Understanding Law 25
Law 25 modernizes Quebec’s personal information protection rules. For businesses, it strengthens governance, transparency and the protection of information that can identify a person.
Compliance involves more than antivirus software or a cookie banner: it also concerns decisions, procedures and the people handling information. Read the main changes explained by Quebec’s Commission d’accès à l’information (CAI, in French).
Key obligations
- Accountability and transparency: designate a privacy officer, publish their title and contact details, and establish personal information governance. Business responsibilities — CAI.
- Collection and consent: determine what information is necessary, explain the purposes and obtain valid consent where required by law. Consent — CAI.
- Retention and providers: establish rules for retention and destruction. Communicating information outside Quebec requires a prior privacy impact assessment and compliance with applicable conditions. Main changes — CAI.
- Incidents: reduce risks, record confidentiality incidents and promptly notify the CAI and affected individuals when an incident presents a risk of serious injury, subject to legal exceptions. Incident management — CAI.
Our rules of conduct
The following principles guide Solutions MC’s work for clients:
- Respect the agreed scope. Define the need and obtain the necessary authorization before accessing a client’s systems or data.
- Limit access. Consult only information necessary for the work and limit permissions to the engagement’s needs.
- Maintain confidentiality. Do not use client data for personal purposes or share it with unauthorized people.
- Protect communications. Choose a method appropriate to the sensitivity of the information. Do not request passwords or sensitive documents through a public form.
- Be transparent. Explain proposed work, its limitations and identified issues so clients can make informed decisions.
- Report concerns. Promptly report suspected unauthorized access, loss or disclosure to the appropriate responsible person and assist with corrective action.
- Manage the end of an engagement. Plan access removal and the handling of working copies according to authorized instructions, the contract and applicable retention obligations.
Technical support and shared responsibilities
Solutions MC helps clients protect and organize their IT environment. Selected measures depend on the engagement and identified risks. Each organization remains responsible for its legal obligations; IT services alone do not constitute certification of compliance with Law 25.
Privacy officer
Christophe Trudel, President
Privacy Officer — Solutions MC
Email: info@solutionsmc.ca
For a question, complaint, access or correction request, or withdrawal of consent, contact the privacy officer. Rights and requests may be subject to legal conditions and exceptions. Describe your request without attaching passwords or sensitive documents; verification and secure transmission arrangements can be agreed afterwards.
To report an incident, explain the known facts and how to contact you. See also our privacy policy and the CAI’s information about your rights (in French).
Last updated: October 7, 2026.
