Short answer
Among other things, Quebec's Law 25 requires an SMB to designate a person in charge of personal information, secure that information, keep a register of confidentiality incidents, report those that present a risk of serious injury, put vendor contracts in writing and assess the privacy impact of any project to acquire, develop or overhaul an information system involving such information.
This guide is for information only and is not legal advice.
Your systems hold personal information. Section 3.1 of Quebec's private sector privacy act sets the starting point: "Any person carrying on an enterprise is responsible for protecting the personal information held by the person." Here is what the Act requires and what it means for your IT.
Law 25 at a glance: who it applies to and since when
An Act that amends the private sector privacy act (CQLR, c. P-39.1)
Law 25 (2021, chapter 25) amended, among others, the Act respecting the protection of personal information in the private sector.
That Act applies to personal information collected, held, used or communicated in the course of carrying on an enterprise, whether the business keeps it itself or through a third person (s. 1). The text sets no exemption based on the size of the business.
Phased entry into force, from 2022 to 2024
According to the Commission d'accès à l'information (CAI), Quebec's privacy regulator, in its checklist Vers la conformité à la Loi sur le privé (in French):
- September 22, 2022: person in charge of the protection of personal information, incident handling and the incident register.
- September 22, 2023: governance policies, privacy impact assessments (PIAs), and new rules for communicating information, including to a service provider or outside Québec.
- September 22, 2024: portability of computerized personal information.
All of these obligations are now in force.
Designate and publish your person in charge of personal information (s. 3.1)
Within the business, the person exercising the highest authority acts as the person in charge of the protection of personal information. That person may delegate all or part of the function in writing to any person. The title and contact information of the person in charge must be published on the business's website or, if there is no website, made available by any other appropriate means (s. 3.1).
This role touches your IT: the person in charge must be consulted from the outset of a project that requires a PIA (s. 3.3) and when assessing an incident (s. 3.7), and your IT provider must notify them of any breach of confidentiality (s. 18.3). Publish an email address that does not depend on one employee, and make sure your IT team and provider know how to reach this person.
Policies, governance and privacy policy (ss. 3.2 and 8.2)
Section 3.2 requires governance policies and practices for personal information. They must cover, in particular, keeping and destroying information, staff roles and complaint handling. They must be proportionate to your activities, approved by the person in charge and described in simple, clear language on your website. Under section 8.2, a business that collects personal information through technological means, such as an online form, must also publish a confidentiality policy written in clear and simple language.
On the IT side, these policies take shape in your systems. The CAI recommends taking an inventory of the personal information held by the business, or on its behalf by a third party, and assessing its sensitivity. Then turn your retention periods into concrete settings, such as purging old records and securely wiping devices before disposal.
Securing the information: expected IT measures (s. 10)
Section 10 requires security measures that are reasonable given the sensitivity of the information, the purposes for which it is used, its quantity, its distribution and the medium on which it is stored. The Act does not list technical measures. The practices below come from the CAI's examples and from the recommendations in the Canadian Centre for Cyber Security's Baseline cyber security controls for small and medium organizations. Adapt them to your context.
Access, two-factor authentication and administrator accounts
The CAI suggests granting access to personal information only to employees whose duties require it, and logging that access. The Cyber Centre recommends two-factor authentication wherever possible, and in particular for financial accounts, system and cloud administrators, privileged users and senior executives. It also recommends using administrator accounts only for administrative tasks.
Encrypted backups and tested restores
The Cyber Centre recommends backing up essential systems, making sure they can be restored, and storing encrypted backups securely with restricted access, ideally offline and offsite. Run regular test restores and keep a record of them.
Updates, firewalls and email (DMARC)
The Cyber Centre recommends enabling automatic patching, turning on device firewalls and placing a firewall at the boundary between your corporate network and the Internet. For email, it recommends filtering malicious messages and implementing DMARC to reduce fraudulent email. Train your staff as well.
For these measures, ask for a cybersecurity quote for your SMB or hand their upkeep to managed IT support.
Confidentiality incidents: define, record, report (ss. 3.5 to 3.8)
What is an incident? (the 4 cases in s. 3.6)
A confidentiality incident is access, use or communication of personal information not authorized by law, or the loss of personal information or any other breach of its protection (s. 3.6). The CAI's examples include an email sent to the wrong recipient, phishing and ransomware. The business must then take reasonable measures to reduce the risk of injury and prevent new incidents of the same nature (s. 3.5).
Assessing the risk of serious injury (s. 3.7)
The business must consider, in particular, the sensitivity of the information, the anticipated consequences of its use and the likelihood that it will be used for injurious purposes, and it must consult its person in charge (s. 3.7). Your access logs help establish what was viewed.
The register: content and retention (Regulation, ss. 7 and 8)
The business must keep a register of confidentiality incidents and send a copy to the CAI on request (s. 3.8). According to the CAI, incidents without a risk of serious injury are recorded too. Section 7 of the Regulation respecting confidentiality incidents sets out the content: the information involved, the circumstances, the date or period of the incident and when the business became aware of it, the number of people concerned, whether there is a risk of serious injury and why, the dates of any notices, and the measures taken.
On retention, section 8 of the Regulation states: "The information in the registers must be kept up to date and kept for at least 5 years after the date or time period when the body became aware of the incident."
