Québec's Act respecting the protection of personal information in the private sector, commonly known as Law 25 (formerly Bill 64), represents the most significant privacy law reform in Canadian history. With its phased implementation now fully in effect, organizations operating in or serving clients in Québec face a regulatory landscape that rivals the European GDPR in both scope and severity. If your organization has not yet achieved full compliance, 2026 is the year to close every remaining gap — the Commission d'accès à l'information du Québec (CAI) has made clear that enforcement actions are accelerating.
What Is Law 25?
Law 25 modernizes Québec's existing privacy framework by amending the Act respecting the protection of personal information in the private sector (originally enacted in 1994) and the Act respecting access to documents held by public bodies and the protection of personal information. The law was adopted on September 22, 2021, with provisions phased in over three years: September 2022, September 2023, and September 2024.
The legislation applies to every private-sector organization that collects, holds, uses, or communicates personal information in Québec — regardless of where the organization is headquartered. This extraterritorial reach means that a company based in Ontario, New York, or Paris that processes personal data of Québec residents must comply. The law operates alongside the federal Personal Information Protection and Electronic Documents Act (PIPEDA) and, where applicable, Canada's Anti-Spam Legislation (CASL).
Key Obligations Under Law 25
1. Privacy Officer Designation
Every organization must designate a person responsible for the protection of personal information. By default, this role falls to the highest-ranking authority within the enterprise (typically the CEO), but it can be delegated in writing to any qualified individual. The designated officer's title and contact information must be published on the organization's website. This role carries genuine accountability — the privacy officer oversees compliance, manages breach response, and serves as the primary point of contact for the CAI.
2. Privacy Impact Assessments (PIAs)
Organizations must conduct a privacy impact assessment before initiating any project involving the acquisition, development, or redesign of an information system or electronic service delivery method that involves the collection, use, communication, retention, or destruction of personal information. PIAs must also be completed before personal information is communicated outside Québec, assessing whether the receiving jurisdiction provides adequate protection. The PIA must evaluate the sensitivity of the information, the purposes of its use, the protection measures applied, and the rights of the individuals concerned.
3. Consent Requirements
Law 25 imposes a heightened standard of consent. Consent must be manifest, free, informed, and given for specific purposes. It must be requested in clear and simple language, separately from any other information communicated to the individual. For sensitive personal information — including biometric data, health records, and financial information — consent must be express. Organizations cannot refuse to provide a product or service to someone who declines to consent to the collection of information beyond what is strictly necessary for the transaction. The law also introduces strict rules for obtaining valid consent for profiling and automated decision-making.
4. Breach Notification — 72-Hour Window
When a confidentiality incident occurs — any unauthorized access to, use, or communication of personal information, or loss of personal information — the organization must notify the CAI and the affected individuals within 72 hours if the incident presents a risk of serious injury. The organization must also maintain a register of all confidentiality incidents, regardless of severity, and provide it to the CAI upon request.
5. De-Identification and Anonymization Rules
Law 25 draws a critical distinction between de-identification (rendering data so that it no longer directly identifies an individual, while remaining reversible) and anonymization (irreversibly preventing identification by any means). Organizations that destroy personal information must do so by anonymizing it rather than simply deleting it, whenever the information could serve a legitimate purpose in anonymized form. Anonymization must be carried out according to generally accepted best practices, and the organization must have reasonable grounds to believe the process is irreversible.
6. Transparency Obligations
Organizations must publish a clear and accessible privacy policy detailing: the personal information collected, the purposes of collection, the means of collection, the rights of individuals, and whether the information is communicated outside Québec. When automated decision-making is used to render a decision about an individual, the organization must inform the person at the time the decision is made, explain the factors and parameters that led to the decision, and inform them of their right to have the decision reviewed by a human being.
7. Right to Data Portability
Individuals have the right to request that their personal information be communicated to them in a structured, commonly used technological format, or that it be transferred directly to another organization authorized to collect it. This portability right applies to information collected from the individual directly and does not extend to information generated or inferred by the organization. Organizations must respond to portability requests within 30 days.
Penalties and Enforcement
The enforcement provisions of Law 25 are among the most severe in North America. Administrative monetary penalties can reach $10 million or 2% of worldwide turnover, whichever is greater. Penal fines for offences can reach $25 million or 4% of worldwide turnover. These thresholds mirror the upper band of the European GDPR. Additionally, Law 25 introduces a private right of action enabling individuals to claim damages — including punitive damages — for privacy violations. The CAI has the authority to conduct investigations, issue orders, and impose sanctions, and has publicly stated that it intends to exercise these powers actively.
Practical Compliance Checklist for 2026
- Appoint and register a privacy officer. Publish their title and contact details on your website. Ensure they have the resources, authority, and training to fulfill the role.
- Audit all personal information holdings. Map every data flow: what you collect, where it is stored, who has access, and whether it crosses provincial or national borders.
- Review and update your privacy policy. Ensure it meets Law 25's transparency requirements, including automated decision-making disclosures and cross-border transfer notifications.
- Implement a consent management framework. Review every consent mechanism for compliance with the manifest, free, informed, and specific standard. Separate consent requests from other communications.
- Establish a PIA process. Create templates and governance workflows for conducting privacy impact assessments before launching new projects or systems.
- Build a breach response plan. Document procedures for detecting, containing, and reporting confidentiality incidents within 72 hours. Maintain a breach register.
- Develop data portability capabilities. Ensure you can export personal information in machine-readable formats within the 30-day response window.
- Review de-identification and anonymization practices. Validate that your anonymization methods meet the standard of irreversibility using generally accepted best practices.
- Train your teams. Conduct mandatory privacy training for all employees who handle personal information. Document training completion.
- Assess cross-border transfers. Conduct PIAs for every international data transfer. Evaluate the adequacy of the destination jurisdiction's privacy protections.
Law 25 in the Broader Canadian and Global Context
Law 25 does not operate in isolation. It exists alongside PIPEDA at the federal level and privacy statutes in other provinces, such as British Columbia's Personal Information Protection Act (PIPA) and Alberta's equivalent. The federal government's proposed Consumer Privacy Protection Act (CPPA) under Bill C-27, if enacted, would further reshape the landscape. Organizations should design their compliance programs to satisfy the most demanding requirements across all applicable jurisdictions.
Globally, Law 25 aligns closely with the GDPR in many respects — including the penalty structure, the emphasis on consent, and the introduction of data portability. Organizations that have already achieved GDPR compliance will find significant overlap, but must not assume equivalence: Law 25 has distinct requirements around de-identification, automated decision-making disclosure, and the role of the privacy officer that require specific attention.
Need Help with Law 25 Compliance?
Our team specializes in privacy compliance, data governance, and regulatory readiness for Canadian and international organizations. We can help you close the gaps and build a defensible compliance posture.
Get in Touch