Quebec Law 25 Turns Privacy Engineering Into an Operational Requirement

Quebec’s Law 25 phased major privacy reforms into force between 2022 and 2024. Its lasting impact is the movement of privacy decisions into system design and executive accountability.

Quebec adopted the legislation commonly known as Law 25 in 2021. The reforms modernised the province’s public- and private-sector privacy laws through a three-year implementation.

The largest group of operational changes took effect on 22 September 2023. By then, organisations needed more than an updated privacy policy. They needed governance, impact assessments, default settings, rights handling and a credible breach process.

Responsibility begins at the top

The person exercising the highest authority in an organisation is, by default, responsible for the protection of personal information, although the function may be delegated in writing. Contact information for the responsible person must be published.

This prevents privacy from becoming an ownerless specialist topic. Delegation can move day-to-day work, but it should not remove executive visibility into risk and decisions.

Organisations should have a formal mandate, reporting route and escalation criteria for the privacy lead.

Privacy impact assessments enter the project lifecycle

An assessment of privacy-related factors is required for projects involving the acquisition, development or redesign of an information system or electronic service-delivery system that handles personal information.

The assessment must be proportionate to the sensitivity, purpose, quantity, distribution and medium of the information. It should occur while the organisation can still change the design—not after procurement or deployment.

A useful assessment asks:

  • Is every data element necessary?
  • Can identifiers be separated or pseudonymised?
  • Who can access production and backup copies?
  • What happens when the purpose ends?
  • Can an individual exercise rights across all replicas?
  • Which suppliers and jurisdictions are involved?

Transfers outside Quebec require assessment

Before communicating personal information outside Quebec, an organisation must conduct an assessment of privacy-related factors and establish that the information will receive adequate protection. The communication must be governed by a written agreement addressing the relevant conditions.

This is not a simple country allow-list. The organisation considers the sensitivity and purpose, protection measures, contractual safeguards and applicable legal regime.

Cloud architecture therefore becomes part of transfer analysis. Support access, disaster recovery and global logging can move information even when the primary region remains in Canada.

The default must protect privacy

Where a technological product or service offered to the public has privacy settings, those settings must provide the highest level of confidentiality by default, subject to statutory exceptions.

This challenges growth patterns that rely on users discovering and disabling sharing after registration. Default settings should reflect necessity and user expectations at the point of use.

Incidents need assessment and a register

Organisations must take reasonable measures to reduce harm from confidentiality incidents and prevent recurrence. Incidents presenting a risk of serious injury must be reported to the regulator and affected individuals as required.

A register of confidentiality incidents must be maintained, including incidents below the notification threshold. That register supports trend analysis and demonstrates that the organisation assessed risk rather than simply counting notifications.

A practical Law 25 control set

Organisations handling Quebec personal information should maintain:

  1. A named privacy officer and published contact route.
  2. A data and system inventory.
  3. Impact-assessment gates in procurement and development.
  4. Transfer assessments and written supplier agreements.
  5. Privacy-protective defaults and consent evidence.
  6. Retention, destruction and compliant anonymisation processes.
  7. Rights-request workflows across live, archived and supplier-held data.
  8. A confidentiality-incident register linked to security response.

Privacy moves into architecture

Law 25 is important beyond Quebec because it demonstrates where privacy regulation is heading. Accountability is moving from published intentions to design choices that can be tested.

An organisation either knows where personal information goes, why it is there and how it is protected—or it does not. No privacy notice can repair that gap on its own.

Official sources

This article provides general information and is not legal advice.

Leave a Reply

Your email address will not be published. Required fields are marked *