QUEBEC LAW 25 · PRIVACY · ALL THREE PHASES NOW IN FORCE

Quebec Law 25, and the duties that came with it.

Quebec's modernised privacy law introduced GDPR-like requirements: mandatory privacy impact assessments, 72-hour incident notification to the CAI, privacy by default, and transparency where a decision is made exclusively by automated processing. All three implementation phases are in force. We scope the gap and tell you what has to change.


A black legal binder with a brass plate and a red wax seal on a dark desk, beside a stamp bearing a set of scales Illustrative materials
Someone has to be able to change the answer
Privacy impact assessments 72-hour notification Privacy by default Automated decisions Cross-border transfers

What is Quebec Law 25?

Law 25 — introduced as Bill 64 — is the Act to modernize legislative provisions as regards the protection of personal information. Enacted in 2021, it substantially rewrites Quebec's private-sector privacy statute and brings it close to the shape of the GDPR. All three implementation phases are now in force, which means mandatory PIAs, 72-hour incident notification, privacy by default and automated decision transparency are live obligations rather than upcoming ones.

  • Shape GDPR-aligned Similar scope, similar duties and a comparable penalty ceiling. GDPR work transfers, with Quebec-specific adjustments.
  • Incidents 72-hour notification To the Commission d'accès à l'information, and to the individuals affected, where there is a risk of serious injury.
  • Status Fully in force Phased in between September 2022 and September 2024. There is no remaining runway to plan against.

Who needs Law 25 compliance?

The test is whose personal information you hold, not where your office is. Six populations are caught, and the last two are the ones organisations outside Quebec routinely miss.

  • Quebec-based organisations Any organisation operating in Quebec that collects personal information in the course of commercial activity.
  • Processors of Quebec residents' data Organisations established outside Quebec that handle the personal information of Quebec residents.
  • Public sector entities Government bodies caught by the modernisation provisions, under the parallel public-sector regime.
  • Operators of AI systems Anyone using automated decision-making that affects Quebec residents — credit, employment, pricing, eligibility.
  • Service providers and processors Suppliers handling personal information on behalf of a Quebec entity. The duty follows the data to you.
  • Anyone transferring data out of Quebec Sending personal information outside the province requires an assessment that the receiving jurisdiction offers equivalent protection.

Law 25 sits alongside the GDPR and the CCPA rather than replacing either. For an organisation already operating across jurisdictions, most of the work is mapping what you have onto the Quebec wording — and finding the two or three duties that have no equivalent elsewhere.

How we help

How iDharma supports Law 25 compliance

Six workstreams against the mandatory privacy obligations. Each one ends in an artefact you can put in front of the CAI, not a slide about intent.

Art. 3.3

Privacy impact assessments

PIAs for the high-risk processing that requires them, structured against CAI guidance: necessity, proportionality, the safeguards actually in place, and the residual risk someone has accepted by name.

Art. 3.5–3.8

Incident notification and breach response

The 72-hour path written down before you need it: who decides there is a risk of serious injury, who drafts to the CAI, who tells the individuals, and where the incident register lives.

Art. 12.1

Automated decision transparency

An inventory of decisions made exclusively by automated processing, the notice each one owes, and a representations route that reaches a human with the authority to change the outcome.

Art. 3.1–3.2

Privacy governance and the officer

The designated privacy officer, published; the accountability framework behind them; and a policy set that says who may do what with personal information, in language the people doing it can follow.

Art. 3.4

Privacy by design and by default

The technical and organisational measures, checked where they are meant to bite: default settings on release, data minimisation in the schema, and retention that actually deletes.

Art. 17

Cross-border transfer assessments

The equivalent-protection analysis for every route personal information takes out of Quebec, the contractual safeguards behind it, and the disclosure your privacy notice owes about it.

Every assessment activity is dated, owned and evidenced. That record is the point: what a CAI investigation asks for is not a claim that you were compliant, but the trail showing the decision was made, by whom, and on what basis.

Coverage

Complete Law 25 requirements coverage

The assessment tests against every major Law 25 obligation, grouped into four families. Nothing in scope is left to a follow-up engagement.

