Quebec Law 25 (formerly Bill 64) is the real Canadian privacy stick. PIPEDA has been on the books for over two decades with fines that rarely bite. Law 25 is different: it carries administrative monetary penalties up to $10 million or 2% of worldwide turnover, and penal fines up to $25 million or 4% of worldwide turnover for the most serious violations. If your organization handles personal information belonging to Quebec residents, this law applies to you, regardless of where your company is headquartered.
The law rolled out in three phases between September 2022 and September 2024, and all three are now fully in force. There is no grace period left. Below is a practical checklist of what compliance actually requires, in plain language, without the legal jargon.
The Law 25 Compliance Checklist
1. Appoint a Privacy Officer
Every organization subject to Law 25 must designate a person responsible for the protection of personal information. By default, this is the most senior person in the organization (often the CEO or president) unless that responsibility is formally delegated in writing to someone else, such as a privacy officer, general counsel, or head of compliance. Their name and contact information must be published, typically on your website's privacy page.
2. Conduct Privacy Impact Assessments (PIAs)
Before acquiring, developing, or significantly redesigning any information system or electronic service that involves personal information, you need a documented privacy impact assessment. This applies to new SaaS products, CRM migrations, analytics tooling, and AI features alike. A PIA should be proportional to the sensitivity of the data involved, but skipping it entirely is a common gap we see in early-stage companies moving fast.
3. Get Consent That Actually Meets the Bar
Consent under Law 25 must be clear, free, and informed, and it must be requested separately from other information given to the person (no more burying it in a wall of terms and conditions). For sensitive personal information, consent must be given expressly. Pre-checked boxes and implied consent through inaction do not meet the standard.
4. Build a Data Breach Notification Process
If a confidentiality incident presents a risk of serious injury, you must notify the Commission d'acces a l'information (CAI) and the affected individuals as soon as possible. You also need to maintain an internal incident register, whether or not the incident met the notification threshold, and that register must be available to the CAI on request. Most organizations underestimate how fast "as soon as possible" needs to be in practice, so the process has to be built and tested before an incident happens, not during one.
5. Honour the Right to Data Portability
Individuals can request that computerized personal information you hold about them be transferred to them or to a third party, in a structured, commonly used technology format. This took effect in September 2024 and requires your systems to actually support structured export, not just deletion or access requests.
6. Implement Privacy by Default
Any technological product or service offered to the public that has default parameters allowing the identification, location, or profiling of a person must be configured, by default, to the highest level of privacy protection. This is one of the more overlooked requirements because it touches product and engineering decisions, not just legal policy documents.
7. Publish a Clear, Accessible Privacy Policy
Your privacy policy has to be written in clear and simple language and made available on your website. It should describe what personal information you collect, why, how long you retain it, and how individuals can exercise their rights. Generic, boilerplate policies copied from a template rarely hold up to scrutiny.
8. Assess Cross-Border and Third-Party Data Transfers
Before transferring personal information outside Quebec, whether to a cloud provider, a subprocessor, or a parent company in another country, you need to conduct a transfer assessment confirming the destination offers protection equivalent to Quebec's standard. This is especially relevant for companies using US-based SaaS infrastructure, which is most of them.
9. Establish Governance Policies and Procedures
Organizations must implement and publish governance policies and practices regarding the personal information they hold, covering the entire lifecycle from collection to destruction. This is the connective tissue that ties the other requirements together into something auditable rather than a one-time exercise.
10. Prepare for Automated Decision-Making Disclosure
If you use personal information to render a decision based exclusively on automated processing (credit scoring, algorithmic hiring screens, automated pricing), you must inform the individual at the time of the decision, and they have the right to request an explanation and to have a human review the decision. As more companies bolt AI into customer-facing workflows, this requirement gets triggered more often than founders expect.
Why This Checklist Isn't the Whole Story
Every item above sounds like a discrete task, but Law 25 compliance is really a governance program, not a checklist you complete once and file away. The CAI has shown it will investigate and fine organizations that treat privacy as a paperwork exercise rather than an operating practice. We break down the full requirement set, enforcement history, and how it maps to existing frameworks like SOC 2 in our Quebec Law 25 framework guide.
If your organization is also pursuing SOC 2 or other security attestations, there's meaningful overlap between Law 25's governance requirements and standard compliance controls, which is worth mapping early rather than building two separate programs. Our compliance advisory services cover this kind of framework alignment for Canadian and cross-border companies.
Get a Straight Answer on Where You Stand
If you're not sure whether your organization is fully covered under Law 25, or you've completed some of the checklist above but not all of it, it's worth getting a direct assessment rather than guessing. Contact traztech to talk through your current privacy posture and what a practical path to compliance looks like for your team.