Key Facts
What Quebec Law 25 is
Law 25 is the common name for the law that rebuilt privacy rules in Quebec. It amended the province's private-sector privacy act, the Act respecting the protection of personal information in the private sector (chapter P-39.1), and was adopted on 22 September 2021. Its obligations arrived in three annual waves: the first on 22 September 2022, the bulk of them on 22 September 2023, and the data portability right on 22 September 2024. The Commission d'acces a l'information du Quebec, known as the CAI, enforces it.
Who Law 25 applies to
Law 25 applies to any organization carrying on an enterprise that collects, holds, uses or shares personal information about people in Quebec. Where your head office sits does not decide this. If you sell to Quebec residents or track their behaviour on your website, you are in scope whether or not you have a Quebec entity, Quebec staff or Quebec servers.
What Law 25 requires for cookies and tracking
Two sections carry most of the weight for websites.
Section 14 sets the consent standard. Consent must be "clear, free and informed" and given for specific purposes, and it must be requested for each purpose separately, in clear and simple language. Consent that misses that standard "is without effect", which means the tracking it was meant to authorize has no legal footing at all.
Section 8.1 covers tracking technology directly. If you collect personal information using technology with functions that can identify, locate or profile a person, you have to tell people you are using it and tell them how to activate those functions. Analytics, advertising pixels, session recording and device fingerprinting all fit that description.
Read together, a single "by continuing to browse, you accept cookies" line does not meet the standard. Purposes have to be separable, the request has to be specific, and profiling has to be something a visitor switches on rather than something already running by the time they see the banner.
Does Law 25 require cookies to be off by default?
Not through the by-default rule itself. Section 9.1 requires technological products and services that have privacy settings to ship those settings at the highest level of confidentiality by default, then adds one sentence: "The first paragraph does not apply to privacy settings for browser cookies." Non-essential cookies still need consent under section 14, so in practice they still wait.
That carve-out gets quoted as evidence that cookies escape Law 25. They do not. What it removes is the automatic by-default rule as applied to browser cookie preferences, which the browser controls and you do not. It leaves the consent requirement in section 14 and the disclosure requirement in section 8.1 fully intact. Advertising, analytics and profiling cookies still need consent before they run, which is why Quebec is treated as an opt-in market.
What a Law 25 cookie banner has to do
- Ask before anything non-essential loads, so advertising and analytics tags wait until the visitor has chosen.
- Separate consent by purpose. One combined switch for everything does not meet section 14's per-purpose requirement.
- Make refusing as easy as accepting. Consent has to be free, and a prominent accept button beside a buried refusal is hard to defend as free.
- Name what the tracking does, which is what section 8.1 asks for, along with how to activate those functions.
- Publish a confidentiality policy on the site in clear, simple language, as section 8.2 requires.
- Publish the title and contact details of the person in charge of protecting personal information, which section 3.1 requires and which defaults to whoever holds the highest authority in the business unless it is delegated in writing.
- Let visitors change their decision later, and keep a dated record of what each one chose.
How ConsentStack handles Law 25
ConsentStack resolves the visitor's province, not just the country, so someone browsing from Quebec gets the opt-in model Law 25 expects while the rest of your traffic gets whatever its own jurisdiction requires. Non-essential tags are held until that visitor decides, every purpose gets its own control, and each decision is stored with a timestamp so you can show what was agreed and when.
If you want to know where you stand today, the free compliance scanner loads your site and reports which cookies and trackers fire before anyone consents. Quebec also sits under Canada's federal PIPEDA, and the cookie consent requirements guide covers how one banner can satisfy several jurisdictions at once.
Law 25 effective dates
Law 25 was adopted on September 22, 2021 and phased in over three anniversaries. Every phase is now in force, so a site tracking visitors in Quebec today is measured against the full Act.
· Adopted
Bill 64 receives assent and becomes chapter 25 of the 2021 statutes, which is where the name Law 25 comes from.
· First obligations
Every business needs a person in charge of protecting personal information, with their title and contact details published (s. 3.1). Confidentiality incidents must be reported to the CAI and to the people affected when there is a risk of serious injury, and logged in an incident register (ss. 3.5 and 3.8).
· The consent and tracking rules
The rules that shape a cookie banner arrive: consent must be clear, free, informed and requested per purpose (s. 14), technology that identifies, locates or profiles a visitor must be disclosed along with how to activate it (s. 8.1), a confidentiality policy must be published (s. 8.2), and privacy settings default to the highest level, with browser cookies carved out (s. 9.1). Privacy impact assessments (s. 3.3), the rule for minors under 14 (s. 4.1), and the penalty regime (ss. 90.1 to 93.1) start on the same day.
· Data portability
People can ask for the computerized personal information collected from them in a structured, commonly used format (s. 27). This was the last phase.
