This week marks two years since the final provisions of Quebec's Law 25 came fully into force. It is the strictest private-sector privacy law in Canada, it reaches many businesses well beyond Quebec, and, two years in, it is no longer a theoretical deadline on the horizon. The province's regulator is actively enforcing it, issuing penalties and publicly naming organizations that fall short. Yet a lot of small businesses that are on the hook still have not caught up. On the anniversary, here is an honest look at the gaps that persist and how to close them.
Two years in, this is real
The grace period is over. Quebec's Commission d'acces a l'information, the regulator, has moved from guidance into genuine enforcement, with published decisions and monetary penalties, and Law 25 carries some of the highest privacy penalties in the country. The old wait-and-see posture, common when the law was new, is now a risk. And because Law 25 can apply to any business handling the personal information of people in Quebec, plenty of companies outside the province are covered without realizing it, a point worth checking against which privacy law applies to you.
The obligations small businesses still miss
Across the businesses we and others see, the same few gaps come up again and again:
- No one is formally in charge of privacy. Law 25 requires a designated person responsible for protecting personal information, and it is the single most commonly missed obligation. Naming a Privacy Officer is step one.
- No vendor due diligence. Businesses hand personal data to suppliers without checking how it is handled or where it goes, another frequent gap, and one Law 25 specifically cares about, including for data leaving Quebec.
- No privacy assessments for new systems or cross-border data transfers, which Law 25 requires in defined situations.
- No breach register or notification plan, so a business would not be ready to report a confidentiality incident on time.
How to close them without a compliance department
The reassuring news is that these gaps are not expensive to fix, they are mostly about doing a few defined things rather than buying anything. Name someone accountable for privacy. Keep a simple record of what data you hold and which vendors touch it. Do a quick privacy check before new projects and data transfers. Set up a basic way to record and report a breach. None of that requires a legal team; it requires deciding to do it. A small business can meet the spirit of Law 25 with a focused afternoon and a bit of upkeep.
The takeaway
Two years in, Law 25 is settled law with a regulator willing to use it, and "we will get to it" is no longer a safe plan for a business it covers. But catching up is far more achievable than most owners fear. The businesses that close these gaps are not the ones with the biggest budgets; they are the ones that finally assigned the responsibility and did the basics. We help Canadian small businesses figure out whether Law 25 applies to them and get compliant efficiently, without the enterprise overhead.