If your SaaS product has even one paying customer with users in Quebec, Law 25 likely applies to you, and the penalties (up to 4% of worldwide turnover or 25 million dollars, whichever is higher) are steeper than anything else in Canadian privacy law. Most B2B SaaS companies outside Quebec have not scoped this properly, which makes it one of the more winnable compliance gaps a security team can close.
What Quebec Law 25 Actually Is
Law 25 (formerly Bill 64) overhauled Quebec's private sector privacy statute in phases between 2022 and September 2024. It is now the strictest privacy regime in Canada, closer in spirit to GDPR than to PIPEDA. It applies based on where the individuals whose data you process are located, not where your company is headquartered. A SaaS vendor in Toronto, Waterloo, or Austin with Quebec-based end users or customer contacts is in scope the same as a company operating out of Montreal.
The law introduced mandatory breach notification to Quebec's privacy regulator (the CAI) and to affected individuals, a right to data portability, consent requirements for automated decision-making, and privacy impact assessments for any project involving personal information. It also requires a named privacy officer, by default the company's most senior executive unless that role is formally delegated.
Why This Matters More for B2B SaaS Than It Looks
Founders often assume B2B products are lower risk because they are not consumer-facing. That assumption does not hold under Law 25. The law protects any personal information, including employee data, contact records in your CRM, and usage telemetry tied to identifiable individuals at customer companies. If your platform stores names, emails, or behavioural data on Quebec-based employees of your customers, that data is in scope, regardless of whether your own headquarters or servers sit outside the province.
This is also exactly the kind of question that shows up in enterprise vendor security reviews now. Canadian enterprise buyers, particularly in finance and government-adjacent sectors, are adding Law 25 attestations to procurement checklists alongside SOC 2. A SaaS company that cannot answer a Quebec privacy question cleanly loses deals to one that can, even outside Quebec.
The Real Penalty Structure
Law 25 penalties are tiered. Administrative monetary penalties reach 2% of worldwide turnover or 10 million dollars, whichever is greater. Penal fines, prosecuted in court for the most serious violations, reach 4% of worldwide turnover or 25 million dollars. Natural persons face separate, much smaller ranges: up to 50,000 dollars administratively and 5,000 to 100,000 dollars on a penal conviction. These numbers were set deliberately to mirror GDPR's scale, and the CAI has shown it is willing to investigate. For a growth-stage SaaS company, a Law 25 finding is not a slap on the wrist, it is a board-level event and a due diligence flag in any future financing or acquisition.
Where B2B SaaS Companies Usually Fall Short
- No privacy officer designated. Many companies have not formally named one, defaulting the obligation to the CEO by law.
- Missing privacy impact assessments. New features that touch personal data, especially anything involving analytics or AI features, need a documented assessment before launch, not after.
- Consent language that predates the law. Terms of service and privacy policies written for PIPEDA alone rarely meet Law 25's more specific consent standards.
- No breach notification runbook. Law 25 has firm timelines for notifying the CAI and affected individuals. Improvising this during an actual incident is where companies get penalized twice, once for the breach and once for the response.
- Vendor and subprocessor gaps. If your subprocessors (hosting, analytics, support tooling) touch Quebec residents' data, your contracts need to reflect that.
How TrazTech Scopes a Law 25 Engagement
Because Law 25 is a defined, bounded statute rather than an open-ended framework, it is one of the more tractable compliance projects a lean SaaS team can run. traztech's approach starts with a data mapping exercise to confirm actual exposure, since many companies overestimate or underestimate their Quebec footprint until someone actually traces where personal information flows. From there we build or update the required privacy impact assessment process, formalize the privacy officer designation, rewrite consent and disclosure language to match the statute, and put a breach notification runbook in place that your team can actually execute under pressure. Full detail on our approach lives on the Quebec Law 25 framework page.
For companies also chasing SOC 2 or building a broader compliance program, Law 25 work overlaps meaningfully with our compliance solutions practice, particularly on breach response and data governance controls that satisfy both regimes at once. We scope it as a standalone engagement or as a module inside a larger compliance sprint, depending on where you already stand.
The Canadian Privacy Picture Beyond Quebec
Law 25 does not exist in isolation. It sits alongside PIPEDA at the federal level and signals where Canadian privacy regulation is heading generally, toward stricter consent standards, mandatory breach reporting, and real financial consequences. B2B SaaS companies based in Toronto, Ottawa, Vancouver, or Calgary that serve Quebec customers need a program that treats Quebec as its own jurisdiction, not an afterthought bolted onto a national privacy policy.
