loi-25
-
Law 25: SMB Getting-Started Checklist (30-60-90 Days)
6 min read
Law 25 imposes twelve obligations across three phases (2022, 2023, 2024). For an SMB starting out, order matters: appoint the officer, stand up the incident register, then build governance. Here is a 30-60-90-day checklist by phase.
-
Quebec Law 25: Appointing the Personal-Information Officer
6 min read
Law 25 (Article 3.1) requires every private-sector organisation to appoint a personal-information officer and publish their contact details. It is the first obligation, in force since 22 September 2022. Here is the role, the delegation, and how an SMB stands it up.
-
Quebec Law 25: Confidentiality Incidents, Register, and Notice Deadline
6 min read
Law 25 (Articles 3.5–3.8) requires a register of every confidentiality incident and notice to the CAI and affected individuals when there is a risk of serious prejudice. Unlike GDPR, there is no 72-hour clock — notice is ‘as soon as possible.’ Here is what the Law requires.
-
PIPEDA vs Loi 25 vs GDPR: The Cross-Border SMB Compliance Map
6 min read
A Canadian SMB that also serves EU or Quebec customers can trigger all three regimes at once. Side-by-side map of PIPEDA, Loi 25, and GDPR — scope, authority, officer, breach clock, access response, impact assessment, portability, transfers, and enforcement — grounded in the statute and regulation text.
-
Law 25 and GDPR: Parallelism and a Joint Programme for an SMB
6 min read
Law 25 transposes several GDPR elements into Quebec’s private sector: an officer, a PIA, an incident register, portability. An SMB subject to both can fuse the artifacts and run one programme. Here is the correspondence and the divergences.
-
Law 25: SMB Getting-Started Checklist (30-60-90 Days)
Law 25 imposes twelve obligations across three phases (2022, 2023, 2024). For an SMB starting out, order matters: appoint the officer, stand up the incident register, then build governance. Here is a 30-60-90-day checklist by phase.
-
Quebec Law 25: Appointing the Personal-Information Officer
Law 25 (Article 3.1) requires every private-sector organisation to appoint a personal-information officer and publish their contact details. It is the first obligation, in force since 22 September 2022. Here is the role, the delegation, and how an SMB stands it up.
-
Quebec Law 25: Confidentiality Incidents, Register, and Notice Deadline
Law 25 (Articles 3.5–3.8) requires a register of every confidentiality incident and notice to the CAI and affected individuals when there is a risk of serious prejudice. Unlike GDPR, there is no 72-hour clock — notice is ‘as soon as possible.’ Here is what the Law requires.
-
PIPEDA vs Loi 25 vs GDPR: The Cross-Border SMB Compliance Map
A Canadian SMB that also serves EU or Quebec customers can trigger all three regimes at once. Side-by-side map of PIPEDA, Loi 25, and GDPR — scope, authority, officer, breach clock, access response, impact assessment, portability, transfers, and enforcement — grounded in the statute and regulation text.
-
Law 25 and GDPR: Parallelism and a Joint Programme for an SMB
Law 25 transposes several GDPR elements into Quebec’s private sector: an officer, a PIA, an incident register, portability. An SMB subject to both can fuse the artifacts and run one programme. Here is the correspondence and the divergences.