Quebec Law 25, and the duties that came with it.
Quebec's modernised privacy law introduced GDPR-like requirements: mandatory privacy impact assessments, 72-hour incident notification to the CAI, privacy by default, and transparency where a decision is made exclusively by automated processing. All three implementation phases are in force. We scope the gap and tell you what has to change.
What is Quebec Law 25?
Law 25 — introduced as Bill 64 — is the Act to modernize legislative provisions as regards the protection of personal information. Enacted in 2021, it substantially rewrites Quebec's private-sector privacy statute and brings it close to the shape of the GDPR. All three implementation phases are now in force, which means mandatory PIAs, 72-hour incident notification, privacy by default and automated decision transparency are live obligations rather than upcoming ones.
- Shape GDPR-aligned Similar scope, similar duties and a comparable penalty ceiling. GDPR work transfers, with Quebec-specific adjustments.
- Incidents 72-hour notification To the Commission d'accès à l'information, and to the individuals affected, where there is a risk of serious injury.
- Status Fully in force Phased in between September 2022 and September 2024. There is no remaining runway to plan against.
Who needs Law 25 compliance?
The test is whose personal information you hold, not where your office is. Six populations are caught, and the last two are the ones organisations outside Quebec routinely miss.
- Quebec-based organisations Any organisation operating in Quebec that collects personal information in the course of commercial activity.
- Processors of Quebec residents' data Organisations established outside Quebec that handle the personal information of Quebec residents.
- Public sector entities Government bodies caught by the modernisation provisions, under the parallel public-sector regime.
- Operators of AI systems Anyone using automated decision-making that affects Quebec residents — credit, employment, pricing, eligibility.
- Service providers and processors Suppliers handling personal information on behalf of a Quebec entity. The duty follows the data to you.
- Anyone transferring data out of Quebec Sending personal information outside the province requires an assessment that the receiving jurisdiction offers equivalent protection.
Law 25 sits alongside the GDPR and the CCPA rather than replacing either. For an organisation already operating across jurisdictions, most of the work is mapping what you have onto the Quebec wording — and finding the two or three duties that have no equivalent elsewhere.
How iDharma supports Law 25 compliance
Six workstreams against the mandatory privacy obligations. Each one ends in an artefact you can put in front of the CAI, not a slide about intent.
Privacy impact assessments
PIAs for the high-risk processing that requires them, structured against CAI guidance: necessity, proportionality, the safeguards actually in place, and the residual risk someone has accepted by name.
Incident notification and breach response
The 72-hour path written down before you need it: who decides there is a risk of serious injury, who drafts to the CAI, who tells the individuals, and where the incident register lives.
Automated decision transparency
An inventory of decisions made exclusively by automated processing, the notice each one owes, and a representations route that reaches a human with the authority to change the outcome.
Privacy governance and the officer
The designated privacy officer, published; the accountability framework behind them; and a policy set that says who may do what with personal information, in language the people doing it can follow.
Privacy by design and by default
The technical and organisational measures, checked where they are meant to bite: default settings on release, data minimisation in the schema, and retention that actually deletes.
Cross-border transfer assessments
The equivalent-protection analysis for every route personal information takes out of Quebec, the contractual safeguards behind it, and the disclosure your privacy notice owes about it.
Every assessment activity is dated, owned and evidenced. That record is the point: what a CAI investigation asks for is not a claim that you were compliant, but the trail showing the decision was made, by whom, and on what basis.
Complete Law 25 requirements coverage
The assessment tests against every major Law 25 obligation, grouped into four families. Nothing in scope is left to a follow-up engagement.
- Privacy governance Policies, accountability, the designated privacy officer and the governance structure behind them.
- 8 of 8 by the assessment
- Individual rights Access, portability, rectification, erasure, withdrawal of consent and the automated-decision rights.
- 12 of 12 by the assessment
- Processing obligations PIAs, privacy by design and by default, security safeguards and retention limits.
