Quebec Law 25

Act respecting the protection of personal information in the private sector, as amended by Law 25 (formerly Bill 64)

Key Facts

Effective Date
September 22, 2023
Enacted
September 22, 2021
Enforcing Authority
Commission d'acces a l'information du Quebec (CAI)
Consent Model
Opt-in
Fulfillment Time
30 days
Applies To
Any organization collecting personal information of Quebec residents in commercial activities, regardless of location (extraterritorial scope)

What Quebec Law 25 is

Law 25 is the common name for the law that rebuilt privacy rules in Quebec. It amended the province's private-sector privacy act, the Act respecting the protection of personal information in the private sector (chapter P-39.1), and was adopted on 22 September 2021. Its obligations arrived in three annual waves: the first on 22 September 2022, the bulk of them on 22 September 2023, and the data portability right on 22 September 2024. The Commission d'acces a l'information du Quebec, known as the CAI, enforces it.

Who Law 25 applies to

Law 25 applies to any organization carrying on an enterprise that collects, holds, uses or shares personal information about people in Quebec. Where your head office sits does not decide this. If you sell to Quebec residents or track their behaviour on your website, you are in scope whether or not you have a Quebec entity, Quebec staff or Quebec servers.

What Law 25 requires for cookies and tracking

Two sections carry most of the weight for websites.

Section 14 sets the consent standard. Consent must be "clear, free and informed" and given for specific purposes, and it must be requested for each purpose separately, in clear and simple language. Consent that misses that standard "is without effect", which means the tracking it was meant to authorize has no legal footing at all.

Section 8.1 covers tracking technology directly. If you collect personal information using technology with functions that can identify, locate or profile a person, you have to tell people you are using it and tell them how to activate those functions. Analytics, advertising pixels, session recording and device fingerprinting all fit that description.

Read together, a single "by continuing to browse, you accept cookies" line does not meet the standard. Purposes have to be separable, the request has to be specific, and profiling has to be something a visitor switches on rather than something already running by the time they see the banner.

Does Law 25 require cookies to be off by default?

Not through the by-default rule itself. Section 9.1 requires technological products and services that have privacy settings to ship those settings at the highest level of confidentiality by default, then adds one sentence: "The first paragraph does not apply to privacy settings for browser cookies." Non-essential cookies still need consent under section 14, so in practice they still wait.

That carve-out gets quoted as evidence that cookies escape Law 25. They do not. What it removes is the automatic by-default rule as applied to browser cookie preferences, which the browser controls and you do not. It leaves the consent requirement in section 14 and the disclosure requirement in section 8.1 fully intact. Advertising, analytics and profiling cookies still need consent before they run, which is why Quebec is treated as an opt-in market.

What a Law 25 cookie banner has to do

  • Ask before anything non-essential loads, so advertising and analytics tags wait until the visitor has chosen.
  • Separate consent by purpose. One combined switch for everything does not meet section 14's per-purpose requirement.
  • Make refusing as easy as accepting. Consent has to be free, and a prominent accept button beside a buried refusal is hard to defend as free.
  • Name what the tracking does, which is what section 8.1 asks for, along with how to activate those functions.
  • Publish a confidentiality policy on the site in clear, simple language, as section 8.2 requires.
  • Publish the title and contact details of the person in charge of protecting personal information, which section 3.1 requires and which defaults to whoever holds the highest authority in the business unless it is delegated in writing.
  • Let visitors change their decision later, and keep a dated record of what each one chose.

How ConsentStack handles Law 25

ConsentStack resolves the visitor's province, not just the country, so someone browsing from Quebec gets the opt-in model Law 25 expects while the rest of your traffic gets whatever its own jurisdiction requires. Non-essential tags are held until that visitor decides, every purpose gets its own control, and each decision is stored with a timestamp so you can show what was agreed and when.

If you want to know where you stand today, the free compliance scanner loads your site and reports which cookies and trackers fire before anyone consents. Quebec also sits under Canada's federal PIPEDA, and the cookie consent requirements guide covers how one banner can satisfy several jurisdictions at once.

Law 25 effective dates

Law 25 was adopted on September 22, 2021 and phased in over three anniversaries. Every phase is now in force, so a site tracking visitors in Quebec today is measured against the full Act.

  1. · Adopted

    Bill 64 receives assent and becomes chapter 25 of the 2021 statutes, which is where the name Law 25 comes from.

