White paper · Compliance
Law 25 Compliance with Microsoft 365
SMB guide: the 11 obligations translated into concrete Microsoft settings
The 11 obligations of Québec's Law 25, translated into concrete settings across Purview, Defender and Entra ID. Includes internal policy templates, a sample incident register, and a Privacy Impact Assessment (PIA) template.
Who it's for
SMBs, non-profits and Québec organizations · Privacy Officer (RPRP), Executive Director, leadership
White paper contents
5 chapters, 15 pages.
- 1
Law 25 in 2026 - where things really stand
3 sections
- 2
The 11 obligations to validate
11 sections
- 3
Microsoft 365 as your compliance stack
2 sections
- 4
Compliance roadmap
3 sections
- 5
Sustaining compliance over time
2 sections
What you'll learn
Concrete takeaways you can apply tomorrow.
- The 11 obligations of Québec's Law 25, explained without the legal jargon and translated into concrete Microsoft 365 settings.
- A public privacy policy template, a sample incident register, and a ready-to-adapt Privacy Impact Assessment (PIA) template.
- A realistic compliance roadmap spanning 4 to 8 weeks for an SMB, and 12 to 20 weeks for a public-sector organization.
- The real penalties at stake and how to avoid them - based on the first public cases since the law took effect.
Free excerpt
Why this white paper.
The 11 obligations of Québec's Law 25, explained without the legal jargon and translated into concrete Microsoft 365 settings.
A public privacy policy template, a sample incident register, and a ready-to-adapt Privacy Impact Assessment (PIA) template.
A realistic compliance roadmap spanning 4 to 8 weeks for an SMB, and 12 to 20 weeks for a public-sector organization.
The real penalties at stake and how to avoid them - based on the first public cases since the law took effect.
Chapter 1
Law 25 in 2026 - where things really stand
The three waves of entry into force
Law 25 (officially the "Act to modernize legislative provisions as regards the protection of personal information", formerly Bill 64) came into force in three waves: September 2022, September 2023 and September 2024.
Wave 1 (Sept. 2022): appointment of the person in charge of the protection of personal information (Privacy Officer, RPRP), an incident notification procedure, and rules governing biometrics. Wave 2 (Sept. 2023, the most demanding): public privacy policies, specific purposes, the right of access and rectification, transfers outside Québec (art. 17), automated decision-making (art. 12.1, particularly relevant with Copilot), administrative monetary penalties of up to $10M or 2% of worldwide turnover, and private civil remedies (art. 93.1). Wave 3 (Sept. 2024): the right to data portability.
In 2026, any Québec organization - private or public - that collects or handles personal information must be compliant. Yet industry estimates suggest that more than 60% of Québec SMBs still are not - more out of unawareness than bad faith.
Who is affected
Law 25 applies to: any Québec public body, any private business operating in Québec, any organization handling the personal information of Québec residents (even if its head office is outside the province), and any non-profit.
Size is irrelevant: a 5-person SMB is just as much in scope as a multinational, the moment it handles personal information (clients, employees, suppliers, prospects).
A broad definition
"Personal information" includes a name, email, address and phone number, but also an IP address, an employee ID, and notes about a client in a CRM - any data that makes it possible to identify a person, directly or indirectly.
The penalties actually being applied
Law 25 penalties fall into three tiers that can be combined, and the CAI began applying them actively in 2024-2025:
- Administrative monetary penalties of up to $10 million or 2% of worldwide turnover, imposed by the CAI without a trial.
- Penal fines of up to $25 million or 4% of worldwide turnover, imposed by the courts.
- Private civil remedies (art. 93.1) in effect since September 2023: any person who suffers harm can sue your organization directly in the civil courts, with minimum punitive damages of $1,000.
- And the indirect impact: soaring cyber-insurance premiums, the loss of client contracts that require compliance, and reputational damage.
Chapter 2
The 11 obligations to validate
1 - Appoint a Privacy Officer (RPRP)
Every organization must appoint a person in charge of the protection of personal information (Privacy Officer, RPRP). By default, this is the most senior executive (CEO, Executive Director) - who may formally delegate the role but remains accountable.
