Global Privacy Law Quebec, Canada

Quebec Law 25 Overview: Canada's Strictest Privacy Regime

Quebec's Law 25 explained: phased 2022-2024 obligations, mandatory PIAs, consent rules, confidentiality incidents, CAI enforcement, and fines to CAD $25 million or 4%.

Regulation

Law 25 (formerly Bill 64), modernizing the Act respecting the protection of personal information in the private sector; phased in force September 22, 2022, 2023, and 2024

Max Penalty

Administrative monetary penalties up to CAD $10 million or 2% of worldwide turnover; penal fines up to CAD $25 million or 4% of worldwide turnover; a private right of action with minimum CAD $1,000 punitive damages for intentional or grossly negligent violations

Enforcing Authority

Commission d'accès à l'information du Québec (CAI)

Official Source

www.cai.gouv.qc.ca

Executive Summary

  • Law 25 rebuilt Quebec's private-sector privacy law into the closest thing North America has to the GDPR, phased in across September 2022, 2023, and 2024.
  • Since 2022: a designated privacy officer (the CEO by default, publicly named), confidentiality-incident reporting to the CAI and affected individuals, an incident register, and biometric-system disclosure.
  • Since 2023: privacy governance policies, PIAs for high-risk projects and for communications outside Quebec, GDPR-grade consent, automated-decision notices, tracking-technology transparency, and default-on privacy settings.
  • Since 2024: data portability in a structured, commonly used technological format.
  • Penalties dwarf the rest of Canada: administrative penalties to CAD $10 million or 2% of turnover, penal fines to CAD $25 million or 4%, plus a private right of action with punitive-damage minimums.

Law 25 is what happens when a legislature reads the GDPR and decides the missing piece was nerve. Quebec kept the European architecture, governance, assessments, express consent, incident duties, portability, turnover-scaled penalties, then went further in places Europe did not: PIAs for every system project, adequacy assessments for every communication outside the province, tracking functions off by default, punitive-damage floors for private plaintiffs. For any organization touching Quebec the planning consequence is settled: this is the ceiling of Canadian privacy law, the standard a national program builds to once so that PIPEDA and the PIPAs come along free. And for everyone watching North American privacy drift, Quebec is the proof of concept that GDPR-grade law functions on this continent, which is precisely why its provisions keep reappearing in every serious federal reform draft.

PhasesSept 22, 2022 (officer, incidents, biometrics) → 2023 (governance, PIAs, consent, transparency) → 2024 (portability)
RegulatorCAI, with direct administrative penalty power
PenaltiesAMPs to CAD $10M / 2%; penal to CAD $25M / 4%; private action with CAD $1,000 punitive floor
DistinctivesTransfer PIAs (even interprovincial), tracking off by default, no size thresholds
Regulator siteCAI

Going deeper

Work the full requirement set. The Law 25 guide turns the phases into a build list.

Master the assessments. Quebec PIAs covers both project and transfer assessments.

Handle biometrics first. Biometric registration duties bite 60 days before deployment.

Run one national program. Triple compliance aligns Law 25, PIPEDA, and GDPR obligations.

Tracking off by default starts with knowing what your site runs: check yours with a free scan.

Frequently Asked Questions

Who does Law 25 apply to, and does it reach companies outside Quebec?

The law applies to every enterprise (any organized economic activity, incorporated or not, profit or non-profit) that collects, holds, uses, or communicates personal information about individuals in Quebec in the course of carrying on an enterprise, with no revenue floor and no headcount threshold, a scope decision that distinguishes it sharply from US state laws with their thresholds. Territorial reach follows the information, not the address: an Ontario retailer shipping to Montreal customers, a US SaaS company with Quebec users, and a French firm marketing into the province all process Quebec personal information and are within the CAI's asserted reach. Personal information means any information concerning a natural person that allows the person to be identified, directly or indirectly, with sensitive information (medical, biometric, otherwise intimate, or context-sensitive) triggering heightened duties, notably express consent. The interaction with federal law: Quebec's act is deemed substantially similar to PIPEDA, so it displaces PIPEDA for intra-Quebec processing, while interprovincial and international flows and federally regulated employers keep a PIPEDA overlay; in practice the Quebec statute is stricter on nearly every shared axis, so building to Law 25 and letting PIPEDA ride along is the standard architecture for national programs. There are no small-business carve-outs to hide behind: proportionality tempers what compliance looks like, not whether obligations apply.

What did each phase (2022, 2023, 2024) actually require?

