Canada - Quebec - Personal Information Protection (Law 25)

An Act to modernize legislative provisions as regards the protection of personal information (Law 25)

Loi modernisant des dispositions législatives concernant la protection des renseignements personnels (Loi 25)

Canada

RAI-CA-QC-MLPARXX-2021
Effective: September 22, 2022
In Force (Amended)(In Force (Amended))
ActData Protection and PrivacyGovernance and OversightEnforcement and Penalties
Export PDF

Quebec's Law 25 modernizes provincial privacy laws, strengthening individual rights, mandating explicit consent, PIAs, and a Privacy Officer, with significant penalties for non-compliance.

Overview

An Act to modernize legislative provisions as regards the protection of personal information, commonly known as Law 25 (formerly Bill 64), represents a significant overhaul of Quebec's privacy legislation. Adopted on September 22, 2021, this provincial Act aims to strengthen the protection of personal information for individuals and impose new, more stringent responsibilities on both public bodies and private sector organizations operating within Quebec, or handling the personal information of Quebec residents. The legislation introduces a comprehensive framework that was implemented in a phased approach, with key provisions coming into effect in September 2022, September 2023, and the final provisions by September 2024. This modernization effort positions Quebec at the forefront of data privacy in Canada, drawing parallels with global benchmarks such as the European Union's General Data Protection Regulation (GDPR).

The primary objective of Law 25 is to enhance transparency and accountability in how personal information is collected, used, communicated, retained, and destroyed. It significantly expands individual data rights, requiring organizations to obtain explicit and informed consent for data processing, conduct privacy impact assessments, and designate a privacy officer. Furthermore, the law introduces robust enforcement mechanisms, including substantial administrative monetary penalties and penal fines for non-compliance, along with a private right of action for individuals who suffer harm due to privacy breaches. This legislative update reflects a global trend towards adapting privacy frameworks to the complexities and challenges presented by evolving technological tools and the increasing sophistication of data processing activities.

Definitions

Law 25 introduces or clarifies several key definitions central to its application. "Personal information" is broadly defined as any information that relates to a natural person and allows that person to be identified. This encompasses a wide range of data, including full name, physical address, email address, phone number, financial records, and health records. The law applies to such information regardless of its format or accessibility, explicitly excluding public records and information pertaining to journalistic, historical, or genealogical material collected, held, used, or communicated in the public interest. The legislation also recognizes "sensitive personal information," which includes data related to an individual's health, biometric characteristics, financial situation, or any other information of an intimate nature. The disclosure or abuse of such sensitive data is deemed to carry a higher risk of harm to an individual.

A crucial distinction is made between "de-identification" and "anonymization." Personal information is considered de-identified if it no longer allows the person concerned to be directly identified. In contrast, "anonymization" requires that the information no longer allows the person to be identified, either directly or indirectly, and that this anonymization is irreversible. While Law 25 permits the retention of anonymized personal information for serious and legitimate purposes instead of destruction, the Commission d'accès à l'information (CAI) has expressed reservations regarding the standards for achieving complete and irreversible anonymization. The CAI indicates that further government regulations are needed to clarify the criteria and procedures for effective anonymization, creating a degree of uncertainty for organizations in this area.

Governance and Institutional Framework

The governance and institutional framework under Law 25 is significantly strengthened, with the Commission d'accès à l'information (CAI) serving as Quebec's primary privacy regulator. The Act enhances the CAI's functions and powers, granting it the authority to impose administrative monetary penalties (AMPs) and initiate penal proceedings for non-compliance. The CAI is responsible for developing guidelines on the application of the Act, evaluating confidentiality incident notices, and, where appropriate, ordering notifications to affected individuals. It also conducts research, studies, and analyses on access to information and personal information protection, and issues opinions on legislative projects and information system developments.

A cornerstone of the new governance structure is the mandatory designation of a "person in charge of the protection of personal information," often referred to as a Privacy Officer. While any employee can be appointed to this role, Law 25 defaults this responsibility to the highest senior employee (e.g., the CEO) if no specific individual is designated. Organizations are required to publish the name, title, and contact information of their Privacy Officer on their website. Furthermore, organizations must establish and implement governance policies and practices regarding personal information, which must be publicly disseminated. These rules must outline frameworks for the keeping and destruction of information, define the roles and responsibilities of staff throughout the information lifecycle, and provide a clear process for handling privacy complaints. Public bodies are also mandated to establish a committee on access to information and personal information protection to support them in fulfilling their responsibilities.

