Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Compliance

What Is Quebec Law 25? A Plain-Language Guide (2026)

If you sell into Quebec, handle Quebec residents' personal information, or run a business with any Quebec footprint, you've probably heard the name Law 25 dropped in a sales call or a legal review. Most explanations of it are written for lawyers, not for the founders, CTOs, and operators who actually have to make the changes. Here's what it means in plain terms.

What is Law 25?

Law 25 (formerly Bill 64) is Quebec's overhaul of its private sector privacy law, formally an amendment to the province's Act Respecting the Protection of Personal Information in the Private Sector. It phased in between September 2022 and September 2024, and by now every provision is in force.

The short version: it's the real Canadian privacy stick. PIPEDA, the federal privacy law, has been on the books for years but its enforcement teeth are limited. Law 25 is different. It gives Quebec's privacy regulator, the CAI (Commission d'accès à l'information), the power to issue administrative monetary penalties up to 10 million dollars or 2 percent of worldwide turnover, whichever is higher, and penal fines that go even further for serious violations. That is closer to GDPR-scale enforcement than anything else in Canada, and it's why buyers, procurement teams, and legal counsel now ask about it directly instead of treating it as a footnote to PIPEDA.

Who actually needs to comply

Law 25 applies based on whose data you handle, not where your company is incorporated. If your organization collects, uses, stores, or discloses the personal information of Quebec residents, in the course of commercial activity, the law applies to you, whether you're headquartered in Toronto, Vancouver, or Austin. There's no minimum revenue or headcount threshold that exempts small companies.

In practice, this catches a wide range of businesses that don't think of themselves as "Quebec companies": SaaS platforms with Quebec customers or users, e-commerce sites shipping to Quebec, staffing and HR platforms with Quebec employee data, and any B2B vendor whose customer's customer happens to be in Quebec. If you're going through a vendor security review with a company that operates in Quebec, expect Law 25 questions in the questionnaire even if your own head office is nowhere near the province.

What compliance actually involves

Law 25 isn't a single certificate you buy. It's a set of operational obligations that touch legal, product, and security. The core requirements are:

  • Privacy officer designation. You need a named person responsible for privacy compliance, by default the most senior person in the organization unless that role is formally delegated.
  • Privacy impact assessments (PIAs). Required before any project involving the acquisition, development, or overhaul of a system or service that handles personal information, and before transferring personal information outside Quebec.
  • Consent and transparency. Consent for collecting personal information has to be clear, specific, and separate from other terms, and you have to explain, in plain language, why you're collecting the data.
  • Breach notification. Any incident involving a confidentiality breach that poses a risk of serious harm must be reported to the CAI and to the affected individuals, and you have to keep an internal breach register regardless of whether it was reportable.
  • Data subject rights. Individuals can request access to, correction of, and in some cases deletion of their personal information, plus data portability and the right to object to automated decision-making.
  • Cross-border and inter-provincial transfers. Before sending personal information outside Quebec, including to another Canadian province or to a cloud provider hosted in the US, you need a documented assessment showing the data will get comparable protection.

For a full breakdown of the specific clauses and how they map to technical controls, our Quebec Law 25 framework page walks through each requirement in more detail.

Privacy obligations piling up? Law 25 and PIPEDA readiness, with a named privacy officer where the law asks for one. Privacy officer

A realistic timeline

Companies starting from zero, no privacy officer, no PIA process, no breach procedure, are usually looking at eight to twelve weeks to get a defensible compliance posture in place. That covers a gap assessment against the law's requirements, standing up a PIA process and a breach response procedure, updating consent language and privacy notices, and documenting your cross-border data flows. Companies that already have SOC 2 or ISO 27001 controls in place move faster, often four to six weeks, because the underlying security and incident response infrastructure already exists. Law 25 compliance in that case is largely a documentation and policy exercise layered on top of controls you've already built, rather than a from-scratch security build.

Common misconceptions

A few things trip up companies working through this for the first time.

"We're not based in Quebec, so it doesn't apply to us." The law follows the data subject, not the company's address. If you have Quebec customers or Quebec employees, it applies.

"PIPEDA compliance covers this." It doesn't. Law 25 has stricter consent requirements, a mandatory breach register, PIA obligations PIPEDA doesn't have, and enforcement with real financial consequences. Meeting PIPEDA is a starting point, not the finish line.

"This is just a legal task, not a security one." Roughly half of what the law requires, breach detection and response, access controls, data inventory, and secure handling of cross-border transfers, is technical and security work, not legal drafting. Treating it purely as a legal checklist is one of the most common reasons companies stall midway through.

"It only matters if we get audited." The CAI can and does act on complaints from individuals, not just proactive audits. A single unhappy customer or employee filing a complaint can trigger a review.

