Quebec Law 25: Privacy Officer Requirements and Responsibilities

What Law 25 requires of a Quebec business's privacy officer: who qualifies, what you must publish on your website, the duties and small-business options.

Canada Compliance AI• Compliance Team
April 1, 2026
Updated September 15, 2026
9 min read
Law 25 Privacy Officer
CPVP Quebec
Quebec Privacy Officer Requirements
Law 25 Compliance
Personne responsable protection renseignements

One of Law 25's most distinctive requirements is the mandatory designation of a Privacy Officer — a "person in charge of personal information" (CPVP) — whose name and contact information must be published on your website. This transparency obligation is significantly stronger than anything in PIPEDA. Here's what Quebec businesses need to know.

Last updated: April 2026

The Law 25 Privacy Officer Requirement

Under Quebec's Act Respecting the Protection of Personal Information in the Private Sector (as amended by Law 25), every enterprise that collects personal information must:

  1. Designate a person responsible for the protection of personal information
  2. Publish that person's title and contact information on the enterprise's website (or, if the enterprise has no website, make it available by any other appropriate means)
  3. By default, the person in charge is the person exercising the highest authority (e.g., the CEO), who may delegate the function in writing (s. 3.1)

This requirement came into force on September 22, 2022 as part of Law 25's first wave of obligations (CAI 2022-2023 annual report).

Who Must Be the Privacy Officer?

The Default Rule: The CEO

If an enterprise does not explicitly designate someone else, the CEO (or equivalent) is automatically the person responsible for personal information protection. This is Law 25's baseline — the responsibility sits at the top.

Designating Someone Else

For most businesses with more than a handful of employees, the CEO will want to delegate the CPVP role to another person. That person can be:

  • A Chief Privacy Officer (CPO)
  • The General Counsel or in-house legal counsel
  • The Head of IT or IT Security Manager
  • An HR Director
  • A designated compliance officer
  • A senior manager with the appropriate authority and capacity

What matters: The designated person must have the authority and resources to fulfil the role. Designating a junior administrator as Privacy Officer without giving them authority to change data practices is a compliance failure.

Must the CPVP Be an Employee?

Not necessarily. Some enterprises engage external privacy consultants or law firms as their designated CPVP. Law 25 doesn't prohibit this, but the person must genuinely fulfill the responsibilities — not just be a name on the website.

What Must Be Published on Your Website

This is where Law 25 distinguishes itself from PIPEDA. You must publish:

  • The title of the person responsible (not necessarily their name, but their title/role)
  • Contact information allowing individuals to reach them

What this means in practice:

  • Most businesses publish the job title and an email address (e.g., "Privacy Officer — privacy@yourcompany.com")
  • Publishing a name is best practice and recommended for transparency
  • The information must be easy to find — it should appear in or near your privacy policy, not buried in a careers page

Example:

Person Responsible for the Protection of Personal Information: [Job Title] | privacy@company.com | [Phone] (optional)

Responsibilities of the Quebec Privacy Officer

The CPVP under Law 25 has broad responsibilities:

1. Policy and Programme Oversight

The CPVP is responsible for the enterprise's overall personal information protection programme, including:

  • Maintaining the privacy policy (and its French version)
  • Ensuring policies are up to date with legal requirements
  • Reviewing and approving significant changes to data practices

2. Privacy Impact Assessments (PIAs)

Law 25 requires PIAs before any new project involving personal information that presents privacy risks. The CPVP:

  • Oversees or conducts PIAs for new projects
  • Reviews PIA results and approves or rejects proposed projects
  • Documents all PIAs conducted

3. Breach Response

When a confidentiality incident (data breach) occurs, the CPVP:

  • Coordinates the breach response
  • Assesses whether the breach meets the CAI notification threshold
  • Files the report with the CAI promptly for incidents presenting a risk of serious injury
  • Coordinates notification to affected individuals
  • Maintains the breach register

4. Access and Correction Request Handling

The CPVP manages or oversees:

  • Processing individual access requests within 30 days
  • Processing correction requests
  • Responding to portability and de-indexing requests under Law 25

5. Employee Training

The CPVP is responsible for ensuring employees understand:

  • The enterprise's data practices
  • Their obligations under Law 25 and the enterprise's policies
  • How to identify and report a potential breach

6. Vendor and Third-Party Oversight

Law 25 imposes obligations on cross-border data transfers and third-party service provider agreements. The CPVP:

  • Reviews third-party agreements for data protection terms
  • Ensures PIAs are completed before cross-border data transfers
  • Monitors vendor compliance

7. Register Maintenance

Enterprises subject to Law 25 must keep a register of confidentiality incidents (s. 3.8) and must make an entry of certain communications of personal information made without consent (ss. 18 and 18.1). The CPVP oversees these records.

The CPVP Under PIPEDA vs. Law 25: Comparison

FeaturePIPEDALaw 25
Designation requiredYesYes
Must publish name/titleNoYes — title and contact info
Default to CEONo (but accountability principle applies)Yes, explicitly
Breach response roleYesYes (prompt CAI notification)
PIA oversightBest practiceMandatory
Portability request handlingN/AYes
De-indexing request handlingN/AYes

Small Business Considerations

For small enterprises (under 25 employees), the CPVP role is often held by the owner. Practical steps:

  1. Decide who — owner, office manager, or HR lead
  2. Document the designation — even a short internal memo naming the CPVP
  3. Update your website — add a "Privacy Officer" section to your privacy policy page with their title and a privacy@yourcompany.com email
  4. Train yourself — understand the key Law 25 obligations and how to respond to common scenarios

Frequently Asked Questions

Q: We're a small 5-person business. Does Law 25's CPVP requirement apply to us? A: Yes — Law 25 applies to any enterprise collecting personal information in Quebec, regardless of size. The CEO is your default Privacy Officer unless you designate someone else.

Q: Can we just add a "privacy contact" link to our website instead of naming a person? A: Law 25 requires publishing the title (at minimum) of the person responsible and their contact information. A generic "contact us" link is not sufficient. A title-linked email (e.g., "Privacy Officer: privacy@company.com") satisfies the requirement.

Q: What happens if we don't designate a CPVP? A: By default, the CEO bears the responsibility. But more importantly, failure to meet the Law 25 requirements can attract CAI enforcement and penalties.

Q: Does the CPVP need privacy law training? A: Law 25 doesn't mandate specific certifications, but the CPVP must be capable of fulfilling the role. Basic privacy law training is highly recommended, and keeping up with CAI guidance is essential.


Make Your Law 25 Privacy Officer Role Manageable

Canada Compliance AI helps Canadian SMEs work through CASL, PIPEDA and Quebec Law 25: a free two-minute compliance check, readiness scores, a prioritized task plan, a 24-month breach register and an exportable audit log. See what's live and what's planned.

Start your free trial today — Law 25 compliance support for Quebec businesses.

Related reading: What is Quebec Law 25 | Law 25 vs PIPEDA | PIPEDA Compliance Guide

Found this article helpful?

Share it with your team or save it for later reference.

Related compliance guides

Explore step-by-step guidance for PIPEDA, CASL, and Quebec Law 25.