Back to Blog
Compliance
4 min read

Quebec Law 25: The Requirements Most Organisations Miss

Privacy by default, a named privacy officer, mandatory assessments before crossing the border, and a private right of action. Law 25 is the strictest regime in Canada.

GuardsArm Team

Security Experts

September 25, 2026

Quebec Law 25 compliance requirements

Law 25 moved Quebec from the most ordinary private-sector privacy regime in Canada to the most demanding. It borrows heavily from GDPR — assessments, portability, privacy by default, serious financial penalties — and adds a private right of action that makes non-compliance litigable without a regulator ever getting involved.

If you have customers or employees in Quebec, Law 25 is likely the strictest standard you are subject to, which makes it the sensible one to build to.

Strictest in Canada
GDPR-style duties plus a private right of action
Outside Quebec includes Canada
A server in Ontario is a cross-border transfer
Privacy by default is engineering
Highest setting, with no user action

The obligations that carry real work

A privacy officer, named and published. By default the most senior person in the organisation holds the role, and it stays with them unless delegated in writing. The title and contact details must be published on your website. This is a five-minute fix that a surprising number of organisations still fail.

A confidentiality incident register. Every confidentiality incident is recorded — not only the ones meeting the notification threshold. Where an incident presents a risk of serious injury, you notify the Commission d'accès à l'information and the affected individuals.

Privacy impact assessments. Required before acquiring, developing or overhauling an information system involving personal information, and again before communicating personal information outside Quebec.

When a Law 25 assessment is requiredBefore acquiring, developing or overhauling a system involving personal information, and again before communicating personal information outside Quebec.New systemor major overhaulAssessprivacy impactMitigatereduce to proportionateTransfer checkif leaving QuebecProceedwith the record kept
Two separate triggers, and the second one catches ordinary cloud hosting.

Privacy by default. Where a product or service is offered to the public with privacy settings, the highest privacy setting must be the default, without the user intervening. This is a product engineering requirement, not a policy one, and it is the requirement most often discovered late because it lands on a team that never reads the privacy programme.


Crossing the border

Before communicating personal information outside Quebec, you must assess whether it will receive adequate protection — considering the sensitivity of the information, the purpose, the protections in place and the legal framework of the destination.

Question the assessment must answerTypical gap
Where does the data physically go?Sub-processors and backup regions unmapped
What law governs the recipient?Never examined
What contractual protections exist?A generic DPA with no Quebec-specific terms
Is the transfer necessary at all?Not asked

This applies to a cloud provider in Ontario as much as one in Ohio — "outside Quebec" includes the rest of Canada. Organisations reading Law 25 as a cross-border-to-the-US rule miss most of their own exposure.


Individual rights that need engineering

Law 25 individual rights, by engineering effortPortability, de-indexing and automated decision explanation require product work. Access, correction and consent are largely process.PortabilityStructured, commonly used format — a data model problemDe-indexing and deletionCessation of dissemination on requestAutomated decision explanationInformation used, reasons, principal factors, human reviewAccess and correctionFamiliar from other regimesConsent for sensitive informationExpress, and separate from general terms
The top three are features. They do not get delivered by a policy update.

Portability in particular is not satisfiable by an export button that produces a PDF. It requires computerised personal information in a structured, commonly used technological format. That is a data model question, and the teams that handle it well treated it as a feature with a ticket rather than a policy paragraph.

Automated decision-making carries an obligation to inform the individual and, on request, to explain the personal information used, the reasons and the principal factors — and to allow submissions to a human who can review.


Why the penalties change the conversation

Law 25 carries administrative monetary penalties and penal fines at a scale well beyond anything else in Canadian private-sector privacy law, calculated against worldwide turnover at the upper end. Separately, the private right of action provides for damages where a breach of the Act causes injury, with a minimum award available in cases of intentional or gross fault.

That combination — a regulator with financial powers and a plaintiff's bar with a statutory hook — is why Law 25 tends to get budget when other privacy work does not.


Where to start

Three things you can confirm today: is your privacy officer named and published; does a confidentiality incident register exist; and has anyone assessed a transfer of personal information outside Quebec. Those three answers predict the state of the rest of the programme.

If all three are missing, a realistic first ninety days looks like this:

WeeksWork
1-2Name and publish the privacy officer; open the incident register
3-6Inventory personal information and map every flow leaving Quebec
5-8Assess the highest-volume transfer; put Quebec-specific terms in that contract
7-10Review default privacy settings in public-facing products
9-12Build the assessment template into project intake so new systems are gated

That sequence front-loads the items that are cheap and visible, and leaves the engineering work — defaults, portability, automated decision explanations — to be scheduled properly rather than rushed.

GuardsArm runs Law 25 gap assessments and builds the assessment and incident machinery. See Quebec Law 25 compliance or book a scoping call.

Written by GuardsArm Team

Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.

Take the next step on “Quebec Law 25: The Requirements Most Organisations Miss”

Talk to the GuardsArm team about how these services apply to your environment.