Key Focus Areas

Law 25 introduces several critical focus areas to bolster personal information protection. Central to these is the concept of enhanced consent. The Act mandates that consent for the collection, use, or communication of personal information must be explicit, free, informed, specific, and unambiguous. Requests for consent must be presented in clear and simple language, separate from any other information provided to the individual, ensuring that consent is not buried in fine print. For sensitive personal information, consent must be given expressly. The law also sets the age of consent for minors at 14 years, requiring the consent of a person having parental authority or a tutor for individuals under this age. Organizations are further required to obtain opt-in consent for the use of tracking technologies, such as cookies, that identify, locate, or profile individuals.

Another significant focus is the expansion of data subject rights, aligning Quebec's framework with the GDPR. Individuals now possess the right to be informed about the collection and use of their data, the right to access and rectify their personal information, and the right to request its erasure or de-identification. They also have the right to withdraw their consent for the communication or use of their information and to restrict its processing. A new right to data portability, effective September 2024, allows individuals to obtain their computerized personal information in a structured, commonly used, and machine-readable format, and to request its transfer to another organization. Law 25 also introduces the requirement for Privacy Impact Assessments (PIAs) in various circumstances, including any project involving the acquisition, development, or overhaul of information systems or electronic service delivery systems that handle personal information. PIAs are explicitly required when personal information is to be communicated outside Quebec, or when implementing high-risk technologies like AI or biometrics. Organizations must also adhere to principles of privacy by design and by default, ensuring the highest level of confidentiality is applied to personal information.

Implementation Framework

The implementation framework for Law 25 necessitates a comprehensive approach from organizations to ensure compliance across all operational aspects. Businesses are expected to undertake a thorough privacy audit to identify all personal information they collect, hold, use, or communicate, including defining sensitive data and the necessity of its retention. This initial data mapping exercise is crucial for understanding the scope of personal information managed and for developing an effective compliance strategy. Following this, organizations must update existing privacy policies and procedures or develop new ones to reflect the stringent requirements of Law 25, particularly concerning consent management, data subject rights, and incident response. These policies must be written in clear and simple language and made easily accessible to individuals.

Beyond policy development, the implementation framework requires tangible operational changes. Organizations must implement robust security measures to protect personal information throughout its lifecycle, from collection to destruction or anonymization. Staff training is also a critical component, ensuring that all personnel understand their roles and responsibilities regarding personal information protection and the organization's privacy policies. Furthermore, organizations must review and update contracts with third-party service providers to ensure that appropriate safeguards are in place for any personal information shared or processed on their behalf. This includes assessing the legal framework and protection measures in jurisdictions where data may be transferred. The phased rollout of Law 25 allows for a gradual adaptation, but continuous monitoring and adjustment of internal processes are essential to maintain ongoing compliance as new provisions come into full effect.

Monitoring and Evaluation

The monitoring and evaluation of compliance with Law 25 are primarily overseen by the Commission d'accès à l'information (CAI), Quebec's independent administrative body responsible for the enforcement of privacy legislation. The CAI has been granted significantly enhanced powers under Law 25 to ensure organizations adhere to the new requirements. These powers include the ability to conduct inquiries and inspections into how public bodies and private enterprises manage personal information. The CAI actively monitors compliance through various means, including the review of confidentiality incident reports submitted by organizations and assessing their governance rules and privacy policies.

In its role, the CAI is also mandated to develop guidelines and issue advisories to assist organizations in understanding and implementing the law's provisions. For instance, the Commission has taken a stance on complex issues like anonymization, indicating that further regulatory clarity is needed before organizations can confidently implement certain practices. This proactive engagement in clarifying legislative ambiguities and providing guidance is a key aspect of the monitoring framework. Organizations are expected to cooperate fully with CAI inquiries and inspections, with impeding the CAI's work being an offense punishable by penalties. The CAI's oversight ensures that organizations not only establish the necessary policies and procedures but also effectively implement and maintain them, fostering a culture of accountability and continuous improvement in personal information protection.

