Quebec turned privacy accountability into an operating requirement.
Quebec Law 25 strengthened the province’s private-sector privacy requirements across governance, consent, tracking, privacy impact assessments, individual rights, automated decisions, confidentiality incidents, and transfers outside Quebec. Captain Compliance helps your team put those obligations into repeatable workflows.
One law. Several operational responsibilities.
Law 25 modernized Quebec’s Act respecting the protection of personal information in the private sector. Its principal implementation phases took effect in September 2022, September 2023, and September 2024. The summary card above sets out the jurisdiction, statute, regulator, privacy-leadership rule, response timeline, and the separate administrative and penal exposure ranges that shape day-to-day operations.
Law 25 reaches far beyond a privacy policy.
The law connects public-facing transparency with internal governance. A banner alone cannot address project reviews, incident records, privacy requests, automated decisions, retention, or transfers outside Quebec.
The person exercising the highest authority in the enterprise becomes the privacy officer by default. The function may be delegated in writing, and the officer’s title and contact information must be published.
Privacy impact assessments may be required when acquiring, developing, or overhauling systems or electronic services involving personal information—and before communicating personal information outside Quebec.
Organizations must explain their collection practices in clear language. Technologies that identify, locate, or profile people trigger additional notice requirements, and sensitive personal information generally requires express consent.
The CAI can investigate and pursue corrective or monetary action. The statute also provides penal offences and a damages provision: where an unlawful infringement causes injury and is intentional or results from gross fault, a court must award punitive damages of at least C$1,000.
Turn Law 25 obligations into repeatable workflows.
Captain Compliance brings website controls, privacy operations, evidence, and accountability into one coordinated program.
Consent management
Present clear choices, separate purposes, support withdrawal, and record the consent signals associated with each visitor. Configure Quebec-aware experiences without forcing every visitor into the same workflow.
Cookie and tracker monitoring
Scan for cookies, pixels, tags, SDKs, and other website technologies. Detect changes over time and block configured non-essential technologies until the appropriate choice is recorded. Law 25’s highest-privacy-default provision expressly excludes browser-cookie privacy settings, but separate transparency, consent, necessity, and profiling requirements may still affect website tracking.
English and French privacy experiences
Deliver Quebec-specific consent and privacy experiences in English and French while keeping the underlying purposes, categories, vendors, and consent records aligned. French-language requirements arise primarily under Quebec’s language laws rather than under Law 25 itself.
Clear privacy notices
Publish a clear confidentiality policy describing collection purposes, methods, rights, withdrawals, relevant third parties, possible transfers outside Quebec, and privacy-officer contact information.
Individual-rights workflows
Receive, verify, assign, and document access, rectification, portability, and other qualifying privacy requests. Track the 30-day response period and preserve the response history. De-indexing is a qualified right that applies only when the statutory conditions are satisfied—not an unconditional right to erase unfavorable information.
Privacy impact assessments
Start PIAs early, document the data involved, evaluate sensitivity and risk, record safeguards, and retain approvals for system projects and for transfers of personal information outside Quebec.
Confidentiality incident management
Document confidentiality incidents, assess the risk of serious injury, record mitigation, coordinate required notifications, and maintain an incident register that can be produced to the CAI on request. Register information must generally be kept for at least five years after the organization becomes aware of the incident.
Governance and privacy leadership
Publish privacy-officer contact information, assign internal responsibilities, document retention and destruction practices, manage complaints, and maintain evidence of continuing oversight.
A Quebec-specific layer inside your broader privacy program.
Law 25 can overlap with PIPEDA and other Canadian privacy requirements. Captain Compliance lets your organization operate one coordinated privacy stack while routing notices, consent experiences, requests, PIAs, and records according to the relevant jurisdiction and activity.
Geolocation can help deliver the appropriate experience, but a visitor’s detected location is an implementation signal—not a complete legal determination of whether Law 25 applies.
Book a Quebec privacy review- Detect — Identify trackers, collection points, vendors, and changes across your digital properties.
- Respond — Route requests, consent choices, PIAs, incidents, and approvals to the right owners.
- Demonstrate — Keep notices, logs, assessments, decisions, and remediation records connected to the underlying workflow.
Build the program in manageable stages.
This sequence is an implementation path, not a guarantee of legal compliance. Timing depends on your systems, vendors, and the decisions your privacy officer and counsel make along the way.
- Day 1 · Discover — Scan the website and identify cookies, trackers, collection forms, vendors, and possible transfers outside Quebec.
- Week 1 · Control — Configure consent behavior, blocking rules, preference controls, and aligned English and French experiences.
- Week 2 · Publish — Deploy the Quebec-facing confidentiality policy and publish the privacy officer’s title and contact information.
- Week 3 · Operationalize rights — Launch request intake, identity verification, assignment, deadline tracking, portability, and response records.
- Week 4 · Add governance — Implement PIA templates, transfer assessments, incident procedures, retention practices, and the confidentiality-incident register.
- Ongoing · Monitor — Rescan digital properties, review new vendors and projects, update notices, and preserve evidence of changes and decisions.
From scattered obligations to documented operations.
- Unknown cookies and trackers
- One generic Canadian privacy notice
- No visible privacy contact
- PIAs handled informally
- Privacy requests arrive in email
- No central incident history
- Automated decisions are undocumented
- Vendors transfer data without review
- Continuously scanned technologies and documented changes
- Quebec-aware notice content in English and French
- Published privacy-officer title and contact information
- Structured assessments with owners, safeguards, and approvals
- Verified and tracked request workflows
- A maintained confidentiality-incident register
- Recorded inputs, factors, explanations, and review paths
- Documented outside-Quebec transfer assessments and agreements
Quebec Law 25, answered plainly.
What is Quebec Law 25?+
Who is subject to Quebec’s private-sector privacy law?+
Is Law 25 the same as PIPEDA?+
Does Law 25 require cookie opt-in consent?+
What counts as valid consent?+
When is a privacy impact assessment required?+
Does every organization need a privacy officer?+
What rights do individuals have?+
What happens after a confidentiality incident?+
What are the potential penalties under Law 25?+
Make Law 25 part of how your organization actually works.
Connect consent, tracker monitoring, privacy notices, individual requests, PIAs, confidentiality incidents, and governance in one coordinated privacy program.
Book a Quebec privacy review See Consent Management