Most driving school owners, when Law 25 comes up, say some version of: "that's for big companies."

It isn't, and it's probably the most expensive misunderstanding available on this subject. Law 25 applies to every Québec business that collects personal information, from a sole proprietor to a multinational. There is no employee threshold, no revenue threshold, no small-business exemption.

A driving school collects personal information on its first registration form. You've been covered since day one.

Why a driving school is more exposed than average

It isn't about size. It's about the nature of what you hold.

A retail shop knows its customers' names, emails and purchase history. A driving school holds, for every student:

  • name, date of birth, address, phone number;
  • their learner's licence number — a government identifier;
  • contact details for a parent or guardian, because a large share of your clientele are minors;
  • sometimes medical information, where a condition affects fitness to drive;
  • the complete history of a relationship spanning more than a year.

Minors, government identifiers, sometimes medical data. That risk profile has nothing in common with a corner store's, and it's why this deserves to be taken seriously even at 40 students.

The eight obligations, concretely

Here's what the law asks. Tick what's already in place:

Law 25 self-check

Tick what's already in place. Nothing is saved or transmitted.

0 of 8 obligations covered

0%

If nothing is ticked, start with the first: designate the responsible person. By default that's already you — it's mostly a matter of saying so explicitly.

Your answers stay in your browser.

None of these needs a budget. They need a decision, and a written trace of that decision. That's the good news: baseline Law 25 compliance for a driving school is essentially an organizational exercise, not an investment.

Three of them are worth expanding, because they're the ones most often misunderstood.

1. The responsible person is already you

Many schools assume they need to "hire someone" or "appoint an officer". In practice the law designates, by default, the person with the highest authority in the business. If you're the owner, that's you — whether you've formalized it or not.

You may delegate the role to a staff member, but that delegation must be in writing.

And there's a second half almost everyone misses: that person's name and contact details must be published on your website. Knowing internally who it is doesn't satisfy the requirement. A student, a parent, or the Commission must be able to find it without asking you.

This is probably the fastest fix on the whole list: one line on your contact page.

2. The incident register includes minor incidents

A very common confusion: people assume only "real" data breaches need recording.

That isn't what the law says. You must keep a register of all confidentiality incidents, including those that present no serious risk of harm.

An email containing a student's contact details sent to the wrong person is an incident. A paper file left on a counter is an incident. A former employee whose access was never revoked is an incident.

The distinction between "record" and "report" is this:

  • Every incident → entered in the register.
  • An incident presenting a serious risk of harm → additionally reported to the Commission d'accès à l'information and to the people affected.

The register isn't an admission of weakness. A business that has never recorded anything isn't a business without incidents — it's a business that doesn't notice them.

3. Your out-of-province suppliers commit you

This is the most ignored obligation, and the one that catches the most schools without their knowing.

Before entrusting personal information to a business located outside Québec, you must have carried out a privacy impact assessment and concluded a written agreement with that supplier.

The operative words are "outside Québec" — not "outside Canada". A supplier in Ontario or British Columbia triggers the same obligation.

And most schools use, without a second thought:

  • a cloud service for their files;
  • an email or SMS sending platform;
  • management software hosted elsewhere;
  • an online backup solution.

Each of those, if hosted outside Québec and receiving information about your students, falls under section 17.

That doesn't make it forbidden — the law does not require your data to stay in Québec. It means the transfer has to be assessed and governed in writing, rather than happening by default.

Where to start from zero

In this order, because it's the best effort-to-risk ratio:

  1. Publish the responsible person. One line on your site. Fifteen minutes.
  2. Open the incident register. Even a simple dated document is enough to begin — what matters is that it exists before you need it.
  3. List your suppliers and flag the ones hosted outside Québec. You can't assess what you haven't inventoried.
  4. Write the privacy policy. It follows naturally from the first three steps, once you know what you hold and who touches it.

The principle that simplifies everything else

There's one way to cut your exposure dramatically, and it costs nothing: don't hold what you don't need.

Every scanned document you keep "just in case" is one more piece of personal information to protect, to include in an incident report, and to locate if someone asks for its deletion.

A school that records which proofs exist and where they're kept, rather than storing a copy of each, meets the same inspection requirements at a fraction of the risk. What isn't stored can't leak.

That's the most useful reasoning in all of Law 25, and the only one that saves you time instead of costing it.

This describes general obligations. For your specific situation — particularly your agreements with existing suppliers — confirm with a qualified advisor or directly with the Commission d'accès à l'information.