Law 25: what your website must comply with (2026 SMB guide)

Published August 11, 2026 · By the Boréo team · 8-minute read

If your business has a website in Quebec, Law 25 applies to you — whatever your size. A freelancer with a simple contact form is covered just like a large corporation. The good news: for a typical small business website, compliance is far less complicated than it's made out to be. Here's what the law concretely requires, explained simply.

Important note: we're a web agency, not a law firm. This guide explains the common obligations for an SMB website in plain terms; for your specific situation, consult a legal professional.

✅ The essentials in 30 seconds

Law 25 applies to every business, even a solo freelancer. For an SMB website, it comes down to 6 actions: designate a privacy officer (published on the site), publish a privacy policy describing your real practices, get consent before any tracking cookie, keep an incident log, respond within 30 days to access requests, and assess your tools that send data outside Quebec.

What is Law 25?

It's the Quebec law that modernizes the protection of personal information in the private sector. It came into force in stages between 2022 and 2024 and is now fully applicable. "Personal information" means anything that can identify a person: a name, an email, a phone number, an IP address. The moment your site has a contact form, you're collecting it.

The concrete obligations for your website

1

Privacy officer

Named and published on the site

2

Privacy policy

Your real practices, in plain language

3

Cookie consent

No tracking before the visitor agrees

4

Incident log

Document; notify the CAI if serious risk

5

Individual rights

Access, correction, deletion — 30 days

6

Tools outside Quebec

Assessed and named in the policy

1. Designate a privacy officer

Every business must have a designated person responsible for protecting personal information. By default, it's the person with the highest authority — the owner, in a small business. Their title and contact information must be published on your website. It's the simplest obligation, and one of the most often forgotten.

2. Publish a clear privacy policy

Your site must explain, in plain language: what information you collect, why, how it's stored and protected, whether it's shared with third parties (your hosting provider, your form or newsletter tools count), and how someone can access or delete it. A policy copied from an American site isn't enough: it has to describe your actual practices.

3. Get valid consent for tracking cookies

If your site uses tracking or advertising cookies (Google Analytics with ads, Meta pixel, etc.), they must stay inactive until the visitor agrees. Useful nuance: a site that uses no tracking cookies at all — which is possible, notably with cookieless analytics — doesn't need a consent banner. The famous banner isn't mandatory in itself; non-consented tracking is what's prohibited.

4. Respond properly to incidents

If personal information is lost or stolen (a hack, an email sent to the wrong recipient), you must keep an incident log and, where there's a risk of serious injury, notify the Commission d'accès à l'information and the people affected.

5. Respect individual rights

Anyone can ask to access the information you hold about them, have it corrected or deleted, and since 2024, obtain a copy in a structured format (portability). Your policy must explain how to make the request, and you must respond within 30 days.

6. Assess tools that send data outside Quebec

Most small businesses use American tools (forms, newsletters, hosting). That's allowed — provided you assess that the information is adequately protected there and say so in your policy.

Are the fines real?

$10M or 2%

of worldwide revenue — administrative penalties (CAI)

$25M or 4%

of worldwide revenue — penal sanctions

Yes — they're among the highest in Canada. But for a small business, the realistic risk isn't the maximum fine — it's a complaint from a customer or competitor triggering a review, and the hit to your reputation. Basic compliance costs a few hours; a complaint costs much more.

Where to start (in order)

  1. Designate your privacy officer and publish their contact information on your site.
  2. Take inventory: which forms, tools and cookies does your site actually use?
  3. Publish a privacy policy that describes those real practices.
  4. If you use tracking cookies, set up a real consent mechanism — or switch to cookieless tools.
  5. Create an incident log (a simple document is enough to start).

To save you time: our free privacy policy generator builds a Law 25-ready policy in minutes, based on what your website actually does. No sign-up.

In short

Law 25 doesn't require your small business to have a legal department — it requires transparency: say what you collect, protect what you hold, and respond when asked. A compliant website is also a trust signal for your customers: more and more people check.

Is your current website compliant? We review it as part of every website project — baseline compliance is built in at Boréo. Get a free quote →

Get a free quote