Home/ Blog/ Law 25 one year on
Blog · Canadian compliance

Law 25 one year on: the five gaps Quebec organizations are still missing

Full enforcement has been in effect since September 2023, and the CAI has issued its first enforcement actions. Here are the five most common Law 25 gaps we find in new customer assessments — and how to close them.

Canadian compliance · Published Mar 24, 2026 · 8 min read

Quebec’s Law 25 has now been fully in force for over two years. The early scramble to publish a privacy policy and stand up a consent banner is well behind most organizations. What we still see, walking into new customer assessments, is not a lack of effort — it is a set of specific, recurring gaps that surface once you look past the visible parts of a compliance program and into how it actually operates day to day.

1. A Records of Processing Activities register that stops being maintained

Almost every organization we assess built a ROPA register at some point — usually as part of an initial Law 25 project. Far fewer keep it current. New data flows, new vendors, new internal systems get added to the business without anyone updating the register that is supposed to describe them. By the time the CAI or an auditor asks for it, the register describes an organization that no longer quite exists. A static document reviewed annually is not a register — it is a snapshot with an expiry date nobody tracks.

2. Privacy Impact Assessments triggered too late, or not at all

Law 25 requires an EFVP — a Privacy Impact Assessment — before launching a new project involving personal information, not after. In practice, we regularly find PIAs completed retroactively, once a project is already in production, because no one on the project team knew to trigger one at the start. The gap is rarely a lack of a PIA template. It is the absence of a workflow that catches new projects early enough for the assessment to actually influence design decisions rather than document a system that already shipped.

3. Breach notification playbooks that were never rehearsed

Every organization we meet has a documented breach notification procedure covering the 72-hour CAI notification requirement. Far fewer have actually walked through it against a realistic scenario. The gap shows up in the details that only surface under pressure: who has authority to declare an incident meets the "serious injury" threshold, how severity scoring actually gets applied at 2 a.m., and whether the people named in the playbook still work there. A procedure that has never been rehearsed is a procedure you are testing for the first time during an actual incident.

4. Consent records that cannot be tied back to a specific purpose

Cookie banners and consent capture are usually in place. What is frequently missing is the link between a specific consent event and the specific processing purpose it authorizes. When a data subject request comes in asking what they consented to and why, organizations often can produce a timestamp and a category, but not a clear record of exactly what purpose that consent covered — which makes it difficult to demonstrate that processing has stayed within the bounds of what was actually agreed to.

5. A PIPEDA crosswalk that exists in someone’s head, not in the program

Most Quebec private-sector organizations are subject to both Law 25 and the federal PIPEDA, and increasingly need to track the proposed Consumer Privacy Protection Act under Bill C-27 as well. In practice, the mapping between these regimes usually lives in the experience of one privacy officer rather than in documented control mappings the rest of the organization can rely on. That works fine until the person who understands the crosswalk leaves, or the organization needs to demonstrate to the CAI exactly how a given control satisfies both frameworks at once.

The common thread

None of these five gaps come from a lack of an initial Law 25 project. They come from compliance artifacts — registers, assessments, playbooks, consent records, crosswalks — that were built once and left to age instead of being maintained as living parts of the business. A point-in-time compliance project produces a point-in-time register. Continuous compliance requires the register, the workflows, and the evidence to update themselves as the business changes.

These patterns reflect common findings across Law 25 assessments generally and are not statistics from a specific study — treat them as a starting checklist for your own program review, not a benchmark.

How Sentrix helps

Sentrix automates the ROPA register, EFVP workflows, breach notification, consent management, and PIPEDA crosswalk described above as one continuously maintained program. See the full Law 25 framework page for how each piece works.

See your Law 25 program mapped end to end.

We walk through ROPA, EFVP, and breach notification live in the demo.