Law 25 and GDPR: Parallelism and a Joint Programme for an SMB
Law 25 and GDPR: Parallelism and a Joint Programme for an SMB
Law 25 drew on GDPR. The two regimes share a privacy officer, an impact assessment, an incident register, and a portability right. A Quebec SMB that processes EU individuals’ data — EU customers, EU employees — is subject to both, and risks running two parallel programmes. The artifacts fuse; the divergences isolate.
The Act modernizing legislative provisions on the protection of personal information (Law 25) modernizes Quebec’s framework by transposing several elements already present in the European regime (GDPR). For an SMB subject to both — any Quebec organisation that processes GDPR-data subjects’ personal data — duplication is avoidable. The content below is grounded in the Cybereco primary guide on Law 25 and the canonical GDPR summary; confirm exact wording against the official texts (CAI / LégisQuébec for Law 25; EUR-Lex for GDPR).
Why an SMB ends up with both
Law 25 applies to any private-sector organisation holding personal information in Quebec — Quebec customers and employees. GDPR applies the moment an organisation processes GDPR-data subjects’ personal data — which includes, for a Quebec SMB, any customer or employee located in the EU, or any processing offered to people in the EU (GDPR Article 3). An SMB selling to Europe, employing European staff, or operating a site accessible and marketed to the EU is subject to both. The fix is a joint programme, not two separate tracks.
The correspondence, concept by concept
| Concept | Law 25 | GDPR | Merge |
|---|---|---|---|
| Privacy officer | Art 3.1, personal-information officer, written delegation, published contact | Art 37–39, DPO, mandatory under threshold conditions | One function-holder in an SMB — the Law 25 officer is also the GDPR DPO |
| Processing register | Personal-information inventory (phase 1) | Art 30, record of processing activities (RoPA) | One register, with both regimes’ columns |
| Impact assessment | EFVP — privacy impact assessment (phase 2), before high-risk processing including out-of-Quebec transfer | Art 35, DPIA, triggers profiling/special-category/surveillance | One assessment, two report cuts |
| Confidentiality incidents / breaches | Art 3.5–3.8, register for every incident, notice CAI + individuals if serious-prejudice risk, "as soon as possible" | Art 33–34, breach register, notice authority within 72 h, communicate to individuals if high risk | One incident register, one response procedure, two notice paths |
| Consent | Manifest, free, informed consent; opt-in for sensitive data | Art 6 + 7, free, specific, informed, withdrawable consent; explicit for special categories | One consent policy aligned to the stricter standard (explicit/opt-in) |
| Data subject rights | Access, rectification, objection, portability (phase 3), de-indexation rights | Arts 15–22, access, rectification, erasure, restriction, portability, objection, automated decisions | One request-handling process covering both regimes |
| Out-of-jurisdiction transfers | EFVP before out-of-Quebec transfer | Art 44–49, appropriate safeguards (SCCs, adequacy) for out-of-EU transfer | A transfer matrix by jurisdiction, one assessment per destination |
| Anonymisation | Irreversible anonymisation (Art 3.2, phase 2) | Anonymisation takes data out of GDPR scope | One anonymisation policy |
The divergences that do not fuse
- **The notice clock.** GDPR sets 72 hours to the authority; Law 25 sets "as soon as possible" with no numbered deadline. The 72-hour internal target satisfies both — see confidentiality incidents — but the GDPR rule is the floor, not Law 25’s.
- **The notice threshold.** GDPR: risk to rights and freedoms (Art 33), then high risk for communication to individuals (Art 34). Law 25: risk of serious prejudice, which triggers both CAI and individual notice. An incident may trigger Law 25 notice but not GDPR notice, or vice versa; the assessment is run for each regime.
- **The supervisory authority.** GDPR: the member-state supervisory authority (or the EDPB at EU level). Law 25: the Commission d’accès à l’information du Québec (CAI). Two distinct notice recipients.
- **Scope.** Law 25 follows personal information held in Quebec; GDPR follows data subjects in the EU. The same processing may fall under one regime and not the other.
- **Threshold-mandated DPO (GDPR).** GDPR makes the DPO mandatory for certain organisations (over 250 employees by default, or risk processing). Law 25 makes the officer mandatory for *every* organisation, no threshold. Law 25 is therefore the floor — if you must appoint someone under Law 25 and GDPR does not require it, the appointment holds for both.
The joint programme: one shared artifact set
1. One function-holder. The personal-information officer (Art 3.1) also holds the GDPR DPO role. One appointment, one published-contact page, one point of contact. See personal-information officer. 2. One unified register. The GDPR RoPA (Art 30) and the Law 25 inventory fuse into one register — one row per processing activity, with both regimes’ columns (purpose, GDPR lawful basis, security measures, recipients, transfers, retention). See GDPR Article 30 RoPA. 3. One impact assessment. The Law 25 EFVP and the GDPR DPIA (Art 35) are run as one assessment, with two report cuts. See DPIA template. 4. One incident register and response procedure. A confidentiality-incident register (Law 25) that is also the GDPR breach register. One incident-response procedure that runs both notice paths (CAI + individuals if serious prejudice; GDPR authority within 72 h + individuals if high risk). See Law 25 incidents and GDPR data subject rights and 72-hour clock. 5. One request-handling process. The access, rectification, objection, and portability rights — present in both regimes — are handled by one process covering the full rights set, regardless of the individual’s jurisdiction. 6. A transfer matrix. Each out-of-Quebec transfer (EFVP) and out-of-EU transfer (GDPR appropriate safeguards) is assessed per destination. One destination (for example, a US host) triggers the Law 25 EFVP and the GDPR Standard Contractual Clauses — one assessment, two safeguards documented.
The cadence: align the years
Both regimes lend themselves to an annual heartbeat: refresh the unified register, re-review impact assessments for high-risk processing, test the incident-response procedure once a year (a tabletop exercising both notice paths), and re-review the transfer matrix. If the organisation also runs ISO 27001, this heartbeat aligns with the ISMS internal audit (clause 9.2) — one audit that feeds Law 25, GDPR, and ISO 27001 compliance. See the GDPR / ISO 27001 joint implementation.
How this fits the series
This is the cross-pillar bridge between the Law 25 pillar and the GDPR pillar. It assumes you have read the officer and confidentiality incidents on the Law 25 side, and the Article 30 RoPA, the data subject rights and 72-hour clock, and the DPIA on the GDPR side. The Law 25 SMB getting-started checklist can be built as a subset of the joint programme.
What to do next
If you are subject to both regimes, the first move is the correspondence table above, filled with your real processing — one row per activity, with the Law 25 and GDPR requirements side by side. Appoint one function-holder. Fuse the Law 25 register and the GDPR RoPA into one unified register. Align the incident-response procedure to both notice paths, with the 72-hour internal target. The joint programme collapses two tracks to one; the divergences (notice recipient, threshold, clock) isolate as branches of a common procedure.
Subject to Law 25 and GDPR and unsure where they overlap? Book a **45-minute Law 25 programme start** — we build the correspondence table for your processing, fuse the register and incident procedure, and set the unified notification target. Bilingual FR/EN, no obligation.
→ /loi-25-starter/ · /contact · download the Law 25 SMB getting-started checklist
Get Your Free Security Readiness Assessment
Map your controls, identify compliance gaps, and secure your systems before the audit.