Clym Logo

Quebec Law 25 Checklist: Your 2026 Compliance Readiness Guide

Published
AS
AuthorAdam Safar
9 min read

Quebec Law 25 compliance checklist 2026

A 2026 checklist covering every Quebec Law 25 requirement for businesses: privacy officer, consent, PIAs, biometric data, and data portability.

Summarize full article with:

Quebec's Law 25 has been fully in force since September 2024. If it has been a while since you last reviewed where your organization stands, this is the page to work through. For the full explanation of what the law covers and why, read Clym's Quebec Law 25 guide first. This checklist assumes you already understand the basics and walks through exactly what to check, what evidence to look for, and where organizations most often still have gaps.

Key takeaways
  • Quebec Law 25 has no revenue or employee threshold. Organization size does not exempt anyone.

  • The CAI has published a specific 8-point test for valid consent (see its 2023 guidelines) that most consent banners still do not fully meet.

  • Data portability requests must be fulfilled within 30 days, in a structured, machine-readable format.

  • Biometric identification systems require advance notice to the CAI, not just user consent.

  • Non-compliance can mean administrative penalties up to $10 million CAD or 2% of worldwide turnover, or penal fines up to $25 million CAD or 4%.

  • The CAI stopped publishing its public breach-incident list in May 2025, but the reporting obligation itself has not changed.

Quick Law 25 applicability check

You almost certainly need to work through this checklist if any of the following is true, since Law 25 does not exempt organizations by size:

  • You collect, use, or store personal information about people in Quebec, whether they are customers, employees, or website visitors.

  • You operate a website, app, or service that people in Quebec can access, regardless of where your organization is headquartered.

  • You are a nonprofit, association, or professional order that carries on an enterprise, not only a for-profit company.

You are likely exempt only if:

  • You are a public body, which falls under a separate access-to-information law.

  • You process personal information solely for personal or domestic purposes.

The Quebec Law 25 compliance checklist

1. Confirm Law 25 applies to your organization

Quebec Law 25 applies to any organization carrying on an enterprise that collects personal information about people in Quebec, with no revenue or headcount threshold.

  • What to check: Whether your organization collects personal information from Quebec customers, employees, or website visitors. Even a single mailing address or IP address counts.

  • Evidence to look for: A data inventory or website analytics showing Quebec-based users, customers, or staff.

  • Potential gap: Assuming a "small business exemption" exists. It does not.

2. Appoint and publish a privacy officer

Every organization must designate a person responsible for protecting personal information, and publish that person's title and contact information.

  • What to check: Whether a specific person, not just "the company," has been formally assigned this role, and whether their contact details are actually live on your website.

  • Evidence to look for: A privacy policy or contact page listing a named privacy officer or role, plus an internal delegation record if the role has been assigned to someone other than the CEO.

  • Potential gap: A privacy officer is assigned internally but never published anywhere the public can find it.

3. Build a personal information inventory

Law 25 does not name a single required inventory document, but you cannot meet its incident, retention, or rights obligations without knowing what personal information you hold and where.

  • What to check: Whether you have a current list of the personal information categories you collect, where each is stored, and who inside or outside your organization can access it.

  • Evidence to look for: A data map, inventory spreadsheet, or discovery tool output that is less than 12 months old.

  • Potential gap: An inventory was built once during initial compliance work and has not been updated since.

4. Publish a plain-language privacy policy

Organizations that collect personal information through technological means, including a website, must maintain a clear, understandable privacy policy and update it whenever practices change.

  • What to check: Whether your policy is written in plain language rather than dense legal text, and whether it reflects what you are actually doing with data today.

  • Evidence to look for: A published privacy policy with a visible "last updated" date, reviewed within the past 12 months. Tools like Clym's policy management solution can help keep it current as regulations and practices change.

  • Potential gap: A privacy policy was written once for launch and has not been reviewed since your data practices changed.

5. Set privacy-protective default settings

Technologies that allow identification, location tracking, or profiling must not be turned on by default, and default settings must provide the highest level of confidentiality without the user having to do anything.

  • What to check: Your website's default cookie and tracking behavior before a visitor makes any choice.

  • Evidence to look for: A cookie or consent banner that blocks non-essential tracking until the visitor actively opts in.

  • Potential gap: A cookie banner exists, but tracking scripts fire before the visitor makes a choice. That is one of the most common Law 25 gaps, not a minor detail.

