Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Compliance

How to Get Quebec Law 25: A Step-by-Step Guide

Quebec Law 25 compliance takes most mid-sized companies four to nine months and follows a fixed sequence: confirm the law applies to you, appoint a privacy officer, run a privacy impact assessment, rewrite your consent and policy language, fix your incident response process, and lock down cross-border data transfers. There is no shortcut and no single tool that does it for you, but the steps are well-defined and a lot of companies get stuck on the same two or three.

What Quebec Law 25 Actually Requires

Law 25 (formerly Bill 64) is Quebec's overhaul of its private-sector privacy statute, and it is the closest thing Canada has to GDPR. It applies to any business, anywhere in Canada or beyond, that collects or processes personal information about Quebec residents, whether or not the company is headquartered in Quebec. That catches a lot of SaaS companies in Toronto, Waterloo, and Ottawa who assumed a Quebec-specific law was a Quebec-office problem. It is not. If you have Quebec customers, employees, or even trial users, the law reaches you.

Unlike PIPEDA, which sets a national floor, Law 25 adds hard requirements: mandatory privacy impact assessments for certain projects, a named privacy officer by default (the CEO, unless someone else is designated), breach notification duties with real teeth, and consent rules that go further than "check a box at signup." We break down the full legal requirements on our Quebec Law 25 framework page, but the short version is: this is a compliance program, not a policy update.

Step 1: Determine If Law 25 Applies to You

Start by mapping where your customers, employees, and contractors actually live. If any personal information touches a Quebec resident, the law applies to that data, even if your company is incorporated in Vancouver or Calgary and has never opened a Quebec office. This step usually takes a day or two and it changes the shape of everything that follows, so do not skip it or assume based on your billing address.

Step 2: Appoint a Privacy Officer

Law 25 makes the person with the highest authority in the organization, typically the CEO, the default privacy officer unless someone else is formally designated. In practice, almost no founder wants that job sitting on their desk. Most companies delegate it to a VP of Operations, Legal, or Security, document the delegation in writing, and publish the officer's contact information as the law requires. This is a one-week task, but it has to be done properly, with a documented decision, not just a title change in Slack.

Step 3: Conduct a Privacy Impact Assessment (PIA)

This is where most timelines slip. Law 25 requires a formal privacy impact assessment, sometimes called an EFVP, before you launch any new project, system, or service that involves collecting, using, or disclosing personal information. If you already run a mature product, this means retroactively assessing your existing data flows, not just future ones. Expect this to take four to eight weeks for a typical SaaS platform: mapping data flows, identifying legal bases for collection, assessing risk to individuals, and documenting mitigations. Companies that skip a real data inventory here end up redoing the PIA twice.

Step 4: Rewrite Your Privacy Policy and Consent Mechanisms

Law 25 requires consent to be clear, specific, and given for explicit purposes, not buried in a wall of legalese at signup. You need plain-language notices, granular consent options, and a documented process for withdrawing consent. You also need a mechanism for individuals to request access to, correction of, or deletion of their personal information, and you need to actually be able to fulfill those requests within the statutory timeframe. Budget three to six weeks here, more if your product touches sensitive categories of data like biometrics or health information.

Privacy obligations piling up? Law 25 and PIPEDA readiness, with a named privacy officer where the law asks for one. Privacy officer

Step 5: Build or Fix Your Incident Response Process

Law 25 mandates notification of both the regulator (the Commission d'accès à l'information) and affected individuals when a breach poses a risk of serious harm. That means you need a documented, tested incident response plan with clear thresholds for what counts as reportable, who makes the call, and how fast notification goes out. If you already have SOC 2 or ISO 27001 controls, a lot of this overlaps with existing incident response work. If you don't, this is typically a three to five week build, including a tabletop exercise to make sure the plan actually works under pressure.

Step 6: Address Cross-Border and Third-Party Data Transfers

If personal information about Quebec residents leaves the province, whether to a cloud provider in the US, a subprocessor, or an affiliate office, you need a documented assessment showing the data will receive equivalent protection. This means reviewing vendor contracts, data processing agreements, and subprocessor lists, and updating them where they fall short. Companies using major cloud providers usually find the infrastructure is fine; it's the smaller SaaS subprocessors, the ones nobody has reviewed since the contract was signed, that create gaps.

