Law 25, from A to Z.
The complete guide to the law that redefined data protection in Quebec: obligations, deadlines, penalties, and how it compares to GDPR.
Law 25 in brief
Guide updated July 27, 2026
Key takeaways
- In force since September 22, 2024, at the end of a three-phase rollout.
- Applies to any organization that processes personal information about people in Quebec, wherever the organization is based.
- Requires clear consent, transparency, a designated privacy officer and incident management.
- Penalties up to 25 million dollars or 4 percent of worldwide revenue.
What is Law 25?
Law 25 is the common name of the law that deeply modernized the protection of personal information in Quebec. Adopted in September 2021 (it was then known as Bill 64), it updates the rules for the private and public sectors alike.
Its goal: give Quebecers back control over their personal information and force organizations to protect it by default, with transparency and accountability. It is one of the strictest digital privacy regimes in North America.
It draws on the most demanding standards in the world, including the European GDPR, and makes Quebec a North American leader on data privacy. The Commission d'accès à l'information (CAI) oversees its application and can impose penalties.
Who must comply?
Law 25 applies to any enterprise that collects, holds, uses or communicates personal information in Quebec. Regardless of its size, its industry, or whether it is for-profit or not.
Personal information is any information about a natural person that directly or indirectly identifies them: a name, an email, an IP address, a cookie identifier, a purchase history.
What triggers the law is the presence of people in Quebec, not only the location of your business. An online store based in Toronto, New York or Paris that serves Quebec customers is covered.
The rollout timeline
The law came into force progressively, over three years. Since September 2024, everything applies.
The foundations
Phase 1 · September 22, 2022
- Designation of the privacy officer
- Obligation to report confidentiality incidents
- Keeping an incident register
- Rules on biometric information
The heart of the law
Phase 2 · September 22, 2023
- New consent rules
- Governance policies and transparency
- Privacy impact assessments
- Rules on automated decisions
- Transfers outside Quebec and privacy by default
- Right to de-indexing and penalties come into force
Portability
Phase 3 · September 22, 2024
- Right to data portability
- Communication of information in a structured technological format
- All provisions now in force
The main obligations for businesses
Here, one by one, are the concrete obligations the law imposes on organizations.
Designate a privacy officer
By default, the person with the highest authority in the enterprise holds this role. Their title and contact details must be published. The function can be delegated in writing, in whole or in part.
Adopt governance policies
Set internal rules for the retention and destruction of information, staff roles and responsibilities, and the handling of complaints.
Publish a clear privacy policy
Written in plain language and published on your website: what you collect, why, who it is shared with and how people can exercise their rights.
Obtain valid consent
Consent must be clear, free and informed, and given for specific purposes. It is requested separately from any other information, must be explicit for sensitive information, and parental for children under 14.
Inform at the time of collection
Tell the person the purposes, the means used, their access and correction rights, the third parties who will receive their information and any communication outside Quebec.
Manage confidentiality incidents
Keep an incident register and, as soon as an incident presents a serious risk of harm, notify the Commission d'accès à l'information and the people affected.
Run privacy impact assessments
Before any project to acquire, develop or overhaul an information system involving personal information, and before communicating it outside Quebec.
Apply privacy by default
Any technological product or service offered to the public must provide the highest level of privacy by default, without the person having to do anything.
Govern automated decisions
When a decision is based exclusively on automated processing, inform the person, let them have the information corrected and allow them to present observations to a human being.
Govern transfers outside Quebec
Assess whether the information will receive adequate protection at destination and conclude a written agreement before communicating it outside Quebec.
Declare biometric databases
Creating a database of biometric characteristics or measurements must be declared to the Commission at least 60 days before it goes live, with the consent of the people concerned.
Destroy or anonymize information no longer needed
Once the purposes are fulfilled, the information must be destroyed, or anonymized according to best practices if you wish to keep it for serious and legitimate purposes.
Consent, at the heart of the law
Under Law 25, soft consent is worthless. To be valid, it must check every one of these boxes.
