GetSOC2

SOC 2 and Quebec Law 25

A SOC 2 report and Law 25 compliance are different things bought for different reasons. The report is evidence you gave a customer. Law 25 is a statute that applies to you whether or not anyone ever asks for a report, and it carries penalties the audit cannot protect you from.

Last reviewed 2026-09-01Written by Jacob Masse, TrazTech Inc.

No, a SOC 2 report does not make you compliant with Quebec's Law 25, and holding one is not a defence if the Commission d'acces a l'information opens a file on you. The report is an opinion from a CPA firm that the controls you described operated as described. Law 25 is legislation with named duties, fixed deadlines that have already passed, and administrative monetary penalties reaching $10 million CAD or two percent of worldwide turnover, with penal fines reaching $25 million CAD or four percent. There is no overlap in the enforcement mechanism.

The overlap that does exist is in the work. Roughly half of what Law 25 asks for is control work you are already doing for the Security criteria, so do it once for both. The other half is governance and record-keeping that no Trust Services criterion asks about, and that is the half companies discover late.

$25M CAD Top penal fine under Law 25, or 4% of worldwide turnover

7 of 10 Law 25 duties a SOC 2 examination does not touch at all

Does Law 25 apply to us if we are not in Quebec?

Probably, if you have Quebec customers or Quebec employees. Law 25 amends Quebec's Act respecting the protection of personal information in the private sector, and that Act applies to an enterprise that collects, holds, uses or communicates personal information about a person in Quebec. It is not written around where your office is. A Toronto or Vancouver SaaS company with three hundred Quebec end users is inside it, and so is one with a single Quebec-based employee whose HR records you keep.

This catches people out because PIPEDA behaves differently. PIPEDA is federal and applies to commercial activity across most of the country, but Quebec's provincial law has been declared substantially similar, which means for provincially regulated activity in Quebec, the Quebec statute displaces PIPEDA rather than stacking on top of it. Alberta and British Columbia have their own substantially similar statutes as well. Quebec's is the strictest of the three by a wide margin.

Which Law 25 duties does a SOC 2 report actually evidence?

Enough to be worth the mapping exercise, and nowhere near all of it. The right column is the part that matters. That work will not appear in your audit, and it will not appear on your readiness consultant's gap list unless you ask.

Law 25 duties against what a SOC 2 examination evidences
Law 25 dutyCovered by SOC 2?What is left for you
Security safeguards proportionate to sensitivityLargely, through the Security criteriaShow the safeguards are proportionate to the sensitivity of the data, not just present. The audit tests presence
Named person in charge of protection of personal informationNoAppoint one, publish the title and contact details on your website. The default holder is the person with the highest authority in the enterprise until you delegate in writing
Confidentiality incident registerNoKeep a register of every confidentiality incident, including ones you assessed as low risk and did not report
Reporting incidents of serious injury risk to the CAI and to affected peoplePartly. The audit tests that you have an incident processThe statutory trigger, the assessment of serious injury risk, and the notice wording are yours
Privacy impact assessment before a new system or a transfer outside QuebecNoRun and document one. This is the single most commonly missed duty
Governance policies for personal information, publishedNoWrite them, approve them, publish them in clear and simple language
Privacy by default on any product offered to the publicNoHighest privacy settings on by default, without the user having to act
Data portability on requestNoBe able to hand a person their computerised personal information in a structured, commonly used technological format
Consent, and separate consent for sensitive informationNoYour consent flows, in the product
Retention and destruction when the purpose is fulfilledPartly, if you scoped it inA retention schedule that names a period per data category

SOC 2 tests whether the machinery runs. Law 25 asks who is accountable, what you decided before you built the thing, and whether you can prove the decision. Those are governance artefacts, and an auditor does not ask for them because no Trust Services criterion mentions them.

Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.

Should we add the Privacy criteria to deal with this?

Usually not. The Privacy category tests whether you keep the commitments in your own privacy notice. If your notice is thin, Privacy tests a thin promise and passes. It adds roughly a quarter to your examination fee and it does not test a single Law 25 duty from the right column above.

Include Privacy when a customer named it in writing, or when personal information is the actual product rather than a by-product. Do not include it because a lawyer said the word privacy. Do the Law 25 work first, then decide about the Privacy criteria on commercial grounds.

