Quebec Law 25 requirements guide
Quebec's Law 25 has been fully in force since September 2024. This guide covers who it applies to, core requirements, penalties, and enforcement.
Quebec's Law 25 has been fully in force since September 2024. This guide covers who it applies to, core requirements, penalties, and enforcement.
Quebec's Law 25 is now fully in force. The legislation significantly changed Quebec's private-sector privacy rules, introducing stronger requirements around consent, privacy governance, impact assessments, data subject rights, incident management, and data portability.
If your organization handles the personal information of people in Quebec, this guide explains who Law 25 applies to, its core requirements, how enforcement works, and what businesses should review in 2026.
Quebec's Law 25, formally An Act to modernize legislative provisions as regards the protection of personal information and originally introduced as Bill 64, is a set of amendments to Quebec's Act respecting the protection of personal information in the private sector. It governs how private-sector organizations collect, use, retain, and share people's personal information in Quebec. It is widely considered one of Canada's strictest privacy regimes.
The law was passed in September 2021 and phased in over three years starting in September 2022. It is overseen by the Commission d'accès à l'information du Québec (CAI), the province's independent privacy regulator, which investigates complaints, audits organizations, and issues penalties.
For a fast reference on scope, timeline, and enforcement, see Clym's Quebec Law 25 regulation summary.
Law 25 applies to any person or entity "carrying on an enterprise" in Quebec, a standard drawn from Quebec's Civil Code that covers organized economic activity, not only registered corporations.
Unlike laws such as the CCPA, Law 25 sets no minimum revenue or headcount threshold for coverage. The main exemptions are public bodies, which fall under a separate access-to-information law, and purely personal or domestic use of information.
Law 25's obligations were introduced in three phases between 2022 and 2024. All three are now active, so treat every item in this guide as a current obligation, not a future deadline.
Phase | Effective date | What it required |
|---|---|---|
Phase 1 | September 22, 2022 | Designate a privacy officer, update security-incident practices, and begin governance planning. |
Phase 2 | September 22, 2023 | Obtain valid, specific consent; publish a plain-language privacy policy; conduct privacy impact assessments; respect the right to de-indexation; restrict the collection of children's data. |
Phase 3 | September 22, 2024 | Fulfil the right to data portability and respond to requests within 30 days. |
The phased rollout is complete, so organizations should now treat the following as ongoing privacy obligations rather than a one-time project.
Every organization covered by Law 25 must designate a privacy officer responsible for protecting personal information. If no one is appointed, that responsibility defaults to whoever exercises the highest authority in the organization, typically the CEO. You can delegate the role in writing to any staff member or outsource it entirely, but you must publish the person's title and contact information on your website or make it available by other appropriate means.
Consent under Law 25 must generally be requested separately from other information, presented in clear and simple language, and obtained before collection, subject to specific exceptions set out in the Act. For children aged 14 or under, consent must come from a parent or legal guardian, and people must be able to withdraw consent as easily as they gave it.
A cookie banner that defaults to tracking before a visitor chooses is unlikely to meet Law 25's consent standard. See our cookie consent banner guide for what a compliant flow looks like.
See how Clym's consent management platform can help you support Law 25's consent requirements across every jurisdiction you operate in.
Any organization collecting personal information through technological means, including a website, must display a privacy policy written in clear, straightforward terms and keep it current as practices change.
Law 25 grants Quebec residents the right to access, correct, or request the destruction of their personal information, the right to de-indexation and cessation of dissemination (Quebec's version of the right to be forgotten), and, since September 2024, the right to data portability.
Portability requests must be fulfilled within 30 days, using a structured, commonly used, machine-readable format such as CSV, XML, or JSON. Before releasing data to a third party at the individual's request, the organization receiving it must also confirm that the third party is legally entitled to collect it, a nuance Osler's analysis of the portability right breaks down in more detail.
Clym's data subject request management solution helps route, verify, and track access, correction, and portability requests against the 30-day deadline.
Law 25 requires a privacy impact assessment (PIA) before certain projects involving the collection, use, or communication of personal information, particularly projects involving new technology, profiling, or the transfer of personal information outside Quebec. Requirements and exceptions vary by project type, so organizations should confirm the specifics against the statutory text or with legal counsel. The assessment should document the purpose of the processing, the risks involved, and the measures taken to address them.
Organizations must have a documented process for detecting, containing, and reporting confidentiality incidents that pose a risk of serious harm, including notifying both the CAI and affected individuals. Incident response is also where recent CAI activity is worth watching closely, covered in the enforcement section below.
Any organization planning to use biometric characteristics, such as facial recognition or fingerprint scanning, to verify or identify a person must notify the CAI in advance. This is one of the areas where the CAI has been most active, a trend covered in more detail below.
