Quebec Law 25 and Dental Practices: What You Need to Know in 2026

Since September 2023, Law 25 (An Act to modernize legislative provisions respecting the protection of personal information) has been fully in effect in Quebec. For dental practices, this law creates concrete obligations — and real risks for non-compliance. In 2026, ignoring Law 25 is no longer an option.

What Is Law 25?

Law 25 is the most significant reform of personal information protection in Quebec since the 1990s. It modernizes the Act respecting the protection of personal information in the private sector and aligns Quebec with international standards, notably the European GDPR.

For dental practices, Law 25 acknowledges a simple reality: you collect and process sensitive personal information every day — names, contact details, health card numbers, medical histories, payment information. You have a legal responsibility to protect it.

It's also worth noting the federal counterpart: PIPEDA (Personal Information Protection and Electronic Documents Act) applies to interprovincial transactions. For most Quebec dental practices operating locally, Law 25 is the primary framework, but awareness of PIPEDA is valuable if you operate across provincial lines.

Obligations for Dental Practices

Law 25 imposes several obligations that apply directly to your practice:

1. Informed consent: You must obtain explicit consent from patients before collecting, using, or sharing their personal information. Consent must be freely given, informed, specific to defined purposes, and revocable.

2. Transparency: Your practice must have an accessible privacy policy explaining what information is collected, why, how it's used, and with whom it's shared.

3. Data security: Appropriate security measures must protect personal information against unauthorized access, disclosure, or destruction. This includes your computer systems, emails, and any recorded phone communications.

4. Right to erasure: Patients can request deletion of their personal information when it's no longer needed for the purposes for which it was collected. You must have a process to handle these requests.

What the Law Says About Call Recordings

This section is especially relevant for dental practices that use a call recording system — or that are considering adopting an AI receptionist.

Law 25 is clear: if you record your patients' phone conversations, you must:

  • Inform the patient that the conversation is being recorded, ideally at the start of the call
  • Store recordings securely, preferably on servers located in Canada
  • Restrict access to recordings to those who need them
  • Delete recordings when they are no longer needed

Storage outside Canada (for example, on U.S. servers) is permitted under certain conditions, but is strongly discouraged for health information due to legal risks associated with U.S. laws like the Cloud Act.

How Zenicall Helps You Stay Compliant

Zenicall was built with Law 25 compliance as a core requirement — not an afterthought.

  • Canadian hosting: All data and transcriptions are stored on servers located in Canada, eliminating risks related to cross-border data transfers.
  • End-to-end encryption: Communications and stored data are encrypted, protecting your patients' information against unauthorized access.
  • Verbal consent collection: Zenicall informs each caller that the conversation may be recorded and collects verbal consent before any interaction begins.
  • Deletable transcriptions: Your Zenicall dashboard allows you to delete transcriptions and recordings at any time, making it easy to honour patients' right to erasure.
  • Restricted access: Only team members you authorize can access transcriptions and call reports.

Penalties for Non-Compliance

The Commission d'accès à l'information (CAI) of Quebec is responsible for enforcing Law 25. Penalties for non-compliance are severe:

For an organization: Up to $25 million Canadian or 4% of global revenue, whichever is higher. These amounts apply to serious violations, such as an unreported data breach.

For less serious violations, administrative fines can reach $10 million or 2% of revenue. For a dental practice, even a fine of a few thousand dollars can have a significant impact — not counting the reputational damage.

Beyond fines, a data breach exposing patients' personal information must be reported to the CAI and to each affected patient. The costs of notification, crisis management, and loss of patient trust can far exceed the fine itself.

First Step: Take Inventory of Your Data

Law 25 compliance begins with a simple inventory: what personal information do you collect, where is it stored, who has access, and how is it protected? If you can't answer those questions precisely, that's a signal that adjustments are needed.

For phone communications, Zenicall provides a turnkey solution that handles compliance end-to-end — from initial consent to secure data deletion. You focus on dental care; we handle phone compliance.

Your practice software

Appointments land straight in your software, not in an inbox.

Compare before choosing

We also say where other solutions do better than us.

Go further