- 10 of 10 by the assessment
- Incident management 72-hour notification, individual alerts, the CAI report and the remediation record.
- 6 of 6 by the assessment
Scoped for Quebec privacy compliance
PIA method
CAI-aligned privacy impact assessment templates and the trigger test that decides when one is required.
72-hour path
Incident triage, the risk-of-serious-injury call and a CAI notification route with named owners.
Automated decisions
System inventory, the notice each decision owes, and a representations route that reaches a person.
Multi-jurisdiction map
A crosswalk to GDPR and CCPA so one control set answers three regulators instead of three programmes.
Three-phase implementation timeline
Law 25 came into force gradually between September 2022 and September 2024. The phases matter now only as a way of finding which duties an older programme was built before.
-
22 Sept 2022 · In force
Initial requirements
Governance and transparency first, which is why programmes that started here often stop here.
- Privacy governance and accountability obligations
- Consent changes, including opt-in for minors
- Enhanced transparency requirements
- New individual rights, including data portability
-
22 Sept 2023 · In force
Core compliance
The phase that added the two duties with real operational weight.
- Mandatory privacy impact assessments
- Privacy by default in live systems
- Incident notification within 72 hours to the CAI
- A designated privacy officer, published
-
22 Sept 2024 · Fully in force
Full enforcement
Everything applies, and the penalty ceiling applies with it.
- All Law 25 provisions fully in force
- Maximum penalties now available to the CAI
- Automated decision-making transparency complete
- Cross-border transfer protections active
All provisions are in force. An organisation that scoped its Law 25 work in 2022 and has not revisited it is almost certainly missing the phase-two duties — PIAs and the 72-hour path are the two that most often turn out never to have been built.
Key compliance obligations
The core requirements an organisation has to implement under Law 25, with what each one actually asks for.
Privacy impact assessments
Mandatory before any processing likely to create a significant risk of serious injury to privacy, and updated when the circumstances change.
- High-risk processing activities
- New technologies or processing methods
- Large-scale systematic monitoring
- Sensitive categories of personal information
Incident notification
Notify the CAI and the individuals affected within 72 hours of becoming aware of a confidentiality incident presenting a risk of serious injury.
- Notification to the CAI within 72 hours
- Direct notification to affected individuals
- Incident documentation and a register
- Remediation measures, recorded
Automated decision-making
Where a decision is made exclusively by automated processing, the individual must be told, and must be able to reach a human who can change the answer.
- Inform individuals of automated decisions
- Accept representations on the decision
- Provide human intervention on request
- Explain the criteria the decision used
Transparency and consent
Notices in clear language, consent that is express and given purpose by purpose, and heightened protection for minors.
- Clear, plain privacy notices
- Specific consent for each purpose
- Opt-in consent required for minors
- A working withdrawal mechanism
Law 25 implementation roadmap
A practical path to full compliance. The weeks are indicative — the variable is how much of the processing inventory already exists.
-
Weeks 1–3
Gap assessment
Find out what you have before deciding what to build.
- Audit current privacy practice against Law 25
- Identify high-risk processing requiring a PIA
- Designate or confirm the privacy officer
- Document the consent mechanisms in use
-
Weeks 4–8
Governance foundation
The framework the rest of the work hangs from.
- Draft the privacy governance policy set
- Put a privacy-by-design framework in place
- Establish the incident response procedure
- Rewrite the privacy notices
-
Weeks 9–14
Operational compliance
Where the duties stop being documents and start being controls.
- Run the PIAs for high-risk processing
- Stand up the 72-hour notification path
- Document automated decision-making systems
- Assess cross-border transfer mechanisms
-
Ongoing
Continuous monitoring
The stage most programmes skip, and the one the CAI will ask about.
