Business
Business Security · Overview Scope · Domain Audit Shadow · Mailbox Forensics Monitoring · Continuous Coverage Fix Session · Implementation
Individual
Personal Protection · Overview Scope · Personal Credential Scan
Solutions
Dark Web Monitoring Domain Impersonation Protection Credential Breach Detection Compliance Monitoring
Intelligence
Threat Intelligence Global Breach Map Breach Feed
Company
Partners How It Works About Press & Media
Sign In
Home · Frameworks · Quebec Law 25
Reference · LeakTrace Intelligence Team

Quebec Law 25.

An Act to modernize legislative provisions as regards the protection of personal information (Bill 64)
At a glance
Jurisdiction
Quebec
Breach reporting deadline
With diligence (no fixed hour deadline)
Applies to
AllPrivate SectorPublic Sector
Authoritative source
https://www.legisquebec.gouv.qc.ca/en/document/cs/p-39.1
Last updated
August 5, 2026
## What it is Law 25 (formerly Bill 64) is Quebec's comprehensive privacy modernization act, adopted September 22, 2021. It amends the Act Respecting the Protection of Personal Information in the Private Sector (P-39.1) and the Act Respecting Access to Documents Held by Public Bodies and the Protection of Personal Information. Enforced by the Commission d'accès à l'information (CAI), it introduces GDPR-adjacent requirements and Canada's most punitive privacy penalties to date. ## Who it applies to Any enterprise or public body collecting, holding, using, or disclosing personal information of Quebec residents — regardless of where the enterprise is headquartered. Extraterritorial reach mirrors the GDPR pattern: if you offer goods or services to Quebec residents or monitor their behaviour, you are covered. ## Phased implementation - **September 22, 2022 (Phase 1):** Mandatory Privacy Officer designation; breach reporting to the CAI; incident register; breach notification to affected individuals; safeguards proportionate to sensitivity - **September 22, 2023 (Phase 2):** Consent requirements; automated decision-making transparency; privacy by default; data portability [VERIFY 2023 portability implementation timing]; privacy impact assessments for high-risk projects - **September 22, 2024 (Phase 3):** Right to data portability fully in force ## Key data protection requirements Enterprises must designate a person in charge of privacy (default: the person exercising the highest authority), maintain records of processing, conduct privacy impact assessments (PIAs) before implementing information systems or communicating personal information outside Quebec, and obtain express consent for sensitive personal information. Cross-border transfers require a PIA and can be blocked if the destination does not provide adequate protection. ## Breach reporting Following a confidentiality incident, enterprises must: - **Notify the CAI** and affected individuals with diligence if the incident presents a risk of serious injury - **Maintain a register** of all confidentiality incidents (regardless of severity) — the CAI can request the register - **Take reasonable measures** to reduce the risk of injury and prevent recurrence ## Penalties Administrative monetary penalties up to the greater of CAD $10 million or 2% of worldwide turnover. Penal fines up to the greater of CAD $25 million or 4% of worldwide turnover. Private right of action available for punitive damages of at least CAD $1,000 per affected individual for intentional or grossly negligent violations. These figures are the highest in Canada. ## How LeakTrace aligns LeakTrace supports Quebec entities with continuous external-surface monitoring aligned to the CAI's confidentiality-incident framework — including register-ready incident documentation, chain-of-custody evidence bundles, and cross-border-transfer risk indicators.
Key provisions
Section 3.1 — Privacy Officer
Every enterprise must designate a person in charge of the protection of personal information; contact details must be published on the enterprise's website.
Section 3.5 — Privacy Impact Assessments
PIA required before deploying an information system involving personal information, and before communicating personal information outside Quebec.
Section 3.7 — Automated decisions
Individuals must be informed of decisions based exclusively on automated processing and given a right to make observations.
Section 3.8 — Confidentiality incident
Report to CAI and affected individuals with diligence when incident presents a risk of serious injury. Maintain a register of all incidents.
Section 91 — Administrative penalties
Up to CAD $10 million or 2% of worldwide turnover, whichever is greater.
Section 93 — Penal offences
Up to CAD $25 million or 4% of worldwide turnover for offences including breach-reporting failures.
Recent amendments & guidance
2022-09-22
Phase 1 in force — breach reporting, privacy officer designation, incident register.
2023-09-22
Phase 2 in force — consent, transparency, PIA requirements.
2024-09-22
Phase 3 in force — data portability rights.
Operating under this framework?
LeakTrace runs continuous external-surface intelligence aligned to your regulatory posture. Discovery call under mutual NDA; first-touch reply within one business day from an authenticated LeakTrace address.
View programs