Canada - Quebec - Personal Information Protection (Law 25)
An Act to modernize legislative provisions as regards the protection of personal information (Law 25)
Loi modernisant des dispositions législatives concernant la protection des renseignements personnels (Loi 25)
Canada
RAI-CA-QC-MLPARXX-2021Quebec's Law 25 modernizes provincial privacy laws, strengthening individual rights, mandating explicit consent, PIAs, and a Privacy Officer, with significant penalties for non-compliance.
Summary
Read full text ↗Plain English
Overview
An Act to modernize legislative provisions as regards the protection of personal information, commonly known as Law 25 (formerly Bill 64), represents a significant overhaul of Quebec's privacy legislation. Adopted on September 22, 2021, this provincial Act aims to strengthen the protection of personal information for individuals and impose new, more stringent responsibilities on both public bodies and private sector organizations operating within Quebec, or handling the personal information of Quebec residents. The legislation introduces a comprehensive framework that was implemented in a phased approach, with key provisions coming into effect in September 2022, September 2023, and the final provisions by September 2024. This modernization effort positions Quebec at the forefront of data privacy in Canada, drawing parallels with global benchmarks such as the European Union's General Data Protection Regulation (GDPR).
The primary objective of Law 25 is to enhance transparency and accountability in how personal information is collected, used, communicated, retained, and destroyed. It significantly expands individual data rights, requiring organizations to obtain explicit and informed consent for data processing, conduct privacy impact assessments, and designate a privacy officer. Furthermore, the law introduces robust enforcement mechanisms, including substantial administrative monetary penalties and penal fines for non-compliance, along with a private right of action for individuals who suffer harm due to privacy breaches. This legislative update reflects a global trend towards adapting privacy frameworks to the complexities and challenges presented by evolving technological tools and the increasing sophistication of data processing activities.
Definitions
Law 25 introduces or clarifies several key definitions central to its application. "Personal information" is broadly defined as any information that relates to a natural person and allows that person to be identified. This encompasses a wide range of data, including full name, physical address, email address, phone number, financial records, and health records. The law applies to such information regardless of its format or accessibility, explicitly excluding public records and information pertaining to journalistic, historical, or genealogical material collected, held, used, or communicated in the public interest. The legislation also recognizes "sensitive personal information," which includes data related to an individual's health, biometric characteristics, financial situation, or any other information of an intimate nature. The disclosure or abuse of such sensitive data is deemed to carry a higher risk of harm to an individual.
A crucial distinction is made between "de-identification" and "anonymization." Personal information is considered de-identified if it no longer allows the person concerned to be directly identified. In contrast, "anonymization" requires that the information no longer allows the person to be identified, either directly or indirectly, and that this anonymization is irreversible. While Law 25 permits the retention of anonymized personal information for serious and legitimate purposes instead of destruction, the Commission d'accès à l'information (CAI) has expressed reservations regarding the standards for achieving complete and irreversible anonymization. The CAI indicates that further government regulations are needed to clarify the criteria and procedures for effective anonymization, creating a degree of uncertainty for organizations in this area.
Governance and Institutional Framework
The governance and institutional framework under Law 25 is significantly strengthened, with the Commission d'accès à l'information (CAI) serving as Quebec's primary privacy regulator. The Act enhances the CAI's functions and powers, granting it the authority to impose administrative monetary penalties (AMPs) and initiate penal proceedings for non-compliance. The CAI is responsible for developing guidelines on the application of the Act, evaluating confidentiality incident notices, and, where appropriate, ordering notifications to affected individuals. It also conducts research, studies, and analyses on access to information and personal information protection, and issues opinions on legislative projects and information system developments.
A cornerstone of the new governance structure is the mandatory designation of a "person in charge of the protection of personal information," often referred to as a Privacy Officer. While any employee can be appointed to this role, Law 25 defaults this responsibility to the highest senior employee (e.g., the CEO) if no specific individual is designated. Organizations are required to publish the name, title, and contact information of their Privacy Officer on their website. Furthermore, organizations must establish and implement governance policies and practices regarding personal information, which must be publicly disseminated. These rules must outline frameworks for the keeping and destruction of information, define the roles and responsibilities of staff throughout the information lifecycle, and provide a clear process for handling privacy complaints. Public bodies are also mandated to establish a committee on access to information and personal information protection to support them in fulfilling their responsibilities.
