What is Quebec Law 25? Requirements and Who It Applies To

What Quebec Law 25 requires, which businesses it covers, and the obligations now in force — the person in charge, consent, incidents and PIAs.

Canada Compliance AI• Compliance Team
April 1, 2026
Updated September 15, 2026
14 min read
Quebec Law 25
Quebec Privacy Law
Law 25 Compliance
CAI Quebec
Privacy Canada

Quebec's Law 25 — formally known as An Act to modernize legislative provisions as regards the protection of personal information — is the most significant update to privacy law in Canada in a generation. It imposes obligations stricter than any other Canadian jurisdiction, with penalties that rival the EU's GDPR. If your business operates in Quebec, collects data from Quebec residents, or provides services to Quebec customers, Law 25 applies to you.

Last updated: April 2026

What is Quebec Law 25?

Law 25 (Bill 64) amends several Quebec statutes, including the Act respecting the protection of personal information in the private sector. It was adopted on September 21, 2021, assented to on September 22, 2021, and rolled out in three phases:

PhaseDateKey Requirements
Phase 1September 22, 2022Privacy Officer appointment; breach reporting to CAI
Phase 2September 22, 2023Privacy Impact Assessments; new consent rules; data governance; automated decision-making rights
Phase 3September 22, 2024Right to data portability

All three phases are now in force as of 2026.

Who Does Law 25 Apply To?

Law 25 applies to any enterprise (private-sector organisation) that:

  • Collects, holds, uses, or communicates personal information about Quebec residents
  • Conducts this activity in the course of carrying on an enterprise (i.e., commercial activities)

Critically, Law 25 applies based on where your customers are located — not where your business is located. An Ontario-based SaaS company with Quebec customers must comply with Law 25. A US-based e-commerce retailer shipping to Quebec must comply with Law 25.

There is no SME exemption. The law applies to businesses of all sizes.

Key Obligations Under Law 25

1. Privacy Officer Appointment (In Force Since 2022)

Every enterprise subject to Law 25 must designate a person responsible for the protection of personal information (the equivalent of a Privacy Officer). This person:

  • Is responsible for ensuring compliance with the law
  • Their title and contact information must be published on the enterprise's website
  • Is accountable to the enterprise's governing body

For a small business, this can be the owner. For a corporation, it is typically a senior officer. Unlike GDPR's Data Protection Officer, Law 25 does not require special qualifications — but the person must have resources and authority to do the job.

2. Mandatory Breach Reporting (In Force Since 2022)

Any confidentiality incident (breach) that presents a risk of serious injury to an affected person must be:

  1. Reported promptly to the Commission d'accès à l'information (CAI) (s. 3.5)
  2. Notified to the affected individuals
  3. Entered in a confidentiality incident register maintained by the enterprise

The CAI can be reached at cai.gouv.qc.ca. The reporting threshold ("risk of serious injury") is similar to PIPEDA's "real risk of significant harm."

3. Privacy Policy Publication (In Force Since 2023)

Enterprises that collect personal information must publish a privacy policy that explains:

  • The categories of personal information collected
  • The purposes of collection
  • The rights of the individuals concerned
  • How to exercise those rights
  • Contact information for the Privacy Officer

This policy must be written in clear, simple language and published in a way that is accessible to the persons concerned (i.e., on your website).

4. Privacy Impact Assessments (PIAs) (In Force Since 2023)

Enterprises must conduct a Privacy Impact Assessment (PIA) for any project to acquire, develop or overhaul an information system or electronic service delivery system involving personal information (s. 3.3), and before communicating personal information outside Québec (s. 17). Examples include:

  • Launching a new app or software system
  • Acquiring a new software system from a technology vendor
  • Transferring or outsourcing personal information outside Québec

PIAs must assess privacy risks and document measures taken to reduce them. The law requires these to be conducted before the project begins.

5. Consent Requirements (In Force Since 2023)

Law 25 imposes stricter consent rules than PIPEDA:

  • Consent must be manifest, free, and informed
  • It must be sought for each specific purpose
  • It must be given separately from other agreements
  • Sensitive information requires explicit consent
  • Personal information about a minor under 14 may not be collected from the minor without the consent of the person having parental authority or the tutor, unless collection is clearly for the minor's benefit (s. 4.1)

Law 25 defines personal information as sensitive if, due to its nature (in particular its medical, biometric or otherwise intimate nature) or the context of its use or communication, it entails a high level of reasonable expectation of privacy (s. 12).

6. Right to Data Portability (In Force Since 2024)

Individuals have the right to receive their personal information in a technologically structured, commonly used format that can be communicated to another enterprise. This is the equivalent of GDPR's right to data portability.

Practically, this means your systems must be able to export a user's data in a machine-readable format (CSV, JSON, etc.) upon request.

