Law 25: What Changed on September 22, 2022 for Your Website Forms
What took effect under Quebec's Law 25 on September 22, 2022, and the website form audit I run for a client before touching their CRM setup.
As of September 22, 2022, Quebec's Law 25 puts two concrete obligations on every private business operating in the province, regardless of size: name a person in charge of protecting personal information, and keep a register of confidentiality incidents. If you run a website with a contact form, a quote request, or a booking form, every form on your site is now a collection point for personal information whose contents and destination you need to know. Here is what took effect on that date, and the form audit I run before touching a client's CRM.
What took effect on September 22, 2022?
Law 25, formally An Act to modernize legislative provisions as respects the protection of personal information, received royal assent on September 22, 2021, and comes into force in stages over three years. The first stage, the one dated September 22, 2022, is about internal governance: who is responsible for protecting personal information inside your business, and how you respond when a confidentiality incident happens. The rules on explicit consent and on tracking technologies such as cookies arrive in September 2023. Those are not in force yet, and they change nothing about what you need to do this week.
Who has to be named responsible for protecting personal information?
By default, that responsibility falls to whoever holds the highest authority in the business, meaning you, if you own or run a small business. Nothing stops you from delegating that role to someone else, such as an employee who already manages your CRM or your client communications, but the delegation has to be documented in writing. The title and contact details of whoever holds the role then need to be published on your website, usually in the privacy policy or on the contact page. A small business that does not yet have a privacy policy posted has nowhere to put that information, which is itself a gap to fix before anything else.
Does a website redesign or a new CRM need an extra step?
Not yet, but soon. The next stage of Law 25, the one dated September 22, 2023, will require any business starting a project to acquire, develop, or significantly overhaul an information system or electronic service that processes personal information to first complete a privacy impact assessment, scaled to how sensitive that information is. That requirement is not in force this week: the two obligations active since September 22, 2022, are the ones covered above, naming a responsible person and keeping an incident register. If you are planning a site redesign that adds new forms, or a first CRM rollout meant to centralize your clients, it is still worth starting now to list what personal information the new system will handle, where it will be stored, and who will have access, rather than waiting until the requirement becomes official.
What has to be in a confidentiality incident register?
Under the law, a confidentiality incident is unauthorized access to, use of, or disclosure of personal information, or its loss. That can be a submission emailed to the wrong recipient, a client file left on a shared computer, or a configuration mistake that leaves a database open to the public. Section 3.8 of the Act respecting the protection of personal information in the private sector, in force since September 22, 2022, requires every business to keep such a register. What I have clients log for every incident, even a minor one: the date, the nature of the information involved, how many people were affected, an assessment of the risk of harm, and the steps taken to limit the fallout. If an incident carries a risk of serious harm, you have to notify Quebec's Commission d'accès à l'information and the people affected. A register that does not exist protects no one; a simple shared file with those columns, updated as incidents happen, is enough for a small business.
What does each form on your site collect?
Before you can name someone responsible, or keep a register that means anything, you need to know what each form on your site is asking for. A basic contact form usually collects a name, an email, and a message, but a quote request for a renovation job or a booking form for a clinic can ask for a mailing address, a phone number, and sometimes more sensitive details, such as the kind of treatment someone is looking for. The exercise I run with a client before touching anything in their CRM is to list every form on the site one by one, field by field, and write down next to each one why that field is there. A field that serves no purpose in following up with the client, like a birth date on a general contact form, is a field to remove: the less you collect, the less risk you carry.
Where does that information land once the form is submitted?
This is the second half of the audit, and it is usually the part that turns up the most surprises. A form built with a generic WordPress plugin sometimes emails a copy to a shared inbox and never touches the business's actual CRM. A submission can end up sitting in the inbox of an employee who has since left the company, or get copied into a spreadsheet exported for a campaign, with no one keeping track of where every copy ended up. For each form, trace the exact path: does the submission go straight into the CRM? Does it also get emailed out? Is that email copy deleted once it has been handled, or does it just keep piling up? A piece of personal information that exists in three copies across three systems is harder to protect, and harder to delete if a client asks you to.
How does this audit play out with a client?
At SIB, a form audit is now part of every CRM and lead management project: before a single automated follow-up step gets configured, we list every form on the site, every field it collects, and the exact destination of every submission. That audit is what makes it possible to build one complete client record in the CRM instead of having personal information scattered across an inbox, a spreadsheet, and a booking system. It is also the same exercise that gives an owner the answers needed to correctly name whoever is responsible for protecting personal information: you cannot protect what you have not listed yet.
What should you do this week if none of this is in place?
Three things do not wait. Put in writing who is responsible for protecting personal information in your business, even if that is you by default. Start a confidentiality incident register, empty at first if it has to be, ready to log the first incident. List every form on your site along with the fields it collects and where each submission lands. None of these three steps needs a big budget or a developer. They mostly need you to sit down with the list of forms on your site and answer one question honestly: what are we collecting, and where does it go.
This piece summarizes the outline of Law 25's first stage for general information, not legal advice: to confirm exactly how these obligations apply to your situation, have your register and your privacy officer designation validated by a privacy law professional.
If that audit turns up personal information being sent to places you no longer control, this is the moment to fix it before the next stage of the law takes effect.
Drafted with AI assistance, checked and published by Marven Salgado.