Law 25: what it concretely changes for a building inspector
Many inspectors assume Law 25 targets large tech companies. In reality, an inspector working alone holds exactly the kind of information the law regulates most strictly.
This article is informational and does not constitute legal advice. For your specific situation, consult a legal advisor.
Why this applies to you
Law 25 â Quebec's act modernizing legislative provisions on the protection of personal information â applies to any enterprise operating in Quebec, regardless of size. A self-employed inspector is an enterprise under the law.
Look at what a typical inspection file contains:
- Your client's name, phone number and email
- The residential address of the inspected building
- Photos of the interior of a private home
- A handwritten or electronic signature
- Sometimes details about the real estate transaction underway
That's a file of sensitive personal information. Storing it in a folder on your laptop rather than a database changes nothing about your obligations.
Five obligations that touch you directly
1. Designate a privacy officer
Every enterprise must designate one. In a one-person business, that's you. The obligation isn't to hire someone â it's that the role be identified and the contact details published, typically on your website.
2. Obtain clear, separate consent
Consent must be requested separately for each purpose. A single checkbox covering both "perform the inspection" and "send me your newsletter" does not comply.
In practice: your service contract covers performing the inspection. If you then want to send commercial communications, that needs a separate, unchecked box.
3. Inform at the time of collection
When you collect the information, the person must know why you're collecting it, how you'll use it, who you might share it with, and what their rights are.
A short mention in your service contract plus an accessible privacy policy generally suffices.
4. Respond to access and correction requests
A client can ask for a copy of the information you hold about them, or its correction. You must respond within 30 days.
The practical question: if a client wrote to you today, how long would it take to gather everything you hold on them â emails, photos, contract, report, invoice? If the answer exceeds an hour, your organization is the real problem.
5. Report confidentiality incidents
For an incident presenting a risk of serious harm, you must notify the Commission d'accĂšs Ă l'information and the people concerned, and keep an incident register.
An incident isn't only a hack. It's also: a lost laptop containing files, a report sent to the wrong recipient, a mislaid USB key, a compromised email account.
The most overlooked point
The law requires a defined retention period. You can't keep files indefinitely "just in case."
This creates real tension with your professional risk management, since a claim can surface years after an inspection. The answer isn't to keep everything forever, nor to delete quickly: it's a written retention policy, with periods justified by your professional and legal obligations, actually applied.
The particular case of photos
Inspection photos deserve separate attention. You're photographing the inside of someone's home. Those images can capture far more than what you're documenting: personal effects, documents left on a table, family photos, sometimes the occupants themselves.
- Photograph only what documents an observation.
- Avoid capturing identifiable people or documents when avoidable.
- Never share inspection photos for promotional purposes without explicit written consent.
Your vendors bind you too
If you use cloud software, an email service or an e-signature tool, your information passes through them. You remain responsible.
- Where is the data hosted? Communication outside Quebec requires a privacy impact assessment.
- What security measures are in place? Encryption, access control, logging, backups.
Checklist
- A privacy officer is designated and contact details published
- A privacy policy is publicly accessible
- Commercial consent is separate from the service contract
- A written retention policy exists, with justified periods
- Files are findable by client within minutes
- An incident register is ready to use
- Vendors are documented, including where data is hosted
- File access is protected by strong authentication
- Reports are delivered by secure link rather than unprotected attachment
Where to start
If this feels heavy, start with the simplest and most visible: publish a privacy policy, designate yourself as officer, and separate commercial consent from the service contract. Those three steps address much of what is immediately verifiable.
The rest â retention, incidents, vendors â is built afterward, and benefits enormously from being carried by your tools rather than your memory.
Privacy built in by design
Consents, controlled access, secure links, retention policy and logging.
See the DomiSpect approach