How does Quebec's Law 25 affect the tools I use?
Law 25 is the strictest privacy regime in Canada and it constrains what you may collect, where it may be stored, how long you keep it, and what you must disclose — which in practice constrains your CRM configuration, your forms, and any tool that moves personal information outside Quebec.
Law 25 modernized Quebec's private-sector privacy act in phases between 2022 and 2024, and its obligations now apply in full to any business handling the personal information of people in Quebec — including businesses based elsewhere. The structural requirements come first: someone in your organization is the person responsible for the protection of personal information (by default the highest-ranking officer, delegable in writing, with contact details published), you must keep a register of confidentiality incidents, and incidents presenting a risk of serious injury must be reported to the Commission d'accès à l'information and to the affected individuals. None of that is a tooling decision on its face, but all of it becomes one: an incident register is only maintainable if your systems can tell you what was accessed, and a breach is only reportable on time if someone can actually enumerate whose data a compromised tool held.
The obligation that reaches deepest into an ordinary SMB stack is the privacy impact assessment for communicating personal information outside Quebec. Most SaaS tools — the CRM, the email platform, the analytics suite, the AI service — process data in the US, so before adopting one you are required to assess whether the information will receive adequate protection, considering the destination's legal regime and the contractual safeguards. In practice this converts tool selection into a documented exercise: what personal information does this vendor touch, where does it process and store it, what does its data processing agreement commit to, and can we get the data back and deleted. Teams that build a one-page assessment template and fill it per vendor turn a legal obligation into a manageable habit; teams that skip it accumulate a stack they cannot account for.
Consent and transparency requirements shape the front of your funnel. Consent must be clear, informed, genuinely voluntary, and requested for each specific purpose, in plain language — which ends the pre-checked box and the single consent covering marketing, analytics, and 'partners'. Technologies that identify, locate, or profile a person must be off until the person turns them on, which is why Quebec-facing sites now ship consent banners where tracking is genuinely inactive by default rather than cosmetically acknowledged. Forms should collect only what the stated purpose needs: every extra 'nice to have' field is now a liability rather than an asset. Individuals also hold rights your systems must be able to honour — access, correction, deletion, and since the final phase, portability of the computerized personal information they provided, in a structured, commonly used format. A CRM where deletion is a support ticket to a vendor who 'archives' instead is a compliance gap you inherited by purchase.
The penalty ceiling explains why this law changed vendor behaviour where earlier Canadian regimes did not: administrative monetary penalties run up to $10 million or 2% of worldwide turnover, and penal provisions up to $25 million or 4% of worldwide turnover, whichever is greater. Enforcement to date has focused on bringing organizations into line rather than maximal fines, but the ceiling means 'we are too small to matter' is a bet rather than a policy — and the register, the designated officer, and the assessments are exactly the artifacts that demonstrate good faith if the Commission ever asks.
Businesses serving Quebec customers inherit these obligations even when they are not based there, and the practical posture that follows is the one we build to: treat Law 25 as the ceiling for your whole Canadian stack, because a system that satisfies it clears PIPEDA and every other provincial regime without separate work. Retention schedules configured in the tools rather than promised in a policy, consent recorded as data with purpose and date, deletion that actually deletes, and a vendor list you can produce on request. Building for the stricter standard is generally cheaper than retrofitting after a complaint — retrofits happen under deadline, against systems that were never designed to answer the questions being asked.
Last reviewed 28 August 2026