6. Meet the CAI's 8-point standard for valid consent

The Commission d'accès à l'information (CAI) has published specific criteria consent must meet to be valid: evident, free, informed, for specific purposes, granular, in understandable language, temporary, and distinguishable from your terms of use. See Clym's breakdown of the CAI's consent criteria for the full explanation of each one.

  • What to check: Each consent request against all 8 criteria individually, not just whether a checkbox exists.

  • Evidence to look for: Consent language that is separated from your terms of use, uses plain language, and lets someone say no as easily as yes.

  • Potential gap: A single, bundled consent checkbox covers multiple unrelated purposes. Under the CAI's granularity requirement, that is not valid consent.

7. Handle children's personal information correctly

Collecting personal information from a minor under 14 requires consent from a parent or legal guardian, not the child.

  • What to check: Whether any of your forms, apps, or services could realistically be used by someone under 14, even if that is not your target audience.

  • Evidence to look for: An age-verification or parental consent step on any form collecting personal information where under-14 users are plausible.

  • Potential gap: No age gate exists because "we don't market to kids," even though nothing stops a younger visitor from submitting the form.

8. Conduct privacy impact assessments (PIAs)

A PIA is required before certain projects, including new information systems that handle personal data, and before communicating personal information outside Quebec. The requirement is set out directly in the Act itself.

  • What to check: Whether your organization has a PIA process at all, and whether it gets triggered automatically by qualifying projects rather than left to individual judgment.

  • Evidence to look for: Documented PIAs, or a checklist that flags when new vendors, systems, or projects require one, covering purpose, risk, and mitigation.

  • Potential gap: PIAs are only done for "major" projects, while smaller changes, like a new marketing tool or plug-in that touches personal data, get skipped even though they may still trigger the requirement.

9. Handle biometric data with extra caution

Biometric information, including fingerprints, facial recognition, and voiceprints, is treated as sensitive personal information. Using biometric identification technology requires express consent, and organizations must notify the CAI at least 60 days before putting a biometric system into service.

  • What to check: Any building access, timekeeping, or device login system that uses fingerprint or facial recognition.

  • Evidence to look for: A CAI notification filed at least 60 days before go-live, and a separate express consent record for each person enrolled.

  • Potential gap: Facial recognition or fingerprint access control was deployed for convenience, such as office entry, without CAI notification. The CAI has actively enforced this exact scenario.

10. Assess cross-border data transfers

Before sending personal information outside Quebec, whether to a cloud provider, a US-based vendor, or a foreign parent company, you must complete a PIA confirming the destination offers adequate protection, and put a compliant written agreement in place.

  • What to check: Every vendor and subprocessor that stores or processes Quebec residents' data outside the province, including cloud infrastructure.

  • Evidence to look for: A vendor list with data-location details, a transfer-specific PIA, and data processing agreements that include Law 25's required protections.

  • Potential gap: Assuming a GDPR-compliant data processing agreement automatically satisfies Law 25's transfer requirements. It does not cover the same criteria.

11. Build a confidentiality incident response process

You must be able to detect, contain, and assess any confidentiality incident, notifying the CAI and affected individuals when it creates a risk of serious injury, and logging every incident internally even when that threshold isn't met.

  • What to check: Whether a documented incident response process exists, and whether your team actually knows how to trigger it.

  • Evidence to look for: A written incident response plan, a confidentiality incident registry that covers every incident regardless of severity, and a record of at least one internal test or tabletop run-through.

  • Potential gap: An incident response plan exists on paper but has never been tested, or only "serious" incidents get logged, while smaller ones go unrecorded.

12. Enable full data subject rights, including portability

People must be able to access, correct, or request the deletion of their personal information, request de-indexation, and, since September 2024, receive their data in a structured, commonly used, machine-readable format such as CSV, JSON, or XML within 30 days.

  • What to check: Whether your process can actually produce a portable export, not just a PDF summary, and whether you can meet the 30-day clock consistently.

  • Evidence to look for: A documented request-handling workflow with defined response times, and at least one completed portability request showing the machine-readable output. Tools like Clym's data subject request solution can help route, verify, and track these requests against their deadlines.

  • Potential gap: Your team can manually export data on request, but has no process for verifying the requester’s identity or providing the data in a suitable machine-readable format before sending it to a third party.

