Skip to content
discover Hilo Intelligence
Hilo Tech wiki

Law 25 Guide

A complete guide to Quebec's Law 25 (formerly Bill 64) for small and medium-sized businesses, scope, consent, breach notification, privacy officer, individual rights, cross-border transfers and penalties.

Last updated: 2026-04-19

This guide explains, in plain language, how a Quebec SMB can comply with the Act to modernize legislative provisions as regards the protection of personal information: commonly called Law 25 (enacted as Bill 64 in 2021, fully in force as of September 22, 2024).

It is written for executives, IT leads and privacy officers of SMBs that operate in Quebec and collect, use or communicate personal information, which is effectively every business based in the province.

Who this guide is for

  • SMB executives: to understand the legal obligations, risk exposure and decisions ahead.
  • Internal IT leads: to map the technical controls required (logging, access, encryption, backup, incident response).
  • Newly designated privacy officers: to understand the role, its powers and responsibilities, now mandatory for every private business in Quebec (s. 3.1 PPIPSA).
  • Legal and compliance teams: as an operational reference to cross-check against formal legal opinions.

Primary sources cited in this guide

This guide is not a substitute for legal advice. It draws on:

When we cite a specific rule, we reference the corresponding section of the PPIPSA so you can return directly to the statute.

How to use this guide

Chapters are designed to be read in order, but each is self-contained. Start with Scope and definitions if this is your first exposure to Law 25, or jump to the chapter that answers the question at hand (e.g. "a laptop has been stolen, what do we do?" → Breach notification).

Each chapter closes with:

  • a quick checklist of obligations,
  • common mistakes we see in the field,
  • questions to ask your IT provider or legal counsel.

Our role: the IT layer, in partnership with a lawyer

Hilo Tech is not a law firm. We are a managed IT services firm. On a Law 25 compliance engagement, our contribution covers the technology and operational side:

  • technical mapping of personal information flows (where it lives, who has access, how it moves);
  • implementation of the required IT controls (encryption, logging, access management, backup, incident response plan);
  • authoring internal procedures (breach notification, access requests, retention and destruction);
  • configuration of the tools (Microsoft 365, Azure, Canadian backups, EDR, identity management) to meet the requirements.

For the legal analysis, the drafting of official policies, and the interpretation of the Act in complex cases, we partner with a lawyer appointed by the client (or, if the client does not have one, we can suggest an external firm). Every Law 25 compliance project is carried out jointly with legal counsel, the lawyer validates the legal scope, Hilo Tech handles the IT execution.

If you want your current posture assessed, Pascal Dupuis: Hilo Tech's designated privacy officer, offers a free discovery call to identify the major IT-side gaps, help prioritize action, and flag where outside legal counsel will also be needed.

Hilo Tech also delivers a structured Law 25 compliance audit (IT track): review of existing technical controls, mapping of processing activities, infrastructure-side risk assessment, prioritized action plan, and follow-through on implementation. Deliverables are agreed before the engagement begins, and pricing is set after the discovery call.

Pages in this collection

  1. 01

    Scope and definitions

    Who Law 25 applies to, since when, the key terms to know (personal information, sensitive information, privacy officer) and what the Act does not cover.

  2. 02

    Consent

    Quebec's Law 25 consent rules — what makes consent valid, how to obtain it, document it and withdraw it, plus the special cases of sensitive information and minors.

  3. 03

    Confidentiality incident notification

    Step-by-step procedure for a confidentiality incident — risk-of-serious-harm assessment, notification to the CAI and affected individuals, incident register, timelines and responsibilities.

  4. 04

    Person in charge of the protection of personal information

    Mandatory designation, role, responsibilities, powers and published contact details of the privacy officer in a Quebec SMB.

  5. 05

    Individual rights

    The six rights every Quebec individual can exercise — access, rectification, de-indexing, portability, withdrawal of consent and information about automated decisions. Deadlines, motivated refusals, remedies.

  6. 06

    Transfers outside Quebec

    When a PIA is required, how to assess the equivalence of protection offered by a third country, which contractual clauses to include, and the real impact on SMBs using Microsoft 365, AWS, Salesforce or any out-of-province SaaS.

  7. 07

    Sanctions and penalties

    The three sanction regimes under Law 25 — administrative monetary penalties up to $10M or 2% of global revenue, penal fines up to $25M or 4% of global revenue, and civil recourse with $1,000 minimum punitive damages.

  8. 08

    Templates and samples

    Reusable starting points for your privacy policy, consent notices, incident procedure, incident register and PIAs. To be adapted by a lawyer before publication.

  9. 09

    Version history

    Log of changes to this guide, new chapters, legal updates, corrections to article citations, changes in CAI practice.