Quebec Law 25Data PrivacyQuebec, CanadaAll Industries

Quebec Law 25 - An Act to Modernize Legislative Provisions Respecting Personal Information

Quebec comprehensive privacy law with strict requirements for logging personal information access. Fully effective September 2024 with significant penalties.

Get a Gap Assessment
The Mapping

What your auditor cites,
and what produces the evidence

The regulator's text is quoted below in italic, exactly as written. What follows each one is what the platform records, detects, or proves — not a claim about your compliance status, which no tool can confer.

Quebec Law 25Section 3.1A record of access

Access Logging

Organizations MUST log every single instance a staff member accesses or shares customer personal information.

A record of processing is only as good as the layer producing it. Real-time SQL auditing captures every statement against the data — the identity, the session, the client, the objects touched, the outcome — with no nightly batch window where activity goes unrecorded. Classification is what makes that a record of *regulated* data rather than a log of everything: it tells you which tables are in scope, so the register describes the processing you actually have to declare. Policy templates then produce it in the shape the framework asks for, instead of leaving you to assemble it from raw logs the week before an inspection.

Quebec Law 25Section 3.3Assessment backed by evidence

Privacy Impact Assessment

REQUIRES Privacy Impact Assessment for any project involving personal information.

An assessment is only defensible if the findings in it are observed rather than asserted. Discovery supplies what regulated data exists and where, scanning supplies the configuration and exposure posture, and the audit trail supplies who has actually been reaching it — so the assessment describes the estate as measured. Our advisory engagements then map each finding to the specific mandate it touches and sequence the remediation.

Quebec Law 25Section 3.5Detecting it in time to notify

Breach Notification

Confidentiality incidents MUST be reported to the CAI and affected individuals.

Notification clocks start when you become aware, so detection latency is the whole exposure. Behavioural baselines score each deviation as it happens and flag it in under a second, rather than surfacing it in a weekly review. Severity is decided at the collector and routed immediately, so the window between the access and someone knowing about it is measured in seconds — and the audit trail behind it already holds what was reached, by whom, and when.

Quebec Law 25Section 8A record of access

Anonymization

Organizations MUST implement and audit anonymization techniques for personal information.

A record of processing is only as good as the layer producing it. Real-time SQL auditing captures every statement against the data — the identity, the session, the client, the objects touched, the outcome — with no nightly batch window where activity goes unrecorded. Classification is what makes that a record of *regulated* data rather than a log of everything: it tells you which tables are in scope, so the register describes the processing you actually have to declare. Policy templates then produce it in the shape the framework asks for, instead of leaving you to assemble it from raw logs the week before an inspection.

What Quebec Law 25 covers

s. 2; de-identification and anonymisation at s. 23

Any information which relates to a natural person and directly or indirectly allows that person to be identified.

In scope

  • Information allowing direct identification
  • Information allowing indirect identification

Sensitive personal information (s. 59)

The instrument's own term, kept as it writes it — these labels differ between frameworks on purpose.

  • Information which, due to its nature or the context of its use, entails a high level of reasonable expectation of privacy

What falls outside

Anonymised information, but only where anonymisation is irreversible according to generally accepted best practices.

Quebec is the only instrument in this corpus that statutorily SEPARATES de-identified from anonymised. Section 23 makes de-identified data still personal information and anonymised data not — a distinction most programmes collapse, and one that decides whether the rest of the Act applies.

Act respecting the protection of personal information in the private sector · as at 2026-08

How Quebec Law 25 is enforced

Every figure below is the ceiling the instrument publishes about itself, not a prediction of what anything would cost. Enforced by The Commission d’accès à l’information, and individuals directly.

Published maximumChargedAs at
CAD 25 million or 4% of worldwide turnoveras a penal fine, doubled on a repeat offence2026-08
CAD 10 million or 2% of worldwide turnoveras an administrative monetary penalty2026-08
CAD 1,000No ceilingminimum punitive damages per person where the infringement is intentional or results from gross fault, with no pecuniary loss required2026-08

Quebec runs two parallel tracks. Administrative monetary penalties are imposed by the Commission; penal fines are prosecuted and can be doubled for a repeat offence. Section 93.1 adds a private right of action, and an infringement that is intentional or results from gross fault carries a minimum award of CAD 1,000 in punitive damages per person, which is what makes class proceedings viable.

The punitive damages minimum is per individual and does not require proof of pecuniary loss, so the aggregate in a class action is driven by headcount.

Uncapped exposure that sits outside this instrument

These come from company law rather than from Quebec Law 25, and they are not penalties — they are liability for a loss, which is why nothing caps them at a published maximum.

Directors’ duty of care

Canada, under s. 122(1)(b) of the Canada Business Corporations Act and its provincial equivalents.

Triggered by. Failing to exercise the care, diligence and skill a reasonably prudent person would exercise in comparable circumstances. Unlike the Delaware doctrine, the standard is objective.

Who. Directors and officers personally.

The CBCA permits indemnification only where the director acted honestly and in good faith, so the cases that matter most are the ones where indemnity is unavailable.

Peoples Department Stores Inc. v. Wise (SCC 2004); BCE Inc. v. 1976 Debentureholders (SCC 2008).

Enforcement data reviewed August 2026. Several figures are indexed annually and move.

Ships With It

Built for Quebec Law 25,
not configured for it afterwards

Policy Template

Quebec PII Access Tracking

Log every instance of personal information access or sharing

Report

Law 25 PIA Evidence

Privacy Impact Assessment documentation with access logs

Classification

Quebec Resident Patterns

Identify Quebec-specific identifiers and resident data

Alert

PII Access Notification

Real-time logging of all personal information access

Other Data Privacy frameworks

Walk into the Quebec Law 25 audit knowing the answer

228 cited requirements across 57 frameworks are mapped to the controls that evidence them. A fixed-fee gap assessment tells you which of them you can already prove today.

Get a Gap Assessment