Before personal information is transferred outside Quebec, whether to a cloud provider, a US-based vendor, or a parent company abroad, organizations must complete a privacy impact assessment confirming the data will receive adequate protection and inform the individual concerned.
Businesses already subject to the GDPR or PIPEDA may recognize several Law 25 requirements, but the frameworks do not fully overlap.
Feature | Law 25 (Quebec) | GDPR (EU) | PIPEDA (Canada, federal) |
|---|---|---|---|
Regulator | CAI | National supervisory authorities | Office of the Privacy Commissioner of Canada |
Scope threshold | None. Any enterprise handling Quebec residents' data. | Contextual: offering goods or services to, or monitoring, people in the EU. | Applies to commercial activity across Canada. |
Max administrative penalty | $10 million CAD or 2% of worldwide turnover | 20 million euros or 4% of global turnover | No administrative penalty regime yet; reform proposals under Bill C-27 remain pending |
Max penal fine | $25 million CAD or 4% of worldwide turnover | Not applicable (administrative fines only) | Up to $100,000 CAD per violation in limited cases |
Right to data portability | Yes, since September 2024 | Yes, Article 20 | No explicit statutory right |
Biometric notification | Mandatory advance notice to the CAI | Treated as special category data requiring a lawful basis | No specific advance-notice requirement |
Consent language, biometric notification, and the de-indexation right differ from GDPR in detail, so organizations should not assume full overlap even where a GDPR program already exists.
Law 25 uses a two-tier penalty system. The CAI can issue administrative monetary penalties directly, up to $10 million CAD or 2% of worldwide turnover for the preceding fiscal year, whichever is greater. For more serious violations, Quebec's courts can pursue penal fines of up to $25 million CAD or 4% of worldwide turnover.
Osler's overview of the enforcement scheme notes that penal proceedings are generally reserved for cases involving serious harm, vulnerable individuals, sensitive information, intent or negligence, or an organization that obstructs the CAI's investigation. For individuals, not organizations, administrative penalties are capped at $50,000 CAD and penal fines at $100,000 CAD.
Enforcement activity has picked up alongside the phased rollout. In one notable shift, the CAI stopped publishing its public list of organizations that reported confidentiality incidents as of May 2025, though it still publishes aggregate statistics. The reporting obligation itself has not softened, only its visibility to the public.
The CAI has also been active on biometrics specifically. Recent orders have required organizations to stop using facial recognition systems for tasks as routine as employee access control, a trend Osler's biometrics analysis describes as the CAI continuing to set a high bar.
This guide covers what Law 25 requires and why. For a shorter, action-oriented walkthrough you can use to review your own privacy program item by item, see Clym's Quebec Law 25 compliance checklist.
View the Quebec Law 25 compliance checklist
Clym helps organizations manage privacy requirements across consent, policies, data subject requests, and privacy governance. ReadyCompliance® supports preconfigured settings for 190+ privacy regulations, including Quebec Law 25, while the Governance Portal provides a central place to manage privacy workflows. Clym's policy management solution can also help keep bilingual privacy and cookie policies current as your practices change.
Quebec's Law 25 is no longer in a phased implementation period. Organizations subject to the law should treat privacy governance, consent, impact assessments, incident management, and privacy rights requests as ongoing operational responsibilities, not a one-time checklist.
Regularly reviewing these processes can help identify gaps as technology, vendors, data practices, and regulatory guidance change.
Law 25 is Quebec's modernized private-sector privacy law, formally An Act to modernize legislative provisions as regards the protection of personal information. It governs how businesses collect, use, and share people's personal information in Quebec and has been fully in force since September 2024.
Any person or organization carrying on an enterprise that collects, uses, or discloses personal information about people in Quebec, regardless of size or revenue. There is no small-business exemption, though whether an out-of-province organization is covered depends on the specifics of its activities.
Law 25 was passed in September 2021 and phased in over three years. Phase 1 took effect in September 2022, Phase 2 in September 2023, and Phase 3, including the right to data portability, in September 2024. All three phases are now fully in force.
Administrative monetary penalties can reach $10 million CAD or 2% of worldwide turnover. For the most serious violations, Quebec's courts can impose penal fines of up to $25 million CAD or 4% of worldwide turnover, whichever is greater.
Both require consent, data subject rights, and impact assessments, but Law 25 has no scope threshold, adds a mandatory biometric notification requirement, and includes a right to de-indexation that differs in mechanics from the GDPR's right to erasure.
Since September 2024, Quebec residents can request their personal information in a structured, commonly used, machine-readable format such as CSV, JSON, or XML. Organizations have 30 days to respond and must verify that any third-party recipient is legally entitled to the data.