01
What is Québec’s Law 25?
Law 25 (S.Q. 2021, chapter 25) is an amending statute that modernizes personal information protection in Québec. Adopted in 2021, it notably amended the private-sector law, P-39.1, and the public-sector law, A-2.1. The obligations are set out in those amended laws. Its main provisions took effect in stages from September 2022 to September 2024.
It concerns how organizations collect, use, disclose, retain and protect personal information. Its scope extends well beyond a website’s cookies.
Start with information your teams actually use: customer records, job applications, payroll, forms, user accounts and marketing tools. For each, ask why it is collected, who needs access and when retention should end.
02
Private business or public body: which rules apply?
Businesses generally fall under P-39.1 for personal information handled in their operations. Public bodies fall under A-2.1. Their provisions, procedures and deadlines are not interchangeable. Health and social services information may fall under R-22.1, a distinct framework outside the scope of this guide.
Identify each client’s legal framework before reusing a template. One firm may advise several organizations with different obligations. Keep a separate file for each client’s officer, documents and decisions.
This guide distinguishes the main requirements of both frameworks. Also check the rules specific to your organization and the information involved. P-39.1, section 3; A-2.1, section 2.
03
A practical work plan for your organization
This suggested sequence helps assign work. Adapt it to your situation; completing it does not automatically establish compliance.
Who is responsible?
In a business, the person with the highest authority acts as privacy officer by default. Delegation must be in writing. The officer’s title and contact information must be made public. P-39.1, section 3.1.
In a public body, the person with the highest authority exercises the functions of person in charge of access to documents and protection of personal information. Written delegation is possible to eligible people specified by the Act. The body must notify the CAI of the officers’ titles, contact information and starting dates. A-2.1, section 8.
- Assign responsibilities. Identify the privacy officer and the people handling requests, incidents and updates.
- Inventory actual practices. Connect information to purposes, products, suppliers and processing locations.
- Align your documents. Compare what policies say with what teams and systems actually do.
- Prepare the workflows. Walk through an access request, a consent withdrawal and an incident report.
- Review projects and retention. Plan assessments before changes and document retention rules.
- Keep useful records. Assign an owner, next action and supporting documents to each file.
For example, before introducing a new HR system, bring together HR, the privacy officer and the supplier relationship owner. The contract, project assessment and employee policy should describe the same practices.
04
Privacy policies: write, publish and maintain
When a business collects personal information through technological means, it must publish a clear, simple confidentiality policy on its website, if applicable, and distribute it through appropriate means to reach the people concerned. The same applies to notices of changes. Public bodies must also publish the policy on their website and distribute it. P-39.1, section 8.2; A-2.1, section 63.4.
The confidentiality policy is distinct from governance rules. In the private sector, governance policies and practices require the privacy officer’s approval, and detailed information about them must be made public. In the public sector, governance rules require approval by the relevant committee and publication on the body’s website. P-39.1, section 3.2; A-2.1, section 63.3.
A generic template can describe processing you do not perform or omit a supplier you use. Start from a catalog of information, purposes, collection methods and disclosures. Validate each part with the team responsible for those operations.
Informing someone and obtaining consent are different steps
Publishing a policy does not automatically establish consent. Where consent is required, it must be clear, free and informed, and requested for each specific purpose in plain language. A written consent request must be presented separately from other information. P-39.1, section 14; A-2.1, section 53.1.
The approved version, publication date, public location and distribution records. When a product changes, identify what needs revision and who needs to be informed.
Agreely generates organization-wide or product-specific policies from your catalog, hosts their public page and lets you document distribution. Your organization remains responsible for validating the content.
05
Access, rectification and portability requests
In the private sector, an access or rectification request must receive a written reply promptly and no later than 30 days after receipt. P-39.1, section 32.
Public bodies must act on a release or correction request promptly and no later than 20 days after receipt. An extension of up to 10 days is possible if processing would impede normal operations, with written notice before the initial deadline expires. A-2.1, section 98.
In both frameworks, portability concerns computerized information collected from the person, excluding information created or inferred from their personal information. On request, it is provided in a structured, commonly used technological format unless this raises serious practical difficulties. P-39.1, section 27; A-2.1, section 84.
A public form simplifies intake. Processing also involves appropriate identity checks, finding information, assessing applicable restrictions and responding securely.
