Law 25 Privacy Officer Requirements: A Practical Guide
Designate the person in charge of the protection of personal information in your business.
The essentials
The person in charge of the protection of personal information, Quebec's version of a privacy officer (RPRP in French), is the person responsible for ensuring Law 25 compliance in a business. Since September 22, 2022, every Quebec business must have one, regardless of size.
By default, the role falls to the most senior executive. It can be delegated in writing to an employee or an external provider. The privacy officer's title and contact information must be published on the company website, usually in the privacy policy.
Without a privacy officer, the business is exposed to penalties from the Commission d'accès à l'information of up to $10 million or 2% of worldwide turnover.
Your three options at a glance
Qui sera votre RPRP ?
Trois options valides selon la loi. Dans tous les cas, une seule personne porte le rôle.
Le dirigeant
Par défautLa loi lui attribue le rôle automatiquement. Aucune délégation requise, mais la nomination gagne à être documentée.
Un employé désigné
Délégation écriteUn gestionnaire de confiance (RH, administration) formé aux exigences de la loi.
Un prestataire externe
Délégation écriteAvocat, comptable ou consultant. La responsabilité de l'entreprise demeure.
Dans tous les cas : le titre et les coordonnées du RPRP doivent être publiés sur votre site web, habituellement dans la politique de confidentialité.
What the law says
Since September 22, 2022, section 3.1 of the Act respecting the protection of personal information in the private sector (CQLR, c. P-39.1), as amended by Law 25, requires every business that collects, holds or uses personal information to have a person in charge of the protection of personal information, Quebec's equivalent of a privacy officer (known in French as the RPRP).
By default, this role falls to the person with the highest authority in the business (CEO, owner). It can be delegated in writing, in whole or in part, to anyone able to perform it effectively: an employee, or even an external third party.
The privacy officer must:
- Ensure the organization complies with Law 25
- Respond to requests for access to or rectification of personal information
- Manage confidentiality incidents
- Oversee data protection policies and procedures
The law also requires the title and contact information of the privacy officer to be published on the company website or, if there is no website, made available by any other appropriate means (source: Commission d'accès à l'information (in French)).
For a small business
In a small business, this role can be assigned:
- To the owner or general manager
- To a trusted manager (HR, administration)
- To an employee trained on the law's requirements
It is important to officially document this appointment and to make the privacy officer's contact information easy to find, for example on your website and in your privacy policy.
Good to know
Without an officially designated privacy officer, the owner or most senior executive is automatically considered responsible. In the event of a confidentiality incident, that person will have to answer to the authorities and could face penalties.
Concrete examples
Example 1: A hair salon with 4 employees appoints its administrative manager as privacy officer.
Her contact information (name, email, phone) appears in the privacy policy on the website.
An internal document sets out her responsibilities and the procedure to follow when a client makes a request.
Example 2: A freelance marketing consultant works alone and manages his clients' data (contact lists, campaign statistics).
As the only employee, he is automatically the privacy officer. He still writes a short privacy policy that he shares with his clients.
What do you risk without a privacy officer?
Failing to designate a privacy officer, or to publish their contact information, breaches an obligation in force since September 2022. The Commission d'accès à l'information (CAI) can impose administrative monetary penalties (in French) of up to $10 million or 2% of worldwide turnover, whichever is higher.
The most serious penal offences expose the business to fines from $15,000 up to $25 million or 4% of worldwide turnover, doubled for repeat offences. For individuals, fines range from $5,000 to $100,000.
In practice, the CAI scales its interventions. For a small business, the typical trigger is a complaint from a client or an employee. A missing privacy officer listing on the website is then the most immediately visible breach during an inspection.
Internal or external privacy officer?
Section 3.1 allows the function to be delegated in writing, in whole or in part, to any person: an internal manager, but also an external provider (lawyer, accountant, compliance consultant). The CAI specifies that this person must be able to perform the role effectively: delegation does not dilute the company's accountability.
For most small businesses, an internal privacy officer is enough: once compliance is in place, the role takes a few hours per month. Outsourcing becomes relevant if you process sensitive data (health, finances) or large volumes of information.
Who should take on the privacy officer role
| Option | Best when | Watch out for |
|---|---|---|
| The owner or CEO (the law's default choice) | Very small team, little data processed | They already carry the responsibility; formalizing the appointment is still useful so it can be published |
| An internal manager (HR, administration) | The owner lacks time, the team is more than a few people | Written delegation is mandatory; allow time and basic training |
| An external provider (lawyer, consultant) | Sensitive data, large volumes, industry-specific requirements | The company remains accountable; formalize the mandate in writing |
Law 25 penalties at a glance
| Type of penalty | Who can be targeted | Maximum amount |
|---|---|---|
| Administrative monetary penalty, imposed by the CAI | Businesses | $10 million or 2% of worldwide turnover, whichever is higher |
| Penal fine | Businesses | $15,000 to $25 million or 4% of worldwide turnover; doubled for repeat offences |
| Penal fine | Individuals | $5,000 to $100,000 |
Mistakes to avoid
- Not formalizing the appointment (no written record)
- Appointing someone who lacks the time or skills needed
- Not publishing the privacy officer's contact information
- Forgetting to update the information when the officer changes
Step-by-step instructions
Checklist: Step 1 complete?
- I have identified and appointed my privacy officer
- I have documented the appointment in writing
- I have updated my privacy policy
- The privacy officer's contact information is publicly available
- I have informed my employees
Templates included in the Law 25 Kit
- Privacy Officer Appointment Letter template
- Law 25 Compliant Privacy Policy template
- Internal Privacy Officer Appointment Email template
Frequently asked questions
Does a self-employed worker need to appoint a privacy officer?
Yes. The law provides no exemption based on company size. If you work alone, you are automatically the privacy officer. You still need to publish your title and contact information, for example in the privacy policy of your website.
Can the privacy officer be someone outside the company?
Yes. The function can be delegated in writing, in whole or in part, to any person able to perform it effectively, including an external third party such as a lawyer, an accountant or a compliance consultant.
Do you have to register your privacy officer with the CAI?
No. No filing with the Commission d'accès à l'information is required when designating a privacy officer. Your obligations are to document the appointment in writing and to publish the officer's title and contact information on your website.
What exactly must be published on the website?
The title and contact information of the privacy officer (a dedicated email address is enough, for example privacy@yourbusiness.ca). The usual place is the privacy policy. Without a website, the information must be made available by any other appropriate means.
Since when has this obligation been in force?
Since September 22, 2022. It was part of the first wave of Law 25 provisions, which came into force at the same time as mandatory reporting of confidentiality incidents and the rules on biometrics.
Is the privacy officer the equivalent of the European DPO (GDPR)?
The roles are comparable, but the Quebec obligation is broader: the GDPR only requires a data protection officer in specific cases, whereas Law 25 requires a privacy officer in every business, regardless of size or industry.