All articles
Actualités & Tendances du marché

Quebec Law 25 and Recruitment: Compliance Guide for HR Professionals

Quebec Law 25 (Bill 64) introduces strict privacy rules for recruitment. Understand your legal obligations, candidate data protection requirements, and how to stay compliant in 2026.

Équipe RecruitEasy

Équipe RecruitEasy

Author

April 1, 2026
14 min read
0
Quebec Law 25 and Recruitment: Compliance Guide for HR Professionals

Quebec Law 25 (Bill 64) fundamentally changed how companies handle candidate data. Implemented in 2023, with ongoing compliance requirements through 2026, it's stricter than Canada's federal PIPEDA in several ways. Yet many HR teams in Quebec are still operating under old practices, putting their companies at legal and financial risk.

This guide explains what Law 25 requires for recruitment, how to audit your current practices, and how to ensure compliance without compromising hiring effectiveness.

What Is Quebec Law 25?

Quebec Law 25 (Bill 64: Amendments to Law 25 of the Civil Code) modernizes Quebec's private sector privacy law. Key changes:

  1. Stricter consent requirements for collecting candidate data
  2. Enhanced data subject rights (candidates can demand data deletion)
  3. Mandatory security measures (data breach notification within 24 hours)
  4. Increased penalties (up to $10 million for violations)
  5. Right to explanation (candidates can ask why they were rejected)

Unlike PIPEDA (federal law), Law 25 applies only to Quebec-based companies OR companies processing data of Quebec residents.

Law 25 vs. PIPEDA: Key Differences in Recruitment

RequirementPIPEDA (Federal)Law 25 (Quebec)
Consent for recruitmentImplied (using data for recruiting is reasonable)Explicit (must ask before using data)
Data retentionNo limit specifiedMust delete within "reasonable time" after hiring decision
Data breach notificationWithin "reasonable time" (interpreted as 30 days)Within 24 hours
Right to explanationNo explicit rightYES—candidate can ask why rejected
PenaltiesUp to $100,000Up to $10 million
Foreign data transferAllowed if protection equivalentRestricted—must have explicit legal basis

Translation for HR: Law 25 is stricter than PIPEDA. If you're currently compliant with PIPEDA, you need to do more to be compliant with Law 25.

Law 25 Recruitment Compliance: Step by Step

Step 1: Audit Your Data Collection Practices

Current practice (often NOT compliant with Law 25):

  • Candidate applies via job board (Indeed, LinkedIn)
  • You scrape their data and add to ATS without explicit consent
  • You store their data in your ATS indefinitely
  • If rejected, you never delete their data

Law 25 compliant practice:

  • Candidate applies and explicitly consents to data processing
  • Your consent notice explains: "We'll collect your data and use it to evaluate your application. We'll keep it for 12 months after hiring decision, then delete unless you apply again."
  • You honor that timeline
  • You can be reached to delete data before timeline expires

Action item: Review your job postings and application form. Does it explicitly ask candidates to consent to data processing?

Every recruitment touchpoint needs consent language.

On your careers page: ❌ Poor: "Submit your resume" ✅ Compliant:

"By submitting your application, you consent to the collection and processing of your personal data for the purpose of evaluating your candidacy for this position. Your data will be kept for up to 12 months after our hiring decision, then securely deleted. You can request deletion at any time by emailing [email]. We comply with Quebec Law 25."

In your ATS application form: Add a checkbox: ☐ "I consent to the processing of my personal data according to the company's privacy policy and Quebec Law 25"

In LinkedIn message or email outreach:

"Hi Alex, we're interested in your profile for our Senior Developer role. If you're interested, we'd need to collect some personal information. We process your data according to Quebec Law 25 and delete it within 12 months if you're not hired. Is that OK?"

In recruiter phone calls: Document that you explained data usage: "During the call, I explained that we're processing your data per Law 25, storing it securely, and deleting it within 12 months if you're not hired. They confirmed understanding."

Step 3: Create a Data Retention Policy

Law 25 requires data deletion within "reasonable time" after hiring decision. Define what "reasonable" means for your company.