- Clear: the person takes a clear, positive action. No pre-checked boxes, no silence counting as agreement.
- Free: a service cannot be conditioned on consent that is not necessary to provide it.
- Informed: the person understands what they are consenting to, explained in plain language.
- For specific purposes: one consent per purpose, never a catch-all consent.
- Separate: requested apart from any other information given to the person.
- Reinforced for sensitive data: health, biometrics and other sensitive information require explicit consent.
- Framed for minors: parental or guardian consent is required for children under 14.
- Revocable: the person can withdraw it at any time, as simply as they gave it.
Individual rights
Alongside business obligations, the law gives individuals concrete rights over their information.
Access
See the information an organization holds about you, and know where it comes from.
Correction
Have inaccurate, incomplete or ambiguous information corrected.
Withdrawal of consent
Take back your consent at any time, as simply as it was given.
De-indexing
Require that information stop being disseminated, or that a link to it be removed, when the dissemination causes harm.
Portability
Retrieve your information in a structured technological format, or have it transferred elsewhere.
Human review
Be informed of an automated decision, have the data corrected and present observations to a person.
Penalties with real teeth
Compliance is no longer optional. Law 25 gives the Commission d'accès à l'information real enforcement powers, comparable to GDPR fines in Europe.
$10M
Administrative penalties
Up to 10 million dollars or 2 percent of worldwide revenue, whichever is higher.
$25M
Penal sanctions
Up to 25 million dollars or 4 percent of worldwide revenue for the most serious offences.
$1,000
Punitive damages
Minimum a person can claim for an intentional or grossly negligent breach, on top of actual damages.
Fines can be doubled for repeat offences. The Commission can also order corrective measures, and injured individuals can sue in civil court. Beyond the amounts, it is your customers' trust that is at stake.
How to get compliant
Compliance is not a one-day project, but it breaks down into clear steps.
- Designate your privacy officer and publish their contact details.
- Map the personal information you collect and why.
- Write and publish your privacy policy.
- Install a consent banner that actually blocks trackers.
- Set up a consent record and an incident register.
- Build a process to answer access, correction and withdrawal requests.
- Train your team and review your practices regularly.
How Consorm helps
We cannot designate your privacy officer for you, but we cover the entire web side of Law 25 and GDPR consent, without code.
A banner that really blocks
Non-essential trackers stay blocked until the visitor consents, exactly as the law requires.
Compliance scanner
We scan your site and spot the trackers and gaps before a regulator does.
Consent records
Every choice is timestamped and kept, ready to produce in an audit.
Hosted in Quebec
Your consent data stays in Canada, with no transfer to foreign servers.
Frequently asked questions
Does Law 25 apply to my small business?
Yes. The law covers any enterprise that collects personal information in Quebec, regardless of size or industry. The obligations are proportionate, but they exist from your very first customer.
Am I covered if my company is outside Quebec?
Yes, if you process personal information about people located in Quebec. What matters is where the people are, not only where your company is. An online store based elsewhere that serves Quebec customers is covered.
Is Law 25 the same as the European GDPR?
They share the same philosophy and many principles, but they are two distinct regimes. Being GDPR compliant helps, without guaranteeing Law 25 compliance, which has its own rules and deadlines.
Do I really need a consent banner?
As soon as your site sets non-essential cookies (analytics, advertising, profiling), yes. Consent must be obtained before the cookies are set, and refusing must be as easy as accepting.
What counts as sensitive personal information?
Information that, by its nature or context, carries a high expectation of privacy: health, biometric data, orientation, financial situation. It requires explicit consent.
Since when is the law fully in force?
All provisions have been in force since September 22, 2024, at the end of a phased rollout that started in 2022.
This guide is provided for general information in plain language. It is not legal advice. For your specific situation, consult the Commission d'accès à l'information or a legal advisor.
The consent platform teams actually trust.
Installed in five minutes. Blocks trackers for real, compliant with Law 25 and GDPR, built in Quebec.