Skip to content
Digital Security Consulting

Law 25 and Data Breaches in Quebec: What You Must Do

If personal information your business holds is lost, stolen or accessed without authorisation, Quebec's Law 25 imposes specific obligations. Here is what they are, in plain language — and the preparation that makes them manageable.

Published 3 min read

Quebec’s Act to modernize legislative provisions as regards the protection of personal information — widely called Law 25 — changed what happens after a breach. The confidentiality-incident provisions have been in force since September 2022, and they apply to businesses of every size.

This is a practical overview, not legal advice. For decisions about notification and liability, involve counsel early.

What counts as a confidentiality incident

Broadly, any access, use or communication of personal information that isn’t authorised by law, or the loss of that information, or any other breach of its protection. That covers more than a dramatic hack:

  • Ransomware that touched a file server holding client records
  • A laptop with unencrypted customer data left in a taxi
  • An email containing personal details sent to the wrong recipient
  • A former employee who still had access to the client database

The obligations, in order

1. Act to reduce the risk. Take reasonable measures to limit the harm and prevent a repeat — contain the incident, revoke access, rotate credentials.

2. Assess whether there’s a risk of serious injury. The assessment considers the sensitivity of the information, the anticipated consequences of its use, and the likelihood that it will be misused.

3. If there is, notify. The Commission d’accès à l’information (CAI) and the people whose information was involved must be notified promptly.

4. Record it — every time. Every confidentiality incident goes in a register, including those you conclude don’t present a risk of serious injury. The CAI can ask to see it.

Why the technical investigation decides everything

Every one of those steps depends on one question: what was actually accessed?

“The attacker could theoretically have reached the client database” and “the attacker exfiltrated the client database” lead to very different conclusions. You can’t make that call — or defend it later — without evidence. This is why the first hour of an incident matters so much: powering machines off and wiping logs destroys exactly the evidence you’ll need.

What to have ready before anything happens

  • A named person responsible for the protection of personal information. By default that’s the person with the highest authority in the business.
  • An inventory of where personal information lives — systems, shared drives, spreadsheets, email.
  • An empty incident register, so the first entry isn’t created in a panic.
  • Logging that’s actually retained, so there’s evidence to assess scope from.
  • Tested backups, so containment doesn’t mean choosing between evidence and getting back to work.

The penalties are real

Law 25 introduced administrative monetary penalties and penal fines that scale with company size and can reach into the millions. For most small businesses the practical risk isn’t the maximum fine — it’s a poorly handled incident, an unrecorded breach discovered later, or a notification made without evidence to support it.

The technical side of this is what our cybersecurity practice handles. For a situation that frequently triggers these obligations, see someone left and still has access.

Frequently asked questions

Does Law 25 apply to small businesses?

Yes. It applies to enterprises operating in Quebec that hold personal information about people, regardless of size. There is no small-business exemption for the confidentiality incident obligations.

Do I have to report every incident?

You must record every confidentiality incident in a register. You must notify the Commission d'accès à l'information and the affected people when the incident presents a risk of serious injury, assessed using factors such as the sensitivity of the information, the likely consequences and the likelihood of misuse.

Is this legal advice?

No. This is a practical overview from an engineering firm. For decisions about notification and liability, involve legal counsel early. What we help with is the technical part: establishing what happened and what was accessed, which is what those decisions depend on.

Tell us what is breaking — or what you are trying to build.

You get a senior engineer on the first call, not a salesperson. If we are not the right fit, we will say so and point you somewhere better.

Active incident? Write “URGENT” in your message and we prioritise it.