Key Focus Areas
Law 25 introduces several critical focus areas to bolster personal information protection. Central to these is the concept of enhanced consent. The Act mandates that consent for the collection, use, or communication of personal information must be explicit, free, informed, specific, and unambiguous. Requests for consent must be presented in clear and simple language, separate from any other information provided to the individual, ensuring that consent is not buried in fine print. For sensitive personal information, consent must be given expressly. The law also sets the age of consent for minors at 14 years, requiring the consent of a person having parental authority or a tutor for individuals under this age. Organizations are further required to obtain opt-in consent for the use of tracking technologies, such as cookies, that identify, locate, or profile individuals.
Another significant focus is the expansion of data subject rights, aligning Quebec's framework with the GDPR. Individuals now possess the right to be informed about the collection and use of their data, the right to access and rectify their personal information, and the right to request its erasure or de-identification. They also have the right to withdraw their consent for the communication or use of their information and to restrict its processing. A new right to data portability, effective September 2024, allows individuals to obtain their computerized personal information in a structured, commonly used, and machine-readable format, and to request its transfer to another organization. Law 25 also introduces the requirement for Privacy Impact Assessments (PIAs) in various circumstances, including any project involving the acquisition, development, or overhaul of information systems or electronic service delivery systems that handle personal information. PIAs are explicitly required when personal information is to be communicated outside Quebec, or when implementing high-risk technologies like AI or biometrics. Organizations must also adhere to principles of privacy by design and by default, ensuring the highest level of confidentiality is applied to personal information.
Implementation Framework
The implementation framework for Law 25 necessitates a comprehensive approach from organizations to ensure compliance across all operational aspects. Businesses are expected to undertake a thorough privacy audit to identify all personal information they collect, hold, use, or communicate, including defining sensitive data and the necessity of its retention. This initial data mapping exercise is crucial for understanding the scope of personal information managed and for developing an effective compliance strategy. Following this, organizations must update existing privacy policies and procedures or develop new ones to reflect the stringent requirements of Law 25, particularly concerning consent management, data subject rights, and incident response. These policies must be written in clear and simple language and made easily accessible to individuals.
Beyond policy development, the implementation framework requires tangible operational changes. Organizations must implement robust security measures to protect personal information throughout its lifecycle, from collection to destruction or anonymization. Staff training is also a critical component, ensuring that all personnel understand their roles and responsibilities regarding personal information protection and the organization's privacy policies. Furthermore, organizations must review and update contracts with third-party service providers to ensure that appropriate safeguards are in place for any personal information shared or processed on their behalf. This includes assessing the legal framework and protection measures in jurisdictions where data may be transferred. The phased rollout of Law 25 allows for a gradual adaptation, but continuous monitoring and adjustment of internal processes are essential to maintain ongoing compliance as new provisions come into full effect.
Monitoring and Evaluation
The monitoring and evaluation of compliance with Law 25 are primarily overseen by the Commission d'accès à l'information (CAI), Quebec's independent administrative body responsible for the enforcement of privacy legislation. The CAI has been granted significantly enhanced powers under Law 25 to ensure organizations adhere to the new requirements. These powers include the ability to conduct inquiries and inspections into how public bodies and private enterprises manage personal information. The CAI actively monitors compliance through various means, including the review of confidentiality incident reports submitted by organizations and assessing their governance rules and privacy policies.
In its role, the CAI is also mandated to develop guidelines and issue advisories to assist organizations in understanding and implementing the law's provisions. For instance, the Commission has taken a stance on complex issues like anonymization, indicating that further regulatory clarity is needed before organizations can confidently implement certain practices. This proactive engagement in clarifying legislative ambiguities and providing guidance is a key aspect of the monitoring framework. Organizations are expected to cooperate fully with CAI inquiries and inspections, with impeding the CAI's work being an offense punishable by penalties. The CAI's oversight ensures that organizations not only establish the necessary policies and procedures but also effectively implement and maintain them, fostering a culture of accountability and continuous improvement in personal information protection.
Penalties, Liability, and Appeals
Law 25 introduces a rigorous enforcement scheme with substantial penalties for non-compliance, designed to be dissuasive and to align with international standards such as the GDPR. For private sector organizations, administrative monetary penalties (AMPs) can be imposed by the CAI, reaching up to C$10 million or an amount corresponding to 2% of the enterprise's worldwide turnover for the preceding fiscal year, whichever is greater. These AMPs can be levied for various breaches, such as failing to inform individuals of the source, purpose, and means of collection of their personal information upon request. Before imposing an AMP, the CAI typically issues a notice of non-compliance, allowing the defaulting party an opportunity to remedy the alleged breach.
