Skip to the main content.

12 min read

Quebec Law 25 (Loi 25): What Every Canadian Business Needs to Know in 2026 Not Just Quebec Companies

Quebec Law 25 (Loi 25): What Every Canadian Business Needs to Know in 2026 Not Just Quebec Companies
Quebec Law 25 (Loi 25): What Every Canadian Business Needs to Know in 2026 Not Just Quebec Companies
25:43

A Vancouver-based e-commerce SMB gets an email in September 2025 from the Commission d'accès à l'information du Québec (CAI). The company has never had an office in Quebec, never had an employee in Quebec, and has never intentionally marketed to Quebec residents. But their online store accepts orders from anyone in Canada including, as it turns out, several hundred customers from Quebec over the past three years. The CAI is asking about their privacy officer designation, their consent management practices, their breach notification procedures, and their retention policies. Under Quebec Law 25, all of these are now their legal obligation.

This scenario is not hypothetical. Quebec Law 25 formally 'An Act to modernize legislative provisions as regards the protection of personal information,' originally introduced as Bill 64 has extraterritorial reach that many Canadian businesses have not fully absorbed. It applies to any organization holding personal information about Quebec residents, regardless of where the organization itself is located. A Calgary manufacturer with Quebec customers, a Toronto SaaS company with Quebec subscribers, a Vancouver clinic with Quebec patients, and a Halifax retailer with Quebec online orders are all subject to Law 25.

The Office of the Privacy Commissioner of Canada has publicly acknowledged that Quebec Law 25 imposes obligations that exceed PIPEDA in several material respects. The Canadian Bar Association's national privacy section has issued guidance noting that Law 25 is the strictest private-sector privacy law in Canada and, in some respects, in North America.

Law 25 has been rolled out in phases since September 2022, with the final major provisions taking effect in September 2024 data portability, right to demand deidentification, and the full breadth of automated decision-making transparency obligations. As of 2026, the Commission d'accès à l'information du Québec (CAI) is actively enforcing Law 25 with published decisions, monetary administrative penalties, and public naming of non-compliant organizations.

GAM Tech has supported Canadian businesses through Law 25 compliance from our 8 offices across Alberta (Calgary HQ, Edmonton, Red Deer), British Columbia (Vancouver, Victoria), Ontario (Toronto, Ottawa), and Quebec (Montréal) with bilingual English and French support in Ottawa and Montréal, and a Montréal office located at 2485 Rue Fleury E that gives us direct expertise in Quebec regulatory expectations. What follows is a practical guide for Canadian businesses outside Quebec whose operations, customer base, or supply chain now brings them under Law 25.

 

Does Quebec Law 25 Apply to Your Canadian Business?

The Extraterritorial Reach: Who's Actually Covered

Quebec Law 25 applies to 'any enterprise, whether private or public, that carries on its activity in Quebec or that collects, holds, uses or communicates personal information in the course of activities in Quebec.' Courts and the CAI have interpreted this broadly. Practical scope includes:

  • Any organization with a physical office, employee, or contractor in Quebec.

  • Any organization with Quebec-resident customers, subscribers, or end users including through e-commerce, SaaS, or digital services.

  • Any organization holding personal information about Quebec residents, even if collected outside Quebec (a Toronto medical clinic seeing a Quebec resident temporarily in Ontario, for example).

  • Any organization processing Quebec residents' personal information as a service provider to another company (data processors, cloud vendors, marketing agencies).

  • Any organization whose website is accessible to Quebec residents and that collects personal information through that website.

For most Canadian SMBs with any customer base spanning multiple provinces or any online presence, Law 25 applies.

What Counts as 'Personal Information' Under Law 25

Law 25 defines personal information broadly any information about a natural person that allows the person to be identified. This includes: name, address, phone number, email, date of birth, financial information, health information, IP address, cookie data that can be linked to an individual, behavioural profiles, and metadata associated with any of the above. The definition is functionally equivalent to PIPEDA's, but Law 25 imposes materially stricter obligations on how you collect, use, disclose, and protect it.

Sensitive Personal Information Gets Special Treatment

Law 25 introduces the category of 'sensitive personal information,' which includes health data, biometric data, ethnic or racial origin data, sexual orientation, religious beliefs, and financial information indicating economic vulnerability. Sensitive personal information requires explicit, granular, informed consent no lumping together with general terms of service.

