Know what is on your site before a plaintiff’s firm does.Free website scanScan Your Site
Log in Sign up Book a demo
Solutions / Quebec Law 25 · Canada
QUEBEC LAW 25 · PRIVATE-SECTOR PRIVACY

Quebec turned privacy accountability into an operating requirement.

Quebec Law 25 strengthened the province’s private-sector privacy requirements across governance, consent, tracking, privacy impact assessments, individual rights, automated decisions, confidentiality incidents, and transfers outside Quebec. Captain Compliance helps your team put those obligations into repeatable workflows.

English and French experiencesPrivacy impact assessment workflowsDocumented accountability

One law. Several operational responsibilities.

Law 25 modernized Quebec’s Act respecting the protection of personal information in the private sector. Its principal implementation phases took effect in September 2022, September 2023, and September 2024. The summary card above sets out the jurisdiction, statute, regulator, privacy-leadership rule, response timeline, and the separate administrative and penal exposure ranges that shape day-to-day operations.

Law 25 reaches far beyond a privacy policy.

The law connects public-facing transparency with internal governance. A banner alone cannot address project reviews, incident records, privacy requests, automated decisions, retention, or transfers outside Quebec.

Officer
Named accountability

The person exercising the highest authority in the enterprise becomes the privacy officer by default. The function may be delegated in writing, and the officer’s title and contact information must be published.

PIA
PIAs before higher-risk activity

Privacy impact assessments may be required when acquiring, developing, or overhauling systems or electronic services involving personal information—and before communicating personal information outside Quebec.

Consent
Consent and tracking transparency

Organizations must explain their collection practices in clear language. Technologies that identify, locate, or profile people trigger additional notice requirements, and sensitive personal information generally requires express consent.

CAI
Multiple forms of exposure

The CAI can investigate and pursue corrective or monetary action. The statute also provides penal offences and a damages provision: where an unlawful infringement causes injury and is intentional or results from gross fault, a court must award punitive damages of at least C$1,000.

Turn Law 25 obligations into repeatable workflows.

Captain Compliance brings website controls, privacy operations, evidence, and accountability into one coordinated program.

C

Consent management

Present clear choices, separate purposes, support withdrawal, and record the consent signals associated with each visitor. Configure Quebec-aware experiences without forcing every visitor into the same workflow.

S

Cookie and tracker monitoring

Scan for cookies, pixels, tags, SDKs, and other website technologies. Detect changes over time and block configured non-essential technologies until the appropriate choice is recorded. Law 25’s highest-privacy-default provision expressly excludes browser-cookie privacy settings, but separate transparency, consent, necessity, and profiling requirements may still affect website tracking.

F

English and French privacy experiences

Deliver Quebec-specific consent and privacy experiences in English and French while keeping the underlying purposes, categories, vendors, and consent records aligned. French-language requirements arise primarily under Quebec’s language laws rather than under Law 25 itself.

N

Clear privacy notices

Publish a clear confidentiality policy describing collection purposes, methods, rights, withdrawals, relevant third parties, possible transfers outside Quebec, and privacy-officer contact information.

R

Individual-rights workflows

Receive, verify, assign, and document access, rectification, portability, and other qualifying privacy requests. Track the 30-day response period and preserve the response history. De-indexing is a qualified right that applies only when the statutory conditions are satisfied—not an unconditional right to erase unfavorable information.

A

Privacy impact assessments

Start PIAs early, document the data involved, evaluate sensitivity and risk, record safeguards, and retain approvals for system projects and for transfers of personal information outside Quebec.

I

Confidentiality incident management

Document confidentiality incidents, assess the risk of serious injury, record mitigation, coordinate required notifications, and maintain an incident register that can be produced to the CAI on request. Register information must generally be kept for at least five years after the organization becomes aware of the incident.

G

Governance and privacy leadership

Publish privacy-officer contact information, assign internal responsibilities, document retention and destruction practices, manage complaints, and maintain evidence of continuing oversight.

A Quebec-specific layer inside your broader privacy program.

Law 25 can overlap with PIPEDA and other Canadian privacy requirements. Captain Compliance lets your organization operate one coordinated privacy stack while routing notices, consent experiences, requests, PIAs, and records according to the relevant jurisdiction and activity.

Geolocation can help deliver the appropriate experience, but a visitor’s detected location is an implementation signal—not a complete legal determination of whether Law 25 applies.

Book a Quebec privacy review
Detect · Respond · Demonstrate
  • Detect — Identify trackers, collection points, vendors, and changes across your digital properties.
  • Respond — Route requests, consent choices, PIAs, incidents, and approvals to the right owners.
  • Demonstrate — Keep notices, logs, assessments, decisions, and remediation records connected to the underlying workflow.

Build the program in manageable stages.

This sequence is an implementation path, not a guarantee of legal compliance. Timing depends on your systems, vendors, and the decisions your privacy officer and counsel make along the way.

