If your business collects, stores, or processes personal information from anyone living in Quebec, the answer is almost certainly yes, regardless of where your company is headquartered. Law 25 is not optional and it is not a "nice to have" privacy badge. It is Quebec's private-sector privacy statute with real fines attached, and it applies based on whose data you hold, not where your office sits.
What Law 25 Actually Requires (In Plain Language)
Law 25, formerly Bill 64, amended Quebec's private-sector privacy law and phased in requirements between September 2022 and September 2024. The core obligations now in force include:
- A named privacy officer responsible for compliance
- Privacy impact assessments before certain data transfers or new projects involving personal information
- Mandatory breach notification to Quebec's privacy regulator, the Commission d'accès à l'information (CAI), and to affected individuals
- Consent requirements that are more prescriptive than PIPEDA's, including clear, separate consent for sensitive data
- A right to data portability and the right to request deletion
- Rules governing automated decision-making, including a right to be informed when a decision about someone is made solely by an algorithm
This is meaningfully stricter than baseline PIPEDA obligations, and it is the closest thing Canada has to GDPR-style enforcement. If you already treat PIPEDA as a checkbox, Law 25 will feel like a step change.
Who Genuinely Needs Law 25 Compliance
You need to take Law 25 seriously if any of the following describe your business:
- You have customers, users, or employees based in Quebec, even a small number
- You run a SaaS product with any Canadian sign-up flow and do not geofence Quebec out
- You process payment, health, or biometric data touching Quebec residents
- You use automated decision systems (credit scoring, fraud flags, hiring screens) that could affect a Quebec resident
- You are a B2B vendor whose customer contracts require Law 25 attestation, which is increasingly common in RFPs from Quebec-based enterprises and public bodies
Notably, Law 25 has no minimum revenue or headcount threshold. A five-person startup in Toronto with one Quebec customer has the same legal exposure, proportionally, as a national bank. That surprises a lot of founders.
Who Is Over-Buying Law 25 Compliance
Here is where honesty matters more than upsell. Some companies come to us asking for full Law 25 program builds when they do not need one yet:
- US-only or Ontario-only businesses with zero Quebec footprint. If you have deliberately geofenced Quebec or have no plans to sell there, Law 25 does not apply to you today. Do not pay for a compliance program against a jurisdiction you are not operating in.
- Early-stage startups pre-product-market fit. If you have no customers in Quebec and no near-term plan to expand there, a full privacy impact assessment framework is premature. A lightweight privacy policy and a plan to revisit at your next funding round is proportionate.
- Companies conflating Law 25 with SOC 2. These solve different problems. SOC 2 proves your security controls to enterprise buyers; Law 25 is a legal privacy obligation triggered by Quebec residents' data. Some vendors will happily sell you both bundled together whether you need it or not.
The honest test is simple: do you currently handle, or will you within the next 12 months handle, personal information belonging to someone who lives in Quebec? If not, your dollars are better spent elsewhere in your compliance roadmap.
The Real Penalties Behind Quebec's Privacy Stick
Law 25 gave the CAI teeth that PIPEDA never had. Administrative monetary penalties can reach the greater of $10 million or 2 percent of worldwide turnover for corporations, with penal fines reaching the greater of $25 million or 4 percent of worldwide turnover for the most serious violations. Individuals face separate, smaller fine ranges. These figures are set in the statute itself, not our estimate, and they scale with global revenue, not just Quebec revenue, which is what catches companies off guard.
Beyond the fines, the CAI has shown it will act. Breach notification triggers regulatory scrutiny, and enterprise procurement teams in Quebec now routinely ask vendors to attest to Law 25 readiness as a contract condition. Losing a deal over an unanswered privacy questionnaire is a quieter but just as real cost.
Law 25 in the Wider Canadian Privacy Picture
Quebec is ahead of the rest of the country here. PIPEDA still governs federally regulated businesses and provinces without their own substantially similar law, and reform at the federal level has stalled repeatedly. That leaves Quebec as the strictest, most enforced privacy regime a Canadian or cross-border company is likely to encounter domestically. For companies building out of Toronto, Waterloo, Ottawa, Vancouver, Calgary, or Montreal, Law 25 is frequently the first real privacy compliance test they face, well before GDPR ever becomes relevant.
How to Decide Without Guessing
Rather than defaulting to "better safe than sorry" spending, map your actual data flows: where your customers and employees are located, what personal information you collect, and whether any automated decisions touch Quebec residents. That exercise alone tells you whether you are in scope, and if you are, how much program you actually need versus what a vendor might try to sell you. We've built out the specifics of scope, obligations, and implementation steps in our Quebec Law 25 framework guide, which is a useful next stop if you want the compliance detail without the sales pitch.
