Skip to content
Guide

Quebec's Law 25, plainly: what it actually requires of a business

“Law 25” is the common name for the Quebec statute adopted in 2021 that rewrote the rules on personal information. For a private business, those rules live in the Act respecting the protection of personal information in the private sector (CQLR, chapter P-39.1). This page summarizes what the text requires, section by section, with a link to the official text for every point. It is not legal advice: it is the summary we had to write for ourselves, published as is.

Read from the official consolidated version, current to 1 April 2026.

Last reviewed:

Four things to know

  • What it is

    An overhaul, not a new statute

    “Law 25” refers to chapter 25 of the 2021 statutes. It did not create a separate regime: it amended existing legislation. For a private business, the text to read is the Act respecting the protection of personal information in the private sector (P-39.1).

  • Who is covered

    Every business, no threshold

    Section 1 covers anyone who collects, holds, uses or communicates to third parties personal information about others in the course of carrying on an enterprise within the meaning of article 1525 of the Civil Code. There is no employee threshold, no revenue threshold and no small-business exemption. The Act does set out a few subject-matter exclusions — notably journalistic, historical or genealogical material released for the legitimate information of the public.

  • Since when

    In waves, since 2022

    The obligations came into force in waves. The person in charge of the protection of personal information and the confidentiality-incident regime (ss. 3.1 and 3.5 to 3.8) have applied since 22 September 2022; most of the rest — impact assessments, communication outside Quebec, rules for service providers, retention, automated decisions — since 22 September 2023; the right to portability since 22 September 2024.

  • What it costs

    Up to $25M or 4%

    Three regimes, not two. Administrative monetary penalty: at most $10,000,000 or 2% of worldwide turnover for the preceding fiscal year, whichever is higher (s. 90.12). Penal prosecution: a fine of $15,000 to $25,000,000 or 4% of that same turnover, whichever is higher (s. 91). And, without going through the Commission, punitive damages of at least $1,000 for unlawful and intentional interference or interference resulting from gross negligence (s. 93.1).

The obligations, section by section

Every line is a summary of our reading, not a quotation — the official text is linked at each point, and it is the official text that is authoritative. Where a section carries a condition or an exception that changes the outcome, we keep it rather than prune it: a summary that lightens the rule is exactly the shortcut that turns on whoever relied on it.

  1. s. 3.1

    Appoint a person in charge — and publish their contact details

    The person with the highest authority in the enterprise is by law the person in charge of the protection of personal information. They may delegate the function in writing, in whole or in part. The title and contact details of the person in charge must be published.

    Source

  2. s. 3.2

    Governance policies — written, approved, published

    The enterprise must establish and implement policies and practices governing its handling of personal information. They must provide a framework for retention and destruction, set out the roles and responsibilities of staff throughout the life cycle of the information, and include a process for dealing with complaints. They must be proportionate to the nature and scope of the enterprise's activities and be approved by the person in charge. Detailed information about them must be published, in clear and simple language, on the enterprise's website — or made available by other means if it has no website.

    Source

  3. s. 8

    Say why and how, at collection

    Where information is collected from the person concerned, they must be informed — at the time of collection and afterwards on request — of the purposes pursued, the means of collection, their rights of access and rectification, and their right to withdraw consent. Where applicable, they must also be told the name of the third party for whom the collection is made, the third parties or categories of third parties to whom the information will have to be communicated, and the possibility that the information could be communicated outside Quebec. On request, add the information collected, the categories of persons within the enterprise who have access to it, the retention period and the contact details of the person in charge. All of it in clear and simple language, whatever the means of collection.

    Source

  4. s. 14

    Valid consent: manifest, free, enlightened — and asked purpose by purpose

    Consent must be manifest, free and enlightened, and given for specific purposes. It is requested for each of those purposes, in clear and simple language, and, where it is requested in writing, presented separately from any other information. It is valid only for the time necessary to achieve the purposes for which it was requested. For a minor under 14, it is given by the person having parental authority or by the tutor. Consent that does not meet these requirements is without effect.

