Practical guide · Quebec compliance
Law 25 and Microsoft 365: what Quebec privacy rules ask of your tenant
Quebec’s Law 25 and Canada’s federal privacy law ask precise questions: who is responsible, how is an incident recorded, who has access to which data. This guide connects those questions to Microsoft 365 settings and decisions that your monthly cadence can genuinely maintain.
The decision to make
This guide helps an organization see how its Microsoft 365 tenant can support privacy obligations it already knows about - it does not replace legal advice and does not certify compliance with anything.
What this guide does not do
The exact scope of Law 25 and federal privacy law depends on your organization’s size, sector, and the kind of information it handles. This site is not a law firm and does not draft your privacy policy. What follows connects commonly cited obligations to concrete Microsoft 365 practices, to be confirmed with your legal counsel or your organization’s privacy officer.
A named owner, not just a checked box
Naming a privacy officer becomes concrete once that person can actually retrieve access logs, confirm who viewed what, and hold the permissions needed to do so - not just carry a title on an org chart.
An incident needs to be reconstructable
Meeting an incident-notification requirement assumes you can reconstruct what happened: sign-in logs, security alerts, and a retention period for those logs long enough to support an investigation. The Defender basics already covered in monthly management feed directly into this capability.
- Log retention period confirmed and documented
- Relevant security alerts retained, not just displayed and lost
- A known procedure names who must be notified if an incident occurs
The record behind personal data handling
Knowing where the most sensitive information lives - which SharePoint sites, accessible to which guests, under which sensitivity labels - is as much an access-hygiene question as a legal one. Recurring review of access and shared spaces becomes useful evidence rather than a separate exercise.
What the cadence can record, and what stays your decision
Ongoing management can maintain settings, document decisions, and supply logs at the moment of an incident. Legal interpretation of your obligations, drafting your privacy policy, and the relationship with your provincial or federal privacy regulator remain your organization’s responsibility and that of its legal counsel.
Official reference material
Check the governing guidance before making a compliance decision.
These official resources are reference material. They do not replace legal advice tailored to your organization.
A simple matrix for assigning the work.
| Situation | Owner | Cadence | Useful evidence |
|---|---|---|---|
| Incident register | Privacy officer + M365 owner | At every incident | Dated incident log |
| Sign-in logs and alerts | M365 owner | Confirmed retention period | Logs available for investigation |
| Access to personal data | Business owner | Periodic review | List of justified access |
Decision checklist
What should be true before considering this area under control.
- A privacy officer is named and actually equipped to act
- Sign-in and security logs are retained long enough to support an investigation
- Spaces holding sensitive data have regularly reviewed access
- An incident-notification procedure is known to the team
- Your organization’s exact obligations have been confirmed with legal counsel
Next step
Connect this compliance work to the governance and record already in place.
M365 governance details who decides and where the record lives. Then use the assessment to see whether responsibility for your personal data is clear today.