HACOEUR  ·  Édition
Cliquez sur un texte pour modifier Admin ↗
Law 25: what it changes for your marketing
Blog/Uncategorized

Law 25: what it changes for your marketing

Quebec Law 25 touches your pixels, your forms and your CRM. What it actually requires, what you really risk, and the five jobs to tackle in order.

Your expert septembre 2026 9 min read

Quebec's Law 25 applies to your business the moment you hold a name, an email address or a phone number — which means very nearly every SMB in the province. For your marketing it changes four concrete things: your advertising pixels can no longer fire before the visitor has consented, every form has to state what the data will be used for, your privacy policy has to be readable by a human being, and somebody at your company has to be named as responsible. Everything else follows from one question: why are you keeping this data?

This is not legal advice — for that, talk to a lawyer. It is a marketing practitioner's reading: what changes in your tools, your forms and your campaigns, and in what order to deal with it when you are an SMB with no legal department. If you are starting from nothing, begin by looking at where compliance actually touches your acquisition rather than by downloading a privacy policy template.

Does Law 25 apply to your business?

Yes, almost certainly. The law covers anyone carrying on an enterprise in Quebec. There is no size threshold, no revenue threshold, no exemption for small operations. A general contractor with eight employees is covered exactly as a retail chain is. No-profits too.

Two frequent misunderstandings are worth clearing up. The first: we are B2B, we do not collect personal data. Wrong. Marie Tremblay, purchasing director, is still a natural person; her work email, her mobile number and the notes your salesperson took about her are personal information. The second: our servers are in the United States, so this does not concern us. Also wrong. It is where you carry on business that triggers the law, not where the database sleeps.

Three dates, all of them behind you

The law came into force in stages. September 2022 brought the designation of a person in charge, the privacy incident register and the duty to report breaches. September 2023 brought the heavy part: the new consent rules, transparency, the mandatory privacy policy, and rules around profiling and geolocation. September 2024 completed the picture with the right to data portability.

The practical consequence: there is no transition period left to invoke. Every provision applies, and the Commission d'accès à l'information, which initially took an educational stance, now issues decisions. If your site is still running the cookie banner installed in 2021, you are two years behind.

What valid consent actually means

The law requires consent that is clear, free and informed, given for specific purposes, and requested separately for each purpose. Translated into practice, that rules out four still-common habits. A pre-ticked box is not consent: the person has to take an active step. Consent buried in paragraph 14 of your terms of use is not informed. A single I agree covering the quote request, the newsletter and sharing with partners is not specific — that needs three separate asks. And a cookie banner offering only an Accept button leaves no choice, so it is not free.

Consent is not eternal either: it holds for the stated purpose, and for as long as that purpose requires. If you collected an email address to send a roofing quote in 2019, that is not consent to receive your newsletter in 2026. That specific point deserves separate treatment: see how to obtain valid consent for your newsletter.

A cookie banner offering only Accept is not consent. It is a door with no handle.

Your pixels and your analytics: the real job

This is where the law costs you something. The Meta pixel, Google remarketing tags, session recording tools, behavioural analytics: all of them collect information that identifies or tracks a person, and none of them should fire before the visitor has said yes. A purely informational banner along the lines of by continuing to browse you accept is no longer enough. You need a mechanism that genuinely blocks the scripts from loading until the choice is made, and that lets people refuse as easily as accept.

The effect on your numbers is immediate and you should prepare for it. A significant share of visitors refuse non-essential cookies — often a quarter, sometimes more. Your remarketing audiences shrink, and your conversions are under-reported in the ad platforms. That is not a drop in performance, it is a drop in measurement, and confusing the two leads to killing campaigns that are working. Recalibrate your benchmarks instead of comparing against the before.

The right technical answer is not to work around the banner, it is to legally recover the signal that remains: Google consent mode, server-side tracking and Meta's conversions API rebuild part of the attribution from the visitors who did accept. It is also the moment to check your budget is allocated on data you can still measure properly — our reference points on choosing between Google Ads and Meta Ads still hold, provided you know what your numbers no longer see.

Your forms and your landing pages

Every form has to state, at the point of collection, what the information will be used for, who will have access to it, and how the person can withdraw consent. One sentence under the submit button is enough in most cases: it has to be readable, not hidden behind a grey six-point link. And if you are using the quote form to add the person to your newsletter, that is asked separately, with an empty box.

What to do
Open your main form and count the fields. For each one, answer out loud: what do we actually do with this? A field nobody can explain the use of is a field to remove. You win twice: less data to protect, and a higher completion rate. It is the only compliance job that increases your conversions instead of reducing them.

The three obligations you settle once

Some requirements need no upkeep: you put them in place and only revisit them if something changes. First, designate someone responsible for the protection of personal information. By default that is the person with the highest authority in the business — so the owner, until somebody else is named. The role can be delegated to an employee or an outsider, and the contact details have to be published on the site.

Second, publish a privacy policy in simple, clear terms: what you collect, why, who you share it with, how long you keep it, and how to exercise one's rights. A translated American template does not pass the clarity test. Third, keep a register of privacy incidents and know what to do when one occurs: assess the risk, notify the Commission d'accès à l'information and the people affected if the risk of serious injury exists. That procedure gets written calmly, not on the day of the breach.

And the data living at somebody else's place

Your CRM, your newsletter platform, your booking tool and your agency all hold your customer data. Entrusting the data does not transfer the responsibility: you remain answerable for its protection, its retention period and its destruction. The sorting is done field by field, and it is a shorter exercise than people fear: see which data you can keep in your CRM and which no longer has any reason to be there.

What you actually risk

The numbers going around are spectacular: the Commission d'accès à l'information can impose administrative penalties of up to $10 million or 2 % of worldwide revenue, and penal proceedings can reach $25 million or 4 %. Let us be honest: those ceilings do not describe what awaits a twelve-person SMB. They describe the top of the scale, reserved for serious or repeated failures.

The realistic risk is elsewhere, and it has two heads. A complaint from a former customer or a former employee triggers an investigation, and an investigation is answered with documentation you do not have — weeks of internal work reconstructing what would have taken three hours to set up. And there is the commercial risk, more immediate: prime contractors, institutions and large companies now ask for compliance guarantees in their tenders. Being unable to answer takes you off the list before the price discussion even starts.

Where to start, in order

Five jobs, from the most exposed to the least urgent. One: the cookie banner, because it is public, visible to anyone, and it either does or does not genuinely block your pixels — checkable in thirty seconds. Two: the forms, with the purpose statement and separated consents. Three: the privacy policy and the designation of the person responsible, both settled in half a day. Four: sorting the CRM and the mailing lists. Five: the incident register and the procedure for the day it happens.

Noe of these is technical enough to require a project. What costs money is doing them out of order, or doing them twice because the first pass was handed to a generic template. If you want to know in fifteen minutes which of the five are settled at your place and which are not, book the diagnostic call: we look at your site live, and you leave with the list.

Free diagnostic
Where does YOUR marketing stand?

8 questions, 2 minutes. You get a score out of 100 and your three concrete priorities.

Take the free diagnostic →
or talk to an expert directly →
Read next
Article
Website Speed and Core Web Vitals: What Matters for a Small Business
Article
Site Migration Without Losing Your SEO: The Procedure