Suggested timeline:

  • Hired candidate: Keep data for employee file purposes (legal/tax requirement)
  • Rejected in screening: Delete within 3 months
  • Rejected after interview: Delete within 12 months
  • Not interviewed, multiple applications: Delete within 12 months after first application
  • Candidate who withdrew: Delete within 3 months of withdrawal

Document this policy and reference it in your privacy notice:

"We retain your data as follows: [your timeline]. If you'd like your data deleted sooner, contact [privacy contact]."

Step 4: Secure Your Candidate Data

Law 25 mandates "appropriate security measures" to protect personal data.

Required security practices:

  • ✅ ATS with encryption at rest (data protected when stored)
  • ✅ Encryption in transit (HTTPS, not HTTP)
  • ✅ Access controls (only recruiters can see candidate data, not entire company)
  • ✅ Password protection for accounts
  • ✅ Regular security audits
  • ✅ Data breach incident plan (notify candidates within 24 hours if data is exposed)

Audit your ATS: Does RecruitEasy or your current platform provide:

  • Encryption? ✓
  • Access controls? ✓
  • Audit logs (who accessed what data, when)? ✓
  • 24/7 security monitoring? ✓

Red flag: If your ATS doesn't provide these, you're non-compliant.

Step 5: Implement "Right to Explanation"

New with Law 25: Candidates can ask "Why was I rejected?" and you must provide explanation.

This doesn't mean you need to change decisions. It means you must explain your reasoning.

Example:

Candidate: "I want to know why I was rejected."

Your response (Compliant):

"We reviewed your application against our criteria for this role. While you have strong marketing experience, we decided to move forward with a candidate who had more direct SaaS product management experience. The decision was based on [specific criteria from job description]. We encourage you to apply for future roles that match your background."

Your response (NOT compliant):

"We've moved forward with another candidate."

How to implement:

  • Train recruiters to document rejection reasons in ATS
  • Create email template for "right to explanation" requests
  • Assign someone to respond within 10 days (Law 25 doesn't specify timeline, but 10 days is reasonable)

Step 6: Create a Data Breach Response Plan

If candidate data is exposed, Law 25 requires notification within 24 hours.

Your incident response plan should include:

  1. Detection: How you discover data has been breached (ATS alert, security team notice, candidate report)
  2. Assessment: Determine scope (which candidates affected, what data exposed)
  3. Notification: Within 24 hours, email candidates:

"We discovered that your data (name, email, resume) was exposed on [date]. We immediately [action taken]. We recommend [steps you can take]. Contact us if you have questions: [contact]."

  1. Documentation: Keep records of breach, notification, and remediation
  2. Remediation: Strengthen security, change systems, audit everything

Who to notify:

  • Candidates whose data was exposed (required)
  • PIPEDA/Law 25 regulator if risk to privacy rights (required if significant)
  • Cyber insurance company (for legal defense)

Document your plan and share with:

  • IT/Security team
  • Legal team
  • Senior leadership

Common Law 25 Recruitment Mistakes

What happens: You find a promising candidate on LinkedIn, manually add them to your ATS, and start recruiting them.

Why it's non-compliant: You collected their data without explicit consent. LinkedIn's ToS technically forbid scraping, but even if allowed, Law 25 requires you to ask the candidate first.

Fix:

  • Use LinkedIn's official recruitment tool (InMail)
  • Or reach out directly and ask: "Can we process your data for this role?"
  • Avoid bulk scraping

Mistake #2: Keeping Rejected Candidate Data "Just in Case"

What happens: You keep all rejected resumes in your ATS forever, in case you need them for future roles.

Why it's non-compliant: Law 25 requires deletion after "reasonable time." Indefinite storage = non-compliant.

Fix:

  • Set data deletion reminders (12 months after rejection)
  • Use ATS with automated deletion functionality
  • Document your retention policy in privacy notice

What happens: You collect consent verbally ("Yes, I agree to processing") but don't document it.

Why it's risky: If a dispute arises, you have no proof of consent.

Fix:

  • Require checkbox consent in application form (documented automatically)
  • For phone conversations: document the call and confirm consent in follow-up email
  • Keep dated records of consent

Mistake #4: Automated Rejection Emails Without Explanation Option

What happens: Candidate receives: "Your application was not selected. Good luck with your search."

