Quebec Law 25 applies to every dental clinic in the province. As of September 2024, all three implementation phases are in force, requiring clinics to designate a privacy officer, maintain a confidentiality incident register, conduct privacy impact assessments before implementing new systems or sharing data outside Quebec, and obtain explicit consent for sensitive personal information. Administrative penalties reach $10 million CAD or 2% of worldwide revenue.

What Is Quebec Law 25?

Law 25, formally titled An Act to modernise legislative provisions as regards the protection of personal information, was adopted by Quebec's National Assembly in 2021. It amended the existing Act respecting the protection of personal information in the private sector (chapter P-39.1), which is Quebec's primary private-sector privacy statute. The amendments introduced a phased set of obligations that rolled out from September 2022 through September 2024.

The law is enforced by the Commission d'accès à l'information (CAI), Quebec's independent privacy regulator. The CAI has authority to impose administrative monetary penalties, investigate complaints, conduct audits, and refer matters for penal prosecution. According to the Office of the Privacy Commissioner of Canada, Quebec's Act has been deemed "substantially similar" to Canada's federal privacy law (PIPEDA), meaning Quebec clinics that handle patient information exclusively within the province operate primarily under the provincial regime rather than the federal one.

For context on how Quebec's law compares to the privacy frameworks in other provinces, the provincial privacy laws guide for dental clinics in Alberta, BC, and Quebec provides a side-by-side overview.

Who Must Comply?

The Act applies to any private-sector enterprise that collects, uses, or communicates personal information as part of commercial activity. A dental clinic collects patient names, contact details, health histories, appointment records, billing information, and in many cases biometric data (such as facial photographs or X-rays). All of this constitutes personal information under the Act. Every Quebec dental practice, regardless of size, is therefore subject to Law 25.

There is no small-business exemption. A sole-practitioner clinic with two staff members has the same obligations as a multi-location group practice. The practical difference is one of resources: a large group may appoint a dedicated privacy officer, while a solo practitioner typically designates themselves as the responsible person. Both must meet the same statutory requirements.

Clinics that share patient data outside Quebec, for example by using a practice management system or cloud platform hosted in another province, face an additional layer of complexity. Federal PIPEDA continues to govern personal information that crosses provincial or national borders. Clinics in this situation must satisfy both Law 25 and PIPEDA. A solid grounding in PIPEDA compliance requirements for dental practices is therefore a foundation, not a substitute, for Law 25 readiness.

The Three-Phase Implementation Timeline

Law 25 came into force in three phases. As of September 2024, all three are fully implemented and all obligations are enforceable. Understanding the timeline helps practice owners recognise which requirements have been in place longest and may already be the subject of enforcement activity.

Admin Penalty
$10M
CAD or 2% of worldwide revenue
Penal Sanction
$25M
CAD or 4% of worldwide revenue
Access Window
30 Days
to respond to patient requests
Phase 1
September 2022
  • Rules introduced for communicating personal information without consent in certain commercial transactions
  • Research and statistics disclosure exceptions clarified
  • New obligations for disclosing commercial transactions that involve personal information
Phase 2
September 2023
  • Privacy impact assessments (Évaluation des facteurs relatifs à la vie privée, or EFVP) required before implementing new systems, service projects, or data transfers outside Quebec
  • Enhanced consent: must be manifest, free, informed, and given for a specific purpose
  • Transparency obligations: clinics must disclose collection purposes, means used, individuals' rights, and whether data is sent outside Quebec
  • Privacy by design: default settings in new technology must offer the highest level of protection
  • Privacy policies required whenever personal information is collected via technology
  • Biometric information formally classified as sensitive personal information
  • Mandatory designation of a person responsible for personal information protection
Phase 3
September 22, 2024
  • Data portability rights become enforceable: individuals may request their personal information in a structured, commonly used technological format

Five Core Obligations for Quebec Dental Practices

With all three phases now fully in force, Quebec dental clinic owners must satisfy the following obligations. Each one carries potential enforcement consequences if neglected.

1. Designate a Privacy Officer

Every enterprise subject to Law 25 must designate a person responsible for the protection of personal information. According to the CAI, the person with the highest authority in the organisation (the clinic owner or principal dentist) holds this responsibility by default. The role may be delegated in writing to someone with the competency and decision-making authority to carry it out, but even with delegation, the most senior person remains accountable for compliance.

The privacy officer's title and contact information must be published on the clinic's website or communicated through appropriate alternative means if no website exists. The officer is responsible for approving governance policies, processing patient access and correction requests within 30 days, and overseeing privacy impact assessments.

