Quebec Law 25 (Bill 64) introduces strict privacy rules for recruitment. Understand your legal obligations, candidate data protection requirements, and how to stay compliant in 2026.
Équipe RecruitEasy
Author
Sommaire
Quebec Law 25 (Bill 64) fundamentally changed how companies handle candidate data. Implemented in 2023, with ongoing compliance requirements through 2026, it's stricter than Canada's federal PIPEDA in several ways. Yet many HR teams in Quebec are still operating under old practices, putting their companies at legal and financial risk.
This guide explains what Law 25 requires for recruitment, how to audit your current practices, and how to ensure compliance without compromising hiring effectiveness.
Quebec Law 25 (Bill 64: Amendments to Law 25 of the Civil Code) modernizes Quebec's private sector privacy law. Key changes:
Unlike PIPEDA (federal law), Law 25 applies only to Quebec-based companies OR companies processing data of Quebec residents.
| Requirement | PIPEDA (Federal) | Law 25 (Quebec) |
|---|---|---|
| Consent for recruitment | Implied (using data for recruiting is reasonable) | Explicit (must ask before using data) |
| Data retention | No limit specified | Must delete within "reasonable time" after hiring decision |
| Data breach notification | Within "reasonable time" (interpreted as 30 days) | Within 24 hours |
| Right to explanation | No explicit right | YES—candidate can ask why rejected |
| Penalties | Up to $100,000 | Up to $10 million |
| Foreign data transfer | Allowed if protection equivalent | Restricted—must have explicit legal basis |
Translation for HR: Law 25 is stricter than PIPEDA. If you're currently compliant with PIPEDA, you need to do more to be compliant with Law 25.
Current practice (often NOT compliant with Law 25):
Law 25 compliant practice:
Action item: Review your job postings and application form. Does it explicitly ask candidates to consent to data processing?
Every recruitment touchpoint needs consent language.
On your careers page: ❌ Poor: "Submit your resume" ✅ Compliant:
"By submitting your application, you consent to the collection and processing of your personal data for the purpose of evaluating your candidacy for this position. Your data will be kept for up to 12 months after our hiring decision, then securely deleted. You can request deletion at any time by emailing [email]. We comply with Quebec Law 25."
In your ATS application form: Add a checkbox: ☐ "I consent to the processing of my personal data according to the company's privacy policy and Quebec Law 25"
In LinkedIn message or email outreach:
"Hi Alex, we're interested in your profile for our Senior Developer role. If you're interested, we'd need to collect some personal information. We process your data according to Quebec Law 25 and delete it within 12 months if you're not hired. Is that OK?"
In recruiter phone calls: Document that you explained data usage: "During the call, I explained that we're processing your data per Law 25, storing it securely, and deleting it within 12 months if you're not hired. They confirmed understanding."
Law 25 requires data deletion within "reasonable time" after hiring decision. Define what "reasonable" means for your company.
Suggested timeline:
Document this policy and reference it in your privacy notice:
"We retain your data as follows: [your timeline]. If you'd like your data deleted sooner, contact [privacy contact]."
Law 25 mandates "appropriate security measures" to protect personal data.
Required security practices:
Audit your ATS: Does RecruitEasy or your current platform provide:
Red flag: If your ATS doesn't provide these, you're non-compliant.
New with Law 25: Candidates can ask "Why was I rejected?" and you must provide explanation.
This doesn't mean you need to change decisions. It means you must explain your reasoning.
Example:
Candidate: "I want to know why I was rejected."
Your response (Compliant):
"We reviewed your application against our criteria for this role. While you have strong marketing experience, we decided to move forward with a candidate who had more direct SaaS product management experience. The decision was based on [specific criteria from job description]. We encourage you to apply for future roles that match your background."
Your response (NOT compliant):
"We've moved forward with another candidate."
How to implement:
If candidate data is exposed, Law 25 requires notification within 24 hours.
Your incident response plan should include:
"We discovered that your data (name, email, resume) was exposed on [date]. We immediately [action taken]. We recommend [steps you can take]. Contact us if you have questions: [contact]."
Who to notify:
Document your plan and share with:
What happens: You find a promising candidate on LinkedIn, manually add them to your ATS, and start recruiting them.
Why it's non-compliant: You collected their data without explicit consent. LinkedIn's ToS technically forbid scraping, but even if allowed, Law 25 requires you to ask the candidate first.
Fix:
What happens: You keep all rejected resumes in your ATS forever, in case you need them for future roles.
Why it's non-compliant: Law 25 requires deletion after "reasonable time." Indefinite storage = non-compliant.
Fix:
What happens: You collect consent verbally ("Yes, I agree to processing") but don't document it.
Why it's risky: If a dispute arises, you have no proof of consent.
Fix:
What happens: Candidate receives: "Your application was not selected. Good luck with your search."
Why it's risky: Violates right to explanation. Candidate can file complaint.
Fix:
What happens: You hire a recruiter to help find candidates. You send them your rejected candidate list.
Why it's non-compliant: You're sharing data with third parties without explicit consent and documented data processing agreement.
Fix:
Privacy Notice & Consent: ☐ Privacy notice on all recruitment touchpoints (website, application form, emails) ☐ Explicit consent checkbox in application form ☐ Consent language in job posting ☐ Consent language in outreach emails to passive candidates
Data Security: ☐ ATS has encryption at rest and in transit ☐ Access controls (only authorized people see candidate data) ☐ No data on unencrypted USB drives or unsecured email ☐ Audit log of who accessed candidate data ☐ Data breach response plan documented
Data Management: ☐ Data retention policy defined (when you delete) ☐ Automated deletion setup in ATS ☐ Process for candidate deletion requests (within 10 days) ☐ Process for "right to explanation" requests
Vendor Management: ☐ DPA (Data Processing Agreement) with ATS provider ☐ DPA with any external recruiter or vendor ☐ Confirmation that vendors are Law 25 compliant
Documentation: ☐ Training records for recruitment team on Law 25 ☐ Documentation of consent for each candidate ☐ Incident response plan for data breaches ☐ Regular audit of compliance (quarterly minimum)
Cost of non-compliance:
Cost of compliance:
ROI: Compliance costs are negligible compared to fine risk.
Quebec Law 25 is stricter than PIPEDA and actively enforced. The "we didn't know" defense no longer works—as of 2026, it's expected knowledge.
Companies that invest in Law 25 compliance now:
Ready to audit your recruitment for Law 25 compliance?
RecruitEasy is built for Quebec compliance—encryption, access controls, audit logs, and integrated privacy management. Try free for 14 days.
Also read: Candidate Experience Optimization and Cost of Hiring in Canada 2026.
Written by
Sharing practical tips to help recruiters work better with AI.
Comments