The Privacy Officer's name and contact details must be published (usually on the website, alongside the privacy policy). This is the easiest obligation to meet - and the one most often forgotten.
2 - Public privacy policy
A compliant privacy policy must be published and accessible. It must describe: the types of information collected, the specific purposes, the third parties to whom information is disclosed, transfers outside Québec, individuals' rights, and the Privacy Officer's contact details.
A common mistake: importing a translated American policy. Law 25 has specific requirements (transfers outside Québec under article 17, explicit purposes) that generic templates do not cover.
3 - Privacy Impact Assessment (PIA)
For any new project involving personal information - a new application, a new CRM, a new HR practice, a Copilot rollout - a Privacy Impact Assessment (PIA) must be carried out beforehand.
The PIA documents: the nature of the project, the types of information handled, the purposes, the retention period, the security measures, any transfers, and the residual risks. It is kept on file and produced to the CAI on request.
Template included
The PDF of this white paper includes a 4-page PIA template, tailored to an SMB, for use on your new projects. Typical cases: a Copilot rollout, a CRM migration, a new HR application.
4 - Incident register
Keep an internal register of every confidentiality incident, even if the incident does not appear to require reporting to the CAI. A significant incident (one likely to cause serious injury) must be reported to the CAI AND to the individuals concerned without delay.
Register template included: date, type of incident, data affected, individuals concerned, measures taken, and the decision on notification.
5 - Access and rectification request procedure
Everyone has the right to ask to see the information you hold about them, and to request its rectification. You have 30 days to respond. The procedure must be documented, and the individual informed that they may turn to the CAI if you refuse.
6 - The right to portability (since Sept. 2024)
Anyone can request that the information concerning them be communicated to them, or transferred to a third party, in a structured, commonly used technological format. You have 30 days.
For a Microsoft 365 organization, Microsoft Purview's Data Subject Request (DSR) Tool automates much of this extraction.
7 - Mapping transfers outside Québec (article 17)
Any transfer of personal information outside Québec must undergo a prior assessment: the adequacy of the destination jurisdiction, contractual measures with the recipient, and technical measures (encryption, access controls).
Microsoft 365 hosted in Canada Central or Canada East: not a transfer outside Québec in the strict sense (Canada). Microsoft 365 hosted in the US: a transfer that must be assessed and documented.
8 - Explicit consent and specific purposes
Consent must be free, informed, and given for specific purposes. The pre-checked box is no longer permitted. Neither is "bundled consent" covering 12 purposes at once.
For each purpose, ask for specific consent - for example, consent for marketing should be separate from consent to deliver the service.
9 - Article 12.1 - Automated decisions and AI
If you use a system (including Copilot or any AI tool) to make a decision based "exclusively on automated processing" of personal information, you must: inform the individual, allow them to learn the factors and the reasons behind it, and allow them to request a human review.
Practical cases: automated screening of job applications, lead scoring, dynamic pricing, credit decisions. If Copilot is in the loop, document and inform.
10 - Notification plan for the CAI and affected individuals
In the event of an incident likely to cause serious injury, you must notify the CAI AND the individuals concerned without delay. "Without delay" is interpreted strictly: 24 to 72 hours under best practice.
Prepare a notification template (for both the CAI and individuals) ahead of time, not in the middle of a crisis.
11 - Training and awareness
Employees must receive training on the protection of personal information - at least annually, ideally at onboarding and then annually. Keep a written record (who took it, when, and the content).
A 30- to 45-minute session with a quiz is enough for most employees. Provide enhanced training for higher-risk roles (HR, finance, sales, marketing, IT).
Rest of the document
The next 3 chapters are in the full version.
You just read the opening chapters in full, with no form. The complete document has 5 chapters: fill in the form to get the full printable PDF.
Still to read
- 3Microsoft 365 as your compliance stack
- 4Compliance roadmap
- 5Sustaining compliance over time
Further reading
Related blog articles.
A shorter format, direct access with no form. To dig into a specific angle of the topic.
30 minutes to frame what matters.
A direct conversation with one of our experts. No commitment, no pressure. You leave with a clear, reasoned perspective on your situation.