2. Obtain Valid Consent

Law 25 raised the standard for consent. It must now be manifest, free, informed, and given for a specific, clearly identified purpose. A bundled consent buried in a general intake form is unlikely to meet this standard for sensitive information such as health records. Clinics must seek separate consent for each distinct purpose, and patients must be able to withdraw consent without penalty.

Reviewing your patient consent forms against the Law 25 standard is a sensible starting point. The DentRecall guide on PIPEDA-compliant dental patient consent forms covers the foundational principles that apply across both federal and provincial frameworks. Quebec Law 25 adds the explicit requirement that consent for sensitive personal information be manifestly given, meaning it cannot be inferred from silence or inaction.

3. Post a Privacy Policy for Technology-Based Collection

Whenever a dental clinic collects personal information through technology (online booking forms, patient portals, digital intake forms, or automated SMS reminder systems), a privacy policy is required. The policy must explain what information is collected, why it is collected, how it is used, who receives it, whether it is sent outside Quebec, and how patients can access, correct, or withdraw consent for their data.

If your clinic uses automated SMS or email patient communication tools, reviewing the CASL obligations alongside Law 25 is important. The guide on CASL compliance for dental SMS reminders addresses the federal commercial electronic message rules that layer on top of Law 25 for any outbound patient communications.

4. Conduct Privacy Impact Assessments

Before acquiring or implementing a new technology system, before launching a project that involves the personal information of a significant number of individuals, and before communicating personal information outside Quebec, clinics must conduct a privacy impact assessment (PIA, known in French as an EFVP). The PIA documents the privacy risks associated with the initiative and the measures taken to mitigate them.

For dental practices, the most common PIA trigger is adopting a new practice management system, cloud-based patient communication platform, or billing software. Any of these that process patient data outside Quebec requires a documented PIA before the system goes live.

5. Apply Privacy by Design

Law 25 requires that the default technological settings for any new system or tool offer the highest available level of privacy protection. In practice, this means that when evaluating new software, clinics should confirm that data sharing, analytics, or third-party integrations are disabled by default and must be actively enabled, rather than the reverse. Privacy considerations belong at the procurement stage, not as an afterthought after deployment.

Confidentiality Incidents and Breach Notification

According to the CAI, a confidentiality incident is any unauthorised access to personal information, unauthorised use or communication of personal information, or loss of personal information. In a dental clinic context, this includes a ransomware attack on the clinic's practice management system, a staff member accessing patient records without a legitimate clinical reason, or a paper file being sent to the wrong patient.

Not every incident requires notification. The notification obligation is triggered when the incident presents a serious risk of harm to the individuals whose information was affected. The CAI assesses serious risk by considering the sensitivity of the information involved, the anticipated consequences of the incident, and the probability that the information will be used in a way that causes harm.

When the serious-risk threshold is met, the clinic must notify the CAI and the affected individuals "without delay." Notices to affected individuals must include a description of the personal information involved, a brief account of the incident circumstances, the approximate date or period, the measures the clinic is taking to reduce harm risks, the protective measures individuals can take themselves, and a contact name for enquiries.

Confidentiality Incident Register: What It Must Contain

Clinics must maintain a register of all confidentiality incidents, regardless of whether they trigger the notification obligation. Each entry must record: a description of the personal information involved, the incident circumstances and approximate dates, the number of affected individuals, the elements of the risk assessment, the dates on which the CAI and individuals were notified (if applicable), and the remedial measures implemented. The CAI may request access to this register at any time. Minimum retention period: five years from the date of the incident.

Penalties for Non-Compliance

Law 25 establishes two distinct penalty tracks, and the amounts are among the highest in Canada's private-sector privacy framework. According to the CAI's sanctions guidance for enterprises:

  • Administrative monetary penalties (AMPs): Up to $10 million CAD or 2% of worldwide revenue for the previous fiscal year, whichever is greater. These are imposed directly by the CAI and do not require a court proceeding.
  • Penal sanctions (criminal fines): For enterprises, between $15,000 and $25 million CAD, or up to 4% of worldwide revenue, whichever is greater. Natural persons (including individual dentists prosecuted personally) face fines of $5,000 to $100,000 CAD. Fines double upon recidivism.

The five-year limitation period for penal proceedings runs from the date of the offence. Sentencing courts must consider the severity and repetition of the violation, the sensitivity of the information involved, whether the breach was intentional, and the number of individuals affected.