- Monitor compliance against every obligation
- Update PIAs when the processing changes
- Keep incident response exercised, not just written
- Run privacy training on a real cadence
Penalties and enforcement
The Commission d'accès à l'information du Québec has broad investigative powers and a penalty ceiling comparable to the GDPR's.
Up to CAD $25 million or 4% of worldwide turnover
Whichever is greater, for serious violations.
- Failure to conduct a mandatory PIA
- Non-compliance with incident notification
- Inadequate privacy governance
- Cross-border transfer violations
Up to CAD $10 million or 2% of worldwide turnover
For penal violations and repeated non-compliance.
- Obstruction of a CAI investigation
- False or misleading information to the CAI
- Intentional privacy violations
- Repeated failure to comply with an order
Commission d'accès à l'information
Quebec's independent privacy authority, with investigation and enforcement powers.
- Compliance investigations and audits
- Orders to cease non-compliant practices
- Public reporting of violations
- Referral for prosecution
The ceiling is not the point. The CAI can investigate a complaint, audit on its own initiative and order a practice stopped — and an order to stop processing lands on a business faster than any fine does.
How Law 25 compares to other privacy laws
Quebec's privacy law set beside the two regimes most organisations already run. The rows where the three genuinely differ are consent, impact assessments and the breach clock.
| Aspect | Quebec Law 25 | GDPR | CCPA |
|---|---|---|---|
| Jurisdiction | Quebec, Canada | European Union and EEA | California, USA |
| Legal status | Provincial statute | EU regulation, directly applicable | State statute |
| Applies to | Quebec residents' data | EU residents' data | California consumers' data |
| Penalties | Up to CAD $25M or 4% of turnover | Up to EUR 20M or 4% of turnover | Up to $7,500 per intentional violation |
| Breach notification | 72 hours, to the CAI and individuals | 72 hours, to the DPA and individuals | No fixed notification deadline |
| Consent model | Opt-in, express, purpose by purpose | Opt-in, explicit | Opt-out |
| Impact assessments | Mandatory PIAs for high-risk | Mandatory DPIAs for high-risk | None mandated |
| Data portability | Yes, a new right under Law 25 | Yes, full right | Limited |
| Automated decisions | Notice and representations to a human | Article 22 restrictions and safeguards | Limited opt-out of profiling |
| Enforcement | CAI | National supervisory authorities | California AG and the CPPA |
An organisation already compliant with the GDPR will recognise most of Law 25. PIAs, breach notification and privacy by design transfer almost directly; what does not transfer is the automated-decision representations right, the Quebec-specific minors' consent rule, and the equivalent-protection test for transfers out of the province.
Privacy governance policy repository
Ready-to-use privacy policy templates aligned to Law 25, and mapped across to GDPR and CCPA so one document set answers all three.
Privacy governance
- Privacy Governance Policy
- Privacy Officer Charter
- Accountability Framework
- Privacy by Design Policy
- Third-Party Privacy Policy
- Privacy Training Programme
+ 4 more policies
Risk and assessment
- Privacy Impact Assessment Policy
- PIA Templates, CAI-aligned
- Risk Assessment Methodology
- Data Protection Impact Assessment
- Transfer Risk Assessment
- Vendor Privacy Assessment
+ 5 more policies
Incident and response
- Incident Response Policy
- 72-Hour Notification Procedure
- Breach Assessment Template
- CAI Notification Form
- Individual Notification Template
- Incident Register
+ 3 more policies
Frequently asked questions
Scope, the deadlines, the duties that have no GDPR equivalent, and what happens if you are not ready.
What is Quebec Law 25?
The Act to modernize legislative provisions as regards the protection of personal information, introduced as Bill 64 and enacted in 2021. It substantially amends Quebec's private-sector privacy statute and introduces requirements close in shape to the GDPR.
Who needs to comply with Law 25?
Organisations that collect, hold, use or disclose personal information in the course of commercial activity in Quebec, and organisations established outside Quebec that process the personal information of Quebec residents. Businesses, non-profits and public bodies are all caught, under the private-sector or public-sector regime as applicable.
