DSAR 2026 · 5 min read

Quebec Law 25 DSAR Redaction

Respond to Quebec access requests within the 30-day deadline. AI-powered redaction of third-party personal information, processed in your browser.

Law 25 is the common name for Quebec's modernized private-sector privacy law, the Act to modernize legislative provisions as regards the protection of personal information, which amended the Act respecting the protection of personal information in the private sector. Its provisions phased in between September 2022 and September 2024, and together they give Quebec residents a set of rights that closely resembles the GDPR: access, rectification, deletion, and, since September 2024, data portability.

The law applies to any person or organization carrying on an enterprise in Quebec, which in practice reaches well beyond the province. A company headquartered in Toronto, London, or Chicago that serves Quebec customers or employs Quebec residents handles personal information under Law 25. Within Quebec's private sector, Law 25 governs rather than federal PIPEDA, so a PIPEDA program alone does not answer a Quebec access request. This page is informational, not legal advice; the statute and your counsel govern.

What Law 25 Requires When Someone Requests Their Data

An access request under Law 25 works like a DSAR under GDPR or UK GDPR. The individual asks for the personal information the enterprise holds about them, and section 32 of the Private Sector Act requires a written response within 30 days of receipt. Miss the window and the law deems the request refused, which opens the door to an examination of disagreement before the Commission d'acces a l'information (CAI), Quebec's privacy regulator.

The enterprise must verify the requester's identity before releasing anything, process the request free of charge in the ordinary case, and, if it refuses any part of the request, state the reasons, cite the statutory provision relied on, and explain the remedies and deadlines available to the requester. A refusal is not a shortcut: the person in charge of the protection of personal information must be able to defend each withholding decision.

The Third-Party Problem: Section 40

The hard part of an access response is rarely finding the requester's information. It is everyone else's. Emails, chat threads, HR files, and shared documents about the requester are dense with other people's names, contact details, and personal circumstances.

Section 40 of the Private Sector Act addresses this directly: an enterprise must refuse to communicate personal information where disclosure would be likely to reveal personal information about a third person and could seriously harm that person, unless the third person consents. The practical mechanism that satisfies both obligations at once, disclosing the requester's information while protecting third parties, is redaction. You deliver the documents with the requester's information intact and the protected third-party information removed.

Done manually, that means a reviewer reading every page of every document against the clock. On a mailbox-sized request, the 30-day deadline makes pure manual review difficult to sustain, which is why organizations look for detection tooling that surfaces the personal information and leaves the judgment calls to a human reviewer.

Redaction and Deletion Are Different Workflows

Law 25 gives individuals both an access right and deletion rights, and the two are often requested together but fulfilled separately. An access response is about producing copies: you gather the responsive documents, redact what section 40 protects, and deliver the result. A deletion request is about the source systems: the information itself must be removed or de-indexed where it lives.

SafeRedact does the first job. It produces redacted copies for disclosure and never alters the originals in your systems. Deletion is a records-management function executed in the platforms that hold the data. In a Microsoft 365 environment, that is Microsoft Purview territory: retention policies, retention labels, and deletion workflows applied to Exchange, SharePoint, OneDrive, and Teams content. A complete Law 25 program uses both: redaction tooling to answer access requests, and Purview or equivalent records management to honor deletion obligations.

Law 25 Requests in Microsoft 365 Environments

Most Quebec enterprises of any size run on Microsoft 365, so the raw material of an access response is usually a Purview or eDiscovery export: PST mailbox files, SharePoint and OneDrive documents, and Teams conversations. SafeRedact processes these exports directly and supports 11 file types (PST, PDF, DOCX, XLSX, EML, MSG, HTML, TXT, CSV, JSON, ZIP), covering the full range of data found in a Microsoft 365 export, with attachments and forwarded messages included in detection.

The recommended workflow is the same one described in our Microsoft 365 DSAR redaction guide: export mailboxes as PSTs through Purview, keep one case per custodian, and run detection across the whole export. The Purview export guide walks through the exact export settings.

How SafeRedact Handles a Law 25 Case

Files never leave your browser: documents are processed client-side, only extracted text is sent for AI detection, and no documents are stored on servers. Detection text is never used for training and is deleted within 30 days. DSAR mode lets you name the data subject whose information should be preserved while other individuals' personal information is flagged for redaction across every file in the case. Every detection is reviewed by a human before anything is exported, and the output includes a processing summary and audit trail your privacy officer can stand behind if the CAI asks how the response was produced.

A Data Processing Agreement is available, and enterprise cases are priced per case, with the price set with you and shown before you download. See the enterprise overview or the enterprise FAQ for how cases run end to end.

Penalties and Enforcement

Law 25 gave the CAI real enforcement teeth. Administrative monetary penalties can reach $10 million CAD or 2% of worldwide turnover, whichever is greater, and penal offences carry fines up to $25 million CAD or 4% of worldwide turnover. Individuals whose requests are refused or ignored can bring the matter to the CAI, and a response that discloses third-party personal information in breach of section 40 is its own incident.

Law 25 Alongside Other Regimes

Organizations rarely face Law 25 alone. A UK or EU company with Quebec operations is already running UK GDPR or GDPR subject access processes; Law 25 requests slot into the same pipeline with a tighter framing of the third-party rule and Quebec's own regulator. Elsewhere in Canada, federal PIPEDA governs, and the same redaction workflow serves both. The mechanics of the response, collect, detect, review, redact, deliver, are identical across regimes; what changes is the clock and the statute cited in the cover letter.

Respond to Law 25 Requests On Time

AI-powered detection, human review, and third-party redaction for Quebec access requests. Files never leave your browser.

Start Your Evaluation

Related Guides

Microsoft, Microsoft 365, SharePoint, Exchange Online, OneDrive, Teams, and Purview are trademarks of Microsoft Corporation. SafeRedact is not affiliated with or endorsed by Microsoft.

Found this useful?
Link copied!