  2. · First obligations

    Every business needs a person in charge of protecting personal information, with their title and contact details published (s. 3.1). Confidentiality incidents must be reported to the CAI and to the people affected when there is a risk of serious injury, and logged in an incident register (ss. 3.5 and 3.8).

  3. · The consent and tracking rules

    The rules that shape a cookie banner arrive: consent must be clear, free, informed and requested per purpose (s. 14), technology that identifies, locates or profiles a visitor must be disclosed along with how to activate it (s. 8.1), a confidentiality policy must be published (s. 8.2), and privacy settings default to the highest level, with browser cookies carved out (s. 9.1). Privacy impact assessments (s. 3.3), the rule for minors under 14 (s. 4.1), and the penalty regime (ss. 90.1 to 93.1) start on the same day.

  4. · Data portability

    People can ask for the computerized personal information collected from them in a structured, commonly used format (s. 27). This was the last phase.

Law 25 vs GDPR vs PIPEDA

Most teams reaching Quebec already run a GDPR banner, or a Canada-wide setup built for PIPEDA. This table shows where Law 25 lines up with each and where it does not. Section numbers refer to the private-sector Act as amended by Law 25.

RequirementQuebec Law 25GDPR (EU)PIPEDA (Canada, federal)
Consent for non-essential cookiesOpt-in. Consent must be clear, free, informed and requested separately for each purpose (s. 14), and tracking technology must be disclosed with the means to activate it (s. 8.1).Opt-in. The ePrivacy Directive (art. 5(3)) requires consent to store or read non-essential cookies, measured against the GDPR consent standard (arts. 4(11) and 7).Meaningful consent (Principle 4.3). OPC guidance accepts opt-out consent for non-sensitive online advertising with clear notice and an easy way out; sensitive information needs express consent.
Privacy by defaultYes, for public technological products with privacy settings (s. 9.1), but the section states it does not apply to privacy settings for browser cookies.Yes. Data protection by design and by default (art. 25).No equivalent provision.
Privacy officerMandatory. The person with the highest authority holds the role unless delegated in writing; the title and contact details must be published on the website (s. 3.1).A data protection officer is required only for public bodies, large-scale monitoring or large-scale special-category processing (art. 37).An individual accountable for compliance, whose identity is made known on request (Principle 4.1).
Breach notificationPromptly to the CAI and to the people affected when the incident presents a risk of serious injury; keep a register of incidents (ss. 3.5 and 3.8). No fixed hour count.To the supervisory authority within 72 hours where the breach is likely to pose a risk (art. 33); to individuals without undue delay where the risk is high (art. 34).To the OPC and to individuals as soon as feasible where there is a real risk of significant harm; keep a record of every breach (ss. 10.1 and 10.3).
Impact assessmentsRequired for any project to acquire, develop or overhaul a system that handles personal information (s. 3.3), and before communicating information outside Quebec (s. 17).Required for processing likely to result in a high risk to individuals (art. 35).Not required by the Act.
Access request deadline30 days from receipt; silence counts as a refusal (s. 32).One month, extendable by two further months for complex requests (art. 12(3)).30 days, extendable by up to 30 more in limited cases (s. 8(3) and (4)).
Portability and erasurePortability of computerized information collected from the person, in force since September 22, 2024 (s. 27); a right to have information de-indexed (s. 28.1).Portability (art. 20) and erasure (art. 17).Neither. PIPEDA grants access and correction only (Principle 4.9).
MinorsConsent for a child under 14 comes from the parent or tutor (ss. 4.1 and 14).Under 16 for online services, and member states may lower that to 13 (art. 8).No age in the Act. OPC guidance treats consent for children under 13 as needing a parent or guardian.
Reach beyond the borderFollows the Quebec resident's information, not the location of the business.Applies to businesses outside the EU that offer goods or services to, or monitor, people in the EU (art. 3(2)).Applies to commercial activity with a real and substantial connection to Canada, a test set by the Federal Court.
Administrative finesUp to CAD $10 million or 2% of worldwide turnover, whichever is greater (s. 90.12), imposed by the CAI.Up to EUR 20 million or 4% of worldwide turnover, whichever is higher (art. 83(5)), imposed by national authorities.None. The OPC issues findings and recommendations; orders come from the Federal Court.
Court finesCAD $15,000 to $25 million, or 4% of worldwide turnover if greater, doubled for a repeat offense (ss. 91 and 92.1).Member states set their own penalties for infringements not covered by art. 83 (art. 84).Up to CAD $100,000 for specific offenses such as failing to report a breach or obstructing the OPC (s. 28).
What individuals can claimPunitive damages of at least CAD $1,000 where an intentional or grossly negligent breach causes injury (s. 93.1).Compensation for material or non-material damage (art. 82).Damages awarded by the Federal Court after a complaint (s. 16).

