Law 25 changed how every business in Quebec, regardless of size, has to handle personal information. If you collect names, emails, employee records, or customer data, this law applies to you. Here’s what it actually requires, what’s already in force, and where to start.
Law 25 (formerly Bill 64) is Quebec’s modernized private-sector privacy law. It rolled out in three phases between September 2022 and September 2024, and every phase is now in effect.
At its core, Law 25 requires organizations to know what personal information they collect, limit collection to what’s actually needed, protect that information, and be transparent with the people it belongs to. It also gives Quebec residents new rights over their own data, and gives the province’s privacy regulator, the Commission d’accès à l’information (CAI), real enforcement power.
Most SMBs already meet some of these requirements through existing IT and HR practices without realizing it. The real work is figuring out which ones, and closing the gaps that remain.
There’s no minimum size threshold. If your business collects or stores personal information about employees, customers, suppliers, or website visitors, Law 25 applies to you, whether you have 5 employees or 500.
“Personal information” is broader than most people expect. It includes names, email addresses, phone numbers, home addresses, employee records, customer files, and in some contexts, IP addresses or other online identifiers.
Law 25 was rolled out gradually so organizations had time to adjust. All three phases are now in force.
The transfer right applies where it’s technically feasible to do so; it’s not an unconditional requirement.
Law 25 gave the CAI real enforcement teeth, and it opened the courthouse door too. Three kinds of exposure apply:
Up to $10 million CAD, or 2% of worldwide turnover for the preceding fiscal year, whichever is greater.
Up to $25 million CAD, or 4% of worldwide turnover, whichever is greater, for the most serious offences. Fines can double for repeat offences.
Individuals can sue for damages. Courts must award punitive damages of at least $1,000 per person where an unlawful infringement is intentional or results from gross fault.
In practice, most enforcement action starts with a complaint or a security incident, not a routine audit. The bigger everyday risk for most SMBs is a data breach that exposes gaps in how personal information has been handled all along.
The CAI ordered a Quebec property-management company to stop collecting SINs and driver’s licences without justification, destroy what it had improperly collected, and put governance and privacy policies in place within 30 days. Read the decision, then check those items on the checklist.
Ottawa tabled Bill C-36, which would replace PIPEDA with a new federal privacy law. It changes nothing about your Law 25 obligations yet. What it means for Quebec businesses.
The Anonymization Regulation means data doesn’t count as “anonymized” without documented methods and a re-identification risk analysis. How it works.
This section is updated quarterly. Last reviewed August 5, 2026.