What Law 25 actually is

Law 25 is the informal name for Quebec's Act to modernize legislative provisions as regards the protection of personal information — formally Bill 64, which received royal assent in September 2021. It substantially amended Quebec's existing private-sector privacy law, the Act respecting the protection of personal information in the private sector, and brought Quebec privacy law much closer to the European GDPR standard than anywhere else in Canada.

The law did not appear overnight. Quebec legislators had been watching GDPR enforcement in Europe and concluded that Canada's federal privacy law — PIPEDA — was not keeping pace with how businesses actually collect and use data in the digital era. Law 25 was designed to raise the bar significantly, particularly for how websites handle personal information, obtain consent, and respond to individuals who want to know what data is held about them.

The Commission d'accès à l'information du Québec (CAI) is the regulatory body responsible for enforcement. It has real powers — including the ability to impose administrative fines of up to $25 million or 4% of worldwide turnover, whichever is greater, for serious violations. These numbers are not hypothetical. Quebec privacy enforcement is serious.

Who it applies to — including you

Law 25 applies to any enterprise that collects, holds, uses, or communicates personal information about Quebec residents in the course of carrying on business — regardless of where that enterprise is based. A business in Victoria, BC with no physical presence in Quebec that runs a website accessible to Quebec residents and collects email addresses through a contact form is, technically, subject to Law 25.

In practice, the CAI has signalled that its enforcement priorities focus on enterprises that collect significant volumes of personal data, handle sensitive information, or have caused demonstrable harm. A small local service business with a brochure-style website is unlikely to be the CAI's first enforcement target. But the legal obligation still exists — and compliance is not especially difficult once you know what is required.

The question to ask is simple: does your website collect any personal information from people who might be in Quebec? If you have a contact form, a newsletter signup, an analytics tool that logs IP addresses, or an ecommerce checkout — the answer is yes.

The phased rollout: what came into force when

Law 25 did not take effect all at once. Quebec built in a phased implementation to give businesses time to adapt, which is worth understanding because some obligations have been in force since 2022 while others came in later.

September 22, 2022 — Phase 1. The first obligations came into force: mandatory reporting of confidentiality incidents (data breaches) to the CAI, and the obligation to designate a person responsible for protecting personal information. A register of confidentiality incidents also became required.

September 22, 2023 — Phase 2. The most substantial obligations came into force: the privacy policy requirements, the rules around consent, the rights of individuals (access, correction, deletion, portability), the privacy by design requirements, and the rules around automated decision-making. This is the phase that changed most of what a typical website needs to do.

September 22, 2024 — Phase 3. The right to data portability came into full force, meaning individuals can now formally request that their personal information be communicated to them or transferred to another enterprise in a structured, commonly used technological format.

All three phases are now in effect. There is no further grace period.

The privacy officer requirement

One of the first and clearest requirements of Law 25 is that every enterprise must designate a person responsible for protecting personal information. This is your privacy officer — and unlike PIPEDA's softer version of this requirement, Law 25 mandates that the title and contact information for this person be published on your website.

For a sole proprietor or small business, the person responsible is almost certainly you. That is completely fine. The law does not require a dedicated full-time role — it requires accountability and a named, reachable contact. What it does require is that your website actually publishes this information. "Contact us" is not sufficient; the published information needs to identify that the person is responsible for privacy, and provide a way to reach them specifically about privacy matters.

In practice, this is usually handled with a line in your privacy policy: "The person responsible for protecting personal information at [Business Name] is [Name or Title], who can be reached at [email address]." Simple and compliant.

What your privacy policy must now include

Law 25 significantly expanded what a Quebec-compliant privacy policy must contain. A generic template written for PIPEDA or GDPR will not cover all of it.

Your policy must identify the name and contact information of the person responsible for personal information protection. It must describe what personal information you collect and for what specific purposes — "marketing" alone is not a sufficient purpose description. It must include actual retention periods for each category of personal information, not vague language about keeping data "as long as necessary." It must explain who the information is shared with, including service providers and third parties outside Quebec.

