Aller au contenu principal

Law 25 Compliance - Turnkey Solution for Quebec SMBs

IT, Data, and Website: We cover the 3 dimensions of Law 25 under one roof.

Since September 2023, Law 25 applies to any business collecting personal information in Quebec - including SMBs, NPOs, and self-employed workers. Penalties can reach $25M or 4% of global turnover. ABCnumérique gets you fully compliant in 4 to 8 weeks, without you having to coordinate three different vendors.

Get a free compliance assessment

Your business collects data. Do you know if you are compliant?

Law 25 is complex because it touches three dimensions simultaneously: your IT infrastructure (access, backups, encryption), your data (mapping, policies, retention), and your website (privacy policy, consent, cookies). Most SMBs hire a legal consultant, an IT guy, and a web agency separately—and eventually fall into the gaps between mandates.

  • You don't know exactly what personal information you collect or where it's stored
  • Your website lacks a compliant privacy policy or a cookie consent banner
  • Your customer data is scattered across Excel or a CRM without documented retention policies
  • Your Microsoft 365 environment lacks governance rules for personal data
  • You haven't officially designated a Privacy Officer (person in charge of the protection of personal information)
  • You are unsure if your cloud providers (Azure, Google, Salesforce) require a PIA (Privacy Impact Assessment)
34 %

of Canadian businesses said they were fully prepared to comply with new privacy laws—and Quebec's Law 25 is among the strictest in North America.

Norton Rose Fulbright — Data Protection Survey, 2023

A one-stop shop. All 3 dimensions covered.

ABCnumérique is the only Quebec firm covering all three dimensions of Law 25 compliance under one roof. Our IT, Data, and Digital Strategy teams work in parallel—cutting the compliance timeline in half compared to the multi-vendor approach.

Unlike law firms that stop at drafting paper policies, we actually implement technical measures in your infrastructure (M365 access rights, encryption, backups). Unlike traditional IT firms that stop at servers, we also produce the legal documents required by the CAI and train your teams.
1

Compliance Assessment (Weeks 1–2)

A one-hour executive interview. Preliminary mapping of the personal information collected, used, and communicated. Evaluation of IT infrastructure (access, backups, encryption) and website (cookies, forms, tracking). Compliance score report out of 100 with prioritized gaps.

2

Data Mapping & Policies (Weeks 2–4)

Complete registry of processing activities. Conduction of a PIA (Privacy Impact Assessment) if required (cloud vendors, cross-border transfers). Drafting of internal and external policies. Designation and coaching of the Privacy Officer.

3

Technical Implementation (Weeks 4–6)

Configuration of access rights in Microsoft 365 (Entra ID, SharePoint, Exchange). Encryption of sensitive data at rest and in transit. Deployment of the consent banner on the website. Configuration of consent mode v2 for Google Analytics 4. Microsoft Purview configuration if applicable.

4

Training & Validation (Weeks 6–8)

Company-wide training (2 hours, certificates included). Simulation of a privacy breach / confidentiality incident to test the notification workflow. Delivery of the complete compliance dossier (ready for CAI inspection). Maintenance plan and regulatory monitoring for the first 12 months.

What you get at the end of the mandate

Legal Documents and Policies

  • Registry of personal information processing activities
  • Complete mapping of personal information (inventory)
  • Privacy Impact Assessment (PIA) if required
  • Internal privacy policy (for your employees)
  • External privacy policy (published on your website)
  • Consent policy and documented collection mechanisms
  • Confidentiality incident management policy
  • Incident registry (ready to use)
  • Letter of designation for the Privacy Officer

Technical Implementation

  • Audit and reconfiguration of access rights (Microsoft 365 / Entra ID)
  • Cybersecurity audit (MFA, privileged access, leaks)
  • Law 25 compliant consent banner deployed on the website
  • Google Analytics 4 configured with consent mode v2
  • Encryption of sensitive data at rest and in transit
  • Retention policies configured in Microsoft 365 / SharePoint

Training and Maintenance

  • Law 25 training for the whole team (2 hours, certificates included)
  • Confidentiality incident simulation + notification process test
  • Complete compliance dossier (CAI inspection-ready)
  • Regulatory monitoring and post-compliance support (12 months)
  • Recommended annual compliance review

Questions fréquentes

Prêt à passer à l'action avec ABCnumérique ?

Discutons de vos enjeux. Notre audit de maturité numérique gratuit vous donne un portrait clair en 30 minutes.