 

The Core Obligations Under Quebec Law 25

Designation of a Privacy Officer

Every organization subject to Law 25 must designate an individual responsible for the protection of personal information. For SMBs, this can be an existing executive (CEO, COO, CFO) or a designated privacy officer. The person's title and contact information must be published on the organization's website. This obligation took effect September 2022 and is one of the most commonly missed baseline requirements.

Privacy Impact Assessments (PIAs)

Law 25 requires a documented Privacy Impact Assessment before any 'project of acquisition, development or overhaul of an information system or electronic service delivery system' involving personal information. In practice, this means:

  • Before deploying a new CRM, marketing platform, or customer database.

  • Before adopting a new cloud service that will hold Quebec residents' data.

  • Before implementing analytics, tracking, or profiling technology.

  • Before any material change to how personal information is collected, used, or disclosed.

PIAs must be documented, retained, and made available to the CAI on request. For organizations processing sensitive personal information at scale, PIAs are functionally the equivalent of the Data Protection Impact Assessments required under the EU GDPR.

Transparency and Consent

Law 25 requires clear, specific, and informed consent for collection, use, and disclosure of personal information. Consent must be:

  • Granular — a single 'I agree to the terms' checkbox is insufficient for the collection of multiple types of personal information for multiple purposes.

  • Distinct from other terms — privacy consent cannot be buried in general terms of service.

  • Explicit for sensitive personal information — implicit consent is not sufficient.

  • Revocable — individuals must be able to withdraw consent as easily as they gave it.

  • Prospective — you cannot obtain 'blanket' consent for unspecified future uses.

Breach Notification

Law 25 requires notification of the Commission d'accès à l'information du Québec and affected individuals for any 'confidentiality incident' presenting a risk of serious injury. The definition of 'confidentiality incident' is broader than PIPEDA's it captures not just unauthorized access but also loss, use, or communication contrary to law. Notification obligations run in parallel with PIPEDA and federal notification requirements. Organizations that experience a breach affecting Quebec residents must therefore make two (or more) parallel notifications with different content, format, and timing requirements.

Data Portability and Right to Deidentification

As of September 2024, individuals have the right to obtain their personal information in a structured, commonly used technological format (data portability). Individuals also have the right to demand that their personal information be deidentified or destroyed when the purpose of collection has been fulfilled. Both rights require IT infrastructure that can identify, extract, deidentify, or delete an individual's data across all systems where it's stored.

 

IT Architecture Requirements for Law 25 Compliance

Data Inventory and Mapping

You cannot comply with Law 25 if you don't know what personal information you hold, where it lives, why you collected it, or who has access. Every organization subject to Law 25 needs:

  • A documented inventory of personal information held categories, source, purpose, retention period.

  • A data flow map how personal information moves through your systems and to third parties.

  • A list of service providers and processors handling personal information on your behalf, with executed contracts covering their Law 25 obligations.

  • A retention schedule aligned to the purpose of collection.

Consent Management Infrastructure

Manual consent tracking does not scale. Practical Law 25 compliance requires infrastructure a consent management platform, granular preference centers, and audit-logged consent records tied to individual users. For SMBs, this typically means integrating a consent platform (OneTrust, Cookiebot, Termly, Iubenda, or equivalent) with your CRM and marketing systems.

Cross-Border Data Transfers

Law 25 imposes specific requirements on transfers of personal information outside Quebec, including transfers within Canada. Organizations must conduct a Privacy Impact Assessment for cross-border transfers considering the sensitivity of the information, the purpose, the safeguards in place, and the legal framework in the destination jurisdiction. This applies to routine business scenarios hosting data on servers outside Quebec, using cloud services with US-based infrastructure, sharing data with parent companies or affiliates elsewhere.

Right to Deidentification: The Technical Challenge

The right to demand deidentification or deletion is technically demanding. Your systems need to be able to:

  • Locate all instances of an individual's personal information across databases, backups, and third-party systems.

  • Deidentify or delete on request while preserving records required by other legal obligations (tax records, contractual obligations, health record retention).

  • Document what was deidentified or deleted and when.

  • Extend the deletion request to processors and third parties as required.

