Coworking for Confidential Work: Privacy, Security, and Quebec's Law 25

A lawyer drafting a settlement, an accountant reviewing a client's tax file, a financial advisor discussing a portfolio, or a healthcare consultant reading a patient intake form all handle the kind of personal and confidential information that makes "should I work from a coworking space" a genuinely different question than it is for a marketing freelancer or a software contractor. Quebec's Law 25 has raised the stakes on that question since it started coming into force in 2022, and regulated professionals reasonably want to know whether an open, shared workspace is even compatible with their privacy and professional-conduct obligations. The short answer is that Law 25 does not single out coworking, or any other physical arrangement, for special treatment: your obligations as a business handling personal information are the same whether you work from a shared floor, a home office, or a traditional leased suite. What changes in a shared environment is not the legal standard, it is how much deliberate effort it takes to meet it. This guide walks through what Law 25 actually requires, what additional confidentiality duties apply to certain regulated professions, and the concrete physical and digital safeguards that make a coworking space workable, or not, for confidential client work.

2727 Coworking - workspace

Executive Summary

  • Law 25's obligations attach to the personal information a business handles, not to the type of workspace it operates from; nothing in the law creates a coworking-specific exemption or a coworking-specific extra burden [7]
  • Since September 22, 2022, every business subject to Quebec's private-sector privacy law must designate a person responsible for the protection of personal information, by default the highest-ranking person in the organization, and publish that person's title and contact information [1]
  • The bulk of Law 25's remaining obligations, including new consent rules, mandatory privacy policies, and privacy impact assessments, took effect on September 22, 2023 [3][2]
  • Businesses must implement security measures that are "reasonable" given the sensitivity, purpose, quantity, distribution, and storage format of the personal information involved, spanning administrative, physical, and technical safeguards [4]
  • Non-compliance can carry serious financial consequences: administrative monetary penalties of up to $10 million or 2% of worldwide turnover, and penal fines of up to $25 million or 4% of worldwide turnover, whichever amount is greater in each case [5]
  • For certain professions, confidentiality obligations that predate and exceed Law 25 still apply in full: a lawyer's duty of professional secrecy, for example, "applies at all times" under the Barreau du Québec's own guidance, regardless of where the lawyer happens to be sitting when the information is handled [6]

What Law 25 Actually Requires

Law 25, formally the Act to modernize legislative provisions as regards the protection of personal information, overhauled Quebec's private-sector privacy regime and phased in its requirements over three years rather than all at once. The first tranche of obligations took effect on September 22, 2022, and required businesses to designate a person responsible for the protection of personal information and to begin maintaining a confidentiality incident register, along with reporting incidents that present a risk of serious harm [3]. The great majority of the law's remaining substance came into force on September 22, 2023: new granular consent requirements, an obligation to publish a public-facing privacy policy, mandatory privacy impact assessments for projects involving personal information, and rules governing the transfer of personal information outside Quebec, among others [2]. A final set of provisions, centered on the right to data portability, took effect on September 22, 2024, closing out the phased rollout [8].

Two obligations sit at the center of the question a regulated professional is really asking when they wonder whether coworking is compatible with Law 25: the security-safeguards requirement, and the requirement to designate a responsible person.

Reasonable security safeguards. The Commission d'accès à l'information du Québec (CAI), the regulator responsible for enforcing the law, states that the security measures a business puts in place must be reasonable, taking into account the sensitivity of the personal information, the purpose for which it is used, the quantity and distribution of the information, and the medium on which it is stored [4]. Notably, the CAI does not prescribe a specific list of physical arrangements or a specific type of office. Instead it describes a risk-based framework built around administrative measures (policies, staff training, an incident-response plan), physical measures (controlled access to premises, secure document storage), and technical measures (encryption, access controls, secure destruction of data, activity logging) [4]. A business handling large volumes of highly sensitive information, medical records or financial account details, for instance, needs stronger safeguards than one handling a short client contact list, regardless of whether either business works from a coworking space, a home office, or a conventional lease.