Law 25 vs GDPR vs PIPEDA
Most teams reaching Quebec already run a GDPR banner, or a Canada-wide setup built for PIPEDA. This table shows where Law 25 lines up with each and where it does not. Section numbers refer to the private-sector Act as amended by Law 25.
| Requirement | Quebec Law 25 | GDPR (EU) | PIPEDA (Canada, federal) |
|---|---|---|---|
| Consent for non-essential cookies | Opt-in. Consent must be clear, free, informed and requested separately for each purpose (s. 14), and tracking technology must be disclosed with the means to activate it (s. 8.1). | Opt-in. The ePrivacy Directive (art. 5(3)) requires consent to store or read non-essential cookies, measured against the GDPR consent standard (arts. 4(11) and 7). | Meaningful consent (Principle 4.3). OPC guidance accepts opt-out consent for non-sensitive online advertising with clear notice and an easy way out; sensitive information needs express consent. |
| Privacy by default | Yes, for public technological products with privacy settings (s. 9.1), but the section states it does not apply to privacy settings for browser cookies. | Yes. Data protection by design and by default (art. 25). | No equivalent provision. |
| Privacy officer | Mandatory. The person with the highest authority holds the role unless delegated in writing; the title and contact details must be published on the website (s. 3.1). | A data protection officer is required only for public bodies, large-scale monitoring or large-scale special-category processing (art. 37). | An individual accountable for compliance, whose identity is made known on request (Principle 4.1). |
| Breach notification | Promptly to the CAI and to the people affected when the incident presents a risk of serious injury; keep a register of incidents (ss. 3.5 and 3.8). No fixed hour count. | To the supervisory authority within 72 hours where the breach is likely to pose a risk (art. 33); to individuals without undue delay where the risk is high (art. 34). | To the OPC and to individuals as soon as feasible where there is a real risk of significant harm; keep a record of every breach (ss. 10.1 and 10.3). |
| Impact assessments | Required for any project to acquire, develop or overhaul a system that handles personal information (s. 3.3), and before communicating information outside Quebec (s. 17). | Required for processing likely to result in a high risk to individuals (art. 35). | Not required by the Act. |
| Access request deadline | 30 days from receipt; silence counts as a refusal (s. 32). | One month, extendable by two further months for complex requests (art. 12(3)). | 30 days, extendable by up to 30 more in limited cases (s. 8(3) and (4)). |
| Portability and erasure | Portability of computerized information collected from the person, in force since September 22, 2024 (s. 27); a right to have information de-indexed (s. 28.1). | Portability (art. 20) and erasure (art. 17). | Neither. PIPEDA grants access and correction only (Principle 4.9). |
| Minors | Consent for a child under 14 comes from the parent or tutor (ss. 4.1 and 14). | Under 16 for online services, and member states may lower that to 13 (art. 8). | No age in the Act. OPC guidance treats consent for children under 13 as needing a parent or guardian. |
| Reach beyond the border | Follows the Quebec resident's information, not the location of the business. | Applies to businesses outside the EU that offer goods or services to, or monitor, people in the EU (art. 3(2)). | Applies to commercial activity with a real and substantial connection to Canada, a test set by the Federal Court. |
| Administrative fines | Up to CAD $10 million or 2% of worldwide turnover, whichever is greater (s. 90.12), imposed by the CAI. | Up to EUR 20 million or 4% of worldwide turnover, whichever is higher (art. 83(5)), imposed by national authorities. | None. The OPC issues findings and recommendations; orders come from the Federal Court. |
| Court fines | CAD $15,000 to $25 million, or 4% of worldwide turnover if greater, doubled for a repeat offense (ss. 91 and 92.1). | Member states set their own penalties for infringements not covered by art. 83 (art. 84). | Up to CAD $100,000 for specific offenses such as failing to report a breach or obstructing the OPC (s. 28). |
| What individuals can claim | Punitive damages of at least CAD $1,000 where an intentional or grossly negligent breach causes injury (s. 93.1). | Compensation for material or non-material damage (art. 82). | Damages awarded by the Federal Court after a complaint (s. 16). |
Figures read from the consolidated statutes on September 7, 2026. Currency stays in the law's own units: CAD for Law 25 and PIPEDA, EUR for the GDPR.
Penalties
Law 25 carries two separate money penalties. The CAI can impose an administrative monetary penalty of up to CAD $10 million or 2% of worldwide turnover for the preceding fiscal year, whichever is greater (s. 90.12). Prosecuted offences carry fines of CAD $15,000 to $25 million, or 4% of worldwide turnover if that is greater (s. 91), and those fines double for a repeat offence (s. 92.1). Separately, a court must award at least CAD $1,000 in punitive damages where an intentional or grossly negligent breach of the Act causes injury (s. 93.1).
Key Requirements
- Consent must be clear, free and informed, and requested separately for each purpose in clear and simple language (s. 14)
- Disclose any technology that can identify, locate or profile a visitor, and how to activate those functions (s. 8.1)
- Privacy settings on public technological products default to the highest confidentiality, with browser cookie settings carved out (s. 9.1)
- Publish a confidentiality policy on the website in clear, simple language (s. 8.2)
- The person with the highest authority in the business is the privacy officer by default and may delegate in writing; the title and contact details must be published (s. 3.1)
- Report confidentiality incidents to the CAI and affected individuals promptly where there is a risk of serious injury, and keep an incident register (s. 3.5). There is no fixed 72-hour deadline
- Conduct a privacy impact assessment before acquiring, developing or overhauling a system that handles personal information (s. 3.3)
- Honour access, correction, de-indexing and data portability requests within 30 days
Notable Provisions
- Section 9.1 sets privacy by default, then explicitly exempts privacy settings for browser cookies
- Consent given outside the Act's standard is 'without effect', so the collection it authorized has no legal basis (s. 14)
- Courts must award at least CAD $1,000 in punitive damages for intentional or grossly negligent breaches (s. 93.1)
- Fines double on a repeat offence (s. 92.1)
- Extraterritorial: it follows the Quebec resident, not the location of the business
- Consent for a minor under 14 is given by the parent or tutor (s. 4.1)
Other PIPEDA Related Regulations
Other North America Regulations
Frequently Asked Questions
Stay compliant with Quebec Law 25
ConsentStack helps you implement Opt-in consent for Quebec, Canada automatically.