Penalties, Liability, and Appeals

Law 25 introduces a rigorous enforcement scheme with substantial penalties for non-compliance, designed to be dissuasive and to align with international standards such as the GDPR. For private sector organizations, administrative monetary penalties (AMPs) can be imposed by the CAI, reaching up to C$10 million or an amount corresponding to 2% of the enterprise's worldwide turnover for the preceding fiscal year, whichever is greater. These AMPs can be levied for various breaches, such as failing to inform individuals of the source, purpose, and means of collection of their personal information upon request. Before imposing an AMP, the CAI typically issues a notice of non-compliance, allowing the defaulting party an opportunity to remedy the alleged breach.

Beyond administrative penalties, Law 25 also establishes a new penal enforcement scheme with even higher fines. Since September 22, 2023, the CAI has the power to initiate penal proceedings within five years of an offense. Penal fines for corporations can reach up to C$25 million or 4% of worldwide turnover for the preceding fiscal year, whichever is greater, with a minimum fine of C$15,000 for corporations. For individuals, penal fines can range from C$5,000 to C$100,000. These fines can be doubled in the case of a subsequent offense. Offenses include unlawful collection, use, communication, keeping, or destruction of personal information, failure to report confidentiality incidents, or impeding the CAI's inquiries. Uniquely, Law 25 grants individuals a private right of action, allowing them to take legal action, including collective actions, against businesses that violate their privacy rights. Individuals who suffer harm due to intentional misconduct or gross negligence can claim damages of at least C$1,000, providing a direct avenue for redress not commonly found in other Canadian privacy laws.

Relationship to Other Instruments

Law 25 operates within a broader legal landscape, significantly modernizing and strengthening Quebec's existing privacy framework. It amends two primary provincial statutes: the Act respecting Access to documents held by public bodies and the Protection of personal information, and the Act respecting the protection of personal information in the private sector. This legislative update is considered more comprehensive and stringent than Canada's federal privacy law, the Personal Information Protection and Electronic Documents Act (PIPEDA), which applies to most commercial organizations across Canada. Law 25 introduces stronger safeguards, clearer explicit consent requirements, and broader individual rights compared to PIPEDA, which allows for implied consent in some situations. Organizations operating in Quebec or handling data from individuals residing there must comply with both Law 25 and PIPEDA where applicable, with Law 25 often imposing higher standards.

The Act also establishes a close alignment with the European Union's General Data Protection Regulation (GDPR), adopting similar principles regarding enhanced user consent, data subject rights (such as the right to erasure and data portability), and robust enforcement mechanisms with significant penalties. This resemblance means that businesses already compliant with GDPR may find it easier to adapt to Law 25's requirements. While there are similarities, Law 25 also introduces unique provisions, such as the private right of action for individuals, which is not available under GDPR. The law also modifies the Election Act to subject political entities to certain provisions of the Act respecting the protection of personal information in the private sector, extending privacy obligations to political parties, independent Members of the National Assembly, and independent candidates.

International Alignment

Quebec's Law 25 demonstrates a strong commitment to international best practices in data protection, particularly through its alignment with the European Union's General Data Protection Regulation (GDPR). This alignment is evident in several key areas, including the emphasis on explicit and informed consent, the expansion of individual data subject rights, and the introduction of significant penalties for non-compliance. The law's provisions for consent, requiring it to be free, informed, specific, and unambiguous, mirror the high standards set by the GDPR. Similarly, the comprehensive suite of individual rights, such as the right to access, rectification, erasure (right to be forgotten), restriction of processing, and data portability, directly reflects rights enshrined in the GDPR.

Furthermore, the substantial administrative monetary penalties and penal fines stipulated in Law 25, which can reach up to 4% of an organization's worldwide turnover, are directly comparable to the maximum penalties under the GDPR, signaling a similar level of regulatory seriousness. The requirement for Privacy Impact Assessments (PIAs) in certain high-risk processing activities, including cross-border data transfers, also aligns with GDPR principles that mandate risk-based assessments for data protection. This strong international alignment positions Quebec as a jurisdiction with a robust data privacy framework, facilitating data flows with other regions that adhere to similar high standards, while also requiring organizations to adopt globally recognized privacy principles.

