Contents
Back to articles
Quebec Law 25: obligations, deadlines and compliance (2026 guide)
Law 25 Quebec GDPR Compliance

Quebec Law 25: obligations, deadlines and compliance (2026 guide)

Hichem AMMAR-BOUDJELAL
Hichem AMMAR-BOUDJELALCEO & Co-founder of DPLIANCE
11 min read

Quick Answer: Quebec Law 25 in brief

Law 25 (adopted in September 2021) is Quebec’s sweeping modernisation of how private-sector enterprises must handle personal information. It came into force in three phases:

  • September 22, 2022 — designate a person in charge of the protection of personal information (a privacy officer), keep a register of confidentiality incidents, and notify the CAI (Commission d’accès à l’information, Quebec’s privacy regulator) when an incident presents a risk of serious injury.
  • September 22, 2023 — the bulk of the obligations: published governance policies, consent that is manifest, free and informed (express for sensitive information), privacy impact assessments (PIA — EFVP in French) for information-system projects and for any communication of personal information outside Quebec, transparency on automated decisions, and destruction or anonymisation of data once purposes are fulfilled.
  • September 22, 2024 — the right to data portability: providing computerised personal information in a structured, commonly used technological format.

Who is covered? Any enterprise handling personal information of people in Quebec — including businesses based elsewhere in Canada, in the US or in Europe.

Penalties: administrative monetary penalties from the CAI up to CAD $10 million or 2% of worldwide turnover, and penal fines up to CAD $25 million or 4% of worldwide turnover.

Already GDPR-ready? Roughly 80% of the work carries over. The delta: a formally designated privacy officer, broader PIA triggers (including every data flow leaving Quebec), the incident register, and a few consent nuances.


What is Quebec Law 25?

Law 25 — formally An Act to modernise legislative provisions as regards the protection of personal information — answers a simple observation: Quebec’s privacy framework dated from the 1990s, a world without cloud computing, programmatic advertising or artificial intelligence.

Rather than copying Europe’s GDPR, the Quebec legislature modernised its own statutes, chiefly the Act respecting the protection of personal information in the private sector. The result shares the GDPR’s philosophy — organisational accountability, stronger individual rights, deterrent penalties — while keeping mechanisms of its own.

The supervisory authority is the Commission d’accès à l’information (CAI). It receives incident notifications, publishes guidance, and imposes administrative monetary penalties.

One trait sets Law 25 apart: its staggered entry into force over three years (2022, 2023, 2024). By 2026, every phase is in effect. There is no grace period left: an organisation processing Quebecers’ personal information without complying is in breach, not merely behind schedule.

Who does Law 25 apply to?

The short answer: any enterprise that collects, holds, uses or communicates personal information in the course of carrying on business in Quebec. There is no size threshold — a three-person startup and a multinational face the same core obligations.

Three profiles are worth spelling out.

Quebec businesses, obviously — retail, professional services, SaaS, nonprofits. As soon as a customer file, a CRM, a newsletter or a data-collecting website exists, the law applies.

Canadian and US companies outside Quebec serving Quebec customers. Head-office location is no shield: what matters is the handling of personal information of people in Quebec.

European and international companies — the point many discover late. A French online store shipping to Quebec, a European SaaS with Montreal users, a media site dropping ad trackers on Quebec visitors: all handle Quebecers’ personal information. The logic is symmetrical to Article 3 of the GDPR, which reaches non-European businesses targeting Europeans. If your organisation has already been through GDPR compliance, the extraterritoriality reasoning is familiar — it now runs in the other direction.

Law 25 obligations, phase by phase

Phase 1 — since September 22, 2022

  • Designate a person in charge of the protection of personal information. By default, this is the person with the highest authority in the enterprise (the CEO), who may delegate the role in writing. The officer’s title and contact details must be published, including on the website.
  • Keep a register of confidentiality incidents: any unauthorised access, use or communication of personal information, or its loss.
  • Notify the CAI and affected individuals promptly when an incident presents a risk of serious injury.

