If your company collects personal information from anyone in Canada, you are almost certainly subject to PIPEDA. If you also do business with residents of Quebec, or you are headquartered there, you are subject to Law 25 as well, and Law 25 is the one with actual enforcement muscle behind it. Founders and compliance leads often assume these two frameworks are interchangeable. They are not, and the gap between them has gotten more consequential every year since Law 25's phased rollout began in 2022.
This is a common point of confusion for Canadian B2B SaaS companies, especially those selling into the US and fielding vendor security questionnaires that reference both regimes by name. Here is a plain-language breakdown of what each law covers, where they diverge, and what that means for your compliance posture.
PIPEDA: the federal baseline
The Personal Information Protection and Electronic Documents Act is Canada's federal private-sector privacy law. It applies to any organization that collects, uses, or discloses personal information in the course of commercial activity, unless a province has its own substantially similar law covering that activity (Quebec, British Columbia, and Alberta all have provincial alternatives for intra-provincial commercial activity, though PIPEDA still applies to interprovincial and international data flows). PIPEDA is built around ten fair information principles: accountability, identifying purposes, consent, limiting collection, limiting use and disclosure, accuracy, safeguards, openness, individual access, and challenging compliance. It requires organizations to report material breaches to the Office of the Privacy Commissioner of Canada and to affected individuals when there is a real risk of significant harm. Where PIPEDA falls short, in the eyes of many privacy advocates and the OPC itself, is enforcement. The Commissioner can investigate, publish findings, and pursue orders through Federal Court, but historically has had limited ability to levy direct administrative penalties. Bill C-27, which would have introduced a new Consumer Privacy Protection Act with real fining power, died when Parliament was prorogued in January 2025. Its successor, Bill C-36, the Protecting Privacy and Consumer Data Act, was introduced on 15 June 2026 and is at second reading. It would replace Part 1 of PIPEDA, add order-making powers and administrative monetary penalties, and create a new Digital Safety and Data Protection Commission. For now, PIPEDA remains largely a compliance-and-reputation regime rather than a financial-risk regime.
Law 25: Quebec's teeth
Law 25 (formerly Bill 64) amended Quebec's private-sector privacy legislation and phased in new obligations through September 2023. It applies to any organization, regardless of where it is headquartered, that collects or processes the personal information of Quebec residents in the course of business. Location of your servers or your head office does not matter. If you have Quebec customers, employees, or website visitors whose personal information you process, Law 25 applies to you. The substantive requirements will look familiar to anyone who has worked through GDPR: mandatory privacy impact assessments before any project involving personal information (including a new SaaS vendor relationship), a designated privacy officer by default the most senior executive if no one else is named, plain-language privacy policies, enhanced consent requirements including for automated decision-making and profiling, breach notification to Quebec's privacy regulator (the CAI) and affected individuals, and a right to data portability that came into force in 2024. The part that gets attention, and that we cover in more detail in our Quebec Law 25 framework guide, is the penalty structure. Law 25 gives the CAI authority to levy administrative monetary penalties of up to CAD 10 million or 2 percent of worldwide turnover, whichever is greater, for administrative violations, and penal fines up to CAD 25 million or 4 percent of worldwide turnover for the most serious offences. Those numbers put Law 25 in the same weight class as GDPR, and they are a material step up from anything PIPEDA currently allows.
Where the two laws actually diverge
The principles underneath both laws overlap heavily: consent, purpose limitation, safeguards, breach notification. Where they diverge is scope of applicability, penalty exposure, and procedural specificity. Applicability is the first fork. PIPEDA is the federal floor and applies coast to coast for commercial activity not otherwise covered by a substantially similar provincial law. Law 25 applies specifically to anyone touching Quebec residents' data, which for most SaaS companies with a national or continental customer base means both laws apply simultaneously, not one or the other. Enforcement is the second and larger fork. A PIPEDA violation today typically results in an investigation, published findings, and pressure to remediate. A Law 25 violation can result in a fine large enough to matter on a board agenda. That asymmetry is exactly why enterprise procurement teams and legal departments in Quebec ask pointed Law 25 questions in vendor due diligence even when the vendor is based in Ontario or elsewhere, because their own exposure flows through their vendors. Procedural specificity is the third. Law 25's mandatory privacy impact assessment requirement has no direct PIPEDA equivalent. If you are standing up a new tool, feature, or data-sharing arrangement that touches Quebec residents' personal information, you need a documented PIA before you launch it, not after a complaint arrives.