Beyond administrative penalties, Law 25 also establishes a new penal enforcement scheme with even higher fines. Since September 22, 2023, the CAI has the power to initiate penal proceedings within five years of an offense. Penal fines for corporations can reach up to C$25 million or 4% of worldwide turnover for the preceding fiscal year, whichever is greater, with a minimum fine of C$15,000 for corporations. For individuals, penal fines can range from C$5,000 to C$100,000. These fines can be doubled in the case of a subsequent offense. Offenses include unlawful collection, use, communication, keeping, or destruction of personal information, failure to report confidentiality incidents, or impeding the CAI's inquiries. Uniquely, Law 25 grants individuals a private right of action, allowing them to take legal action, including collective actions, against businesses that violate their privacy rights. Individuals who suffer harm due to intentional misconduct or gross negligence can claim damages of at least C$1,000, providing a direct avenue for redress not commonly found in other Canadian privacy laws.
Relationship to Other Instruments
Law 25 operates within a broader legal landscape, significantly modernizing and strengthening Quebec's existing privacy framework. It amends two primary provincial statutes: the Act respecting Access to documents held by public bodies and the Protection of personal information, and the Act respecting the protection of personal information in the private sector. This legislative update is considered more comprehensive and stringent than Canada's federal privacy law, the Personal Information Protection and Electronic Documents Act (PIPEDA), which applies to most commercial organizations across Canada. Law 25 introduces stronger safeguards, clearer explicit consent requirements, and broader individual rights compared to PIPEDA, which allows for implied consent in some situations. Organizations operating in Quebec or handling data from individuals residing there must comply with both Law 25 and PIPEDA where applicable, with Law 25 often imposing higher standards.
The Act also establishes a close alignment with the European Union's General Data Protection Regulation (GDPR), adopting similar principles regarding enhanced user consent, data subject rights (such as the right to erasure and data portability), and robust enforcement mechanisms with significant penalties. This resemblance means that businesses already compliant with GDPR may find it easier to adapt to Law 25's requirements. While there are similarities, Law 25 also introduces unique provisions, such as the private right of action for individuals, which is not available under GDPR. The law also modifies the Election Act to subject political entities to certain provisions of the Act respecting the protection of personal information in the private sector, extending privacy obligations to political parties, independent Members of the National Assembly, and independent candidates.
International Alignment
Quebec's Law 25 demonstrates a strong commitment to international best practices in data protection, particularly through its alignment with the European Union's General Data Protection Regulation (GDPR). This alignment is evident in several key areas, including the emphasis on explicit and informed consent, the expansion of individual data subject rights, and the introduction of significant penalties for non-compliance. The law's provisions for consent, requiring it to be free, informed, specific, and unambiguous, mirror the high standards set by the GDPR. Similarly, the comprehensive suite of individual rights, such as the right to access, rectification, erasure (right to be forgotten), restriction of processing, and data portability, directly reflects rights enshrined in the GDPR.
Furthermore, the substantial administrative monetary penalties and penal fines stipulated in Law 25, which can reach up to 4% of an organization's worldwide turnover, are directly comparable to the maximum penalties under the GDPR, signaling a similar level of regulatory seriousness. The requirement for Privacy Impact Assessments (PIAs) in certain high-risk processing activities, including cross-border data transfers, also aligns with GDPR principles that mandate risk-based assessments for data protection. This strong international alignment positions Quebec as a jurisdiction with a robust data privacy framework, facilitating data flows with other regions that adhere to similar high standards, while also requiring organizations to adopt globally recognized privacy principles.