36
Law 25 key requirements
36
Covered by the assessment
100%
Coverage across all categories
Privacy governance Policies, accountability, the designated privacy officer and the governance structure behind them.
8 of 8 by the assessment
Individual rights Access, portability, rectification, erasure, withdrawal of consent and the automated-decision rights.
12 of 12 by the assessment
Processing obligations PIAs, privacy by design and by default, security safeguards and retention limits.
10 of 10 by the assessment
Incident management 72-hour notification, individual alerts, the CAI report and the remediation record.
6 of 6 by the assessment
Built for Quebec

Scoped for Quebec privacy compliance

PIA method

CAI-aligned privacy impact assessment templates and the trigger test that decides when one is required.

72-hour path

Incident triage, the risk-of-serious-injury call and a CAI notification route with named owners.

Automated decisions

System inventory, the notice each decision owes, and a representations route that reaches a person.

Multi-jurisdiction map

A crosswalk to GDPR and CCPA so one control set answers three regulators instead of three programmes.

Timeline

Three-phase implementation timeline

Law 25 came into force gradually between September 2022 and September 2024. The phases matter now only as a way of finding which duties an older programme was built before.

  1. 22 Sept 2022 · In force

    Initial requirements

    Governance and transparency first, which is why programmes that started here often stop here.

    • Privacy governance and accountability obligations
    • Consent changes, including opt-in for minors
    • Enhanced transparency requirements
    • New individual rights, including data portability
  2. 22 Sept 2023 · In force

    Core compliance

    The phase that added the two duties with real operational weight.

    • Mandatory privacy impact assessments
    • Privacy by default in live systems
    • Incident notification within 72 hours to the CAI
    • A designated privacy officer, published
  3. 22 Sept 2024 · Fully in force

    Full enforcement

    Everything applies, and the penalty ceiling applies with it.

    • All Law 25 provisions fully in force
    • Maximum penalties now available to the CAI
    • Automated decision-making transparency complete
    • Cross-border transfer protections active

All provisions are in force. An organisation that scoped its Law 25 work in 2022 and has not revisited it is almost certainly missing the phase-two duties — PIAs and the 72-hour path are the two that most often turn out never to have been built.

Obligations

Key compliance obligations

The core requirements an organisation has to implement under Law 25, with what each one actually asks for.

Art. 3.3

Privacy impact assessments

Mandatory before any processing likely to create a significant risk of serious injury to privacy, and updated when the circumstances change.

  • High-risk processing activities
  • New technologies or processing methods
  • Large-scale systematic monitoring
  • Sensitive categories of personal information
Art. 3.5–3.8

Incident notification

Notify the CAI and the individuals affected within 72 hours of becoming aware of a confidentiality incident presenting a risk of serious injury.

  • Notification to the CAI within 72 hours
  • Direct notification to affected individuals
  • Incident documentation and a register
  • Remediation measures, recorded
Art. 12.1

Automated decision-making

Where a decision is made exclusively by automated processing, the individual must be told, and must be able to reach a human who can change the answer.

  • Inform individuals of automated decisions
  • Accept representations on the decision
  • Provide human intervention on request
  • Explain the criteria the decision used
Art. 8–14

Transparency and consent

Notices in clear language, consent that is express and given purpose by purpose, and heightened protection for minors.

  • Clear, plain privacy notices
  • Specific consent for each purpose
  • Opt-in consent required for minors
  • A working withdrawal mechanism
The engagement

Law 25 implementation roadmap

A practical path to full compliance. The weeks are indicative — the variable is how much of the processing inventory already exists.

  1. Weeks 1–3

    Gap assessment

    Find out what you have before deciding what to build.

    • Audit current privacy practice against Law 25
    • Identify high-risk processing requiring a PIA
    • Designate or confirm the privacy officer
    • Document the consent mechanisms in use
  2. Weeks 4–8

    Governance foundation

    The framework the rest of the work hangs from.

    • Draft the privacy governance policy set
    • Put a privacy-by-design framework in place
    • Establish the incident response procedure
    • Rewrite the privacy notices
  3. Weeks 9–14

    Operational compliance

    Where the duties stop being documents and start being controls.