The transfer assessment is the one that bites

Before communicating personal information outside Quebec, you must conduct a privacy impact assessment that considers the sensitivity of the information, the purposes, the protections it would receive, and the legal framework of the destination. For a Canadian SaaS company hosting in us-east-1, that is a transfer, and it needs an assessment on file. The assessment is a document, not a checkbox, and it is exactly what a Quebec enterprise buyer will ask for in their vendor review. Your subservice organisations are in scope for it too.

What to do first, in order

If you are running a SOC 2 project and Law 25 has just landed on your desk, do not run them as two projects. Run one control set and two evidence destinations.

  1. Name the person in charge of the protection of personal information, in writing, with a date. It takes an hour and it is the first thing anyone asks for.
  2. Publish that name and contact route on your website, along with your governance policies in language a customer can read. Quebec is specific about the plain language part.
  3. Build a data inventory: what personal information you hold, where it physically sits, who it goes to, and why. Your SOC 2 system description needs most of this anyway, which is why doing it once is worth the effort.
  4. Run the transfer assessment for every jurisdiction on that inventory. If everything is in a US region, that is one assessment, not twenty.
  5. Open a confidentiality incident register, even if it is empty. An empty register with a start date is evidence. A register created after an incident is not.
  6. Write a retention schedule with a period per category, then make it true in the product. This is the one that takes engineering time, so start it early.
  7. Only then decide whether the SOC 2 Privacy criteria are worth buying.

The terms Quebec uses that nobody else does

Confidentiality incident
Quebec's term for unauthorised access, use, communication, or loss of personal information. Broader than most breach definitions, because loss of access counts.
Risk of serious injury
The threshold that turns an incident into a reportable one. You assess sensitivity, apprehended consequences, and the likelihood of misuse. There is no headcount trigger.
Person in charge of the protection of personal information
The statutory role. Defaults to the person with the highest authority in the enterprise unless delegated in writing to someone else.
CAI
The Commission d'acces a l'information du Quebec, the regulator. It has order-making power and can impose administrative monetary penalties.

The case for not doing any of this yet

Enforcement against small Canadian SaaS companies has been sparse, the CAI has finite investigators, and the headline penalty figures are statutory maximums that no small enterprise has been anywhere near. If you have four Quebec users and a deal closing on Thursday, spending three weeks on a retention schedule instead of finishing your audit evidence is the wrong call this week.

What makes that argument fail over a longer horizon is not the regulator. It is procurement. Quebec buyers, Quebec public bodies and their suppliers now ask for the transfer assessment and the named person by name in vendor questionnaires, because their own compliance depends on yours. The duty arrives as a sales blocker long before it arrives as an investigation, which is exactly how the SOC 2 report itself arrived on your desk.

Get quotes from Canadian firms

Firms that run SOC 2 readiness alongside Quebec privacy work are a narrower list than firms that do one or the other.

Get matched
Does a SOC 2 report make us Law 25 compliant?

No. A SOC 2 report is an auditor's opinion on controls you described. Law 25 imposes statutory duties including a named person in charge, privacy impact assessments before transfers outside Quebec, a confidentiality incident register, published governance policies and data portability. None of those are tested by any Trust Services criterion, and the report is not a defence in an enforcement proceeding.

We are an Ontario company. Does Law 25 apply to us?

If you collect, hold, use or communicate personal information about people in Quebec, yes. The statute follows the person, not your head office. A Quebec customer base or a single Quebec employee is enough to bring you inside it.

Do we need the SOC 2 Privacy criteria to satisfy Law 25?

No, and buying them for that reason is usually wasted money. The Privacy category tests whether you keep the commitments in your own privacy notice. It does not test any of the Law 25 duties that a SOC 2 examination misses. Add Privacy when a customer names it in a contract, not because a statute exists.

Does hosting in a US region breach Law 25?

Not by itself. It triggers a duty. Before communicating personal information outside Quebec you must conduct and document a privacy impact assessment covering the sensitivity of the data, the protections it will receive and the legal framework of the destination. Companies fail on the missing assessment far more often than on the hosting decision itself. Our data residency page works through what is actually required.

How much does Law 25 work add to a SOC 2 budget in Canada?

Expect $8,000 to $25,000 CAD in advisory time if you buy help, mostly for the data inventory, the transfer assessment and the retention schedule. The figure drops sharply if you sequence it alongside SOC 2 readiness rather than after it, because the inventory work is shared. The full cost breakdown covers the audit lines themselves.