Canadian Privacy
Featured
Part of the Quebec Law 25 guide

Quebec Law 25 Penalties: Maximum Fines and How Penalties Are Set

Law 25 penalties explained: the monetary administrative penalties and penal fines in the Act, who can be held liable, and how exposure is assessed.

Canada Compliance AI• Compliance Team
January 6, 2026
Updated September 12, 2026
6 min read
Law 25
Quebec Privacy
CAI Quebec
Privacy Penalties
Bill 64

Understanding Law 25's Penalty Structure

Quebec's Act respecting the protection of personal information in the private sector, as amended by Law 25, provides two kinds of monetary sanctions: administrative monetary penalties imposed through the Commission d'accès à l'information (CAI), and penal fines imposed on conviction for an offence. The amounts below come from the Act's text on LégisQuébec.

1. Administrative Monetary Penalties (s. 90.12)

Maximum: $50,000 for a natural person Maximum for all others (e.g., businesses): $10,000,000 or, if greater, 2% of worldwide turnover for the preceding fiscal year

Under s. 90.1, a penalty may be imposed on anyone who, among other things:

  • Does not inform the persons concerned as required by sections 7 and 8
  • Collects, uses, communicates, keeps or destroys personal information in contravention of the law
  • Does not report, where required, a confidentiality incident to the Commission or to the persons concerned
  • Does not take the security measures necessary to protect personal information in accordance with section 10
  • Does not inform a person concerned by a decision based exclusively on automated processing, or does not give the person an opportunity to submit observations (section 12.1)

2. Penal Offences (s. 91)

Fine for a natural person: $5,000 to $100,000 Fine for all others: $15,000 to $25,000,000 or, if greater, 4% of worldwide turnover for the preceding fiscal year

Offences include failing to report a confidentiality incident where required, failing to take the security measures required by section 10, impeding a CAI inquiry or inspection, and failing to comply with an order of the Commission. For a subsequent offence, the fines are doubled (s. 92.1).


CAI Decisions

The CAI publishes its decisions on its website, cai.gouv.qc.ca. Review published decisions directly rather than relying on summaries of enforcement outcomes.


The Wider Cost of Non-Compliance

Regulatory sanctions are only part of the exposure. The true cost of Law 25 violations can include:

1. Regulatory Sanctions

  • Administrative monetary penalties
  • Penal proceedings, which the Commission may institute (s. 92)
  • Doubled fines for a subsequent offence (s. 92.1)

2. Legal and Professional Fees

  • Legal defence
  • Forensic investigation
  • Privacy consultant remediation

3. Operational Remediation

  • System upgrades and security improvements
  • Policy and procedure rewrites
  • Staff training and awareness programs

4. Customer and Revenue Impact

  • Customer churn
  • Difficulty acquiring new customers
  • Negative online reviews

Factors That Affect Penalty Amounts

Administrative Monetary Penalties

The CAI must publish a general framework for applying administrative monetary penalties (s. 90.2). The criteria for deciding whether to impose a penalty and its amount include:

  • The nature, seriousness, repetitiveness and duration of the failure
  • The sensitivity of the personal information concerned
  • The number of persons concerned and the risk of injury to which they are exposed
  • The measures taken to remedy the failure or mitigate its consequences
  • The degree of cooperation provided to the Commission
  • Compensation offered to the persons concerned
  • The ability to pay of the person in default

Penal Fines

In determining the penalty, the judge takes into account, among other factors (s. 92.3):

  • The nature, seriousness, repetitiveness and duration of the offence
  • The sensitivity of the personal information concerned
  • Whether the offender acted intentionally or was negligent or reckless
  • Whether the offence was foreseeable, or recommendations or warnings to prevent it were not followed
  • Attempts to cover up the offence or failure to mitigate its consequences
  • Failure to take reasonable measures to prevent the offence
  • Whether the offender obtained or intended to obtain increased revenues or decreased expenses
  • The number of persons concerned and the risk of injury to which they are exposed

How to Avoid These Violations

Critical Actions (Do These First)

1. Confirm Your Person in Charge of the Protection of Personal Information — by default the person exercising the highest authority in the enterprise, who may delegate the function in writing; publish their title and contact information (s. 3.1)

2. Conduct Privacy Impact Assessments for projects to acquire, develop or overhaul information systems or electronic service delivery systems involving personal information (s. 3.3)

3. Review Consent and Transparency Practices

4. Establish a Breach Response Plan so you can notify the CAI and affected persons promptly when a confidentiality incident presents a risk of serious injury (s. 3.5), and keep a register of confidentiality incidents (s. 3.8)

5. Create a Data Retention Schedule


Frequently Asked Questions

Q: Can I be penalized even if there's no data breach? Yes. The failures that can lead to an administrative monetary penalty (s. 90.1) include failing to inform persons concerned and collecting, using or communicating personal information in contravention of the law — not only incident-related failures.

Q: Can I challenge a penalty? A person in default may apply to the Commission in writing for a review of the decision within 30 days after notification of the notice of claim (s. 90.6), and may contest the review decision before the Court of Québec within 30 days (s. 90.9). The debtor and the Commission may also enter into a payment agreement (s. 90.13).

Q: Can I avoid a penalty by committing to fix the problem? Following a failure, a person may enter into an undertaking with the Commission to remedy the failure or mitigate its consequences. If the Commission accepts the undertaking and it is complied with, no administrative monetary penalty may be imposed for the acts or omissions it covers (s. 90.1).

Q: What if I'm compliant with PIPEDA—am I compliant with Law 25? Not necessarily. Law 25 has its own requirements, including privacy impact assessments for certain projects (s. 3.3) and prompt notification of confidentiality incidents that present a risk of serious injury (s. 3.5).


Take Action: Law 25 Compliance Assessment

Get Your Free Law 25 Risk Score

On the Business plan, the in-app self-assessment scores your Quebec Law 25 readiness and turns the gaps into a prioritized task plan. Start with the free compliance check — about two minutes, no account needed.

Don't wait for a CAI investigation letter. Take action today.

Found this article helpful?

Share it with your team or save it for later reference.

Related compliance guides

Explore step-by-step guidance for PIPEDA, CASL, and Quebec Law 25.