What is Quebec Law 25? Requirements and Who It Applies To
What Quebec Law 25 requires, which businesses it covers, and the obligations now in force — the person in charge, consent, incidents and PIAs.
Quebec's Law 25 — formally known as An Act to modernize legislative provisions as regards the protection of personal information — is the most significant update to privacy law in Canada in a generation. It imposes obligations stricter than any other Canadian jurisdiction, with penalties that rival the EU's GDPR. If your business operates in Quebec, collects data from Quebec residents, or provides services to Quebec customers, Law 25 applies to you.
Last updated: April 2026
What is Quebec Law 25?
Law 25 (Bill 64) amends several Quebec statutes, including the Act respecting the protection of personal information in the private sector. It was adopted on September 21, 2021, assented to on September 22, 2021, and rolled out in three phases:
| Phase | Date | Key Requirements |
|---|---|---|
| Phase 1 | September 22, 2022 | Privacy Officer appointment; breach reporting to CAI |
| Phase 2 | September 22, 2023 | Privacy Impact Assessments; new consent rules; data governance; automated decision-making rights |
| Phase 3 | September 22, 2024 | Right to data portability |
All three phases are now in force as of 2026.
Who Does Law 25 Apply To?
Law 25 applies to any enterprise (private-sector organisation) that:
- Collects, holds, uses, or communicates personal information about Quebec residents
- Conducts this activity in the course of carrying on an enterprise (i.e., commercial activities)
Critically, Law 25 applies based on where your customers are located — not where your business is located. An Ontario-based SaaS company with Quebec customers must comply with Law 25. A US-based e-commerce retailer shipping to Quebec must comply with Law 25.
There is no SME exemption. The law applies to businesses of all sizes.
Key Obligations Under Law 25
1. Privacy Officer Appointment (In Force Since 2022)
Every enterprise subject to Law 25 must designate a person responsible for the protection of personal information (the equivalent of a Privacy Officer). This person:
- Is responsible for ensuring compliance with the law
- Their title and contact information must be published on the enterprise's website
- Is accountable to the enterprise's governing body
For a small business, this can be the owner. For a corporation, it is typically a senior officer. Unlike GDPR's Data Protection Officer, Law 25 does not require special qualifications — but the person must have resources and authority to do the job.
2. Mandatory Breach Reporting (In Force Since 2022)
Any confidentiality incident (breach) that presents a risk of serious injury to an affected person must be:
- Reported promptly to the Commission d'accès à l'information (CAI) (s. 3.5)
- Notified to the affected individuals
- Entered in a confidentiality incident register maintained by the enterprise
The CAI can be reached at cai.gouv.qc.ca. The reporting threshold ("risk of serious injury") is similar to PIPEDA's "real risk of significant harm."
3. Privacy Policy Publication (In Force Since 2023)
Enterprises that collect personal information must publish a privacy policy that explains:
- The categories of personal information collected
- The purposes of collection
- The rights of the individuals concerned
- How to exercise those rights
- Contact information for the Privacy Officer
This policy must be written in clear, simple language and published in a way that is accessible to the persons concerned (i.e., on your website).
4. Privacy Impact Assessments (PIAs) (In Force Since 2023)
Enterprises must conduct a Privacy Impact Assessment (PIA) for any project to acquire, develop or overhaul an information system or electronic service delivery system involving personal information (s. 3.3), and before communicating personal information outside Québec (s. 17). Examples include:
- Launching a new app or software system
- Acquiring a new software system from a technology vendor
- Transferring or outsourcing personal information outside Québec
PIAs must assess privacy risks and document measures taken to reduce them. The law requires these to be conducted before the project begins.
5. Consent Requirements (In Force Since 2023)
Law 25 imposes stricter consent rules than PIPEDA:
- Consent must be manifest, free, and informed
- It must be sought for each specific purpose
- It must be given separately from other agreements
- Sensitive information requires explicit consent
- Personal information about a minor under 14 may not be collected from the minor without the consent of the person having parental authority or the tutor, unless collection is clearly for the minor's benefit (s. 4.1)
Law 25 defines personal information as sensitive if, due to its nature (in particular its medical, biometric or otherwise intimate nature) or the context of its use or communication, it entails a high level of reasonable expectation of privacy (s. 12).
6. Right to Data Portability (In Force Since 2024)
Individuals have the right to receive their personal information in a technologically structured, commonly used format that can be communicated to another enterprise. This is the equivalent of GDPR's right to data portability.
Practically, this means your systems must be able to export a user's data in a machine-readable format (CSV, JSON, etc.) upon request.
7. Automated Decision-Making Rights (In Force Since 2023)
If you make decisions based solely on automated processing (including AI) that affect an individual, you must:
- Inform the person of this fact when making or communicating the decision
- On request, tell them the personal information used and the reasons and principal factors and parameters that led to the decision
- Give them the opportunity to submit observations to a member of staff who is in a position to review the decision (s. 12.1)
This applies to credit decisions, insurance assessments, job applications, and similar AI-driven processes.