7. Automated Decision-Making Rights (In Force Since 2023)

If you make decisions based solely on automated processing (including AI) that affect an individual, you must:

  • Inform the person of this fact when making or communicating the decision
  • On request, tell them the personal information used and the reasons and principal factors and parameters that led to the decision
  • Give them the opportunity to submit observations to a member of staff who is in a position to review the decision (s. 12.1)

This applies to credit decisions, insurance assessments, job applications, and similar AI-driven processes.

8. Service Providers: Written Contracts Required

When you communicate personal information without consent to a service provider or mandatary because it is necessary for the mandate or contract, the mandate or contract must be in writing and must specify the measures the provider must take to protect the information, use it only for the mandate or contract, and not keep it after the contract ends (s. 18.3). This is mandatory — not just a best practice.

Quebec Law 25 Penalties

Law 25 introduced significant penalties under the private sector act:

ViolationMaximum Penalty
Penal offence (s. 91) — enterprises$15,000 up to the greater of $25,000,000 or 4% of worldwide turnover
Penal offence (s. 91) — natural persons$5,000 to $100,000
Administrative monetary penalty (s. 90.12) — enterprisesUp to the greater of $10,000,000 or 2% of worldwide turnover
Administrative monetary penalty (s. 90.12) — natural personsUp to $50,000

Penal fines are doubled for subsequent offences (s. 92.1).

Law 25 vs PIPEDA: Key Differences

AspectPIPEDAQuebec Law 25
Geographic scopeFederal private sectorAll businesses dealing with Quebec residents
Maximum fine$100,000 (criminal)$25M or 4% of turnover
Consent standardExpress or impliedManifest, free, informed; explicit for sensitive
PIAs requiredNo formal requirementYes, for tech projects
PortabilityNo explicit rightYes, since 2024
Automated decisionsNo specific rightsRight to human review
Privacy OfficerMandatory (Schedule 1, Principle 4.1)Mandatory (publicly listed)
Breach reportingReal risk of significant harmRisk of serious injury

For a detailed comparison, see our dedicated Quebec Law 25 vs PIPEDA guide.

French Language Requirements

Law 25 has a critical implication for French language compliance: privacy policies, consent mechanisms, and communications with Quebec consumers must be available in French. The Charter of the French language (as amended by Bill 96) reinforces this requirement.

Practically: your website's privacy policy, cookie consent banner, and access request procedures must all be available in French for Quebec users.

Canada Compliance AI helps Canadian SMEs work through CASL, PIPEDA and Quebec Law 25: a free two-minute compliance check, readiness scores, a prioritized task plan, a 24-month breach register and an exportable audit log. See what's live and what's planned.

How to Achieve Law 25 Compliance

Immediate priorities:

  1. ✅ Appoint and publish your Privacy Officer's contact information
  2. ✅ Publish a compliant, bilingual privacy policy
  3. ✅ Set up breach detection and reporting procedures
  4. ✅ Audit all third-party vendor contracts for confidentiality clauses
  5. ✅ Review and update consent mechanisms for Quebec users

Ongoing obligations:

  • Conduct PIAs before launching new projects involving personal data
  • Maintain a confidentiality incident register
  • Process access and portability requests within required timelines
  • Train staff annually on Law 25 obligations

Canada Compliance AI helps Canadian SMEs work through CASL, PIPEDA and Quebec Law 25: a free two-minute compliance check, readiness scores, a prioritized task plan, a 24-month breach register and an exportable audit log. See what's live and what's planned.

Frequently Asked Questions

Q: Does Law 25 apply to my Ontario business if I have Quebec customers? A: Yes. Law 25 applies to any enterprise that collects personal information from Quebec residents in the course of commercial activities, regardless of where the enterprise is located.

Q: What is the CAI? A: The Commission d'accès à l'information is Quebec's privacy regulator, equivalent to the federal OPC but with significantly stronger enforcement powers, including the ability to issue administrative penalties directly.

Q: Do I need a bilingual privacy policy? A: Yes, for Quebec consumers. Your privacy policy must be accessible and intelligible, which in Quebec means available in French. English-only policies may not satisfy the law.

Q: Is Law 25 stricter than GDPR? A: In terms of penalties, Law 25 matches GDPR (4% of worldwide turnover). In some respects (automated decision-making, PIAs) the obligations are broadly similar. The consent standard under GDPR is arguably stricter in some dimensions, but Law 25 is clearly the strongest privacy framework in Canada.

Q: What if I had no Quebec customers until recently? A: Once you start collecting personal information from Quebec residents commercially, Law 25 obligations apply. There is no grace period for new market entrants.


Simplify Your Law 25 Compliance

Quebec's Law 25 is complex but manageable with the right tools. Start with our Quebec Law 25 compliance guide, then see what's live and what's planned in the product.

Get your free compliance check — about two minutes, no account needed.

Further reading: Quebec Law 25 Guide | Law 25 PIAs Guide | Commission d'accès à l'information

Found this article helpful?

Share it with your team or save it for later reference.

Related compliance guides

Explore step-by-step guidance for PIPEDA, CASL, and Quebec Law 25.