Why This Is a Winnable Niche
Unlike SOC 2, which is broad and can run for months, Law 25 compliance is narrow enough to close in weeks for most B2B SaaS companies, provided someone actually maps the exposure correctly. That makes it an efficient first compliance win, and it removes a specific, recurring objection from Canadian enterprise sales cycles. For a boutique consultancy, this is exactly the kind of engagement where a focused, senior-led team beats a generic compliance platform: the statute is specific enough that templated software cannot substitute for someone who has actually read it and mapped it against your product.
Getting Started
If your SaaS company has Quebec-based customers, employees, or end users and you have not formally scoped Law 25 exposure, that is the first gap worth closing before it shows up in a procurement questionnaire or, worse, a breach. Contact traztech to scope a Law 25 assessment for your platform.
The phases, and which obligations landed when
Law 25 arrived in three tranches, and knowing which obligation came from which tranche is useful because it explains why so many companies are half compliant without realizing it. The 2022 tranche was small and structural: designate a privacy officer, publish their title and contact details, handle confidentiality incidents including keeping a register of them, and disclose biometric databases to the CAI before putting them into service.
The 2023 tranche is the large one and the one most SaaS teams have not fully worked through. It brought published privacy policies in clear and simple language, privacy impact assessments for projects that acquire, develop or overhaul an information system involving personal information, a separate assessment before communicating personal information outside Quebec, tightened consent standards requiring that consent be clear, free, informed and given for specific purposes, confidentiality by default for technological products and services offered to the public, notice when technology is used to identify, locate or profile a person along with the means to deactivate it, notice at the time an exclusively automated decision is made about someone, and a de-indexing right.
The 2024 tranche added data portability: on request, personal information collected from the individual must be provided in a structured, commonly used technological format. That one is quietly an engineering ticket rather than a policy ticket, and companies that wrote a policy promising portability without building an export path have created a commitment they cannot meet on a deadline.
The cross-border assessment is the provision that bites SaaS hardest
If you are a Canadian or American SaaS company running on infrastructure outside Quebec, and your platform holds personal information about people in Quebec, you are communicating personal information outside the province continuously. Law 25 requires an assessment before doing that, considering the sensitivity of the information, the purposes for which it will be used, the protections it would receive including contractual measures, and the legal framework applicable where it will be held. If the assessment concludes the information would receive adequate protection, the transfer proceeds and the communication must be governed by a written agreement that reflects the outcome.
Two things go wrong here in practice. The first is that nobody performs the assessment at all, because the data has been in a US region since the company was founded and it never felt like a transfer decision. The second is subtler: the assessment gets written once for the primary hosting region and never covers the support desk in another country, the analytics processor, the email provider, the AI feature calling a model API, or the offshore contractor with production access. Each of those is a communication outside Quebec and each needs to be inside the assessment or explicitly out of scope with a reason.
This is bounded, repeatable work: one template, one pass over your subprocessor list, one contract amendment cycle. What it requires is an accurate subprocessor list, and building that honestly is where the effort goes.
Incident handling: the standard is diligence, not seventy-two hours
Teams that built a GDPR runbook often assume a seventy-two hour clock and plan around it. Law 25 does not set one. The obligation on becoming aware of a confidentiality incident is to take reasonable measures to reduce the risk of injury and prevent recurrence, and where the incident presents a risk of serious injury, to notify the CAI and the affected individuals with diligence. A vague standard is harder to manage than a fixed deadline, because you cannot demonstrate you moved fast enough by pointing at a clock. You demonstrate it with a timeline: when the alert fired, when it was triaged, when the assessment concluded, when notice went out, and who decided.
Two elements catch companies out. The risk of serious injury assessment is a documented judgement weighing sensitivity, apprehended consequences, and the likelihood the information is used for a harmful purpose. Deciding an incident does not meet the threshold is legitimate; deciding it without a record is not, because the register is where you show your work. And the register itself covers confidentiality incidents generally, not only the notifiable ones, which means a lost laptop or a misdirected export that you handled internally still belongs in it.
The other trap is contractual. Your enterprise customers' data processing agreements often impose a twenty-four or forty-eight hour notification obligation on you regardless of what the statute says. When you build the runbook, build it to the shortest commitment you have made anywhere, then map the statutory obligations on top. Running two clocks in an actual incident is how notifications get missed.
Automated decisions, profiling, and the AI feature you shipped last quarter
Law 25 has provisions that pre-date the current wave of AI features but land squarely on them. If a decision about an individual is made exclusively by automated processing, you must inform them at the time of the decision, and on request tell them what personal information was used, the reasons and principal factors that led to the decision, and their right to have the information corrected. The person also has the right to submit observations to a member of your staff who can review the decision.
