Understanding the law

What is Law 25? Quebec's Personal Information Protection Law

Often called Quebec's "personal data law", it applies to every business operating in Quebec. Definition, dates, obligations and penalties, explained in plain language.

Updated July 30, 2026

The essentials

Law 25 is the Quebec law that modernizes the protection of personal information. Its official title: Act to modernize legislative provisions as regards the protection of personal information (SQ 2021, chapter 25). It received assent on September 22, 2021.

Its obligations came into force in three waves, from September 2022 to September 2024. The law is now fully in force.

It applies to every business that collects, holds or uses personal information in Quebec, regardless of size. Non-compliance exposes businesses to penalties of up to 25 million dollars or 4% of worldwide turnover.

Where Law 25 comes from

First introduced as Bill 64, Law 25 was adopted by Quebec's National Assembly and received assent on September 22, 2021. It does not replace existing laws: it modernizes them in depth. For private businesses, it is the Act respecting the protection of personal information in the private sector (CQLR, c. P-39.1) (in French) that was transformed; for public bodies, the Act respecting access to documents held by public bodies.

The goal: give Quebecers real control over their personal information, in line with the international standards set notably by the European GDPR, and make the organizations that hold this information accountable.

Personal information is any information that can identify a person, directly or indirectly: name, contact details, date of birth, social insurance number, financial data, IP address, purchase history.

A note on vocabulary: Quebec legislation says "personal information", where Europe and everyday language say "personal data". Both expressions refer to the same thing. If you are looking for "Quebec's personal data protection law", Law 25 is exactly that.

The three waves of entry into force

1

22 septembre 2021

Sanction de la loi

Le projet de loi 64 devient la Loi 25 (LQ 2021, c. 25).

2

22 septembre 2022

Première vague

RPRP obligatoire, registre des incidents, encadrement de la biométrie.

3

22 septembre 2023

Deuxième vague

Politique de confidentialité, gouvernance, consentement renforcé, ÉFVP.

4

22 septembre 2024

Troisième vague

Droit à la portabilité des données. La loi est entièrement en vigueur.

DateObligations that came into force
September 22, 2022Designate a privacy officer responsible for the protection of personal information, keep a confidentiality incident log and report serious incidents to the CAI, regulate biometrics
September 22, 2023The heart of the law: privacy policy published on your website, governance policies, stricter consent rules, privacy impact assessments (PIA), destruction or anonymization of data
September 22, 2024Right to portability: on request, provide a person with their computerized personal information in a structured, commonly used technological format

The main obligations for businesses

Our free guide covers each of these obligations in detail, with concrete examples for small businesses:

Penalties for non-compliance

The Commission d'accès à l'information (CAI) oversees the application of the law. It can conduct inspections, order corrective measures and impose penalties (in French).

Type of penaltyWho can be targetedMaximum amount
Administrative monetary penalty, imposed by the CAIBusinesses$10 million or 2% of worldwide turnover, whichever is greater
Penal fineBusinessesFrom $15,000 to $25 million or 4% of worldwide turnover; doubled for repeat offences
Penal fineIndividualsFrom $5,000 to $100,000

Law 25 and the GDPR: close, but not identical

Law 25 is sometimes nicknamed the "Quebec GDPR", and the family resemblance is real: stricter consent, transparency, rights of access and rectification, incident notification, penalties proportional to worldwide turnover. A business already compliant with the European regulation has a head start.

The differences matter, though. Law 25 requires every business, even a self-employed worker, to designate a privacy officer responsible for the protection of personal information, where the GDPR only requires it in certain cases. It also specifically regulates biometrics, requires a privacy impact assessment (PIA) for certain projects, and entrusts enforcement to the CAI rather than a network of national authorities.

Frequently asked questions

What does "Law 25" mean?

It is the chapter number of the law in Quebec's annual statute book: Statutes of Quebec 2021, chapter 25. Before it was adopted, it was known as Bill 64. Its official title is the Act to modernize legislative provisions as regards the protection of personal information.

Are "Law 25" and "Quebec's personal data protection law" the same thing?

Yes. Law 25 is the Quebec law that protects what everyday language and Europe call "personal data". The official term used in Quebec legislation is "personal information", but both expressions refer to the same thing: any information that can identify a person.

Is Law 25 in force?

Yes, fully. Its provisions came into force in three waves: September 22, 2022 (privacy officer, incidents, biometrics), September 22, 2023 (most obligations, including the privacy policy and consent) and September 22, 2024 (right to data portability).

Who must comply with Law 25?

Every business that collects, holds, uses or communicates personal information in Quebec, regardless of its size or sector: self-employed workers, small businesses, large companies. The law also modernizes the rules that apply to Quebec public bodies.

What are the fines?

The CAI can impose administrative monetary penalties of up to 10 million dollars or 2% of worldwide turnover. Penal offences expose businesses to fines of $15,000 to 25 million dollars or 4% of worldwide turnover, doubled for repeat offences. For individuals: $5,000 to $100,000.

Is Law 25 the Quebec GDPR?

The comparison comes up often and is useful: Law 25 draws on the European regulation and pursues the same goals (consent, transparency, individual rights, incident notification). It has its own rules, however, including the obligation for every business, with no exception for size, to designate a privacy officer responsible for the protection of personal information.

Where should I start to become compliant?

Two free tools: our 16-question self-assessment quiz, which identifies your gaps in 2 minutes, and our 9-step guide, which covers every obligation with concrete examples for small businesses.

Is your business compliant?

Assess your situation in 2 minutes with our free quiz, or follow the 9-step guide to put everything in place.