Skip to content
Cogio
Compliance· 16 min read· by Alexandre Sauvageau

Law 25: the complete compliance guide for Quebec businesses

Scope, timeline, 12 obligations, penal fines up to $25M and the requirements that apply to AI: the Law 25 guide for every Quebec business.

Signing a contract
Photo: Cytonn Photography, Pexels

A law that applies to every business, with no exceptions

Law 25, formally the Act to modernize legislative provisions as regards the protection of personal information (CQLR c. P-39.1), governs how private businesses collect, use, disclose and destroy personal information in Quebec. It sets no threshold for application: no minimum headcount, no revenue floor, no industry exemption. The three-person accounting practice, the manufacturing SME in Granby and the large industrial company in Saguenay are all subject to the same substantive obligations.

Personal information means any information that concerns a natural person and that makes it possible, directly or indirectly, to identify them: a name, an email address, a mailing address, a phone number in the CRM, an employee file. The law therefore covers your clients, but also your employees, your suppliers and your prospects. A business convinced that it holds “no sensitive data” almost always holds personal information within the meaning of the Act, if only its payroll list.

The timeline: everything is in force, and the penalties have started

The Act came into force in three waves, from September 2022 to September 2024. Since September 22, 2024, every obligation applies, including the right to data portability. The Regulation respecting the anonymization of personal information has been in force since May 30, 2024.

The grace period is over. In 2026 the Commission d’accès à l’information du Québec (CAI) made its first monetary penalties public. A business discovering the law today is therefore starting more than three years behind on its obligations.

Phased coming into force of Law 25
DateWhat comes into force
September 22, 2022Privacy officer; reporting of confidentiality incidents; incident register
September 22, 2023The core of the Act: strengthened consent, privacy impact assessments, transparency, governance policies, automated decisions, disclosures outside Quebec, right to de-indexing
May 30, 2024Regulation respecting the anonymization of personal information
September 22, 2024Right to portability (structured, commonly used technological format)
2026First monetary penalties made public by the CAI

The 12 obligations every business has to meet

Behind the text of the Act, the practical obligations come down to twelve pieces of work. Some are settled in a day, such as appointing the privacy officer. Others, such as the personal information register, call for real mapping: which controller, handed an access request tomorrow from a former employee, could say where all the information concerning that person actually sits?

  • Appoint a privacy officer, or in the Act’s own words the person in charge of the protection of personal information, and publish their title and contact details on the website (failing that, the role falls to the person with the highest authority).
  • Publish a privacy policy that is clear, accessible and faithful to what actually happens to the data.
  • Maintain a personal information register: what data, where, why, for how long, and who has access.
  • Carry out a privacy impact assessment before any project involving a system that processes personal information (s. 3.3).
  • Govern consent: manifest, free, informed, given for specific purposes, and requested separately for each purpose.
  • Handle confidentiality incidents: notify the CAI and the people concerned “promptly” where there is a risk of serious injury; keep the incident register for at least five years.
  • Set retention periods, then destroy or anonymize the information once the purpose has been fulfilled.
  • Process individual requests: access, correction, withdrawal of consent, de-indexing, portability, human review.
  • Audit third-party suppliers: processing agreement, data residency, incident notification timelines (s. 18.3).
  • Minimize collection to what is strictly necessary for the stated purpose.
  • Provide portability of information (in force since September 2024).
  • Disclose automated decisions and allow submissions and review (s. 12.1).

Three penalty regimes that can stack

Law 25 does not set out one penalty regime, it sets out three. The CAI can impose administrative monetary penalties directly, without going through the courts, of up to $10M or 2% of worldwide revenue, whichever is higher. The courts can additionally impose penal fines of $15,000 to $25M or 4% of worldwide revenue, and those prosecutions can target directors personally. The two ceilings should not be confused: the $10M belongs to the CAI, the $25M to the courts.

The third regime is the one that most sets Quebec apart: the private right of action. Anyone whose information was poorly protected can sue the business in civil court, including through a class action, and obtain punitive damages of at least $1,000 where the fault was intentional or gross. Multiply that floor by the number of client files caught up in an incident and the financial exposure becomes very concrete. A single breach can trigger all three regimes at once.

$10M

ceiling on administrative penalties the CAI can impose directly (or 2% of worldwide revenue)

$25M

ceiling on penal fines imposed by the courts (or 4% of worldwide revenue)

$1,000

minimum punitive damages per person where the fault was intentional or gross

GDPR or Law 25: which regime is the more demanding?

Businesses that have already complied with the European GDPR start with a head start, but they would be wrong to think the work is done. For people located in Quebec, Law 25 bites harder on several points: it applies with no threshold, it opens a private right of action with punitive damages attached, and it layers two ceilings of public penalties on top of each other.

One point of honesty is owed, however: Law 25 does not set the GDPR’s fixed 72-hour deadline for notifying the regulator of an incident. It requires notice “promptly,” which is no excuse for taking your time.