    Source

  5. s. 9.1

    Confidentiality by default, with nothing for the user to do

    Anyone who collects personal information while offering to the public a technological product or service with privacy settings must ensure that, by default, those settings provide the highest level of confidentiality, without any intervention by the person concerned. The privacy settings of a cookie are not covered.

    Source

  6. s. 8.2

    A published confidentiality policy — and a notice for every amendment

    Anyone who collects personal information through technological means must publish a confidentiality policy on the enterprise's website, where applicable, and disseminate it by any means capable of reaching the persons concerned, drafted in clear and simple language. The same dissemination is required for the notice that must be given of any amendment to that policy.

    Source

  7. s. 10

    Security measures in proportion

    Measures must be reasonable given the sensitivity of the information, the purpose of its use, its quantity, distribution and medium. This section predates Law 25 and was not amended by it — it already applied.

    Source

  8. s. 12.1

    A fully automated decision: say so

    Where a decision is based exclusively on automated processing, the person must be informed no later than when the decision is communicated to them. On request, you must also tell them the information used, the reasons and the principal factors and parameters that led to the decision, and their right to have that information corrected. And they must be given the opportunity to submit observations to a member of staff who is in a position to review the decision. This is the section any AI project should read first.

    Source

  9. s. 12

    Using information for another purpose: the list is closed

    Information may be used within the enterprise only for the purposes for which it was collected, unless the person consents — express consent where the information is sensitive. Only five exceptions allow another use without consent: a consistent purpose, the clear benefit of the person, the prevention and detection of fraud or the assessment and improvement of protection and security measures, the supply of a product or service requested by the person, and study, research or the production of statistics on de-identified information. A purpose is “consistent” only where there is a relevant and direct connection with the purpose of collection, and commercial or philanthropic prospection is never one. De-identified information remains personal information, and whoever uses it must take reasonable measures to limit the risk of re-identification.

    Source

  10. s. 3.3

    An impact assessment for any information-system project

    A privacy impact assessment is required for any project to acquire, develop or overhaul an information system or an electronic service delivery system that involves the collection, use, communication, keeping or destruction of personal information. The person in charge must be consulted from the outset of the project. The project must also allow computerized personal information collected from the person concerned to be communicated to them in a structured, commonly used technological format. The extent of the assessment must be proportionate to the sensitivity of the information, the purpose of its use, its quantity, distribution and medium.

    Source

  11. s. 17

    An impact assessment before anything goes outside Quebec

    Before communicating personal information outside Quebec, you must conduct a privacy impact assessment taking into account, in particular, the sensitivity of the information, the purpose of its use, the protection measures — including contractual ones — it would receive, and the legal framework of the receiving state. The Act does not prohibit the transfer, it conditions it: the communication may take place only where the assessment establishes that the information would receive adequate protection, and it must be the subject of a written agreement taking into account the results of the assessment and the mitigation measures agreed on. The SAME applies where a person or body outside Quebec is entrusted with collecting, using, communicating or keeping such information on your behalf — hosting and outsourced operation are therefore covered, even with no “communication” in the ordinary sense. One exception only: a communication made in an emergency that endangers the life, health or safety of the person concerned (s. 18, para. 1, subpara. 7).

    Source

  12. s. 18.3

    Outsourcing: a written contract, and named measures

    Information may be communicated to a mandatary or a service provider without the consent of the person concerned where it is necessary for performing the mandate or the contract of enterprise or for services. Two conditions: the mandate or contract must be conferred IN WRITING, and it must state the measures the provider is to take to protect the confidentiality of the information, to ensure it is used only in performing the contract, and to ensure it is not kept after the contract expires. The provider, for its part, must notify the person in charge without delay of any violation or attempted violation of those obligations, and must allow any verification relating to confidentiality. That content requirement — the one in the second paragraph, which lists the measures to be stated — does not apply where the mandatary is a public body or a member of a professional order. The obligation to confer the mandate IN WRITING, for its part, remains.

