← Back to Blog
    BlogComplianceAugust 7, 20268 min readBy Mirage Informatique

    Law 25 Enforcement in 2026: Ready for a CAI Inspection?

    Quebec's privacy regulator now holds every Law 25 power, including penalties up to 4% of worldwide turnover. Here's what an inspection asks for and how Microsoft 365 answers.

    Share
    Law 25 Enforcement in 2026: Ready for a CAI Inspection?

    Law 25 enforcement in Quebec has quietly shifted gears. Every obligation in the law has been in force since September 22, 2024, the Commission d'accès à l'information (CAI) has held the power to impose administrative monetary penalties since September 2023, and the regulator has published the framework it applies when deciding whether to sanction a business and for how much. The education phase, those years of webinars and gentle reminders, is behind us.

    For an SMB in Quebec City or anywhere in the province, that changes the math. A single declared confidentiality incident, or one complaint from a customer or former employee, can open a file at the CAI. When that happens, the questions arrive in writing and they are specific. This article maps each Law 25 obligation to a concrete Microsoft 365 control so the answers exist before anyone asks. It builds on our earlier Law 25 and Microsoft 365 guide with an enforcement-readiness lens.

    Key Takeaways

    • All Law 25 obligations have been enforceable since September 2024. No grace period remains.
    • The CAI can impose administrative penalties of up to $10 million or 2% of worldwide turnover.
    • Penal fines can reach $25 million or 4% of worldwide turnover, doubled for repeat offences.
    • The CAI can request your confidentiality incident register at any time.
    • Purview, DLP, retention and Conditional Access turn most CAI questions into evidence, not promises.

    Why 2026 is different: the CAI holds its full toolkit

    Law 25 arrived in three waves. September 2022 brought mandatory reporting of confidentiality incidents that present a risk of serious injury, plus the obligation to keep an incident register. September 2023 added the bulk: a designated privacy officer, published governance policies, privacy impact assessments (PIAs) for system projects and for communicating personal information outside Quebec, stricter consent rules, and confidentiality by default. September 2024 completed the picture with data portability (per the CAI's summary of the main changes). Nothing in the law is "coming soon" anymore.

    The enforcement powers followed the same arc. Since September 22, 2023, the CAI can impose administrative monetary penalties on private-sector enterprises: up to $10 million or 2% of worldwide turnover, whichever is greater. Serious offences move to penal court, where fines climb to $25 million or 4% of worldwide turnover, and double for a repeat offence (per the CAI's sanctions page). The Commission has also published the general framework it uses to decide when a penalty applies and how the amount is set, which tells you two useful things: these powers are meant to be used, and cooperation counts. A business can propose a formal undertaking to correct a violation, and an accepted, respected undertaking can avoid a monetary penalty. Decisions, however, are public. For a 40-person firm, the reputational line item can cost more than the cheque.

    Professional working on a laptop in a modern office, reviewing privacy compliance settings
    Professional working on a laptop in a modern office, reviewing privacy compliance settings

    What a CAI file will ask you to produce

    Files typically start one of three ways: you declare an incident, someone files a complaint, or the Commission takes an interest on its own initiative. Whatever the trigger, expect to produce evidence, in writing, on a deadline. Based on the obligations in the law, that means:

    • The name, title and contact information of your privacy officer, published on your website
    • Your policies and practices governing personal information, written in clear language
    • Your confidentiality incident register, which the CAI may request at any time
    • PIAs for projects involving personal information and for any communication of data outside Quebec
    • Proof that valid consent was obtained for each purpose
    • Evidence of security measures proportional to the sensitivity of the data you hold

    Two observations from the field. First, none of these documents can be produced credibly at the last minute; an incident register created the week the CAI asks for it convinces no one. Second, the technical items on that list are exactly where most SMBs are strongest, because Microsoft 365 already contains the machinery. It just has to be turned on and documented.

    Mapping each Law 25 obligation to Microsoft 365 controls

    Here is how the obligations line up against tools most Quebec SMBs already pay for through Business Premium or E3/E5 licensing.