Rollout · typical Quebec org
  • Day 1 · Discover — Scan the website and identify cookies, trackers, collection forms, vendors, and possible transfers outside Quebec.
  • Week 1 · Control — Configure consent behavior, blocking rules, preference controls, and aligned English and French experiences.
  • Week 2 · Publish — Deploy the Quebec-facing confidentiality policy and publish the privacy officer’s title and contact information.
  • Week 3 · Operationalize rights — Launch request intake, identity verification, assignment, deadline tracking, portability, and response records.
  • Week 4 · Add governance — Implement PIA templates, transfer assessments, incident procedures, retention practices, and the confidentiality-incident register.
  • Ongoing · Monitor — Rescan digital properties, review new vendors and projects, update notices, and preserve evidence of changes and decisions.

From scattered obligations to documented operations.

Before
  • Unknown cookies and trackers
  • One generic Canadian privacy notice
  • No visible privacy contact
  • PIAs handled informally
  • Privacy requests arrive in email
  • No central incident history
  • Automated decisions are undocumented
  • Vendors transfer data without review
After
  • Continuously scanned technologies and documented changes
  • Quebec-aware notice content in English and French
  • Published privacy-officer title and contact information
  • Structured assessments with owners, safeguards, and approvals
  • Verified and tracked request workflows
  • A maintained confidentiality-incident register
  • Recorded inputs, factors, explanations, and review paths
  • Documented outside-Quebec transfer assessments and agreements

Quebec Law 25, answered plainly.

What is Quebec Law 25?+
Law 25 is the modernization legislation that substantially amended Quebec’s existing private-sector privacy law. Among other changes, it strengthened governance, consent, transparency, privacy impact assessment, incident, individual-rights, automated-decision, transfer, and enforcement requirements. Its principal implementation phases are now in effect.
Who is subject to Quebec’s private-sector privacy law?+
The statute applies to personal information collected, held, used, or communicated in the course of carrying on an enterprise within the meaning of Quebec law. Whether it applies to a particular organization or activity requires a fact-specific analysis. A Quebec visitor or customer can be relevant, but location alone should not be treated as the complete legal test.
Is Law 25 the same as PIPEDA?+
No. Law 25 modernized Quebec’s provincial private-sector law, while PIPEDA is federal legislation. Quebec’s private-sector statute has been recognized as substantially similar to PIPEDA, but PIPEDA can still apply in areas such as federal works, undertakings, and businesses, or certain interprovincial and international commercial data flows.
Does Law 25 require cookie opt-in consent?+
Law 25 does not contain a single rule stating that every browser cookie always requires opt-in consent. Its highest-confidentiality-default provision expressly excludes browser-cookie privacy settings. However, the law’s requirements concerning clear notice, valid consent, necessity, secondary uses, and technologies that identify, locate, or profile people can still affect cookies, pixels, and other tracking technologies. The correct implementation depends on what the technology collects and how the information is used.
What counts as valid consent?+
Consent must be clear, free, informed, and given for specific purposes. Each purpose must be requested in clear and simple language, and written consent requests must be presented separately from other information. Consent is valid only for the time necessary to accomplish the purposes for which it was requested. Express consent is generally required when sensitive personal information is involved.
When is a privacy impact assessment required?+
A PIA is required for a project involving the acquisition, development, or overhaul of an information system or electronic service delivery system that involves personal information, and the privacy officer must be consulted from the outset. A PIA is also required before communicating personal information outside Quebec, including where an outside-Quebec service provider handles it on the organization’s behalf.
Does every organization need a privacy officer?+
The person exercising the highest authority in the enterprise performs the privacy-officer function by default. All or part of that function may be delegated in writing. The privacy officer’s title and contact information must be published on the organization’s website, or made available through another appropriate method if it has no website.
What rights do individuals have?+
Depending on the circumstances, individuals may request access to and rectification of their personal information. Qualifying computerized information collected from the requester must generally be supplied in a structured, commonly used technological format unless doing so raises serious practical difficulties. The law also creates qualified rights relating to dissemination and de-indexing. Access and rectification requests generally require a written response within 30 days.
What happens after a confidentiality incident?+
The organization must take reasonable measures to reduce the risk of injury and prevent similar incidents. If an incident presents a risk of serious injury, the organization must promptly notify the CAI and affected individuals, subject to the law’s provisions. Every confidentiality incident must be recorded, and the register must be available to the CAI on request.
What are the potential penalties under Law 25?+
Administrative monetary penalties for organizations can reach the greater of C$10 million or 2% of worldwide turnover for the preceding fiscal year. Penal fines can reach the greater of C$25 million or 4% of worldwide turnover. Separately, where an unlawful infringement causes injury and is intentional or results from gross fault, a court must award punitive damages of at least C$1,000. The existence and amount of any exposure depend on the applicable provision and the facts.

Make Law 25 part of how your organization actually works.

Connect consent, tracker monitoring, privacy notices, individual requests, PIAs, confidentiality incidents, and governance in one coordinated privacy program.

Book a Quebec privacy review See Consent Management