Law 25: The Complete Guide to Making Your Website Compliant

Law 25 applies to every business that collects personal information in Quebec, regardless of size. For your website, that translates into concrete obligations: obtaining valid consent before activating non-essential cookies, publishing a clear privacy policy, framing every form that collects data and appointing a person in charge of the protection of personal information. Since September 2024, all of the law’s provisions have been in force. Here’s what that means, without the legal jargon.

What exactly is Law 25?

Adopted in 2021, Law 25 modernizes Quebec’s Act respecting the protection of personal information in the private sector. It came into force in three phases: September 2022 (person in charge of the protection of personal information, incident management), September 2023 (the majority of obligations, including consent and the privacy policy) and September 2024 (the right to data portability).

An important point for SMBs: contrary to what many believe, there is no minimum threshold. A two-person business in Drummondville is subject to the same rules as a multinational, as soon as it collects personal information — a name, an email address, an IP address, browsing behaviour.

What Law 25 concretely requires on your website

Cookie consent

This is the most visible requirement. Any technology that can identify, locate or profile a visitor — think Google Analytics, the Meta pixel or ad-retargeting tools — must be disabled by default. The visitor must give free and informed consent before it activates. In practice, that means a cookie-management banner that actually blocks the scripts until the visitor has accepted, not just a decorative strip with an “OK” button.

Beware of false compliance: many sites display a banner but still load trackers before consent. A technical test of a few minutes is enough to check — and the Commission d’accès à l’information can run the same test.

The privacy policy

Your site must publish, in simple and clear terms, a policy that explains what information you collect, why, how it’s stored and protected, who it’s shared with, and how a person can exercise their rights (access, correction, withdrawal of consent). Copy-pasting another site’s policy is a bad idea: it must reflect your actual practices. For the drafting, an adapted template is a good starting point, but if your activities are sensitive (health, finance, minors’ data), validation by a specialized lawyer remains the prudent route.

Forms and data collection

Every form on your site — contact, quote, newsletter, careers — is a collection point. The basic rule: ask only for what is necessary for the stated purpose. A contact form doesn’t need a date of birth. For the newsletter, consent must be explicit: no pre-checked box, no automatic subscription hidden inside another form. And the data collected must be hosted and transmitted securely, which brings us back to sound technical basics: an SSL certificate, up-to-date plugins, regular website maintenance.

The obligations that go beyond the website

Law 25 isn’t limited to your site. A few obligations affect the business as a whole:

  • Person in charge of the protection of personal information: by default, it’s the person with the highest authority (often the owner in an SMB). Their name and contact information must be published on your site.
  • Confidentiality incident register: any leak or unauthorized access must be recorded, and reported to the Commission d’accès à l’information if it presents a risk of serious harm.
  • Privacy impact assessment (PIA): required before certain projects, notably when data is communicated outside Quebec — which includes several common American cloud tools.
  • Portability: since September 2024, a person can ask to receive their personal information in a structured technological format.

What are the risks of doing nothing?

The penalties on the books are serious: administrative penalties of up to $10 million or 2% of worldwide revenue, and penal sanctions of up to $25 million or 4% of revenue. Let’s be honest: the Commission isn’t handing out maximum fines to good-faith SMBs. The real risk for a small business is rather a complaint from a customer or a competitor, an investigation request, lost time and a dented credibility. Compliance has also become a business criterion: more and more large clients and public bodies check it before signing.

Three myths we still hear in 2026

  • “I’m too small to be covered.” False: the law applies from the first piece of personal information collected, regardless of the size of the business or the site.
  • “My cookie banner makes me compliant.” Not necessarily: if the trackers load before consent, or if the privacy policy doesn’t keep up, the banner solves only part of the problem.
  • “It’s a one-and-done job.” No: every new tool added to the site — an advertising pixel, a chat module, a newsletter platform — changes what you collect and must be integrated into your consent management and your policy.

Where to start, concretely

For a typical SMB WordPress site, basic compliance is a reasonable undertaking — a few well-managed hours of work, not months. The logical order:

  • Take inventory of what your site collects: forms, analytics, advertising pixels, integrated tools.
  • Install real cookie management that blocks trackers before consent.
  • Write or update the privacy policy so it reflects your actual practices.
  • Appoint the person in charge of the protection of personal information and publish their contact information.
  • Review every form: necessary fields only, explicit consents.

To guide you step by step, we’ve prepared a Law 25 checklist for WordPress sites that you can follow at your own pace. And if you’d rather have us look at your situation with you — something we do regularly for local SMBs — write to us: we’ll tell you frankly what’s compliant, what isn’t, and what it takes to fix it.

La Loi 25 : La Nécessité d'une Gestion des Cookies et de Politique de Confidentialité