If Law 25 is one piece of a broader compliance push, for example alongside SOC 2 for a US-bound SaaS deal, it is worth looking at how the pieces fit together rather than buying them as separate engagements. Our compliance solutions page lays out how we sequence privacy, security, and framework work so you are not paying twice for overlapping controls.
Get an Honest Read on Your Exposure
If you are unsure whether Law 25 applies to your business, or you suspect a vendor is trying to sell you more compliance than your actual risk warrants, talk to us. TrazTech is a boutique Canadian security and compliance consultancy, and we will tell you plainly if you do not need what you are asking for. Contact us for a straight assessment of your Quebec privacy exposure and what, if anything, needs to change.
The obligations companies miss most often
Teams that decide they are in scope usually get the visible items done: a privacy policy refresh, a consent banner, a designated officer. The misses are quieter, and they are what a complaint or a procurement review surfaces first.
Publishing the privacy officer. The role defaults to the person with the highest authority unless delegated in writing, and the title and contact details belong on your website. A named person in an internal document with nothing on the site is a ten-minute gap that stays open for years.
Keeping a register of confidentiality incidents. Every incident goes in the register, not only the ones that met the notification threshold. The regulator can ask for it. Companies that log only reportable breaches cannot show the judgement they applied to the ones they chose not to report, which is the judgement that gets questioned.
Assessing transfers outside Quebec. If personal information is communicated outside the province, and for most SaaS companies it is the moment a US cloud region is involved, an assessment of the privacy implications is expected before the transfer, along with contractual terms with the recipient. Naming your subprocessors is not the same as having assessed them.
Language. Notices, consent text, and the terms you rely on need to work for a French-speaking user. An English-only consent flow is fragile under both privacy expectations and Quebec's separate language obligations, and it is the first thing a Quebec buyer notices.
What a privacy impact assessment actually contains
The phrase intimidates people because it sounds like an audit. In practice it is a short structured document per project or transfer: what personal information is involved and how sensitive it is, why you need it and whether less would do, who receives it and where they sit, what security measures apply in transit and at rest, how long it is kept and what triggers deletion, and what risk remains once mitigations are applied. Five to eight pages, written by someone who understands the system and reviewed by the privacy officer.
The failure mode is doing one for a launch, filing it, and never doing another as the product changes. Tie the trigger to something your team already does, such as adding a subprocessor, a sensitive data field, or a new storage region. If it is not attached to an existing process, it will not happen twice.
The first 48 hours of a confidentiality incident
Notification obligations run on the risk of serious injury, and you have to make that determination quickly, with incomplete information, while your engineers are still working out what happened. Decide in advance who owns the call, usually the privacy officer with counsel involved, and what facts they need: which categories of information were exposed, how many Quebec residents are affected, whether the data was usable or protected, and whether there is evidence of malicious access.
Two practical points. Mitigating measures you take to reduce the risk of injury count toward that assessment, so record them with timestamps as you take them rather than from memory afterwards. And the same event usually triggers PIPEDA record-keeping and contractual notice clauses with enterprise customers, on clocks that are not aligned. Working out who calls whom mid-incident is how deadlines get missed, which is the argument for a plan rather than a retainer set out in our incident response piece.
The cheaper answer is often the right one
If you are a small team with a modest Quebec footprint, a full programme build is not proportionate and we will say so. The proportionate version is: name and publish an officer, write a data inventory that says where personal information sits and who it goes to, fix the consent flow so sensitive data is asked for separately and in French, stand up the incident register as a spreadsheet, and put one assessment on file for your main cross-border transfer. That is a few weeks of internal work, not a retained engagement.
Two other cases worth naming. If you serve Quebec residents only as employees rather than customers, your obligations are real but narrower, and an HR-focused review beats a product-wide programme. And if your real driver is a stalled deal rather than regulatory exposure, what you need is defensible answers to a buyer's questions, a documentation problem more than a legal one. That is closer to questionnaire work than to a privacy build.
What a Quebec enterprise buyer will ask
Public bodies and Quebec-based enterprises have converged on a short list: who is your privacy officer and can we see the page, where is our data stored and processed, have you assessed the transfer, what are your retention periods by data category, what is your incident notification commitment to us in hours, do you use automated decision-making on our data, and can we get a copy of your subprocessor list with locations. Every one of those should exist in writing before a deal reaches security review, because assembling them under pressure is where inconsistencies creep in. If you want the whole set handled as one body of work alongside security frameworks rather than as separate projects, that is what our compliance work is arranged around, and ongoing upkeep sits under a retainer when the obligations become continuous rather than one-time.
Privacy obligations piling up? Law 25 and PIPEDA readiness, with a named privacy officer where the law asks for one.
Privacy officerOr talk about a retainer