Quebec's Law 25 (An Act to modernize legislative provisions as regards the protection of personal information) came fully into force in September 2024. If you collect personal information about your clients — and if you use a CRM, you necessarily do — you have serious legal obligations. Fines can reach 25 million dollars or 4% of worldwide revenue. This isn't a file to take lightly.
What Law 25 requires of your business
In short, Law 25 requires you to: appoint a person responsible for the protection of personal information, keep an up-to-date privacy policy, obtain consent before collecting information, inform clients how their data is used, let clients access and correct their data, and report any security incident within 72 hours.
The impact on your CRM
Your CRM is where you store most of your clients' personal information: names, emails, phone numbers, addresses, purchase history, conversation notes. If your CRM isn't compliant with Law 25, your whole business is in violation. The first question to ask: where is the data stored?
The problem of undocumented out-of-Quebec transfers
Law 25 does NOT forbid you from transferring data outside Quebec. It requires you to carry out a privacy impact assessment (PIA) that shows the destination territory offers an equivalent level of protection. If your CRM transfers data abroad without a documented PIA, you're the one in violation — not the CRM. Most American CRMs (GoHighLevel, Salesforce, HubSpot) leave you to handle that obligation on your own.
How toncrm.io is compliant
toncrm.io completed its privacy impact assessment (PIA) on July 3, 2026 for out-of-Quebec communications, available on request at privacy@toncrm.io. Encryption is applied in transit (TLS 1.2+), sensitive secrets (email connection tokens, telephony credentials) are encrypted, and off-site backups are encrypted; generalized encryption at rest is being rolled out. Two-factor authentication is available for all users. The audit log traces every access, change, and deletion of data. The complete list of subprocessors and their locations is in our privacy policy.
Consent management
toncrm.io tracks each contact's consent: when and how consent was obtained, for what purpose, and whether it was withdrawn. When a client exercises their right to withdraw, the system marks the contact as inactive and stops automated communications. It's handled natively, not with a plugin.
Right of access and rectification
When a client asks to see their data (which is their right), you can generate a complete report of all the information held in toncrm.io in a few clicks. If corrections are needed, they're applied and traced in the audit log.
Incident response plan
In case of a security incident (data breach, unauthorized access), Law 25 requires notification within 72 hours. toncrm.io offers detection and response tools: suspicious-access alerts, instant account freeze, and a notification template that complies with the law.
The mistakes to avoid
The most common mistake: thinking Law 25 doesn't apply to small businesses. It applies to any business that collects personal information in Quebec, regardless of size. The other mistake: using American tools while assuming no one will check. Quebec's Commission d'accès à l'information (CAI) has the powers and resources to investigate.
Compliance with Law 25 isn't optional. If you use a CRM with data hosted in the United States, it's time to assess your risks. toncrm.io is built for Quebec compliance from the ground up. Combine that with our GST/QST invoicing and you have a tool fully adapted to the legal reality here.