GDPR and Law 25 compared
CriterionGDPRLaw 25
Threshold for applicationDepends on the processingNone: every business
Private right of actionLimitedYes, civil and class actions
Punitive damagesNot provided for as suchYes, minimum $1,000 per person
Maximum penalties€20M or 4% of worldwide revenue$10M or 2% (CAI) and $25M or 4% (penal)
Officer to appointDPO, depending on the casePrivacy officer (by default: the most senior executive)
Incident notification deadline72 hours“Promptly” (no fixed deadline)

What Law 25 demands of your artificial intelligence projects

Section 3.3 requires a privacy impact assessment before any project to acquire, develop or redesign an information system that processes personal information. An AI assistant plugged into email, an agent that reads HR files, a meeting transcription tool: each of those projects triggers the obligation, and the assessment has to be documented before deployment, not after. We set out the method in our practical guide to the privacy impact assessment.

Section 12.1 governs decisions based exclusively on automated processing. If a system decides on its own (granting credit, screening out a candidate, setting a premium), you must inform the person no later than at the time of the decision, tell them what information was used and what the main factors were, then let them make submissions and ask for a review. The simplest design rule is still to keep a human able to review before any action is taken: the decision is then no longer “exclusively” automated, which takes it outside the scope of the section and simplifies compliance.

Section 17 requires a prior assessment before any disclosure of personal information outside Quebec, in order to demonstrate adequate protection. Using a cloud AI tool hosted in the United States without that assessment is one of the most common non-compliances we see. And server location does not settle the matter: under the US CLOUD Act, an American-owned provider can be compelled to hand over data even when it is stored in Canada. We go deeper into this in our article on the CLOUD Act and data sovereignty. Keeping the inference and the data in Quebec, on your own premises or with a host not subject to US law, removes that friction at the source.

Two last points bear directly on model training. First, information is only anonymized if it can no longer be used, irreversibly, to identify the person, according to the criteria in the anonymization regulation. In practice it is safer to de-identify information (redact it) before feeding it to a model than to claim it has been anonymized. Second, reusing personal information to train an AI model amounts to a new purpose, which needs its own legal basis. Requiring a written undertaking from your suppliers that your data is never used to train their models is not a whim: it is a compliance requirement.

The three mistakes we see most often

No officer appointed. Where no appointment is made, the role of privacy officer automatically falls to the person with the highest authority. Many SME presidents therefore carry that responsibility without knowing it, without their title and contact details being published on the website as the law requires.

American tools with no transfer assessment. The cloud CRM, the marketing email platform, the free AI assistant adopted by a busy employee: every flow of personal information leaving Quebec has to be assessed under section 17 and recorded in the register. Shadow AI, meaning tools used without IT approval, makes the problem worse because nobody knows what information is going where.

A decorative privacy policy. Copying a competitor’s policy or filling in a generic template creates a gap between what you promise and what you actually do. Promising what you do not do is an exploitable fault, both for the CAI and in a civil claim. A short, accurate policy beats an ambitious, false one.

Where to start: a realistic sequence in four pieces of work

Full compliance can feel crushing. It sequences well, though. First piece, in a day: formally appoint the privacy officer and publish their title and contact details. Second piece, over a few weeks: map the information you hold (systems, purposes, access, retention periods) in order to build the register. Third piece: fix the visible gaps, meaning the privacy policy, the consent mechanisms and the incident handling procedure. Fourth piece, ongoing: build the privacy impact assessment and the supplier assessment into the lifecycle of every new project, AI projects above all.

To turn this into action, our 12-step compliance checklist converts this guide into a concrete work plan, step by step. And if you would rather have an outside eye, our approach always begins with a diagnostic that maps your personal information flows and your AI tools before recommending anything at all.

Frequently asked questions

Does Law 25 apply to an SME with five employees?

Yes. Law 25 sets no threshold of size, revenue or industry: it applies to every business that holds personal information in Quebec. An SME with five employees that has a client list, employee files or a CRM is caught just as much as a large company.

What is the difference between administrative penalties and penal fines?

Administrative monetary penalties are imposed directly by the CAI, with no trial, up to $10M or 2% of worldwide revenue. Penal fines are imposed by the courts following a prosecution and range from $15,000 to $25M or 4% of worldwide revenue; they can target directors. A single breach can lead to both, on top of a civil claim by the people concerned.

Do we have to report a confidentiality incident within 72 hours?

No. Unlike the GDPR, Law 25 imposes no fixed 72-hour deadline. It requires the CAI and the people concerned to be notified “promptly” where an incident presents a risk of serious injury. In practice that means acting without undue delay as soon as the incident is identified, and recording every incident in a register kept for at least five years, whether or not it was reported.

Can we use an AI tool hosted in the United States and stay compliant?

It is possible, but on strict conditions: carry out the transfer assessment required by section 17, obtain written contractual guarantees (no use for training, data location, incident notification timelines) and document all of it in the register. You also have to reckon with the US CLOUD Act, which allows an American-owned provider to be compelled to hand over data even when it is stored in Canada. Hosting the AI in Quebec removes that friction at the source.

Who is the privacy officer if nobody has been appointed?

The Act provides that, where no appointment is made, the role automatically falls to the person with the highest authority in the business, usually the president. In other words, doing nothing does not remove the responsibility: it lands on the most senior executive, often without their knowledge. The role can be delegated in writing, and the officer’s title and contact details must be published on the website.

Sources and references

This article is a plain-language summary, accurate as of the date shown. It is not legal advice: for your own situation, consult a legal adviser or contact the Commission d’accès à l’information.