
Quebec's Law 25: What Every Financial Advisor Needs to Know in 2026
Law 25 modernizes personal information protection in Quebec. Here's what financial advisors, brokers, and firms need to understand to stay compliant in 2026.
Insights on compliant communications, fintech innovation, and AI in Canadian financial services.

Law 25 modernizes personal information protection in Quebec. Here's what financial advisors, brokers, and firms need to understand to stay compliant in 2026.

$10M or 2% of global revenue: how does the penalty calculation work under Quebec's Law 25? Three enforcement paths, concrete examples for a financial firm, and the risk that SMBs underestimate.

Checklist of the 7 Law 25 obligations for financial services firms in Quebec: privacy officer, incident register, notification, PIA, consent, portability. All in force.

Practical guide for financial firms: how to respond to a confidentiality incident under Law 25. Risk assessment, CAI notification, individual notices, and register documentation.

Detailed comparison between Quebec's Law 25 and the European GDPR: direct borrowings, Quebec additions, fine mechanisms, repeat offenses, private right of action. What it means for your firm.

Practical guide to conducting a PIA under Quebec's Law 25. When it's mandatory, what to include, the special case of transfers outside Quebec, and a simplified template for financial firms.

Section 93.1 of Law 25 grants a minimum of $1,000 per person in punitive damages. For a financial firm with 2,000 clients, exposure exceeds $2M. Here's how this mechanism works.

Your firm is responsible for client data even when a vendor processes it. Here are the 5 evaluation criteria, the certifications that matter, and a 10-question checklist to ask every vendor.

Quebec financial firms must comply with Law 25 and AMF/CIRO requirements simultaneously. Here are the overlaps, the frictions, and how to navigate both frameworks without doubling the work.

AI is already in your financial firm. Here are your obligations under Law 25 (automated decisions, PIAs, consent) and the AMF's 30 practices for responsible AI. A practical guide to staying compliant.

Simple, advanced, AATL: not all electronic signatures are equal. PDF vs PDF/A, why printing an AATL document destroys the signature, and what financial firms should demand.