Act 25 Compliance

Act 25: Specific Requirements for Quebec Businesses

Act 25: Specific Requirements for Quebec Businesses

Two reassuring misconceptions are circulating among Quebec SME leaders. The first: “Bill 25 is for large companies.” The second: “I have a cookie consent banner on my website, so I’m compliant.” Both are false, but rest assured—understanding why takes only a few minutes, and that’s more than enough to know where to start.

This article isn’t just a theoretical checklist. We’ll walk you through, question by question, what the law actually requires and why, in the form of a brief self-assessment of Bill 25’s requirements for Quebec SMEs. Not to make you feel like a failure, but so you’ll walk away with a clear picture of your situation and a clear next step.

Who Is Actually Covered by Act 25

The size of the business makes no difference. Act 25 applies to any organization that collects, uses, or discloses personal information about Quebec residents, whether it is a one-person business or a multinational corporation. Businesses located outside Quebec that do business with Quebec residents are also covered. The law came into effect in three phases between September 2022 and September 2024; as of September 22, 2024, all of its provisions are in effect, and the Quebec Access to Information Commission (CAI), the body responsible for enforcing it, significantly stepped up its oversight in 2025 and 2026.

What surprises business leaders the most is that it’s not just your customers’ data that matters. Information about your employees, suppliers, and even visitors to your website falls within the scope of the law. If your small business maintains an email list, a payroll system, or a contact form, you are subject to the law—period.

No, a cookie banner does not make you compliant

This is one of the most widespread and costly misconceptions. The cookie consent banner covers only a very specific fraction of your obligations: consent to the collection of browsing data on your website. It’s the tip of the iceberg—and, unfortunately, the smallest part.

This is not a trivial issue. As of 2024, barely 3% of Quebec businesses had actually complied with the law, and 60% of SMEs said they had no intention of doing so in the short term, according to data reported by Le Devoir. A significant number of these companies were relying precisely on a cookie banner to give themselves the illusion of being in compliance.

What the banner does not cover: an inventory of all the personal data you hold; internal management of access to that data; retention and destruction policies; agreements with your subcontractors and cloud service providers; incident management procedures; and the rights of access and rectification that you must be able to honour upon request. A company can have the most polished banner in Quebec and yet, in essence, be completely non-compliant. This is the difference between superficial compliance and true compliance with Act 25: the former is visible on the website, while the latter is verified through your internal processes.

The Five Practical Requirements, Explained Simply

Here are the five pillars of Bill 25 for an SME. What they mean in practice, why they exist, and what’s most often missing in a small business. Ask yourself the question at the end of each one: it’s this simple exercise, more than the law itself, that reveals where you truly stand.

1. A designated and identified person in charge

The law requires you to appoint a person responsible for protecting personal information. The idea behind this requirement is simple: if a customer, an employee, or the CAI has a question about your data, they need to know who to contact. By default, this role falls to the person with the highest authority in the organization, often the owner in an SME, but it can be delegated or even outsourced. In practical terms, this means that this person’s name (or title) must be published on your website, not just noted somewhere internally.

2. Documented Practices, Not Just Followed Ones

What data do you collect, why, how long do you retain it, and with whom do you share it? Many small and medium-sized businesses already follow best practices informally; the problem isn’t that they’re doing things wrong, it’s that they’ve never put them in writing. However, an undocumented practice cannot be verified by you or demonstrated to the CAI if questioned. Documenting it means turning a good intuition into evidence.

3. Clear and Distinct Consent, Not Hidden Consent

Before any data collection for marketing purposes or any sharing with a third party, consent must be explicit, freely given, and informed—not buried in a ten-page terms of service that no one reads. For any new project involving personal information, a Privacy Impact Assessment (PIA) is also required. The test to ask yourself: if a customer asked you, “What exactly did I consent to?”, could you answer in one clear sentence?

4. An incident response procedure, ready before you need it

Any privacy incident posing a serious risk must be reported to the CAI and to the individuals concerned as soon as possible. A record of all incidents, even minor ones, must be maintained, whether or not they are reported. This requirement exists because an incident handled in a panic, without an established procedure, consistently takes longer and leaves more traces than one handled according to a pre-established plan.

5. The Ability to Respond to an Access Request

Everyone has the right to request access to their personal information, to have it corrected, and to request its portability, and the law sets a timeframe within which you must respond. This obligation is not merely legal; it is also a matter of trust. A company capable of calmly responding to this type of request sends a strong signal to its customers, far beyond mere compliance.

Want to know exactly where your compliance gaps lie? Let's discuss it for 30 minutes—without any legal jargon.

 

Book a discovery call →

What You Risk, and What Really Matters

Let’s talk numbers, honestly and accurately, because the penalty system under Act 25 actually consists of several tiers, not a single catch-all amount.

