Why Law 25 applies to you, even if you are small
Law 25 sets no size threshold. A five-person clinic, a ten-employee web agency or a corner shop fall under the same principles as a bank. What varies is the proportional effort expected: no one asks an SMB for a multinational's apparatus, but a serious, consistent and documented approach is expected.
The legislator starts from a simple premise: personal information has become sensitive material, and its leak causes real harm to people. The law therefore makes you accountable across the entire life cycle of that data, from collection to destruction.
In practice, you must know what information you hold, why, where it is stored and who can access it. This is often the weak point: very few businesses have this mapping. The good news is that once this groundwork is done, the rest of compliance follows almost naturally.
Appoint a privacy officer
The law requires that someone be officially responsible for the protection of personal information. By default this role falls to the person with the highest authority in the company, but it can be delegated in writing. In an SMB, it is often the owner, the operations manager or the administrative lead.
This officer need not be a lawyer or an IT specialist. Their role is to ensure the rules are respected, handle access and rectification requests, and act as a point of contact for the Commission and the public. Their contact details must be published, usually on your website.
It is a simple formality, but its absence is a visible and easily flagged shortcoming. Naming this officer and publishing their contact details is one of the first quick, low-cost actions in a compliance effort.
Keep an incident register
Any incident affecting personal information must be logged in a dedicated register: an email sent to the wrong recipient, a stolen laptop, a computer intrusion, a lost USB key. The register notes the nature of the incident, the data involved, the measures taken and the assessment of the risk of harm.
When an incident presents a risk of serious harm, you must notify the Commission as well as the affected individuals. The line between a minor and a serious incident calls for judgement, and that judgement must rest on documented facts rather than an impression.
Good cybersecurity management makes this obligation far easier: logging accesses and events lets you reconstruct what happened, gauge the real scope and decide calmly, rather than in the panic of a late discovery.
Run a privacy impact assessment
Before launching a project involving personal information (new software, a move to the cloud, data sharing with a partner), the law requires a privacy impact assessment. The idea is to think through the risks upfront, not to discover them after the damage is done.
For an SMB, an assessment need not be a hundred-page report. A clear grid is usually enough: what data is involved, which provider will process it, where will it be hosted, what protections are in place, and is there a transfer outside Quebec?
Documenting this reasoning protects you twice. It demonstrates your diligence in case of an audit, and it speeds up future decisions: a reusable assessment framework avoids starting from scratch with each new project.
The security measures actually expected
The law speaks of reasonable security measures without listing them rigidly. In practice, a precise and recognized technical baseline is expected: strong authentication (MFA) on sensitive accounts, encryption of data and backups, access management based on least privilege, and logging that traces accesses in case of incident.
On top of this baseline come tested backups and a credible recovery plan. These measures are not just a regulatory checkbox: they are also your best defence against ransomware and outages, which remain the leading causes of data loss in SMBs.
Our cybersecurity and compliance page details these controls. The key lesson is that compliance and security advance hand in hand: strengthening one improves the other, which makes the investment doubly worthwhile.
Where to host your data: the sovereignty question
Law 25 strictly governs transfers of personal information outside Quebec. You can still use a foreign provider, but you must then assess the protection it offers and, where applicable, justify that choice. This is a heavy and uncertain process, especially with giants subject to extraterritorial laws.
The simplest path is to host your data in Canada. A sovereign cloud hosted in Quebec guarantees that your information stays under Canadian jurisdiction, shielded from foreign requests, which immediately removes a large share of grey areas.
For a Montreal SMB, combining local managed hosting with a compliance approach simplifies life considerably. You address performance, security and the legal dimension at once, with a single contact who understands the Quebec context.
Document and prove your compliance
With Law 25, what is not documented does not exist. In case of a complaint, an incident or an audit, you will need to present your written policies, your incident register, your access logs and your backup evidence. Documentation makes the difference between an SMB caught off guard and one able to demonstrate its diligence.
This requirement often deters owners, who see it as paperwork. Yet once the templates are in place (privacy policy, incident procedure, assessment grid), upkeep becomes routine and light, especially when integrated into daily operations.
Entrusting this record-keeping to a managed IT provider in Montreal has a concrete benefit: the technical documentation stays up to date without you having to think about it, and a competent third party can attest to it.
Train your team: the human factor
Technology stops many breaches, but people remain the prime target. A well-crafted phishing email fools even careful staff, and a single careless click can expose personal information. Regular, short and concrete awareness training markedly reduces this risk, provided it is run without blame: an employee who fears punishment hides their mistake instead of reporting it.
The goal is not to turn everyone into an expert, but to instil simple reflexes: be wary of an unexpected email, check the sender, never enter credentials from a link, and report any doubt freely. These basic habits block a large share of attempts before they reach your data.
Awareness is not a one-off session but a culture built in small, repeated doses. Combined with the technical baseline, it forms the practical backbone of Law 25 compliance, because the law expects organizational measures as much as technical ones.
Review and keep compliance alive
Compliance is not a project you finish and forget. Your data, tools and team change; a framework that is not reviewed quickly drifts out of step with reality. A periodic review, at least annual, keeps your inventory, accesses and policies accurate.
This review is also the moment to fold in lessons from any incidents and from regulatory updates. The Commission refines its expectations over time, and what was sufficient last year may need adjustment today. Staying current is far cheaper than scrambling after a complaint.
For the technical side, a managed IT partner maintains the evidence (logs, backup proofs, security settings) continuously. You keep oversight and decision-making while the day-to-day upkeep happens without monopolizing your attention.
A realistic six-step action plan
There is no need to do everything in a day. Start by inventorying the personal information you hold: where it is, in what form, for how long. Then map the accesses: who sees what, and for what legitimate reason. This foundation informs every later decision.
Next, fix the obvious gaps, the ones with the best effort-to-risk ratio: enable MFA, verify that backups actually work, restrict excessive rights. Appoint your officer and publish their details. Formalize your policies and your incident procedure.
Finally, schedule an annual review to keep the framework alive. An external assessment helps prioritize wisely: address what carries the most risk for the least effort first, rather than scattering on details while gaping holes remain.
| Law 25 obligation | Concrete measure | Typical owner |
|---|---|---|
| Privacy officer | Written appointment + published contact | Management |
| Incident register | Logging + assessment procedure | IT / managed provider |
| Data security | MFA, encryption, tested backups | IT / managed provider |
| Privacy impact assessment | Grid per sensitive project | Management + IT |
| Incident notification | Documented response plan | Management + IT |
FAQ
Does Law 25 apply to very small businesses?
Yes. The law sets no size threshold: any organization that collects personal information in Quebec is concerned. The expected effort is simply proportional to the size of the business and the sensitivity of the data.
Must data be hosted in Canada?
It is not an absolute obligation, but it clearly simplifies compliance. A transfer outside Quebec requires assessing and sometimes justifying the protection offered; hosting in Canada avoids this and greatly reduces legal risk.
What are the penalties for non-compliance?
Administrative and penal fines can be very high for serious breaches. Beyond the amount, it is often the reputational damage and loss of customer trust that cost an SMB the most.
How long does it take to become compliant?
A well-supported SMB lays the foundations in a few weeks: data inventory, MFA, reliable backups, an appointed officer and written policies. Compliance then becomes light, ongoing upkeep rather than a one-off project.