
Quebec Law 25: The Requirements Most Organisations Miss
Privacy by default, a named privacy officer, mandatory assessments before crossing the border, and a private right of action. Law 25 is the strictest regime in Canada.
GuardsArm Team
Security Experts

Law 25 moved Quebec from the most ordinary private-sector privacy regime in Canada to the most demanding. It borrows heavily from GDPR — assessments, portability, privacy by default, serious financial penalties — and adds a private right of action that makes non-compliance litigable without a regulator ever getting involved.
If you have customers or employees in Quebec, Law 25 is likely the strictest standard you are subject to, which makes it the sensible one to build to.
The obligations that carry real work
A privacy officer, named and published. By default the most senior person in the organisation holds the role, and it stays with them unless delegated in writing. The title and contact details must be published on your website. This is a five-minute fix that a surprising number of organisations still fail.
A confidentiality incident register. Every confidentiality incident is recorded — not only the ones meeting the notification threshold. Where an incident presents a risk of serious injury, you notify the Commission d'accès à l'information and the affected individuals.
Privacy impact assessments. Required before acquiring, developing or overhauling an information system involving personal information, and again before communicating personal information outside Quebec.
Privacy by default. Where a product or service is offered to the public with privacy settings, the highest privacy setting must be the default, without the user intervening. This is a product engineering requirement, not a policy one, and it is the requirement most often discovered late because it lands on a team that never reads the privacy programme.
Crossing the border
Before communicating personal information outside Quebec, you must assess whether it will receive adequate protection — considering the sensitivity of the information, the purpose, the protections in place and the legal framework of the destination.
| Question the assessment must answer | Typical gap |
|---|---|
| Where does the data physically go? | Sub-processors and backup regions unmapped |
| What law governs the recipient? | Never examined |
| What contractual protections exist? | A generic DPA with no Quebec-specific terms |
| Is the transfer necessary at all? | Not asked |
This applies to a cloud provider in Ontario as much as one in Ohio — "outside Quebec" includes the rest of Canada. Organisations reading Law 25 as a cross-border-to-the-US rule miss most of their own exposure.
Individual rights that need engineering
Portability in particular is not satisfiable by an export button that produces a PDF. It requires computerised personal information in a structured, commonly used technological format. That is a data model question, and the teams that handle it well treated it as a feature with a ticket rather than a policy paragraph.
Automated decision-making carries an obligation to inform the individual and, on request, to explain the personal information used, the reasons and the principal factors — and to allow submissions to a human who can review.
Why the penalties change the conversation
Law 25 carries administrative monetary penalties and penal fines at a scale well beyond anything else in Canadian private-sector privacy law, calculated against worldwide turnover at the upper end. Separately, the private right of action provides for damages where a breach of the Act causes injury, with a minimum award available in cases of intentional or gross fault.
That combination — a regulator with financial powers and a plaintiff's bar with a statutory hook — is why Law 25 tends to get budget when other privacy work does not.
Where to start
Three things you can confirm today: is your privacy officer named and published; does a confidentiality incident register exist; and has anyone assessed a transfer of personal information outside Quebec. Those three answers predict the state of the rest of the programme.
If all three are missing, a realistic first ninety days looks like this:
| Weeks | Work |
|---|---|
| 1-2 | Name and publish the privacy officer; open the incident register |
| 3-6 | Inventory personal information and map every flow leaving Quebec |
| 5-8 | Assess the highest-volume transfer; put Quebec-specific terms in that contract |
| 7-10 | Review default privacy settings in public-facing products |
| 9-12 | Build the assessment template into project intake so new systems are gated |
That sequence front-loads the items that are cheap and visible, and leaves the engineering work — defaults, portability, automated decision explanations — to be scheduled properly rather than rushed.
GuardsArm runs Law 25 gap assessments and builds the assessment and incident machinery. See Quebec Law 25 compliance or book a scoping call.
Written by GuardsArm Team
Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.
Take the next step on “Quebec Law 25: The Requirements Most Organisations Miss”
Talk to the GuardsArm team about how these services apply to your environment.