Realistic Timeline: How Long Does Law 25 Compliance Actually Take

For a company with a straightforward SaaS product and no in-house privacy counsel, plan on four to nine months from kickoff to a defensible compliance posture:

  • Applicability assessment and privacy officer designation: 1 to 2 weeks
  • Data inventory and privacy impact assessment: 4 to 8 weeks
  • Policy, consent, and rights-request process rewrite: 3 to 6 weeks
  • Incident response build and test: 3 to 5 weeks
  • Vendor and cross-border review: 3 to 6 weeks
  • Internal rollout, staff training, and documentation: 2 to 4 weeks

Companies with messy data inventories, dozens of undocumented subprocessors, or no existing security program tend to land at the long end. Companies that already have SOC 2 or ISO 27001 in place move faster because the evidence-gathering habits and vendor review processes already exist.

The Penalties for Non-Compliance

Law 25 is the sharpest privacy stick in Canada right now. Administrative monetary penalties run up to $10 million or 2% of worldwide turnover, and penal provisions for serious violations go up to $25 million or 4% of worldwide turnover, whichever is higher. Quebec's regulator has also shown it will use these powers. This is not a law you can treat as a checkbox exercise buried in the terms of service, and it is not something a generic privacy policy template will satisfy.

Where a Compliance Partner Actually Helps

The steps above are not complicated individually. What trips companies up is sequencing, evidence quality, and knowing what a regulator will actually accept as sufficient documentation versus what merely feels thorough internally. A boutique partner earns its keep in three places: running the privacy impact assessment so it holds up under scrutiny, reviewing vendor and subprocessor agreements against the actual legal standard rather than a generic checklist, and building an incident response plan that works when tested, not just when read. This is the same discipline traztech applies across our broader compliance advisory work, whether the driver is Law 25, SOC 2, or a customer security questionnaire. We work with companies from Montreal to Vancouver, and Law 25 reach is national by design, so location has never been the limiting factor. Fit and follow-through are.

If you need a Law 25 program built properly the first time, with realistic timelines and documentation that holds up to regulator or auditor scrutiny, contact traztech to talk through where your organization actually stands today.

The Obligations That Arrived After the Headlines Moved On

Most Law 25 coverage was written around the September 2022 and September 2023 milestones, so the later obligations get missed by companies working from an old checklist. Three of them come up constantly. Privacy by default applies to any technological product or service offered to the public that collects personal information: the highest confidentiality setting must be on out of the box, without the user configuring anything, and cookie-style functionality that is strictly necessary for the service is the narrow carve-out rather than the general rule. Automated decision-making carries a disclosure duty, so if you use a model or a rule engine to make a decision about a person with no human involvement, you have to tell them at the time of the decision, and on request explain the personal information used, the principal factors and their weight, and let them submit observations to someone who can review it. Data portability has been live since September 2024, meaning a computerised copy of the personal information the individual supplied, in a structured and commonly used technological format. That last one is an engineering ticket, not a policy paragraph, and teams routinely discover they have no export path that excludes other people's data.

Keep the Incident Register Before You Need It

Law 25 requires you to maintain a register of confidentiality incidents and to provide it to the Commission d'accès à l'information on request. This is separate from the duty to notify, and it catches everyone. The register covers incidents, not just reportable ones, so the laptop left in a taxi, the support agent who pasted a customer list into the wrong channel and the misconfigured storage bucket that was open for six hours all belong in it whether or not anyone was notified. Build it as a simple structured record: date of the incident, date you became aware, description, the categories and approximate number of people affected, the assessment of risk of serious injury with the reasoning, whether the CAI and the individuals were notified and when, and the measures taken to reduce harm or prevent recurrence. Retain entries for five years from the date you became aware. A regulator asking for the register and receiving a well-kept one with several minor entries reads that as a functioning programme. Receiving an empty register from a company with two hundred staff reads as an absent one.

How to Run the Serious Injury Assessment Without Guessing

The notification trigger is a risk of serious injury, and the statute points you at the sensitivity of the information, the anticipated consequences of its use and the likelihood it will be used for a harmful purpose. Turn that into a written assessment template your on-call team can complete under pressure at eleven at night. In practice the factors that move the answer are whether the data set includes government identifiers, financial account details, health information or credentials, whether it was exfiltrated or merely exposed, whether it was encrypted and whether the key was in the same place, whether the recipient is known and cooperative, and whether the population includes minors. Write the reasoning down at the time, including the reasons for a decision not to notify. A defensible no is a documented no. The failure mode we see is a company that made a reasonable call and kept nothing, and then has to reconstruct its thinking a year later while a regulator reads over its shoulder. Notification to the CAI and to affected individuals should go out with diligence, so treat the assessment as something measured in hours rather than a matter for the next legal review.

