Quebec Privacy Law and Law 25, for Companies Based Elsewhere
Quebec is a jurisdiction of its own
Canada does not have one privacy law. Federal legislation covers commercial activity crossing provincial or national borders, and several provinces have their own. Quebec’s is the oldest and, since 2021, the most demanding.
Law 25 (An Act to modernize legislative provisions as regards the protection of personal information) did not create a new statute. It rewrote an existing one, the Act respecting the protection of personal information in the private sector, phasing the amendments in between September 2022 and September 2024. All now apply.
The statute speaks to any person who operates an enterprise and who collects, holds, uses or communicates personal information. It contains no territorial clause modelled on the GDPR. Its reach follows from the activity instead: an enterprise doing business in Quebec, serving customers there or employing people there answers to the Commission d’accès à l’information du Québec (CAI), with or without an office in the province.
For a company in Toronto, Boston or Berlin, Quebec compliance is not a subset of GDPR or federal work. Some overlaps. Some does not.
What the Act requires
A person in charge of the protection of personal information. Every enterprise must have one. By default the role sits with the person exercising the highest authority in the organization (the chief executive, not the privacy team). It may be delegated in writing, including to someone outside the enterprise. The title and contact details of the person in charge are published on the website.
Consent built purpose by purpose. Consent must be clear, free, informed and given for specific purposes. It is requested for each purpose separately, in clear and simple language, and apart from any other information given to the person. Sensitive personal information calls for express consent. For a person under 14, consent comes from the holder of parental authority.
Transparency at the point of collection. The person concerned must be told the purposes of the collection, the means used, the rights of access, rectification and withdrawal of consent, and the categories of third parties who will receive the information. If it may be communicated outside Quebec, that must be said. Technology used to identify, locate or profile a person must be disclosed along with the means of deactivating it. Policies and practices go on the website in clear and simple language.
Confidentiality incidents. Quebec does not use the vocabulary of a data breach. A confidentiality incident is unauthorized access to, use or communication of personal information, its loss, or any other breach in its protection. Where one presents a risk of serious injury, the enterprise must promptly notify both the CAI and the persons concerned, and take reasonable measures to reduce the risk and prevent recurrence. Every enterprise keeps a register of its confidentiality incidents and sends a copy to the CAI on request.
Rights that go beyond access and correction. Alongside access and rectification, the Act gives individuals the right to have information de-indexed or its dissemination stopped in defined circumstances, and the right to receive computerized information collected from them in a structured, commonly used technological format. Decisions based exclusively on automated processing must be disclosed as such, with an explanation on request and a chance to submit observations to a human reviewer.
Where it diverges from the GDPR
There is no general legitimate interests basis in Quebec. Consent is the rule, and use without it depends on defined statutory exceptions rather than a balancing test. There is no adequacy list and no regulator-issued standard contractual clauses: before personal information is communicated outside Quebec, the enterprise runs its own assessment and puts a written agreement in place reflecting it. An enterprise offering a technological product or service must set its privacy parameters to the highest level of confidentiality by default, with no action by the user. A database of biometric characteristics must be declared to the CAI before it is put into service.
Where it diverges from the federal statute
The federal Act leans on implied consent measured against what a reasonable person would consider appropriate. Quebec is more prescriptive, on the form of consent and on sensitive information. Federal breach reporting turns on a real risk of significant harm; Quebec on a risk of serious injury, with a mandatory register attached. Privacy impact assessments, privacy by default, automated decision transparency and portability have no federal equivalent in force.
How the work runs
An engagement usually begins with a diagnostic: what personal information the organization holds about people in Quebec, where it sits, who it flows to, and which obligations existing GDPR or federal work already satisfies. The outputs are then a short list. A governance policy and the procedures behind it. A privacy notice and consent flows that hold up in Quebec, in French as well as English, since the Charter of the French language carries its own requirements for consumer-facing documents. An incident procedure and register. Privacy impact assessments. Training, and support during an incident or a CAI file.
Jurisdiction
Erwan Jonchères is a member of the Barreau du Québec and practises Quebec law. Satoshi Legal does not provide legal services governed by the law of another Canadian province or territory.
Frequently asked questions
Does Law 25 apply to us if we have no office, staff or servers in Quebec? Possibly. The Act applies to any person operating an enterprise who collects, holds, uses or communicates personal information, and the connecting factor is the activity rather than the address. An enterprise that markets to, contracts with or employs people in Quebec is generally within reach of the Act and of the CAI. The answer turns on facts, so it is worth settling early rather than assuming either way.
We are already GDPR compliant. How much is left to do? Less than starting from zero, more than a mapping exercise. Records, security measures, retention discipline and breach processes usually transfer. What typically does not: the absence of a legitimate interests basis, consent requested purpose by purpose, the privacy impact assessment triggers, the privacy-by-default rule for technological products and services, the incident register, the French-language obligations, and the specific content of Quebec transparency notices.
Is Law 25 the same thing as PIPEDA? No. PIPEDA is federal. Quebec’s private sector Act has long been recognized as substantially similar to the federal statute, which is why activity within Quebec is governed by the Quebec Act. Since Law 25, the two have diverged considerably, particularly on consent, impact assessments and enforcement powers.
What actually happens if we do nothing? The CAI can investigate on complaint or on its own initiative, order corrective measures, and impose administrative monetary penalties. Separately, penal proceedings can be brought, and individuals can sue. In practice, the first contact is often a customer complaint or a client’s due diligence questionnaire.
Book a Quebec privacy diagnostic
If your organization holds personal information about people in Quebec, the useful first step is a scoped diagnostic: what applies, what is already covered by work you have done elsewhere, and what needs to be built. Book a consultation at satoshilegal.cliogrow.com/book, write to bonjour@satoshi.legal, or call +1 438 506-1792.
