Home › Law library › Quebec Law 25
CA
Quebec Law 25
Act respecting the protection of personal information in the private sector (CQLR c P-39.1), as amended by Law 25 (Bill 64)
Sourced. Last verified 9 October 2026
Quebec, Canada Privacy
- Status
- In force; amendments phased in Sep 2022, Sep 2023 (main wave) and Sep 2024 (data portability).
- Who it applies to
- Enterprises that collect, hold, use or communicate personal info in the course of carrying on business in Quebec.
- Size thresholds
- No size or revenue thresholds; applies to any enterprise handling personal info.
- Regulator
- Commission d'accès à l'information du Québec (CAI)
- Breach or incident reporting
- Notify the CAI and affected persons of any confidentiality incident that presents a risk of serious injury; keep an incident register and give it to the CAI on request.
- Deadline to answer personal data requests
- Being verified
- Data protection officer
- The person with the highest authority (e.g., CEO) is by default the person in charge of protecting personal information; may delegate in writing. Title and contact details must be published on the website.
- Local representative
- Being verified
- Sending data abroad
- Before communicating personal info outside Quebec (including to other provinces), complete a privacy impact assessment; transfer only if it shows adequate protection, and put a written agreement in place (since Sep 2023).
- Cookies and consent
- Express consent for sensitive data. Disclose any technology that identifies, locates or profiles people (e.g., ad cookies) and how to activate it. Highest privacy settings by default (CAI says not for cookies).
- Maximum penalty
- Administrative monetary penalties up to C$10M or 2% of worldwide turnover (whichever is greater); penal fines up to C$25M or 4% of worldwide turnover for enterprises (C$5,000-C$100,000 for individuals).
Facts marked “Being verified” are still being confirmed and are not given as answers.
What you must do
- Designate and publish the person in charge of personal information (default: the CEO).
- Adopt and publish governance policies and a plain-language privacy policy.
- Do a privacy impact assessment before sending personal info outside Quebec and sign a written agreement.
- Report confidentiality incidents with risk of serious injury to the CAI and affected people; keep an incident register.
- Disclose use of identification, location or profiling technologies and how to turn them on.
- Tell people when a decision is made solely by automated processing and explain it on request.
- Provide personal info in a portable, structured format on request.
Recent changes
Final phase (data portability right) took effect 22 Sep 2024. CAI can now impose administrative monetary penalties and pursue penal fines under the amended Act.
Sources
- Primary source: https://www.cai.gouv.qc.ca/protection-renseignements-personnels/sujets-et-domaines-dinteret/principaux-changements-loi-25
- Second source: https://www.clydeco.com/en/insights/2023/09/law-25-quebec-s-second-wave-of-new-privacy-amendme
- Regulator: Commission d'accès à l'information du Québec (CAI)
Information only, not legal advice. Laws change; confirm with the regulator or a qualified lawyer before relying on this page. Spotted an error? Email [email protected].