For most B2B SaaS this raises a scoping question rather than an immediate compliance problem: is the decision exclusively automated, and is it a decision about a person. A model that scores a lead is not deciding anything about an individual's rights. A model that automatically declines an application, flags an employee, or removes access is much closer to the line. Where your product performs the decision on behalf of a customer, work out who is responsible for the notice, write it into the contract, and give the customer the configuration they need to comply. Quebec buyers ask this exact question during procurement, and a vendor who has thought it through clears the review faster.
The profiling provision is separate and broader. Where you use technology to identify, locate or profile a person, you must inform them and give them the means to deactivate the functions that do so. Product analytics, session replay, and behavioural targeting all sit in this area, which is also where the confidentiality by default requirement applies: settings for a technological product or service offered to the public must provide the highest level of confidentiality by default, without any intervention by the user.
What a Quebec procurement review actually asks
The questions that arrive from Quebec buyers, particularly in finance, insurance, health, and public-sector-adjacent organizations, are more specific than a generic privacy questionnaire. Who is your designated privacy officer, by name and title. Have you completed a privacy impact assessment covering the communication of personal information outside Quebec, and will you share the conclusion. What is your subprocessor list and how are we notified of changes. What is your incident notification commitment, and does it start on discovery or on confirmation. Can you export a data subject's information in a structured format, and how long does that take. Do you make any exclusively automated decisions about our employees or our customers.
None of those require a certificate. They require artifacts you either have or do not. That is why this is a winnable gap: the effort is measured in weeks and the result is a set of documents you hand over rather than an audit you wait for. Keeping them in one place with review dates attached, rather than scattered across a drive, is most of the ongoing discipline, and the free traztech Workspace is there for that whether or not we run the engagement.
What actually drives the cost
The variables that move a Law 25 project are not the ones people expect. Volume of personal information matters far less than the number of distinct places it lives. A company with one database and six subprocessors is a straightforward engagement. A company with three acquired products, two legacy databases nobody fully owns, a data warehouse fed by everything, and a support tool with production access is not, and the difference is entirely in the data mapping phase.
The other cost drivers: whether you process anything sensitive such as health or biometric information, whether you make automated decisions about individuals, whether your existing contracts need amendment with subprocessors who will resist, and whether anyone internally can own the privacy officer role or you need it filled from outside. If you also serve customers under GDPR, much of the work is shared, and doing them together is meaningfully cheaper than doing them a year apart.
When you should not hire us for this
Law 25 is one of the engagements we most often talk people out of, because a lot of companies can do it themselves.
When you genuinely have no Quebec footprint. Check before you buy. If your customer base, your end users, and your staff are all outside Quebec, and you can show that from your own data rather than assuming it, you have a monitoring task and not a compliance project. Set a trigger: when the first Quebec customer signs, the work starts.
When you have a privacy lead already. A company with someone competent on privacy can work through the statute directly. It is a readable law, the CAI publishes guidance, and the obligations are enumerable. Buy a review of their data map and their cross-border assessment instead of the whole build. Our Law 25 requirements checklist is deliberately detailed enough to run from.
When the deal is blocked on something else. If the procurement objection is really about SOC 2, or about a language requirement under Quebec's French-language legislation, closing the privacy gap will not unblock it. Read the actual objection carefully before scoping anything, because Quebec buyers frequently raise several distinct requirements in one email and only one of them is the blocker.
When you are about to re-architect. If you are mid-migration to a new data platform, mapping the current state is throwaway work. Wait, or map the target state and build the controls into the migration, which is cheaper than retrofitting twice.
When a lawyer is the better spend. Contract amendments with resistant subprocessors, and any question about your exposure on decisions already made, belong with counsel. We will tell you that rather than drafting around it, and we work alongside your lawyer rather than in place of one.
If you discover you have been out of scope for two years
This is the common situation, and panic makes it worse. The sensible order: designate the privacy officer formally and record the date, because that is a single decision and it is a prerequisite for everything else. Build the incident register even if it starts empty. Map the data, honestly, including the tools nobody approved. Run the cross-border assessment on what the map shows. Fix the published privacy policy and consent language against the statute rather than against a template. Build the portability export. Then write down what remains outstanding with owners and dates.
That last document matters more than people think. Regulators and enterprise buyers both respond differently to a company with a dated, owned remediation plan than to one discovering its obligations during the conversation. Ongoing, the discipline is small: review the subprocessor list quarterly, run an assessment whenever a new system touches personal information, and rehearse the incident runbook once a year with the people who would actually be woken up. If you would rather that discipline sit with someone outside the team, that is what a retainer covers, and it is a fraction of the cost of the initial mapping work.
Privacy obligations piling up? Law 25 and PIPEDA readiness, with a named privacy officer where the law asks for one.
Privacy officerOr talk about a retainer