Resources

Law 25 for Law Firms and Notaries: Between Professional Secrecy and Compliance

Elite Consultation·2026-06-29
Law 25lawyersnotariesprofessional secrecy

Law firms and notarial practices hold some of the most sensitive information ever entrusted to a third party: real estate transactions, separation agreements, litigation files, estate planning, commercial mandates, personal financial details. Professional secrecy already governed this information rigorously. Law 25 adds to it without replacing it.

For many firms, the first reaction to Law 25 is to assume that compliance with the Code of Ethics is enough. That reading is incomplete. The two regimes coexist, their obligations partially overlap, and several Law 25 requirements (incident register, PIA, oversight of technology vendors) have no equivalent in the Code of Ethics.

This guide explains how to align Law 25 with the ethical framework of lawyers under the Barreau du Québec and notaries under the Chambre des notaires, and how to structure compliance in a firm of any size.

Professional Secrecy and Law 25: Two Complementary Frameworks

Professional secrecy is a constitutional right and an ethical duty. It prohibits a lawyer or notary from disclosing information confided by a client, except with consent, by court order, or by exception provided by law.

Law 25 governs the collection, use, communication, retention, and destruction of personal information by every Quebec private organization. Legal practices fall within this category.

Where professional secrecy answers the question "may I disclose this information?", Law 25 answers complementary questions:

  • How is this information collected and stored?
  • What access controls exist within the firm?
  • How long is it kept?
  • What do you do in case of an incident (loss, theft, unauthorized access)?
  • How do you govern technology vendors that have access to it (practice management software, hosting, backups)?

Strictly observing professional secrecy does not guarantee Law 25 compliance, and vice versa. The two frameworks must be maintained in parallel.

The Privacy Officer at the Firm

Every Quebec organization subject to Law 25 must designate a privacy officer. In a legal practice, this role is often held by:

  • A managing partner, in small firms
  • A designated lawyer or notary, in mid-sized firms
  • A dedicated person (privacy officer, in-house counsel) in large firms

The privacy officer's name and contact information must be published. For most firms, this publication appears on the website and in the privacy policy.

The privacy officer must have actual authority to enforce decisions on personal information governance. A purely nominal designation does not meet the spirit of the Act.

Technology Vendors at a Legal Practice

Modern firms run on a wide technology stack: practice management software (Clio, Soluno, Affinity), document management (NetDocuments, iManage), office suite (Microsoft 365, Google Workspace), billing, payment, electronic signature, communications. Each of these vendors qualifies as a service provider under section 18.3 of Law 25.

For each vendor, the firm must have:

  • A written contract that includes the six mandatory elements
  • An assessment of the sensitivity of the data being handled
  • Clarity on the hosting jurisdiction (and a PIA if outside Quebec, in line with section 17)

Professional secrecy adds an extra layer: the client should in principle be informed when their file is handled by a vendor that is not a member of the firm. This obligation does not appear in Law 25 itself; it stems from the codes of ethics.

File Structure and Access Controls

Under Law 25, the principle of minimization also applies to internal access. A client file should only be accessible to members of the firm who need it for their work.

In practice, this means:

  • A document management system that allows access restrictions on a file-by-file basis
  • A procedure to handle conflicts of interest that isolates the affected files (an "ethical wall")
  • Access logging for the most sensitive files
  • Periodic review of access, particularly after departures or role changes

Firms that operate with open access ("everyone can see everything") do not have a defensible access control posture under Law 25, even when professional secrecy is observed by social convention.

The Special Case of Notaries: The Minute Book

Notaries are subject to the Notaries Act, which imposes a particular framework for the keeping and transmission of their minutes. A notary's minute book is a protected estate that must be preserved for long periods, sometimes perpetually for certain instruments.

This obligation coexists with Law 25 but generally takes precedence for the information contained within the notarial deeds themselves. Law 25 applies fully to the administrative information tied to the files (contact information, email exchanges, invoices, working notes) that does not form part of the minute itself.

Managing a digital minute book raises specific questions under Law 25: where is it hosted, who has access, how is it backed up, what is the procedure during an incident. These questions warrant a dedicated PIA for firms that have recently digitized their archives.

AI in Legal Practice

Generative AI tools (ChatGPT, Copilot, Claude, Lexis+ AI, Westlaw Precision AI, Casetext CoCounsel) are increasingly used for legal research, drafting, document review, and case law summarization. Their use in practice triggers several obligations:

  • Confidentiality: pasting a client file into a consumer tool may breach professional secrecy
  • Law 25: sharing personal information with an AI vendor outside Quebec triggers the obligations of sections 17 and 18.3
  • Verification: AI hallucinations (invented case law, fabricated citations) are a documented cause of disciplinary sanctions

Several North American bar associations have published opinions on AI use. The Barreau du Québec and the Chambre des notaires generally recommend:

  • Prioritizing enterprise versions of tools
  • Systematic human verification of any AI output before use
  • Informing the client about AI use in their file in certain circumstances
  • No sharing of identifiable information in consumer tools

An internal AI usage policy has become a recognized best practice.

Practical Steps for a Firm

For a firm looking to bring its Law 25 compliance up to standard, here is a realistic approach.

  1. Formal designation of the privacy officer and publication of contact information
  2. Privacy policy revised to reflect Law 25 (collection, purposes, rights, privacy officer contact, vendors outside Quebec)
  3. Inventory of technology vendors with access to personal information
  4. Contract review with these vendors (section 18.3) and signing of any missing addenda
  5. PIA for tools hosted outside Quebec (section 17)
  6. Internal security policy: access controls, password management, multi-factor authentication, device management
  7. AI usage policy: approved tools, prohibited inputs, mandatory verification
  8. Incident register in place with a documented notification procedure
  9. File retention schedule and a procedure for secure destruction
  10. Training of partners and staff on Law 25 and how it interacts with professional secrecy

For a firm of 5 to 25 people, this work generally takes 60 to 120 hours spread over several months.

How Observantia Supports Legal Practices

Observantia centralizes the technology vendor register, keeps the PIAs completed for the firm's tools, manages the incident register, and documents the file retention policy. The dashboard helps the privacy officer coordinate compliance work alongside the firm's ethical obligations. Start your 14-day free trial.

Related articles


This content is provided for informational purposes only and does not constitute legal advice. For questions specific to your situation, consult a qualified legal professional.

Ready to simplify your compliance?

Try Observantia free for 14 days.