Implementation Timeline
| Milestone | Date | Notes |
|---|---|---|
| Designation of Privacy Officer | 2022-09-22 | Organizations must designate a person in charge of personal information protection (Privacy Officer); defaults to CEO if not designated. Contact information must be published. |
| Breach Notification Requirements | 2022-09-22 | Mandatory reporting of confidentiality incidents presenting a risk of serious injury to the CAI and affected individuals. Requirement to maintain a register of all incidents. |
| New Rules for Communication of Personal Information without Consent | 2022-09-22 | Specific conditions for communicating personal information without consent for study, research, or statistical purposes, and in commercial transactions. |
| PIA for Research/Statistics | 2022-09-22 | Requirement to conduct a Privacy Impact Assessment before communicating personal information without consent for study, research, or statistical purposes. |
| Biometric Database Notification | 2022-09-22 | Notification to the CAI at least 60 days before carrying out identity verification or confirmation using biometric characteristics or measurements. |
| Governance Policies and Practices | 2023-09-22 | Establishment and publication of governance rules regarding personal information, including retention/destruction policies, staff roles/responsibilities, and a complaint process. |
| Enhanced Consent Requirements | 2023-09-22 | Stricter rules for obtaining free, informed, explicit consent in clear and simple language, separate from other information. Opt-in for tracking technologies. |
| Privacy by Design and by Default | 2023-09-22 | Organizations must ensure the highest level of confidentiality by default for personal information. |
| Expanded Individual Rights | 2023-09-22 | Rights to be informed, access, rectification, erasure (de-identification), withdrawal of consent, and restriction of processing come into force. |
| PIA for Systems and Cross-Border Transfers | 2023-09-22 | Mandatory Privacy Impact Assessments for any project involving the acquisition, development, or overhaul of information systems or electronic service delivery systems, or for communicating personal information outside Quebec. |
| Transparency for Automated Decision-Making | 2023-09-22 | Obligation to inform individuals when personal information is used for identification, location, profiling, or automated decision-making. |
| Right to Data Portability | 2024-09-22 | Individuals gain the right to obtain their computerized personal information in a structured, commonly used, and machine-readable format, and to request its transfer to another organization. |
Compliance Checklist
| Check | Required Action |
|---|---|
| Designate Privacy Officer | Appoint a Privacy Officer (person in charge of personal information protection) and publish their name, title, and contact information on your website. |
| Develop/Update Governance Policies | Establish and publicly disseminate clear policies and practices for the governance of personal information, including retention, destruction, staff roles, and a complaint process. |
| Implement Explicit Consent Mechanisms | Ensure all collection, use, and communication of personal information is based on free, informed, specific, and explicit consent, presented clearly and separately. Implement opt-in for tracking technologies. |
| Conduct Privacy Impact Assessments (PIAs) | Perform PIAs for new or overhauled information systems, electronic service delivery systems, cross-border data transfers, and high-risk technologies (e.g., AI, biometrics). |
| Establish Breach Notification Protocol | Develop and implement procedures for mandatory notification of confidentiality incidents to the CAI and affected individuals if there is a risk of serious injury. Maintain an incident register. |
| Respect Data Subject Rights | Establish processes to respond to requests for information, access, rectification, erasure, withdrawal of consent, restriction of processing, and data portability (by Sept 2024). |
| Ensure Privacy by Design and Default | Integrate privacy protection into the design of all systems and services, ensuring the highest level of confidentiality by default. |
| Manage Cross-Border Data Transfers | Assess the adequacy of protection in destination jurisdictions, conduct PIAs, implement contractual safeguards, and inform individuals before transferring data outside Quebec. |
| Provide Transparency for Automated Processing | Inform individuals when personal information is used for identification, location, profiling, or automated decision-making. |
| Implement Data Minimization and Retention Policies | Destroy personal information once its purpose is accomplished or anonymize it irreversibly, subject to legal retention periods. |
| Train Staff | Provide ongoing training to staff on privacy policies, procedures, and their responsibilities under Law 25. |
Sources and References
| Source | Type |
|---|---|
| An Act to modernize legislative provisions as regards the protection of personal information (2021, c. 25) | Official Legal Text |
| Act respecting Access to documents held by public bodies and the Protection of personal information (A-2.1) | Official Legal Text |
| Act respecting the protection of personal information in the private sector (P-39.1) | Official Legal Text |
| Loi 25 sur la protection des renseignements personnels des citoyens du Québec - Entrée en vigueur de nouvelles dispositions qui font du Québec un chef de file mondial (2023-09-22) | Government News Release |
| Projet de loi n° 64, Loi modernisant des dispositions législatives en matière de protection des renseignements personnels - Assemblée nationale du Québec | Government Legislative Portal |
| Principaux changements aux lois sur la protection des renseignements personnels - Commission d'accès à l'information du Québec | Government Agency Website |
Quebec's Law 25 significantly updates provincial privacy laws, strengthening individual rights and imposing new responsibilities on public bodies and private organizations operating in Quebec or handling the personal information of its residents.
This comprehensive legislation applies to any organization that collects, uses, or communicates personal information of individuals in Quebec. It mandates several key changes: - Organizations must designate a Privacy Officer, with the CEO automatically assuming this role if no one else is appointed. - Consent for data collection, use, or communication must be explicit, free, informed, specific, and unambiguous, presented in clear language. Opt-in consent is required for tracking technologies like cookies. - "Privacy by Design" and "Privacy by Default" are now legal requirements, meaning privacy protections must be built into systems and processes, with the highest level of confidentiality applied automatically. - Organizations must conduct Privacy Impact Assessments (PIAs) for projects involving new information systems, electronic services, or when transferring data outside Quebec. They also need to report serious data breaches to the Commission d'accès à l'information (CAI) and affected individuals.