Implementation Timeline

MilestoneDateNotes
Designation of Privacy Officer2022-09-22Organizations must designate a person in charge of personal information protection (Privacy Officer); defaults to CEO if not designated. Contact information must be published.
Breach Notification Requirements2022-09-22Mandatory reporting of confidentiality incidents presenting a risk of serious injury to the CAI and affected individuals. Requirement to maintain a register of all incidents.
New Rules for Communication of Personal Information without Consent2022-09-22Specific conditions for communicating personal information without consent for study, research, or statistical purposes, and in commercial transactions.
PIA for Research/Statistics2022-09-22Requirement to conduct a Privacy Impact Assessment before communicating personal information without consent for study, research, or statistical purposes.
Biometric Database Notification2022-09-22Notification to the CAI at least 60 days before carrying out identity verification or confirmation using biometric characteristics or measurements.
Governance Policies and Practices2023-09-22Establishment and publication of governance rules regarding personal information, including retention/destruction policies, staff roles/responsibilities, and a complaint process.
Enhanced Consent Requirements2023-09-22Stricter rules for obtaining free, informed, explicit consent in clear and simple language, separate from other information. Opt-in for tracking technologies.
Privacy by Design and by Default2023-09-22Organizations must ensure the highest level of confidentiality by default for personal information.
Expanded Individual Rights2023-09-22Rights to be informed, access, rectification, erasure (de-identification), withdrawal of consent, and restriction of processing come into force.
PIA for Systems and Cross-Border Transfers2023-09-22Mandatory Privacy Impact Assessments for any project involving the acquisition, development, or overhaul of information systems or electronic service delivery systems, or for communicating personal information outside Quebec.
Transparency for Automated Decision-Making2023-09-22Obligation to inform individuals when personal information is used for identification, location, profiling, or automated decision-making.
Right to Data Portability2024-09-22Individuals gain the right to obtain their computerized personal information in a structured, commonly used, and machine-readable format, and to request its transfer to another organization.

Compliance Checklist

CheckRequired Action
Designate Privacy OfficerAppoint a Privacy Officer (person in charge of personal information protection) and publish their name, title, and contact information on your website.
Develop/Update Governance PoliciesEstablish and publicly disseminate clear policies and practices for the governance of personal information, including retention, destruction, staff roles, and a complaint process.
Implement Explicit Consent MechanismsEnsure all collection, use, and communication of personal information is based on free, informed, specific, and explicit consent, presented clearly and separately. Implement opt-in for tracking technologies.
Conduct Privacy Impact Assessments (PIAs)Perform PIAs for new or overhauled information systems, electronic service delivery systems, cross-border data transfers, and high-risk technologies (e.g., AI, biometrics).
Establish Breach Notification ProtocolDevelop and implement procedures for mandatory notification of confidentiality incidents to the CAI and affected individuals if there is a risk of serious injury. Maintain an incident register.
Respect Data Subject RightsEstablish processes to respond to requests for information, access, rectification, erasure, withdrawal of consent, restriction of processing, and data portability (by Sept 2024).
Ensure Privacy by Design and DefaultIntegrate privacy protection into the design of all systems and services, ensuring the highest level of confidentiality by default.
Manage Cross-Border Data TransfersAssess the adequacy of protection in destination jurisdictions, conduct PIAs, implement contractual safeguards, and inform individuals before transferring data outside Quebec.
Provide Transparency for Automated ProcessingInform individuals when personal information is used for identification, location, profiling, or automated decision-making.
Implement Data Minimization and Retention PoliciesDestroy personal information once its purpose is accomplished or anonymize it irreversibly, subject to legal retention periods.
Train StaffProvide ongoing training to staff on privacy policies, procedures, and their responsibilities under Law 25.

Sources and References

SourceType
An Act to modernize legislative provisions as regards the protection of personal information (2021, c. 25)Official Legal Text
Act respecting Access to documents held by public bodies and the Protection of personal information (A-2.1)Official Legal Text
Act respecting the protection of personal information in the private sector (P-39.1)Official Legal Text
Loi 25 sur la protection des renseignements personnels des citoyens du Québec - Entrée en vigueur de nouvelles dispositions qui font du Québec un chef de file mondial (2023-09-22)Government News Release
Projet de loi n° 64, Loi modernisant des dispositions législatives en matière de protection des renseignements personnels - Assemblée nationale du QuébecGovernment Legislative Portal
Principaux changements aux lois sur la protection des renseignements personnels - Commission d'accès à l'information du QuébecGovernment Agency Website
Plain English

Quebec's Law 25 significantly updates provincial privacy laws, strengthening individual rights and imposing new responsibilities on public bodies and private organizations operating in Quebec or handling the personal information of its residents.