    Source

  13. ss. 3.5 to 3.8

    Confidentiality incidents: act, notify, record

    As soon as an enterprise has REASONABLE GROUNDS TO BELIEVE that a confidentiality incident has occurred, it must take reasonable measures to reduce the risk of harm being caused and to prevent new incidents of the same nature. To assess the risk it must consider the sensitivity of the information, the anticipated consequences of its use and the likelihood that it will be used for harmful purposes, and it must consult its person in charge of the protection of personal information. Where the incident presents a risk of SERIOUS injury, it must promptly notify the Commission d'accès à l'information, and it must also notify every person concerned. Mind the scope of the deferral: the section suspends ONLY the notice to the persons concerned, “for as long as this would be likely to hinder an investigation” by a body responsible for preventing, detecting or repressing crime. The notice to the Commission is not deferrable. A register of incidents must be kept and sent to the Commission on request; the content of the notices and of the register is prescribed by the Regulation respecting confidentiality incidents, and the register is kept for five years.

    Source

  14. s. 23

    Destroy or anonymize when it is over

    Once the purposes for which information was collected or used have been achieved, it must be destroyed or anonymized in order to be used for serious and legitimate purposes, subject to any retention period provided for by an Act. The threshold is demanding: information is anonymized only where it is, AT ALL TIMES, reasonably foreseeable in the circumstances that it irreversibly no longer allows the person to be identified DIRECTLY OR INDIRECTLY — and the anonymization must follow generally accepted best practices as well as the criteria and terms of the Regulation respecting the anonymization of personal information (re-identification analysis, supervision by a qualified person, a register). Not to be confused with DE-IDENTIFICATION (s. 12), which removes only direct identification: de-identified information remains personal information subject to the Act, and whoever holds it must limit the risk of someone being re-identified from it. Attempting to re-identify a person from anonymized information is an offence (s. 91, subpara. 5).

    Source

  15. s. 32

    Answer within 30 days — silence counts as a refusal

    The person in charge must answer an access or rectification request in writing, with diligence and no later than 30 days after receiving it; failing to answer within that period, they are deemed to have refused it. Two neighbouring sections complete the mechanism and are not what this one says: section 30 requires the request to be made in writing and obliges the person in charge to assist when it is not sufficiently precise; section 33 makes access free of charge, subject to reasonable fees for transcription, reproduction or transmission whose approximate amount must be given before proceeding.

    Source

  16. ss. 27 and 28

    Access and rectification

    On request, the business must confirm that information exists and communicate it, allowing a copy to be obtained. Section 27 goes further than access: computerised information collected FROM the applicant — not created or inferred from information concerning them — must, on request, be communicated “in a structured, commonly used technological format”, unless this raises serious practical difficulties. That is the portability right, and it is the clause that bears most directly on a tool vendor. Section 28 adds rectification of information that is inaccurate, incomplete or equivocal, or whose collection, communication or retention is not authorized by law.

    Source

  17. Guide de la CAI

    How to document an impact assessment

    The statute requires the assessment but does not dictate its form. The Commission d'accès à l'information publishes a companion guide to the exercise and its documentation — that is the regulator's expectation, and the document we follow.

    Source

This page is a reading summary, not legal advice, and it replaces neither the official text nor your own counsel. Every point links to the source so you can verify rather than take our word for it.

What changes when you add AI

Adopting an AI platform creates no new obligations: it triggers the ones that already existed, all at once. It is an information-system project (s. 3.3), so an impact assessment applies. The request is usually computed outside Quebec, so section 17 applies. The vendor is a service provider, so section 18.3 requires a written contract naming the measures. And if the model's output decides anything on its own, section 12.1 applies.

  • An AI project is an information-system project — the s. 3.3 assessment is not optional.
  • Location is not prohibited by the statute; what is required is the s. 17 assessment, and documenting it.
  • The AI vendor is a service provider under s. 18.3: written contract, measures stated.
  • A decision made exclusively by the machine triggers the notice obligation in s. 12.1.
  • Training on your content is not a purpose the person consented to — check the clause.