    Know what you hold: Purview classification and sensitivity labels

    You cannot protect, minimize or destroy data you have not located. Microsoft Purview's sensitive information types detect Quebec-relevant identifiers (social insurance numbers, health card numbers, financial data) across Exchange, SharePoint, OneDrive and Teams. Sensitivity labels then mark and encrypt the files that carry them. When the CAI asks what personal information you hold and why, Content Explorer gives you an answer with numbers in it.

    Control who gets in: Entra ID and Conditional Access

    Law 25 requires security measures against unlawful access, and in practice that starts with identity: multifactor authentication everywhere, legacy authentication blocked, risky sign-ins challenged. Our free Conditional Access baseline covers the policies we deploy for every client, and our cybersecurity services team layers Intune device compliance checks on top.

    Keep less, expose less: DLP and retention policies

    The law expects personal information to be destroyed or anonymized once its purpose is fulfilled. Retention policies and labels in Purview automate that end of life instead of leaving it to good intentions; a tenant that keeps every file forever is carrying liability, not archives. On the outbound side, DLP policies block or flag social insurance numbers, health numbers and card numbers leaving through Exchange, Teams or SharePoint sharing links, a direct answer to the obligation to prevent unlawful communication.

    Prove what happened, or did not: audit logging and eDiscovery

    An inspection is an exercise in evidence. The unified audit log records who accessed which mailbox, file or admin setting, which is what you need both to investigate an incident and to demonstrate that access is limited. eDiscovery finds every item tied to one person when they exercise their access or portability rights, on a deadline, without anyone digging through mailboxes by hand.

    Detect, respond, document: Defender and your incident register

    Incident obligations have three parts: detect, assess the risk of serious injury, then notify the CAI and affected individuals with diligence when the threshold is met. Defender for Business surfaces the compromise; your runbook should end with the assessment, the CAI's official declaration form, and an entry in the register. If nobody owns that last step, the technical response succeeds while the legal one fails.

    Four professionals discussing compliance priorities in a modern office meeting space
    Four professionals discussing compliance priorities in a modern office meeting space

    A 90-day Law 25 enforcement readiness plan

    1. Weeks 1-2: Confirm your privacy officer designation, publish their contact information, and refresh your privacy policy in plain language.
    2. Weeks 3-4: Run Purview discovery across the tenant, then label the repositories where personal information concentrates.
    3. Weeks 5-6: Deploy the Conditional Access baseline and close the MFA gaps it reveals.
    4. Weeks 7-8: Turn on DLP for social insurance numbers, health numbers and financial data; set retention policies with real deletion dates.
    5. Weeks 9-10: Write the incident runbook, build the register template, and run one tabletop exercise.
    6. Weeks 11-12: Complete PIAs for tools that move personal information outside Quebec, then assemble everything into one binder a stranger could follow.

    If you would rather compress that timeline, our IT assessment benchmarks a tenant against this exact list in a week, and managed IT clients get the register and runbook maintained for them.

    FAQ

    What are the maximum penalties under Law 25 in Quebec?

    The CAI can impose administrative monetary penalties of up to $10 million or 2% of worldwide turnover, whichever is greater. Serious offences prosecuted penally can reach $25 million or 4% of worldwide turnover, and those fines double for repeat offences. Beyond the money, decisions are public and can include binding corrective orders.

    Can the CAI really investigate a small business?

    Yes. Quebec's private-sector privacy law applies to every enterprise that collects personal information, regardless of headcount. Files most often start with a declared incident or a complaint from a customer or former employee, so a small business with one unhappy contact is exposed the same day. Size influences what measures are proportional, not whether the law applies.

    Does using Microsoft 365 make my business compliant with Law 25?

    No. Microsoft 365 supplies the technical controls, but the law also requires governance: a designated officer, published policies, valid consent, impact assessments and an incident process. A well-configured tenant covers the security, retention and evidence obligations, which removes the hardest technical work and leaves you the documentation to complete.

    Where should we start if we have done nothing yet?

    Start with the visible basics: designate the privacy officer, publish the policy, and create the incident register even if it stays empty. Then close the identity gap with MFA and Conditional Access, since credential compromise is the most common incident we see in the field. Inventory with Purview comes next, and document each step as you go.

    Sources

    Enforcement readiness is mostly discipline: the same handful of controls, configured once and documented well. If you would like a second set of eyes on your tenant before the CAI supplies one, contact us and we will walk through it together.

    Share

    Related Articles