Quebec's Law 25 has been fully in force since September 2024, and the penalties are no longer theoretical. Under the Act respecting the protection of personal information in the private sector (P-39.1), the CAI can now impose administrative monetary penalties up to $10 million or 2% of worldwide turnover (s. 90.1), penal fines up to $25 million or 4% with a corporate minimum of $15,000 (s. 91), and individuals can pursue private action for punitive damages of not less than $1,000 per violation (s. 93.1).
Many of the Law 25 compliance guides out there are written by privacy software vendors or law firms, and they explain what the law says. This post covers what security and IT teams need to implement, broken down into concrete actions with references to the legislation itself.
Watch out
A note on scope
Truvo Cyber is not a law firm, and this post is not legal advice. What follows is a security practitioner's interpretation of Law 25's requirements as they map to technical controls and operational processes. When working with clients on Law 25 compliance, we coordinate with qualified privacy counsel to validate the legal specifics for their situation.
Who Needs to Care About Law 25
Law 25 applies to any private-sector organization that collects personal information from Quebec residents, regardless of where the organization is headquartered. If a company has customers, employees, or users in Quebec, the law applies.
At a glance
The Jurisdictional Reach
A SaaS company in Ontario with a handful of Quebec-based users is in scope. A services firm with one employee working remotely from Montreal is in scope. The reach is broader than PIPEDA, and the penalties are significantly sharper. Where PIPEDA is enforced by the Office of the Privacy Commissioner through recommendations, Law 25 gives the CAI direct penalty authority.
For organizations already pursuing SOC 2 or ISO 27001, the overlap is substantial. Many of the technical safeguards Law 25 requires are controls that a well-built security program already implements. The gaps tend to be in privacy governance, consent management, and data lifecycle processes rather than in security infrastructure.
The Law 25 Compliance Checklist
1. Designate a Privacy Officer (s. 3.1)
Under section 3.1 of Law 25, the person exercising the highest authority in the organization is responsible for ensuring compliance. This responsibility can be delegated in writing, in whole or in part, to any member of the organization's personnel. If delegated, the privacy officer's title and contact details must be published on the company website.
What to do:
- Formally designate the privacy officer in writing
- Publish their name and contact details on the company website, accessible rather than buried in a footer link
- Ensure the privacy officer has the authority and resources to fulfill the role
For smaller organizations, this often falls to the same person managing the security program. That works, as long as the responsibilities are clearly documented.
2. Establish a Privacy Governance Policy (s. 3.2)
Section 3.2 of Law 25 requires organizations to establish and implement governance policies and practices for the protection of personal information. The policy must cover retention and destruction of information, define roles and responsibilities of personnel, and include a complaint process. The policy must be proportionate to the nature and scope of the enterprise's activities, and a simplified version must be published in clear, simple language.
This is an internal governance document that describes how the organization handles personal information across its operations, separate from the privacy policy on the website.
What to do:
- Create an internal policy covering what personal information is collected, why, where it is stored, who has access, how long it is retained, and how it is destroyed
- Align retention periods with actual business needs, not indefinite defaults
- Publish a simplified version on the website that describes practices in clear language
- Have the privacy officer approve the policy
Organizations with an existing Information Security Management System (ISMS) under ISO 27001 or a SOC 2 program will find that much of this governance structure already exists. The gap is typically in privacy-specific language and data lifecycle documentation.
3. Implement Breach Notification and Record-Keeping (ss. 3.5-3.8)
Section 3.5 of Law 25 requires organizations to notify the CAI and affected individuals when a confidentiality incident presents a risk of serious injury. Section 3.6 defines a confidentiality incident as any unauthorized access, use, or communication of personal information, or any loss or breach of information protection. Section 3.7 specifies that when assessing injury risk, organizations must consider the sensitivity of the information and the anticipated consequences of its use. Section 3.8 requires organizations to maintain a register of all confidentiality incidents.