September 22, 2022: designate a person in charge of the protection of personal information, by default the highest-ranking officer, delegable in writing, with title and contact details published on the website; report confidentiality incidents presenting a risk of serious injury to the CAI and affected individuals, keep a register of all incidents (producible to the CAI); and disclose to the CAI before creating a database of biometric characteristics or verifying identity with biometrics (the disclosure regime under the parallel IT-framework act, since tightened so that biometric databases require CAI disclosure 60 days before use). September 22, 2023, the heavy phase: governance policies and practices (roles, retention, complaint handling) approved by the privacy officer and summarized publicly; privacy impact assessments for any acquisition, development, or overhaul of information systems involving personal information, and, distinctively, before communicating personal information outside Quebec (an adequacy-style assessment concluding the information would receive protection consistent with Quebec's law, contractualized); consent rules rebuilt (clear, free, informed, purpose-specific, requested separately from other terms, express for sensitive information); transparency duties including notice of automated decisions and of technologies with tracking, locating, or profiling functions (which must be off by default, the provision behind Quebec's cookie-consent distinctiveness); confidentiality by default for public-facing product settings; destruction or anonymization (per regulation) at purpose end; and de-indexing rights. September 22, 2024: portability, on request, computerized personal information collected from the person, in a structured, commonly used technological format, to the person or a designated organization where technically feasible.

How do the PIA and cross-border rules work, since they go beyond even the GDPR?

Two assessment triggers make Quebec unusual. Project PIAs: any project to acquire, develop, or redesign an information system or electronic service delivery involving personal information requires a privacy impact assessment proportionate to sensitivity, purpose, quantity, and distribution, meaning routine system procurement, CRM migrations, analytics implementations, and AI deployments each generate an assessment duty, with the privacy officer consulted from the project's outset (privacy by design as a process requirement, not a slogan). Transfer PIAs: before communicating personal information outside Quebec, including to the rest of Canada, the enterprise must assess whether the information would receive adequate protection in light of generally recognized principles, considering sensitivity, purposes, protections in the destination regime, and contractual safeguards; the communication may proceed only if the assessment concludes adequate protection exists, and the transfer must be papered with a written agreement addressing the assessment's findings. There is no official adequacy list, so each destination-and-vendor combination is the enterprise's own documented judgment, in practice handled through standardized transfer-assessment templates per destination country plus contractual clauses mirroring SCC logic. The operational consequence: Quebec compliance forces a live data map (what leaves the province, to whom, under what contract), which is why organizations that did Law 25 properly report the transfer-PIA exercise, not the penalties, as the thing that actually changed their data governance.

What are the incident, consent, and individual-rights mechanics day to day?

Confidentiality incidents: any access, use, communication, or loss of personal information not authorized by law. Assess seriousness (sensitivity, apprehended consequences, likelihood of harmful use); where risk of serious injury exists, notify the CAI (a prescribed form) and affected individuals promptly, notify third parties where that can reduce the injury, and record every incident, serious or not, in the register for five years. Consent: requested in clear, simple language, separately from other information, purpose by purpose; express for sensitive information; minors under 14 require parental consent; consent obtained through default-on settings or bundled terms fails the standard; and secondary uses need fresh consent unless a listed exception (compatible purpose with a direct connection, fraud prevention, research with conditions) applies and is documented. Individual rights: access and rectification (30-day response); de-indexing and cessation-of-dissemination where dissemination harms reputation or privacy contrary to law or a court order; automated-decision rights (notice that a decision was made exclusively by automated processing, the personal information used, the reasons and principal factors on request, and correction and observation rights); portability since 2024; and posthumous and minors' provisions Quebec practitioners know to check. Tracking technologies: any technology with functions allowing identification, location, or profiling must be disclosed and those functions activated only by the person's affirmative action, the rule that makes 'reject by default' the Quebec baseline for analytics and advertising tech, distinct from implied-consent practice elsewhere in Canada.

What are the penalties, and what has CAI enforcement looked like so far?

Three tiers stack. Administrative monetary penalties, imposed directly by the CAI after a notice-and-observations process: up to CAD $10 million or 2% of worldwide turnover for the preceding year, whichever is greater, for violations including inadequate incident handling, consent failures, and transparency breaches; a published general framework governs how the CAI calculates them. Penal proceedings: fines up to CAD $25 million or 4% of worldwide turnover for the gravest violations (unlawful use or communication, obstructing the CAI, identity-related offenses), doubled for repeat offenses. Private action: individuals may sue for injury from unlawful infringement of the act, and where the infringement is intentional or results from gross fault, punitive damages of at least CAD $1,000, a floor designed to make class actions arithmetically attractive, and Quebec's class-action bar has taken the invitation, with privacy classes routinely certified in the province. Enforcement practice to date: the CAI has favored investigations, orders, and compliance supervision while the phases bedded in, with inquiries spanning retailers' facial-recognition trials, breach handling, and biometric deployments (its orders halting or conditioning biometric attendance systems signal where its patience is thinnest), and joint work with the OPC on national matters (TikTok, Clearview AI lineage). The realistic exposure stack for an ordinary enterprise: a CAI order plus supervision after a mishandled incident, an AMP where governance artifacts (officer designation, register, PIAs) are missing, and the class action that follows any sizable breach, three exposures the same set of documents defends.

Regulatory Crosswalk

GDPRPIPEDAAlberta/BC PIPAs

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.