Baseline Controls News Resources Glossary About

Quebec Law 25 Compliance for Canadian Businesses Outside the Province

Quebec Law 25 Compliance for Canadian Businesses Outside the Province

Quebec Law 25, fully in force since September 2024, is Canada's strictest private-sector privacy law, and it applies to businesses outside Quebec that handle personal information of Quebec residents. If you run a Toronto-based e-commerce shop, a Vancouver consulting firm, or a Calgary service provider with even one Quebec customer, this law likely applies to you. The penalties are significant: administrative fines up to C$10 million or 2% of worldwide turnover, whichever is greater, under section 90.12 of the Act (P-39.1).

This guide explains the key obligations, timelines, and practical steps for Canadian small businesses serving Quebec customers from outside the province. This is informational context (not legal advice), and you should consult qualified legal counsel for your specific situation.

Does Quebec Law 25 Actually Apply to Businesses Outside Quebec?

Yes. Law 25 applies to any organization "carrying on an enterprise" in Quebec that collects, uses, or discloses personal information of Quebec residents. Legal commentators agree that selling goods or services into Quebec, even without a physical office there, can meet this threshold. According to Bryan Cave Leighton Paisner, "Law 25 likely is in scope for any organization, either within or outside the borders of Quebec, which processes Personal Information associated with one or more of Quebec's approximately 9 million residents."

There are no minimum thresholds for the number of Quebec customers you serve or the revenue you earn from them. If your online store ships to Montreal, your SaaS platform has users in Quebec City, or your professional services firm advises Quebec clients, you should assess your compliance obligations.

To understand how Law 25 fits into the broader Canadian privacy landscape alongside PIPEDA and other provincial laws, see our overview of Canada's privacy landscape.

What Are the Key Deadlines?

Law 25 rolled out in three phases, all now in effect:

  • September 22, 2022: Privacy officer designation, confidentiality incident (breach) notification to the CAI, and incident register requirements
  • September 22, 2023: Most substantive obligations: privacy policies, consent requirements, privacy impact assessments, individual rights (access, rectification, withdrawal), transparency rules, automated decision-making disclosures, and enforcement powers including administrative monetary penalties
  • September 22, 2024: Right to data portability

These dates come from the Quebec government and the official law text on CanLII. If you haven't started compliance work, you're already behind, but the practical steps are manageable for most small businesses.

Do I Need a Privacy Officer?

Yes, and you may already have one without realizing it. Under Law 25, the highest-ranking person in your organization is automatically the "person in charge of the protection of personal information" unless you formally designate someone else in writing. For a sole proprietorship, that's you.

You must publish the privacy officer's title and contact information on your website. This doesn't require filing anything with the CAI: just a public posting, typically in your privacy policy. According to CAI guidance and sources like Law 25 Kit, you can delegate the role to a trusted employee or even an external consultant, as long as the delegation is documented in writing.

For small businesses, this is often the owner, a general manager, or an administrative lead with some training on the requirements. The key is that someone is accountable and reachable.

What Goes in a Quebec Law 25 Privacy Policy?

Law 25 requires a published privacy policy that explains how you collect, use, and protect personal information. Separately, Quebec's Charter of the French Language (as amended by Bill 96) requires that businesses serving Quebec customers provide a French version of their privacy policy (with quality at least equal to any English version), as noted by Smart & Biggar. This French-language requirement comes from the Charter, not from Law 25 itself.

Your policy should cover:

  • The types of personal information you collect and why
  • How you use the information
  • Whether you share it with third parties, and if so, who and for what purpose
  • How long you retain the information
  • How individuals can access, correct, or withdraw consent for their information
  • Contact information for your privacy officer
  • Whether personal information may be transferred outside Quebec (and if so, to where)

If you use technology that profiles, identifies, or locates individuals (such as analytics or tracking tools), Law 25's privacy-by-default rules require those features to be off by default, with users actively choosing to enable them. For more on security controls that support privacy compliance, see secure configuration and hardening.

When Must I Report a Breach to the CAI?

You must notify the CAI and affected individuals "promptly" when a confidentiality incident presents a "risk of serious injury." To assess this, consider the sensitivity of the information, the anticipated consequences of its misuse, and the likelihood it will be used harmfully. Your privacy officer must be consulted during this assessment.

Regardless of whether an incident meets the notification threshold, you must record all incidents in an internal register and retain those records for at least five years. The CAI can request a copy of this register.

This is similar in concept to PIPEDA's breach reporting requirements, but the terminology differs ("risk of serious injury" rather than "real risk of significant harm"). The practical approach is the same: have an incident response plan ready before you need it.

Do I Need a Privacy Impact Assessment for Out-of-Province Data Transfers?

