ISO 27001 · ISO 42001 · GDPR · PCI DSS · Loi 25

Law 25: SMB Getting-Started Checklist (30-60-90 Days)

Law 25: SMB Getting-Started Checklist (30-60-90 Days)

An SMB discovering Law 25 faces twelve obligations spread across three entry-into-force phases. The mistake is to attack everything in parallel. Order matters: phase 1 (22 September 2022) is in force and mandatory now; phase 2 (22 September 2023) builds on it; phase 3 (22 September 2024) adds portability. Here is a 30-60-90-day checklist that respects the dependency order.

The Act modernizing legislative provisions on the protection of personal information (Law 25) entered into force in phases: 22 September 2022, 22 September 2023, and 22 September 2024. The twelve obligations distribute across these phases, with dependencies — the officer precedes governance, which precedes the PIA. The content below is grounded in the Cybereco primary guide on Law 25; confirm the exact wording against the official text on the CAI website and LégisQuébec.

The prerequisite: appoint the officer (day 1)

Before the checklist, one action that conditions everything else. Article 3.1 requires the person with the highest authority to ensure compliance with and implementation of the Law, and to exercise — or delegate in writing — the function of personal-information officer. The officer’s title and contact details are published on the website. Without this appointment, none of the following obligations has an operational owner.

Do now: appoint the officer (the executive by default), write the delegation if delegating, create the dedicated email address, publish the title and contact details on a “Personal information protection” page of the site.

Phase 1 (22 September 2022) — days 1–30

These obligations are in force. They are the foundations.

  • [ ] **Appoint the personal-information officer** (Art 3.1) — written delegation, published contact. *(Prerequisite above.)*
  • [ ] **Stand up the confidentiality-incident register** (Art 3.5–3.8) — a simple template (spreadsheet or table) aligned with the CAI schema, with columns: nature, information concerned, individuals affected, discovery date, serious-prejudice risk assessment, measures taken, notification decision. See confidentiality incidents.
  • [ ] **Stand up the incident-notice process** — the serious-prejudice assessment grid (with legal counsel), the two notice templates (CAI and individuals), the containment runbook.
  • [ ] **Start the personal-information inventory** — map where the organisation holds personal information, by activity. The inventory feeds the GDPR RoPA if the organisation is subject to both — see Law 25 / GDPR parallelism.
  • [ ] **Launch the training programme** — a first personal-information-protection awareness module for staff, documented.

Day-30 deliverable: officer appointed and published, incident register and notice process in place, inventory started, training launched.

Phase 2 (22 September 2023) — days 31–60

These obligations build on the phase-1 foundations. They concern formalised governance.

  • [ ] **Adopt the governance policies and practices** (Art 3.2) — personal-information governance policies, proportionate to the nature and scale of activities, in simple and clear terms.
  • [ ] **Frame retention, destruction, and anonymisation** (Art 3.2) — retention and destruction rules per information category, irreversible anonymisation documented.
  • [ ] **Stand up the complaint-handling process** (Art 3.2) — a channel for personal-information complaints, a handling and response process.
  • [ ] **Publish the key governance elements on the website** — the governance rules set out in simple and clear terms, accessible to the public.
  • [ ] **Stand up the PIA (EFVP) process** — the privacy impact assessment (évaluation des facteurs relatifs à la vie privée), mandatory before high-risk processing including any out-of-Quebec transfer. This is Law 25’s equivalent of the GDPR DPIA — fuse them if subject to both.
  • [ ] **Stand up the consent-collection process** — manifest, free, informed consent; opt-in for sensitive data.
  • [ ] **Stand up the de-indexation process** — the mechanism for responding to individuals’ de-indexation requests.

Day-60 deliverable: governance policies adopted and published, retention/destruction/anonymisation framed, complaint process in place, PIA and consent and de-indexation defined.

Phase 3 (22 September 2024) — days 61–90

Phase 3 adds one new right. Prepare it on the foundation of the first two phases.

  • [ ] **Implement the data-portability measures** — the individual’s right to obtain their personal information in a structured, commonly used format, for transmission to another third party. Check your systems’ technical ability to export the data concerned.

Day-90 deliverable: portability implemented, full Law 25 programme in a working state.

The dependencies to respect

The order is not arbitrary:

  • **The officer precedes everything.** Without an owner, no obligation is exercised in practice.
  • **The incident register precedes governance.** An incident can occur while you build the policies; the register must already exist.
  • **The inventory precedes the PIA.** You cannot assess the impact of processing whose data you have not mapped.
  • **Governance precedes publication.** You publish the rules you have adopted, not the reverse.
  • **Consent and PIA precede portability.** Portability assumes you know which data you lawfully hold and at what risk.

The shortcuts for an SMB subject to multiple regimes

  • **Subject to Law 25 and GDPR** — fuse the Law 25 register and the GDPR RoPA, fuse the EFVP and the DPIA, align the incident procedure to both notice paths. See Law 25 / GDPR parallelism.
  • **Subject to Law 25 and ISO 27001** — the Law 25 officer is the counterpart to the ISMS contact; the incident register is the Law 25 view of the ISMS incident-response procedure (Annex A.5.24–A.5.27).
  • **Subject to all three** — one function-holder, one unified register, one incident procedure with three paths (CAI, GDPR authority, ISMS response), one impact assessment feeding EFVP + DPIA + ISO 27001 risk assessment.

Three pitfalls to avoid

  • **Attacking the twelve obligations in parallel.** The dependencies mean phase-2 work without phase 1 gets redone.
  • **An empty incident register because "no incident has occurred."** The register is the accountability artifact; it stands before the incident, and every incident — minor or major — is recorded.
  • **Publishing unadopted governance policies.** Publication follows adoption; publishing a draft is not compliant.

How this fits the series

This is the operational checklist for the Law 25 pillar. It assumes the officer is appointed, and points to confidentiality incidents and GDPR parallelism for the detailed obligations. It is the entry point for an SMB starting out.

What to do next

Today: appoint the officer and publish their contact details. This week: stand up the incident-register template and the serious-prejudice assessment grid. This month: start the inventory and launch training. The next 30 days: adopt and publish the governance policies. The 30 days after: implement portability. Three months to a complete Law 25 programme — if the dependency order is respected.

Want a guided start? Book a **45-minute Law 25 programme start** — we validate your officer and publication, stand up your incident register and serious-prejudice grid, and build your 30-60-90-day roadmap by phase. Bilingual FR/EN, no obligation.

/loi-25-starter/ · download the Law 25 SMB getting-started checklist

Get Your Free Security Readiness Assessment

Map your controls, identify compliance gaps, and secure your systems before the audit.

About the author

adsystemsentry

Governance, Risk, and Cybersecurity leader enabling enterprise resilience and SaaS scale through strategic security architecture. I design and lead integrated governance frameworks that align regulatory compliance, risk oversight, and business growth objectives. Certified ISO 27001 Lead Implementer with direct exposure to senior leadership and governance bodies across SaaS, cloud, and regulated environments.

View LinkedIn profile →

Related articles

Search

Stay Secure

Get weekly security insights and actionable guidance straight to your inbox.