Law 25, from A to Z.

The complete guide to the law that redefined data protection in Quebec: obligations, deadlines, penalties, and how it compares to GDPR.

Law 25 in brief

Guide updated July 27, 2026

Key takeaways

  • In force since September 22, 2024, at the end of a three-phase rollout.
  • Applies to any organization that processes personal information about people in Quebec, wherever the organization is based.
  • Requires clear consent, transparency, a designated privacy officer and incident management.
  • Penalties up to 25 million dollars or 4 percent of worldwide revenue.

What is Law 25?

Law 25 is the common name of the law that deeply modernized the protection of personal information in Quebec. Adopted in September 2021 (it was then known as Bill 64), it updates the rules for the private and public sectors alike.

Its goal: give Quebecers back control over their personal information and force organizations to protect it by default, with transparency and accountability. It is one of the strictest digital privacy regimes in North America.

It draws on the most demanding standards in the world, including the European GDPR, and makes Quebec a North American leader on data privacy. The Commission d'accès à l'information (CAI) oversees its application and can impose penalties.

Who must comply?

Law 25 applies to any enterprise that collects, holds, uses or communicates personal information in Quebec. Regardless of its size, its industry, or whether it is for-profit or not.

Personal information is any information about a natural person that directly or indirectly identifies them: a name, an email, an IP address, a cookie identifier, a purchase history.

What triggers the law is the presence of people in Quebec, not only the location of your business. An online store based in Toronto, New York or Paris that serves Quebec customers is covered.

The rollout timeline

The law came into force progressively, over three years. Since September 2024, everything applies.

The foundations

Phase 1 · September 22, 2022

  • Designation of the privacy officer
  • Obligation to report confidentiality incidents
  • Keeping an incident register
  • Rules on biometric information

The heart of the law

Phase 2 · September 22, 2023

  • New consent rules
  • Governance policies and transparency
  • Privacy impact assessments
  • Rules on automated decisions
  • Transfers outside Quebec and privacy by default
  • Right to de-indexing and penalties come into force

Portability

Phase 3 · September 22, 2024

  • Right to data portability
  • Communication of information in a structured technological format
  • All provisions now in force

The main obligations for businesses

Here, one by one, are the concrete obligations the law imposes on organizations.

Designate a privacy officer

By default, the person with the highest authority in the enterprise holds this role. Their title and contact details must be published. The function can be delegated in writing, in whole or in part.

Adopt governance policies

Set internal rules for the retention and destruction of information, staff roles and responsibilities, and the handling of complaints.

Publish a clear privacy policy

Written in plain language and published on your website: what you collect, why, who it is shared with and how people can exercise their rights.

Obtain valid consent

Consent must be clear, free and informed, and given for specific purposes. It is requested separately from any other information, must be explicit for sensitive information, and parental for children under 14.

Inform at the time of collection

Tell the person the purposes, the means used, their access and correction rights, the third parties who will receive their information and any communication outside Quebec.

Manage confidentiality incidents

Keep an incident register and, as soon as an incident presents a serious risk of harm, notify the Commission d'accès à l'information and the people affected.

Run privacy impact assessments

Before any project to acquire, develop or overhaul an information system involving personal information, and before communicating it outside Quebec.

Apply privacy by default

Any technological product or service offered to the public must provide the highest level of privacy by default, without the person having to do anything.

Govern automated decisions

When a decision is based exclusively on automated processing, inform the person, let them have the information corrected and allow them to present observations to a human being.

Govern transfers outside Quebec

Assess whether the information will receive adequate protection at destination and conclude a written agreement before communicating it outside Quebec.

Declare biometric databases

Creating a database of biometric characteristics or measurements must be declared to the Commission at least 60 days before it goes live, with the consent of the people concerned.

Destroy or anonymize information no longer needed

Once the purposes are fulfilled, the information must be destroyed, or anonymized according to best practices if you wish to keep it for serious and legitimate purposes.

