Law 25 and Data Breaches in Quebec: What You Must Do
If personal information your business holds is lost, stolen or accessed without authorisation, Quebec's Law 25 imposes specific obligations. Here is what they are, in plain language — and the preparation that makes them manageable.
Quebec’s Act to modernize legislative provisions as regards the protection of personal information — widely called Law 25 — changed what happens after a breach. The confidentiality-incident provisions have been in force since September 2022, and they apply to businesses of every size.
This is a practical overview, not legal advice. For decisions about notification and liability, involve counsel early.
What counts as a confidentiality incident
Broadly, any access, use or communication of personal information that isn’t authorised by law, or the loss of that information, or any other breach of its protection. That covers more than a dramatic hack:
- Ransomware that touched a file server holding client records
- A laptop with unencrypted customer data left in a taxi
- An email containing personal details sent to the wrong recipient
- A former employee who still had access to the client database
The obligations, in order
1. Act to reduce the risk. Take reasonable measures to limit the harm and prevent a repeat — contain the incident, revoke access, rotate credentials.
2. Assess whether there’s a risk of serious injury. The assessment considers the sensitivity of the information, the anticipated consequences of its use, and the likelihood that it will be misused.
3. If there is, notify. The Commission d’accès à l’information (CAI) and the people whose information was involved must be notified promptly.
4. Record it — every time. Every confidentiality incident goes in a register, including those you conclude don’t present a risk of serious injury. The CAI can ask to see it.
Why the technical investigation decides everything
Every one of those steps depends on one question: what was actually accessed?
“The attacker could theoretically have reached the client database” and “the attacker exfiltrated the client database” lead to very different conclusions. You can’t make that call — or defend it later — without evidence. This is why the first hour of an incident matters so much: powering machines off and wiping logs destroys exactly the evidence you’ll need.
What to have ready before anything happens
- A named person responsible for the protection of personal information. By default that’s the person with the highest authority in the business.
- An inventory of where personal information lives — systems, shared drives, spreadsheets, email.
- An empty incident register, so the first entry isn’t created in a panic.
- Logging that’s actually retained, so there’s evidence to assess scope from.
- Tested backups, so containment doesn’t mean choosing between evidence and getting back to work.
The penalties are real
Law 25 introduced administrative monetary penalties and penal fines that scale with company size and can reach into the millions. For most small businesses the practical risk isn’t the maximum fine — it’s a poorly handled incident, an unrecorded breach discovered later, or a notification made without evidence to support it.
The technical side of this is what our cybersecurity practice handles. For a situation that frequently triggers these obligations, see someone left and still has access.
- Law 25
- Compliance
- Privacy
- Quebec