Canada Quebec, Canada

Quebec PIA Requirements Under Law 25 Explained

Law 25 requires PIAs for new information systems and before sending data outside Quebec. What triggers one and what it must contain.

Regulation

Quebec P-39.1 (private sector act), ss. 3.3, 17, as amended by Law 25

Max Penalty

CAD 25 million or 4% of worldwide turnover

Enforcing Authority

Commission d'accès à l'information du Québec (CAI)

Official Source

www.legisquebec.gouv.qc.ca

Executive Summary

  • Since September 2023, section 3.3 requires a privacy impact assessment for any project to acquire, develop, or overhaul an information system or electronic service delivery involving personal information.
  • Section 17 requires a PIA before communicating personal information outside Quebec, assessing whether the destination provides adequate protection in light of generally accepted data protection principles.
  • PIAs must be proportionate to the sensitivity, purpose, quantity, distribution, and medium of the information.
  • The privacy officer must be consulted from the outset of the project, and cross-border transfers must be covered by written agreements addressing identified risks.
  • Skipping mandatory PIAs exposes the enterprise to Law 25's penalty regime: administrative penalties to CAD 10 million or 2% of turnover, penal fines to CAD 25 million or 4%.

Law 25 made privacy impact assessments a legal requirement in Quebec on two fronts: system projects and cross-border data flows. Since September 2023, an enterprise that stands up a new CRM without a PIA, or routes personal information to a US cloud without the transfer assessment, is violating the statute, not just best practice. The obligation is proportionate but not optional, and it is one of the easiest compliance failures for the CAI to spot because it is documentary: either the assessment exists or it does not.

RegulationQuebec P-39.1, ss. 3.3 and 17
In force22 September 2023
Max penaltyCAD 25M or 4% of worldwide turnover
Official textLégisQuébec P-39.1

Trigger one: system projects (s. 3.3)

Any project to acquire, develop, or overhaul an information system or electronic service delivery system involving personal information requires a PIA, with the privacy officer consulted from the outset. “Overhaul” catches major upgrades and migrations, not just greenfield builds. The statute scales the exercise: the assessment must be proportionate to the sensitivity of the information, the purposes, its quantity, distribution, and medium. A marketing-preferences widget merits pages; a health-data platform merits a project.

A workable Quebec PIA covers: project and data-flow description; personal information inventory with sensitivity classification; purposes and necessity; consent and transparency design; retention and destruction; security measures; access controls; automated-decision features (which carry their own disclosure duties); risks identified with mitigations and owners; and privacy-officer sign-off.

Trigger two: leaving Quebec (s. 17)

Before communicating personal information outside Quebec, or entrusting a person outside Quebec to hold, use, or communicate it, the enterprise must assess whether the information would receive adequate protection, in light of generally accepted data protection principles, considering sensitivity, purposes, safeguards, and the destination’s legal regime. The communication may proceed only if the assessment establishes adequacy, and must be covered by a written agreement addressing the identified risks. Note the breadth: Ontario counts as outside Quebec, so ordinary Canadian cloud arrangements are in scope, as is every US SaaS vendor.

Making it efficient

Organizations already running GDPR DPIAs should extend their template with Quebec’s proportionality factors and the s. 17 destination analysis rather than maintain parallel processes; the same file then evidences compliance for both regimes, alongside PIPEDA accountability, as mapped in the triple compliance guide. Build the trigger into procurement: no new system or vendor without the assessment attached. And baseline what your existing web properties already send out of province with a free scan, which maps the third-party endpoints your pages contact.

Frequently Asked Questions

When is a PIA legally required in Quebec?

Two statutory triggers: any project of acquisition, development, or overhaul of an information system or electronic service delivery involving personal information (s. 3.3), and before communicating personal information outside Quebec, including to service providers in other provinces or countries (s. 17).

Does a routine SaaS purchase trigger a PIA?

Usually yes, twice over: adopting a new system handling personal information is a s. 3.3 trigger, and if the vendor hosts or processes data outside Quebec, s. 17 requires the transfer assessment too. Proportionality lets low-sensitivity projects use a lightweight assessment.

What must the cross-border assessment conclude?

That the information would receive adequate protection in the destination, considering its sensitivity, purposes, the safeguards including contractual ones, and the destination's legal regime. If adequacy cannot be established even with contract terms, the communication should not proceed.

How is a Quebec PIA different from a GDPR DPIA?

A GDPR DPIA is triggered by high-risk processing regardless of system changes; Quebec's s. 3.3 is triggered by system projects regardless of risk level (scaled by proportionality), plus every cross-border communication. One assessment can serve both if it covers Quebec's specific factors and the GDPR Article 35 elements.

Who must be involved in the PIA?

The privacy officer (by default the person with highest authority, often delegated) must be consulted from the start of the project. Good practice adds the system owner, security, legal, and the vendor's documentation; the CAI can ask for the PIA, so it should be a real record, not a checkbox.

Regulatory Crosswalk

GDPR Art. 35 DPIAPIPEDAISO 29134

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.