The AMP track is the more immediate enforcement risk for most practices: the CAI can issue a penalty administratively, without the time and resource demands of a criminal prosecution. A clinic that fails to designate a privacy officer, neglects to notify the CAI of a high-risk incident, or cannot produce a confidentiality incident register on inspection faces AMP exposure.

Ontario and BC Clinic Owners: Your Province Has Different Rules

Quebec Law 25 applies only to Quebec-based dental practices. Ontario dentists are subject to PHIPA, Ontario's health information privacy law, which carries different obligations and penalty structures. British Columbia and Alberta operate under their own substantially similar legislation. The compliance requirements differ materially across provinces, so verify which framework applies before implementing any changes.

Frequently Asked Questions

Does Quebec Law 25 apply to dental clinics?

Yes. Quebec's Law 25 amended the Act respecting the protection of personal information in the private sector, which covers all private-sector organisations that collect, use, or communicate personal information in the course of commercial activity. Dental clinics collect patient names, contact details, health histories, appointment records, and billing information, all of which are personal information under the Act. Every Quebec dental practice is therefore subject to Law 25.

What is the role of the privacy officer under Law 25?

Under Law 25, every private-sector organisation must designate a person responsible for protecting personal information. By default, this is the person with the highest authority, typically the clinic owner or principal dentist, although the role may be delegated in writing. The privacy officer's name and contact information must be published on the clinic's website. The role carries responsibility for approving privacy policies, processing patient access requests within 30 days, and overseeing privacy impact assessments for new systems.

What is a confidentiality incident under Law 25?

A confidentiality incident is any unauthorised access to personal information, unauthorised use or communication of personal information, or loss of personal information. For a dental clinic, this includes events such as a ransomware attack on the clinic's practice management system, an employee accessing patient records without a legitimate purpose, or paper records being sent to the wrong recipient. Not every incident triggers notification to the CAI; only those that present a serious risk of harm to the individuals concerned.

When must a dental clinic notify the CAI of a data breach?

A dental clinic must notify the Commission d'accès à l'information (CAI) and the affected individuals "without delay" when a confidentiality incident presents a serious risk of harm. The CAI assesses serious risk by considering the sensitivity of the information involved, the anticipated consequences, and the probability that the information will be used to cause harm. All incidents, whether or not they meet this threshold, must be recorded in the clinic's confidentiality incident register for a minimum of five years.

What are the penalties for violating Law 25?

Law 25 establishes two penalty tracks. Administrative monetary penalties can reach $10 million CAD or 2% of worldwide revenue, whichever is greater. Penal sanctions for enterprises are higher: between $15,000 and $25 million CAD, or up to 4% of worldwide revenue, whichever is greater. Individual dentists prosecuted personally face fines of $5,000 to $100,000 CAD. Fines double upon recidivism. The Commission d'accès à l'information can issue administrative penalties directly, without a court proceeding.

Is PIPEDA replaced by Law 25 for Quebec dental clinics?

Quebec's Act respecting the protection of personal information in the private sector has been deemed substantially similar to Canada's federal privacy law (PIPEDA) by the Office of the Privacy Commissioner of Canada. For dental clinics that handle patient information exclusively within Quebec, Law 25 generally applies in place of PIPEDA. However, PIPEDA continues to govern personal information that crosses provincial or national borders, such as when clinic data flows through a software platform hosted in another province. Clinics using cloud-based tools must therefore ensure compliance with both frameworks.

Key Takeaways

  • Quebec Law 25 is fully in force as of September 2024. All three implementation phases have completed and every obligation is now enforceable.
  • Every Quebec dental clinic must designate a privacy officer, publish their contact information, and document patient consent in a way that meets the manifest, free, informed, and purpose-specific standard.
  • Privacy impact assessments are required before adopting new software systems or sharing patient data outside Quebec.
  • A confidentiality incident register must be maintained and available to the CAI on request, with a minimum five-year retention period. High-risk incidents require prompt notification to the CAI and affected patients.
  • Administrative penalties reach $10 million CAD or 2% of worldwide revenue. Penal sanctions for enterprises can reach $25 million CAD or 4% of worldwide revenue, and double on recidivism. No clinic is too small to be subject to enforcement.
About DentRecall

DentRecall is an AI-powered dental recall and patient engagement platform built specifically for Canadian clinics. It automates SMS and email reminders, recall management, and patient communication from $99/month (billed annually). All patient data handling is designed around Canadian privacy principles, including PIPEDA and provincial equivalents.

See how DentRecall works →