Compliance & Bill 25

Bill 25 in 2026: what every Quebec SMB needs to have in place

Two years after full enforcement, Bill 25 continues to catch businesses off guard — and issue penalties. Here is a precise overview of the obligations that apply to Quebec SMBs in 2026, with the concrete actions required.

10 min read Comulead Team March 2026
Bill 25 in 2026 — obligations for Quebec SMBs on personal data protection
Published · March 2026

Bill 25: background and enforcement timeline

Bill 25 — officially the Act to modernize legislative provisions as regards the protection of personal information (formerly Bill 64) — was adopted in 2021 and rolled out in three phases from 2022 to 2023. By 2026, all obligations are fully in force and the Commission d'accès à l'information (CAI) of Quebec has significantly stepped up its inspection and enforcement activities.

The law applies to any business that collects, uses, communicates or retains personal information about Quebec residents — regardless of the size of the organization. There is no SMB exemption. Ignorance of the law is also not an acceptable defence before the CAI.

Fines under Bill 25 can reach $25 million or 4% of worldwide turnover — whichever is higher. For an SMB, even a minor administrative penalty can represent a significant reputational risk with B2B clients.

1. Governance: Privacy Protection Officer

This is the obligation most often overlooked by SMBs — and one of the first things the CAI checks during an inspection. Every organization must formally designate a Privacy Protection Officer (PPO).

What the law specifically requires

  • Official designation of a PPO — by default, the person holding the highest authority in the organization (CEO, Executive Director). The role can be delegated to another team member or an external service provider.
  • Publication of the PPO's title and contact information on the company website — accessible without registration or login.
  • A documented process for handling access and correction requests for personal information.
  • Maintenance of a confidentiality incident register (breaches) — even incidents not reported to the CAI must be recorded.

What is frequently missing in SMBs

Audits of Quebec SMBs regularly reveal three gaps: an outdated privacy policy (or a policy copied from a generic template that does not reflect actual practices), PPO contact details that are missing or impossible to find on the website, and a complete absence of an incident register.

2. Consent: collecting and managing it properly

Bill 25 has fundamentally redefined the conditions for valid consent. Implied consent — browsing a website, ticking a pre-checked box, or simply not objecting — is no longer sufficient for most purposes.

Manifest, free and informed consent

To be valid, consent must be:

  • Manifest: a deliberate, positive action by the individual (checking an unchecked box, clicking an explicit button).
  • Free: the service cannot be conditioned on consent, unless the information is strictly necessary to deliver that service.
  • Informed: the individual must clearly understand what they are consenting to, who is collecting the data, for what purpose, and how to exercise their rights.
  • Granular: a single blanket consent covering all purposes is no longer acceptable. Each distinct use requires separate consent.

Forms and cookies: key watchpoints in 2026

Cookie banners remain one of the most frequently audited elements. In 2026, a compliant banner must make it just as easy to refuse non-essential cookies as to accept them — an "Accept all" button with no equivalent "Reject all" option violates Bill 25. Collection forms must also indicate the purpose of each field being collected.

3. Transparency: privacy policy and notices

The privacy policy is no longer a peripheral legal document — it is an operational document that must accurately reflect the reality of your data collection and processing practices.

Required elementDetail requiredTypical SMB status
Collection purposesExhaustive list of reasons why data is collectedOften incomplete
Categories of informationPrecise types of data collected (name, email, behaviour, IP…)Often generic
Third-party recipientsName or category of each third party receiving data (SaaS vendors, partners)Often absent
Hosting and countryCountry where data is stored and processedOften absent
Retention periodRetention period by data categoryOften vague
Individual rightsConcrete procedure for access, correction, deletion, portabilityGenerally present
PPO contact detailsName, title and email of the designated officerOften absent

4. Security: Privacy Impact Assessment (PIA)

Bill 25 introduces a new and often overlooked obligation: conducting a Privacy Impact Assessment (PIA) before any project that involves collecting or using personal information at scale, or that uses surveillance or profiling technologies.

When is a PIA mandatory for an SMB?

  • Launching a new product or service that collects personal data
  • Implementing a behavioural analytics or customer profiling system
  • Adopting a SaaS tool that processes data belonging to your customers or employees
  • Automation projects involving individual decisions based on personal data
  • Transferring data to a service provider located outside Quebec

What a PIA must contain

A PIA does not have to be a 50-page document — for an SMB, a structured 3-to-5-page document is sufficient in most cases, covering: a description of the project, the data involved, identified risks, planned mitigation measures, and formal approval from the PPO.

5. Confidentiality incidents: detection and notification

The obligation to report incidents is one of the most operationally demanding. Bill 25 distinguishes two levels of response depending on the severity of the incident.

Type of incidentObligation to the CAIObligation to affected individualsTimeline
Incident posing serious riskMandatory notificationMandatory notificationAs soon as possible — without undue delay
Incident without serious riskRegister entry onlyNot requiredNo set deadline, but without unnecessary delay

A "serious risk" is defined as a potentially significant harm to the affected individual: identity theft, discrimination, financial harm, or reputational damage. When in doubt about classification, the CAI recommends notifying — failure to notify is consistently penalized more heavily than precautionary notification.

Bill 25 compliance checklist for SMBs — 2026 status

Here is a practical checklist to quickly assess your level of compliance:

  1. PPO formally designated, with title and contact details published on the company website
  2. Privacy policy up to date, reflecting actual practices, accessible from every page
  3. Compliant cookie banner: rejection as accessible as acceptance, no pre-checked boxes
  4. Collection forms documented with explicit purposes for each field
  5. Confidentiality incident register maintained and accessible to the PPO
  6. Documented process to handle access, correction and deletion requests within 30 days
  7. Inventory of SaaS vendors processing personal data, with up-to-date confidentiality agreements
  8. PIA completed for each new project or tool involving personal data
  9. Retention periods defined and enforced for each data category
  10. Minimum training provided to team members with access to personal data

Bill 25 compliance is not a one-time project — it is an ongoing process. Collection practices evolve, SaaS tools change, teams grow. An annual compliance audit is the standard recommended by the CAI for SMBs with 10 to 200 employees.

For SMBs doing business internationally, see our article on the key differences between Bill 25 and GDPR — particularly if you have clients or partners in Europe.

Montreal-hosted · Bill 25 compliant

Cortex Voice is hosted in Quebec and built for Bill 25 compliance — with no additional configuration required on your end.

Book a demo