Quebec's Law 25 — formally the Act to modernize legislative provisions as regards the protection of personal information — places strict obligations on Quebec organizations regarding how personal information is collected, hosted and moved. The email signature, often overlooked in audits, is directly affected: it contains personal information and, depending on the solution chosen, is sometimes routed through foreign servers.
What is Law 25?
Law 25 is Quebec's reform of personal information protection, which came into force in stages from 2022 to 2024. It modernizes the rules for enterprises and public bodies that collect, use or communicate the personal information of individuals located in Quebec. It is administered by the Commission d'accès à l'information (CAI).
It introduces obligations of transparency, the notion of clear consent, the right to erasure, the appointment of a person in charge of personal information protection, and the duty to assess risks before certain data communications. Breaches expose organizations to administrative and penal sanctions of up to CAD $25M or 4% of worldwide turnover, depending on the applicable provision.
Which signatures are affected?
Any signature that identifies a natural person is covered. In practice, nearly every company signature is: it shows an employee's name, title, a phone number, sometimes a photo. These elements are personal information under the law as soon as they make the person identifiable.
When signatures are managed centrally by an external provider, that provider acts as a service provider. The organization entrusts it with personal information — it must therefore govern the relationship, but it remains accountable.
Personal information in a signature
A good practice is to limit the signature to genuinely useful professional contact details, and to leave out sensitive or superfluous data:
- Generally appropriate: name, title, organization name, professional email and phone, website.
- Handle with care: photo, personal mobile number, links to private profiles — include only with a clear reason.
- Avoid: any personal information unrelated to the professional role.
Managing these fields centrally — rather than letting each employee compose their own signature — makes it easier to apply these rules uniformly and to update them when someone leaves the organization.
Canadian hosting and transfers outside Quebec
Law 25 does not require data to be hosted in Quebec. However, before communicating personal information outside Quebec, an organization must carry out a privacy impact assessment that takes into account, among other things, the legal framework of the destination territory.
In practice, choosing a provider that hosts data in Canada and does not route email out of the country avoids that transfer, lightens the assessment burden and reduces legal exposure. This is one of the few points where the tool's technical architecture has a direct effect on compliance.
Client-side or server-side: why it matters
Signature solutions fall into two families, with very different consequences for how data moves:
| Criterion | Server-side (relay) | Client-side (add-in) |
|---|---|---|
| Where the email is routed | Every message passes through the vendor's servers | The message never leaves Microsoft 365 |
| Email content exposed to the third party | Yes, to apply the signature | No |
| Transfer outside Canada | Possible if servers are abroad | Avoided when hosting is Canadian |
| Law 25 exposure | Higher (routing + data residency) | Reduced |
ATOM Signatures works client-side: the signature is inserted by an add-in in Outlook, at compose time. The email is never routed through a third-party server, and the configuration data is hosted in Canada.
Compliance checklist for your signatures
- Inventory the personal information present in your signatures (names, titles, contact details, photos).
- Limit the content to the professional contact details that are strictly useful.
- Verify where the provider hosts the data and where the email is routed.
- Require a contract covering hosting, security and deletion of the data.
- Plan for data deletion at the end of the relationship (right to erasure).
- Document these choices in your processing register.
Frequently asked questions
Does Law 25 apply to email signatures?
Yes. As soon as a signature contains an employee's personal information (name, title, contact details), it falls under Law 25. The organization must know where that data is hosted, govern any transfer outside Quebec, and be able to delete it.
Where should signature data be hosted?
Law 25 does not require hosting in Quebec, but it requires an assessment before any personal information is communicated outside Quebec. Choosing a provider that hosts data in Canada avoids that transfer and simplifies compliance.
Does a server-side signature create a compliance problem?
It warrants scrutiny. In the server-side approach, every email is routed through the vendor's servers to receive its signature. If those servers are outside Canada, the email content — often carrying personal information — leaves the country. The client-side approach avoids that routing.
Who is responsible for compliance, the organization or the vendor?
The organization remains accountable for its employees' personal information, even when a provider manages the signatures. A contract covering hosting, security and deletion is required, but accountability stays with the organization.
Compliant signatures, hosted in Canada. ATOM Signatures automatically applies your organization's signature in Outlook, client-side, with 100% Canadian hosting.
Go further: the complete Microsoft 365 email signature guide and Canadian data residency.
Sources
- Commission d'accès à l'information du Québec — cai.gouv.qc.ca
- Law 25 (official text) — LégisQuébec
This article is provided for information purposes and does not constitute legal advice. To assess your situation, consult a legal advisor or the Commission d'accès à l'information.