Quebec's Law 25 is the most demanding privacy statute in Canada, and the full regime has been in force since 2024. If you sell software to a Quebec customer, employ anybody in Quebec, or hold personal information about someone who lives there, it applies whether or not you have an office in the province. This guide sets out what it requires, in the order you would build it.
What Law 25 is and who it applies to
Law 25 is the common name for the statute formerly known as Bill 64, the Act to modernize legislative provisions as regards the protection of personal information. It amended several existing Quebec laws, and for private businesses the one that matters is the Act respecting the protection of personal information in the private sector.
The scope test is about the information, not your address. An enterprise that collects, holds, uses or communicates personal information concerning a person in Quebec is caught. There is no revenue or headcount floor: a twelve-person startup in Halifax with forty Quebec users carries the same core obligations as a bank.
The phased coming into force, and why it still matters
22 September 2022. Designating a person in charge of the protection of personal information, the confidentiality incident obligations including the register and the duty to report incidents presenting a risk of serious injury, and the framework for communicating personal information without consent in a commercial transaction.
22 September 2023. The main body of the reform: privacy impact assessments, published governance policies, the modernized consent rules, transparency at the point of collection, privacy by default for technological products offered to the public, notice for profiling, identification and geolocation, the right to cessation of dissemination and de-indexing, and the disclosure duty for decisions based exclusively on automated processing.
22 September 2024. Data portability.
Everything above is live now. The phasing still matters because companies that ran a project in 2022 and stopped often never came back for the later items. If your last privacy work was a breach procedure and a named officer, you are about one third of the way there.
Obligation one: a named person in charge of the protection of personal information
By default the role sits with the person with the highest authority in the enterprise, who may delegate it in writing. Either way, the title and contact details of the person in charge must be published on the enterprise's website. Two failures recur: the delegation exists in somebody's head rather than on paper, and the contact details are buried where a Quebec resident will not find them.
Obligation two: the confidentiality incident register and incident reporting
A confidentiality incident is unauthorized access to, use of, or communication of personal information, along with loss of personal information or any other breach in its protection. That is broader than most people's model of a breach: an email to the wrong customer, a misconfigured storage bucket and a laptop left in a taxi are all incidents.
Every enterprise must keep a register of confidentiality incidents, and every incident goes in it, not only the serious ones. It must be produced to the Commission on request, and the Regulation respecting confidentiality incidents sets out what each entry contains.
Where an incident presents a risk of serious injury, you must promptly notify the Commission d'acces a l'information and the affected individuals, and take reasonable measures to reduce the risk and prevent recurrence. Serious injury is assessed against the sensitivity of the information, the anticipated consequences of its use, and the likelihood of harmful use.
Obligation three: privacy impact assessments
A privacy impact assessment, or PIA, is required in three situations: any project to acquire, develop or overhaul an information system or electronic service delivery system involving personal information; before communicating personal information outside Quebec; and before communicating it without consent for study, research or statistics.
The first trigger changes how engineering works. A new CRM, data warehouse, analytics pipeline or major re-platforming each requires an assessment proportionate to the sensitivity of the information, the purpose of its use, its quantity, distribution and medium, and the person in charge must be consulted from the start, not shown the finished system. A standard template plus a trigger question in your change and procurement process keeps most assessments to an hour.
The cross-border assessment, in detail
This is the obligation most often missed. Before communicating personal information outside Quebec, the enterprise must assess the privacy-related factors, taking into account the sensitivity of the information, the purposes for which it is to be used, the protection measures that would apply including contractual measures, and the legal framework applicable in the state to which it would be communicated, including the personal information protection principles applicable there. The information may be communicated only if the assessment establishes that it would receive adequate protection, in particular in light of generally recognized principles. The communication must be the subject of a written agreement that takes into account the results of the assessment and any terms agreed to mitigate the risks identified.
