Quebec Law 25 for E-Commerce: What Online Retailers Must Do
Selling online to Quebec customers? Law 25 imposes stricter consent, cookie, and privacy obligations than federal PIPEDA.
Quebec's Law 25 applies to any enterprise that collects personal information from Quebec residents — including online retailers that don't have a physical presence in Quebec but whose website serves Quebec customers. For e-commerce businesses, Law 25's requirements are stricter than PIPEDA in several areas that directly affect how you operate your online store. Here's what you need to do.
Last updated: April 2026
Does Law 25 Apply to My E-Commerce Business?
Yes, if you sell to Quebec residents, regardless of where your business is located. Quebec's private sector privacy act applies to personal information that a person collects, holds, uses or communicates to third persons in the course of carrying on an enterprise (s. 1).
Practical threshold: If you ship goods to Quebec, have Quebec customers, or knowingly serve Quebec residents through your website, Law 25 applies to your interactions with those customers.
This means a Calgary-based Shopify store shipping to Quebec must comply with Law 25 for Quebec customer data — in addition to federal PIPEDA.
What Law 25 Requires That PIPEDA Doesn't (Or Does More Strictly)
1. Cookie Consent: Stricter Than PIPEDA
PIPEDA: Requires disclosure of cookie use and meaningful consent for cookies that collect personal information. The standard for what constitutes "meaningful" consent for analytics cookies is less prescriptive than GDPR.
Law 25: Section 8.1 requires that, before collecting personal information using technology with functions that allow people to be identified, located, or profiled, you inform them of the use of that technology and of the means available to activate those functions. In practice, this points to a cookie consent mechanism for Quebec visitors that allows active consent/refusal for tracking cookies.
For e-commerce sites: Your cookie banner must:
- Appear for Quebec visitors
- Allow them to accept or reject non-essential cookies (analytics, advertising, remarketing)
- Not pre-set non-essential cookies before consent
Implementing this:
- Use a cookie consent management platform (CookieYes, Complianz, Cookiebot)
- Configure the platform to detect Quebec visitor location (based on IP geolocation)
- Ensure non-essential cookies are not set before consent is given
2. Privacy Policy: Must Be Available in French
Your privacy policy must be available in French for Quebec customers. This is both a Law 25 obligation and a Charter of the French Language requirement.
Minimum requirement: A French-language version of your privacy policy, equivalent in content to your English version.
E-commerce implementation:
- Add a /politique-de-confidentialite or /fr/privacy page with your French policy
- Add a language toggle to your privacy policy page
- Link to the French version in footer, checkout, and cookie banner for Quebec visitors
3. Privacy Officer Must Be Publicly Named
Law 25 requires you to designate a Privacy Officer (CPVP — Responsable de la protection des renseignements personnels) and publish their title and contact information on your website.
For e-commerce stores: Add a section to your privacy policy footer:
"Person Responsible for Personal Information Protection / Responsable de la protection des renseignements personnels: [Job Title — e.g., Privacy Officer] privacy@yourbusiness.com"
Publishing a dedicated email address (privacy@yourbusiness.com) and the person's title satisfies this requirement.
4. Higher Penalties for Privacy Violations
PIPEDA: Criminal penalties up to $100,000. OPC enforcement is primarily through recommendations, not fines.
Law 25: Administrative monetary penalties up to $10 million or 2% of worldwide turnover, whichever is greater, and penal fines on conviction up to $25 million or 4% of worldwide turnover, whichever is greater.
For e-commerce: A cookie consent violation (setting tracking cookies without consent) or an inadequate privacy policy could trigger CAI enforcement. Take the requirements seriously.
5. Mandatory PIA for Cross-Border Data Transfers
If you use US-based e-commerce tools (Shopify, Klaviyo, Mailchimp, Stripe, Zendesk) and those tools process Quebec customer data on US servers, Law 25 requires a Privacy Impact Assessment (PIA) before the transfer.
In practice, this means:
- Document each vendor that processes Quebec customer data
- Assess whether the information would receive adequate protection, taking into account the receiving jurisdiction's legal framework (s. 17)
- Put a written agreement in place that reflects the assessment's results and any agreed risk-mitigation measures
Most major e-commerce vendors (Shopify, Stripe, Klaviyo) have data processing agreements (DPAs) available. Signing these DPAs is part of your cross-border transfer management.