Where Law 25 fits into your broader compliance picture

If you're already working toward SOC 2 or another framework because a US enterprise customer is asking for it, Law 25 compliance overlaps significantly with the security controls you're building anyway: access management, incident response, data inventory, and vendor risk assessment all serve both. Handling them together, rather than as separate projects run by separate teams, is usually the faster and cheaper path. Our compliance advisory work is built around exactly that kind of overlap, so you're not paying twice to satisfy two different frameworks with the same underlying controls.

Getting started

The right first step is almost always a gap assessment: a clear-eyed look at where your current privacy and security practices stand against what Law 25 actually requires, and a realistic estimate of what closing the gap will take. That tells you whether you're a few weeks out or a genuine project, before you commit budget or a deadline to it.

If you want a straight answer on where your organization stands with Law 25, get in touch with traztech and we'll walk through your current setup and what it would take to close the gap.

The provisions that catch product teams by surprise

The obligations most companies miss are the ones that land in the product, not in the policy binder.

Privacy by default. If you operate a technological product or service that collects personal information, the privacy settings have to default to the highest level of confidentiality, without the user doing anything. That is a product requirement, not a legal one. Public-by-default profiles, discoverability toggles switched on at signup and opt-out sharing features are the usual failures. Cookies used strictly to provide a service the user asked for are carved out, which is narrower than most cookie banners assume.

Automated decisions. If a decision about someone is based exclusively on automated processing, you have to tell them at or before the decision, and on request tell them what personal information was used, the reasons and the principal factors that led to the outcome, and let them submit observations to a person who can review it. "Exclusively" is doing a lot of work in that sentence. A scoring model whose output a human genuinely reviews falls outside it. A model whose output a human rubber-stamps does not, and that distinction is worth documenting honestly, because your logs will show which one it was.

Biometrics. Creating a database of biometric measurements requires disclosure to the CAI, and using biometrics to verify identity requires notice to the Commission before the system goes into service. The lead time here is real and it is the item most likely to derail a launch date that was set without asking.

French. Separately from Law 25, the Charter of the French Language governs how you present commercial and contractual material in Quebec. In practice, a privacy notice and consent flow available only in English is a finding waiting to happen, and translation is a longer lead item than teams expect.

How transfer assessments and breach registers actually get done

Two obligations generate most of the operational work, and both are more mechanical than they sound.

The transfer assessment applies before you send personal information outside Quebec, including to Ontario and including to a US cloud region. It is a written analysis covering the sensitivity of the information, the purpose, the protections in place including contractual ones, and the legal regime of the destination. You need one per data flow rather than per record, so build a table with one row per destination system and write the assessment once per row with a review date. Most companies have between eight and thirty rows and are astonished by that number, because the exercise surfaces the analytics tools and support platforms nobody inventoried.

The breach register is separate from breach notification and catches more organizations out. Every confidentiality incident goes in it, whether or not it met the reporting threshold, and the register is retained for five years. Capture these fields from the start: date of the incident, date you became aware, description, personal information involved, number of people affected, whether serious injury was likely, what you did, and the notification decision with its reasoning. That last field is what a regulator reads first if a complaint arrives, and a contemporaneous entry showing a considered decision not to notify defends far better than an unblemished record with nothing written down.

When you should handle Law 25 yourself

Plenty of companies do not need to hire anyone for this, and it is worth being blunt about which ones. If you have a single product, no biometrics, no automated decision-making, one cloud provider, and Quebec personal information that amounts to names and work email addresses, this is a week of internal effort rather than a project. Designate the privacy officer and publish the name, write the transfer assessments for your handful of flows, stand up the register, unbundle your consent from your terms of service, and translate the notice. The CAI publishes its own guidance and it is readable. Paying a consultant to reproduce that for you is a poor use of your money.

The threshold where outside help earns its cost is narrower than the market implies: sensitive information such as health or financial data, biometrics, automated decisions that affect people materially, employee data across multiple provinces, or a genuine incident already in progress. That last one is not a gap assessment, it is incident response, and the two should not be confused when the clock is running.

And if you are already mid-flight on SOC 2 or ISO 27001, fold this into that work rather than running it separately. The data inventory, access controls, vendor assessments and incident procedures are shared, the incremental Law 25 effort is small, and our fixed-scope engagements are priced on the assumption that you are not paying twice for the same control. If you are unsure which side of the threshold you sit on, say so and ask; the answer takes one conversation, and often it is that you do not need us.

Privacy obligations piling up? Law 25 and PIPEDA readiness, with a named privacy officer where the law asks for one.

Privacy officerOr talk about a retainer

Before you go

Want the rest of this by email?

If this was useful, I send a few short notes on privacy law. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, principal of traztech. No spam, unsubscribe in one click.

Want a second opinion on where you stand?

We run SOC 2, ISO 27001 and the rest of the compliance stack for startups and SMEs, and the security testing that sits behind it. The first call is free, and we will tell you if you are not ready to start yet.

Book a free call

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.