ISO 27001 · ISO 42001 · GDPR · PCI DSS · Loi 25

Quebec Law 25: Appointing the Personal-Information Officer

Quebec Law 25: Appointing the Personal-Information Officer

The first obligation under Law 25 is not technical. It is to appoint a person. Article 3.1 requires the person with the highest authority in the organisation to ensure compliance with and implementation of the Law, and to exercise — or delegate in writing — the function of personal-information officer. Their contact details must be published. Without this appointment, none of the other obligations hold.

The Act modernizing legislative provisions on the protection of personal information (Law 25), assented to in September 2021 and phased into force, transposes into Quebec’s private sector elements already present in the European regime. The first phase (22 September 2022) imposes three governance obligations, of which appointing the officer is the cornerstone. The content below is grounded in the Cybereco primary guide on Law 25; confirm the exact wording against the official text on the CAI website and LégisQuébec before relying on it legally.

What Article 3.1 says

Article 3.1 of the Act respecting the protection of personal information in the private sector establishes that the person with the highest authority in the organisation must ensure compliance with and implementation of the Law. That person exercises the function of “personal-information officer” (responsable de la protection des renseignements personnels). The function may be delegated in writing, in whole or in part, to any person. The title and contact details of the officer must be published on the organisation’s website or, absent a website, made accessible by any other appropriate means.

Three points stand out:

1. Accountability sits with the highest authority. By default, the executive (CEO, president, or equivalent) is the officer. It is not a function that can be left vacant. 2. Delegation is permitted, in writing. The executive may delegate the function, in whole or in part, to another person — but the delegation must be written, and ultimate accountability remains with the executive. 3. Transparency is mandatory. The officer’s title and contact details are public. An organisation that does not publish how to reach it on personal-information matters is non-compliant, even if it has appointed someone.

The officer’s role

The officer is the person who sees to compliance with and implementation of the Law inside the organisation. Concretely, that covers the twelve obligations spread across the Law’s three phases:

  • **Governance** — adopt and maintain the policies and practices framing personal-information governance (Article 3.2, phase 2).
  • **Incident register** — stand up the confidentiality-incident register and the notification process (Articles 3.5–3.8, phase 1) — see confidentiality incidents.
  • **Inventory** — maintain the inventory of the organisation’s personal information (phase 1).
  • **Training** — stand up the personal-information-protection training programme (phase 1).
  • **Retention, destruction, anonymisation** — frame retention and destruction, and irreversible anonymisation (Article 3.2, phase 2).
  • **Complaint handling** — the personal-information complaint process (Article 3.2, phase 2).
  • **Publishing governance rules** — publish the key elements on the website (phase 2).
  • **PIA (EFVP)** — the privacy-impact-assessment process (évaluation des facteurs relatifs à la vie privée) before high-risk processing, including out-of-Quebec transfers (phase 2).
  • **Consent** — the consent-collection process (phase 2).
  • **De-indexation** — the de-indexation process (phase 2).
  • **Portability** — the measures facilitating the data-portability right (phase 3, 22 September 2024).

The officer is the point of contact for the Commission d’accès à l’information (CAI) and the person the public reaches to exercise its rights. It is also the person who, with legal counsel, assesses whether a serious-prejudice risk exists in an incident to determine the notification obligation.

Appoint vs delegate: an SMB’s decision

For an SMB, the practical question is who exercises the function. Three profiles:

  • **The executive holds the function.** Compliant by default, no delegation. Realistic for a very small SMB where the executive is already involved in everything. The risk: the function is not exercised in practice because the executive has no time, and the accountability sits on them.
  • **The executive delegates in writing to an employee.** An internal person — often the IT lead, legal counsel, or an operations director — receives the written delegation. The delegation defines the scope (in whole or in part). The executive remains ultimately accountable. The most common SMB scenario.
  • **The executive delegates externally.** The Law permits delegation to "any person," which opens delegation to an external consultant or external officer. Useful when the SMB lacks internal expertise. The written delegation and published contact details apply the same.

Delegation is not a transfer of accountability — it is a transfer of execution. The executive remains the person the Law designates; the delegate executes the function. Document the delegation in writing and date it.

What to publish

Article 3.1 requires publishing the officer’s title and contact details on the organisation’s website. Concretely:

  • **A "Personal information protection" page or section** on the site, reachable from the footer or main menu.
  • **The officer’s title** (for example, "Personal Information Officer" / "Responsable de la protection des renseignements personnels").
  • **A contact means** — a dedicated email address (for example, privacy@company.ca) or a contact form. A phone number is useful but not essential; a written means is preferable for traceable requests.
  • **If delegated, the delegate’s title** may be published alongside the executive, depending on how the organisation chooses to present itself.

An organisation without a website must make the contact details accessible “by any other appropriate means” — for example, on written request, posted in-store, or in the terms of service.

Three common mistakes

  • **Vacant function.** No formal appointment, no one holds the title, contact details not published. Immediate non-compliance, independent of the other obligations.
  • **Unwritten delegation.** A verbal agreement between the executive and an employee is not a delegation under Article 3.1. The delegation must be written.
  • **Unreachable contact details.** The officer is appointed but the public cannot reach them. Publication is an obligation distinct from appointment — both must hold.

The link to the rest of the Law 25 programme

The officer is the operational owner of the other obligations. The incident register and notification process are maintained under their responsibility; the EFVP (Law 25’s PIA equivalent) is conducted under their supervision; the parallelism with GDPR is coordinated by them to avoid duplication. The SMB getting-started checklist starts with this appointment. If the organisation also runs ISO 27001, the Law 25 officer is the natural counterpart to the GDPR DPO and the ISMS contact — often the same person in an SMB.

How this fits the series

This is the use-case companion to the Law 25 pillar. It is the first phase-1 obligation (22 September 2022) and the prerequisite for all the others — the incident register, the EFVP, and the getting-started checklist attach to it. The parallelism with GDPR compares the role to the DPO.

What to do next

Appoint the officer — the highest-authority person, by default. If you delegate, write the delegation, date it, define the scope. Create the dedicated email address and publish the title and contact details on a “Personal information protection” page of your site. It is an afternoon, it has been mandatory since September 2022, and it is the prerequisite to everything else in the programme.

Unsure of the role’s scope or the delegation? Book a **45-minute Law 25 programme start** — we draft the written delegation, define the role’s scope, and build the contact-details publication page. Bilingual FR/EN, no obligation.

/loi-25-starter/ · download the Law 25 SMB getting-started checklist

Get Your Free Security Readiness Assessment

Map your controls, identify compliance gaps, and secure your systems before the audit.

About the author

adsystemsentry

Governance, Risk, and Cybersecurity leader enabling enterprise resilience and SaaS scale through strategic security architecture. I design and lead integrated governance frameworks that align regulatory compliance, risk oversight, and business growth objectives. Certified ISO 27001 Lead Implementer with direct exposure to senior leadership and governance bodies across SaaS, cloud, and regulated environments.

View LinkedIn profile →

Related articles

Search

Stay Secure

Get weekly security insights and actionable guidance straight to your inbox.