What to do:
- Update the incident response plan to include privacy breach notification procedures
- Establish a breach register that tracks what happened, what information was affected, how many individuals, what remediation was taken, and whether the CAI and individuals were notified
- Define risk of serious injury criteria internally so the response team can make the notification decision quickly, considering the sensitivity of the information and anticipated consequences (s. 3.7)
- Set up a process to notify the CAI and affected individuals promptly when the threshold is met
Teams already running SOC 2 CC7.1 (security event monitoring) and CC7.3 (incident response) have the infrastructure for this. The addition is the privacy-specific notification workflow and the formal breach register.
4. Conduct Privacy Impact Assessments (s. 3.3)
Section 3.3 of Law 25 makes Privacy Impact Assessments (PIAs) mandatory for any project to acquire, develop, or overhaul an information system or electronic service delivery system that involves the collection, use, communication, retention, or destruction of personal information. The privacy officer must be consulted from the outset of the project. Assessments must be proportionate to the sensitivity of the information, the purposes for which it is to be used, the quantity and distribution of the information, and the medium on which it is stored.
The CAI published its official PIA guide and template in September 2023, which provides a methodology for quantifying and addressing privacy risks. The template is not mandatory, but it provides a solid starting point.
What to do:
- Create a PIA template that evaluates what personal information is involved, the purpose of processing, risks to individuals, and safeguards to mitigate those risks
- Build PIA triggers into the project intake process so assessments happen before development starts, not after
- For cross-border data transfers, the PIA must evaluate whether the receiving jurisdiction offers protection equivalent to Quebec's standards
- Document PIA outcomes and track remediation of identified risks
This is where organizations handling data in cloud environments need to pay attention. If the infrastructure is hosted outside Quebec, which is nearly always the case, the cross-border transfer rules apply. The PIA needs to assess whether the hosting jurisdiction's legal framework provides adequate protection.
5. Implement Consent Management (ss. 8, 8.1, 12)
Law 25 takes a stricter position on consent than PIPEDA. Under section 8, when collecting personal information, organizations must inform individuals of the collection purposes, means of collection, access and rectification rights, and consent withdrawal rights, all in clear and simple language. Section 8.1 adds that any technology enabling identification, location, or profiling requires prior notification and consent. Section 12 restricts use of information to the purposes for which it was collected, and requires express consent for any use of sensitive personal information.
Watch out
Quebec is an Outlier on Cookies
Quebec is the only Canadian jurisdiction requiring explicit opt-in consent for tracking technologies like cookies. A compliance posture copied from PIPEDA guidance will not satisfy Law 25's consent bar.
What to do:
- Audit all points where personal information is collected and ensure each has a clear, specific consent mechanism
- Implement cookie consent management that defaults to opt-out rather than pre-checked boxes
- Ensure consent requests are presented in clear, plain language, separate from terms of service
- Build a system to record and store proof of consent: what was consented to, when, and by whom
- Allow individuals to withdraw consent as easily as they gave it
In our experience, consent management is where security programs have the largest Law 25 gap. Security controls protect data after it is collected, but consent management governs whether it should be collected at all. For most organizations, this requires new tooling or workflows that sit outside the traditional security stack.
6. Enable Data Subject Rights (s. 27)
Section 27 of Law 25 grants individuals the right to access their personal information, have it corrected, and receive it in a structured, commonly used technological format (data portability). Under section 32, the person in charge must reply in writing to access or correction requests promptly and not later than 30 days after the date the request is received.
What to do:
- Create a clear process for individuals to submit access, correction, deletion, and portability requests
- Publish this process on the website alongside the privacy officer's contact information
- Build internal workflows to fulfill these requests within the 30-day window set by section 32
- For data portability, ensure the organization can export an individual's personal information in a commonly used technological format, as specified in s. 27
- Handle the separate right to de-indexation and cessation of dissemination under section 28.1, which applies when the injury to reputation or privacy is clearly greater than the public interest in the information
The 30-day response window under section 32 is firm, and it requires knowing where personal information lives across the organization's systems. Companies without a data inventory will struggle here. Building that inventory is a prerequisite, and it often reveals personal information in systems that nobody remembered to include.
