Introductory guide · Québec

Law 25 protects people—and requires organizations to act.

Compliance must be reflected in collection, access, vendors, systems, incidents and daily governance.

Why now

A legal obligation and a discipline of trust.

Protect people

Limit collection, secure information and respect individual rights.

Prevent losses

Reduce the likelihood and impact of leaks, misuse and excessive retention.

Preserve trust

Be ready to explain, demonstrate and correct practices before an incident becomes a crisis.

Cost of inaction

Consequences extend far beyond a fine.

Administrative monetary penalties may reach $10 million or 2% of worldwide turnover. Penal fines for businesses may reach the greater of $25 million or 4% of worldwide turnover, subject to the applicable legal provisions.

Operational, commercial and legal impact

Disruption, investigation, notification, system recovery, lost contracts, reputational damage and civil proceedings may compound the direct penalty.

Foundations

What organizations need to establish.

Governance

Designate the privacy officer and document roles, policies and practices.

Information lifecycle

Inventory information, justify collection, limit use, define retention and destroy securely.

Consent & transparency

Provide clear information and meaningful choices for tracking technologies.

Security & incidents

Apply proportionate safeguards, maintain a register and report serious-risk incidents.

Privacy impact assessments

Assess relevant technology projects and transfers outside Québec before proceeding.

Individual rights

Maintain verifiable processes for access, correction, portability and other applicable rights.

International perspective

Law 25, GDPR, California and Brazil.

These regimes share transparency, accountability, security and individual-rights principles, but their scope, legal bases and procedures are not interchangeable.

GDPR · European Union

Detailed legal bases, extraterritorial reach, privacy by design and penalties tied to worldwide turnover.

CCPA/CPRA · California

Consumer rights, sale or sharing opt-out, Global Privacy Control and sensitive-information limits.

LGPD · Brazil

National framework with defined legal bases, controller responsibilities and ANPD oversight.

Law 25 · Québec

Privacy impact assessments, designated officer, transfers, privacy settings and accountability.

General information only; this page is not legal advice.