← Back to Insights
Compliance Education

Law 25 penalties: will a C$25M fine actually hit a nine-person business?

Quebec's Law 25 caps fines at C$25M, but small firms rarely see that number. Here's what real enforcement looks like and how to lower your risk.

By Augure·
person wearing suit reading business newspaper

Quebec's Law 25 lets regulators fine a company up to C$25 million, or 4% of worldwide revenue, whichever is higher. That number is real. It is also almost never the number that lands on a nine-person business. This is about the gap between the maximum and what actually happens to firms your size.

What is Law 25, in one sentence?

Law 25 is Quebec's privacy law. It applies to any organization that collects personal information from people in Quebec, no matter where the company is based. If you have one customer or one employee in Quebec, it applies to you. It has been rolling out since 2022, with the last major requirements arriving in September 2024.

Does the C$25 million maximum apply to me?

No. That ceiling exists for the largest violations by the largest companies, think data brokers, national retailers, telecoms. Quebec's privacy regulator sets penalties based on the size of the organization and the severity of the breach. A small business that mishandles a customer list is not treated like a national bank that loses millions of records.

Real penalty amounts against small and mid-sized organizations in Quebec have run from a few thousand dollars up to the low tens of thousands. Painful, yes. Business-ending, rarely.

The number that should worry you isn't the maximum fine. It's the cost of a breach notification process, legal advice, and the customers who leave once they find out you had no basic protections in place.

What actually gets a small business in trouble?

Investigations rarely start with regulators knocking on doors. They start with a complaint, or a breach you're legally required to report.

Here's what tends to trigger action:

  • A customer asks what data you hold on them and you can't answer.
  • An employee's personal information leaks in a phishing incident and you don't report it in time.
  • A former client complains that you shared their data with a third party without telling them.
  • You had no privacy policy at all when someone asked to see one.

None of these require you to be a big company. They just require you to be caught flat-footed.

A privacy officer costs you nothing but a job title. Not having one is the actual violation. Law 25 requires every organization, no matter how small, to name someone responsible for privacy. It doesn't have to be a lawyer. It can be the owner, the office manager, whoever already handles customer questions. The requirement is that someone is named and reachable, not that you hire a specialist.

What does compliance actually cost?

Less than most owners assume. The expensive path is hiring a privacy consultant or lawyer to build a full program from scratch, which can run several thousand dollars for a small firm. The cheap path is doing the basics yourself, which costs almost nothing but time.

The basics: know what personal data you collect, write down why you collect it, tell people in plain language, and have a plan for what happens if it leaks. Quebec's privacy law also requires a privacy impact assessment before you start any new project that handles personal data in a new way. That's a bigger deal for a hospital rolling out a new records system than for a shop that starts using a Canadian AI tool to draft emails, but the requirement applies in both cases.

This is where a Canadian AI platform earns its keep, separate from the compliance angle. If you're already using a US chatbot to draft policies or answer customer questions, that data is being handled by a company under US legal reach. Switching to a Canadian platform doesn't erase your Law 25 obligations, nothing does that for you, but it removes one variable from the equation.

Augure is one option built around this problem. It's a Canadian company with no US corporate parent and no US investors, and customer data is stored in Canada, as Canadian privacy rules require. AI inference runs on Canadian infrastructure or with vetted EU partners under zero-data-retention agreements, never in the US, though payment processing and email delivery still involve some US infrastructure, the same as almost any small business tool. Because customer conversations and documents aren't handled by US-jurisdiction providers, the CLOUD Act's reach over those providers doesn't extend to that content. Augure starts free, with a paid tier at C$20 a month if you need more than the daily message limit. For a business drafting its first privacy notice, that's a fraction of what a consultant charges for the same first draft.

What about PIPEDA — do I need to worry about that too?

PIPEDA, the federal privacy law, applies to your business if you're not in Quebec, British Columbia, or Alberta, which each have their own private-sector privacy law. If you operate across provinces, you may need to satisfy more than one law at once. That sounds worse than it is, since the core requirements overlap heavily: tell people what you collect, get consent, protect it, report breaches. Federal regulators have also leaned more toward naming companies publicly than chasing maximum fines against small operators.

The honest takeaway: the laws overlap enough that fixing your practices for one mostly fixes them for the other. Nobody is coming after a nine-person firm for the sport of it. They're coming after firms that ignored a complaint, sat on a breach for weeks, or never wrote anything down.

Where this gets genuinely uncertain, and where even lawyers disagree, is how far these obligations stretch once you start using AI tools trained on customer data, or contractors who handle files from outside the country. That's less a checklist item and more a judgment call, one worth a real conversation with someone who knows your business.

What to do this week

  1. Name a privacy contact. Pick one person, even yourself, and write their name down as the one who answers privacy questions. Takes ten minutes.
  2. List what personal data you actually hold. Customer names, emails, payment info, employee records. A spreadsheet is fine. This is the single most-checked item in any investigation.
  3. Write one page in plain language explaining what you collect and why, and put it somewhere customers can find it. Use a Canadian AI tool to draft it if writing isn't your thing. Augure's free tier can produce a first draft in minutes, and you edit from there.

Start at augureai.ca.

Where this comes from: Law 25's administrative monetary penalties are set at up to C$25 million or 4% of worldwide turnover.

A

About Augure

Augure is a sovereign AI platform for regulated Canadian organizations. Chat, knowledge base, and compliance tools — all running on Canadian infrastructure.

Ready to try sovereign AI?

Start free. No credit card required.

Get Started