What this means if you sell across Canada
Treating PIPEDA compliance as sufficient because "we're not a Quebec company" is a common and expensive misread. Applicability under Law 25 turns on where your data subjects are, not where your office is. A Vancouver-based SaaS company with Quebec customers is squarely in scope. The practical path most companies take is to build a privacy program to the higher bar, which is Law 25, and treat PIPEDA compliance as a natural byproduct. The core mechanics, an accurate data inventory, a named privacy officer, a real breach response plan, documented consent flows, and a defensible retention schedule, satisfy both regimes at once. Building two parallel programs is more work for no additional protection. This also intersects directly with security certifications buyers ask for. A SOC 2 report demonstrates operational controls, but it does not by itself demonstrate Law 25 compliance, the two serve different purposes and different questions in a vendor security review. Companies going through both processes together, as many of our clients in compliance-driven engagements do, tend to find real efficiency in doing the privacy impact assessment and the SOC 2 readiness work in the same cycle, since much of the underlying documentation (data flows, access controls, incident response) is shared.
Getting started
If you have not mapped where your personal information touches Quebec residents, that is the first step, before policy language or consent banners. From there: name a privacy officer (even a fractional or part-time designation satisfies the requirement), build a PIA template you can reuse for new projects, and confirm your breach notification process actually names the CAI and the OPC as separate reporting obligations, because they are. None of this needs to be built from scratch or guessed at. If you want a second set of eyes on where your current privacy program stands against Law 25 and PIPEDA, or you need a practical plan to close the gap before your next enterprise deal or vendor questionnaire, get in touch with traztech and we will walk through where you stand.
The Law 25 obligations that surprise people most
Companies that read a summary of Law 25 usually come away with consent, breach notification, and the privacy officer requirement. Those are the easy parts. The obligations that generate the most rework are the ones buried further into the text.
Assessment before transferring information outside Quebec. Section 17 requires an assessment of privacy-related factors before you communicate personal information outside the province, taking into account the sensitivity of the information, the purposes, the protective measures including contractual ones, and the legal framework in the destination jurisdiction. The information may only be transferred if the assessment shows it will receive adequate protection, and the transfer has to be governed by a written agreement. For a SaaS company running on US cloud infrastructure with US-based subprocessors, this is not one assessment, it is one per material transfer, and it needs to be kept current as your vendor list changes. Most companies we look at have the vendor list and no assessments attached to it.
Confidentiality by default. Any organization that collects personal information through technological means offering privacy settings has to ensure those settings provide the highest level of confidentiality by default, without any intervention by the person. Cookies used strictly to provide the service are carved out. In practice this means a product that ships with a public-by-default profile, or analytics enabled unless the user opts out, is offside regardless of what your privacy policy says.
Biometric database notification. If you create a database of biometric characteristics, you have to notify the Commission d'accès à l'information no later than 60 days before it is brought into service, and verification or identification using biometrics has to be disclosed to the CAI promptly. Companies building facial or voice authentication into a consumer product routinely miss this because it does not appear in generic privacy checklists. It is a filing obligation with a hard clock and no equivalent under PIPEDA.
Automated decision-making. Where a decision is based exclusively on automated processing, the individual has to be informed of that at or before the time the decision is made, and on request must be told the personal information used, the principal factors and parameters that led to the decision, and their right to have the information corrected. They also have the right to submit observations to a person who can review the decision. That last part is a product requirement, not a policy requirement. Someone has to exist, be reachable, and have authority to change the outcome.
The confidentiality incident register nobody maintains
Both regimes require you to keep records of incidents, and both requirements are broader than the notification requirement people focus on.
Under Law 25, you must keep a register of confidentiality incidents and provide a copy to the CAI on request. That register covers every confidentiality incident, not only the ones serious enough to notify anyone about. The regulation specifies what each entry contains, including a description of the information involved, when and how you became aware of it, the number of people affected, a description of the injury risk, the measures taken to reduce risk, and whether notification was given. Entries are kept for five years after you became aware of the incident.
Under PIPEDA, section 10.3 requires you to maintain records of every breach of security safeguards, again regardless of whether the real risk of significant harm threshold was met, and to keep them for 24 months. The Privacy Commissioner can ask for them.
