SOC2Prep

SOC 2 and Quebec Law 25 together

A SOC 2 report proves nothing about Law 25. The two overlap on maybe half the security controls and not at all on the obligations that carry the penalties.

Last reviewed 2026-09-01Written by Jacob Masse, TrazTech Inc.

If you hold personal information about people in Quebec, Law 25 applies to you whether or not you have an office there, and no SOC 2 report satisfies any part of it. The overlap is narrower than people assume: SOC 2's security criterion and Law 25's safeguards obligation ask for similar controls, so perhaps half your technical work counts twice. Everything Law 25 is actually enforced on, a named privacy officer, a published policy, confidentiality by default, privacy impact assessments and mandatory incident reporting to the Commission d'acces a l'information, has no SOC 2 counterpart at all. Penalties run to $25,000,000 CAD or 4 percent of worldwide turnover for the most serious administrative findings.

7 Documents Law 25 needs that SOC 2 does not ask for

$25M CAD Upper administrative penalty, or 4% of turnover

Sept 2023 When confidentiality by default came into force

Does Law 25 apply to us if we are not in Quebec?

Almost certainly yes if you have Quebec users. The statute reaches any enterprise that collects, holds, uses or communicates personal information about a person in Quebec in the course of carrying on an enterprise, and it does not require an establishment in the province. A Toronto or Vancouver SaaS company with Quebec customers is in scope. So is a company whose only Quebec connection is employee data, because Law 25 covers employee personal information where federal PIPEDA largely does not.

The employee-data trap

This is the one that catches Canadian SaaS companies. PIPEDA applies to employee personal information only in federally regulated workplaces, so most companies never think about their HR data as regulated. Law 25 has no such carve-out. One remote engineer in Montreal puts your HR system, your payroll processor and your background-check vendor inside the statute.

What does SOC 2 already cover?

Law 25 obligations mapped against SOC 2 criteria
Law 25 obligationNearest SOC 2 criterionCovered?
Reasonable security safeguards for personal informationCC6 seriesLargely, yes
Detect and respond to confidentiality incidentsCC7.3 to CC7.5Mechanism yes, duties no
Vendors handling personal information under written termsCC9.2Partly. Law 25 dictates specific clauses
Named privacy officer, published, by title and contactNoneNo
Published privacy policy in clear language, in FrenchNoneNo
Confidentiality by default in productsNoneNo
Privacy impact assessment before certain projectsNoneNo
Register of confidentiality incidentsNoneNo
Report incidents of serious injury risk to the Commission and affected peopleNoneNo
Data portability on requestPrivacy category, if selectedOnly if you chose the privacy criterion
Assessment before communicating outside QuebecNoneNo
Rules on automated decision-making, including noticeNoneNo

Nine of twelve rows say no. That is why the policy checklist tool asks whether you hold Quebec personal information before it produces a list. The American template packs everyone downloads carry none of these documents.

Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.

Which documents do we need on top of the SOC 2 set?

Work through this list against what you already have. Nothing here is satisfied by a SOC 2 policy you already wrote, though several sit naturally as sections inside one.

0 of 0 done ·

Seven of these produce artifacts an auditor would also accept as SOC 2 evidence if you wire them in: the incident register feeds CC7, the processor clauses feed CC9.2, and the retention rules feed CC6.5. Wire them in deliberately rather than keeping two filing systems, which is the point of the evidence collection routine.

How does incident reporting differ from PIPEDA?

Breach and confidentiality incident duties compared
QuestionPIPEDA, federalLaw 25, Quebec
Trigger for reportingReal risk of significant harmRisk of serious injury
Who is toldPrivacy Commissioner of Canada and affected individualsCommission d'acces a l'information and affected individuals
TimingAs soon as feasibleWith diligence, promptly
Record of every incidentYes, kept 24 monthsYes, register with no fixed minimum period stated
Record required when not reportableYesYes
What the record must containEnough for the Commissioner to verify compliancePrescribed content including the description, the number of people affected and the measures taken

Two registers with different prescribed fields is a bad idea. Keep one, with a superset of the fields, and a column recording which regime applied. Your incident response plan is the place that decision belongs, and an auditor testing CC7.4 will read the same document.

Where does this fit in a SOC 2 timeline?

  1. Decide it in scope or out during scoping, not later. Whether Quebec personal information is inside the system boundary changes your system description, and changing the boundary after the observation window opens is expensive.
  2. Designate the privacy officer in week one. It is a signature and a line on the website, and until it exists every other Law 25 obligation has no owner.
  3. Write the governance policies alongside the SOC 2 policy set, not after. Retention and destruction rules belong in the same document as your data classification, and writing them twice produces two answers.
  4. Do the outside-Quebec transfer assessments before you sign the next processor. Each one is an afternoon if the vendor register exists, and weeks if you are reconstructing which vendors touch what.
  5. Start the incident register now, empty. A register opened on day one of the observation window with nothing in it reads better than one opened in month three with three back-filled entries.

Is Law 25 work worth doing if no customer has asked?

The case for waiting is real. Enforcement to date has concentrated on large holders of sensitive personal information rather than on small SaaS companies, the maximum penalties quoted everywhere are ceilings that have not been approached, and a fifteen-person company doing all eleven items above properly is spending four to six weeks it does not obviously have.

The case for doing it anyway is that most of the cost is in the first two items and the rest is marginal once the SOC 2 work is happening. A privacy officer and a published policy is a day. The register is a spreadsheet. The expensive items, confidentiality by default and the transfer assessments, are the ones that get more expensive the longer you wait, because product defaults harden and vendor lists grow. If you are doing SOC 2 in the same six months, do Law 25 in the same six months. If you are not, do the first two items and leave the rest until a Quebec customer asks, which they will, usually in a security questionnaire.

Does a SOC 2 report satisfy Law 25?

No. A SOC 2 report is an opinion about controls, not a statement of compliance with any statute, and the Commission d'acces a l'information does not treat it as one. It is useful supporting evidence that your safeguards obligation is being met, and it is useful in a security questionnaire, but it addresses none of the governance, notice or reporting obligations.

Do we need the SOC 2 privacy criterion for Law 25?

No, and adding it is usually the wrong way to spend the money. The privacy category is written against the AICPA's own privacy criteria, not against Quebec law, so it adds audit fee and scope without closing the Law 25 gaps. Add it when a customer asks for it by name.

Do we have to store Quebec data in Canada?

No. Law 25 does not require data residency in Quebec or in Canada. What it requires is an assessment before personal information is communicated outside Quebec, considering sensitivity, purpose, the protections in place and the legal framework where the data lands. Storing in a US region is allowed if that assessment exists and reaches a defensible conclusion.

Does our privacy policy have to be in French?

Yes for anything presented to people in Quebec. Quebec's language rules and Law 25's clear-language requirement work together here: a policy offered only in English to Quebec users is a problem under both, and the practical answer is a French version at the same prominence.

Is Law 25 the same as PIPEDA?

No, and Quebec's regime is stricter on almost every point compared here. Law 25 covers employee data, mandates a privacy officer, requires privacy impact assessments and imposes confidentiality by default, none of which PIPEDA does. Where both apply, meeting Law 25 generally means you have met PIPEDA, but not the reverse. The federal picture is on getaudited.ca.

Get quotes from firms that do both

Tell us you hold Quebec personal information and we will route it to Canadian firms that treat Law 25 as part of the readiness scope rather than a separate project.

Get matched