Who does Law 25 apply to, and does it reach companies outside Quebec?
The law applies to every enterprise (any organized economic activity, incorporated or not, profit or non-profit) that collects, holds, uses, or communicates personal information about individuals in Quebec in the course of carrying on an enterprise, with no revenue floor and no headcount threshold, a scope decision that distinguishes it sharply from US state laws with their thresholds. Territorial reach follows the information, not the address: an Ontario retailer shipping to Montreal customers, a US SaaS company with Quebec users, and a French firm marketing into the province all process Quebec personal information and are within the CAI's asserted reach. Personal information means any information concerning a natural person that allows the person to be identified, directly or indirectly, with sensitive information (medical, biometric, otherwise intimate, or context-sensitive) triggering heightened duties, notably express consent. The interaction with federal law: Quebec's act is deemed substantially similar to PIPEDA, so it displaces PIPEDA for intra-Quebec processing, while interprovincial and international flows and federally regulated employers keep a PIPEDA overlay; in practice the Quebec statute is stricter on nearly every shared axis, so building to Law 25 and letting PIPEDA ride along is the standard architecture for national programs. There are no small-business carve-outs to hide behind: proportionality tempers what compliance looks like, not whether obligations apply.
What did each phase (2022, 2023, 2024) actually require?
September 22, 2022: designate a person in charge of the protection of personal information, by default the highest-ranking officer, delegable in writing, with title and contact details published on the website; report confidentiality incidents presenting a risk of serious injury to the CAI and affected individuals, keep a register of all incidents (producible to the CAI); and disclose to the CAI before creating a database of biometric characteristics or verifying identity with biometrics (the disclosure regime under the parallel IT-framework act, since tightened so that biometric databases require CAI disclosure 60 days before use). September 22, 2023, the heavy phase: governance policies and practices (roles, retention, complaint handling) approved by the privacy officer and summarized publicly; privacy impact assessments for any acquisition, development, or overhaul of information systems involving personal information, and, distinctively, before communicating personal information outside Quebec (an adequacy-style assessment concluding the information would receive protection consistent with Quebec's law, contractualized); consent rules rebuilt (clear, free, informed, purpose-specific, requested separately from other terms, express for sensitive information); transparency duties including notice of automated decisions and of technologies with tracking, locating, or profiling functions (which must be off by default, the provision behind Quebec's cookie-consent distinctiveness); confidentiality by default for public-facing product settings; destruction or anonymization (per regulation) at purpose end; and de-indexing rights. September 22, 2024: portability, on request, computerized personal information collected from the person, in a structured, commonly used technological format, to the person or a designated organization where technically feasible.
How do the PIA and cross-border rules work, since they go beyond even the GDPR?
Two assessment triggers make Quebec unusual. Project PIAs: any project to acquire, develop, or redesign an information system or electronic service delivery involving personal information requires a privacy impact assessment proportionate to sensitivity, purpose, quantity, and distribution, meaning routine system procurement, CRM migrations, analytics implementations, and AI deployments each generate an assessment duty, with the privacy officer consulted from the project's outset (privacy by design as a process requirement, not a slogan). Transfer PIAs: before communicating personal information outside Quebec, including to the rest of Canada, the enterprise must assess whether the information would receive adequate protection in light of generally recognized principles, considering sensitivity, purposes, protections in the destination regime, and contractual safeguards; the communication may proceed only if the assessment concludes adequate protection exists, and the transfer must be papered with a written agreement addressing the assessment's findings. There is no official adequacy list, so each destination-and-vendor combination is the enterprise's own documented judgment, in practice handled through standardized transfer-assessment templates per destination country plus contractual clauses mirroring SCC logic. The operational consequence: Quebec compliance forces a live data map (what leaves the province, to whom, under what contract), which is why organizations that did Law 25 properly report the transfer-PIA exercise, not the penalties, as the thing that actually changed their data governance.
What are the incident, consent, and individual-rights mechanics day to day?
Confidentiality incidents: any access, use, communication, or loss of personal information not authorized by law. Assess seriousness (sensitivity, apprehended consequences, likelihood of harmful use); where risk of serious injury exists, notify the CAI (a prescribed form) and affected individuals promptly, notify third parties where that can reduce the injury, and record every incident, serious or not, in the register for five years. Consent: requested in clear, simple language, separately from other information, purpose by purpose; express for sensitive information; minors under 14 require parental consent; consent obtained through default-on settings or bundled terms fails the standard; and secondary uses need fresh consent unless a listed exception (compatible purpose with a direct connection, fraud prevention, research with conditions) applies and is documented. Individual rights: access and rectification (30-day response); de-indexing and cessation-of-dissemination where dissemination harms reputation or privacy contrary to law or a court order; automated-decision rights (notice that a decision was made exclusively by automated processing, the personal information used, the reasons and principal factors on request, and correction and observation rights); portability since 2024; and posthumous and minors' provisions Quebec practitioners know to check. Tracking technologies: any technology with functions allowing identification, location, or profiling must be disclosed and those functions activated only by the person's affirmative action, the rule that makes 'reject by default' the Quebec baseline for analytics and advertising tech, distinct from implied-consent practice elsewhere in Canada.
What are the penalties, and what has CAI enforcement looked like so far?
Three tiers stack. Administrative monetary penalties, imposed directly by the CAI after a notice-and-observations process: up to CAD $10 million or 2% of worldwide turnover for the preceding year, whichever is greater, for violations including inadequate incident handling, consent failures, and transparency breaches; a published general framework governs how the CAI calculates them. Penal proceedings: fines up to CAD $25 million or 4% of worldwide turnover for the gravest violations (unlawful use or communication, obstructing the CAI, identity-related offenses), doubled for repeat offenses. Private action: individuals may sue for injury from unlawful infringement of the act, and where the infringement is intentional or results from gross fault, punitive damages of at least CAD $1,000, a floor designed to make class actions arithmetically attractive, and Quebec's class-action bar has taken the invitation, with privacy classes routinely certified in the province. Enforcement practice to date: the CAI has favored investigations, orders, and compliance supervision while the phases bedded in, with inquiries spanning retailers' facial-recognition trials, breach handling, and biometric deployments (its orders halting or conditioning biometric attendance systems signal where its patience is thinnest), and joint work with the OPC on national matters (TikTok, Clearview AI lineage). The realistic exposure stack for an ordinary enterprise: a CAI order plus supervision after a mishandled incident, an AMP where governance artifacts (officer designation, register, PIAs) are missing, and the class action that follows any sizable breach, three exposures the same set of documents defends.