Two registers, two retention periods, one underlying set of facts. Build one register with fields that satisfy both and a retention rule set to the longer clock. The failure mode we see is a company with a good incident response runbook that produces Slack threads and a post-mortem document, and nothing in a form that survives a regulator's request two years later. Keeping that register somewhere durable and separate from the tools that might themselves be involved in an incident is the point of a workspace like the free traztech Workspace we hand to clients.
Employee data is the gap that catches Ontario and BC companies
PIPEDA covers employee personal information only for federally regulated employers: banks, telecoms, airlines, interprovincial transport, and similar. If you are an Ontario software company, your employees' personal information is largely outside PIPEDA's employment scope, which is why HR privacy has historically felt like a lighter subject in the Canadian tech sector.
Law 25 does not work that way. Quebec's private-sector legislation covers personal information about employees and candidates in the same manner as customer data. So an Ontario-headquartered company with a handful of remote employees in Montreal has recruiting records, performance data, background check results, and monitoring data in scope, and those files are exactly where retention discipline is usually worst. The privacy officer designation, the incident register, the transfer assessment, and the access rights all apply to the HR data set.
Alberta and British Columbia add their own layer through provincial PIPA statutes, both of which do cover employee personal information for provincially regulated employers within those provinces. A distributed Canadian company with staff in four provinces genuinely has four overlapping regimes touching its HR records, which is an argument for building to the strictest one rather than mapping each.
What Quebec buyers actually ask in vendor due diligence
The Law 25 questions that show up in questionnaires from Quebec enterprises and public bodies are more specific than generic privacy questions, and they are answerable in a page if you have done the work.
Who is your designated person responsible for the protection of personal information, and is their title and contact information published? Where is personal information about our users stored and processed, and can you provide the assessment supporting any transfer outside Quebec? Do you have a documented process for responding to access, rectification, de-indexing, and portability requests, and what is your response time? Do you profile users or make automated decisions about them, and how is that disclosed? Can you provide your confidentiality incident register policy? What are your retention periods by data category, and what triggers deletion?
Notice what is missing from that list. Almost none of it is answered by a SOC 2 report or an ISO 27001 certificate. Those instruments demonstrate that your security controls work, which is a different question from whether your handling of personal information is lawful. Companies that assume a clean audit report closes privacy diligence get sent back with a second questionnaire, and the gap between the two is usually four to six weeks of unplanned work in the middle of a deal.
Planning around a moving federal law
Bill C-36 would change the federal picture materially by adding order-making powers and administrative monetary penalties. It is not law yet, and building a programme on the assumption that it passes in a particular form is speculative. The practical stance is to build to Law 25 now, since it is in force and it is the stricter of the two, and treat any federal reform as a set of documentation and reporting adjustments rather than a rebuild. A company with an accurate data inventory, a named privacy officer, working individual rights processes, transfer assessments, and a maintained incident register is well positioned under any version of the federal statute that plausibly emerges.
When you do not need to hire anyone for this
If you have no Quebec users, no Quebec employees, and no Quebec prospects, Law 25 does not apply to you and paying for a Law 25 readiness engagement is spending money to solve a problem you do not have. Write down how you concluded that, revisit it when sales expands, and move on.
If you are a small company with a simple product and one cloud provider, the first two steps genuinely do not need us. Map where personal information enters, where it goes, and who can reach it. Name a privacy officer and publish the title and contact. Those two items close a disproportionate share of the gap, and a founder with a spreadsheet and a free afternoon can do the first pass better than an outsider can, because you know your own data flows.
If your question is contractual or interpretive, whether a particular arrangement makes you a service provider, how to word a consent mechanism, whether a clause survives, that is legal advice and you want a Quebec privacy lawyer, not a security consultancy. We work alongside counsel on these engagements rather than substituting for them, and we will say so early rather than let you buy the wrong professional.
Where we are useful is the operational half: turning the legal position into working processes, evidence, and a control set that also carries into whatever security framework your buyers ask for next, which is how our compliance advisory work is normally scoped. If you are unsure whether you have a legal question or an operational one, ask us and we will point you at the right one even when that is not us.
Privacy obligations piling up? Law 25 and PIPEDA readiness, with a named privacy officer where the law asks for one.
Privacy officerOr talk about a retainer