Bill 25 compliance for Quebec businesses

Two steps. First, a free scan of your website: we read what is visible (encryption, cookies, banner, privacy policy). This is not legal advice, and not an attestation. Then Certi360 supports you: we pick up the result, walk through it, and build the tools.

The tool is explained in this article.

What Bill 25 requires!

Bill 25 has been in force since September 22, 2022, in full since September 22, 2024. It amended Quebec's Act respecting the protection of personal information in the private sector. Any organization that collects, uses or discloses personal information in the course of commercial activities in Quebec is subject to it, regardless of size.

In practice, an SMB must notably:

  • appoint a person responsible for the protection of personal information (PRPI);
  • establish governance policies: retention, destruction, roles, complaint handling;
  • know what personal information it holds, where, why and for how long;
  • inform individuals at collection and obtain informed consent when required;
  • apply security measures proportionate to the sensitivity of the data;
  • conduct a privacy impact assessment (PIA) for certain projects;
  • notify the Commission d'accès à l'information and affected individuals when an incident presents a risk of serious injury;
  • govern disclosures of personal information outside Quebec.

An SMB that invoices clients, keeps a CRM, receives CVs or sends a newsletter is already collecting personal information. A contact form or an employee file is enough.

What we see too often

In our engagements, the problem is almost never "we have never heard of Bill 25". It is usually this:

  • a website with third-party cookies and a banner that does not actually block anything;
  • a copied privacy policy that does not describe real processing;
  • cloud vendors with no clauses and no transfer assessment;
  • client questionnaires nobody can answer with evidence;
  • an incident with no procedure, and nobody who knows what to tell the CAI.

Based in Laval, Certi360 works with SMBs in Greater Montreal and across Quebec to close those gaps. Not to produce a stack of documents nobody will open.

Next: Bill 25 support

After the scan, the engagement starts. We turn each obligation into actions that fit your size, your tools and your clients. Not a program copied from a bank or a government department.

  1. Gap assessment: what is in place, what is missing, what comes first.
  2. Mapping: inventory of personal information, flows, retention and processors.
  3. Policies and notices: governance, privacy policy, collection notices, consent.
  4. Governance: PRPI mandate, roles, complaints and individual rights.
  5. Security measures: proportionate controls, aligned with ISO 27001 and ISO 27701 when useful.
  6. Incidents: notification procedure aligned with CAI timelines.

What you receive

  • Prioritized gap report, readable by leadership
  • Inventory of personal information and data flows
  • Policies, notices and procedures adapted to your organization
  • Framework for the PRPI, complaints and access rights
  • Confidentiality incident response plan
  • ISO 27001 or ISO 27701 alignment, if your clients ask for it

Request support

Bill 25 and ISO 27001: a useful combination

Bill 25 defines your legal obligations. ISO 27001 structures the security program. Together, they demonstrate reasonable diligence to the CAI and your clients, without duplicating effort. ISO 27701 goes further if you want an auditable privacy management system.

Who is this service for?

Professional services firms, technology companies, NPOs, accounting firms, integrators and any organization that processes personal information of clients, employees or citizens in Quebec. If clients send you data protection questionnaires, this service is for you.

Frequently asked questions

What is Quebec Bill 25?
Bill 25 amended the Act respecting the protection of personal information in the private sector. It imposes in-force obligations on consent, transparency, security, incident notification and appointing a person responsible for the protection of personal information.
Is my business subject to Bill 25?
Any organization that collects, uses or discloses personal information in the course of commercial activities in Quebec is subject to Bill 25, regardless of size. This includes SMBs, NPOs and cloud-based businesses.
Who is the person responsible for the protection of personal information?
Bill 25 designates by default the person with the highest authority. That role can be delegated. The PRPI oversees policies, incidents and requests from individuals. Certi360 supports this role without replacing it.
When is a privacy impact assessment required?
A PIA is required for a project to acquire, develop or overhaul an information system or electronic service delivery that involves personal information. It is a risk analysis before you build, not a cosmetic form.
Does my website need a consent banner?
Not automatically. If you set non-essential cookies, advertising or analytics, yes. If the site only does what is necessary to function, a clear policy can suffice. The test: does the banner actually block cookies before consent?
What are the penalties for non-compliance with Bill 25?
The Commission d'accès à l'information du Québec can impose administrative penalties of up to $25 million or 4% of worldwide revenue. Beyond fines, reputation and client trust are at stake.
Does Bill 25 require certification?
No. It requires proportionate security measures and documented governance. ISO 27001 or 27701 certification can nonetheless demonstrate reasonable diligence to your clients.

Move on to support

We pick up the scan (or your situation), walk through it, and build the tools: policies, governance, privacy officer, mapping, incidents, security measures. ISO 27001 or 27701, if it helps.

Request support