This comprehensive legislation applies to any organization that collects, uses, or communicates personal information of individuals in Quebec. It mandates several key changes: - Organizations must designate a Privacy Officer, with the CEO automatically assuming this role if no one else is appointed. - Consent for data collection, use, or communication must be explicit, free, informed, specific, and unambiguous, presented in clear language. Opt-in consent is required for tracking technologies like cookies. - "Privacy by Design" and "Privacy by Default" are now legal requirements, meaning privacy protections must be built into systems and processes, with the highest level of confidentiality applied automatically. - Organizations must conduct Privacy Impact Assessments (PIAs) for projects involving new information systems, electronic services, or when transferring data outside Quebec. They also need to report serious data breaches to the Commission d'accès à l'information (CAI) and affected individuals.

Law 25 rolled out in phases. Key provisions like the Privacy Officer designation and breach notification took effect in September 2022. Enhanced consent, privacy by design, and PIAs became mandatory in September 2023. The final provision, the right to data portability, comes into force in September 2024. Non-compliance carries substantial penalties. The CAI can issue administrative fines up to C$10 million or 2% of worldwide turnover, and penal fines up to C$25 million or 4% of worldwide turnover. A significant surprise for many is the new private right of action, allowing individuals to sue organizations for damages (at least C$1,000 for intentional misconduct or gross negligence) if their privacy rights are violated. This means direct legal risk from individuals, not just regulators.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 13 marked complete

Plain-English obligations under Canada - Quebec - Personal Information Protection (Law 25). Not legal advice — verify against the official text before relying on it.

  1. #1CriticalSep 22, 2022

    Applies to: Organizations processing personal information of Quebec residents

    Organizations are required to publish the name, title, and contact information of their Privacy Officer on their website.
  2. #2CriticalSep 22, 2022

    Applies to: Organizations processing personal information of Quebec residents

    Mandatory reporting of confidentiality incidents presenting a risk of serious injury to the CAI and affected individuals.
  3. #3CriticalSep 22, 2022

    Applies to: Organizations using biometric characteristics for identity verification

    Notification to the CAI at least 60 days before carrying out identity verification or confirmation using biometric characteristics or measurements.
  4. #4CriticalSep 22, 2023

    Applies to: Organizations implementing new systems, cross-border transfers, or high-risk technologies like AI

    PIAs are explicitly required when personal information is to be communicated outside Quebec, or when implementing high-risk technologies like AI or biometrics.
  5. #5CriticalSep 22, 2023

    Applies to: Organizations collecting, using, or communicating personal information

    The Act mandates that consent for the collection, use, or communication of personal information must be explicit, free, informed, specific, and unambiguous.
  6. #6CriticalSep 22, 2023

    Applies to: Organizations processing personal information of Quebec residents

    Organizations must establish and implement governance policies and practices regarding personal information, which must be publicly disseminated.
  7. #7CriticalSep 22, 2023

    Applies to: Organizations processing personal information of Quebec residents

    Individuals now possess the right to be informed about the collection and use of their data, the right to access and rectify their personal information.
  8. #8CriticalSep 22, 2023

    Applies to: Organizations processing personal information of Quebec residents

    Organizations must implement robust security measures to protect personal information throughout its lifecycle.
  9. #9CriticalSep 22, 2024

    Applies to: Organizations holding computerized personal information of Quebec residents

    Individuals gain the right to obtain their computerized personal information in a structured, commonly used, and machine-readable format.
  10. #10ImportantSep 22, 2023

    Applies to: Organizations developing or acquiring information systems and services

    Organizations must also adhere to principles of privacy by design and by default, ensuring the highest level of confidentiality is applied to personal information.
  11. #11ImportantSep 22, 2023

    Applies to: Organizations using personal information for automated decision-making or profiling

    Obligation to inform individuals when personal information is used for identification, location, profiling, or automated decision-making.
  12. #12ImportantOngoing

    Applies to: Organizations processing personal information of Quebec residents

    Staff training is also a critical component, ensuring that all personnel understand their roles and responsibilities.
  13. #13ImportantOngoing

    Applies to: Organizations sharing personal information with third-party service providers

    Organizations must review and update contracts with third-party service providers to ensure that appropriate safeguards are in place.

© Regulations.AI — created on 06-Jan-2026 using Gemini 2.5 Flash