Security

Real offensive depth

Testing and defence led by a published security researcher with six CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Compliance

Do You Actually Need Quebec Law 25?

If your business collects, stores, or processes personal information from anyone living in Quebec, the answer is almost certainly yes, regardless of where your company is headquartered. Law 25 is not optional and it is not a "nice to have" privacy badge. It is Quebec's private-sector privacy statute with real fines attached, and it applies based on whose data you hold, not where your office sits.

What Law 25 Actually Requires (In Plain Language)

Law 25, formerly Bill 64, amended Quebec's private-sector privacy law and phased in requirements between September 2022 and September 2024. The core obligations now in force include:

  • A named privacy officer responsible for compliance
  • Privacy impact assessments before certain data transfers or new projects involving personal information
  • Mandatory breach notification to Quebec's privacy regulator, the Commission d'accès à l'information (CAI), and to affected individuals
  • Consent requirements that are more prescriptive than PIPEDA's, including clear, separate consent for sensitive data
  • A right to data portability and the right to request deletion
  • Rules governing automated decision-making, including a right to be informed when a decision about someone is made solely by an algorithm

This is meaningfully stricter than baseline PIPEDA obligations, and it is the closest thing Canada has to GDPR-style enforcement. If you already treat PIPEDA as a checkbox, Law 25 will feel like a step change.

Who Genuinely Needs Law 25 Compliance

You need to take Law 25 seriously if any of the following describe your business:

  • You have customers, users, or employees based in Quebec, even a small number
  • You run a SaaS product with any Canadian sign-up flow and do not geofence Quebec out
  • You process payment, health, or biometric data touching Quebec residents
  • You use automated decision systems (credit scoring, fraud flags, hiring screens) that could affect a Quebec resident
  • You are a B2B vendor whose customer contracts require Law 25 attestation, which is increasingly common in RFPs from Quebec-based enterprises and public bodies

Notably, Law 25 has no minimum revenue or headcount threshold. A five-person startup in Toronto with one Quebec customer has the same legal exposure, proportionally, as a national bank. That surprises a lot of founders.

Who Is Over-Buying Law 25 Compliance

Here is where honesty matters more than upsell. Some companies come to us asking for full Law 25 program builds when they do not need one yet:

  • US-only or Ontario-only businesses with zero Quebec footprint. If you have deliberately geofenced Quebec or have no plans to sell there, Law 25 does not apply to you today. Do not pay for a compliance program against a jurisdiction you are not operating in.
  • Early-stage startups pre-product-market fit. If you have no customers in Quebec and no near-term plan to expand there, a full privacy impact assessment framework is premature. A lightweight privacy policy and a plan to revisit at your next funding round is proportionate.
  • Companies conflating Law 25 with SOC 2. These solve different problems. SOC 2 proves your security controls to enterprise buyers; Law 25 is a legal privacy obligation triggered by Quebec residents' data. Some vendors will happily sell you both bundled together whether you need it or not.

The honest test is simple: do you currently handle, or will you within the next 12 months handle, personal information belonging to someone who lives in Quebec? If not, your dollars are better spent elsewhere in your compliance roadmap.

The Real Penalties Behind Quebec's Privacy Stick

Law 25 gave the CAI teeth that PIPEDA never had. Administrative monetary penalties can reach the greater of $10 million or 2 percent of worldwide turnover for corporations, with penal fines reaching the greater of $25 million or 4 percent of worldwide turnover for the most serious violations. Individuals face separate, smaller fine ranges. These figures are set in the statute itself, not our estimate, and they scale with global revenue, not just Quebec revenue, which is what catches companies off guard.

Beyond the fines, the CAI has shown it will act. Breach notification triggers regulatory scrutiny, and enterprise procurement teams in Quebec now routinely ask vendors to attest to Law 25 readiness as a contract condition. Losing a deal over an unanswered privacy questionnaire is a quieter but just as real cost.

Law 25 in the Wider Canadian Privacy Picture

Quebec is ahead of the rest of the country here. PIPEDA still governs federally regulated businesses and provinces without their own substantially similar law, and reform at the federal level has stalled repeatedly. That leaves Quebec as the strictest, most enforced privacy regime a Canadian or cross-border company is likely to encounter domestically. For companies building out of Toronto, Waterloo, Ottawa, Vancouver, Calgary, or Montreal, Law 25 is frequently the first real privacy compliance test they face, well before GDPR ever becomes relevant. It also tends to arrive at the same time as CPCSC expectations from public-sector and defence-adjacent buyers, so it is worth mapping both rather than treating them as separate projects.

How to Decide Without Guessing

Rather than defaulting to "better safe than sorry" spending, map your actual data flows: where your customers and employees are located, what personal information you collect, and whether any automated decisions touch Quebec residents. That exercise alone tells you whether you are in scope, and if you are, how much program you actually need versus what a vendor might try to sell you. We've built out the specifics of scope, obligations, and implementation steps in our Quebec Law 25 framework guide, which is a useful next stop if you want the compliance detail without the sales pitch.

If Law 25 is one piece of a broader compliance push, for example alongside SOC 2 for a US-bound SaaS deal, it is worth looking at how the pieces fit together rather than buying them as separate engagements. Our compliance solutions page lays out how we sequence privacy, security, and framework work so you are not paying twice for overlapping controls.

Get an Honest Read on Your Exposure

If you are unsure whether Law 25 applies to your business, or you suspect a vendor is trying to sell you more compliance than your actual risk warrants, talk to us. Traztech is a boutique Canadian security and compliance consultancy, and we will tell you plainly if you do not need what you are asking for. Contact us for a straight assessment of your Quebec privacy exposure and what, if anything, needs to change.

Not ready for a call? Same.

Get the playbook, not a sales pitch

If this was useful, Jacob sends a few short, practical notes on locking down your startup without a big security team. No fluff, unsubscribe in one click. Just reply if you want to talk; it reaches him directly.

From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.

Need help with any of this?

We help startups build secure, scalable infrastructure. Book a free strategy call and let's talk about your stack.

Book a free consultation