Try this scenario: someone requests their information. Who receives the request? Who searches the CRM, billing system and other tools? Who validates the response? Where do you keep the receipt date and the reply?
Agreely’s public-page form feeds the requests register after email confirmation. Email confirmation alone does not replace every identity check your circumstances may require.
06
Confidentiality incidents: record and assess
A misdirected email, unauthorized access or lost information can constitute a confidentiality incident. A business or public body must take reasonable measures to reduce risks and prevent recurrence. It must keep an incident register, including incidents that do not require notice to the people concerned. P-39.1, section 3.8; A-2.1, section 63.11.
Where an incident presents a risk of serious injury, the organization must promptly notify the CAI and the people concerned, subject to legal exceptions. Assessment notably considers information sensitivity, likely consequences and the likelihood of harmful use. The privacy officer must be consulted. P-39.1, section 3.5; A-2.1, section 63.8. P-39.1, section 3.7; A-2.1, section 63.10.
Prepare your incident record before you need it: known facts, affected information, measures taken, risk assessment, people consulted and notices sent. Document why notification was or was not considered necessary.
07
Privacy impact assessments and disclosures outside Québec
A privacy impact assessment, or PIA, is notably required for projects acquiring, developing or redesigning an information system or electronic service delivery involving personal information. Consult the privacy officer at the outset in the private sector, or the committee on access to information and protection of personal information in the public sector. P-39.1, section 3.3; A-2.1, section 63.5.
The assessment should inform project decisions. It examines information, risks and protective measures, with a scope proportionate to the context.
Before disclosing information outside Québec or entrusting its collection, use, disclosure or retention to a provider outside Québec, a PIA is required, subject to statutory exceptions. The assessment must establish adequate protection, and the disclosure must be covered by a written agreement. P-39.1, section 17; A-2.1, section 70.1.
For a new cloud tool, ask where information is processed, which subcontractors are involved and what safeguards apply. Hosting in Canada alone does not resolve the question of disclosures outside Québec.
08
Retention and destruction: define the end of the lifecycle
Once the purposes are fulfilled, a business must destroy the information or anonymize it for serious and legitimate purposes, subject to statutory retention periods. P-39.1, section 23.
A public body must also destroy the information or anonymize it for public interest purposes, subject to the Archives Act or the Professional Code. A-2.1, section 73.
In both frameworks, regulatory anonymization requirements apply. Removing a name is not necessarily sufficient to prevent direct or indirect identification.
There is no single retention period for every record. Connect each rule to an information category, a purpose and a starting event. Validate applicable retention obligations before acting.
For example, ending a customer relationship can trigger a deadline calculation under your declared rules. A calculated deadline is not an executed deletion: source systems, copies and exceptions still need attention.
09
What can Law 25 management software do?
Software can bring together documents, registers and follow-up otherwise scattered across emails and spreadsheets. Evaluate it against everyday workflows.
- Policies: can you start from actual practices and retrieve published versions?
- Rights: do requests reach a register where you can track their progress?
- Governance: can you connect suppliers, assessments and supporting records?
- Multiple clients: can one account work across several organizations?
- Integrations: can your ERP send useful events through an API?
Agreely brings these capabilities together in a platform built in Québec. Its cookie banner handles the website journey; the platform supports broader privacy operations. No software replaces organizational decisions or advice tailored to your circumstances.
10
Common questions about Law 25
Does a small business need to address Law 25?
Business size alone does not remove private-sector privacy obligations. Assess the personal information you handle, your activities and the applicable legal framework. P-39.1, section 1.
Is a cookie banner enough?
No. Website consent is one workflow. Policies, rights requests, incidents and governance require their own processes. Start by identifying what your website actually collects and which technologies require consent.
Must every organization buy software?
Choose tools according to your workload. A small team may organize its work with well-maintained documents and registers. A dedicated platform becomes useful when requests, versions, organizations and contributors become harder to coordinate.
Where should we start if our practices are scattered?
Choose one real workflow, such as an access request or a new supplier. List the people involved, the information, the documents and the next decisions. Use that first complete file to identify what is missing elsewhere.
Put it into practice
Give your privacy work a home.
Explore the tools behind the workflows in this guide, or start with your website’s cookie consent.
Explore the Law 25 platform ↗Discover the cookie banner ↗