The person responsible for protection of personal information. Every business subject to the law must have someone accountable for compliance. By default, this responsibility falls to the person holding the highest position in the business, such as its owner or executive director, though it can be delegated in writing, in whole or in part, to another qualified individual [1]. Delegation does not remove accountability: the highest-ranking person remains legally responsible for the business's compliance even after handing day-to-day duties to someone else, and must give that delegate sufficient resources to actually do the job [1]. The title and contact information of this person must be published on the business's website or, if it has none, communicated to the public by another appropriate means. For a solo practitioner, lawyer, accountant, or financial advisor operating alone, this simply means the practitioner is, by default, their own privacy officer.

The financial stakes for getting this wrong are not trivial. The CAI can levy administrative monetary penalties of up to $10 million or 2% of a business's worldwide turnover for the preceding fiscal year, whichever amount is greater, and Quebec's courts can impose penal fines of up to $25 million or 4% of worldwide turnover, with a minimum fine of $15,000 for corporations and doubled fines for repeat offences [5]. For most solo practitioners and small firms these maximums are largely theoretical, penalties scale with the severity of the violation and the size of the business, but they signal how seriously the CAI is empowered to treat a security or governance failure.

Does Working From a Coworking Space Create Extra Obligations Under Law 25?

No, and this is the single most important point for a regulated professional evaluating coworking against a private office or a home office: the CAI's guidance on security measures and on the responsible-person requirement makes no reference to office type, floor plan, or lease structure at all [7]. The law asks what personal information you collect, why you collect it, how you store and protect it, and what happens to it when you no longer need it. A shared coworking floor does not change any of those answers on its own, and Law 25 imposes no special coworking clause, no requirement to disclose your workspace arrangement to the CAI, and no automatic disqualification of shared workspace as a place of business.

What does change in a shared environment is the practical difficulty of meeting the same standard. "Reasonable security measures" is a standard that adjusts to context, and the CAI's own risk-based framework, sensitivity, quantity, distribution, and format of the information, means that a lawyer handling privileged client files or a financial advisor handling account numbers is expected to apply stronger physical and technical safeguards than someone processing a short mailing list, no matter where they work. In a private, single-tenant office, some of those safeguards exist almost by default: a closed door, no foot traffic from strangers, a lock the practitioner controls exclusively. In an open coworking floor, those same protections have to be assembled deliberately, a private office or phone booth for calls, locking storage for documents, and a properly segmented network, rather than assumed. The legal bar does not move. The amount of intentional setup required to clear it does.

Confidentiality Duties That Go Beyond Law 25

Law 25 sets a general floor for how any business in Quebec must handle personal information, but several regulated professions carry confidentiality obligations that are older, narrower, and in some respects stricter than the general privacy law. These obligations come from professional orders and their codes of ethics, not from Law 25 itself, and they typically survive Law 25 compliance rather than being replaced by it.

The clearest example is the legal profession. The Barreau du Québec's own guidance to lawyers states plainly that a lawyer must protect professional secrecy, and that "this duty applies at all times" [6]. Professional secrecy for lawyers in Quebec is not simply a rule of good practice, it is treated as a fundamental right of the client, it survives the end of the lawyer-client relationship, and only the client can waive it. A lawyer may disclose otherwise-protected information only in narrow circumstances, such as to recover unpaid fees or to defend against a complaint about their own conduct [6]. This obligation is entirely independent of where a lawyer's desk sits. A confidential conversation overheard through a thin partition, or a client file glimpsed on an unattended screen, is a professional secrecy problem whether it happens in a shared coworking space or in a traditional law firm's own hallway, and the remedy is the same in both settings: control the physical and visual exposure of the conversation or the document, not the address on the lease.