Crucially, if you communicate personal information outside Quebec — which includes using tools like Google Analytics, Mailchimp, or any cloud-based service with servers outside the province — your policy must disclose this, describe the countries involved, and explain the privacy protections that apply. Law 25 introduced a formal Privacy Impact Assessment requirement for cross-border transfers of personal information that present a risk, and a register must be maintained of such transfers.

The policy must also describe individuals' rights under the law, and the language must be written in clear, plain terms. Dense legal boilerplate does not satisfy Law 25's plain language requirement.

Law 25 tightened the rules around consent in ways that affect how most websites collect data. Consent must be requested separately for each purpose — you cannot bundle consent for multiple uses into a single checkbox. Consent must be clear and free — pre-ticked boxes and bundled consent with terms of service do not qualify. For sensitive categories of personal information, the law requires explicit (opt-in) consent rather than implied consent.

For website analytics, Law 25 does not outright ban analytics tools, but it does require meaningful consent for non-essential data collection. If you are collecting analytics data using a tool that logs IP addresses and sends data to servers outside Quebec, you are collecting and transferring personal information — and your visitors need to be informed about this and given a genuine way to decline.

Withdrawing consent must be as easy as giving it. If someone signed up for your newsletter, they must be able to unsubscribe through a mechanism that is at least as simple as the process for subscribing. This is already required under CASL, but Law 25 reinforces it.

Breach notification obligations

This was the first obligation that came into force (September 2022) and it is one of the most concrete. If your website experiences a confidentiality incident — a data breach, unauthorized access, or unintended disclosure of personal information — and that incident presents a risk of serious injury to an individual, you have specific obligations.

You must notify the CAI as soon as reasonably possible. You must notify the individuals affected. And you must maintain a register of all confidentiality incidents, including ones that did not meet the threshold for notification — because the CAI may ask to see this register during an investigation.

For a small business website, this most commonly becomes relevant in the case of a hosting compromise, a form-to-database leak, or unauthorized access to a CRM or email marketing platform. Having a basic incident response process documented in advance — rather than figuring it out in the moment of a breach — makes compliance significantly easier.

Individual rights: deletion, portability, and more

Law 25 gives Quebec residents a set of rights that go beyond what PIPEDA provides. The right of access — to know what personal information you hold about them — was already in PIPEDA, but Law 25 adds specifics: you must respond within 30 days and provide the information in a structured format if requested.

The right to correction is now explicit. The right to deletion is new at the provincial level — individuals can request that you destroy personal information about them in certain circumstances, including when it is no longer necessary for the purpose it was collected, or when consent has been withdrawn.

The right to portability — the ability to receive their data in a commonly used format and have it transferred to another organization on request — came fully into force in September 2024. For most small business websites this means being able to export and transmit a person's data in a structured format (CSV, JSON, or similar) if they ask for it.

If your website uses automated decision-making that significantly affects individuals — such as credit scoring, personalized pricing, or algorithm-based content decisions — you must disclose this, explain the logic behind it, and provide individuals the right to have the decision reviewed by a human.

Practical steps for small business websites

The gap between Law 25's requirements and what most small Canadian business websites actually have in place is significant — but closing it does not require a legal team or a six-month project. Most of what needs to be done is documentation and honesty: documenting what data you actually collect, how long you keep it, who you share it with, and why.

Start by auditing what personal information your website actually collects. Include contact form submissions, analytics data, newsletter signups, comments, booking forms, and anything collected by third-party tools embedded on your site. Write it down in a simple inventory.

Update your privacy policy to reflect that inventory accurately, add your retention periods, name your privacy officer and their contact details, and disclose every third-party service that receives personal data — including your analytics platform and email provider.

Review your consent mechanisms. If you are using pre-ticked checkboxes, bundled consent, or dark patterns that push people toward agreeing, these need to go. Consent needs to be genuine.

Set up a simple process for responding to individual rights requests. Most small businesses will receive very few of these, but having a documented process — and a named person to handle them — means you can respond within the required 30-day window if one arrives.

Law 25 is not designed to make running a small business impossible. It is designed to make data collection honest and transparent. Most of the requirements, at their core, are just good practice: tell people what you collect, why you collect it, how long you keep it, and give them a real way to say no or ask for their information back. That is not a bad standard to hold yourself to — Quebec or not.