Law 25 and email: the questions to ask your sending provider
Every email your application sends contains at least one email address, and often a name, an order, an amount or a history. For a business operating in Québec, that is personal information, and the provider that sends it for you handles it on your behalf. Here is what the law requires in that case, and the concrete questions to ask before choosing or keeping a provider.
This article is general information, not legal advice. The subject is broad and depends on your sector: talk to your person in charge of the protection of personal information or to a lawyer about your situation.
The law in a nutshell
The Act respecting the protection of personal information in the private sector (CQLR, c. P-39.1) governs the personal information that a person carrying on an enterprise collects, holds, uses or communicates. Law 25 (S.Q. 2021, c. 25) modernized it. A few rules bear directly on the choice of an email provider.
You remain responsible (sections 3.1 and 3.2)
The business is responsible for the personal information it holds, even when a provider handles it for you. The person with the highest authority exercises the function of person in charge of the protection of personal information (the function can be delegated in writing), and that person's title and contact information are published on the business's website. The business must also have governance policies, proportionate to its activities.
Entrusting the processing to a provider (section 18.3)
You may communicate personal information to a provider, without the individual's consent, if it is necessary for carrying out the mandate or performing the service contract you entrust to it. The law then sets conditions:
- the mandate or contract is in writing;
- it specifies the measures the provider must take to protect the confidentiality of the information, to ensure it is used only to carry out the contract, and to ensure the provider does not keep it after the contract expires;
- the provider must notify without delay your person in charge of any breach or attempted breach of the confidentiality obligations, and allow them to carry out any verification relating to that confidentiality.
A serious provider therefore has a document for this: a data processing addendum, or an equivalent section of the contract. If you cannot find it, ask for it.
Outside Québec (section 17)
Before communicating personal information outside Québec, the business must conduct a privacy impact assessment. It takes into account the sensitivity of the information, the purposes for which it is to be used, the protection measures (including contractual ones) and the legal framework of the State where it would be communicated. The communication may take place only if the assessment shows adequate protection, and it requires a written agreement. The same rule applies when you entrust a provider located outside Québec with the task of collecting, using, communicating or keeping information on your behalf.
Two points to remember:
- the test is Québec, not Canada. A provider hosted in Ontario or Alberta is "outside Québec" within the meaning of section 17;
- hosting is only one link. Subcontractors, backup services, the network that distributes traffic, and payment, logging or support tools count too.
Assess before adopting (section 3.3)
Section 3.3 requires a privacy impact assessment for any project to acquire, develop or overhaul an information system or electronic service delivery system involving personal information. It must be proportionate to the sensitivity, the purposes, the quantity and the distribution of the information. Choosing a new sending provider can fall within it, depending on the scale of the project.
Incidents (section 3.5)
In the event of a confidentiality incident presenting a risk of serious injury, the business must promptly notify the Commission d'accès à l'information and the individuals concerned. To do that in time, it has to be notified in time by its provider, which is why the notice clause of section 18.3 matters.
And the federal law (PIPEDA)?
The Personal Information Protection and Electronic Documents Act (S.C. 2000, c. 5), known as PIPEDA, applies to organizations for the personal information they collect, use or disclose in the course of commercial activities (subsection 4(1)). It provides, however, that the federal government may by order exempt organizations in a province that has substantially similar legislation, for information collected, used or disclosed within that province (paragraph 26(2)(b)). Québec, Alberta and British Columbia have such a law for the private sector.
In practice:
- if your business is in Québec, the Québec law applies first to what you do in Québec. PIPEDA can still apply when information crosses provincial borders in the course of commercial activities: a provider outside Québec is an obvious example;
- if your business is elsewhere in Canada, PIPEDA, or your province's substantially similar law, applies.
For choosing a provider, two PIPEDA rules resemble Québec's:
- Responsibility follows the information. Under principle 4.1.3 of Schedule 1, an organization is responsible for information transferred to a third party for processing, and must use contractual or other means to provide a comparable level of protection while it is being processed. This is the federal counterpart of the written contract in section 18.3.
- Breaches of security safeguards. Section 10.1 requires you to report to the Privacy Commissioner of Canada any breach of security safeguards if it is reasonable to believe it creates a real risk of significant harm, and to notify the individuals concerned. Again, you can do it in time only if your provider tells you in time.
The questions to ask a sending provider
- Where is the data, and where does it pass through? Ask for the list of subcontractors and processing locations: servers, backups, logs, support, and any service placed in front of the API (traffic distribution, attack protection).
- Is there a written contract that meets section 18.3? Look for a data processing addendum: security measures, use limited to the service, destruction at the end.
- How long is the content of the emails kept? And the metadata (recipient, subject, delivery events)? Who can read them?
- How quickly are you notified of an incident? "Without delay" is in the law; a specific number of hours is more useful.
- Can you verify? Section 18.3 provides that your person in charge can carry out verifications relating to confidentiality.
- What happens to the account at the end? The information must be destroyed or returned when the contract ends, not kept indefinitely.
- Does the provider use your data for anything else? Model training, product statistics, advertising: none of it is necessary to send an email.
And at Duva?
Rather than asking you to take our word for it, here is where we answer these questions, publicly:
- the privacy policy describes the information collected, the providers (OVHcloud for hosting the servers in Beauharnois, Québec, and encrypted backups in a Canadian data center; Cloudflare; Stripe), the retention periods and what is communicated outside Québec;
- the data processing addendum is part of the contract and sets out the roles, the subprocessors, the incident notice (within 72 hours at most), audit and destruction.
One point illustrates what "hosted in Canada" does not say on its own: web traffic to the API goes through Cloudflare's network before reaching our servers, and some providers may process information elsewhere, notably in the United States. We say so in the privacy policy, because it is exactly the kind of link that section 17 requires you to look at. Ask every provider the same question, including us.
The consequences of a breach
The Act provides for monetary administrative penalties of up to $10,000,000 or 2% of worldwide turnover for the preceding fiscal year (section 90.12), and penal fines of up to $25,000,000 or 4% of worldwide turnover for a business (section 91). In both cases, the greater of the two amounts applies.
Sources
- Act respecting the protection of personal information in the private sector (CQLR, c. P-39.1), sections 3.1, 3.2, 3.3, 3.5, 17, 18.3, 90.12 and 91. Version current to June 10, 2026, consulted on October 1, 2026.
- Personal Information Protection and Electronic Documents Act (S.C. 2000, c. 5), subsection 4(1), paragraph 26(2)(b), section 10.1 and principle 4.1.3 of Schedule 1. Consulted on October 1, 2026.
- Commission d'accès à l'information du Québec (in French): main changes made by Law 25.