7. Apply Technical Security Safeguards (s. 10)
Section 10 of Law 25 requires organizations to take the security measures necessary to ensure the protection of personal information. Measures must be reasonable given the sensitivity of the information, the purposes for which it is to be used. The law does not prescribe specific controls, but the expectation is that safeguards are proportional to the sensitivity of the information.
What to do:
- Encryption at rest and in transit for databases and systems containing personal information
- Access controls based on least privilege, with periodic access reviews
- Logging and monitoring of access to personal information
- Regular vulnerability scanning and timely remediation
- Secure disposal of personal information when retention periods expire
- Network segmentation to limit exposure of systems containing personal information
Organizations with an existing security program aligned to SOC 2 or ISO 27001 will typically meet these requirements without significant additional work. The controls are familiar: access management (CC6.1-CC6.3), system operations (CC7.1-CC7.2), and change management (CC8.1). The difference is that Law 25 applies these expectations specifically to personal information, so the documentation needs to reflect that scope.
8. Manage Automated Decision-Making Transparency (s. 12.1)
Section 12.1 of Law 25 requires that when a decision about an individual is based exclusively on automated processing of personal information, the organization must inform the person at the time the decision is made. Upon request, the organization must explain the information used, the reasons for the decision, and provide an opportunity for the decision to be reviewed by a person.
What to do:
- Inventory any automated decision-making systems that process personal information
- Inform individuals when decisions about them are made by automated means
- Provide a mechanism for individuals to request human intervention or review
- Document the logic behind automated decision-making processes
This requirement is increasingly relevant as organizations adopt AI-driven tools. For companies already working toward ISO 42001 (AI management systems), the transparency requirements overlap considerably.
How Law 25 Maps to Existing Frameworks
For organizations already pursuing compliance with other frameworks, the overlap is significant. This is the core argument for building an effective security program as the foundation rather than chasing individual frameworks one at a time.
| Law 25 Requirement | Section | SOC 2 Overlap | ISO 27001 Overlap |
| Privacy officer designation | s. 3.1 | CC1.1 (control environment) | Clause 5.3 (roles and responsibilities) |
| Governance policy | s. 3.2 | CC5.2 (control activities) | A.5.1 (information security policies) |
| Breach notification | ss. 3.5-3.8 | CC7.3 (incident response) | A.5.24 (incident management planning) |
| Privacy impact assessments | s. 3.3 | Limited direct overlap | Clause 6.1.2 (risk assessment), ISO 27701 extension |
| Consent management | ss. 8, 8.1, 12 | Limited direct overlap | ISO 27701 extension |
| Data subject rights | s. 27 | Limited direct overlap | ISO 27701 extension |
| Security safeguards | s. 10 | CC6.1-CC6.8, CC7.1-CC7.2 | Annex A controls (access, crypto, ops security) |
| Automated decision transparency | s. 12.1 | Limited direct overlap | ISO 42001 alignment |
The security safeguards and incident response requirements are well covered by SOC 2 and ISO 27001. The privacy-specific requirements (PIAs, consent, data subject rights) sit in the gap between security and privacy governance. ISO 27701, the privacy extension to ISO 27001, closes most of that gap, but few organizations have adopted it yet.
Where Organizations Get Stuck on Law 25
Three areas of Law 25 compliance consistently cause the most difficulty.
Data inventory
Fulfilling data subject requests and conducting PIAs requires knowing where personal information lives. Many organizations underestimate how many systems contain personal information, from CRM and HR platforms to logging systems and analytics tools.
Cross-border transfers
Nearly every organization using cloud services is transferring data outside Quebec. The Law 25 PIA for cross-border transfers recurs: it needs to be reassessed when the hosting provider changes jurisdictions, when new services are adopted, or when the legal landscape in the receiving jurisdiction shifts.
