CRM and Law 25
CRM and Law 25: what to check before trusting software with your clients
No CRM makes a business compliant with Quebec’s Law 25: the law applies to the business that holds the information, not to its software. Where it is hosted still matters: an assessment is required before sending personal information outside Quebec. With OKTO PSA, the instance and its dedicated database are hosted in Quebec. Traffic goes through Cloudflare’s protection network, and a backup copy is kept off site, in Canada, so outside Quebec.
This page sums up what the Act respecting the protection of personal information in the private sector requires, as amended by Law 25. The sections cited were read on LégisQuébec on October 2, 2026. This is a general summary, not legal advice.
What does Law 25 require when you keep clients in a CRM?
A CRM holds names, emails, phone numbers and call notes. That is personal information as soon as it concerns a natural person and allows them to be identified. The work contact details of a business contact fall outside part of the rules (section 1), but a CRM almost always holds more than that. Six obligations touch it directly.
A named person in charge
The person with the highest authority in the business is responsible for the protection of personal information. They may delegate the role in writing. Their title and contact details are published on the company website (section 3.1).
An assessment before you buy
Any project to acquire, develop or overhaul a system that handles personal information calls for a privacy impact assessment, proportionate to how sensitive and how plentiful the information is. Changing CRMs is one (section 3.3).
An assessment before leaving Quebec
Before communicating personal information outside Quebec, or entrusting its storage to someone outside Quebec, an assessment and a written agreement are required. The legal framework of the destination is part of the analysis (section 17).
Clear consent
Consent must be clear, free and informed, given for specific purposes and requested in simple, plain terms. It is valid only for the time needed. Information is used for the purposes it was collected for (sections 12 and 14).
Confidentiality incidents
If there is a risk of serious injury, the business promptly notifies the Commission d’accès à l’information and the people affected. It also keeps a register of all its incidents (sections 3.5 and 3.8).
Access and rectification
A person can ask what you hold on them, get a copy and have inaccurate information corrected. The person in charge answers in writing within 30 days of receiving the request (sections 27, 28 and 32).
Is a CRM hosted in Canada enough for Law 25?
Not quite. Section 17 speaks of outside Quebec, not outside Canada. A CRM hosted in Canada but in another province is therefore still subject to the assessment. And hosting is only one of the questions.
Everything in Quebec: one assessment fewer
If the database, the backups and the subprocessors all stay in Quebec, the assessment required before a communication outside Quebec does not have to be done for hosting. The one that comes with buying a new system still does.
Hosted elsewhere: allowed, but documented
The law does not forbid a CRM hosted outside Quebec. It asks you to show, in writing, that the information will receive adequate protection there, then to sign an agreement that reflects it.
In every case: a written contract
Handing your data to a vendor is done by written contract. It sets out the protection measures, limits use to the contract and provides that nothing is kept once it ends. The vendor reports any breach without delay (section 18.3).
What the software will not do for you
Naming the person in charge, writing the privacy policy, deciding what to collect and for how long, answering requests: those tasks belong to the business. A well-built CRM makes them easier. It does not replace them.
Integrations count too
A CRM hosted in Quebec can still send data elsewhere if you connect an outside service to it. In OKTO PSA, integrations such as Stripe, QuickBooks, Microsoft Entra ID or Google are turned on by you, and the product works without them.
Disclaimer
This is a general summary, not legal advice. For your situation, read the text of the law, contact the Commission d’accès à l’information or consult a legal advisor.
What questions should you ask a CRM vendor?
Eight questions to ask before signing, whether the CRM is from Quebec or not. The right-hand column gives the OKTO PSA answer, taken from its security and data processing pages.
| Question to ask | Why ask it | OKTOPSA |
|---|---|---|
| Where is the database hosted? | Outside Quebec, an assessment and a written agreement are required (section 17). | The database is in Quebec. Traffic goes through Cloudflare’s network, and a backup copy is kept off site, in Canada, so outside Quebec. The list of subprocessors is in the data processing agreement. |
| Does my data share a database with other customers? | Separation that depends on code alone is harder to demonstrate. | No. A separate database and runtime environment for each client. |
| Who on your side can see my data? | The contract must set out the protection measures (section 18.3). | Staff access is named, limited to what is strictly necessary and logged. |
| Is there a written data processing contract? | The law requires a written mandate or contract (section 18.3). | Yes. OKTO processes the information on the client’s behalf and on its instructions. |
| What do you do if there is an incident? | You have to assess the risk, notify and keep a register (sections 3.5 and 3.8). | OKTO notifies the client without delay, assists it and records the incident in its register, kept five years. |
| Can I answer an access or rectification request? | You have 30 days to answer in writing (section 32). | Extraction, rectification, deletion or delivery in a structured, commonly used format. |
| Where are my consents recorded? | You need to be able to show a consent (section 14). | A consent register is part of OKTO CRM, with a Regulations tab. |
| What happens to my data if I leave? | The vendor keeps nothing after the contract ends (section 18.3). | Full export delivered before closing, then destruction confirmed in writing. |
OKTO PSA answers taken from the security and hosting page and the data processing agreement. They describe the product and the contract. They are not a certificate of compliance for your business.