For most Canadian SMBs, this requires a systematic approach to data inventory that's typically absent from ad-hoc systems accumulated over years of business growth.

 

Penalties and Enforcement Under Law 25

Administrative Monetary Penalties

The Commission d'accès à l'information du Québec has the authority to impose administrative monetary penalties for Law 25 violations. Fines can reach up to $10 million or 2% of worldwide turnover for enterprises, whichever is greater. Courts can impose penal fines up to $25 million or 4% of worldwide turnover.

These are not theoretical maximums. The CAI has issued published decisions with monetary penalties for organizations that failed to meet basic Law 25 obligations inadequate consent mechanisms, missing privacy officer designations, insufficient breach notification, and failure to conduct PIAs.

Private Right of Action

Law 25 gives individuals a private right of action the ability to sue an organization directly for privacy violations, separate from any CAI enforcement action. Damages awarded under Law 25 civil actions have generally been modest to date, but the framework opens class-action pathways that Canadian privacy law has historically limited.

Reputational Risk

CAI decisions are published publicly. Organizations named in CAI decisions become part of the public record and appear in ongoing regulatory conversations, media coverage, and increasingly cybersecurity underwriter and B2B customer due diligence questionnaires. The reputational cost of a public CAI finding often exceeds the monetary penalty.

 

Practical Steps: Getting Your Canadian Business Compliant

Baseline Compliance Checklist for Non-Quebec Canadian Businesses

For a Canadian SMB outside Quebec that has determined Law 25 applies, the baseline compliance actions are:

  • Designate a privacy officer and publish their name and contact information.

  • Draft and publish a Law 25-compliant privacy policy (bilingual English/French recommended, particularly for the Quebec-facing version).

  • Implement consent management with granular controls and easy withdrawal.

  • Complete a personal information inventory and data flow map.

  • Execute Data Processing Agreements with all service providers handling personal information.

  • Implement a breach notification procedure that satisfies both PIPEDA and Law 25 timelines.

  • Establish a PIA process for new projects and major changes.

  • Implement technical infrastructure for data portability and deidentification requests.

  • Document retention schedules aligned to purpose of collection.

  • Train staff on Law 25 obligations, particularly customer-facing and marketing teams.

Timeline Realism

Full Law 25 compliance typically takes 3-6 months for a mid-sized Canadian SMB starting from a low compliance baseline. Priority sequence:

  • Month 1: Privacy officer designation, privacy policy update, data inventory kickoff.

  • Months 2-3: Consent management implementation, DPA execution with processors, breach notification procedure.

  • Months 4-5: PIA framework, cross-border transfer assessment, staff training.

  • Month 6: Technical infrastructure for data portability and deidentification, ongoing operational integration.

Organizations subject to Law 25 that have not yet started should not delay every day of non-compliance is a day of accumulating regulatory exposure.

 

GAM Tech Differentiators: Law 25 Compliance Support for Canadian Businesses

GAM Tech (GAM Technical Services Inc.) supports Canadian businesses through Quebec Law 25 compliance with a specific advantage: our Montréal office at 2485 Rue Fleury E gives us direct on-the-ground expertise in Quebec regulatory expectations, and bilingual English and French support in both Ottawa and Montréal means we can support your bilingual privacy documentation, Quebec-facing customer communications, and interactions with the Commission d'accès à l'information du Québec.

SOC 2 certified and Certified B Corporation. Ranked #97 globally / #1 in Western Canada on the 2026 MSP 501. Named to Canada's Top 50 Best Managed IT Companies for five consecutive years (2021-2025). Great Place to Work-Certified Top 100 Best Workplaces in Canada. Our SOC 2 certification is directly relevant to Law 25 compliance the SOC 2 Trust Services Criteria for security, availability, confidentiality, and privacy align with the technical safeguards Law 25 expects from service providers.

Our compliance frameworks explicitly cover PIPEDA, HIPAA, PCI-DSS, NIST Cybersecurity Framework, ISO 27001, and Quebec Law 25 (Loi 25). For clients whose operations bring them under Law 25, we support the IT infrastructure side of compliance: data inventory tooling, consent management integration, backup and retention configured to Law 25 retention rules, breach notification response procedures, cross-border transfer assessments, and the technical capabilities needed for data portability and deidentification requests.