First, administrative monetary penalties (AMPs): the CAI can impose these directly, following an investigation, without going through the courts, up to $10 million or 2% of global revenue. A company that commits to rectifying the situation can sometimes avoid the AMP. The most serious violations, illegal use of personal information, failure to report an incident, and obstruction of a CAI investigation, may also lead to criminal prosecution in court: up to $25 million or 4% of global revenue for a company (minimum fine of $15,000, doubled in the event of a repeat offense), and up to $100,000 for an individual, including executives. Finally, affected individuals may themselves file civil lawsuits to seek punitive damages with no upper limit.

These are not abstract figures. The CAI’s 2024–2025 annual report shows that its oversight division received 549 complaints that year, a 98% increase in one year, and 514 privacy incident reports, a 559% increase over three years, 80% of which came from the private sector. Cyberattacks (160 cases) and human error (110 cases) top the list of causes. And SMEs are not spared: in June 2026, the CAI sanctioned a private medical clinic for failing to designate a data protection officer, for lacking a privacy policy, for failing to encrypt its electronic communications, and for collecting health data without valid consent. This proves that SMEs are actively monitored, not just multinational corporations.

But for an SME with 15 or 50 employees, the most likely risk is often neither a fine from the CAI nor criminal prosecution, and dwelling on these nine-zero figures more often leads to avoidance than to action. The immediate risk looks more like this: a complaint from a dissatisfied customer that turns into an investigation, a request for access that no one in the company knows how to respond to, or the loss of a contract because a client now requires compliance guarantees from its suppliers. In many sectors, compliance with Bill 25 is becoming a selling point for your institutional clients, not just a regulatory requirement.

Where to Start with Compliance

Compliance with Bill 25 is not just a legal exercise. It relies heavily on concrete technical and organizational measures, in the following order:

  • Inventory — What personal information is stored in your systems, and where?
    Data Flow Mapping — Who accesses it, from where, and for what reason?
    Access management — configure permissions according to the principle of least privilege: each person has access only to what they need for their work.
    Privacy policy — draft or revise a clear and accessible document.
    Incident response procedure — document the steps to follow before you need them.
    Appointment of the data protection officer — formalize and publish the appointment.

The good news: most small and medium-sized businesses already have some of these elements in place without even realizing it. The work often involves documenting and formalizing what already exists rather than rebuilding everything from scratch. The CAI itself confirms this: its guidelines published in January 2026 recommend starting with a comprehensive inventory of personal information held, exactly the logic behind this self-assessment, before taking any other steps. The role of data protection officer can also be outsourced, notably through a vCISO, for SMEs that lack the internal resources to fill the position full-time. No matter where you are in the process, there’s a package tailored to your situation to help you structure your approach.

In short: You don’t have to handle everything on your own, or all at once.

Compliance with Bill 25 is achieved in stages, not over a single weekend, and it’s not a feat reserved for companies with an in-house legal department. Just by reading this far, you’ve already done the hardest part: understanding what the law actually requires and identifying where you fall short in relation to the five obligations listed above.

The rest is simpler than it seems. In the vast majority of the small and medium-sized businesses we work with, much of the necessary work is already in place, even if it hasn’t been documented or formalized. That’s exactly the kind of support we offer at Eosium: we take stock of your situation with you, calmly identify what’s missing, and help you address the gaps at your own pace, without any legal jargon.

This article is for informational purposes only and does not constitute legal advice. For any questions specific to your situation, consult a legal professional. Eosium assists small and medium-sized businesses with the technical and organizational aspects of compliance with Act 25.

Book a free 30-minute consultation: the easiest way to find out exactly where you stand.

Frequently Asked Questions About Act 25

Does Act 25 apply to small businesses?

Yes, the size of the business makes no difference. Having even just one client or employee in Quebec whose personal information you hold is enough to make you subject to the law.

Is a cookie consent banner sufficient to comply with Law 25?

No. It only covers consent to the collection of browsing data on your website, which is just a small part of your obligations. The bulk of compliance hinges on your internal processes.

Who is responsible for protecting personal information in an SME?

By default, the person with the highest authority in the company, often the owner. This role can be delegated to someone within the company or outsourced.

What Should You Do in the Event of a Data Breach at a Quebec SME?

Document the incident, assess the level of risk, and then notify the CAI and the affected individuals as soon as possible if the risk is serious. Keep a record of all incidents, even minor ones.

What are the fines provided for under Act 25?

Two distinct systems. Administrative penalties, imposed directly by the CAI without going through the courts, can reach $10 million or 2% of global revenue. The most serious violations may also lead to criminal prosecution: up to $25 million or 4% for a company, and up to $100,000 for an individual. Those affected may also file civil lawsuits seeking unlimited damages.

How long does it take to bring an SME into compliance?

For the most part, a few weeks are sufficient, starting with an inventory of the personal information held. Many elements are often already in place and simply need to be documented.