Other regulated professions in Quebec, including accountants, healthcare professionals, and financial advisors, operate under similar confidentiality duties set out in their own professional order's code of ethics, generally requiring that client or patient information be kept confidential except in narrowly defined circumstances. This guide does not attempt to summarize each order's specific rules, since they vary by profession and are periodically updated, and this is exactly the kind of question a reader should direct to their own professional order or a lawyer rather than rely on a general coworking guide to answer. Nothing in this article should be read as legal advice, and a professional with specific Law 25 compliance questions or professional-order obligations should consult a lawyer or their governing body directly before making decisions based on it.

Practical Safeguards That Make Confidential Work in Coworking Viable

None of the obligations above rule out coworking. They do mean the physical and digital setup has to be chosen deliberately rather than defaulted into. The following safeguards address the gap between an open floor plan and the kind of environment confidential work actually requires.

Enclosed spaces for calls and conversations. Any conversation involving a client's name, case details, account numbers, or health information belongs in a private office or a phone booth, not at an open desk. A private, lockable office removes the two biggest open-floor risks at once: being overheard, and having a screen visible to passersby.

Locking storage for physical documents. Paper files, signed contracts, and printed statements need a locked drawer or cabinet that only the practitioner can access, not a shared shelf or an unattended desk. A clean-desk habit, nothing confidential left visible when stepping away, matters as much in coworking as the storage itself.

Screen privacy filters. A simple privacy screen on a laptop meaningfully reduces the risk of a client's information being read over someone's shoulder in a shared area, at a cost of a few dollars.

Device encryption and a VPN. Full-disk encryption protects a lost or stolen laptop, and a VPN protects data in transit on any network, shared or otherwise. Neither is coworking-specific, but both matter more in an environment where the underlying network is used by people outside the practitioner's own firm.

A properly segmented network. Shared coworking Wi-Fi, if not properly configured, can expose members to unauthorized access or interception risk on the same network as other tenants [9]. A reputable operator should offer network segmentation, separate credentials, or a private connection option so that one member's traffic is not visible to another's.

Soundproofed meeting rooms with no line of sight from open areas. For meetings rather than solo calls, the same principle applies at a larger scale: a well-designed meeting room uses sound-absorbing materials, sound masking, and layout choices that keep a confidential conversation from carrying into the surrounding floor, and keeps the room itself out of casual sightlines from open desks [10]. Our guide to renting a meeting room in Montreal covers what to look for when booking a room specifically for client-facing or confidential discussions.

Whether a practitioner needs a full private office or can get by with a dedicated desk plus meeting-room access for calls depends on how much of the day involves confidential conversations. Our comparison of hot desks, dedicated desks, and private offices covers that trade-off directly, and generally concludes that professionals handling confidential client information should default to a private office regardless of team size, since an enclosed, lockable room is close to a practical necessity rather than an optional upgrade for this kind of work.

Questions to Ask a Coworking Operator Before Signing Up

A regulated professional evaluating a coworking space for confidential work should get specific answers to the following before signing anything, rather than assuming a shared space handles these details by default:

  1. Do private offices lock, and who holds the key or access code? A lockable door that only the practitioner controls is the baseline, not an upgrade.
  2. Is there secure, on-site document shredding or storage? Ask specifically whether locking file storage is available, and how confidential paper waste is destroyed.
  3. Is the internet on a shared network or a segmented, private one? Ask whether the operator offers a private VLAN, separate credentials per member, or another form of traffic isolation, not just "high-speed Wi-Fi."
  4. Are meeting rooms soundproofed, and are they visible from open work areas? Glass-walled rooms look professional but can undermine acoustic privacy if there is no sound treatment or masking.
  5. Who else has access to the building outside business hours, and is there a front-desk or reception presence? Controlled building access reduces the risk of an unauthorized person walking through open areas where documents or screens might be visible.
  6. What is the operator's incident-response process if a security or privacy issue occurs on-site? A serious operator should have a clear answer, not a blank look.

