If you sell into Quebec, handle Quebec residents' personal information, or run a business with any Quebec footprint, you've probably heard the name Law 25 dropped in a sales call or a legal review. Most explanations of it are written for lawyers, not for the founders, CTOs, and operators who actually have to make the changes. Here's what it means in plain terms.
What is Law 25?
Law 25 (formerly Bill 64) is Quebec's overhaul of its private sector privacy law, formally an amendment to the province's Act Respecting the Protection of Personal Information in the Private Sector. It phased in between September 2022 and September 2024, and by now every provision is in force.
The short version: it's the real Canadian privacy stick. PIPEDA, the federal privacy law, has been on the books for years but its enforcement teeth are limited. Law 25 is different. It gives Quebec's privacy regulator, the CAI (Commission d'accès à l'information), the power to issue administrative monetary penalties up to 10 million dollars or 2 percent of worldwide turnover, whichever is higher, and criminal fines that go even further for serious violations. That is closer to GDPR-scale enforcement than anything else in Canada, and it's why buyers, procurement teams, and legal counsel now ask about it directly instead of treating it as a footnote to PIPEDA.
Who actually needs to comply
Law 25 applies based on whose data you handle, not where your company is incorporated. If your organization collects, uses, stores, or discloses the personal information of Quebec residents, in the course of commercial activity, the law applies to you, whether you're headquartered in Toronto, Vancouver, or Austin. There's no minimum revenue or headcount threshold that exempts small companies.
In practice, this catches a wide range of businesses that don't think of themselves as "Quebec companies": SaaS platforms with Quebec customers or users, e-commerce sites shipping to Quebec, staffing and HR platforms with Quebec employee data, and any B2B vendor whose customer's customer happens to be in Quebec. If you're going through a vendor security review with a company that operates in Quebec, expect Law 25 questions in the questionnaire even if your own head office is nowhere near the province.
What compliance actually involves
Law 25 isn't a single certificate you buy. It's a set of operational obligations that touch legal, product, and security. The core requirements are:
- Privacy officer designation. You need a named person responsible for privacy compliance, by default the most senior person in the organization unless that role is formally delegated.
- Privacy impact assessments (PIAs). Required before any project involving the acquisition, development, or overhaul of a system or service that handles personal information, and before transferring personal information outside Quebec.
- Consent and transparency. Consent for collecting personal information has to be clear, specific, and separate from other terms, and you have to explain, in plain language, why you're collecting the data.
- Breach notification. Any incident involving a confidentiality breach that poses a risk of serious harm must be reported to the CAI and to the affected individuals, and you have to keep an internal breach register regardless of whether it was reportable.
- Data subject rights. Individuals can request access to, correction of, and in some cases deletion of their personal information, plus data portability and the right to object to automated decision-making.
- Cross-border and inter-provincial transfers. Before sending personal information outside Quebec, including to another Canadian province or to a cloud provider hosted in the US, you need a documented assessment showing the data will get comparable protection.
For a full breakdown of the specific clauses and how they map to technical controls, our Quebec Law 25 framework page walks through each requirement in more detail.
A realistic timeline
Companies starting from zero, no privacy officer, no PIA process, no breach procedure, are usually looking at eight to twelve weeks to get a defensible compliance posture in place. That covers a gap assessment against the law's requirements, standing up a PIA process and a breach response procedure, updating consent language and privacy notices, and documenting your cross-border data flows. Companies that already have SOC 2 or ISO 27001 controls in place move faster, often four to six weeks, because the underlying security and incident response infrastructure already exists. Law 25 compliance in that case is largely a documentation and policy exercise layered on top of controls you've already built, rather than a from-scratch security build.
Common misconceptions
A few things trip up companies working through this for the first time.
"We're not based in Quebec, so it doesn't apply to us." The law follows the data subject, not the company's address. If you have Quebec customers or Quebec employees, it applies.
"PIPEDA compliance covers this." It doesn't. Law 25 has stricter consent requirements, a mandatory breach register, PIA obligations PIPEDA doesn't have, and enforcement with real financial consequences. Meeting PIPEDA is a starting point, not the finish line.
"This is just a legal task, not a security one." Roughly half of what the law requires, breach detection and response, access controls, data inventory, and secure handling of cross-border transfers, is technical and security work, not legal drafting. Treating it purely as a legal checklist is one of the most common reasons companies stall midway through.
"It only matters if we get audited." The CAI can and does act on complaints from individuals, not just proactive audits. A single unhappy customer or employee filing a complaint can trigger a review.
Where Law 25 fits into your broader compliance picture
If you're already working toward SOC 2 or another framework because a US enterprise customer is asking for it, Law 25 compliance overlaps significantly with the security controls you're building anyway: access management, incident response, data inventory, and vendor risk assessment all serve both. Handling them together, rather than as separate projects run by separate teams, is usually the faster and cheaper path. Our compliance advisory work is built around exactly that kind of overlap, so you're not paying twice to satisfy two different frameworks with the same underlying controls.
Getting started
The right first step is almost always a gap assessment: a clear-eyed look at where your current privacy and security practices stand against what Law 25 actually requires, and a realistic estimate of what closing the gap will take. That tells you whether you're a few weeks out or a genuine project, before you commit budget or a deadline to it.
If you want a straight answer on where your organization stands with Law 25, get in touch with traztech and we'll walk through your current setup and what it would take to close the gap.