Bill 25 in 2026: what every Quebec SMB needs to have in place
Two years after full enforcement, Bill 25 continues to catch businesses off guard — and issue penalties. Here is a precise overview of the obligations that apply to Quebec SMBs in 2026, with the concrete actions required.
10 min read
Comulead Team
March 2026
Published · March 2026
Bill 25: background and enforcement timeline
Bill 25 — officially the Act to modernize legislative provisions as regards the protection of personal information (formerly Bill 64) — was adopted in 2021 and rolled out in three phases from 2022 to 2023. By 2026, all obligations are fully in force and the Commission d'accès à l'information (CAI) of Quebec has significantly stepped up its inspection and enforcement activities.
The law applies to any business that collects, uses, communicates or retains personal information about Quebec residents — regardless of the size of the organization. There is no SMB exemption. Ignorance of the law is also not an acceptable defence before the CAI.
Fines under Bill 25 can reach $25 million or 4% of worldwide turnover — whichever is higher. For an SMB, even a minor administrative penalty can represent a significant reputational risk with B2B clients.
1. Governance: Privacy Protection Officer
This is the obligation most often overlooked by SMBs — and one of the first things the CAI checks during an inspection. Every organization must formally designate a Privacy Protection Officer (PPO).
What the law specifically requires
Official designation of a PPO — by default, the person holding the highest authority in the organization (CEO, Executive Director). The role can be delegated to another team member or an external service provider.
Publication of the PPO's title and contact information on the company website — accessible without registration or login.
A documented process for handling access and correction requests for personal information.
Maintenance of a confidentiality incident register (breaches) — even incidents not reported to the CAI must be recorded.
What is frequently missing in SMBs
Audits of Quebec SMBs regularly reveal three gaps: an outdated privacy policy (or a policy copied from a generic template that does not reflect actual practices), PPO contact details that are missing or impossible to find on the website, and a complete absence of an incident register.
2. Consent: collecting and managing it properly
Bill 25 has fundamentally redefined the conditions for valid consent. Implied consent — browsing a website, ticking a pre-checked box, or simply not objecting — is no longer sufficient for most purposes.
Manifest, free and informed consent
To be valid, consent must be:
Manifest: a deliberate, positive action by the individual (checking an unchecked box, clicking an explicit button).
Free: the service cannot be conditioned on consent, unless the information is strictly necessary to deliver that service.
Informed: the individual must clearly understand what they are consenting to, who is collecting the data, for what purpose, and how to exercise their rights.
Granular: a single blanket consent covering all purposes is no longer acceptable. Each distinct use requires separate consent.
Forms and cookies: key watchpoints in 2026
Cookie banners remain one of the most frequently audited elements. In 2026, a compliant banner must make it just as easy to refuse non-essential cookies as to accept them — an "Accept all" button with no equivalent "Reject all" option violates Bill 25. Collection forms must also indicate the purpose of each field being collected.
3. Transparency: privacy policy and notices
The privacy policy is no longer a peripheral legal document — it is an operational document that must accurately reflect the reality of your data collection and processing practices.
Required element
Detail required
Typical SMB status
Collection purposes
Exhaustive list of reasons why data is collected
Often incomplete
Categories of information
Precise types of data collected (name, email, behaviour, IP…)
Often generic
Third-party recipients
Name or category of each third party receiving data (SaaS vendors, partners)
Often absent
Hosting and country
Country where data is stored and processed
Often absent
Retention period
Retention period by data category
Often vague
Individual rights
Concrete procedure for access, correction, deletion, portability
Generally present
PPO contact details
Name, title and email of the designated officer
Often absent
4. Security: Privacy Impact Assessment (PIA)
Bill 25 introduces a new and often overlooked obligation: conducting a Privacy Impact Assessment (PIA) before any project that involves collecting or using personal information at scale, or that uses surveillance or profiling technologies.
When is a PIA mandatory for an SMB?
Launching a new product or service that collects personal data
Implementing a behavioural analytics or customer profiling system
Adopting a SaaS tool that processes data belonging to your customers or employees
Automation projects involving individual decisions based on personal data
Transferring data to a service provider located outside Quebec
What a PIA must contain
A PIA does not have to be a 50-page document — for an SMB, a structured 3-to-5-page document is sufficient in most cases, covering: a description of the project, the data involved, identified risks, planned mitigation measures, and formal approval from the PPO.
5. Confidentiality incidents: detection and notification
The obligation to report incidents is one of the most operationally demanding. Bill 25 distinguishes two levels of response depending on the severity of the incident.
Type of incident
Obligation to the CAI
Obligation to affected individuals
Timeline
Incident posing serious risk
Mandatory notification
Mandatory notification
As soon as possible — without undue delay
Incident without serious risk
Register entry only
Not required
No set deadline, but without unnecessary delay
A "serious risk" is defined as a potentially significant harm to the affected individual: identity theft, discrimination, financial harm, or reputational damage. When in doubt about classification, the CAI recommends notifying — failure to notify is consistently penalized more heavily than precautionary notification.
Bill 25 compliance checklist for SMBs — 2026 status
Here is a practical checklist to quickly assess your level of compliance:
PPO formally designated, with title and contact details published on the company website
Privacy policy up to date, reflecting actual practices, accessible from every page
Compliant cookie banner: rejection as accessible as acceptance, no pre-checked boxes
Collection forms documented with explicit purposes for each field
Confidentiality incident register maintained and accessible to the PPO
Documented process to handle access, correction and deletion requests within 30 days
Inventory of SaaS vendors processing personal data, with up-to-date confidentiality agreements
PIA completed for each new project or tool involving personal data
Retention periods defined and enforced for each data category
Minimum training provided to team members with access to personal data
Bill 25 compliance is not a one-time project — it is an ongoing process. Collection practices evolve, SaaS tools change, teams grow. An annual compliance audit is the standard recommended by the CAI for SMBs with 10 to 200 employees.