Quebec Law 25

Act respecting the protection of personal information in the private sector, as amended by Law 25 (formerly Bill 64)

Key Facts

Effective Date
September 22, 2023
Enacted
September 22, 2021
Enforcing Authority
Commission d'acces a l'information du Quebec (CAI)
Consent Model
Opt-in
Fulfillment Time
30 days
Applies To
Any organization collecting personal information of Quebec residents in commercial activities, regardless of location (extraterritorial scope)

What Quebec Law 25 is

Law 25 is the common name for the law that rebuilt privacy rules in Quebec. It amended the province's private-sector privacy act, the Act respecting the protection of personal information in the private sector (chapter P-39.1), and was adopted on 22 September 2021. Its obligations arrived in three annual waves: the first on 22 September 2022, the bulk of them on 22 September 2023, and the data portability right on 22 September 2024. The Commission d'acces a l'information du Quebec, known as the CAI, enforces it.

Who Law 25 applies to

Law 25 applies to any organization carrying on an enterprise that collects, holds, uses or shares personal information about people in Quebec. Where your head office sits does not decide this. If you sell to Quebec residents or track their behaviour on your website, you are in scope whether or not you have a Quebec entity, Quebec staff or Quebec servers.

What Law 25 requires for cookies and tracking

Two sections carry most of the weight for websites.

Section 14 sets the consent standard. Consent must be "clear, free and informed" and given for specific purposes, and it must be requested for each purpose separately, in clear and simple language. Consent that misses that standard "is without effect", which means the tracking it was meant to authorize has no legal footing at all.

Section 8.1 covers tracking technology directly. If you collect personal information using technology with functions that can identify, locate or profile a person, you have to tell people you are using it and tell them how to activate those functions. Analytics, advertising pixels, session recording and device fingerprinting all fit that description.

Read together, a single "by continuing to browse, you accept cookies" line does not meet the standard. Purposes have to be separable, the request has to be specific, and profiling has to be something a visitor switches on rather than something already running by the time they see the banner.

Does Law 25 require cookies to be off by default?

Not through the by-default rule itself. Section 9.1 requires technological products and services that have privacy settings to ship those settings at the highest level of confidentiality by default, then adds one sentence: "The first paragraph does not apply to privacy settings for browser cookies." Non-essential cookies still need consent under section 14, so in practice they still wait.

That carve-out gets quoted as evidence that cookies escape Law 25. They do not. What it removes is the automatic by-default rule as applied to browser cookie preferences, which the browser controls and you do not. It leaves the consent requirement in section 14 and the disclosure requirement in section 8.1 fully intact. Advertising, analytics and profiling cookies still need consent before they run, which is why Quebec is treated as an opt-in market.

What a Law 25 cookie banner has to do

  • Ask before anything non-essential loads, so advertising and analytics tags wait until the visitor has chosen.
  • Separate consent by purpose. One combined switch for everything does not meet section 14's per-purpose requirement.
  • Make refusing as easy as accepting. Consent has to be free, and a prominent accept button beside a buried refusal is hard to defend as free.
  • Name what the tracking does, which is what section 8.1 asks for, along with how to activate those functions.
  • Publish a confidentiality policy on the site in clear, simple language, as section 8.2 requires.
  • Publish the title and contact details of the person in charge of protecting personal information, which section 3.1 requires and which defaults to whoever holds the highest authority in the business unless it is delegated in writing.
  • Let visitors change their decision later, and keep a dated record of what each one chose.

How ConsentStack handles Law 25

ConsentStack resolves the visitor's province, not just the country, so someone browsing from Quebec gets the opt-in model Law 25 expects while the rest of your traffic gets whatever its own jurisdiction requires. Non-essential tags are held until that visitor decides, every purpose gets its own control, and each decision is stored with a timestamp so you can show what was agreed and when.

If you want to know where you stand today, the free compliance scanner loads your site and reports which cookies and trackers fire before anyone consents. Quebec also sits under Canada's federal PIPEDA, and the cookie consent requirements guide covers how one banner can satisfy several jurisdictions at once.