What are the implementation deadlines?
Law 25 came into force in three phases. Phase one, on 22 September 2022, introduced governance and transparency duties. Phase two, on 22 September 2023, added mandatory privacy impact assessments and 72-hour incident notification. Phase three, on 22 September 2024, brought the remaining provisions and the full penalty ceiling into force. Every applicable requirement applies now.
Do we need a designated privacy officer?
Yes. Law 25 requires an organisation to designate a person responsible for the protection of personal information, and to publish that person's title and contact details. By default the role sits with the person with the highest authority in the organisation, and it can be delegated in writing. The officer oversees compliance, handles access requests and is the contact point for individuals and for the CAI.
What is a privacy impact assessment, and when is one required?
A PIA is a documented assessment carried out before beginning a processing activity that presents a significant risk of serious injury to privacy. That typically covers new technologies, large-scale processing, systematic monitoring, sensitive categories of personal information and automated decision-making. The assessment has to record necessity, proportionality, the safeguards in place and the residual risk.
What triggers the 72-hour incident notification?
A confidentiality incident involving personal information that presents a risk of serious injury. That includes a breach, unauthorised access, accidental disclosure and loss of information. Where the threshold is met, the CAI and the individuals affected must be notified promptly — in practice, within 72 hours of becoming aware — with the nature of the incident, the information involved and the remediation taken.
How does Law 25 apply to automated decision-making and AI?
Where a decision is based exclusively on automated processing, the individual must be informed of that at or before the decision, and must be able to submit observations, obtain human intervention on request, and be told the principal factors and parameters behind the decision. It bites on consequential decisions — credit, employment, eligibility, pricing — and this is the duty with the least direct GDPR equivalent.
What is required for cross-border data transfers?
Before sending personal information outside Quebec you have to assess whether it will receive equivalent protection, taking account of the receiving jurisdiction's legal framework and the safeguards in place. The assessment has to be documented, the transfer covered by contractual safeguards, and the fact of the transfer disclosed in your privacy notice.
What is privacy by design and by default?
Privacy by design means building protection into a system from the outset rather than adding it before launch. Privacy by default means the settings a user is given without touching anything are the most protective ones — which is where most organisations fail the test, because the shipped default was chosen for engagement rather than for privacy.
How does this change our consent requirements?
Consent has to be express, informed, given for specific purposes and requested separately for each — a single bundled agreement no longer works. Heightened protection applies to minors under 14, where consent must come from the person having parental authority. Withdrawal has to be as easy as giving consent, and has to be acted on.
What are the penalties for non-compliance?
Administrative monetary penalties reach CAD $25 million or 4% of worldwide turnover, whichever is greater, for serious violations. Penal penalties reach CAD $10 million or 2% of turnover. Beyond the figures, the CAI can investigate, audit on its own initiative and order a non-compliant practice stopped.
How does Law 25 compare to the GDPR?
Closely, on breach notification, impact assessments, privacy by design and portability. It differs on the automated-decision representations right, on the minors' consent rule, on the equivalent-protection test for transfers out of Quebec, and on the currency of the penalty ceiling. If you run GDPR well, most of the work is mapping rather than building.
What does an iDharma Law 25 assessment cover, and how long does it take?
It is scoped before you are charged. The variables are the size of the processing estate, whether a processing inventory already exists, and whether automated decision-making is in the population. A gap assessment typically runs three weeks, with governance and operational work behind it; we tell you the shape of all three after a short scoping call.
Ready to achieve Law 25 compliance?
Start with a gap assessment against every duty on this page — the PIAs you owe, the 72-hour path, the automated decisions in scope and the transfers leaving Quebec.
This page is guidance on how we scope an assessment, not legal advice. Law 25 is a statute and the CAI publishes its own guidance; where a scoping call turns on the wording, go to the source rather than to this page.