Notifying the CAI and the people concerned
If the incident presents a risk of serious injury, the business must promptly notify the CAI and the people whose information is concerned, failing which the CAI may order it to do so (s. 3.5). The Act sets no fixed number of days. The notice to the CAI must be in writing (Regulation, s. 3), and the CAI provides an incident notice form. The Cyber Centre also recommends having an incident response plan.
Acquiring, developing or overhauling a system: the PIA (s. 3.3)
Section 3.3 requires a privacy impact assessment for "any project to acquire, develop or overhaul an information system or electronic service delivery system involving the collection, use, communication, keeping or destruction of personal information".
The Act adds three points:
- The person in charge is consulted from the outset of the project, for example before you select software.
- The assessment is proportionate to the sensitivity of the information, the purposes for which it is used, its quantity, its distribution and its medium.
- The project must support portability: computerized personal information collected from a person must be able to be communicated to them in a structured, commonly used technological format.
Not every IT change requires a PIA: it takes a project of this kind that involves personal information. The CAI's PIA guide (in French) helps you assess whether one is needed.
IT providers and data outside Québec (ss. 17 and 18.3)
What the written contract must cover (s. 18.3)
When you communicate personal information to a provider to perform a service contract, the contract must be in writing and specify the measures the provider must take to protect the confidentiality of the information, to ensure it is used only to perform the contract and to ensure the provider does not keep it after the contract expires. The provider must notify your person in charge without delay of any violation or attempted violation, and allow that person to conduct any verification relating to confidentiality (s. 18.3). The CAI points out that a business that entrusts personal information to a third party for safekeeping remains responsible for its incident obligations. To assess a provider before you sign, see our guide How to choose an IT service provider in Quebec.
Cloud hosting outside Québec: assessment and written agreement (s. 17)
Before communicating personal information outside Québec, the business must conduct a PIA that takes into account, in particular, the sensitivity of the information, the purposes for which it is used, the protection measures, including contractual ones, and the legal framework of the State concerned. The information may be communicated if the assessment establishes that it would receive adequate protection, and the communication must be the subject of a written agreement. The same applies when you entrust a person or body outside Québec with keeping the information on your behalf, such as a cloud service. The Act refers to outside Québec, not only outside Canada: ask where your data will be hosted at the start of any cloud project.
An 8-step IT action plan for SMBs (checklist)
- 1. Designate the person in charge or delegate the function in writing, and publish their title and contact information (s. 3.1).
- 2. Take an inventory of personal information, the systems that hold it and the providers that can access it.
- 3. Adopt your governance policies and publish your privacy policy (ss. 3.2 and 8.2).
- 4. Restrict access, turn on two-factor authentication and keep administrator accounts separate.
- 5. Encrypt backups, test restores, automate patching and set up DMARC.
- 6. Prepare an incident response plan and open your incident register (ss. 3.5 to 3.8; Regulation, ss. 7 and 8).
- 7. Review your IT provider contracts (s. 18.3) and confirm where your data is hosted (s. 17).
- 8. Build a PIA into projects covered by section 3.3 and consult the person in charge from the outset.
Frequently asked questions
Does Law 25 apply to a small business?
Yes. The private sector act covers personal information collected, held, used or communicated in the course of carrying on an enterprise (s. 1), and its text sets no exemption based on size. Governance policies must, however, be proportionate to the nature and scope of the business's activities (s. 3.2).
Who should be the person in charge of the protection of personal information?
By default, the person exercising the highest authority within the business. That person may delegate all or part of the function in writing to any person, and the title and contact information of the person in charge must be published on the business's website (s. 3.1).
What goes in the confidentiality incident register, and how long must it be kept?
Section 7 of the Regulation respecting confidentiality incidents sets out the content: the information involved, the circumstances, the dates, the number of people concerned, the risk assessment, the notices sent and the measures taken. Under section 8, this information must be kept up to date and kept for at least 5 years after the date or period when the business became aware of the incident.
When must the Commission d'accès à l'information be notified?
When an incident presents a risk of serious injury, the business must promptly notify the CAI and the people concerned (s. 3.5). Incidents without a serious risk must still be recorded in the register.
Is my IT provider responsible for an incident on its side?
According to the CAI, a business that entrusts personal information to a third party remains responsible for its obligations in the event of an incident. The written contract must include the protection measures required by section 18.3, and the provider must notify your person in charge without delay of any violation or attempted violation.
Does a move to the cloud require a PIA?
Yes, if it is a project to acquire, develop or overhaul an information system or electronic service delivery system involving personal information (s. 3.3). If personal information is communicated outside Québec or entrusted to a third party outside Québec, section 17 also requires an assessment and a written agreement.
Sources
- LégisQuébec, Act respecting the protection of personal information in the private sector (CQLR, c. P-39.1), sections 1, 3.1 to 3.8, 8.2, 10, 17 and 18.3
- LégisQuébec, Regulation respecting confidentiality incidents (CQLR, c. A-2.1, r. 3.1), sections 3, 7 and 8
- Commission d'accès à l'information du Québec, Incidents de confidentialité et mesures de sécurité (businesses, in French)
- Commission d'accès à l'information du Québec, Vers la conformité à la Loi sur le privé (PDF, in French)
- Commission d'accès à l'information du Québec, privacy impact assessment guide (in French)
- Commission d'accès à l'information du Québec, confidentiality incident notice form (PDF, in French)
- Canadian Centre for Cyber Security, Baseline cyber security controls for small and medium organizations, sections 3.1, 3.2, 3.3, 3.5, 3.6, 3.7, 3.9 and 3.12