6.19.2026
0
min read

Bill 25: What Unions Need to Know About Their Digital Communications

Bill 25 applies to unions. Here is what it means concretely for your member lists, your communications, and the digital tools your organization uses.

What Bill 25 Requires from a Union

Bill 25 applies to any organization that collects, uses, or communicates personal information in Quebec. A union falls under this definition. Member names and contact details, participation data from votes and assemblies, documents related to representation and negotiations: all of this has value and deserves to be protected.

[IMAGE PLACEHOLDER: union assembly or member meeting]

A Designated Privacy Officer

Every organization must appoint a person responsible for the protection of personal information. By default, this is the person with the highest authority, until a formal delegation is documented.

An Incident Register

If personal information is compromised, the organization must document the incident. Depending on the severity, it must also notify the Commission d'accès à l'information and the individuals concerned.

Rules on Consent and Retention

Information collected must serve specific purposes. It cannot be kept indefinitely without justification.

A Right of Access for Members

Members can request to consult the personal information the union holds about them and ask for corrections.

The Problem With Consumer-Grade Tools

"We have nothing to hide, our members trust us."

Bill 25 is not about bad intentions. It is about control.

[IMAGE PLACEHOLDER: social media apps on phone screen]

When union communications run through a Facebook group, member data is processed by Meta. Privacy settings change without notice. If someone leaves the union and is removed from the group, their past interactions remain on Meta's servers. Messenger, WhatsApp, and personal email have the same structural problem: these tools were designed for individual use, not for the governance of an organization representing hundreds or thousands of workers.

In practice, this creates three concrete gaps.

No traceability. Who received what, when? Hard to document when communications are spread across five different channels.

No access control. A retired member, a worker in dispute: are they still in the Facebook group? In the WhatsApp thread? On Messenger? In most cases, nobody follows up systematically.

Hosting outside Canada. Facebook, Google, WhatsApp: servers are in the United States. Quebec member data passes through them. Bill 25 does not explicitly prohibit this, but the transparency and control obligations become much harder to satisfy.

What Deserves Special Attention in Union Communications

Bill 25 touches the entire lifecycle of information, not just its collection.

Retention

How long does your union keep member lists? Assembly documents? Exchanges related to a negotiation? If the answer is unclear, that is a point to address.

Access

Who in your executive has access to what? Does a regional delegate need to see the contact details of all members? Does a mobilization coordinator need access to confidential negotiation documents? Access control by role and group is not a technical detail. Bill 25 makes it a duty of care.

External Service Providers

When a union uses an external service for mass emails like Mailchimp or a survey tool like SurveyMonkey, it remains responsible for the protection of shared data. The privacy policies of these services must be reviewed carefully.

[IMAGE PLACEHOLDER: data security or document management]

What It Costs to Ignore This

A privacy incident in a union is not primarily a fine. It is damage to the relationship with the members the union represents.

On the ground, the most common consequences are rarely legal sanctions. They are embarrassing situations: a former member still accessing internal communications, a member list circulating by email without encryption, a negotiation document shared in the wrong group. These gaps are avoidable. When they happen, the executive spends time managing the fallout instead of working on the files that matter.

Where to Start

A few concrete steps can significantly reduce exposure without rebuilding everything at once.

Designate a responsible person officially, with documented delegation. Review access to communication tools: who is in which groups, when were the lists last updated. Establish a minimal retention policy, even a basic one. And centralize official communications in a channel where your organization controls who sees what, where data is hosted, and where governance belongs to you.

A union that takes Bill 25 seriously does not do so only to avoid a sanction. It does so because its members entrust it with their personal information, and that trust is earned with every decision.

How we help

No more member data scattered across Facebook groups, Messenger threads, and unstructured email chains.

Fortisia centralizes your union's communications in a structured environment, hosted in Canada, with access defined by role, group, and local section.

Your members get direct access to:

  • Official communications from the executive
  • Important documents in a secure space
  • A channel controlled by your organization, not an algorithm
  • Role-based access management without manual list handling

Result: your data stays in Canada, your access is documented, your governance holds up.

See the security and confidentiality page →

Frequently Asked Questions

Does Bill 25 really apply to unions, not just businesses?

Yes. Bill 25 applies to any organization that collects, uses, or communicates personal information in Quebec, regardless of its legal nature. A union managing a member list, participation data, or representation documents is subject to the same requirements as a private company.

What counts as personal information in a union context?

A member's name, address, phone number, email, employment status, and union participation information are all personal information under the law. Representation documents that identify a member individually also fall into this category.

What does a union risk by not designating a privacy officer?

The Commission d'accès à l'information can impose administrative monetary penalties. But beyond fines, the absence of a designated officer means no one is monitoring incidents, documenting practices, or responding to member access requests. The operational risk is often more immediate than the legal one.

Can a union that uses Facebook be compliant with Bill 25?

Technically possible, but hard to maintain. The law requires control over data shared with third parties, access traceability, and the ability to respond to member requests. Facebook does not allow these requirements to be met rigorously: data moves to American servers, access is difficult to audit, and privacy settings change without notice.

How often should a union review its privacy practices?

The law does not set a specific frequency, but an annual review is good practice. Natural triggers include changes to digital tools, adding a new provider, an executive election, or a privacy incident, even a minor one.

Ready to upgrade your union?

Discover how Fortisia can improve communication between you and your members.