Canada Quebec, Canada

Quebec Law 25: Canada's Strictest Privacy Law Explained

Law 25's obligations: privacy officer, consent, PIAs, breach reporting, portability, and fines up to 4% of worldwide turnover.

Regulation

Act respecting the protection of personal information in the private sector, as amended by Law 25 (Bill 64)

Max Penalty

CAD 25 million or 4% of worldwide turnover, whichever is greater

Enforcing Authority

Commission d'accès à l'information du Québec (CAI)

Official Source

www.legisquebec.gouv.qc.ca

Executive Summary

  • Law 25 (adopted as Bill 64 in September 2021) rewrote Quebec's private-sector privacy act in three phases: September 2022, September 2023 (the bulk), and September 2024 (data portability).
  • It is Canada's closest analogue to GDPR: express consent for sensitive data, privacy impact assessments, privacy by default, breach reporting, automated-decision transparency, and de-indexing rights.
  • Every organization needs a designated privacy officer (by default the CEO) whose title and contact details are published.
  • Administrative monetary penalties reach CAD 10 million or 2% of worldwide turnover; penal fines reach CAD 25 million or 4%, the highest in Canadian privacy law.
  • It applies to any organization processing personal information of people in Quebec, regardless of where the organization sits.

Quebec did not wait for federal reform. Law 25 (Bill 64) turned the province’s 1994 private-sector privacy act into the most demanding privacy law in North America, phased in between September 2022 and September 2024 and now fully in force. If your business touches Quebec residents, the safe assumption is that GDPR-grade obligations apply, enforced by the Commission d’accès à l’information with fines up to 4% of worldwide turnover.

RegulationQuebec P-39.1, as amended by Law 25
Fully in force22 September 2024 (final phase: portability)
Max penaltyCAD 25M or 4% of worldwide turnover
Enforcing authorityCAI
Official textLégisQuébec P-39.1

The obligations that define the law

Governance. The person with highest authority is the privacy officer by default; the function can be delegated in writing, and the officer’s title and contact information must be published on your website. Policies and practices governing the information lifecycle must exist and be published in clear language.

Consent. Must be clear, free, informed, and purpose-specific, requested in clear and simple language, and separately from other terms. Sensitive information (medical, biometric, otherwise intimate) needs express consent. Minors under 14 require parental consent.

PIAs and transfers. Privacy impact assessments are mandatory for new or overhauled systems handling personal information and before any communication of personal information outside Quebec, where the assessment must confirm the destination offers adequate protection, contractually reinforced if needed; see the dedicated Quebec PIA guide.

Technology rules. Privacy by default for public-facing products (section 9.1). Individuals must be informed when technology allows them to be identified, located, or profiled, and how to activate those functions, which is why cookie banners in Quebec increasingly resemble EU ones. Decisions based exclusively on automated processing must be disclosed, with a right to have them reviewed by a person. Biometric databases must be declared to the CAI before use, covered in the biometric registration guide.

Rights. Access and rectification, withdrawal of consent, de-indexing (a Quebec right to be forgotten), automated-decision explanation, and, since September 2024, portability of computerized personal information in a structured, commonly used technological format.

Breaches. Any confidentiality incident presenting a risk of serious injury must be reported to the CAI and affected individuals, with an incident register kept regardless of severity.

Enforcement and strategy

The CAI can issue orders and administrative monetary penalties (to CAD 10 million or 2% of turnover); prosecutors can pursue penal fines to CAD 25 million or 4%, doubled on repeat. The private right of action adds minimum CAD 1,000 punitive damages per person for unlawful intentional or grossly negligent infringements, a class-action magnet.

Most organizations already running GDPR programs can map controls across; the Quebec-specific work is the published officer, French-language notices, the pre-transfer assessments, and biometric declarations, laid out against PIPEDA and GDPR in the triple compliance guide. Start by seeing what your site does to Quebec visitors before consent with a free scan.

Frequently Asked Questions

Does Law 25 apply to companies outside Quebec?

Yes. The act applies to personal information collected in the course of carrying on an enterprise in Quebec, and the CAI reads that to include out-of-province and foreign businesses serving Quebec customers. A US or Ontario company selling into Quebec is in scope.

What were the three compliance phases?

September 2022: privacy officer designation, breach reporting, biometric bank disclosure. September 2023: the bulk, consent rules, PIAs, privacy by default, policies, automated-decision disclosure, de-indexing, cross-border assessment. September 2024: the right to data portability.

What is a PIA and when is one required?

A privacy impact assessment is required for any acquisition, development, or overhaul of an information system involving personal information, and before communicating personal information outside Quebec. Proportionate to sensitivity, purpose, and volume; the CAI can review them.

What does privacy by default require?

Section 9.1: the confidentiality settings of any product or service offered to the public must default to the highest level of confidentiality, without user intervention. Pre-enabled tracking, public-by-default profiles, and opt-out analytics all conflict with it.

How large are Law 25 penalties really?

Administrative monetary penalties: up to CAD 10 million or 2% of worldwide turnover. Penal offences: up to CAD 25 million or 4% of worldwide turnover, doubled for repeat offences. There is also a private right of action with minimum CAD 1,000 punitive damages for unlawful infringements.

Regulatory Crosswalk

GDPRPIPEDACCPA/CPRA

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.