Phase 2 — since September 22, 2023

The core of the law:

  • Governance: adopt policies and practices governing the lifecycle of personal information, and publish a plain-language description on the website.
  • Consent: manifest, free, informed, given for specific purposes, requested in clear and simple language, separately from any other information. For sensitive information (health, biometric data, etc.), consent must be express.
  • Privacy impact assessments (PIA / EFVP): mandatory for any project to acquire, develop or overhaul an information system involving personal information — and before any communication of personal information outside Quebec, with an assessment of the protection the destination jurisdiction offers.
  • Technology transparency: inform individuals when collecting their information through technology that can identify, locate or profile them, and tell them how to deactivate those functions. This is Quebec’s foundation for regulating trackers and ad profiling.
  • Automated decisions: inform individuals when a decision about them is based exclusively on automated processing — a direct concern for AI systems, as our guide to GDPR-compliant AI details, and its principles largely transpose.
  • End of data life: once purposes are fulfilled, destroy the information or anonymise it (under criteria framed by regulation) for serious and legitimate purposes.
  • Stronger penalties: the CAI’s administrative monetary penalty powers also date from 2023.

Phase 3 — since September 22, 2024

  • Right to data portability: individuals can obtain their computerised personal information in a structured, commonly used technological format, and have it communicated to a third party.

GDPR vs Law 25: the comparison table

For teams that know the GDPR, the fastest path is to reason by equivalences and gaps.

TopicGDPR (EU)Law 25 (Quebec)
RegulatorCNIL and EU counterpartsCAI
Legal basis6 lawful bases; consent is only one of themConsent-centric regime, with statutory exceptions
ConsentFree, specific, informed, unambiguousManifest, free, informed, purpose-specific; express for sensitive information
Impact assessmentDPIA, required where risk is highPIA (EFVP), required for any information-system project involving personal information and for any communication outside Quebec
GovernanceDPO mandatory in specific casesPrivacy officer mandatory for every enterprise (the CEO by default)
IncidentsNotify authority within 72 hours where risk existsNotify the CAI promptly where there is a risk of serious injury + mandatory register
International transfersAdequacy decisions, standard contractual clausesCase-by-case PIA before any communication outside Quebec
PortabilityArticle 20, in force since 2018In force since September 2024
Maximum penalties€20M or 4% of worldwide turnoverPenal: CAD $25M or 4% of worldwide turnover; administrative (CAI): CAD $10M or 2%

Two differences deserve attention from GDPR-seasoned teams. First, the PIA fires more systematically than the DPIA: no “high risk” threshold — a CRM overhaul involving personal information is enough. Second, transfers outside Quebec have no general adequacy mechanism comparable to the EU’s: each outbound data flow calls for its own assessment.

How to comply with Law 25

A realistic plan in six workstreams, in order:

  1. Map personal information: what, where, why, for how long, shared with whom — including processors and data flows leaving Quebec.
  2. Designate and publish the person in charge of protecting personal information (written delegation if it is not the CEO).
  3. Formalise governance: internal data-lifecycle policies, a plain-language description published on the website, an incident procedure and register.
  4. Upgrade consent: banners, forms, newsletters — clear, separate, granular requests for sensitive purposes; transparency about identification, location and profiling technologies, with a way to deactivate them.
  5. Industrialise the PIA: a reusable template, triggered upstream of any project touching personal information and any flow outside Quebec.
  6. Operationalise rights: access, rectification, de-indexing, portability — with response deadlines actually met.

The classic trap: treating Law 25 as a paperwork project. Policies protect no one if the technical stack — analytics, trackers, forms, AI systems — keeps collecting more than necessary. Durable compliance lives in the architecture, not in the binder.

Already GDPR-compliant? Here is the delta

Good news: if your organisation did its GDPR compliance work seriously, you start with a real head start. Records of processing, minimisation, security, data subject rights procedures, an impact-assessment culture: all of it transposes.

The delta comes down to five points:

  • Privacy officer: even with a DPO in place, the formal Law 25 designation (and its publication) is a distinct obligation.
  • PIA (EFVP): adapt your DPIA template — and above all, widen the triggers (any information-system project, any communication outside Quebec).
  • Transfers: your European standard contractual clauses are not enough on their own; document a PIA for each data flow leaving Quebec.
  • Incidents: add the CAI to your notification runbook and check that your register covers the “risk of serious injury” test.
  • Consent: review sensitive purposes (express consent) and transparency around profiling.

