Quebec Law 25 vs PIPEDA: Key Differences Canadian Businesses Must Know
Law 25 vs PIPEDA: which law applies to your business, where Quebec goes further, and what to do when both apply to the same personal information.
Quebec's Loi modernisant des dispositions législatives en matière de protection des renseignements personnels — Law 25 — is the most ambitious privacy law reform in Canadian history. It closely resembles the EU's GDPR in several respects and is significantly stricter than PIPEDA in areas that affect most businesses. Here's the definitive comparison.
Last updated: April 2026
The Quick Summary
| Dimension | PIPEDA | Law 25 (Quebec) |
|---|---|---|
| Regulator | OPC Canada | Commission d'accès à l'information (CAI) |
| Maximum penalty | $100,000 (criminal) | AMPs: $10M or 2% of worldwide turnover; penal fines: $25M or 4% (whichever is greater) |
| PIAs required | Best practice | Mandatory for information system projects and transfers outside Quebec |
| Data portability | Not required | Required (individuals can transfer data) |
| Right to deletion | Limited | Explicit right to de-indexing |
| Automated profiling | Not addressed | Disclosure required; right to submit observations on automated decisions |
| Privacy officer | "Designated individual" | Named CPVP (person in charge of PBI) published publicly |
| Data breach timing | "As soon as feasible" | "Promptly" to CAI where risk of serious injury |
| Consent standard | Similar | Stricter; no conditional consent bundles |
| Language requirement | English or French | French required for Quebec residents |
Who Is Subject to Law 25?
Law 25 applies to any enterprise operating in Quebec that collects personal information — including:
- Quebec-based businesses
- Non-Quebec businesses that have Quebec customers or employees
- Online businesses with Quebec users
Unlike PIPEDA, which focuses on "commercial activities," Law 25 applies broadly to enterprises operating in Quebec.
Differences That Affect Most Businesses
1. Significantly Higher Penalties
This is the headline difference.
PIPEDA: Criminal penalties up to $100,000. In practice, the OPC rarely levies fines; it primarily issues findings and recommendations.
Law 25: Administrative monetary penalties of up to $10 million or 2% of worldwide turnover — whichever is greater — which the CAI can impose directly (no court referral required) (s. 90.12). Penal fines imposed on conviction can reach $25 million or 4% of worldwide turnover, whichever is greater (s. 91), and are doubled for subsequent offences.
Impact: The penalty regime under Law 25 is comparable to GDPR and must be taken seriously. A PIPEDA violation may result in a published finding and reputational damage. A Law 25 violation can result in a significant financial penalty.
2. Mandatory Privacy Impact Assessments (PIAs)
PIPEDA: PIAs are considered best practice, encouraged by the OPC, and sometimes required by contract or sector regulation — but not universally mandated.
Law 25: PIAs are mandatory in specific situations, including:
- Any project to acquire, develop or overhaul an information system or electronic service delivery system involving personal information (s. 3.3)
- Communicating personal information outside Quebec (s. 17)
The PIA must assess the privacy risks of the project and propose mitigations. If risks cannot be mitigated, the project should not proceed.
3. Data Portability (Right to Data Transfer)
PIPEDA: No explicit data portability right. Individuals have a right of access but not a right to receive data in a machine-readable, transferable format.
Law 25: Individuals have the right to receive their personal information in a structured, commonly used, technological format and to have it transferred to another enterprise (if technically feasible). This is directly analogous to GDPR's Article 20 data portability right.
Impact: Businesses must build data export functionality for their systems or be able to respond to portability requests.
4. Right to De-indexing
PIPEDA: No explicit right to be "forgotten" or de-indexed from search engines.
Law 25: Individuals have the right to request that their personal information be de-indexed from search results or that hyperlinks to their information be rendered inaccessible in certain circumstances — where dissemination contravenes the law or a court order, or where it causes serious injury to the person's reputation or privacy that clearly outweighs the public interest in the information (s. 28.1).
Impact: Primarily affects technology companies, social platforms, and businesses with significant online content — but any business maintaining a public website with individual profiles, testimonials, or reviews must build a de-indexing process.
5. Automated Decision-Making and Profiling
PIPEDA: No specific provisions on automated decision-making or profiling.
Law 25: When an enterprise uses personal information to make a decision exclusively based on automated processing (including profiling), the individual must be:
- Informed of the use of automated processing
- Informed, on request, of the personal information used and the reasons, principal factors and parameters that led to the decision
- Given the opportunity to present observations to a staff member in a position to review the decision (s. 12.1)
This applies to credit scoring, algorithmic job screening, automated customer risk scoring, and similar applications.
