home / frameworks / quebec-law-25

// Canadian privacy and cyber law

Act respecting the protection of personal information in the private sector, as amended by Law 25

Law 25 rewrote Quebec's private-sector privacy law in 3 phases from 2022 to 2024. Enterprises must name a person in charge of personal information, report confidentiality incidents, keep an incident register, and run privacy impact assessments, with fines of up to $25 million or 4% of turnover.

Quebec

Overview

Bill 64, An Act to modernize legislative provisions as regards the protection of personal information, was assented to on September 22, 2021 and is known as Law 25. It amended both of Quebec's privacy statutes, including the Act respecting the protection of personal information in the private sector (CQLR c. P-39.1). The changes came into force in 3 phases. On September 22, 2022 the person in charge of personal information and the confidentiality incident rules took effect. Most obligations followed on September 22, 2023, including governance policies, privacy impact assessments, stricter consent, transparency, privacy by default, and the new penalty regime. Data portability came last, in 2024.

Accountability starts at the top. The enterprise's highest authority is the default person in charge of personal information and may delegate the role in writing, and the title and contact details must be published on the enterprise's website. A confidentiality incident covers unauthorized access, use, or communication, and any loss of personal information. If an incident presents a risk of serious injury, the enterprise must promptly notify the CAI and the people affected. Every incident goes in a register, kept for at least 5 years.

Enforcement is stronger than in most Canadian privacy laws. Since September 22, 2023 the CAI can impose administrative monetary penalties on enterprises of up to $50,000 for an individual and, in other cases, $10 million or 2% of worldwide turnover, whichever is greater. Penal fines for organizations run from $15,000 to $25 million, or 4% of worldwide turnover if that's higher. Courts set those fines.

Who it applies to in Canada

Every person carrying on an enterprise in Quebec, from sole proprietors to corporations, partnerships, and associations, plus some non-profits that carry on organized economic activity. Organizations located outside Quebec are covered for personal information they handle in the course of their enterprise activities in Quebec.

Quebec's private-sector law is recognized as substantially similar to PIPEDA, so it applies instead of the federal law for activity within the province. Any Canadian business with Quebec customers or staff has to meet its governance, incident, and impact assessment rules, enforced by the Commission d'accès à l'information (CAI).

Controls at a glance

The obligations below follow the main themes of the amended Act and the 3 Law 25 phases.

Governance and accountability

  • Highest authority is person in charge by default
  • Delegate the role in writing if needed
  • Publish the person in charge's title and contact details
  • Adopt and publish governance policies and practices

Confidentiality incidents

  • Take reasonable steps to reduce the risk of injury
  • Assess risk of serious injury for each incident
  • Promptly notify the CAI when risk is serious
  • Notify affected individuals and helpful third parties
  • Keep an incident register for at least 5 years

Privacy impact assessments

  • Assess projects to acquire, develop, or overhaul systems
  • Assess before communicating data outside Quebec
  • Assess certain disclosures for research purposes
  • Involve the person in charge in assessments

Consent and transparency

  • Get consent that is manifest, free, and enlightened
  • Ask for consent separately and for specific purposes
  • Get express consent for sensitive information
  • Tell people why and how data is collected

Technology and profiling

  • Set products to the highest privacy level by default
  • Disclose tracking, locating, or profiling technologies
  • Inform people of fully automated decisions
  • Disclose biometric databases to the CAI in advance

Individual rights

  • Answer access and correction requests within 30 days
  • Provide data in a structured, commonly used format
  • Handle requests to stop dissemination or de-index
  • Explain automated decisions on request

Retention, anonymization, and sharing

  • Destroy or anonymize data once purposes are met
  • Follow regulatory criteria for anonymization
  • Use written agreements when sharing with service providers

Enforcement and penalties

  • CAI penalties up to $10 million or 2% of turnover
  • Penal fines up to $25 million or 4% of turnover
  • CAI may inspect, investigate, and issue orders

Certification and assessment

There is no certification. The CAI receives incident notices and complaints, can inspect and investigate enterprises, issue orders, and impose administrative monetary penalties. It can also start penal proceedings, where a court sets the fine.

Dates to know

2021-09-22
Bill 64 (Law 25) assented to
2022-09-22
Phase 1: person in charge of personal information and confidentiality incident rules in force
2023-09-22
Phase 2: governance policies, impact assessments, consent, transparency, and penalties in force
2024-09-22
Phase 3: right to data portability in force

Resources

Official texts and free tools for Quebec Law 25. Links open the publisher’s site.

Need help? Browse the directory or read the guides.

References

  1. An Act to modernize legislative provisions as regards the protection of personal information (S.Q. 2021, c. 25), Publications du Québec
  2. Bill 64 legislative history, National Assembly of Québec
  3. Principaux changements apportés par la Loi 25, Commission d'accès à l'information du Québec
  4. Incidents de confidentialité et mesures de sécurité (entreprises), Commission d'accès à l'information du Québec