Check your CRM in 6 steps
Half a day is enough to know where you stand. Do it with the person who administers the CRM and the one who signs the contracts.
- 01
Name the person in charge
By default, it is the person who runs the business. If they delegate, do it in writing. Publish their title and contact details on your website.
- 02
Take inventory
List what the CRM holds about people: contact details, notes, emails, attachments. Write down why each field exists. What serves no purpose does not need to be collected.
- 03
Find where the data lives
Ask your vendor in writing where the database and the backups are hosted. Outside Quebec, the assessment and the written agreement have to be produced.
- 04
Reread the contract
Look for the protection measures, the subcontractors, breach notification and what happens to the data at the end. If one of these is missing, ask for it.
- 05
Check your consents
For each mailing list, find when and how consent was obtained, and for what purpose. Record it in a register instead of in a salesperson’s memory.
- 06
Run two drills
Simulate an access request: can you pull one person’s file in under 30 days? Simulate an incident: who notifies, and where is the register?
What OKTO PSA puts on your side
OKTO PSA does not make you compliant. It gives you plain facts to write in your assessment, and tools to keep up with your obligations day to day.
Hosting in Quebec
Your instance and its dedicated database are hosted in Quebec; the Quebec CRM shares that database with tickets, projects and invoicing. Traffic goes through Cloudflare’s protection network, and a backup copy is kept off site, in Canada, so outside Quebec.
Audit log and backups
The product keeps an audit log of access and changes, which you can consult. Backups are daily, encrypted and kept 30 days. Multi-factor authentication is available.
Written commitments
The data processing agreement, the terms and the service commitment set out access, timelines and responsibilities. The list of subprocessors (network protection, off-site backup) is in the agreement; use it for your own privacy impact assessment. Tier pricing includes the CRM, the PSA software and HR.
Frequent questions
The questions we get asked
Your question is not here?
Write to us. A person in Trois-Rivières answers, within one business day.
Ask your questionNot on its own. The law places obligations on the business that holds the personal information: naming a person in charge, getting valid consent, handling incidents, answering access requests. A CRM can help through its hosting, its contract and its features. OKTO PSA helps. It does not make you compliant.
No, the law does not require it. It does require a privacy impact assessment and a written agreement before communicating personal information outside Quebec, or entrusting its storage to someone outside Quebec. OKTO PSA is hosted in Quebec; the list of its subprocessors (network protection, off-site backup) is in the data processing agreement, for your own assessment.
Section 17 of the Act covers communication outside Quebec, not outside Canada. A CRM hosted in another province is therefore still subject to the assessment and the written agreement. It is not forbidden: it is a step to document, taking into account the legal framework of the place.
By default, it is the person with the highest authority in the business. They may delegate the role in writing, in whole or in part. The title and contact details of the person in charge must be published on the company website, or made available another way if there is no website.
First take reasonable steps to reduce the risk of injury. If the incident presents a risk of serious injury, promptly notify the Commission d’accès à l’information and the people concerned. In every case, record the incident in the register the business must keep. Your vendor should have notified you without delay.
The person in charge must answer in writing, promptly, and no later than 30 days after receiving the access or rectification request. With no answer in that time, the request is deemed refused. Your CRM therefore has to let you find and extract one person’s file quickly.
OKTO PSA is hosted in Quebec, with one dedicated database per client. Traffic goes through the Cloudflare protection network, and a backup copy is kept off site, in Canada. It offers a consent register, an audit log you can consult, encrypted backups and a written data processing agreement. Compliance remains your business’s responsibility.
A specific question from your privacy officer? Ask it.
Send us the question list from your assessment. We answer in writing, point by point, and we also tell you what is yours to do and not the software’s.