Law 25 rolled out in phases. Key provisions like the Privacy Officer designation and breach notification took effect in September 2022. Enhanced consent, privacy by design, and PIAs became mandatory in September 2023. The final provision, the right to data portability, comes into force in September 2024. Non-compliance carries substantial penalties. The CAI can issue administrative fines up to C$10 million or 2% of worldwide turnover, and penal fines up to C$25 million or 4% of worldwide turnover. A significant surprise for many is the new private right of action, allowing individuals to sue organizations for damages (at least C$1,000 for intentional misconduct or gross negligence) if their privacy rights are violated. This means direct legal risk from individuals, not just regulators.
Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.
What you must do — compliance checklist
0 / 13 marked completePlain-English obligations under Canada - Quebec - Personal Information Protection (Law 25). Not legal advice — verify against the official text before relying on it.
- #1Critical⏰ Sep 22, 2022
Applies to: Organizations processing personal information of Quebec residents
“Organizations are required to publish the name, title, and contact information of their Privacy Officer on their website.”
- #2Critical⏰ Sep 22, 2022
Applies to: Organizations processing personal information of Quebec residents
“Mandatory reporting of confidentiality incidents presenting a risk of serious injury to the CAI and affected individuals.”
- #3Critical⏰ Sep 22, 2022
Applies to: Organizations using biometric characteristics for identity verification
“Notification to the CAI at least 60 days before carrying out identity verification or confirmation using biometric characteristics or measurements.”
- #4Critical⏰ Sep 22, 2023
Applies to: Organizations implementing new systems, cross-border transfers, or high-risk technologies like AI
“PIAs are explicitly required when personal information is to be communicated outside Quebec, or when implementing high-risk technologies like AI or biometrics.”
- #5Critical⏰ Sep 22, 2023
Applies to: Organizations collecting, using, or communicating personal information
“The Act mandates that consent for the collection, use, or communication of personal information must be explicit, free, informed, specific, and unambiguous.”
- #6Critical⏰ Sep 22, 2023
Applies to: Organizations processing personal information of Quebec residents
“Organizations must establish and implement governance policies and practices regarding personal information, which must be publicly disseminated.”
- #7Critical⏰ Sep 22, 2023
Applies to: Organizations processing personal information of Quebec residents
“Individuals now possess the right to be informed about the collection and use of their data, the right to access and rectify their personal information.”
- #8Critical⏰ Sep 22, 2023
Applies to: Organizations processing personal information of Quebec residents
“Organizations must implement robust security measures to protect personal information throughout its lifecycle.”
- #9Critical⏰ Sep 22, 2024
Applies to: Organizations holding computerized personal information of Quebec residents
“Individuals gain the right to obtain their computerized personal information in a structured, commonly used, and machine-readable format.”
- #10Important⏰ Sep 22, 2023
Applies to: Organizations developing or acquiring information systems and services
“Organizations must also adhere to principles of privacy by design and by default, ensuring the highest level of confidentiality is applied to personal information.”
- #11Important⏰ Sep 22, 2023
Applies to: Organizations using personal information for automated decision-making or profiling
“Obligation to inform individuals when personal information is used for identification, location, profiling, or automated decision-making.”
- #12Important⏰ Ongoing
Applies to: Organizations processing personal information of Quebec residents
“Staff training is also a critical component, ensuring that all personnel understand their roles and responsibilities.”
- #13Important⏰ Ongoing
Applies to: Organizations sharing personal information with third-party service providers
“Organizations must review and update contracts with third-party service providers to ensure that appropriate safeguards are in place.”
Related Regulations
Projet de loi organique relatif à la protection des données à caractère personnel (2025)
Tunisia89% similar
Consumer Privacy Protection Act (CPPA) (proposed, part of Bill C-27)
Canada88% similar
Protection of Privacy Act (Bill 33)
Canada88% similar
Énoncé de principes pour une utilisation responsable de l'intelligence artificielle par les organismes publics (Québec Ministry of Cybersecurity and Digital Affairs)
Canada87% similar
Strengthening Cyber Security and Building Trust in the Public Sector Act, 2024
Canada87% similar
© Regulations.AI — created on 06-Jan-2026 using Gemini 2.5 Flash