    • Run the PIAs for high-risk processing
    • Stand up the 72-hour notification path
    • Document automated decision-making systems
    • Assess cross-border transfer mechanisms
  4. Ongoing

    Continuous monitoring

    The stage most programmes skip, and the one the CAI will ask about.

    • Monitor compliance against every obligation
    • Update PIAs when the processing changes
    • Keep incident response exercised, not just written
    • Run privacy training on a real cadence
Consequences

Penalties and enforcement

The Commission d'accès à l'information du Québec has broad investigative powers and a penalty ceiling comparable to the GDPR's.

Administrative

Up to CAD $25 million or 4% of worldwide turnover

Whichever is greater, for serious violations.

  • Failure to conduct a mandatory PIA
  • Non-compliance with incident notification
  • Inadequate privacy governance
  • Cross-border transfer violations
Penal

Up to CAD $10 million or 2% of worldwide turnover

For penal violations and repeated non-compliance.

  • Obstruction of a CAI investigation
  • False or misleading information to the CAI
  • Intentional privacy violations
  • Repeated failure to comply with an order
Authority

Commission d'accès à l'information

Quebec's independent privacy authority, with investigation and enforcement powers.

  • Compliance investigations and audits
  • Orders to cease non-compliant practices
  • Public reporting of violations
  • Referral for prosecution

The ceiling is not the point. The CAI can investigate a complaint, audit on its own initiative and order a practice stopped — and an order to stop processing lands on a business faster than any fine does.

In context

How Law 25 compares to other privacy laws

Quebec's privacy law set beside the two regimes most organisations already run. The rows where the three genuinely differ are consent, impact assessments and the breach clock.

Aspect Quebec Law 25 GDPR CCPA
Jurisdiction Quebec, Canada European Union and EEA California, USA
Legal status Provincial statute EU regulation, directly applicable State statute
Applies to Quebec residents' data EU residents' data California consumers' data
Penalties Up to CAD $25M or 4% of turnover Up to EUR 20M or 4% of turnover Up to $7,500 per intentional violation
Breach notification 72 hours, to the CAI and individuals 72 hours, to the DPA and individuals No fixed notification deadline
Consent model Opt-in, express, purpose by purpose Opt-in, explicit Opt-out
Impact assessments Mandatory PIAs for high-risk Mandatory DPIAs for high-risk None mandated
Data portability Yes, a new right under Law 25 Yes, full right Limited
Automated decisions Notice and representations to a human Article 22 restrictions and safeguards Limited opt-out of profiling
Enforcement CAI National supervisory authorities California AG and the CPPA

An organisation already compliant with the GDPR will recognise most of Law 25. PIAs, breach notification and privacy by design transfer almost directly; what does not transfer is the automated-decision representations right, the Quebec-specific minors' consent rule, and the equivalent-protection test for transfers out of the province.

Policy templates

Privacy governance policy repository

Ready-to-use privacy policy templates aligned to Law 25, and mapped across to GDPR and CCPA so one document set answers all three.

Privacy governance

  • Privacy Governance Policy
  • Privacy Officer Charter
  • Accountability Framework
  • Privacy by Design Policy
  • Third-Party Privacy Policy
  • Privacy Training Programme

+ 4 more policies

Risk and assessment

  • Privacy Impact Assessment Policy
  • PIA Templates, CAI-aligned
  • Risk Assessment Methodology
  • Data Protection Impact Assessment
  • Transfer Risk Assessment
  • Vendor Privacy Assessment

+ 5 more policies

Incident and response

  • Incident Response Policy
  • 72-Hour Notification Procedure
  • Breach Assessment Template
  • CAI Notification Form
  • Individual Notification Template
  • Incident Register

+ 3 more policies

Questions

Frequently asked questions

Scope, the deadlines, the duties that have no GDPR equivalent, and what happens if you are not ready.

1 Scope and timing
What is Quebec Law 25?

The Act to modernize legislative provisions as regards the protection of personal information, introduced as Bill 64 and enacted in 2021. It substantially amends Quebec's private-sector privacy statute and introduces requirements close in shape to the GDPR.

Who needs to comply with Law 25?

