42 / 63Quebec Law 25 Compliance

Quebec Law 25 compliance, built into the systems and not just the policy

Law 25 Quebec compliance for Canadian businesses, where retention rules, incident registers and portability requests actually work.

  • Engineering, not opinion
  • Delivery in English and French
  • Canadian data residency available
THE WORK

Law 25 Quebec compliance, three pillars, one operator.

One Canadian team finds the data, builds the register, and makes the rights answerable from real systems, so the Quebec data protection rules land in production instead of in a binder.

  1. 1

    Find the data

    Where Quebec personal information actually lives, including the systems nobody wrote down: a reporting database, an old CRM export, a shared drive. The Law 25 requirements start with what you hold, not with what the asset list says you hold.

  2. 2

    The incident register

    A confidentiality incident register that fills itself, plus the reporting path behind it. Section 3.8 asks for a register the regulator can call for, not a spreadsheet somebody remembers to update.

  3. 3

    Rights that answer

    Access, rectification, portability and de-indexing, served from production rather than from promises. Portability has been a right since 2024-09-22, and most estates still can't answer one without a manual project.

THE PROOF

Built to last. Evidence over promises.

Law 25 penalties run in two tiers, and the administrative one reaches $10M or 2% of worldwide turnover, whichever amount is greater.

IN PRODUCTION

Quebec rights answered from Canadian systems.

A policy that says records are destroyed after seven years is a promise about what the systems do. On the estate we were handed, nobody had checked whether they could. We found personal information in four places nobody had written down, including a reporting database, then built the job that makes the policy true.

SMEnode · Engineering principle
  • CCIE Data Center
  • CCIE Security
  • CCDE Design
  • Canadian data residency
THE DEEP DIVE

Law 25 Quebec compliance, made real.

A lawyer can write your retention rules. Somebody still has to make the systems obey them.

What Law 25 penalties actually reach.

The distance between a published policy and a working system is where the exposure sits. Law 25 penalties come in two tiers: administrative penalties up to $10M or 2% of worldwide turnover, whichever is greater, and penal offences up to $25M or 4% (source: Act respecting the protection of personal information in the private sector). The law also gives individuals a private right of action with a minimum of $1,000 in punitive damages, which is rarer than the fines and easier to trigger. A policy your systems contradict is evidence against you, not protection.

Where the risk actually sits.

Risk sits in three predictable places. Personal information in systems nobody wrote down, usually a reporting database, an old CRM export and a shared drive. Destruction schedules that exist on paper while the data stays. And a confidentiality incident register kept as a spreadsheet somebody remembers to update, when section 3.8 asks for a register the regulator can ask to see. Quebec data protection work is mostly this: closing the gap between the written rule and the system that quietly ignores it.

The dates are settled and the reach is national.

Quebec's Law 25, or loi 25 in French, has been phasing in since it was tabled as Bill 64. Since 2022-09-22 you've needed a designated person responsible for protecting personal information, the privacy officer Quebec's regulator expects you to name, plus an incident register. Since 2023-09-22 most obligations apply, including governance rules you publish and explicit consent. Since 2024-09-22 portability is a right, so a person can ask for their data in a structured, commonly used format. And this Quebec privacy law reaches Canadian businesses outside Quebec: what matters is whose personal information you hold, not where your office is.

Control checklist
THE METHOD

How our Loi 25 and Quebec privacy law work runs.

Four steps, and step 01 is the one that changes the plan. Every organisation we meet can name three or four systems holding personal information, and every discovery finds more. The reporting database nobody decommissioned. A vendor portal with names in it. Backups that outlive the destruction schedule by years. You can't write a defensible retention rule for data you don't know you have.

  1. Step 01

    Find it

    Discovery across applications, databases, file shares, backups and vendors, producing a map of what personal information you hold, where it sits, and which of it belongs to Quebec residents.

  2. Step 02

    Decide and write

    Retention and destruction periods per data type, the governance rules the law requires you to publish, and the designated responsible person's remit written down rather than assumed.

  3. Step 03

    Make the systems obey

    Deletion jobs, retention settings, export paths for portability, and de-indexing where it applies. This is engineering work, and it's the half nobody else sells.

  4. Step 04

    Prove it

    A confidentiality incident register that populates from your own alerting, a rehearsed reporting path, and records showing a request was answered inside the statutory window.

QUESTIONS

Law 25 Quebec questions, answered straight.

Answers first, including whether this reaches you at all. An architect takes the call, not a salesperson.

Probably, and this is the most common wrong assumption we meet. The test is whose personal information you hold, not where your office sits. A Toronto or Vancouver business with Quebec customers, Quebec employees or a Quebec subsidiary is inside it. Formerly Bill 64, the law reaches any organisation collecting or holding personal information about Quebec residents. We'll help you settle the answer before you spend anything.

Two tiers, and most summaries name only one of them. Administrative monetary penalties, issued by the Commission d'acces a l'information, reach $10M or 2% of worldwide turnover, whichever is greater. Penal offences reach $25M or 4%, and repeat offences can double. Separately, individuals have a private right of action with punitive damages starting at $1,000 per person, which is the exposure most people miss. None of this is legal advice, and your counsel should confirm your own position.

The systems. A retention policy is a promise about what your infrastructure does, and in most estates nothing enforces it. What's left is finding the data the policy didn't know about, building deletion that runs on schedule, creating an export path so a portability request doesn't become a manual project, and making the incident register populate itself. Your counsel wrote the obligation. We make it true.

Quebec's rules are stricter and they bite harder. Explicit consent, published governance rules, an assessment before you send data outside Quebec, portability since 2024, and a private right of action the federal statute doesn't offer. If you operate across Canada you'll answer to both, and the practical move is building to the Quebec standard once rather than maintaining two sets of rules. We'll map what you already have against both.

When nobody senior will own the designated responsible role, since that appointment isn't something an external team can hold for you. When your counsel hasn't yet decided your scope, because engineering to the wrong scope costs twice. And when a system replacement is already funded for this year, since we'd build retention into the new platform instead of the one you're retiring.

A map of where Quebec personal information lives, retention and destruction rules written per data type, deletion jobs that run on schedule, an export path a portability request can use, and an incident register that populates from your own alerting. The documentation is yours, the work stays in your tenant, and your designated responsible person gets a rehearsed reporting path rather than a policy PDF.

LET'S CONNECT

A senior engineer replies within an hour, 24/7.