For a structured team, this delta is a matter of weeks — not years.

GDPR and Law 25: two shores, one standard

At DPLIANCE, this dual requirement is not theoretical: we live it. Our Data/AI agency was born in Poitiers, France, with one conviction — data protection is not a constraint to work around but an engineering standard. And it grew all the way to Montreal, where Florian Gadal, our co-founder and CTO, lives. In Quebec, our team was welcomed by the Digihub in Shawinigan and by Le Camp in Quebec City, two ecosystems that opened the doors of the local market to us.

That double footing taught us one thing: the GDPR and Law 25 are two shores of the same river. The statutes differ, the regulators differ, but the underlying standard is the same — and a solution built compliant at the architecture level crosses the Atlantic without a rebuild.

That is the principle behind our production-grade Data/AI solutions, compliant by design, and behind our products: Mirage Analytics (cookieless audience measurement that collects no identifying information), Cookilio (consent management) and Complio (compliance auditing). Tools designed so that the transparency required by the CAI — and by the CNIL — is a property of the system, not a retrofit.


FAQ

What is Quebec Law 25?

Law 25 is Quebec’s modernisation of its personal information protection regime. Adopted in September 2021, it came into force in phases: September 2022 (privacy officer, incident register), September 2023 (governance, consent, privacy impact assessments, stronger penalties) and September 2024 (data portability). It is overseen by the Commission d’accès à l’information (CAI), Quebec’s privacy regulator.

Who must comply with Law 25?

Any enterprise that collects, holds, uses or communicates personal information of people in Quebec — regardless of company size, with no minimum headcount threshold. This includes organisations based outside Quebec: Canadian companies in other provinces, US businesses, and European companies serving Quebec customers through a website, app or online service.

What are the penalties under Law 25?

Two regimes stack up: administrative monetary penalties imposed by the CAI of up to CAD $10 million or 2% of worldwide turnover, and penal fines of up to CAD $25 million or 4% of worldwide turnover, whichever is greater. That puts Law 25 in the same order of magnitude as GDPR fines.

What is a PIA (EFVP) under Law 25 and when is it required?

The privacy impact assessment — EFVP in French, for évaluation des facteurs relatifs à la vie privée — is Quebec’s counterpart to the GDPR’s DPIA. It is required for any project to acquire, develop or overhaul an information system involving personal information, and before communicating personal information outside Quebec.

Does Law 25 apply to companies outside Canada?

Yes, whenever they handle personal information of people in Quebec: an online store shipping to Montreal, a SaaS with Quebec users, a website dropping tracking technologies on Quebec visitors. The logic mirrors the GDPR’s extraterritorial reach under Article 3 — being GDPR-compliant is a strong foundation, but it does not replace Law 25’s own obligations.

If we are GDPR-compliant, are we automatically Law 25 compliant?

No, but most of the work is done: data mapping, minimisation, security and data subject rights processes carry over well. The gaps to close: formally designate a person in charge of protecting personal information, adapt DPIAs to the broader PIA triggers, run a PIA for every communication of data outside Quebec, keep a confidentiality incident register and notify the CAI when required.

Does Law 25 regulate cookies and online tracking?

Yes. Since September 2023, an organisation collecting personal information through technology that can identify, locate or profile a person must inform them beforehand and tell them how to deactivate those functions. In practice, ad tracking and profiling require transparency and valid consent.


Sources: An Act to modernise legislative provisions as regards the protection of personal information (Law 25, Quebec, 2021); Act respecting the protection of personal information in the private sector (Quebec); Commission d’accès à l’information du Québec (cai.gouv.qc.ca); Regulation (EU) 2016/679 (GDPR).

To frame a Data/AI project that is compliant on both sides of the Atlantic — GDPR and Law 25 alike — see our GDPR compliance guide, our GDPR-compliant AI guide, or reach our team in Poitiers and Montreal through our custom AI solutions.