13. Put internal governance and training in place

Organizations must have internal policies and procedures for protecting personal information, including staff training.

  • What to check: Whether employees who handle personal information, such as support, sales, marketing, and IT, have actually been trained on your Law 25 obligations, not just your privacy officer.

  • Evidence to look for: Documented internal privacy policies, a training record or completion log, and a governance structure showing who owns which part of compliance. A governance portal can help centralize this instead of tracking it across spreadsheets and email threads.

  • Potential gap: Compliance knowledge lives entirely with one person, often the privacy officer, with no documentation or training for anyone else.

Common Law 25 checklist mistakes

  • Treating the privacy officer appointment as a one-time task instead of keeping the published contact information current as staff change.

  • Running PIAs only for "big" projects and skipping smaller changes, like a new marketing plug-in or CRM field, that still touch personal information.

  • Assuming a cookie banner with a visible close button is compliant, even though tracking still fires before the visitor makes a choice.

  • Logging only the confidentiality incidents that clearly meet the "serious injury" threshold, and skipping the internal registry for everything else.

  • Notifying the CAI about a new biometric system on the day it launches instead of the required 60 days in advance.

  • Building a manual, one-off process for data portability requests instead of one that reliably produces a real machine-readable file within 30 days.

How to stay current on Law 25

Law 25 compliance is not a one-time project. The CAI continues to publish new guidance and to take enforcement action, most recently around facial recognition and workplace surveillance. Since May 2025, the CAI has stopped publishing its public list of reported breaches, though the underlying reporting obligation has not changed, so treat the shorter public list as a change in visibility, not a sign of lighter enforcement.

Build a recurring review, at least annually or after any major change to your data practices, vendors, or website, into your privacy officer's calendar, and check the CAI's news page periodically for new guidance.

How Clym can help with your Law 25 checklist

None of the items on this checklist require a specific vendor, but a platform like Clym's ReadyCompliance® can reduce the manual work behind several of them at once: preconfigured consent settings across 190+ regulations, policy management that keeps your privacy policy current, and workflows for routing and tracking data subject requests.

Treat any tool, including Clym's, as a way to operationalize the checklist above, not a substitute for actually working through it.

Conclusion

Quebec Law 25 has been fully in force since September 2024, and the CAI has shown it will act on real gaps, not just theoretical ones. Working through this checklist item by item, rather than relying on a general privacy program built for GDPR or another law, is the more reliable way to find out where your organization actually stands.

Revisit it whenever your vendors, website, or data practices change, since a checklist completed once and never touched again stops reflecting reality. If a gap turns up, prioritize consent, biometric notification, and portability first, since those are the areas the CAI and this checklist point to most often.

Frequently asked questions

It's a practical, item-by-item resource for confirming whether your organization has each Law 25 requirement actually in place, not just understood. If you need the full explanation of what the law covers and why first, Clym's Quebec Law 25 guide covers that separately.

Anyone responsible for privacy compliance at an organization that collects personal information from people in Quebec: privacy officers, legal and compliance teams, marketing and IT leads, and founders at smaller organizations without a dedicated privacy role.

Start with items 1 and 2: confirm the law applies to you, then appoint and publish a privacy officer. From there, consent and your privacy policy address what the CAI checks first.

Yes. Law 25 covers personal information generally, including information about employees and job applicants, not only customers or website visitors. There is no exemption for internal HR data.

At least once a year, and again any time you add a new vendor, launch a new website feature, or change what personal information you collect. A checklist completed once during initial compliance work does not stay accurate on its own.

Any unauthorized access, use, communication, or loss of personal information, even a single misdirected email. Log it in your internal registry regardless of severity. CAI and individual notification is only required above the "serious injury" threshold.

Yes, at least 60 days before the system goes into service, in addition to obtaining express consent from each person enrolled. This applies to identification or verification uses, including office access control and device logins, not just customer-facing products.

Adam Safar

Head of Digital Marketing

Adam is the Head of Digital Marketing at Clym, where he leverages his diverse expertise in marketing to support businesses with their compliance needs and drive awareness about data privacy and web accessibility. As one of the company’s original team members, Adam has been instrumental in shaping its journey from the very beginning. When he’s not diving into marketing strategies, Adam can be found cheering on his favorite sports teams or enjoying fishing.

Find out more about Adam