Canada Quebec / Canada / EU

Quebec Triple Compliance: Law 25, PIPEDA, and GDPR

How to build one privacy program covering Quebec Law 25, federal PIPEDA, and GDPR: which law applies when, where they diverge, and the strictest-rule map.

Regulation

Quebec P-39.1 (Law 25); PIPEDA; Regulation (EU) 2016/679

Max Penalty

CAD 25M or 4% of turnover (Law 25); EUR 20M or 4% (GDPR); CAD 100,000 (PIPEDA offences)

Enforcing Authority

CAI (Quebec); OPC (federal); EU supervisory authorities

Official Source

www.legisquebec.gouv.qc.ca

Executive Summary

  • A Quebec business serving EU customers answers to three regimes at once: Law 25 (CAI), PIPEDA for interprovincial and international commercial flows (OPC), and GDPR for EU-facing processing.
  • The efficient design is one program built to the strictest applicable rule per topic, which is usually Law 25 or GDPR, never PIPEDA.
  • Law 25 is strictest on: published privacy officer, privacy by default, biometric registration, pre-transfer assessments for any data leaving Quebec, and French-language transparency.
  • GDPR is strictest on: lawful-basis discipline, DPIA risk triggers, 72-hour breach notification, processor contracts, and EU transfer mechanisms.
  • Penalty exposure is real in two of the three: Law 25 to CAD 25 million or 4% of turnover, GDPR to EUR 20 million or 4%; PIPEDA adds reputational and class-action risk.

A Montreal SaaS company with customers in Toronto and Paris is regulated three ways at once: the CAI under Law 25, the OPC under PIPEDA, and an EU supervisory authority under GDPR. Running three parallel compliance programs triples cost and guarantees drift. The workable pattern is one program, strictest-rule-wins, with a short list of jurisdiction-specific add-ons, and it works because the three laws share DNA: purpose limitation, consent, minimization, security, access.

RegimeLaw 25PIPEDAGDPR
RegulatorCAIOPCEU DPAs
Max penaltyCAD 25M / 4%CAD 100k (offences)EUR 20M / 4%
Breach clockPromptly (serious injury risk)ASAP (RROSH)72 hours
Official textP-39.1P-8.632016R0679

The strictest-rule map, topic by topic

Governance: follow Law 25 (privacy officer designated and published on your website) and GDPR (assess whether a formal DPO is mandatory). Consent: Law 25 and GDPR converge on clear, specific, separate consent, with express consent for sensitive data; build the banner and forms to that standard and PIPEDA is satisfied automatically. Defaults: Law 25’s section 9.1 privacy-by-default for public-facing products is the strictest single rule in North America; design to it. Impact assessments: run a combined Quebec PIA / GDPR DPIA template triggered by either regime’s conditions. Transfers: two separate machines that cannot be merged: Quebec’s s. 17 assessment plus written agreement for anything leaving the province, and GDPR’s Chapter V mechanisms for anything leaving the EU. Breach: one playbook on the GDPR 72-hour clock, with the Law 25 and PIPEDA thresholds and registers mapped in. Rights: superset handling covering access, correction, deletion/withdrawal, portability (GDPR and, since September 2024, Law 25), de-indexing (Quebec), and objection/restriction (GDPR).

The Quebec-only add-ons

Even a mature GDPR program must bolt on: French-language notices and policies; the published officer contact; the biometric declaration 60 days before any biometric database goes live; and treating the rest of Canada as “outside Quebec” for transfer purposes, which surprises national IT teams centralizing data in Ontario.

Where the exposure actually sits: GDPR fines and Law 25 penalties dwarf PIPEDA’s offence fines, but OPC findings feed class actions, and joint CAI-OPC investigations mean one incident is judged under multiple standards simultaneously. Start with the visible layer all three regulators check first, what your website collects and fires before consent, with a free scan.

Frequently Asked Questions

Which law applies to which data?

Law 25: personal information handled in the course of carrying on an enterprise in Quebec. PIPEDA: commercial activity in the rest of Canada, plus interprovincial and international flows and federal works. GDPR: processing tied to an EU establishment or offering goods/services to, or monitoring, people in the EU. Most datasets in a Quebec business with EU customers sit under two or three simultaneously.

Can one breach response satisfy all three?

One process, three notifications. GDPR sets the tightest clock (72 hours to the supervisory authority). Law 25 and PIPEDA both require reporting where there is a risk of serious injury / real risk of significant harm, as soon as feasible, plus internal registers (24-month record retention under PIPEDA). Build the playbook to the 72-hour standard and map the differing thresholds.

Do I need both a Quebec PIA and a GDPR DPIA?

One document can serve both if scoped correctly: cover Quebec's s. 3.3 system-project and s. 17 cross-border factors plus GDPR Article 35's risk elements. The triggers differ (Quebec: system projects and transfers; GDPR: high-risk processing), so run the combined template whenever either trigger fires.

What is uniquely Quebec, with no GDPR equivalent to reuse?

The published privacy officer contact, French-language requirements for notices under Quebec's language framework, the 60-day biometric database declaration to the CAI, and de-indexing rights. These need Quebec-specific tasks even in a mature GDPR program.

Does EU adequacy help a Quebec company?

For EU-to-Canada inbound data, yes: Canada's partial adequacy (reaffirmed January 2024) covers PIPEDA-governed commercial processing, and Quebec's regime is at least as protective. Outbound from Quebec, adequacy is irrelevant: s. 17 requires your own transfer assessment for any data leaving the province, including to the rest of Canada.

Regulatory Crosswalk

GDPRPIPEDAQuebec Law 25

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.