Sentrix

Resources · Article

Law 25: the five gaps that persist

Most Law 25 obligations have been in force since September 2023. Five gaps still come up in personal information protection programs; here is how to close them.

By Sentrix · Published 2026-03-24

In short

Most obligations of Quebec's Law 25 have been in force since September 2023. The early scramble to publish a privacy policy and stand up a consent banner is behind most organizations. What we still see, walking into new customer assessments, is not a lack of effort: it is a set of specific, recurring gaps that surface once you look past the visible parts of a compliance program and into how it actually operates day to day. Here are the five most common, and how to close them.

1. A records of processing activities register that stops being maintained

Almost every organization we assess built a records of processing activities (ROPA) register at some point, usually as part of an initial Law 25 project. Far fewer keep it current. New data flows, new vendors, new internal systems get added to the business without anyone updating the register that is supposed to describe them. By the time the CAI or an auditor asks for it, the register describes an organization that no longer quite exists. A static document reviewed annually is not a register: it is a snapshot with an expiry date nobody tracks.

2. Privacy impact assessments triggered too late, or not at all

Law 25 requires a PIA, a privacy impact assessment, before launching a new project involving personal information, not after. In practice, we regularly find PIAs completed retroactively, once a project is already in production, because no one on the project team knew to trigger one at the start. The gap is rarely a lack of a PIA template. It is the absence of a workflow that catches new projects early enough for the assessment to actually influence design decisions rather than document a system that already shipped.

3. Incident notification playbooks that were never rehearsed

Every organization we meet has a documented notification procedure covering the obligation to notify the CAI with diligence when a confidentiality incident presents a risk of serious injury. Far fewer have actually walked through it against a realistic scenario. The gap shows up in the details that only surface under pressure: who has authority to declare an incident meets the "serious injury" threshold, how severity scoring actually gets applied at 2 a.m., and whether the people named in the playbook still work there. A procedure that has never been rehearsed is a procedure you are testing for the first time during an actual incident.

4. Consent records that cannot be tied back to a specific purpose

Cookie banners and consent capture are usually in place. What is frequently missing is the link between a specific consent event and the specific processing purpose it authorizes. When a data subject request comes in asking what they consented to and why, organizations often can produce a timestamp and a category, but not a clear record of exactly what purpose that consent covered, which makes it difficult to demonstrate that processing has stayed within the bounds of what was actually agreed to.

5. A PIPEDA crosswalk that exists in someone's head, not in the program

Most Quebec private-sector organizations are subject to both Law 25 and the federal PIPEDA, and need to follow the progress of federal privacy reform as well. In practice, the mapping between these regimes usually lives in the experience of one privacy officer rather than in documented control mappings the rest of the organization can rely on. That works fine until the person who understands the crosswalk leaves, or the organization needs to demonstrate to the CAI exactly how a given control satisfies both frameworks at once.

The common thread

None of these five gaps come from a lack of an initial Law 25 project. They come from compliance artifacts, registers, assessments, playbooks, consent records, crosswalks, that were built once and left to age instead of being maintained as living parts of the business. A point-in-time compliance project produces a point-in-time register. Continuous compliance requires the register, the workflows, and the evidence to update as the business changes.

These patterns reflect common findings across Law 25 assessments generally and are not statistics from a specific study: treat them as a starting checklist for your own program review, not a benchmark.

A starting checklist for your program review

The five gaps turn into five questions to ask of your own program, at least once a year and at every significant change in the business.

  1. Register. Who updates the records of processing activities when a new vendor, system or data flow enters the organization? When was it last modified, and does that date match the last real change?
  2. PIA. At what point in a project's life cycle is the assessment triggered, and who triggers it? Does every project in flight have a PIA dated before it went into production?
  3. Notification. Has the playbook been rehearsed against a realistic scenario in the last twelve months? Are the people named in it still in their roles? Who decides that the serious-injury threshold is met?
  4. Consent. For a given consent, can you produce the exact purpose it covered, not just a timestamp and a category?
  5. Crosswalk. Is the mapping between Law 25 and PIPEDA documented, control by control, and available to someone other than the privacy officer?

Go further

The managed governance service takes on maintaining these artifacts as a continuous program; the data protection service covers the technical controls that support them. The Law 25 framework page summarizes what the Act requires.

Sources

Frequently asked questions

When must a privacy impact assessment be carried out?
Before launching a project to acquire, develop or overhaul an information system or electronic service delivery system involving personal information, not after. The PIA must influence design decisions; an assessment completed once the system is in production documents a choice already made. The gap is rarely a missing template, it is the absence of a workflow that catches new projects early enough.
What should we do when a confidentiality incident occurs?
Assess whether the incident presents a risk of serious injury; if so, notify the Commission d'accès à l'information and the persons concerned with diligence, and record the incident in the register. The notification playbook must say who has authority to declare the threshold met and how severity is assessed. A playbook never rehearsed against a realistic scenario is tested for the first time during the real incident.
Does Law 25 replace PIPEDA?
No. Most Quebec private-sector organizations are subject to both Law 25 and the federal PIPEDA, depending on the nature of their activities. The crosswalk between the two regimes must be documented in the program, as control mappings, rather than living in one person's experience, so the organization can demonstrate how a given control satisfies both laws at once.

Let's talk about your compliance program.

Last updated: 2026-09-17