Quebec's Law 25 has been fully in force since September 2024, and the penalties are no longer theoretical. Under the Act respecting the protection of personal information in the private sector (P-39.1), the CAI can now impose administrative monetary penalties up to $10 million or 2% of worldwide turnover (s. 90.1), penal fines up to $25 million or 4% with a corporate minimum of $15,000 (s. 91), and individuals can pursue private action for punitive damages of not less than $1,000 per violation (s. 93.1).
Many of the Law 25 compliance guides out there are written by privacy software vendors or law firms, and they explain what the law says. This post covers what security and IT teams need to implement, broken down into concrete actions with references to the legislation itself.
Watch out
A note on scope
Truvo Cyber is not a law firm, and this post is not legal advice. What follows is a security practitioner's interpretation of Law 25's requirements as they map to technical controls and operational processes. When working with clients on Law 25 compliance, we coordinate with qualified privacy counsel to validate the legal specifics for their situation.
Law 25 applies to any private-sector organization that collects personal information from Quebec residents, regardless of where the organization is headquartered. If a company has customers, employees, or users in Quebec, the law applies.
At a glance
The Jurisdictional Reach
A SaaS company in Ontario with a handful of Quebec-based users is in scope. A services firm with one employee working remotely from Montreal is in scope. The reach is broader than PIPEDA, and the penalties are significantly sharper. Where PIPEDA is enforced by the Office of the Privacy Commissioner through recommendations, Law 25 gives the CAI direct penalty authority.
For organizations already pursuing SOC 2 or ISO 27001, the overlap is substantial. Many of the technical safeguards Law 25 requires are controls that a well-built security program already implements. The gaps tend to be in privacy governance, consent management, and data lifecycle processes rather than in security infrastructure.
Under section 3.1 of Law 25, the person exercising the highest authority in the organization is responsible for ensuring compliance. This responsibility can be delegated in writing, in whole or in part, to any member of the organization's personnel. If delegated, the privacy officer's title and contact details must be published on the company website.
What to do:
For smaller organizations, this often falls to the same person managing the security program. That works, as long as the responsibilities are clearly documented.
Section 3.2 of Law 25 requires organizations to establish and implement governance policies and practices for the protection of personal information. The policy must cover retention and destruction of information, define roles and responsibilities of personnel, and include a complaint process. The policy must be proportionate to the nature and scope of the enterprise's activities, and a simplified version must be published in clear, simple language.
This is an internal governance document that describes how the organization handles personal information across its operations, separate from the privacy policy on the website.
What to do:
Organizations with an existing Information Security Management System (ISMS) under ISO 27001 or a SOC 2 program will find that much of this governance structure already exists. The gap is typically in privacy-specific language and data lifecycle documentation.
Section 3.5 of Law 25 requires organizations to notify the CAI and affected individuals when a confidentiality incident presents a risk of serious injury. Section 3.6 defines a confidentiality incident as any unauthorized access, use, or communication of personal information, or any loss or breach of information protection. Section 3.7 specifies that when assessing injury risk, organizations must consider the sensitivity of the information and the anticipated consequences of its use. Section 3.8 requires organizations to maintain a register of all confidentiality incidents.
What to do:
Teams already running SOC 2 CC7.1 (security event monitoring) and CC7.3 (incident response) have the infrastructure for this. The addition is the privacy-specific notification workflow and the formal breach register.
Section 3.3 of Law 25 makes Privacy Impact Assessments (PIAs) mandatory for any project to acquire, develop, or overhaul an information system or electronic service delivery system that involves the collection, use, communication, retention, or destruction of personal information. The privacy officer must be consulted from the outset of the project. Assessments must be proportionate to the sensitivity of the information, the purposes for which it is to be used, the quantity and distribution of the information, and the medium on which it is stored.
The CAI published its official PIA guide and template in September 2023, which provides a methodology for quantifying and addressing privacy risks. The template is not mandatory, but it provides a solid starting point.
What to do:
This is where organizations handling data in cloud environments need to pay attention. If the infrastructure is hosted outside Quebec, which is nearly always the case, the cross-border transfer rules apply. The PIA needs to assess whether the hosting jurisdiction's legal framework provides adequate protection.
Law 25 takes a stricter position on consent than PIPEDA. Under section 8, when collecting personal information, organizations must inform individuals of the collection purposes, means of collection, access and rectification rights, and consent withdrawal rights, all in clear and simple language. Section 8.1 adds that any technology enabling identification, location, or profiling requires prior notification and consent. Section 12 restricts use of information to the purposes for which it was collected, and requires express consent for any use of sensitive personal information.
Watch out
Quebec is an Outlier on Cookies
Quebec is the only Canadian jurisdiction requiring explicit opt-in consent for tracking technologies like cookies. A compliance posture copied from PIPEDA guidance will not satisfy Law 25's consent bar.
What to do:
In our experience, consent management is where security programs have the largest Law 25 gap. Security controls protect data after it is collected, but consent management governs whether it should be collected at all. For most organizations, this requires new tooling or workflows that sit outside the traditional security stack.
Section 27 of Law 25 grants individuals the right to access their personal information, have it corrected, and receive it in a structured, commonly used technological format (data portability). Under section 32, the person in charge must reply in writing to access or correction requests promptly and not later than 30 days after the date the request is received.
What to do:
The 30-day response window under section 32 is firm, and it requires knowing where personal information lives across the organization's systems. Companies without a data inventory will struggle here. Building that inventory is a prerequisite, and it often reveals personal information in systems that nobody remembered to include.
