What Law 25 is
Its full name is the Act to modernize legislative provisions as regards the protection of personal information (2021, chapter 25). It was introduced as Bill 64 and assented to on 22 September 2021. Everybody calls it Law 25 after the chapter number, and almost nobody calls it anything else.
It replaces nothing. It amends the statutes that were already there, including the Act respecting the protection of personal information in the private sector (chapter P‑39.1), which is the one that applies to businesses. That distinction is useful when you are hunting for the exact text of an obligation: Law 25 says what changed, and P‑39.1 says what applies today.
The obligations came into force in stages over three years: 22 September 2022 for the designated person and the incident register, 22 September 2023 for consent, the privacy policy, the assessment before any communication outside Quebec and governance, and 22 September 2024 for the right to portability. All of it is in force now.
The official texts. They are in French, because the statute is; an English summary in their place would be us vouching for a translation we did not make.
Law 25 as assented to (PDF, Commission d’accès à l’information)
Act respecting the protection of personal information in the private sector, chapter P‑39.1
The main changes made by Law 25
The person responsible for the protection of personal information
Who it applies to
Anyone carrying on an enterprise who collects, holds, uses or communicates personal information in the course of it. A three-person clinic is covered on the same terms as a chain. There is no headcount threshold; the 25-employee figure people remember belongs to the Charter of the French Language and registration with the Office québécois de la langue française, not to this.
Being incorporated elsewhere does not settle it. Law 25 attaches to personal information collected in the course of an enterprise in Quebec, and where the server sits exempts nothing: if anything the opposite, since the assessment duty is triggered precisely when the information leaves Quebec. An Ontario business answering calls from Quebec can therefore be both subject to the statute and carrying out the very cross-border communication the statute asks it to assess first.
The obligations, one at a time
Six of them, in the order a business meets them rather than the order the statute numbers them. None of these is a project; all of them are a decision, written down somewhere a person can find it again in two years.
A named person, published
Since 22 September 2022 a private business in Quebec has had to designate a person responsible for the protection of personal information. By default that is the person with the highest authority, and the role can be delegated. Their title and contact details have to be published, on your website or, failing that, by another appropriate means. Naming somebody internally without saying so is not enough.
A published privacy policy
Written in simple, clear terms, saying what you collect and why. For a phone line that means writing down that you hold call records, and for how long. It is the page an unhappy customer reads first, and the page quoted back at you if it describes something other than what you actually do.
Valid consent, one purpose at a time
Consent has to be manifest, free and informed, given for specific purposes, and it is requested for each of those purposes, in simple and clear terms. Asked for in writing, it is presented distinctly from everything else. Consent that is not given in accordance with the law is without effect. Section 14 of the private-sector Act. It is the hardest of these for a phone line, which is why it has a page of its own.
An assessment before anything leaves Quebec
Before communicating personal information outside Quebec you have to assess whether it would receive adequate protection there, having regard to the legal framework where it is going. It is an assessment, not a prohibition: keeping data outside Quebec is not forbidden, doing it without having assessed is. And the obligation belongs to you, the business collecting, not to your provider.
An incident register, and notice when the risk is serious
Every confidentiality incident goes in a register, however small. The Commission asks that the register carry a description of the incident, its date, the number of people affected, the risk assessment, the dates of any notices and the measures taken, and that it be kept for at least five years after the incident became known. Notice to the Commission and to the people affected is a separate duty, owed only when the incident presents a risk of serious harm. The Commission’s guidance covers both.
Governance policies, and the rest of the calendar
Since 22 September 2023 there are also governance policies and practices to keep (retention, staff roles, how complaints are handled), privacy by default on a technological product or service, and anonymisation according to generally accepted best practices where you choose not to destroy. Since 22 September 2024 there is a right to portability: giving a person, on request, the information they supplied you, in a structured, commonly used technological format.
What it means for a phone system
The obligations do not relax because the channel is audio. A business line holds callers’ numbers, recordings if they are switched on, voicemail audio and its transcript, call logs, contact records built from call traffic, and the IP addresses of softphone sessions. All of it is personal information the moment it can be attached to a person. The transcript is worth calling out: it is a new document derived from the recording, and it is retained separately.
Recording and consent
An announcement saying a call “may be recorded” satisfies the duty to inform and is not automatically valid consent. The gap between announcing and obtaining is where most phone systems sit. And quality assurance, training and evidence in a dispute are three purposes, not one: consent obtained for the first does not cover the other two.
The incident register
For a phone line the realistic list is duller than a spectacular breach: a voicemail box still reachable by somebody who left, a recording emailed to the wrong address, a call log exported and left in a shared drive, a softphone left signed in on a returned laptop, somebody replaying recordings they had no reason to hear. That last one counts: unauthorised use is an incident even when nothing left the company and no attacker was involved.
Where your call data lives
This is the least discussed obligation and the one most likely to catch a cloud phone system, because almost none of them keep Quebec data in Quebec. In our own review of eight competing vendors, done on 19 August 2026, not one of the eight named Law 25 anywhere on its site. A good answer to “where is my data stored?” names a region. A bad one says “the cloud”.
Retention
Retention is a purpose limit, not a storage setting. A recording kept indefinitely has outlived the quality-assurance purpose it was collected for, and it is your own announcement a complainant will quote back. The cheapest incident response is not holding the recording at all: scheduled deletion reduces the surface permanently, and it is a configuration decision rather than a project.
Where Ringfully is
Our data is at AWS in us-east-1: Northern Virginia, in the United States. Not a Canadian region. If you are a Quebec business, sending us personal information is a communication outside Quebec, and the statute asks you to assess it before you start. We would rather write that sentence than let you find it in a sub-processor table.
Recording is off by default: an organisation that has not configured it does not record. When it is on, the rule belongs to the company rather than to each person, and playing a recording back is a separate permission from making one. Retention is set rather than left open: an administrator sets a window per class of data, a nightly job deletes whatever has passed it with no archive behind, and an organisation that sets nothing follows 30 days for recordings and 90 for voicemail.
Our sub-processor list is published in full, with no form and no login, naming every party and what reaches each one: that is half the work of your assessment, done in advance. What we hold, who can reach it and what we still lack is on security.

What we cannot do for you
We do not decide your purposes, and no phone system can. We cannot keep your register either: the incidents in it are yours, and it follows you on the day you change providers. And we cannot tell you the communication outside Quebec is acceptable; that judgement is yours, and any vendor who makes it for you has told you something about how carefully they read the statute.
We do not yet name a person responsible for the protection of personal information, because the operating entity is not yet incorporated. That is a gap rather than a feature, and every legal page on this site says so on its face until it is fixed. We would rather it were visible than implied.
Further reading
What Law 25 asks of a phone system
Call-recording consent under Law 25
Recording announcements in Quebec: what to say
The incident register and notice to the Commission
Serving Quebec from outside Quebec: Laws 96 and 25
A description of what the statute asks, not legal advice. What you owe depends on what your business collects and why. Confirm your own situation with a Quebec-qualified adviser.