Bill 25 applies to any organization that collects, uses, or communicates personal information in Quebec. A union falls under this definition. Member names and contact details, participation data from votes and assemblies, documents related to representation and negotiations: all of this has value and deserves to be protected.
[IMAGE PLACEHOLDER: union assembly or member meeting]
Every organization must appoint a person responsible for the protection of personal information. By default, this is the person with the highest authority, until a formal delegation is documented.
If personal information is compromised, the organization must document the incident. Depending on the severity, it must also notify the Commission d'accès à l'information and the individuals concerned.
Information collected must serve specific purposes. It cannot be kept indefinitely without justification.
Members can request to consult the personal information the union holds about them and ask for corrections.
"We have nothing to hide, our members trust us."
Bill 25 is not about bad intentions. It is about control.
[IMAGE PLACEHOLDER: social media apps on phone screen]
When union communications run through a Facebook group, member data is processed by Meta. Privacy settings change without notice. If someone leaves the union and is removed from the group, their past interactions remain on Meta's servers. Messenger, WhatsApp, and personal email have the same structural problem: these tools were designed for individual use, not for the governance of an organization representing hundreds or thousands of workers.
In practice, this creates three concrete gaps.
No traceability. Who received what, when? Hard to document when communications are spread across five different channels.
No access control. A retired member, a worker in dispute: are they still in the Facebook group? In the WhatsApp thread? On Messenger? In most cases, nobody follows up systematically.
Hosting outside Canada. Facebook, Google, WhatsApp: servers are in the United States. Quebec member data passes through them. Bill 25 does not explicitly prohibit this, but the transparency and control obligations become much harder to satisfy.
Bill 25 touches the entire lifecycle of information, not just its collection.
How long does your union keep member lists? Assembly documents? Exchanges related to a negotiation? If the answer is unclear, that is a point to address.
Who in your executive has access to what? Does a regional delegate need to see the contact details of all members? Does a mobilization coordinator need access to confidential negotiation documents? Access control by role and group is not a technical detail. Bill 25 makes it a duty of care.
When a union uses an external service for mass emails like Mailchimp or a survey tool like SurveyMonkey, it remains responsible for the protection of shared data. The privacy policies of these services must be reviewed carefully.
[IMAGE PLACEHOLDER: data security or document management]
A privacy incident in a union is not primarily a fine. It is damage to the relationship with the members the union represents.
On the ground, the most common consequences are rarely legal sanctions. They are embarrassing situations: a former member still accessing internal communications, a member list circulating by email without encryption, a negotiation document shared in the wrong group. These gaps are avoidable. When they happen, the executive spends time managing the fallout instead of working on the files that matter.
.png)
A few concrete steps can significantly reduce exposure without rebuilding everything at once.
Designate a responsible person officially, with documented delegation. Review access to communication tools: who is in which groups, when were the lists last updated. Establish a minimal retention policy, even a basic one. And centralize official communications in a channel where your organization controls who sees what, where data is hosted, and where governance belongs to you.
A union that takes Bill 25 seriously does not do so only to avoid a sanction. It does so because its members entrust it with their personal information, and that trust is earned with every decision.
No more member data scattered across Facebook groups, Messenger threads, and unstructured email chains.
Fortisia centralizes your union's communications in a structured environment, hosted in Canada, with access defined by role, group, and local section.
Your members get direct access to:
Result: your data stays in Canada, your access is documented, your governance holds up.
Yes. Bill 25 applies to any organization that collects, uses, or communicates personal information in Quebec, regardless of its legal nature. A union managing a member list, participation data, or representation documents is subject to the same requirements as a private company.
A member's name, address, phone number, email, employment status, and union participation information are all personal information under the law. Representation documents that identify a member individually also fall into this category.
The Commission d'accès à l'information can impose administrative monetary penalties. But beyond fines, the absence of a designated officer means no one is monitoring incidents, documenting practices, or responding to member access requests. The operational risk is often more immediate than the legal one.
Technically possible, but hard to maintain. The law requires control over data shared with third parties, access traceability, and the ability to respond to member requests. Facebook does not allow these requirements to be met rigorously: data moves to American servers, access is difficult to audit, and privacy settings change without notice.
The law does not set a specific frequency, but an annual review is good practice. Natural triggers include changes to digital tools, adding a new provider, an executive election, or a privacy incident, even a minor one.