And concretely, for your sector?

We ran the same exercise sector by sector: the obligations for an ordinary business, then what regulators add in finance, insurance, law, health, accounting, the public sector and the professional orders. Every requirement there carries our answer and, where that is the case, the gap we have not closed yet.

What people ask us about Law 25

What is Law 25, in one sentence?
It is the Quebec statute adopted in 2021 (chapter 25 of that year's statutes) that modernized the protection of personal information. It did not replace the existing regime: it amended legislation already in place, including the Act respecting the protection of personal information in the private sector (P-39.1), which is the text a private business needs to read.
When did Law 25 come into force?
In stages, and section 175 of the 2021 Act sets them out one by one. The person in charge of the protection of personal information and the confidentiality-incident obligations (ss. 3.1 and 3.5 to 3.8) have applied since 22 September 2022. Most of the others — impact assessments, communication outside Quebec, rules for service providers, retention and destruction, automated decisions — since 22 September 2023. The right to portability arrived on 22 September 2024.
My business is small. Am I really covered?
Yes. Section 1 sets no threshold: not headcount, not revenue — size is never a criterion. As soon as a person collects, holds, uses or communicates to third parties personal information about others in the course of carrying on an enterprise, they are covered. What scales with size is the proportionality of the measures expected — not whether the Act applies.
Does Law 25 require data to be hosted in Quebec?
No, and this is the most widespread misunderstanding — but “no” does not mean “unconditionally”. Section 17 does not prohibit communication outside Quebec: it requires you to assess it beforehand, taking into account, in particular, the sensitivity of the information, the purpose, contractual protection measures and the legal framework of the receiving state. The communication may then take place only where the assessment establishes adequate protection, and it must be the subject of a written agreement. And the section is not limited to sending data out: its third paragraph expressly reaches entrusting a person or body outside Quebec with collecting, using, communicating or keeping information on your behalf — so hosting itself, and not only a transfer. Some sectors do add a genuine localisation requirement: that is the case for the distribution of financial products and services, including insurance, where section 88 of the Act respecting the distribution of financial products and services requires a firm to keep its clients' records in Quebec.
Do I need an impact assessment to adopt an AI tool?
Section 3.3 requires a privacy impact assessment for any project to acquire, develop or overhaul an information system involving personal information. An AI platform your teams feed with your documents fits that description. And if the requests leave Quebec, section 17 imposes a second assessment on that specific point.
What are the penalties?
Three regimes. The administrative monetary penalty, imposed by a person designated by the Commission d'accès à l'information, is capped at $10,000,000 or 2% of the previous year's worldwide turnover, whichever is higher (s. 90.12). Penal prosecution exposes a business to a fine of $15,000 to $25,000,000 or 4% of that same turnover, whichever is higher (s. 91). For a natural person the figures are $50,000 and $5,000 to $100,000 respectively. A third regime exists as well, and it does not go through the Commission: unlawful and intentional interference, or interference resulting from gross negligence, gives rise to punitive damages of at least $1,000 (s. 93.1).
What if an AI makes a decision about someone?
Section 12.1 applies as soon as the decision is based exclusively on automated processing. You must inform the person no later than when the decision is communicated, provide on request the information used, the reasons and the principal factors and parameters, along with their right of rectification — and give them the opportunity to submit observations to a member of staff in a position to review the decision. If a human genuinely decides, the section does not apply. The Act does not define “exclusively”: our reading — and the one privacy authorities generally take — is that a purely formal human intervention, with no real capacity to change the outcome, does not turn an automated decision into a human one. That is an interpretation, not the text.

Compliance is not something you buy with software

No platform makes you compliant with Law 25 — the statute binds the business, not the tool. What a vendor can do is give you something to answer with: an architecture described, a contract that names the measures, and an honest list of what it does not cover. That is what we publish.