Security

Real offensive depth

Testing and defence led by a published security researcher with six CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Compliance

Quebec Law 25 for B2B SaaS

If your SaaS product has even one paying customer with users in Quebec, Law 25 likely applies to you, and the penalties (up to 4% of worldwide turnover or 25 million dollars, whichever is higher) are steeper than anything else in Canadian privacy law. Most B2B SaaS companies outside Quebec have not scoped this properly, which makes it one of the more winnable compliance gaps a security team can close.

What Quebec Law 25 Actually Is

Law 25 (formerly Bill 64) overhauled Quebec's private sector privacy statute in phases between 2022 and September 2024. It is now the strictest privacy regime in Canada, closer in spirit to GDPR than to PIPEDA. It applies based on where the individuals whose data you process are located, not where your company is headquartered. A SaaS vendor in Toronto, Waterloo, or Austin with Quebec-based end users or customer contacts is in scope the same as a company operating out of Montreal.

The law introduced mandatory breach notification to Quebec's privacy regulator (the CAI) and to affected individuals, a right to data portability, consent requirements for automated decision-making, and privacy impact assessments for any project involving personal information. It also requires a named privacy officer, by default the company's most senior executive unless that role is formally delegated.

Why This Matters More for B2B SaaS Than It Looks

Founders often assume B2B products are lower risk because they are not consumer-facing. That assumption does not hold under Law 25. The law protects any personal information, including employee data, contact records in your CRM, and usage telemetry tied to identifiable individuals at customer companies. If your platform stores names, emails, or behavioural data on Quebec-based employees of your customers, that data is in scope, regardless of whether your own headquarters or servers sit outside the province.

This is also exactly the kind of question that shows up in enterprise vendor security reviews now. Canadian enterprise buyers, particularly in finance and government-adjacent sectors, are adding Law 25 attestations to procurement checklists alongside SOC 2. A SaaS company that cannot answer a Quebec privacy question cleanly loses deals to one that can, even outside Quebec.

The Real Penalty Structure

Law 25 penalties are tiered and administrative fines can reach 4% of worldwide turnover or 25 million dollars for the most serious violations, whichever amount is greater. Individual offences under the penal provisions can run into the millions as well. These numbers were set deliberately to mirror GDPR's scale, and the CAI has shown it is willing to investigate. For a growth-stage SaaS company, a Law 25 finding is not a slap on the wrist, it is a board-level event and a due diligence flag in any future financing or acquisition.

Where B2B SaaS Companies Usually Fall Short

  • No privacy officer designated. Many companies have not formally named one, defaulting the obligation to the CEO by law.
  • Missing privacy impact assessments. New features that touch personal data, especially anything involving analytics or AI features, need a documented assessment before launch, not after.
  • Consent language that predates the law. Terms of service and privacy policies written for PIPEDA alone rarely meet Law 25's more specific consent standards.
  • No breach notification runbook. Law 25 has firm timelines for notifying the CAI and affected individuals. Improvising this during an actual incident is where companies get penalized twice, once for the breach and once for the response.
  • Vendor and subprocessor gaps. If your subprocessors (hosting, analytics, support tooling) touch Quebec residents' data, your contracts need to reflect that.

How Traztech Scopes a Law 25 Engagement

Because Law 25 is a defined, bounded statute rather than an open-ended framework, it is one of the more tractable compliance projects a lean SaaS team can run. traztech's approach starts with a data mapping exercise to confirm actual exposure, since many companies overestimate or underestimate their Quebec footprint until someone actually traces where personal information flows. From there we build or update the required privacy impact assessment process, formalize the privacy officer designation, rewrite consent and disclosure language to match the statute, and put a breach notification runbook in place that your team can actually execute under pressure. Full detail on our approach lives on the Quebec Law 25 framework page.

For companies also chasing SOC 2 or building a broader compliance program, Law 25 work overlaps meaningfully with our compliance solutions practice, particularly on breach response and data governance controls that satisfy both regimes at once. We scope it as a standalone engagement or as a module inside a larger compliance sprint, depending on where you already stand.

The Canadian Privacy Picture Beyond Quebec

Law 25 does not exist in isolation. It sits alongside PIPEDA at the federal level and signals where Canadian privacy regulation is heading generally, toward stricter consent standards, mandatory breach reporting, and real financial consequences. B2B SaaS companies based in Toronto, Ottawa, Vancouver, or Calgary that serve Quebec customers need a program that treats Quebec as its own jurisdiction, not an afterthought bolted onto a national privacy policy. Companies building toward the Canadian Program for Cyber Security Certification (CPCSC) baseline should also fold Law 25 obligations into that same governance structure rather than running parallel, duplicate processes.

Why This Is a Winnable Niche

Unlike SOC 2, which is broad and can run for months, Law 25 compliance is narrow enough to close in weeks for most B2B SaaS companies, provided someone actually maps the exposure correctly. That makes it an efficient first compliance win, and it removes a specific, recurring objection from Canadian enterprise sales cycles. For a boutique consultancy, this is exactly the kind of engagement where a focused, senior-led team beats a generic compliance platform: the statute is specific enough that templated software cannot substitute for someone who has actually read it and mapped it against your product.

Getting Started

If your SaaS company has Quebec-based customers, employees, or end users and you have not formally scoped Law 25 exposure, that is the first gap worth closing before it shows up in a procurement questionnaire or, worse, a breach. Contact traztech to scope a Law 25 assessment for your platform.

Not ready for a call? Same.

Get the playbook, not a sales pitch

If this was useful, Jacob sends a few short, practical notes on locking down your startup without a big security team. No fluff, unsubscribe in one click. Just reply if you want to talk; it reaches him directly.

From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.

Need help with any of this?

We help startups build secure, scalable infrastructure. Book a free strategy call and let's talk about your stack.

Book a free consultation