Why it's risky: Violates right to explanation. Candidate can file complaint.

Fix:

  • Add to rejection emails: "If you'd like feedback on your application, reply to this email and we'll explain our decision."
  • Train recruiters to respond with thoughtful explanation when asked

Mistake #5: Sharing Candidate Data with External Recruiters Without Contract

What happens: You hire a recruiter to help find candidates. You send them your rejected candidate list.

Why it's non-compliant: You're sharing data with third parties without explicit consent and documented data processing agreement.

Fix:

  • Get signed Data Processing Agreement (DPA) with any external recruiter
  • Only share data that the recruiter needs
  • Ensure candidate consented to third-party processing

Your Law 25 Recruitment Compliance Checklist

Privacy Notice & Consent: ☐ Privacy notice on all recruitment touchpoints (website, application form, emails) ☐ Explicit consent checkbox in application form ☐ Consent language in job posting ☐ Consent language in outreach emails to passive candidates

Data Security: ☐ ATS has encryption at rest and in transit ☐ Access controls (only authorized people see candidate data) ☐ No data on unencrypted USB drives or unsecured email ☐ Audit log of who accessed candidate data ☐ Data breach response plan documented

Data Management: ☐ Data retention policy defined (when you delete) ☐ Automated deletion setup in ATS ☐ Process for candidate deletion requests (within 10 days) ☐ Process for "right to explanation" requests

Vendor Management: ☐ DPA (Data Processing Agreement) with ATS provider ☐ DPA with any external recruiter or vendor ☐ Confirmation that vendors are Law 25 compliant

Documentation: ☐ Training records for recruitment team on Law 25 ☐ Documentation of consent for each candidate ☐ Incident response plan for data breaches ☐ Regular audit of compliance (quarterly minimum)

Tools and Resources for Law 25 Compliance

Privacy Management Tools

  • Termly: Privacy policy generator for Quebec
  • GDPR.eu: Not Quebec-specific, but helpful for understanding privacy law concepts

ATS Compliance Features

  • RecruitEasy: Built with Law 25 compliance in mind (encryption, access controls, audit logs, PIPEDA compliant)
  • Workable: Offers privacy features, but require verification of Law 25 compliance
  • Bamboo HR: HRIS with privacy controls, but mainly for post-hire
  • CNIL (French): Quebec's privacy regulator
  • PIPEDA Commissioner: Federal equivalent, helpful for guidance
  • Your local law firm: Recommend hiring for privacy policy review

The Business Case: Why Compliance Matters

Cost of non-compliance:

  • Regulatory fines: Up to $10 million (vs. PIPEDA's $100,000 max)
  • Class action lawsuits: Candidates can sue for privacy violation
  • Reputational damage: "Company violates privacy law" in news cycle
  • Remediation costs: Incident response, credit monitoring for candidates, legal fees

Cost of compliance:

  • Privacy notice: $0-$500 (DIY or lawyer review)
  • ATS with compliance features: $100-$500/month
  • Training for team: 2 hours
  • Ongoing management: 1-2 hours/month

ROI: Compliance costs are negligible compared to fine risk.

Conclusion: Law 25 Compliance Is Now Table Stakes

Quebec Law 25 is stricter than PIPEDA and actively enforced. The "we didn't know" defense no longer works—as of 2026, it's expected knowledge.

Companies that invest in Law 25 compliance now:

  • Avoid regulatory fines and lawsuits
  • Build trust with candidates (transparent data practices)
  • Create competitive advantage (candidates prefer compliant companies)
  • Simplify future audits (clean documentation)

Ready to audit your recruitment for Law 25 compliance?

RecruitEasy is built for Quebec compliance—encryption, access controls, audit logs, and integrated privacy management. Try free for 14 days.

Also read: Candidate Experience Optimization and Cost of Hiring in Canada 2026.

Équipe RecruitEasy

Written by

Équipe RecruitEasy

Sharing practical tips to help recruiters work better with AI.

Comments

Want to try RecruitEasy?

Put what you just read into practice. Start free and discover how our AI simplifies every step of your recruitment.

No credit cardQuick setupFrench support