Simplified PIA for standard tools: For widely used, well-known vendors with published security certifications and DPAs, your PIA can be brief — document the vendor, note available DPA, assess risk, conclude safeguards are reasonable. This doesn't need to be a 50-page document.
6. Breach Notification: Notify the CAI Promptly
PIPEDA: Notify OPC "as soon as feasible" after a qualifying breach.
Law 25: Notify the CAI promptly of a "confidentiality incident" presenting a risk of serious injury — there is no fixed 72-hour clock (that is GDPR).
For e-commerce, a customer database breach or payment processing incident involving Quebec customers triggers the CAI notification requirement.
7. Data Portability
Law 25 gives individuals the right to receive their personal information in a structured, machine-readable format and have it transferred to another enterprise.
For e-commerce: You need a process for portability requests — at minimum, the ability to export a customer's order history, account information, and profile data in a common format (CSV, JSON).
Most e-commerce platforms have data export features. Document your process for responding to portability requests.
E-Commerce Law 25 Compliance Checklist
Website and Checkout
- Cookie consent mechanism active for Quebec visitors (accept/reject non-essential cookies)
- Privacy policy available in French (equivalent content to English version)
- French-language cookie banner and consent notices
- Privacy Officer title and contact information published on website
- Privacy policy linked at checkout and in email footers
Data Management
- Designate a Privacy Officer (CPVP) and publish their details
- Document all vendors processing Quebec customer data (cross-border transfer inventory)
- Obtain DPAs from key vendors (Shopify, Klaviyo/Mailchimp, Stripe, etc.)
- Create a brief PIA for cross-border data transfers
Breach Response
- Update breach response plan for prompt CAI notification
- Know the CAI reporting process (cai.gouv.qc.ca)
- Separate breach register entry tracking CAI vs. OPC notifications
Customer Rights
- Establish a process for data portability requests
- Ensure access requests can be fulfilled within 30 days (same as PIPEDA)
- Create a process for de-indexing requests if you have user-generated content about individuals
Practical Steps for Shopify Merchants
If you're using Shopify and serve Quebec customers:
- Cookie consent: Install Complianz or CookieYes; configure Quebec-specific consent requirements
- Privacy policy: Generate a French version; add to Shopify as an additional page; link in footer policies navigation
- Shopify DPA: Sign Shopify's Data Processing Addendum (available in Shopify's legal documents)
- Email marketing: Use CASL-compliant consent at checkout AND Law 25 cookie consent for any tracking cookies associated with email sign-up pop-ups
Frequently Asked Questions
Q: I'm based in Ontario and have maybe 100 Quebec customers a month. Do I really need to comply with Law 25? A: If you're knowingly serving Quebec consumers, Law 25 applies to those customer relationships. 100 customers/month represents a real Quebec presence. Smaller businesses are not exempt from the law.
Q: My website automatically detects language and shows French to Quebec visitors. Does that satisfy Law 25's French language requirement? A: It's a good start — but it depends on whether your French content includes all the required Law 25 elements (complete privacy policy, cookie consent notices, privacy officer contact). Showing a translated UI without a complete French privacy policy doesn't satisfy the legal requirement.
Q: Does Law 25 require a cookie banner even if I don't use advertising cookies? A: If you use analytics cookies that track individual behaviour (even session analytics), Law 25's section 8.1 may apply. Strictly necessary cookies (session management, shopping cart) are generally not subject to this requirement. But most e-commerce sites use analytics cookies that trigger the requirement.
Quebec Law 25 Compliance for Canadian Online Retailers
Canada Compliance AI helps Canadian SMEs work through CASL, PIPEDA and Quebec Law 25: a free two-minute compliance check, readiness scores, a prioritized task plan, a 24-month breach register and an exportable audit log. See what's live and what's planned.
Start your free trial today — Quebec compliance for Canadian online sellers.
Related reading: What is Quebec Law 25 | Law 25 vs PIPEDA | Shopify PIPEDA Compliance
Found this article helpful?
Share it with your team or save it for later reference.
Related compliance guides
Explore step-by-step guidance for PIPEDA, CASL, and Quebec Law 25.
Continue Reading
Law 25 French Language Requirements for Quebec Businesses
What Quebec's Charter of the French Language requires in French for privacy: policies, notices, cook...
Quebec Law 25: Privacy Officer Requirements and Responsibilities
What Law 25 requires of a Quebec business's privacy officer: who qualifies, what you must publish on...