Quebec Law 25 compliance takes most mid-sized companies four to nine months and follows a fixed sequence: confirm the law applies to you, appoint a privacy officer, run a privacy impact assessment, rewrite your consent and policy language, fix your incident response process, and lock down cross-border data transfers. There is no shortcut and no single tool that does it for you, but the steps are well-defined and a lot of companies get stuck on the same two or three.
What Quebec Law 25 Actually Requires
Law 25 (formerly Bill 64) is Quebec's overhaul of its private-sector privacy statute, and it is the closest thing Canada has to GDPR. It applies to any business, anywhere in Canada or beyond, that collects or processes personal information about Quebec residents, whether or not the company is headquartered in Quebec. That catches a lot of SaaS companies in Toronto, Waterloo, and Ottawa who assumed a Quebec-specific law was a Quebec-office problem. It is not. If you have Quebec customers, employees, or even trial users, the law reaches you.
Unlike PIPEDA, which sets a national floor, Law 25 adds hard requirements: mandatory privacy impact assessments for certain projects, a named privacy officer by default (the CEO, unless someone else is designated), breach notification duties with real teeth, and consent rules that go further than "check a box at signup." We break down the full legal requirements on our Quebec Law 25 framework page, but the short version is: this is a compliance program, not a policy update.
Step 1: Determine If Law 25 Applies to You
Start by mapping where your customers, employees, and contractors actually live. If any personal information touches a Quebec resident, the law applies to that data, even if your company is incorporated in Vancouver or Calgary and has never opened a Quebec office. This step usually takes a day or two and it changes the shape of everything that follows, so do not skip it or assume based on your billing address.
Step 2: Appoint a Privacy Officer
Law 25 makes the person with the highest authority in the organization, typically the CEO, the default privacy officer unless someone else is formally designated. In practice, almost no founder wants that job sitting on their desk. Most companies delegate it to a VP of Operations, Legal, or Security, document the delegation in writing, and publish the officer's contact information as the law requires. This is a one-week task, but it has to be done properly, with a documented decision, not just a title change in Slack.
Step 3: Conduct a Privacy Impact Assessment (PIA)
This is where most timelines slip. Law 25 requires a formal privacy impact assessment, sometimes called an EFVP, before you launch any new project, system, or service that involves collecting, using, or disclosing personal information. If you already run a mature product, this means retroactively assessing your existing data flows, not just future ones. Expect this to take four to eight weeks for a typical SaaS platform: mapping data flows, identifying legal bases for collection, assessing risk to individuals, and documenting mitigations. Companies that skip a real data inventory here end up redoing the PIA twice.
Step 4: Rewrite Your Privacy Policy and Consent Mechanisms
Law 25 requires consent to be clear, specific, and given for explicit purposes, not buried in a wall of legalese at signup. You need plain-language notices, granular consent options, and a documented process for withdrawing consent. You also need a mechanism for individuals to request access to, correction of, or deletion of their personal information, and you need to actually be able to fulfill those requests within the statutory timeframe. Budget three to six weeks here, more if your product touches sensitive categories of data like biometrics or health information.
Step 5: Build or Fix Your Incident Response Process
Law 25 mandates notification of both the regulator (the Commission d'accès à l'information) and affected individuals when a breach poses a risk of serious harm. That means you need a documented, tested incident response plan with clear thresholds for what counts as reportable, who makes the call, and how fast notification goes out. If you already have SOC 2 or ISO 27001 controls, a lot of this overlaps with existing incident response work. If you don't, this is typically a three to five week build, including a tabletop exercise to make sure the plan actually works under pressure.
Step 6: Address Cross-Border and Third-Party Data Transfers
If personal information about Quebec residents leaves the province, whether to a cloud provider in the US, a subprocessor, or an affiliate office, you need a documented assessment showing the data will receive equivalent protection. This means reviewing vendor contracts, data processing agreements, and subprocessor lists, and updating them where they fall short. Companies using major cloud providers usually find the infrastructure is fine; it's the smaller SaaS subprocessors, the ones nobody has reviewed since the contract was signed, that create gaps.
Realistic Timeline: How Long Does Law 25 Compliance Actually Take
For a company with a straightforward SaaS product and no in-house privacy counsel, plan on four to nine months from kickoff to a defensible compliance posture:
- Applicability assessment and privacy officer designation: 1 to 2 weeks
- Data inventory and privacy impact assessment: 4 to 8 weeks
- Policy, consent, and rights-request process rewrite: 3 to 6 weeks
- Incident response build and test: 3 to 5 weeks
- Vendor and cross-border review: 3 to 6 weeks
- Internal rollout, staff training, and documentation: 2 to 4 weeks
Companies with messy data inventories, dozens of undocumented subprocessors, or no existing security program tend to land at the long end. Companies that already have SOC 2 or ISO 27001 in place move faster because the evidence-gathering habits and vendor review processes already exist.
The Penalties for Non-Compliance
Law 25 is the sharpest privacy stick in Canada right now. Administrative monetary penalties run up to $10 million or 2% of worldwide turnover, and penal provisions for serious violations go up to $25 million or 4% of worldwide turnover, whichever is higher. Quebec's regulator has also shown it will use these powers. This is not a law you can treat as a checkbox exercise buried in the terms of service, and it is not something a generic privacy policy template will satisfy.
Where a Compliance Partner Actually Helps
The steps above are not complicated individually. What trips companies up is sequencing, evidence quality, and knowing what a regulator will actually accept as sufficient documentation versus what merely feels thorough internally. A boutique partner earns its keep in three places: running the privacy impact assessment so it holds up under scrutiny, reviewing vendor and subprocessor agreements against the actual legal standard rather than a generic checklist, and building an incident response plan that works when tested, not just when read. This is the same discipline traztech applies across our broader compliance advisory work, whether the driver is Law 25, SOC 2, or a customer security questionnaire. We work with companies from Montreal to Vancouver, and Law 25 reach is national by design, so location has never been the limiting factor. Fit and follow-through are.
If you need a Law 25 program built properly the first time, with realistic timelines and documentation that holds up to regulator or auditor scrutiny, contact traztech to talk through where your organization actually stands today.