Every Managed IT plan includes 24/7/365 support with a 5-minute response commitment delivered on 99%+ of tickets, a named Client Success Manager for strategic guidance, and a dedicated 24/7 help desk team for day-to-day tickets. Professional services on the majority of IT projects including Law 25 readiness assessments, technical infrastructure builds, and privacy-related integrations are included in the plan with no separate project fees.

Pricing is per managed device (computer, server, or network device), not per user Silver plans start at $110 per managed device per month, with a $1,000 monthly minimum. Contact GAM Tech for pricing specific to your business size and Law 25 compliance requirements.

 

Frequently Asked Questions: Quebec Law 25 for Canadian Businesses

Does Quebec Law 25 apply to my business if I'm not in Quebec?

Yes, if you hold personal information about Quebec residents. Law 25 has extraterritorial reach it applies to any organization holding, using, or disclosing personal information of Quebec residents regardless of where the organization itself is located. A Vancouver e-commerce store with Quebec customers, a Toronto SaaS platform with Quebec subscribers, a Calgary consulting firm with Quebec clients, and a Halifax retailer accepting orders from Quebec residents are all subject to Law 25.

What is the difference between Quebec Law 25 and PIPEDA?

PIPEDA is the federal baseline for private-sector personal information handling. Quebec Law 25 imposes materially stricter obligations in several respects: granular consent requirements (versus PIPEDA's more flexible standard), mandatory Privacy Impact Assessments for new projects, data portability and right to deidentification rights, higher penalties, and specific requirements around cross-border transfers. Where both apply, organizations must satisfy the higher standard which is generally Law 25.

What are the penalties for non-compliance with Law 25?

Administrative monetary penalties can reach $10 million or 2% of worldwide turnover, whichever is greater. Penal fines can reach $25 million or 4% of worldwide turnover. Individuals have a private right of action. CAI decisions are published publicly, creating reputational exposure. These are not theoretical maximums the Commission d'accès à l'information du Québec has issued published decisions with monetary penalties for organizations failing basic Law 25 obligations.

What is a Privacy Impact Assessment (PIA) under Law 25?

A PIA is a documented assessment of the privacy impacts of a new project, information system, or major change to how personal information is collected, used, or disclosed. Law 25 requires PIAs before any project of acquisition, development, or overhaul of an information system involving personal information. For SMBs this typically covers new CRM deployments, cloud service adoptions, marketing analytics implementations, and cross-border data transfers. PIAs must be documented, retained, and made available to the CAI on request.

Do I need a privacy officer under Law 25?

Yes. Every organization subject to Law 25 must designate an individual responsible for the protection of personal information and publish their name and contact information on the organization's website. For SMBs, this can be an existing executive (CEO, COO, CFO, VP Legal) you do not need to hire a dedicated privacy officer, but you must designate someone and publish the designation. Missing this baseline obligation is one of the most commonly cited findings in CAI enforcement actions.

What does data portability mean and how do I implement it?

Data portability is the right of an individual to obtain their personal information in a structured, commonly used technological format. Implementation typically requires: the ability to identify all personal information about a specific individual across your systems, an extraction process that produces the data in a portable format (JSON, CSV, or similar), and a documented procedure for handling data portability requests within reasonable timeframes. For SMBs with modern SaaS systems, most vendors provide native data export capabilities that support this obligation; older on-premise systems may require custom extraction tooling.

How does Law 25 handle cross-border data transfers?

Law 25 requires a Privacy Impact Assessment before any cross-border transfer of personal information, considering the sensitivity of the information, the purpose of the transfer, the safeguards in place, and the legal framework in the destination jurisdiction. This applies to transfers within Canada (from Quebec to any other province) as well as international transfers. For Canadian SMBs, this typically affects: cloud hosting arrangements with providers using US or international data centers, SaaS platforms hosted outside Canada, shared services with parent companies or affiliates, and outsourced processing arrangements.

How does Law 25 breach notification compare to PIPEDA?

Both require notification of regulators and affected individuals when a breach creates a risk of serious injury (Law 25) or a real risk of significant harm (PIPEDA). The definitions and thresholds are similar but not identical, and organizations affected by a breach involving Quebec residents' data must make parallel notifications: one to the CAI under Law 25, one to the Office of the Privacy Commissioner of Canada under PIPEDA, and to affected individuals with content that satisfies both statutes. Getting the sequence and content wrong compounds regulatory exposure.

