Skip to content

Practical guide · Quebec compliance

Law 25 and Microsoft 365: what Quebec privacy rules ask of your tenant

Quebec’s Law 25 and Canada’s federal privacy law ask precise questions: who is responsible, how is an incident recorded, who has access to which data. This guide connects those questions to Microsoft 365 settings and decisions that your monthly cadence can genuinely maintain.

The decision to make

This guide helps an organization see how its Microsoft 365 tenant can support privacy obligations it already knows about - it does not replace legal advice and does not certify compliance with anything.

What this guide does not do

The exact scope of Law 25 and federal privacy law depends on your organization’s size, sector, and the kind of information it handles. This site is not a law firm and does not draft your privacy policy. What follows connects commonly cited obligations to concrete Microsoft 365 practices, to be confirmed with your legal counsel or your organization’s privacy officer.

A named owner, not just a checked box

Naming a privacy officer becomes concrete once that person can actually retrieve access logs, confirm who viewed what, and hold the permissions needed to do so - not just carry a title on an org chart.

An incident needs to be reconstructable

Meeting an incident-notification requirement assumes you can reconstruct what happened: sign-in logs, security alerts, and a retention period for those logs long enough to support an investigation. The Defender basics already covered in monthly management feed directly into this capability.

  • Log retention period confirmed and documented
  • Relevant security alerts retained, not just displayed and lost
  • A known procedure names who must be notified if an incident occurs

The record behind personal data handling

Knowing where the most sensitive information lives - which SharePoint sites, accessible to which guests, under which sensitivity labels - is as much an access-hygiene question as a legal one. Recurring review of access and shared spaces becomes useful evidence rather than a separate exercise.

What the cadence can record, and what stays your decision

Ongoing management can maintain settings, document decisions, and supply logs at the moment of an incident. Legal interpretation of your obligations, drafting your privacy policy, and the relationship with your provincial or federal privacy regulator remain your organization’s responsibility and that of its legal counsel.

Official reference material

Check the governing guidance before making a compliance decision.

These official resources are reference material. They do not replace legal advice tailored to your organization.

A simple matrix for assigning the work.

SituationOwnerCadenceUseful evidence
Incident registerPrivacy officer + M365 ownerAt every incidentDated incident log
Sign-in logs and alertsM365 ownerConfirmed retention periodLogs available for investigation
Access to personal dataBusiness ownerPeriodic reviewList of justified access

Decision checklist

What should be true before considering this area under control.

  • A privacy officer is named and actually equipped to act
  • Sign-in and security logs are retained long enough to support an investigation
  • Spaces holding sensitive data have regularly reviewed access
  • An incident-notification procedure is known to the team
  • Your organization’s exact obligations have been confirmed with legal counsel

Next step

Connect this compliance work to the governance and record already in place.

M365 governance details who decides and where the record lives. Then use the assessment to see whether responsibility for your personal data is clear today.

Let’s discuss ownership of your M365 tenant

Describe your team, what currently lacks an owner, and the outcome you need. No tenant access is required for this first conversation.

Direct email remains the simplest way to start. Use the public m365care.ca address with an already attributed subject.