Reference · LeakTrace Intelligence Team
Quebec Law 25.
An Act to modernize legislative provisions as regards the protection of personal information (Bill 64)
At a glance
- Jurisdiction
- Quebec
- Breach reporting deadline
- With diligence (no fixed hour deadline)
- Applies to
- AllPrivate SectorPublic Sector
- Authoritative source
- https://www.legisquebec.gouv.qc.ca/en/document/cs/p-39.1
- Last updated
- August 5, 2026
## What it is
Law 25 (formerly Bill 64) is Quebec's comprehensive privacy modernization act, adopted September 22, 2021. It amends the Act Respecting the Protection of Personal Information in the Private Sector (P-39.1) and the Act Respecting Access to Documents Held by Public Bodies and the Protection of Personal Information. Enforced by the Commission d'accès à l'information (CAI), it introduces GDPR-adjacent requirements and Canada's most punitive privacy penalties to date.
## Who it applies to
Any enterprise or public body collecting, holding, using, or disclosing personal information of Quebec residents — regardless of where the enterprise is headquartered. Extraterritorial reach mirrors the GDPR pattern: if you offer goods or services to Quebec residents or monitor their behaviour, you are covered.
## Phased implementation
- **September 22, 2022 (Phase 1):** Mandatory Privacy Officer designation; breach reporting to the CAI; incident register; breach notification to affected individuals; safeguards proportionate to sensitivity
- **September 22, 2023 (Phase 2):** Consent requirements; automated decision-making transparency; privacy by default; data portability [VERIFY 2023 portability implementation timing]; privacy impact assessments for high-risk projects
- **September 22, 2024 (Phase 3):** Right to data portability fully in force
## Key data protection requirements
Enterprises must designate a person in charge of privacy (default: the person exercising the highest authority), maintain records of processing, conduct privacy impact assessments (PIAs) before implementing information systems or communicating personal information outside Quebec, and obtain express consent for sensitive personal information. Cross-border transfers require a PIA and can be blocked if the destination does not provide adequate protection.
## Breach reporting
Following a confidentiality incident, enterprises must:
- **Notify the CAI** and affected individuals with diligence if the incident presents a risk of serious injury
- **Maintain a register** of all confidentiality incidents (regardless of severity) — the CAI can request the register
- **Take reasonable measures** to reduce the risk of injury and prevent recurrence
## Penalties
Administrative monetary penalties up to the greater of CAD $10 million or 2% of worldwide turnover. Penal fines up to the greater of CAD $25 million or 4% of worldwide turnover. Private right of action available for punitive damages of at least CAD $1,000 per affected individual for intentional or grossly negligent violations. These figures are the highest in Canada.
## How LeakTrace aligns
LeakTrace supports Quebec entities with continuous external-surface monitoring aligned to the CAI's confidentiality-incident framework — including register-ready incident documentation, chain-of-custody evidence bundles, and cross-border-transfer risk indicators.
Key provisions
- Section 3.1 — Privacy Officer
- Every enterprise must designate a person in charge of the protection of personal information; contact details must be published on the enterprise's website.
- Section 3.5 — Privacy Impact Assessments
- PIA required before deploying an information system involving personal information, and before communicating personal information outside Quebec.
- Section 3.7 — Automated decisions
- Individuals must be informed of decisions based exclusively on automated processing and given a right to make observations.
- Section 3.8 — Confidentiality incident
- Report to CAI and affected individuals with diligence when incident presents a risk of serious injury. Maintain a register of all incidents.
- Section 91 — Administrative penalties
- Up to CAD $10 million or 2% of worldwide turnover, whichever is greater.
- Section 93 — Penal offences
- Up to CAD $25 million or 4% of worldwide turnover for offences including breach-reporting failures.
Recent amendments & guidance
2022-09-22
Phase 1 in force — breach reporting, privacy officer designation, incident register.
2023-09-22
Phase 2 in force — consent, transparency, PIA requirements.
2024-09-22
Phase 3 in force — data portability rights.
Operating under this framework?
LeakTrace runs continuous external-surface intelligence aligned to your regulatory posture. Discovery call under mutual NDA; first-touch reply within one business day from an authenticated LeakTrace address.
View programs