A Montreal SaaS company with customers in Toronto and Paris is regulated three ways at once: the CAI under Law 25, the OPC under PIPEDA, and an EU supervisory authority under GDPR. Running three parallel compliance programs triples cost and guarantees drift. The workable pattern is one program, strictest-rule-wins, with a short list of jurisdiction-specific add-ons, and it works because the three laws share DNA: purpose limitation, consent, minimization, security, access.
| Regime | Law 25 | PIPEDA | GDPR |
|---|---|---|---|
| Regulator | CAI | OPC | EU DPAs |
| Max penalty | CAD 25M / 4% | CAD 100k (offences) | EUR 20M / 4% |
| Breach clock | Promptly (serious injury risk) | ASAP (RROSH) | 72 hours |
| Official text | P-39.1 | P-8.6 | 32016R0679 |
The strictest-rule map, topic by topic
Governance: follow Law 25 (privacy officer designated and published on your website) and GDPR (assess whether a formal DPO is mandatory). Consent: Law 25 and GDPR converge on clear, specific, separate consent, with express consent for sensitive data; build the banner and forms to that standard and PIPEDA is satisfied automatically. Defaults: Law 25’s section 9.1 privacy-by-default for public-facing products is the strictest single rule in North America; design to it. Impact assessments: run a combined Quebec PIA / GDPR DPIA template triggered by either regime’s conditions. Transfers: two separate machines that cannot be merged: Quebec’s s. 17 assessment plus written agreement for anything leaving the province, and GDPR’s Chapter V mechanisms for anything leaving the EU. Breach: one playbook on the GDPR 72-hour clock, with the Law 25 and PIPEDA thresholds and registers mapped in. Rights: superset handling covering access, correction, deletion/withdrawal, portability (GDPR and, since September 2024, Law 25), de-indexing (Quebec), and objection/restriction (GDPR).
The Quebec-only add-ons
Even a mature GDPR program must bolt on: French-language notices and policies; the published officer contact; the biometric declaration 60 days before any biometric database goes live; and treating the rest of Canada as “outside Quebec” for transfer purposes, which surprises national IT teams centralizing data in Ontario.
Where the exposure actually sits: GDPR fines and Law 25 penalties dwarf PIPEDA’s offence fines, but OPC findings feed class actions, and joint CAI-OPC investigations mean one incident is judged under multiple standards simultaneously. Start with the visible layer all three regulators check first, what your website collects and fires before consent, with a free scan.