Skip to main content
green gradient background, "The Future of Application Security Is Already Here." and a read the report button.
Quebec Nonprofit Wrongly Assumes Exemption, Triggers Law 25 ReviewLaws and Regulations
4 min readFor Compliance Managers

Quebec Nonprofit Wrongly Assumes Exemption, Triggers Law 25 Review

What Happened

A Quebec-based nonprofit running health clinics mistakenly believed it was exempt from Law 25 due to its nonprofit status. This organization processed patient data, coordinated appointments, and managed a network of volunteer healthcare providers. When the Commission d'accès à l'information du Québec (CAI) conducted a compliance review, the nonprofit realized it had been operating as an "enterprise" under Quebec law all along, facing potential fines of up to 4% of worldwide turnover.

The nonprofit lacked privacy impact assessments, formal consent mechanisms for data sharing with third-party platforms, and documented legal bases for processing sensitive health information. Its assumption of exemption left it vulnerable to significant regulatory risk.

Timeline

September 2021: Quebec's Parliament passes Law 25, updating the province's data privacy regime. The law contains no explicit nonprofit exemption.

2021-2023: The nonprofit continues operations, processing patient data through digital scheduling systems and sharing information with volunteer providers. No compliance program is established.

Early 2024: The CAI initiates a compliance review following a patient complaint about data sharing practices.

Review period: The organization scrambles to assess if it qualifies as an "enterprise" under Quebec's civil code definition: "organized economic activity, whether or not it is commercial in nature, consisting of producing, administering or alienating property, or providing a service."

The legal team analyzes the CAI's four-factor test and reviews case law, including decisions that classified private clinics and unions as enterprises while exempting purely spiritual organizations like the Jehovah's Witnesses.

Which Controls Failed or Were Missing

No applicability assessment: The organization never formally analyzed whether Law 25 applied to its operations, relying instead on the assumption that nonprofit status meant exemption.

Missing legal basis documentation: There were no records showing a valid legal basis for processing personal health information, sharing data with third-party platforms, or coordinating patient information across clinic locations.

Absent privacy impact assessments: No PIAs were conducted for the digital scheduling system, the volunteer provider network, or the patient database.

No consent mechanisms: Patient data was collected without consent notices or information on how data would be processed, shared, or stored.

Inadequate vendor management: Third-party scheduling platforms processed patient data without formal data processing agreements or documented compliance requirements.

What the Relevant Standard Requires

Law 25 applies to any entity that qualifies as an "enterprise" under Quebec's civil code. The statute doesn't define "enterprise" itself, so organizations must refer to Article 1525 of the Quebec Civil Code, which defines it as organized economic activity, regardless of commercial nature.

The CAI refined this definition with a four-element test:

  1. Repetitive jurisdictional acts: Does the organization perform ongoing, systematic activities?
  2. Resource coordination: Is there organized coordination of human and material resources?
  3. Needs satisfaction: Does the organization aim to respond to and satisfy specific needs?
  4. Market-force standards: Does success depend on standards related to market forces and organizational effort?

The analysis focuses on the organization's main activity, not ancillary functions. Case law provides examples: private clinics and unions qualify as enterprises; purely spiritual organizations do not.

For the health clinic nonprofit, the answer was clear. It operated repetitive healthcare services, coordinated staff and volunteers systematically, responded to patient healthcare needs, and competed for patients and funding in ways that resembled market dynamics. The spiritual-organization exemption didn't apply because the main purpose was healthcare delivery, not religious activity.

Once classified as an enterprise, the organization became subject to Law 25's full requirements: lawful basis for processing, purpose limitation, data minimization, security safeguards, breach notification, and individual rights including access and deletion.

Lessons and Action Items for Your Team

Conduct an enterprise classification analysis now. Don't wait for a CAI inquiry. Map your organization's activities against the four-factor test. Document your reasoning. If your main activity involves organized service delivery with coordinated resources, you're likely an enterprise regardless of tax status.

Review case law precedents specific to your sector. The CAI has classified unions and private clinics as enterprises. If your nonprofit operates health services, professional associations, or coordinated economic activities, you're in similar territory. Spiritual organizations received different treatment, but only when their main purpose was genuinely spiritual rather than service-oriented.

Document your legal basis for every processing activity. If you're an enterprise under Law 25, you need a lawful basis for processing personal information. Consent is one option, but not always the most practical for ongoing service delivery. Review Law 25's other legal bases and document which applies to each processing activity.

Implement vendor due diligence. If third-party platforms process personal information on your behalf, you need data processing agreements that specify security requirements, breach notification obligations, and data handling restrictions. Your nonprofit status doesn't exempt you from processor oversight responsibilities.

Create a compliance roadmap with specific milestones. If you've been operating without Law 25 compliance controls, build a phased implementation plan. Priority one: document your legal basis and establish consent mechanisms where required. Priority two: conduct PIAs for high-risk processing. Priority three: implement technical safeguards and breach response procedures.

Train staff and volunteers on data handling requirements. Many nonprofits rely on volunteers who may not understand privacy obligations. If you're subject to Law 25, everyone who handles personal information needs training on lawful processing, purpose limitation, and security requirements.

The core lesson: nonprofit status is a tax classification, not a privacy exemption. If your organization operates like an enterprise under Quebec's civil code definition, Law 25 applies in full. The time to assess your status is before the CAI asks the question.

Promotional banner highlighting failures found in PCI audits and how to spot the gaps

You Might Also Like