Quebec Privacy Legislation

Law 25 Explained: Quebec’s Privacy Law for Small Businesses

Law 25 changed how every business in Quebec, regardless of size, has to handle personal information. If you collect names, emails, employee records, or customer data, this law applies to you. Here’s what it actually requires, what’s already in force, and where to start.

Navigation
What is Law 25 Who It Applies To The Three Phases Penalties & Risk Latest Updates Compliance Checklist Take the Assessment

What Is Law 25?

Law 25 (formerly Bill 64) is Quebec’s modernized private-sector privacy law. It rolled out in three phases between September 2022 and September 2024, and every phase is now in effect.

At its core, Law 25 requires organizations to know what personal information they collect, limit collection to what’s actually needed, protect that information, and be transparent with the people it belongs to. It also gives Quebec residents new rights over their own data, and gives the province’s privacy regulator, the Commission d’accès à l’information (CAI), real enforcement power.

Most SMBs already meet some of these requirements through existing IT and HR practices without realizing it. The real work is figuring out which ones, and closing the gaps that remain.

Who Has to Comply?

There’s no minimum size threshold. If your business collects or stores personal information about employees, customers, suppliers, or website visitors, Law 25 applies to you, whether you have 5 employees or 500.

“Personal information” is broader than most people expect. It includes names, email addresses, phone numbers, home addresses, employee records, customer files, and in some contexts, IP addresses or other online identifiers.

The Three Phases of Law 25

Law 25 was rolled out gradually so organizations had time to adjust. All three phases are now in force.

Phase 1: Sept 22, 2022

Governance & incident reporting

  • Designate a person responsible for protecting personal information
  • Publish that person’s contact information
  • Keep an internal register of confidentiality incidents
  • Report incidents that pose a serious risk of harm to the CAI and affected individuals
Phase 2: Sept 22, 2023

Policies, consent & assessments

  • Publish privacy policies and governance rules
  • Give clear notice when collecting personal information
  • Limit collection to what’s necessary for a stated purpose
  • Destroy or anonymize data once it’s no longer needed
  • Conduct privacy impact assessments for certain projects and transfers
  • Meet stricter, more specific consent requirements
Phase 3: Sept 22, 2024

Data portability

  • Individuals can request their personal information in a structured, commonly used format
  • In some cases, they can ask that this information be transferred directly to another organization

The transfer right applies where it’s technically feasible to do so; it’s not an unconditional requirement.

See the full obligations breakdown →

What’s the Risk of Non-Compliance?

Law 25 gave the CAI real enforcement teeth, and it opened the courthouse door too. Three kinds of exposure apply:

Administrative monetary penalties

Up to $10 million CAD, or 2% of worldwide turnover for the preceding fiscal year, whichever is greater.

Penal fines

Up to $25 million CAD, or 4% of worldwide turnover, whichever is greater, for the most serious offences. Fines can double for repeat offences.

Private lawsuits

Individuals can sue for damages. Courts must award punitive damages of at least $1,000 per person where an unlawful infringement is intentional or results from gross fault.

In practice, most enforcement action starts with a complaint or a security incident, not a routine audit. The bigger everyday risk for most SMBs is a data breach that exposes gaps in how personal information has been handled all along.

Latest Developments

May 27, 2026

The CAI ordered a Quebec property-management company to stop collecting SINs and driver’s licences without justification, destroy what it had improperly collected, and put governance and privacy policies in place within 30 days. Read the decision, then check those items on the checklist.

June 15, 2026

Ottawa tabled Bill C-36, which would replace PIPEDA with a new federal privacy law. It changes nothing about your Law 25 obligations yet. What it means for Quebec businesses.

In force since May 30, 2024

The Anonymization Regulation means data doesn’t count as “anonymized” without documented methods and a re-identification risk analysis. How it works.

This section is updated quarterly. Last reviewed August 5, 2026.

Not Sure Where You Stand?

Most businesses are partway there without realizing it. Run through the checklist or take the short self-assessment to see where the gaps are.

Take the Compliance Assessment
3
Implementation Phases
$25M
Maximum Penal Fine
SMB
Designed for Small & Medium Business
QC
Provincial Privacy Law