Organisations that collect, hold, use or disclose personal information in the course of commercial activity in Quebec, and organisations established outside Quebec that process the personal information of Quebec residents. Businesses, non-profits and public bodies are all caught, under the private-sector or public-sector regime as applicable.

What are the implementation deadlines?

Law 25 came into force in three phases. Phase one, on 22 September 2022, introduced governance and transparency duties. Phase two, on 22 September 2023, added mandatory privacy impact assessments and 72-hour incident notification. Phase three, on 22 September 2024, brought the remaining provisions and the full penalty ceiling into force. Every applicable requirement applies now.

Do we need a designated privacy officer?

Yes. Law 25 requires an organisation to designate a person responsible for the protection of personal information, and to publish that person's title and contact details. By default the role sits with the person with the highest authority in the organisation, and it can be delegated in writing. The officer oversees compliance, handles access requests and is the contact point for individuals and for the CAI.

2 The core duties
What is a privacy impact assessment, and when is one required?

A PIA is a documented assessment carried out before beginning a processing activity that presents a significant risk of serious injury to privacy. That typically covers new technologies, large-scale processing, systematic monitoring, sensitive categories of personal information and automated decision-making. The assessment has to record necessity, proportionality, the safeguards in place and the residual risk.

What triggers the 72-hour incident notification?

A confidentiality incident involving personal information that presents a risk of serious injury. That includes a breach, unauthorised access, accidental disclosure and loss of information. Where the threshold is met, the CAI and the individuals affected must be notified promptly — in practice, within 72 hours of becoming aware — with the nature of the incident, the information involved and the remediation taken.

How does Law 25 apply to automated decision-making and AI?

Where a decision is based exclusively on automated processing, the individual must be informed of that at or before the decision, and must be able to submit observations, obtain human intervention on request, and be told the principal factors and parameters behind the decision. It bites on consequential decisions — credit, employment, eligibility, pricing — and this is the duty with the least direct GDPR equivalent.

What is required for cross-border data transfers?

Before sending personal information outside Quebec you have to assess whether it will receive equivalent protection, taking account of the receiving jurisdiction's legal framework and the safeguards in place. The assessment has to be documented, the transfer covered by contractual safeguards, and the fact of the transfer disclosed in your privacy notice.

What is privacy by design and by default?

Privacy by design means building protection into a system from the outset rather than adding it before launch. Privacy by default means the settings a user is given without touching anything are the most protective ones — which is where most organisations fail the test, because the shipped default was chosen for engagement rather than for privacy.

How does this change our consent requirements?

Consent has to be express, informed, given for specific purposes and requested separately for each — a single bundled agreement no longer works. Heightened protection applies to minors under 14, where consent must come from the person having parental authority. Withdrawal has to be as easy as giving consent, and has to be acted on.

3 Penalties, GDPR and the engagement
What are the penalties for non-compliance?

Administrative monetary penalties reach CAD $25 million or 4% of worldwide turnover, whichever is greater, for serious violations. Penal penalties reach CAD $10 million or 2% of turnover. Beyond the figures, the CAI can investigate, audit on its own initiative and order a non-compliant practice stopped.

How does Law 25 compare to the GDPR?

Closely, on breach notification, impact assessments, privacy by design and portability. It differs on the automated-decision representations right, on the minors' consent rule, on the equivalent-protection test for transfers out of Quebec, and on the currency of the penalty ceiling. If you run GDPR well, most of the work is mapping rather than building.

What does an iDharma Law 25 assessment cover, and how long does it take?

It is scoped before you are charged. The variables are the size of the processing estate, whether a processing inventory already exists, and whether automated decision-making is in the population. A gap assessment typically runs three weeks, with governance and operational work behind it; we tell you the shape of all three after a short scoping call.

Get started

Ready to achieve Law 25 compliance?

Start with a gap assessment against every duty on this page — the PIAs you owe, the 72-hour path, the automated decisions in scope and the transfers leaving Quebec.

This page is guidance on how we scope an assessment, not legal advice. Law 25 is a statute and the CAI publishes its own guidance; where a scoping call turns on the wording, go to the source rather than to this page.