Law 25: the checklist for Québec notary practices.
Law 25 applies to Québec notary practices like any business holding personal information. This guide sums up your concrete obligations — designated privacy officer, published policies, assessments, incidents, transfers outside Québec — and the questions to ask your software vendors. For information only: for your specific situation, consult your legal adviser.
The ATOM Solutions team · July 19, 2026 · 11 min read
Law 25 in two minutes
Law 25 thoroughly modernizes the Act respecting the protection of personal information in the private sector (RLRQ c. P-39.1), the statute governing how Québec businesses collect, use, retain, disclose and destroy personal information. Its provisions came into force in stages between 2022 and 2024 — the regime is now fully applicable.
A notary practice holds personal information in abundance: clients' identity and civil status, supporting documents, patrimonial and financial situation, sometimes voice data. It is therefore covered like any other business, on top of its professional obligations and professional secrecy, which remain intact. Non-compliance exposes the practice to measures by the Commission d'accès à l'information and to potentially significant administrative monetary penalties — not to mention the damage to client trust.
Your obligations, in practice
Seven work streams, anchored in the private-sector act as modernized by Law 25. The numbers refer to sections of that act.
A designated privacy officer (s. 3.1)
By default, this is the person with the highest authority — in practice, often the notary-owner or a partner. The role may be delegated in writing; the officer's title and contact details must be published, generally on the practice's website.
Published governance policies (s. 3.2)
The practice must adopt governance policies and practices for the protection of personal information and publish them in clear, simple terms — generally on its website: roles and responsibilities, complaint-handling process, access controls.
Privacy impact assessments (s. 3.3)
Before certain projects — notably acquiring or overhauling an information system involving personal information — an assessment (PIA) is required. Adopting new management or AI software is a typical case; the assessment must be proportionate to the sensitivity of the data.
An incident register and notifications (s. 3.5 and following)
Every confidentiality incident must be logged in a register. Where it presents a risk of serious injury, you must notify the Commission d'accès à l'information and the affected persons, and take reasonable measures to limit the consequences.
Transparency at collection (s. 8)
The person must be informed, at the time of collection, of the purposes and means, among other things, and of the possibility that their information may be disclosed outside Québec. A clear privacy notice — at the practice and on the client portal — does the work.
An assessment before any disclosure outside Québec (s. 17)
Before disclosing personal information outside Québec — for instance to a foreign host or AI provider — the practice must carry out a prior assessment and ensure the information will receive adequate protection.
Destruction or anonymization (s. 23)
Once the purposes are fulfilled, personal information must be destroyed or anonymized, subject to retention periods set by law and to your professional duties to preserve acts and records.
Mapping your personal information
The first concrete step: inventory what the practice holds, where, why and for how long. In a notary practice, five reservoirs usually dominate.
Client files
Acts, draft acts, supporting documents and correspondence: the core of the practice. They hold clients' identity, civil status and patrimonial and financial situation — information that is sensitive by nature.
Identity documents
Copies of passports, driver's licences and other documents collected to verify the parties' identity. Keep as few as possible, with restricted access and a thought-out retention period.
Voice data
Dictations and audio recordings may contain personal information. Local transcription, where the audio is discarded after transcription, markedly reduces exposure.
Email metadata
Senders, recipients, subjects and dates reveal a file's relationships and timeline. Even without reading message content, metadata-only triage belongs in your inventory.
Client portal data
Documents uploaded and information submitted by clients through a secure portal. Magic-link access, with no password to manage, reduces the exposure surface.
Questions to ask any software vendor
Software that processes your files becomes a link in your compliance chain. Before signing, ask these questions — and get the answers in writing.
| Question | Why it matters |
|---|---|
| Where is the data hosted? | Disclosing personal information outside Québec requires a prior assessment (s. 17); hosting in Canada greatly simplifies that analysis. |
| Does the AI provider retain data? | Every retention extends the information's lifecycle; a zero-retention AI gateway reduces it to a minimum. |
| Is the data encrypted? | The law requires security measures proportionate to the sensitivity of the information; encryption in transit and at rest is the baseline. |
| Is there an audit trail? | Knowing who accessed what, and when, is essential to manage an incident and keep the register (s. 3.5 and following). |
| Is data isolated between customers? | Strict per-practice isolation prevents any leak from one file to another of the vendor's customers. |
| Is the mandate covered by a written agreement? | It spells out roles, security measures and what happens to the data when the contract ends — ask for it before any trial. |
How NotarIA fits into your compliance
No software makes you compliant on its own: compliance also depends on the practice's own ways of working — training, access, procedures. Here is what NotarIA contributes, point by point — facts you can verify during a demo.
Data residency in Montréal
Data is hosted in Canada (Montréal) and never leaves the country, which greatly simplifies the analysis required by s. 17.
Zero-retention AI gateway
The AI runs through Vertex AI (Gemini) in a Canadian region; no client data is retained by the AI provider.
End-to-end encryption
Data is encrypted in transit and at rest.
Immutable audit trail
Every access, generation or approval is logged in a hash-chained, verifiable trail — concrete help for keeping the incident register.
Strict per-practice isolation
PostgreSQL Row-Level Security ensures that no query ever crosses a practice's boundary.
Microsoft Entra identity, self-hosted dictation
Single sign-on (SSO) and MFA to reduce unauthorized access; dictation and OCR are self-hosted, and audio is discarded after transcription.
Frequently asked questions
Does Law 25 apply to notary practices?
Yes. The private-sector act, as modernized by Law 25, covers any business holding personal information, including a notary practice. Your professional obligations and professional secrecy come on top and remain intact. For information only: for how this applies to your situation, consult your legal adviser.
Can I use an AI tool hosted in the United States?
It is not prohibited as such, but it is regulated: disclosing personal information outside Québec requires a prior assessment (s. 17) and assurance of adequate protection. In practice, many practices prefer hosting in Canada, which simplifies that analysis. Assess case by case.
Is there such a thing as ‘Law 25 certification'?
No. The law provides for no official certification. Beware of labels: ask for the facts instead — hosting location, AI-provider retention, encryption, audit trail, customer isolation — and get them confirmed in writing.
Who should be the privacy officer?
By default, the person with the highest authority in the business (s. 3.1) — generally the notary-owner or a partner. The role may be delegated in writing to any person; the officer's title and contact details must be published, for example on the practice's website.
A security-focused demo?
We gladly walk through the residency and audit architecture, point by point.
Assistant — not legal advice. The notary reviews, signs and decides on every act.