Read that against a typical Canadian SaaS stack: application hosting in a US region, error monitoring, a US-headquartered support desk tool, analytics, email delivery, a payroll platform holding employee records, a large language model API. Each is a communication outside Quebec needing an assessment on file and a written agreement reflecting it.
A data processing addendum on its own is not the assessment; the DPA is the contractual measure the assessment considers. The law asks for a documented analysis, per destination and per category of information, concluding that adequate protection is provided and recording why. The output is a short memo per sub-processor and a refresh trigger when you change vendors or regions. If you keep a sub-processor list for enterprise customers, what is missing is the analysis behind each line.
Obligation four: governance policies you have to publish
Enterprises must establish and implement governance policies and practices that ensure the protection of personal information. These have to frame the keeping and destruction of the information, define the roles and responsibilities of staff throughout its life cycle, and set out a complaints process. Detailed information about them must be published on the enterprise's website in clear and simple language. Both words matter: published, meaning a Quebec resident can read them without asking, and implemented, meaning a retention schedule that is actually applied.
Obligation five: consent, and the meaning of separate and specific
Consent must be clear, free and informed, and given for specific purposes. It must be requested for each purpose, in clear and simple language, and separately from any other information provided to the person. Consent for sensitive personal information must be express, and is valid only for the time necessary to achieve the purposes requested.
The operative word is separately. Consent cannot be bundled into acceptance of terms of service: collect for three purposes and you present three distinct choices. Where the information is sensitive, and health, biometric and financial information generally is, silence or a pre-ticked box will not do.
At the point of collection you also owe the individual the purposes, the means of collection, the rights of access and rectification, the right to withdraw consent, and, where applicable, the third parties to whom it is necessary to communicate the information and the possibility that it will go outside Quebec. On request, you must also state who has access internally, the retention period, and the contact details of the person in charge.
Obligation six: de-indexing, portability, and the other individual rights
Alongside access and rectification, Law 25 adds three rights.
Cessation of dissemination and de-indexing. A person may require an enterprise to stop disseminating personal information about them, or to de-index a hyperlink attached to their name that gives access to it, where the dissemination contravenes the law or a court order, or where set conditions are met: serious injury to reputation or privacy, injury clearly greater than the public interest in knowing the information, and no cessation broader than necessary.
Portability. Computerized personal information collected from the individual must, on request, be communicated to them in a structured and commonly used technological format, or to a person or body authorized to collect it. It does not extend to information you inferred or created.
Withdrawal of consent, at any time, with a right to be told of that right at collection. Requests must be answered within 30 days, and a refusal must give reasons.
Obligation seven: automated decision-making and profiling
Where a decision is based exclusively on automated processing of personal information, the enterprise must say so no later than when it informs the individual of the decision. On request, the individual must be told the personal information used, the reasons and the principal factors and parameters behind the decision, and their right to have that information corrected, and must be able to submit observations to someone able to review the decision.
Where a technology is used that allows a person to be identified, located or profiled, the enterprise must inform them of its use and of the means available to deactivate it. Profiling means using personal information to assess characteristics of a person, in particular work performance, economic situation, health, preferences, interests or behaviour. If your product scores, ranks, prices or routes users algorithmically, this section usually needs a product change rather than a policy change.
Enforcement: the CAI, penalties and the private right of action
The Commission d'acces a l'information is the regulator. It handles complaints, inquires on its own initiative, and has an oversight division that can impose administrative monetary penalties. Exposure runs on three tracks.
Administrative monetary penalties, imposed by the Commission, of up to $10,000,000 or 2 percent of worldwide turnover for the preceding fiscal year, whichever is greater.
Penal proceedings, prosecuted in court, with fines of up to $25,000,000 or 4 percent of worldwide turnover for the preceding fiscal year, whichever is greater, doubled for a subsequent offence. Note that the test is worldwide turnover, not Quebec revenue.
A private right of action. Where an unlawful infringement of a right conferred by the Act causes injury, and the infringement is intentional or results from a gross fault, the court must award punitive damages of at least $1,000 on top of compensatory damages. In a province with an accessible class action regime, that minimum drives the risk for consumer-facing products.