Yes. Before transferring personal information of Quebec residents outside the province (including Ontario, Alberta, or anywhere else in Canada), you must conduct a privacy impact assessment (PIA). According to the official law text (section 17), the PIA must assess whether the information will receive "adequate protection" in the receiving jurisdiction based on "generally recognized principles" of data protection.

If the assessment is satisfactory, you may proceed with the transfer, but you must document it in a written agreement with the recipient that addresses the identified risks. You must also inform individuals that their data may be communicated outside Quebec.

For many small businesses, this means:

  • If you use a cloud service provider based in Ontario or the U.S., you need a PIA and a data processing agreement
  • If you share customer lists with a marketing partner outside Quebec, the same applies
  • If you're the service provider receiving Quebec customer data, your Quebec clients may ask you to sign agreements confirming adequate safeguards

This requirement also applies when you retain a service provider outside Quebec to collect, hold, or use personal information on your behalf.

What Consent Rules Apply Under Law 25?

Consent under Law 25 must be clear, free, informed, specific, granular, separate, and temporary. For sensitive personal information (health data, financial details, biometrics, or anything with a high expectation of privacy), you need express consent: a clear, affirmative action like checking a box or signing a form.

Implied consent is permitted only when the use doesn't conflict with the individual's reasonable expectations and there's no risk of serious injury. Silence, inactivity, or pre-checked boxes do not constitute valid consent under Law 25.

The CAI's consent guidance makes clear that express consent is the general standard, with implied consent allowed only in narrow circumstances.

What Are the Penalties for Non-Compliance?

Law 25 introduced a two-tier enforcement framework with penalties far higher than PIPEDA's $100,000 maximum. These figures come from sections 90.12 and 91 of the Act (P-39.1):

  • Administrative monetary penalties: Up to the greater of C$10 million or 2% of worldwide turnover for the preceding fiscal year (section 90.12)
  • Penal fines: Up to the greater of C$25 million or 4% of worldwide turnover for more serious offences (section 91)
  • Minimum corporate fine: C$15,000
  • Punitive damages: At least C$1,000 per individual for intentional violations or gross fault (section 93.1)

For context, these penalty levels are modelled on the EU's GDPR and are the highest in Canada. For most small businesses, the reputational and operational costs of a breach or complaint are likely more immediate concerns than maximum fines, but the risk is real.

Practical Steps for a Toronto-Based Business

If you're running a small business in Ontario (or anywhere outside Quebec) with Quebec customers, here's a realistic starting point:

  1. Designate a privacy officer (even if it's yourself) and publish their contact information on your website
  2. Draft or update your privacy policy to meet Law 25 requirements, and ensure a French version is available
  3. Review your consent mechanisms, especially on forms, sign-ups, and any data collection touchpoints
  4. Identify where Quebec customer data goes: list your service providers, cloud platforms, and any third parties receiving personal information
  5. Conduct privacy impact assessments for any transfers of Quebec data outside the province
  6. Establish an incident register and a basic response plan for confidentiality incidents
  7. Train relevant staff on the basics of handling access, rectification, and withdrawal requests

These steps overlap significantly with good privacy hygiene under PIPEDA. For many businesses, Law 25 compliance is an incremental effort rather than a ground-up rebuild, especially if you've already implemented the Canadian Centre for Cyber Security's Baseline Controls.

Assess Your Readiness

If you're unsure whether your business meets the baseline security and data protection requirements that underpin privacy compliance, our free cybersecurity assessment can help you identify gaps. It evaluates your organization against the 13 Baseline Control areas, including access control and incident response, which directly support your privacy obligations under both PIPEDA and Quebec Law 25.

Further Reading

Free Assessment

How prepared is your business?

Find out where you stand against Canada's 13 Baseline Cyber Security Controls. The assessment takes under 30 minutes and your answers stay in your browser.

Check Your Score

Cite This Page

Suggested citation:

Cybersecurity Canada (2026). Quebec Law 25 Compliance for Canadian Businesses Outside the Province. Retrieved from https://cybersecuritycanada.ca/news/posts/quebec-law-25-compliance-guide-canadian-businesses-outside-quebec/

Disclaimer: This article is intended for general informational purposes only and does not constitute professional cybersecurity, legal, IT, or compliance advice. While we strive to ensure accuracy, the cybersecurity landscape changes rapidly and information may become outdated. Organizations should consult with qualified cybersecurity professionals and legal counsel to assess their specific situation and develop appropriate security policies. Use of this information is at your own risk. See our Privacy Policy for more information.

Cybersecurity Canada is an independent resource and is not affiliated with, endorsed by, or connected to the Canadian Centre for Cyber Security, the Communications Security Establishment, or the Government of Canada.

How does your organization measure up?

Take our free cybersecurity assessment based on the Canadian Centre for Cyber Security's Baseline Controls. 50 questions, under 30 minutes, 100% confidential. Your answers never leave your browser.

Take the Free Assessment