Section 10 of Law 25 requires organizations to take the security measures necessary to ensure the protection of personal information. Measures must be reasonable given the sensitivity of the information, the purposes for which it is to be used. The law does not prescribe specific controls, but the expectation is that safeguards are proportional to the sensitivity of the information.
What to do:
Organizations with an existing security program aligned to SOC 2 or ISO 27001 will typically meet these requirements without significant additional work. The controls are familiar: access management (CC6.1-CC6.3), system operations (CC7.1-CC7.2), and change management (CC8.1). The difference is that Law 25 applies these expectations specifically to personal information, so the documentation needs to reflect that scope.
Section 12.1 of Law 25 requires that when a decision about an individual is based exclusively on automated processing of personal information, the organization must inform the person at the time the decision is made. Upon request, the organization must explain the information used, the reasons for the decision, and provide an opportunity for the decision to be reviewed by a person.
What to do:
This requirement is increasingly relevant as organizations adopt AI-driven tools. For companies already working toward ISO 42001 (AI management systems), the transparency requirements overlap considerably.
For organizations already pursuing compliance with other frameworks, the overlap is significant. This is the core argument for building an effective security program as the foundation rather than chasing individual frameworks one at a time.
| Law 25 Requirement | Section | SOC 2 Overlap | ISO 27001 Overlap |
| Privacy officer designation | s. 3.1 | CC1.1 (control environment) | Clause 5.3 (roles and responsibilities) |
| Governance policy | s. 3.2 | CC5.2 (control activities) | A.5.1 (information security policies) |
| Breach notification | ss. 3.5-3.8 | CC7.3 (incident response) | A.5.24 (incident management planning) |
| Privacy impact assessments | s. 3.3 | Limited direct overlap | Clause 6.1.2 (risk assessment), ISO 27701 extension |
| Consent management | ss. 8, 8.1, 12 | Limited direct overlap | ISO 27701 extension |
| Data subject rights | s. 27 | Limited direct overlap | ISO 27701 extension |
| Security safeguards | s. 10 | CC6.1-CC6.8, CC7.1-CC7.2 | Annex A controls (access, crypto, ops security) |
| Automated decision transparency | s. 12.1 | Limited direct overlap | ISO 42001 alignment |
The security safeguards and incident response requirements are well covered by SOC 2 and ISO 27001. The privacy-specific requirements (PIAs, consent, data subject rights) sit in the gap between security and privacy governance. ISO 27701, the privacy extension to ISO 27001, closes most of that gap, but few organizations have adopted it yet.
Three areas of Law 25 compliance consistently cause the most difficulty.
Data inventory
Fulfilling data subject requests and conducting PIAs requires knowing where personal information lives. Many organizations underestimate how many systems contain personal information, from CRM and HR platforms to logging systems and analytics tools.
Cross-border transfers
Nearly every organization using cloud services is transferring data outside Quebec. The Law 25 PIA for cross-border transfers recurs: it needs to be reassessed when the hosting provider changes jurisdictions, when new services are adopted, or when the legal landscape in the receiving jurisdiction shifts.
Consent architecture
Retrofitting explicit consent into existing systems is harder than building it in from the start. The requirement extends beyond cookies to any collection point, including form submissions, account creation, email tracking, and analytics.
For organizations starting Law 25 compliance from scratch, work through the requirements in this order.
Key insight
The Reuse Dividend
The advantage of approaching Law 25 through an existing security program is that the technical safeguards, the most resource-intensive piece, are already in place. The remaining work is governance, process, and documentation.
The compliance snowball effect applies here. Each framework an organization adopts reduces the marginal cost of the next one because the foundational controls, the security program itself, are already running.
Map Law 25's requirements to your existing controls. An effective security program covers more of the law than most teams realize.
Yes. Law 25 applies to any private-sector organization that collects personal information from Quebec residents, regardless of where the organization is headquartered. A SaaS company in Ontario with a handful of Quebec-based users is in scope. The jurisdictional reach is broader than PIPEDA.
Law 25 takes a stricter position on consent, imposes direct penalty authority, and adds privacy-specific requirements such as mandatory Privacy Impact Assessments and automated decision-making transparency. PIPEDA is enforced by the Office of the Privacy Commissioner through recommendations, while Law 25 gives Quebec's CAI the power to issue administrative monetary penalties up to $10 million or 2% of worldwide turnover.
Not on their own. The security safeguards required under section 10 of Law 25 map cleanly to SOC 2 Common Criteria and ISO 27001 Annex A controls, so a company with either certification already covers most of the technical requirements. The gaps are in privacy governance: privacy officer designation, Privacy Impact Assessments, consent management, data subject rights, and automated decision-making transparency. ISO 27701, the privacy extension to ISO 27001, closes most of that gap.
Under section 3.3, a PIA is mandatory for any project to acquire, develop, or overhaul an information system or electronic service delivery system that involves the collection, use, communication, retention, or destruction of personal information. The privacy officer must be consulted from the outset of the project. Assessments must also be conducted for cross-border data transfers to evaluate whether the receiving jurisdiction offers protection equivalent to Quebec's standards.
Under section 3.6, a confidentiality incident is any unauthorized access, use, or communication of personal information, or any loss or breach of information protection. Organizations must notify the CAI and affected individuals when an incident presents a risk of serious injury (section 3.5). Section 3.8 requires a register of all confidentiality incidents, even those that do not trigger notification.
The CAI can impose administrative monetary penalties up to $10 million or 2% of worldwide turnover (s. 90.1) and penal fines up to $25 million or 4% with a corporate minimum of $15,000 (s. 91). Individuals can also pursue private action for punitive damages of not less than $1,000 per violation (s. 93.1).