6. Cross-Border and Privacy Impact Assessments for Data Transfers
PIPEDA: Requires contractual protection when transferring data to third parties, but no formal cross-border assessment requirement.
Law 25: Before communicating personal information outside Quebec, enterprises must conduct a privacy impact assessment. The information may be communicated only if the assessment establishes that it would receive adequate protection, and the communication must be covered by a written agreement that reflects the assessment's results (s. 17).
Impact: This affects SaaS vendors, cloud providers, and any enterprise with operations or vendors outside Quebec.
7. Breach Notification Timeline
PIPEDA: Breach notification to OPC and individuals must occur "as soon as feasible."
Law 25: Breaches meeting the "confidentiality incident" threshold must be reported to the CAI promptly (there is no fixed 72-hour clock — that is GDPR). Affected individuals must also be notified promptly.
Impact: Organisations subject to Law 25 need breach response procedures that can initiate regulatory notification within days, not weeks.
8. Privacy Officer Must Be Named Publicly
PIPEDA: Requires a "designated individual" accountable for PIPEDA compliance, but there is no requirement to publish their name or title publicly.
Law 25: Enterprises must designate a person in charge of personal information (CPVP/Privacy Officer) and publish their title and contact details on the enterprise's website. By default, the person exercising the highest authority within the enterprise holds this role, but may delegate it in writing (s. 3.1).
9. French Language Requirements
Law 25: Privacy notices, policies, and communications with Quebec residents must be provided in French. This is not a Law 25 requirement per se — it flows from Quebec's Charter of the French Language — but it applies to all privacy-related communications with Quebec residents.
What's Similar Between the Two Laws
Despite the differences, the foundational requirements are similar:
- Obtain consent for collection, use, and disclosure
- Limit collection to what's necessary
- Implement appropriate security safeguards
- Provide individuals with access to their information
- Respond to access requests (30 days for both)
- Maintain a privacy policy
If you have a solid PIPEDA compliance programme, you have a head start on Law 25 — but Law 25 requires meaningful enhancements.
Compliance Priority for Quebec-Facing Businesses
If you have Quebec operations or customers, prioritise these Law 25 enhancements:
- Appoint and publicly name a Privacy Officer (CPVP)
- Update breach response for prompt CAI notification
- Conduct PIAs for any new projects involving personal information
- Review cross-border data transfers and assess receiving jurisdictions
- Build portability and de-indexing capabilities
- Add French-language disclosures for Quebec users
- Document automated decision-making and create a human review process
Frequently Asked Questions
Q: Our business is in Toronto. Do we need to comply with Law 25? A: If you have Quebec customers, employees, or operations, Law 25 applies to those activities. A Toronto-based e-commerce store with Quebec customers must comply with Law 25 for those customer relationships.
Q: Law 25 penalties seem massive — has the CAI actually imposed large fines? A: The figures above are statutory maximums, not typical outcomes. For actual enforcement outcomes, consult the decisions published by the CAI's oversight division (in French).
Q: Can our PIPEDA privacy policy cover Law 25 obligations too? A: With targeted additions — French translation, CPVP contact details, portability rights, automated decision-making disclosures — a PIPEDA policy can be expanded to cover Law 25. They're not mutually exclusive; Law 25 is a superset of PIPEDA for Quebec activities.
One Platform for PIPEDA and Law 25
Canada Compliance AI helps Canadian SMEs work through CASL, PIPEDA and Quebec Law 25: a free two-minute compliance check, readiness scores, a prioritized task plan, a 24-month breach register and an exportable audit log. See what's live and what's planned.
Start your free trial today — Canadian compliance that covers every province.
Related reading: What is Quebec Law 25 | PIPEDA Compliance Guide | Quebec Law 25 Privacy Officer Requirements
Found this article helpful?
Share it with your team or save it for later reference.
Related compliance guides
Explore step-by-step guidance for PIPEDA, CASL, and Quebec Law 25.
Continue Reading
What is Quebec Law 25? Requirements and Who It Applies To
What Quebec Law 25 requires, which businesses it covers, and the obligations now in force — the pers...
Quebec Law 25 for E-Commerce: What Online Retailers Must Do
Selling online to Quebec customers? Law 25 imposes stricter consent, cookie, and privacy obligations...