Skip to content

What is Law 25? Quebec personal information protection reform

Law 25 is Quebec's statute that modernizes personal information protection rules in the private and public sectors. Passed in 2021 (from Bill 64), it strengthens organizational duties: data governance, consent, privacy notices, privacy impact assessments, and confidentiality-incident management. The Commission d'accès à l'information du Québec (CAI) oversees enforcement; the private-sector framework appears notably in the Act respecting the protection of personal information in the private sector (P-39.1).

In one sentence

Law 25 modernizes personal-data protection in Quebec and creates concrete duties for businesses.

Key points

  • It is not a geography law: “Law 25” means Quebec's privacy reform.
  • It covers consent, transparency, governance, vendors, and confidentiality incidents.
  • Organizations must designate a person in charge of personal information protection.
  • The CAI can investigate and impose administrative monetary penalties.

Term at a glance

Law 25
Loi 25 · Act to modernize legislative provisions as regards the protection of personal information · Bill 64 · Quebec privacy reform
French term
Loi 25
Domain
Compliance / privacy
Category
Quebec legal framework
Level
Intermediate

What does Law 25 change in practice?

Quebec already had privacy statutes before the reform, but several mechanisms—documented governance, incident registers, clearer tech-vendor duties—were less explicit. Law 25 updated that framework toward modern expectations of transparency and accountability.

For a private business this typically means: appointing someone responsible for personal information protection, publishing clear policies, obtaining valid consent when required, limiting collection to what is necessary, and assessing privacy risks on high-impact projects (new systems, transfers, sensitive tech).

When a confidentiality incident presents a risk of serious injury, the organization must notify affected individuals and the CAI as required, and keep an incident register. On websites and digital products, that often means consent banners, retention rules, vendor clauses, and proportionate security (encryption, least privilege, logging).

How does an SME move toward Law 25 compliance?

  1. 01

    Map personal information

    Identify what you collect (forms, CRM, analytics, HR), where it lives, who accesses it, and for which purposes.

  2. 02

    Appoint a lead and document governance

    Name the person responsible and write policies and procedures (access, retention, destruction, vendors).

  3. 03

    Update consent, notices, and sites

    Refresh privacy notices, consent mechanisms, and marketing / analytics tool settings.

  4. 04

    Prepare incident response

    Define detection, serious-injury risk assessment, CAI / individual notifications, and the incident register.

A concrete Law 25-related example

A private clinic in Quebec City finds an Excel appointment file emailed to the wrong recipient. The team assesses harm risk, logs the incident, notifies affected people when required, then tightens controls (encryption, distribution lists, training). Without a Law 25 process, they might have sent only a corrective email—with no register or corrective measures.

What is Law 25 compliance for?

Govern customer and employee data

Know which data exists, why, and how long it is kept.

Secure forms and marketing tools

Align cookies, CRM, and campaigns with clear consent and purposes.

Frame cloud and IT vendors

Contract confidentiality duties and incident notice expectations.

Respond correctly to a breach

Assess, document, and notify per CAI requirements instead of improvising.

Strengths and demands of Law 25

  • Clarifies transparency expectations toward individuals
  • Pushes organizations to map and govern their data
  • Frames confidentiality incidents with specific duties
  • Aligns with modern accountability culture
  • Real compliance load for SMEs (policies, registers, vendors)
  • Some topics are technical (consent, privacy impact assessments)
  • Investigations and penalties are possible for non-compliance
  • Digital tools (analytics, pixels) often need reconfiguration

How does Law 25 differ from PIPEDA (federal)?

Law 25PIPEDA (federal)
Geographic scopeQuebec law; applies to businesses under the provincial private-sector frameworkCanadian federal private-sector privacy law in federal jurisdiction
Oversight bodyCommission d'accès à l'information du Québec (CAI)Office of the Privacy Commissioner of Canada
SME focus in QCRecent reform highly visible for sites, HR, and incidents in QuebecNational framework that may still apply depending on the organization
TakeawayStart with provincial duties (modernized P-39.1)May coexist for interprovincial / federal activities

Why Law 25 matters for your organization

In Quebec, almost every SME collects personal information—customers, leads, employees, patients, or users. Law 25 turns privacy from a distant legal topic into operational duties: policies, consent, vendors, incidents. Compliance lowers sanction and trust risk; more importantly, it stops you from discovering too late where your data actually flows.

Frequently asked questions

Is Law 25 about geolocation or maps?

No. In Quebec privacy context, “Law 25” means the personal information protection reform—not a geography statute.

Does it apply to every SME?

When a business collects, uses, or discloses personal information in the course of its Quebec activities, the private-sector framework (P-39.1) generally applies. Check CAI guidance for precise scope.

Do you need a lawyer to comply?

Legal advice helps on grey areas, but many actions are operational: data inventory, policies, tool configuration, incident procedure.

What should you do after a confidentiality incident?

Contain, assess risk of serious injury, log it, and notify the CAI and individuals when the law requires. CAI guides detail the steps.

Related terms

Sources and references

Need clarity on Law 25 duties for your site, CRM, or vendors?

Talk about privacy compliance
Glossary