Back to resources
PrivacyArticle

Privacy officer under Law 25: role and how to appoint one

Since 22 September 2022, failing to name someone does not leave the role empty. The person with the highest authority is then responsible.

7 min readSeptember 2026

Law 25 requires the enterprise to designate a person in charge of the protection of personal information. Their title and contact details are published on the website, or made available by another means if there is no website. Access requests, incidents and questions from the Commission go through that person.

Who can be designated

A manager, legal counsel, or an external person who performs the function. In a small organization it is often the chief executive. What matters is that the email is read, not that the title sounds formal.

What the person actually does

They receive access, correction and portability requests. They are involved when a confidentiality incident must be reported. They check that the published policy matches real activities. They do not have to draft every assessment alone, but they need to know where those assessments are kept.

What to publish

The title and a way to reach them, on the site, in a stable place. An address such as privacy@company.ca is enough if someone handles it. A name with no contact details, or a page nobody can find, does not meet the duty.

The most common gap

Leaving the president as privacy officer by default, without them knowing, and without staff knowing where to send a request. Write the designation, publish it, and tell the team where to forward an email that arrives.

An officer who can see requests and incidents

CapPRP groups requests from individuals, incidents and the register for the person you designated.