At 2727 Coworking in Griffintown, private offices come with lockable doors, the building maintains controlled access, and meeting rooms are designed with acoustic separation from the open floor, addressing the core questions above directly rather than as an afterthought. Private offices start from $650 a month, meeting rooms and day passes for desk work start from $55 a day, and a Virtual Mailbox, useful for practitioners who want a compliant business address without committing to daily desk space, starts from $35 a month. For a practitioner who mainly needs a professional mailing address and occasional access to a private room for client calls rather than a full-time desk, our guide comparing a virtual office against a full coworking membership walks through that decision in more detail.

Frequently Asked Questions

Does Law 25 prohibit lawyers, accountants, or healthcare professionals from working out of a coworking space?

No. Law 25 does not mention coworking, shared offices, or any specific workspace type. It requires businesses to implement reasonable security safeguards and designate a person responsible for protecting personal information, obligations that apply the same way regardless of where the work happens. The practical challenge is meeting those obligations in an open environment, not a legal prohibition on the environment itself.

Do I need a separate privacy policy just because I work from a coworking space?

No, the privacy policy requirement under Law 25 applies to your business based on the personal information you collect and process, not based on your workspace. You need a compliant privacy policy because you handle personal information as part of your practice, the same requirement would apply if you worked from a traditional office or a home office.

Is a private office actually required, or is a dedicated desk enough for confidential work?

It depends on how much of your work involves confidential conversations or documents. A dedicated desk in an open area works for administrative tasks, but any regular client calls, document review, or discussion of sensitive details should happen in a private office or booked meeting room. Many regulated professionals use a dedicated desk for general work and rely on private rooms specifically for confidential interactions.

Who counts as the "person responsible for protection of personal information" if I am a solo practitioner?

By default, you are. Quebec's rule assigns this responsibility to the highest-ranking person in the business, and for a solo practitioner, that is simply you. You can formally delegate parts of the role if you bring on staff later, but as a sole practitioner there is generally no one else to delegate to.

Does using a coworking space's shared Wi-Fi violate Law 25?

Not automatically, but it can create the kind of security gap Law 25 expects you to address. If a network is not properly segmented and someone else on it could plausibly intercept your traffic, that is a security risk you are responsible for managing, whether through a VPN, a private network offered by the operator, or both. Ask the operator directly how their network is segmented before relying on it for confidential work.

What should I do if a confidentiality breach happens while I am working from a coworking space?

Treat it the same way you would anywhere else: assess whether the incident creates a risk of serious harm, and if so, you are required to notify the CAI and the affected individuals, and to log the incident in your confidentiality incident register. The physical location of the incident does not change these obligations.

Is this article legal advice?

No. This guide provides general information about Law 25 and coworking, not legal advice, and it does not address every professional order's specific rules. If you have questions about how Law 25 or your professional order's code of ethics applies to your specific practice, consult a lawyer or contact your professional order directly.

Confidential client work deserves a workspace built for it. 2727 Coworking's private offices lock, its meeting rooms are designed for acoustic privacy, and its Griffintown location gives regulated professionals a controlled, professional environment for calls, document review, and client meetings. Call (438) 796-0017 or visit 2727 Coworking to see the private offices and book a tour.

References

[1] Responsabilité des entreprises, Commission d'accès à l'information du Québec

[2] Des dispositions de la Loi 25 qui entrent en vigueur aujourd'hui, Commission d'accès à l'information du Québec

[3] Quebec's Law 25: Many Provisions Take Effect Today, Greenberg Traurig LLP

[4] Incidents de confidentialité et mesures de sécurité, Commission d'accès à l'information du Québec

[5] Law 25: A New Enforcement Scheme for Protection of Personal Information in the Private Sector in Quebec, Osler, Hoskin and Harcourt LLP

[6] Confidentialité, Barreau du Québec

[7] Champ d'application de la loi, Commission d'accès à l'information du Québec

[8] Principaux changements apportés par la Loi 25, Commission d'accès à l'information du Québec

[9] Evaluating Coworking Spaces: Key Factors for Businesses, 2727 Coworking

[10] Principles of Conference Room Design in Coworking Spaces, 2727 Coworking