actually applied when the deadline comes.

What's indefensible is the absence of a rule. The 2015 prospect database sitting on an old network share because nobody ever decided when to delete it isn't an asset: it's a liability.

7. Portability. Since September 2024, any individual can request to receive their computerized personal information in a structured, commonly used technological format.

The penalties — and your real exposure

The numbers that make headlines: administrative monetary penalties of up to $10 million or 2% of worldwide turnover, penal sanctions of up to $25 million or 4% of worldwide turnover, and a private right of action with punitive damages of at least $1,000 per person.

Let's be honest: the CAI is not handing out $10 million fines to SMBs by the batch — its approach favours guidance and correction first. An SMB's real exposure lies elsewhere: the badly handled incident. The compromised mailbox that becomes a reportable incident, the inability to demonstrate that "reasonable security measures" were in place, the loss of customer trust when you have to announce the breach — and the insurer combing through your practices at claim time.

Law 25 is a cybersecurity law in disguise

The operational heart of the Law comes down to three words: "reasonable security measures." And those measures are exactly the fundamentals we cover throughout this series: multi-factor authentication, device encryption, access control based on least privilege , tested backups, logging, revoking access when employees leave, and governing the AI tools your teams are already using.

In other words: compliance and cybersecurity aren't two parallel projects. They're the same project, seen through two windows. A former employee who can still reach your client files, a fake email from the CEO redirecting a wire transfer containing personal data, ransomware that exfiltrates your customer database: each is both a security incident and a confidentiality incident under the Law.

Where to start: the 30-day plan

Week 1 — The officer. Appoint your privacy officer, document the delegation, publish the title and contact details on your website. One hour of work, one obligation settled.

Week 2 — The inventory. Map your personal information: which data, in which systems, who has access. While you're at it, set the intended retention period for each category — it's the best moment, the information is fresh. The exercise overlaps directly with the access inventory we discussed around employee departures — kill two birds with one stone.

Week 3 — The documents. A clear privacy policy on the site, an incident log template, and a one-page reporting procedure: who assesses, who calls the CAI, who notifies customers — including when it happens on a Saturday.

Week 4 — The measures. Validate the security fundamentals (MFA everywhere, tested backups, laptop encryption, access revoked on departure) and build the PIA reflex into every tool purchase that touches personal data.

You don't need a full-time lawyer or a company-wide transformation: you need method, templates, and an IT team that speaks both languages — compliance and security.

The bottom line

Law 25 carries a reputation as a bureaucratic mountain. In practice, most of compliance rests on things you should be doing anyway to protect your business: knowing what data you hold, limiting access to it, securing it, deciding how long you keep it, and knowing what to do when things go wrong. The rest is documentation.

If the CAI wrote to you tomorrow about an incident, could you produce your log, name your privacy officer, and demonstrate your security measures — or would you have to start by creating them?

We can take this on with you

At MMO Techno, we build Law 25 requirements directly into our managed IT services and our cybersecurity and compliance offering: data and access inventory, retention schedule, documented security measures, incident log and procedure, and support during assessments — so that compliance becomes a by-product of your security, not one more project.

You don't have to untangle this alone. Write to us or call 1 855 532-0189 : we'll look at where you stand together, and tell you straight what's missing — and what's already fine.


This article explains the broad strokes of Law 25 for informational purposes and does not constitute legal advice. For the interpretation of your specific obligations, consult a legal advisor.

An IT project or a question?

Talk to an MMO Techno expert. We'll give you a clear, fast answer.

Contact us