Privacy policy vs privacy program: What Law 25 actually requires
A privacy policy is a document. A privacy program is a habit. Law 25 wants the habit. Here's what that costs a nine-person business.
Yes, you can have a privacy policy and still be breaking Quebec's privacy law. A policy is a page on your website. A program is what your business actually does with people's data every day. Law 25 cares about the second thing, not the first.
This trips up a lot of small businesses, especially ones that just bought an AI tool or a template pack and figured that closed the loop. It doesn't. Here's what the law actually wants, and what it costs to get there.
What's the difference between a policy and a program?
A privacy policy is a promise. It says what data you collect and why, usually in a few paragraphs near your website's footer.
A privacy program is the machinery behind that promise. It answers questions like who can see customer data, how long you keep it, what happens if a laptop gets stolen, and who's accountable when a customer asks you to delete their file.
Quebec's privacy law, known as Law 25, was built around the second idea. The policy is just the public summary of a program that's supposed to already exist.
Does this apply to my business?
If you collect personal information from people in Quebec, Law 25 applies to you. Names, emails, addresses, purchase history all count. Size doesn't exempt you. Neither does being based outside Quebec, if you serve customers there.
The federal law, PIPEDA (the Personal Information Protection and Electronic Documents Act), covers the rest of the country in a similar way. Most provinces without their own private-sector law default to PIPEDA. A nine-person company in Halifax selling to clients in Montreal answers to both.
One wrinkle people miss: if you use a payroll processor, a bank, or a booking platform that only handles data inside its own walled system, you're still on the hook. The law follows the data, not the software. Handing information to a vendor doesn't hand off the obligation. You can outsource the storage. You cannot outsource the responsibility.
What does Law 25 actually require, in practice?
Strip out the legal language and it comes down to a short list of habits.
- Name someone responsible for privacy in your organization — it can be the owner, and it doesn't need a title
- Know what personal data you hold and where it's stored
- Get real consent before collecting or sharing that data, and make it easy to say no
- Have a plan for what happens if there's a breach, including telling affected people
- Be able to delete or hand over someone's data if they ask
None of this requires a lawyer on staff. It requires someone in the business owning the answer, and writing it down once. A privacy policy costs nothing to write. A privacy program costs about a day of someone's time to set up properly, and almost nothing after that.
What that day actually looks like: an hour listing every place data enters your business — website forms, invoices, email, chat tools. An hour deciding who can see what, which for nine people is usually "everyone" plus a note about who handles deletion requests. An hour writing a one-page breach plan: who calls the customer, who calls the regulator, how fast. The rest is writing it down somewhere your future self can find it. Skip a step and the gap doesn't show up until something goes wrong and you're rebuilding the answer under pressure, with a regulator's clock already running.
What does ignoring this actually cost?
Quebec's privacy regulator can fine organizations up to $10 million or 2% of worldwide revenue for serious violations, whichever is higher. Most small business cases don't reach that ceiling, but the number exists to make a point. This isn't a rounding-error fine.
More common, and more expensive in a quiet way, is the breach itself. A leaked customer list, a lost laptop, an email sent to the wrong list: each one triggers a notification requirement, and each notification is a moment your customers decide whether they still trust you. That cost doesn't show up on an invoice. It shows up six months later in your churn numbers.
A fair objection here: "We're nine people, nobody's coming after us." Maybe not proactively. But the regulator often shows up after a complaint, not a sweep — a former employee, an angry customer, a competitor. At that point the size of your business doesn't matter. What matters is whether you can show you had a plan before the complaint landed, not one written the week after.
Compare that to the setup cost of doing it right. A few hours naming your privacy lead, mapping what data you hold, and picking tools that don't quietly send your customer data somewhere you didn't agree to. That's the trade being made here.
Where does a Canadian AI tool fit into this?
This is where a lot of small businesses get caught without meaning to. You sign up for a US-based AI chat tool to draft emails or summarize documents. Your customer data, names, contract details, health information, whatever you pasted in, is now sitting with a provider governed by US law, not Canadian law.
That's not automatically illegal. But it complicates your Law 25 obligations, because the law expects you to know where personal data goes and to explain that if asked. A Canadian AI platform makes that mapping simpler by keeping data closer to where your other business records already live.
Augure is one of these. It's a Canadian company with no US corporate parent, storing customer data in Canada. AI inference for customer conversations and documents runs on Canadian infrastructure and with vetted EU partners under zero-data-retention terms, never on US-based providers, so that content sits outside the reach of US authorities under the CLOUD Act. Payment processing and email delivery do involve some US infrastructure, and that's documented in the privacy policy rather than buried. For a business trying to keep its data map simple, that's a meaningfully shorter list of places to worry about.
Augure starts free: 50 messages a day, five documents, no credit card. The paid tier is C$20 a month if you need more room, and it doesn't erase your Law 25 obligations. Nothing does that. It just means one fewer vendor to explain to a regulator someday. You can look at what it stores and where at augureai.ca.
What to do this week
Name one person as your privacy lead. It can be you. Write their name and role in a single sentence and keep it somewhere findable. That's the requirement, not a job posting.
List where customer data actually lives. Your CRM, your inbox, your invoicing tool, any AI chat tool you've pasted client info into. Ten minutes, one spreadsheet tab.
Check your current AI and cloud tools for where data is processed. If it's a US tool and you handle sensitive client information, weigh whether a Canadian AI platform like Augure makes that conversation with a regulator, or a customer, shorter and cleaner.
Where this comes from: Law 25 sets fines up to $10 million or 2% of worldwide revenue for serious violations.
About Augure
Augure is a sovereign AI platform for regulated Canadian organizations. Chat, knowledge base, and compliance tools — all running on Canadian infrastructure.
More insights
View all →PIPEDA in plain language: what Canadian business owners actually owe their customers
What a privacy breach actually costs a small Canadian business
The Consent Question Small Businesses Keep Getting Wrong
Put this to work: Augure Chat, Canadian-hosted AI →