Penalties

Law 25 carries two separate money penalties. The CAI can impose an administrative monetary penalty of up to CAD $10 million or 2% of worldwide turnover for the preceding fiscal year, whichever is greater (s. 90.12). Prosecuted offences carry fines of CAD $15,000 to $25 million, or 4% of worldwide turnover if that is greater (s. 91), and those fines double for a repeat offence (s. 92.1). Separately, a court must award at least CAD $1,000 in punitive damages where an intentional or grossly negligent breach of the Act causes injury (s. 93.1).

Maximum Fine
CA$25,000,000 aggregate
Revenue-based
4% of annual revenue

Key Requirements

  • Consent must be clear, free and informed, and requested separately for each purpose in clear and simple language (s. 14)
  • Disclose any technology that can identify, locate or profile a visitor, and how to activate those functions (s. 8.1)
  • Privacy settings on public technological products default to the highest confidentiality, with browser cookie settings carved out (s. 9.1)
  • Publish a confidentiality policy on the website in clear, simple language (s. 8.2)
  • The person with the highest authority in the business is the privacy officer by default and may delegate in writing; the title and contact details must be published (s. 3.1)
  • Report confidentiality incidents to the CAI and affected individuals promptly where there is a risk of serious injury, and keep an incident register (s. 3.5). There is no fixed 72-hour deadline
  • Conduct a privacy impact assessment before acquiring, developing or overhauling a system that handles personal information (s. 3.3)
  • Honour access, correction, de-indexing and data portability requests within 30 days

Notable Provisions

  • Section 9.1 sets privacy by default, then explicitly exempts privacy settings for browser cookies
  • Consent given outside the Act's standard is 'without effect', so the collection it authorized has no legal basis (s. 14)
  • Courts must award at least CAD $1,000 in punitive damages for intentional or grossly negligent breaches (s. 93.1)
  • Fines double on a repeat offence (s. 92.1)
  • Extraterritorial: it follows the Quebec resident, not the location of the business
  • Consent for a minor under 14 is given by the parent or tutor (s. 4.1)

Other PIPEDA Related Regulations

Other North America Regulations

CPRACalifornia, United States
The CPRA is the most comprehensive US state privacy law with a dedicated enforcement agency (CPPA). Cross-context behavioral advertising via cookies constitutes sharing personal information, triggering opt-out obligations. GPC signals must be honored as valid opt-out requests.
CCPACalifornia, United States
The CCPA was the first comprehensive consumer privacy law in the United States, giving California residents the right to know what personal information businesses collect and to opt out of its sale. It established the opt-out consent model that most subsequent US state privacy laws adopted.
CIPACalifornia, United States
CIPA is a 1967 California chapter covering wiretapping, eavesdropping, and other privacy invasions, not a website-specific law. Since 2022, courts have applied two of its sections to website chat, analytics, and ad tools, and any visitor can sue directly for at least $5,000 per violation, no revenue threshold.
PIPEDACanada
Canada's federal private-sector privacy law based on 10 fair information principles. Requires express consent for sensitive data and implied consent for less sensitive data. OPC guidance addresses cookies and online behavioral advertising. The CPPA replacement bill died January 2025; a new bill is expected.
CPAColorado, United States
Colorado's CPA features the highest per-violation penalties among US state privacy laws at $20,000. Must honor GPC signals since July 2024. Participated in a joint GPC enforcement sweep with California and Connecticut in September 2025. The cure period was eliminated in January 2025.
TDPSATexas, United States
The TDPSA is the broadest US state privacy law: no revenue thresholds and no minimum consumer data volume thresholds. Applies to any non-small-business processing personal data of Texas residents. Must honor GPC signals since January 2025. This breadth means far more businesses are captured than under any other state law.

Frequently Asked Questions

Stay compliant with Quebec Law 25

ConsentStack helps you implement Opt-in consent for Quebec, Canada automatically.