Law 25 made privacy impact assessments a legal requirement in Quebec on two fronts: system projects and cross-border data flows. Since September 2023, an enterprise that stands up a new CRM without a PIA, or routes personal information to a US cloud without the transfer assessment, is violating the statute, not just best practice. The obligation is proportionate but not optional, and it is one of the easiest compliance failures for the CAI to spot because it is documentary: either the assessment exists or it does not.
| Regulation | Quebec P-39.1, ss. 3.3 and 17 |
|---|---|
| In force | 22 September 2023 |
| Max penalty | CAD 25M or 4% of worldwide turnover |
| Official text | LégisQuébec P-39.1 |
Trigger one: system projects (s. 3.3)
Any project to acquire, develop, or overhaul an information system or electronic service delivery system involving personal information requires a PIA, with the privacy officer consulted from the outset. “Overhaul” catches major upgrades and migrations, not just greenfield builds. The statute scales the exercise: the assessment must be proportionate to the sensitivity of the information, the purposes, its quantity, distribution, and medium. A marketing-preferences widget merits pages; a health-data platform merits a project.
A workable Quebec PIA covers: project and data-flow description; personal information inventory with sensitivity classification; purposes and necessity; consent and transparency design; retention and destruction; security measures; access controls; automated-decision features (which carry their own disclosure duties); risks identified with mitigations and owners; and privacy-officer sign-off.
Trigger two: leaving Quebec (s. 17)
Before communicating personal information outside Quebec, or entrusting a person outside Quebec to hold, use, or communicate it, the enterprise must assess whether the information would receive adequate protection, in light of generally accepted data protection principles, considering sensitivity, purposes, safeguards, and the destination’s legal regime. The communication may proceed only if the assessment establishes adequacy, and must be covered by a written agreement addressing the identified risks. Note the breadth: Ontario counts as outside Quebec, so ordinary Canadian cloud arrangements are in scope, as is every US SaaS vendor.
Making it efficient
Organizations already running GDPR DPIAs should extend their template with Quebec’s proportionality factors and the s. 17 destination analysis rather than maintain parallel processes; the same file then evidences compliance for both regimes, alongside PIPEDA accountability, as mapped in the triple compliance guide. Build the trigger into procurement: no new system or vendor without the assessment attached. And baseline what your existing web properties already send out of province with a free scan, which maps the third-party endpoints your pages contact.