Law 25 and Microsoft 365: A Practical Compliance Guide
Law 25 compliance in Microsoft 365 is mostly configuration and documentation, not new software. Here is the tenant-level work that actually satisfies the requirements.

Most Quebec businesses discover their Law 25 gaps the same way: a client's procurement team sends a privacy questionnaire, and three of the questions have no good answer. Where is personal information stored? Who outside the company can reach it? Can you produce an audit trail if someone asks?
If you run Microsoft 365, the encouraging part is that you almost certainly own the tools already. Law 25 compliance in a Microsoft tenant is mostly configuration and documentation rather than new software. The work is real, but it is closer to a fortnight of deliberate setup than a six-figure project.
Key Takeaways
- Law 25 obligations map onto Microsoft 365 settings you already pay for.
- Start by finding where personal information actually lives, before changing any policy.
- External sharing and guest access are the two most common exposure points.
- Audit logging must be on before an incident, not after.
- Documentation is what the CAI asks for, so write decisions down as you make them.
What Law 25 actually asks of a Microsoft 365 tenant
Quebec's Law 25 raised the bar on consent, retention, transparency, breach handling, and accountability for any organization holding personal information about Quebec residents. It applies regardless of company size, and it is enforced by the Commission d'accès à l'information.
Translated into tenant terms, five obligations do most of the work:
- Know what personal information you hold and where it sits
- Limit access to people who genuinely need it
- Obtain and record meaningful consent where consent is your basis for collection
- Respond to access, correction, and deletion requests within the statutory timeline
- Detect, assess, and report confidentiality incidents, and keep a register of them
None of those require a product you do not already have in Business Premium or E3. They do require someone to make decisions and record them.
Step by step: configuring Microsoft 365 for Law 25
Map where personal information actually lives
Before touching a policy, find the data. Run content search across Exchange, SharePoint, OneDrive, and Teams for the categories you actually hold: social insurance numbers, health information, banking details, personnel files. Microsoft Purview's built-in sensitive information types will find most of it without custom work.
Expect surprises. Personal information tends to accumulate in places nobody designed for it, particularly individual OneDrive folders and long-running Teams chats. A finding here is worth more than a policy written against an imagined data map.
Lock down external sharing and guest access
This is where most SMB exposure sits. Review the tenant-wide sharing defaults in SharePoint and OneDrive, and move away from "anyone with the link" unless a specific business case justifies it. Set link expiry. Audit existing guest accounts and remove the ones left over from finished projects.
While you are in there, check which Teams allow guest membership and whether any site holding personnel or client records is externally shareable at all.

Turn on and keep the audit log
Unified audit logging is the single setting people regret not enabling. It has to be on before an incident to be useful during one, and default retention may be shorter than the window you will actually need. Confirm it is enabled, then decide retention deliberately rather than accepting whatever the tenant came with.
If you are also running Sentinel or Defender, point the Entra ID sign-in and audit logs at your workspace so identity events survive alongside everything else.
Handling consent and individual rights in Microsoft 365
Law 25 gives individuals concrete rights, and the practical question is always the same: could you actually service a request within the deadline?
Access and portability requests
When someone asks what you hold about them, you need to find it across every workload without a week of manual searching. Purview eDiscovery handles this, but only if someone in your organization has the role assigned and has run it at least once before the first real request arrives. Practise on a fake subject.
Correction, deletion, and de-indexing
Deletion is harder than it looks in a Microsoft tenant, because copies persist in mailboxes, version history, and retention holds. Decide in advance how you will handle a deletion request against data that is also subject to a legal hold, and write down the reasoning. That written reasoning is often what a regulator wants to see more than a perfect technical outcome.
Securing Teams and Outlook communications
Day to day, most personal information moves through email and chat rather than a formal system of record. A few controls carry disproportionate weight:
- Sensitivity labels applied to documents containing personal information, with encryption on the labels that need it
- Data loss prevention policies that warn or block when personal information leaves the tenant by email
- Phishing-resistant multi-factor authentication and Conditional Access, since a compromised mailbox is a confidentiality incident by default
- Retention policies that actually delete, so old personal information stops being your liability
Start the DLP work in warn mode. Policies deployed straight to block generate an immediate flood of exceptions and get switched off within a week.
Auditing and documenting your compliance
Law 25 requires accountability, which in practice means being able to show your work. Maintain a short set of living documents: your personal information inventory, your privacy policy, the roles of your privacy officer, your incident register, and a record of the technical controls you have enabled and why.
This does not need to be elaborate. A well-kept twelve-page document beats an unmaintained compliance platform, and it is what gets requested when something goes wrong. Our cybersecurity team helps Quebec organizations map Microsoft controls to specific Law 25 obligations so the documentation reflects the tenant as configured.
Training and awareness
The controls above fail quietly if staff route around them. Short, specific training beats an annual policy acknowledgement: how to recognize personal information, when to use a sensitivity label, what to do in the first hour of a suspected incident, and who to call.
For the incident side specifically, walk your team through the 72-hour breach response sequence before you need it. And if you want to know what an inspection actually looks like, we covered CAI enforcement patterns separately.
FAQ
Does Law 25 apply to a business with only ten employees?
Yes. Law 25 applies based on whether you hold personal information about Quebec residents, not on headcount or revenue. Smaller organizations have the same core obligations, though what counts as reasonable security scales with your size and the sensitivity of the data.
Do we need Microsoft 365 E5 to comply with Law 25?
No. Business Premium covers the controls most SMBs need, including sensitivity labels, DLP, Conditional Access, and audit logging. E5 adds depth in areas like advanced eDiscovery and insider risk, which matter more at larger scale or higher sensitivity.
Is storing data in Canada required by Law 25?
Not outright. Law 25 requires a privacy impact assessment before transferring personal information outside Quebec and reasonable assurance of equivalent protection. Canadian data residency simplifies that assessment considerably, which is why many Quebec organizations choose it.
How long do we have to report a confidentiality incident?
You must notify the CAI and affected individuals with diligence once an incident presenting a risk of serious injury is confirmed. In practice that means your assessment process has to be quick, which is why the audit logging and detection work matters before anything happens.
Who should be our privacy officer?
By default the obligation falls to the person with the highest authority in the organization, though it can be delegated in writing. For most SMBs it lands with an owner, a director of operations, or a finance lead, supported by whoever manages IT.
If you would like a straight answer on where your tenant currently stands, our fixed-scope IT assessment reviews your Microsoft 365 configuration against Law 25 expectations and returns a prioritized list rather than a compliance lecture.
Related Articles
Law 25 Enforcement in 2026: Ready for a CAI Inspection?
Law 25 enforcement is ramping up in 2026. Learn how to map each obligation to concrete Microsoft 365 controls before a CAI inspection lands.
Law 25 Breach Notification: Your First 72 Hours, Step by Step
Learn how Law 25 breach notification works: contain fast, assess serious injury, notify the CAI and keep your incident register the right way.

Essential M365 Conditional Access Policies Every SMB Should Implement
Secure your business with essential M365 Conditional Access policies. Step-by-step guide for SMBs with practical tips and implementation strategies.