Law 25 for accountants: what you need to do

Quebec's Law 25 raises the bar for protecting client information. Here is what accountants actually need to do, in plain language, without the legalese.

If you are an accountant in Quebec, Law 25 applies to you. It can also reach beyond the province: the Commission d'accès à l'information's guidance is that an organization outside Quebec is subject to the law when it handles personal information in the course of business activities in Quebec, so serving Quebec clients may bring your practice into scope. The law governs how any business handling personal information must protect it, and it has real teeth. But you do not need a law degree to get the gist. Here is what it means in practice.

What Law 25 asks of you

At its core the law says that if you collect and hold people's personal information, you are responsible for protecting it with appropriate security measures, being transparent about how you handle it, and handling confidentiality incidents properly when something goes wrong.

For an accountant the relevant obligations land in a few concrete places. You should protect client data with real safeguards, and encryption and access controls are explicitly the kinds of measures regulators point to. You need to record and assess every confidentiality incident, and notify the Commission d'accès à l'information and affected clients when an incident presents a risk of serious injury. And you should know where client data lives and which laws govern it.

Why it matters more than the old rules

The penalties changed the calculus. Administrative monetary penalties under Law 25 reach up to $10 million or 2% of worldwide turnover, whichever is greater, and penal sanctions climb to $25 million or 4% for serious violations. Even setting the headline numbers aside, a breach that exposes client SINs and financial data is the kind of reputational event a small firm does not recover from easily.

What this looks like day to day

You do not have to overhaul your practice. In practice, compliance-minded document handling means a few habits:

  • Encrypt sensitive files, ideally before they leave your device, so no third party, including your software vendor, can read them.
  • Control access with expiry, revocation, and limits on who can open what.
  • Know where your data lives. Keeping it in Canada, under Canadian law, is not a Law 25 requirement, but it simplifies the assessment the law asks for when information leaves Quebec.
  • Be able to show your work, that you used appropriate measures, not just good intentions.

How Privatt fits

Privatt is Canadian-owned, and Privatt-hosted storage keeps files on Canadian servers under Canadian law; if you connect your own Google Drive or OneDrive instead, residency follows your provider. Send and the Vault modes where you hold the keys encrypt on your device before anything is stored or sent, and you get expiry and revocation controls out of the box. It will not make you compliant on its own, because no tool does, but it is exactly the kind of appropriate security measure the law is asking for, and it removes the riskiest habit most firms still have, which is sending client data by plain email.

This article is general information, not legal advice. Consult a qualified professional about your specific obligations.