Cookies, banners and online tracking

This is where most sites fail. Cookies and other trackers are directly covered.

  • Cookies strictly necessary for the site to work do not require consent.
  • Analytics, advertising and profiling cookies require the person's prior consent.
  • No non-essential tracker should be set before the person has made their choice.
  • Privacy by default requires that features which identify, locate or profile be turned off at the start.
  • Refusing must be as easy as accepting, and the person must be able to change their mind at any time.

Individual rights

Alongside business obligations, the law gives individuals concrete rights over their information.

Access

See the information an organization holds about you, and know where it comes from.

Correction

Have inaccurate, incomplete or ambiguous information corrected.

Withdrawal of consent

Take back your consent at any time, as simply as it was given.

De-indexing

Require that information stop being disseminated, or that a link to it be removed, when the dissemination causes harm.

Portability

Retrieve your information in a structured technological format, or have it transferred elsewhere.

Human review

Be informed of an automated decision, have the data corrected and present observations to a person.

Penalties with real teeth

Compliance is no longer optional. Law 25 gives the Commission d'accès à l'information real enforcement powers, comparable to GDPR fines in Europe.

$10M

Administrative penalties

Up to 10 million dollars or 2 percent of worldwide revenue, whichever is higher.

$25M

Penal sanctions

Up to 25 million dollars or 4 percent of worldwide revenue for the most serious offences.

$1,000

Punitive damages

Minimum a person can claim for an intentional or grossly negligent breach, on top of actual damages.

Fines can be doubled for repeat offences. The Commission can also order corrective measures, and injured individuals can sue in civil court. Beyond the amounts, it is your customers' trust that is at stake.

How to get compliant

Compliance is not a one-day project, but it breaks down into clear steps.

  1. Designate your privacy officer and publish their contact details.
  2. Map the personal information you collect and why.
  3. Write and publish your privacy policy.
  4. Install a consent banner that actually blocks trackers.
  5. Set up a consent record and an incident register.
  6. Build a process to answer access, correction and withdrawal requests.
  7. Train your team and review your practices regularly.

How Consorm helps

We cannot designate your privacy officer for you, but we cover the entire web side of Law 25 and GDPR consent, without code.

A banner that really blocks

Non-essential trackers stay blocked until the visitor consents, exactly as the law requires.

Compliance scanner

We scan your site and spot the trackers and gaps before a regulator does.

Consent records

Every choice is timestamped and kept, ready to produce in an audit.

Hosted in Quebec

Your consent data stays in Canada, with no transfer to foreign servers.

Frequently asked questions

Does Law 25 apply to my small business?

Yes. The law covers any enterprise that collects personal information in Quebec, regardless of size or industry. The obligations are proportionate, but they exist from your very first customer.

Am I covered if my company is outside Quebec?

Yes, if you process personal information about people located in Quebec. What matters is where the people are, not only where your company is. An online store based elsewhere that serves Quebec customers is covered.

Is Law 25 the same as the European GDPR?

They share the same philosophy and many principles, but they are two distinct regimes. Being GDPR compliant helps, without guaranteeing Law 25 compliance, which has its own rules and deadlines.

Do I really need a consent banner?

As soon as your site sets non-essential cookies (analytics, advertising, profiling), yes. Consent must be obtained before the cookies are set, and refusing must be as easy as accepting.

What counts as sensitive personal information?

Information that, by its nature or context, carries a high expectation of privacy: health, biometric data, orientation, financial situation. It requires explicit consent.

Since when is the law fully in force?

All provisions have been in force since September 22, 2024, at the end of a phased rollout that started in 2022.

This guide is provided for general information in plain language. It is not legal advice. For your specific situation, consult the Commission d'accès à l'information or a legal advisor.

The consent platform teams actually trust.

Installed in five minutes. Blocks trackers for real, compliant with Law 25 and GDPR, built in Quebec.