8. Service Providers: Written Contracts Required
When you communicate personal information without consent to a service provider or mandatary because it is necessary for the mandate or contract, the mandate or contract must be in writing and must specify the measures the provider must take to protect the information, use it only for the mandate or contract, and not keep it after the contract ends (s. 18.3). This is mandatory — not just a best practice.
Quebec Law 25 Penalties
Law 25 introduced significant penalties under the private sector act:
| Violation | Maximum Penalty |
|---|---|
| Penal offence (s. 91) — enterprises | $15,000 up to the greater of $25,000,000 or 4% of worldwide turnover |
| Penal offence (s. 91) — natural persons | $5,000 to $100,000 |
| Administrative monetary penalty (s. 90.12) — enterprises | Up to the greater of $10,000,000 or 2% of worldwide turnover |
| Administrative monetary penalty (s. 90.12) — natural persons | Up to $50,000 |
Penal fines are doubled for subsequent offences (s. 92.1).
Law 25 vs PIPEDA: Key Differences
| Aspect | PIPEDA | Quebec Law 25 |
|---|---|---|
| Geographic scope | Federal private sector | All businesses dealing with Quebec residents |
| Maximum fine | $100,000 (criminal) | $25M or 4% of turnover |
| Consent standard | Express or implied | Manifest, free, informed; explicit for sensitive |
| PIAs required | No formal requirement | Yes, for tech projects |
| Portability | No explicit right | Yes, since 2024 |
| Automated decisions | No specific rights | Right to human review |
| Privacy Officer | Mandatory (Schedule 1, Principle 4.1) | Mandatory (publicly listed) |
| Breach reporting | Real risk of significant harm | Risk of serious injury |
For a detailed comparison, see our dedicated Quebec Law 25 vs PIPEDA guide.
French Language Requirements
Law 25 has a critical implication for French language compliance: privacy policies, consent mechanisms, and communications with Quebec consumers must be available in French. The Charter of the French language (as amended by Bill 96) reinforces this requirement.
Practically: your website's privacy policy, cookie consent banner, and access request procedures must all be available in French for Quebec users.
Canada Compliance AI helps Canadian SMEs work through CASL, PIPEDA and Quebec Law 25: a free two-minute compliance check, readiness scores, a prioritized task plan, a 24-month breach register and an exportable audit log. See what's live and what's planned.
How to Achieve Law 25 Compliance
Immediate priorities:
- ✅ Appoint and publish your Privacy Officer's contact information
- ✅ Publish a compliant, bilingual privacy policy
- ✅ Set up breach detection and reporting procedures
- ✅ Audit all third-party vendor contracts for confidentiality clauses
- ✅ Review and update consent mechanisms for Quebec users
Ongoing obligations:
- Conduct PIAs before launching new projects involving personal data
- Maintain a confidentiality incident register
- Process access and portability requests within required timelines
- Train staff annually on Law 25 obligations
Canada Compliance AI helps Canadian SMEs work through CASL, PIPEDA and Quebec Law 25: a free two-minute compliance check, readiness scores, a prioritized task plan, a 24-month breach register and an exportable audit log. See what's live and what's planned.
Frequently Asked Questions
Q: Does Law 25 apply to my Ontario business if I have Quebec customers? A: Yes. Law 25 applies to any enterprise that collects personal information from Quebec residents in the course of commercial activities, regardless of where the enterprise is located.
Q: What is the CAI? A: The Commission d'accès à l'information is Quebec's privacy regulator, equivalent to the federal OPC but with significantly stronger enforcement powers, including the ability to issue administrative penalties directly.
Q: Do I need a bilingual privacy policy? A: Yes, for Quebec consumers. Your privacy policy must be accessible and intelligible, which in Quebec means available in French. English-only policies may not satisfy the law.
Q: Is Law 25 stricter than GDPR? A: In terms of penalties, Law 25 matches GDPR (4% of worldwide turnover). In some respects (automated decision-making, PIAs) the obligations are broadly similar. The consent standard under GDPR is arguably stricter in some dimensions, but Law 25 is clearly the strongest privacy framework in Canada.
Q: What if I had no Quebec customers until recently? A: Once you start collecting personal information from Quebec residents commercially, Law 25 obligations apply. There is no grace period for new market entrants.
Simplify Your Law 25 Compliance
Quebec's Law 25 is complex but manageable with the right tools. Start with our Quebec Law 25 compliance guide, then see what's live and what's planned in the product.
Get your free compliance check — about two minutes, no account needed.
Further reading: Quebec Law 25 Guide | Law 25 PIAs Guide | Commission d'accès à l'information
Found this article helpful?
Share it with your team or save it for later reference.
Related compliance guides
Explore step-by-step guidance for PIPEDA, CASL, and Quebec Law 25.
Continue Reading
Quebec Law 25 for E-Commerce: What Online Retailers Must Do
Selling online to Quebec customers? Law 25 imposes stricter consent, cookie, and privacy obligations...
Law 25 French Language Requirements for Quebec Businesses
What Quebec's Charter of the French Language requires in French for privacy: policies, notices, cook...