Law 25 | What Main Obligations do SMEs Have?
InsightsContrary to what many believe, Law 25 in respect of personal information also applies to SMEs. What are your obligations?
By: Guillaume Caron
28 Apr 20254 min read

It should be mentioned that Law 25 modernizes certain existing laws including the Act respecting the protection of personal information in the private sector which applies to private organizations of all sizes that operate in Québec and collect the personal information of their clients, employees and partners. For example, this applies to:
Summary of a business's obligations
Since the introduction of Law 25, Québec companies must ensure that visitors to their website can, among other things:
All organizations that use identifying, locating and profiling tools on their website or application must inform users before collecting any information.
The company must:
For example, if your website uses Google Analytics to track visitor behaviour, a consent banner must clearly specify that this technology facilitates the analysis of browsing behaviour and users can activate this function.
Your website and application users must accept a certain number of cookies related to their personal information. A cookie management solution allows users to make informed decisions. This tool must offer the following six elements.
Users may request:
If the data is inaccurate, they may request its correction.
Yes, but only where users have given explicit consent.
Yes, and it must be as visible as the "Accept all" button.
You can use a cookie consent management tool that logs visitor preferences.
Failure to comply with this law may result in sizeable financial sanctions. Organizations could face fines ranging from $15,000 to $25,000,000 or an amount corresponding to up to 4% of worldwide turnover for the preceding fiscal year (whichever is greater).
The following recommendations will help you to avoid sanctions:
By using a compliant cookie management solution and drafting a clear privacy policy, you can reduce your legal risk while respecting the privacy of your website users.
Do you need help? Contact us and one of our protection of personal information experts will assess whether your website is compliant.
Contrary to what many believe, Law 25 in respect of personal information also applies to SMEs. What are your obligations?
Does your organization make decisions based exclusively on automated information processing? Law 25 provides guidelines regarding these practices.
Your organization is required to comply with Law 25 and implement an information governance program. What exactly are your obligations?