Services sociaux
What companies need to know to remain compliant
Bill 25, formerly known as Bill 64, represents a major evolution in the protection of personal information in Quebec. Here are the essential points for businesses, with a focus on changes, penalties and methods of compliance.
Key changes
- Explicit consent: individual consent must now be clear and explicit.
- Appointment of a DPO: companies must appoint a personal data protection officer.
- Greater rights for individuals: individuals' rights of access, rectification and opposition are strengthened.
- Risk assessment: all data collection must undergo a privacy risk assessment.

Sanctions
Companies that fail to comply with stringent regulatory compliance requirements expose themselves to particularly heavy financial and legal penalties. Not only do they risk fines of up to $25 million, or 4% of worldwide annual sales - an amount which, for some companies, can represent a significant loss - but they may also find themselves facing legal action. These lawsuits aim to claim damages for the harm caused by their non-compliance..

Why is compliance essential?
In addition to financial penalties, non-compliance can damage a company's reputation, erode the confidence of customers and partners, reduce competitiveness, and result in costly audits. Companies must therefore adopt rigorous measures to comply with regulations in order to avoid serious repercussions that could compromise their long-term viability.
Complying with Bill 25
- Compliance audit: assess current data protection practices.
- Policy update: adapt internal policies to meet new requirements.
- Staff training: make employees aware of the new obligations.
Be supported by MGP Conseils
We're well aware that this can be a daunting task, and we've seen first-hand how complex it can be for SMEs.
MGP Conseils offers tailor-made support to help companies comply with Law 25, providing auditing, training and ongoing support services.
We support you from diagnostics and gap analysis to the implementation of the measures required to comply with Bill 25 on the protection of personal information.