Biometrics Have a Separate Filing Duty

If you verify or identify people using biometric characteristics, Quebec's IT framework legislation requires you to disclose the creation of a biometric database to the CAI, and the deadline is no later than sixty days before the database is brought into service. Express consent from the individual is required as well, and the general rule is that biometrics must not be the only option offered. Product teams building face or fingerprint login usually have no idea this exists, because it does not sit inside Law 25 itself. If your roadmap includes any biometric feature for a Quebec-facing product, get the disclosure filed while the feature is still in development. Retrofitting it after launch means either pulling the feature or explaining a live database to the regulator, and that is a conversation with a bad opening.

Cross-Border Transfers: What the Assessment Has to Contain

The transfer assessment is the step companies most often perform as a formality and most often fail on substance. It is not a note saying the vendor is SOC 2 certified. The assessment has to consider the sensitivity of the information, the purpose of its use, the protective measures including contractual ones, and the legal framework applicable in the destination jurisdiction, including whether that framework provides protection equivalent to Quebec principles. It has to be recorded in writing, and the transfer has to be governed by a written agreement that reflects the findings. Practically, that means a per-destination analysis rather than a per-vendor tick, and it means naming the sub-processors your vendor uses, because the chain does not end at your direct contract. The realistic first pass is to inventory every destination country in your stack, group vendors by destination, and write one assessment per destination with a vendor annex. That turns forty documents into six and is far easier to keep current.

The De-Indexing and Correction Requests Nobody Staffed For

Quebec residents can ask you to cease disseminating personal information, and to de-index a link where the dissemination contravenes the law or a court order, or where the injury caused outweighs the public interest and the right to information. They can also request access and correction, and the response window is thirty days. Companies build the policy language and then route the requests to a mailbox nobody owns. Decide now who receives these, what identity verification you require before acting, how you search across systems including backups and analytics platforms, and what a refusal letter looks like, because a refusal has to state the reasons and inform the individual of their recourse. Time yourself on a fabricated request before a real one arrives. If it takes your team eleven days to locate every copy of one person's data, thirty days is tighter than it sounds once holidays and a legal review are in it.

Where Companies Actually Fail, in Order

Across the programmes we see, the ranking is consistent. First, an incomplete data inventory, which quietly invalidates the privacy impact assessment, the transfer assessments and the rights-request process at the same time. Second, a privacy officer designation that exists on the website but has no delegated authority, no budget and no calendar time, so decisions default back to whoever is loudest. Third, marketing technology installed outside the programme, where a growth team adds a session-replay tool or an ad pixel that ships Quebec personal information to a destination nobody assessed. Fourth, consent language that is legally revised but technically unimplemented, so the policy promises granular withdrawal and the product offers one toggle that does nothing downstream. The common thread is that the legal work was done well and the engineering work was never scheduled. If your programme plan has no engineering tickets in it, it is not a programme.

When You Should Not Hire Us for Law 25

Plenty of companies do not need a consultancy here. If you are under twenty people, you have one product, your Quebec exposure is a handful of customers, and your data lives in two SaaS systems you can name from memory, you can run this internally with a competent operations lead, a good template set and a few hours of Quebec-qualified legal review on the consent and policy wording. That review is the part worth paying for, and it should come from a lawyer, not from us. We are also the wrong call if what you want is a certificate, because Law 25 does not have one, and any firm implying otherwise is selling you a binder. The place outside help genuinely pays is narrower: a real data inventory across a messy stack, a privacy impact assessment on a product feature that a regulator might actually read, a transfer position across dozens of unreviewed sub-processors, and an incident process that has been tested rather than written. If you already run SOC 2 or ISO 27001, much of that machinery exists and the marginal work is smaller than you think, which is the overlap our compliance advisory work is built around. If you would rather have a named owner carrying it rather than a project, that is a conversation about a retainer, and it is worth having only if the volume of privacy decisions in your business justifies it.

Privacy obligations piling up? Law 25 and PIPEDA readiness, with a named privacy officer where the law asks for one.

Privacy officerOr talk about a retainer

Before you go

Want the rest of this by email?

If this was useful, I send a few short notes on privacy law. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, principal of traztech. No spam, unsubscribe in one click.

Want a second opinion on where you stand?

We run SOC 2, ISO 27001 and the rest of the compliance stack for startups and SMEs, and the security testing that sits behind it. The first call is free, and we will tell you if you are not ready to start yet.

Book a free call

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.