Consent architecture
Retrofitting explicit consent into existing systems is harder than building it in from the start. The requirement extends beyond cookies to any collection point, including form submissions, account creation, email tracking, and analytics.
The Practical Path to Law 25 Compliance
For organizations starting Law 25 compliance from scratch, work through the requirements in this order.
- Designate the privacy officer and publish the appointment. This is immediate and removes a compliance gap that is visible to regulators.
- Build the data inventory. Every other requirement depends on knowing what personal information exists and where it lives.
- Update the incident response plan to include privacy breach notification and create the breach register.
- Draft the governance policy based on what the data inventory reveals about actual practices.
- Implement PIA triggers in the project intake process so new initiatives are assessed before launch.
- Address consent management for existing collection points, starting with the highest-risk areas such as customer-facing systems and marketing tools.
- Establish data subject request workflows and test them end-to-end before they are needed.
Key insight
The Reuse Dividend
The advantage of approaching Law 25 through an existing security program is that the technical safeguards, the most resource-intensive piece, are already in place. The remaining work is governance, process, and documentation.
The compliance snowball effect applies here. Each framework an organization adopts reduces the marginal cost of the next one because the foundational controls, the security program itself, are already running.
Build Law 25 Into Your Security Program
Map Law 25's requirements to your existing controls. An effective security program covers more of the law than most teams realize.
Frequently Asked Questions
Does Law 25 apply to companies outside Quebec?
Yes. Law 25 applies to any private-sector organization that collects personal information from Quebec residents, regardless of where the organization is headquartered. A SaaS company in Ontario with a handful of Quebec-based users is in scope. The jurisdictional reach is broader than PIPEDA.
How is Law 25 different from PIPEDA?
Law 25 takes a stricter position on consent, imposes direct penalty authority, and adds privacy-specific requirements such as mandatory Privacy Impact Assessments and automated decision-making transparency. PIPEDA is enforced by the Office of the Privacy Commissioner through recommendations, while Law 25 gives Quebec's CAI the power to issue administrative monetary penalties up to $10 million or 2% of worldwide turnover.
Do SOC 2 or ISO 27001 certifications satisfy Law 25?
Not on their own. The security safeguards required under section 10 of Law 25 map cleanly to SOC 2 Common Criteria and ISO 27001 Annex A controls, so a company with either certification already covers most of the technical requirements. The gaps are in privacy governance: privacy officer designation, Privacy Impact Assessments, consent management, data subject rights, and automated decision-making transparency. ISO 27701, the privacy extension to ISO 27001, closes most of that gap.
When does a company need to conduct a Privacy Impact Assessment?
Under section 3.3, a PIA is mandatory for any project to acquire, develop, or overhaul an information system or electronic service delivery system that involves the collection, use, communication, retention, or destruction of personal information. The privacy officer must be consulted from the outset of the project. Assessments must also be conducted for cross-border data transfers to evaluate whether the receiving jurisdiction offers protection equivalent to Quebec's standards.
What counts as a confidentiality incident under Law 25?
Under section 3.6, a confidentiality incident is any unauthorized access, use, or communication of personal information, or any loss or breach of information protection. Organizations must notify the CAI and affected individuals when an incident presents a risk of serious injury (section 3.5). Section 3.8 requires a register of all confidentiality incidents, even those that do not trigger notification.
What is the penalty for non-compliance with Law 25?
The CAI can impose administrative monetary penalties up to $10 million or 2% of worldwide turnover (s. 90.1) and penal fines up to $25 million or 4% with a corporate minimum of $15,000 (s. 91). Individuals can also pursue private action for punitive damages of not less than $1,000 per violation (s. 93.1).
Ready to Start Your Compliance Journey?
Get a clear, actionable roadmap with our readiness assessment.
Contact Us
Free Report: The CPCSC Compliance Playbook
Join the waitlist for a free copy when it's released.
About the Author
Former security architect for Bank of Canada and Payments Canada. 20+ years building compliance programs for critical infrastructure.