How Law 25 relates to PIPEDA
PIPEDA still applies to federally regulated businesses in Quebec and to personal information crossing provincial or national borders in the course of commercial activity. Quebec's private sector Act has long been recognized as substantially similar to PIPEDA, which is why intra-provincial commercial activity falls under the provincial statute instead.
PIPEDA's ten Fair Information Principles are the floor. Law 25 runs on the same accountability logic, then adds specific, auditable obligations that PIPEDA states as principles or not at all: the published officer, the incident register, mandatory PIAs, the cross-border assessment, separate consent per purpose, de-indexing, portability and automated decision disclosure. A PIPEDA-compliant company has the inventory and safeguards work done and almost none of the documentation Law 25 asks to see. Most Canadian companies run one program for both, with Law 25 setting the bar.
How Law 25 relates to GDPR, and where GDPR work does not carry over
Carries over well: records of processing activities, which map closely to the Law 25 inventory; data protection impact assessments, which give you a PIA method; breach runbooks, though thresholds differ; retention schedules; the DPO function, which maps to the person in charge; data subject request workflows; sub-processor lists and DPAs.
Does not carry over: the cross-border analysis. GDPR transfer impact assessments are built around adequacy decisions, standard contractual clauses and the questions raised by European jurisprudence. Law 25 asks whether the information receives adequate protection in light of generally recognized principles, and the assessment must be made and documented on Quebec's terms with a written agreement reflecting its results. A transfer impact assessment is useful input, not the deliverable.
Also missing: the published title and contact of the person in charge, the incident register in the form the regulation specifies, the de-indexing right, the automated decision disclosures, and the French language dimension, since publishing privacy documentation for Quebec residents carries implications under Quebec's language legislation. Budget for roughly a third of the program being new work even when GDPR compliance is strong.
What a Law 25 readiness engagement actually covers and produces
TrazTech publishes a four-week Quebec Law 25 Readiness Sprint from $6,000 CAD. It is a gap assessment, and it covers:
- Scoping and data mapping. Which Quebec personal information you hold, where it lives, who touches it, and which systems and vendors it flows through, including the sub-processor inventory the cross-border work needs.
- Obligation-by-obligation gap analysis against the Act: person in charge, incident register and reporting, PIA process, governance policies, consent and transparency, individual rights, automated decisions and profiling, retention and destruction, privacy by default.
- Cross-border transfer review. Every destination outside Quebec, with a documented assessment for each and a review of the supporting agreement.
- Document review. Privacy policy, terms, DPAs and internal procedures against what the Act requires published and implemented.
It produces a findings register: every gap, the obligation it maps to, the evidence behind it, a severity, and what closing it requires, plus the documents you can adopt immediately, including the incident register and the PIA and cross-border templates.
What it is not is remediation. That is a second phase, scoped and priced from the findings register. The sequence is deliberate: nobody can honestly price the work of closing your gaps before knowing what they are, and a fixed remediation price quoted in advance is either padded for the worst case or revisited once the gaps surface.
Questions to ask before you hire anyone
Whoever you engage, including us:
- Has the firm completed Canadian privacy engagements it can show you, with references?
- Is remediation priced before or after the gap assessment, and on what basis?
- What are the practitioner's credentials beyond a baseline certification?
- Which entity signs the contract, and under which province's law?
- Where does engagement data live, and does that answer itself create a transfer you would have to assess?
Your next step
If you hold personal information about people in Quebec and cannot today produce a confidentiality incident register, a cross-border assessment for each destination outside the province, and a published title and contact for your person in charge, you have gaps that are enforceable now.
Start with the inventory, because you cannot assess transfers you have not listed. If you want that done against the Act with a findings register at the end, the Quebec Law 25 Readiness Sprint is a four-week engagement from $6,000 CAD, published at traztech.ca/pricing. Bring your sub-processor list to the call.