
What Quebec's Law 25 Means for Your Client Data
The final phase of Law 25 came into force in September 2024. Most of what it requires is not legal work. It is knowing where personal information sits and being able to act on it.

Quebec’s Law 25, previously Bill 64, finished phasing in on 22 September 2024. It arrived in three stages, in September 2022, September 2023 and September 2024, deliberately staged so organisations could build toward it.
Most businesses treated it as a legal exercise. A lawyer produced a policy, somebody was named as privacy officer, the policy went on the website, and operations carried on exactly as before.
That is the gap worth closing, because almost everything the law actually asks for is operational rather than legal.
This is not legal advice. Take the specifics to a Quebec privacy lawyer. What follows is about what it means for how your business runs.
The obligations that touch daily operations
Strip out the legal architecture and a handful of practical requirements remain.
You need a named privacy officer and an incident response plan, both required since September 2022.
You need to log privacy incidents, which means knowing when one has happened.
You need to answer requests from individuals about the personal information you hold on them, within the timeframes the law sets.
You need consent that is meaningful, for purposes you have actually described.
You need to keep information only as long as the purpose requires, then destroy or anonymise it.
Every one of those depends on the same underlying capability, and it is not a legal capability.
The question most businesses cannot answer
Where does personal information about a given individual currently sit?
For a typical company the honest answer is: the CRM, the accounting system, a project tool, several shared drives, the marketing platform, a spreadsheet somebody built, and the inboxes of four employees. Possibly a form provider and a scheduling tool nobody remembers signing up for.
If somebody submits a request tomorrow, answering it means asking several people to search several systems and hoping nothing was missed. That is not a compliance programme. It is a fire drill, and it is why the retention obligation in particular gets quietly ignored, because you cannot delete on a schedule what you cannot locate.
Where AI does the work
This is the part that was genuinely impractical before and is now straightforward.
Finding personal information across systems means reading unstructured material. Free text notes in a CRM, attachments, email threads, scanned documents. Rules and keyword searches were never good enough because personal information does not announce itself in a consistent format.
AI reads that material and identifies what is personal information, which individual it relates to, and where it lives. That turns an inventory from a consulting project into something that runs continuously.
Once that exists, the rest follows. A request from an individual can be answered by searching one index rather than six systems. Retention schedules can actually run, because there is a record of what exists and when it was collected. And an incident can be assessed quickly, because you know what was in the affected system.
The obligation that catches people out
Retention is the one most commonly ignored, and it is the one that compounds.
Every year of data you keep beyond its purpose is a year of additional exposure in an incident, additional volume in a request, and additional storage nobody audits. Businesses accumulate this without deciding to, because deleting requires knowing what you have.
It is also the obligation with the clearest operational fix. Agree a retention period per category, apply it, and let it run.
The upside nobody mentions
Doing this properly produces something valuable beyond compliance.
A business that knows where its client information lives, keeps it current, and can find anything on request is a business with clean data. Clean data is the precondition for everything else worth doing, including reporting that agrees with itself and any AI system trained on your own material.
Firms that treated Law 25 as an operational project rather than a legal one generally came out with better systems than they had before. Firms that produced a policy have a document and the same mess underneath it.
Consent has to mean something
The requirement people find hardest is not technical. It is that consent must be informed and specific to a purpose you actually described.
A single checkbox agreeing to a privacy policy, covering everything a business might conceivably do, is the pattern the law was written to move away from. If you collect information for one reason and later use it for another, the original consent does not automatically carry over.
Practically, that means writing down what you collect and why, in language a client would understand, and asking separately for anything that falls outside it. Most businesses discover in doing this that they collect several things nobody can justify, which is the cheapest possible fix.
Suppliers are part of your exposure
Information you pass to somebody else is still your responsibility.
Every system holding client data on your behalf is part of the picture: the CRM, the accounting platform, the scheduling tool, the marketing system, the contractor with access to a shared drive. Each represents a place an incident could originate and a place information might sit longer than your own retention rules allow.
List them. For each, know what they hold, where it is processed and what happens when the relationship ends. That list is also the inventory the rest of this depends on, so the work is not duplicated.
The incident you have to be ready for
Obligations around privacy incidents assume you can establish quickly what was affected and who.
That is only possible if the inventory exists beforehand. A business discovering an incident and only then attempting to work out what was in the affected system is going to be slow at exactly the moment speed matters, and slow looks like negligence whether or not it was.
The preparation is modest: know what sits where, keep the log, and agree in advance who decides. An afternoon now against a very bad week later.
Sources
Fasken, Law 25 resource centre, covering the phased implementation of An Act to modernize legislative provisions as regards the protection of personal information, Quebec, in force in stages from 22 September 2022 to 22 September 2024.
AI Optimize builds the information inventory, the request handling and the retention rules that make these obligations something your systems do rather than something your team scrambles to prove. That work sits under Document Intake & Validation and Workflow Automation.
Related reading

What to Ask Before You Put Client Data Into AI
Most businesses are already feeding client information into AI tools, usually without anyone deciding to. Six questions separate a system you can defend from one you cannot.

Why Files Sit for a Week Waiting on One Page
Document collection looks like admin and behaves like a bottleneck. In most businesses it is the single largest source of delay between a client saying yes and the work starting.
WHAT WE BUILD



