Locked laptop symbolizing data confidentiality.
Compliance

Quebec Law 25 and GDPR : what an SMB really needs to know

No panic. Four concrete actions that get you compliant in days.

Back to articles
Author : Sinclaire Mbounda, Co-CEO·Published on April 29, 2026·5 min read

If you operate in Quebec or with European clients, two regimes concern you : Quebec Law 25 (in force since 2024) and GDPR (Europe). We will not give you the full summary. Here are the four concrete actions an SMB leader must take.

A processing register. Not a PowerPoint. A file that lists every personal data point processed, its purpose, its storage, its retention. Excel is enough to start.

An accessible privacy policy. A footer link, readable by a customer in two minutes. Not a 20-page PDF copied from the internet.

A request response process. When a customer asks for access, rectification or deletion, you have 30 days to reply. Name an internal owner, write the procedure.

An incident notification. If you suffer a breach, you must notify the CAI (Quebec) or CNIL (Europe) within 72 hours. Prepare the form and distribution list before you need it.

These are the basics. They will not get you through a full audit but they protect you from a notice the day it lands.

FlyTech Inc team mid-session, section backdrop.
The FlyTech Inc team
Next step

30 minutes.A plan.Or an argued no.

No pitch. No slides. We get your need, we say yes or no, we cost it. You decide.

Book nowor contact@flytech-inc.com