Figures read from the consolidated statutes on September 7, 2026. Currency stays in the law's own units: CAD for Law 25 and PIPEDA, EUR for the GDPR.

Penalties

Law 25 carries two separate money penalties. The CAI can impose an administrative monetary penalty of up to CAD $10 million or 2% of worldwide turnover for the preceding fiscal year, whichever is greater (s. 90.12). Prosecuted offences carry fines of CAD $15,000 to $25 million, or 4% of worldwide turnover if that is greater (s. 91), and those fines double for a repeat offence (s. 92.1). Separately, a court must award at least CAD $1,000 in punitive damages where an intentional or grossly negligent breach of the Act causes injury (s. 93.1).

Maximum Fine
CA$25,000,000 aggregate
Revenue-based
4% of annual revenue

Key Requirements

  • Consent must be clear, free and informed, and requested separately for each purpose in clear and simple language (s. 14)
  • Disclose any technology that can identify, locate or profile a visitor, and how to activate those functions (s. 8.1)
  • Privacy settings on public technological products default to the highest confidentiality, with browser cookie settings carved out (s. 9.1)
  • Publish a confidentiality policy on the website in clear, simple language (s. 8.2)
  • The person with the highest authority in the business is the privacy officer by default and may delegate in writing; the title and contact details must be published (s. 3.1)
  • Report confidentiality incidents to the CAI and affected individuals promptly where there is a risk of serious injury, and keep an incident register (s. 3.5). There is no fixed 72-hour deadline
  • Conduct a privacy impact assessment before acquiring, developing or overhauling a system that handles personal information (s. 3.3)
  • Honour access, correction, de-indexing and data portability requests within 30 days

Notable Provisions

  • Section 9.1 sets privacy by default, then explicitly exempts privacy settings for browser cookies
  • Consent given outside the Act's standard is 'without effect', so the collection it authorized has no legal basis (s. 14)
  • Courts must award at least CAD $1,000 in punitive damages for intentional or grossly negligent breaches (s. 93.1)
  • Fines double on a repeat offence (s. 92.1)
  • Extraterritorial: it follows the Quebec resident, not the location of the business
  • Consent for a minor under 14 is given by the parent or tutor (s. 4.1)

Other PIPEDA Related Regulations

Other North America Regulations

CPRACalifornia, United States
The CPRA is the most comprehensive US state privacy law with a dedicated enforcement agency (CPPA). Cross-context behavioral advertising via cookies constitutes sharing personal information, triggering opt-out obligations. GPC signals must be honored as valid opt-out requests.
CCPACalifornia, United States
The CCPA was the first comprehensive consumer privacy law in the United States, giving California residents the right to know what personal information businesses collect and to opt out of its sale. It established the opt-out consent model that most subsequent US state privacy laws adopted.
CIPACalifornia, United States
CIPA is a 1967 California chapter covering wiretapping, eavesdropping, and other privacy invasions, not a website-specific law. Since 2022, courts have applied two of its sections to website chat, analytics, and ad tools, and any visitor can sue directly for at least $5,000 per violation, no revenue threshold.
PIPEDACanada
Canada's federal private-sector privacy law based on 10 fair information principles. Requires express consent for sensitive data and implied consent for less sensitive data. OPC guidance addresses cookies and online behavioral advertising. The CPPA replacement bill died January 2025; a new bill is expected.
CPAColorado, United States
Colorado's CPA features the highest per-violation penalties among US state privacy laws at $20,000. Must honor GPC signals since July 2024. Participated in a joint GPC enforcement sweep with California and Connecticut in September 2025. The cure period was eliminated in January 2025.
TDPSATexas, United States
The TDPSA is the broadest US state privacy law: no revenue thresholds and no minimum consumer data volume thresholds. Applies to any non-small-business processing personal data of Texas residents. Must honor GPC signals since January 2025. This breadth means far more businesses are captured than under any other state law.

Frequently Asked Questions

Stay compliant with Quebec Law 25

ConsentStack helps you implement Opt-in consent for Quebec, Canada automatically.