What is the biggest Law 25 compliance mistake Canadian businesses make?

Assuming Law 25 doesn't apply to them because they don't have a Quebec office. Extraterritorial reach means any Canadian business with Quebec-resident customers, subscribers, or users is subject to Law 25. The second most common mistake is treating Law 25 as a checklist of policies without implementing the technical infrastructure consent management, data inventory, breach notification response, cross-border transfer controls that Law 25 actually requires.

How much does Law 25 compliance cost for a Canadian SMB?

Compliance costs vary significantly by starting baseline and business complexity. For a mid-sized Canadian SMB starting from a low compliance baseline, Law 25 readiness typically involves: legal counsel for privacy policy and framework work ($10,000-$30,000), consent management platform ($3,000-$15,000 annually), technical infrastructure work for data inventory and portability ($10,000-$40,000 one-time), staff training and ongoing operational integration ($5,000-$15,000 annually). GAM Tech includes the technical infrastructure side of Law 25 compliance in Managed IT plan professional services with no separate project fee.

What should I look for in a managed IT provider for Law 25 compliance?

Look for: SOC 2 certification (aligns with Law 25 technical safeguard expectations); Quebec presence and bilingual French/English support (essential for Quebec-facing documentation and CAI interactions); documented Law 25 experience with references from Canadian SMBs; explicit compliance framework support including Law 25 and Loi 25 in service documentation; technical capabilities for data inventory, consent integration, and breach response; and 24/7 support for breach response. GAM Tech meets all of these criteria with an operating Montréal office and bilingual EN/FR support in both Ottawa and Montréal.

 

Law 25 Compliance Is a Canada-Wide Obligation, Not a Quebec One

Quebec Law 25 is the strictest private-sector privacy law in Canada, and its extraterritorial reach makes it a Canada-wide compliance obligation for any business with Quebec customers, users, or supply chain touchpoints. The CAI is actively enforcing Law 25 with published decisions and monetary penalties, and the reputational exposure of being named in a CAI finding compounds the direct regulatory cost.

GAM Tech supports Canadian businesses through Law 25 compliance with a specific structural advantage: our Montréal office at 2485 Rue Fleury E provides on-the-ground Quebec expertise, and bilingual English and French support in both Ottawa and Montréal covers the documentation and communication needs of Law 25 compliance. Our SOC 2 certification, compliance framework coverage, and technical capabilities are structured to support the IT-side obligations Law 25 imposes.

Contact GAM Tech to discuss your business's Law 25 compliance requirements. Call toll-free 1-833-GAM-TECH (1-833-426-8324) or book a free 30-minute consultation at gamtech.ca/book-a-consultation. We serve Canadian businesses from 8 offices Calgary (HQ), Edmonton, Red Deer, Vancouver, Victoria, Toronto, Ottawa, and Montréal with bilingual English and French support in Ottawa and Montréal.

Managed IT for Canadian Manufacturing and Logistics: OT/IT Convergence, ERP Security, and Supply Chain Risk in 2026

1 min read

Managed IT for Canadian Manufacturing and Logistics: OT/IT Convergence, ERP Security, and Supply Chain Risk in 2026

A mid-sized manufacturer in the Edmonton corridor calls their MSP on a Wednesday morning. Their ERP system is running slow. Not down slow. Orders are...

Learn more about our Managed IT Services
IT for Alberta's Oil & Gas Industry: Cybersecurity, OT/IT Convergence, and Field Connectivity in 2026

1 min read

IT for Alberta's Oil & Gas Industry: Cybersecurity, OT/IT Convergence, and Field Connectivity in 2026

Alberta's oil and gas sector is in active expansion. The Canadian Association of Energy Contractors projects 5,709 wells to be drilled in 2026 a...

Learn more about our Managed IT Services
Hardware-as-a-Service in 2026: Why Smart Canadian Businesses Are Ditching CapEx IT

1 min read

Hardware-as-a-Service in 2026: Why Smart Canadian Businesses Are Ditching CapEx IT

Introduction: The Hidden Cost of "We'll Refresh When We Have To" Walk through the offices of most Canadian SMBs and you'll see a familiar pattern: a...

Learn more about our Managed IT Services