Penal offences (Law 25)#
Law 25 creates penal offences for conduct like collecting, using, or disclosing personal information in breach of the law, and for knowingly obstructing the CAI. Penalties escalate for repeat offenders and are higher for legal persons than for individuals. Directors and officers can also be personally liable when they direct or authorize the offence.
Person carrying on an enterprise#
Under Quebec privacy law, this is the entity that collects and holds personal information in a business context. The phrase covers companies, partnerships, and solo operators, not just corporations. Law 25 places duties like consent, transparency, and security on this person, and their liability cannot be quietly shifted to a vendor.
Personal health information is identifying information about a person's health or health care: diagnoses, treatment records, health numbers, and even the fact that someone received care. Ontario's PHIPA and similar provincial laws give it stronger protection than general personal information. Custodians can only collect, use, or disclose it with consent or specific legal authority.
Personal information is any information about an identifiable individual, from a name and email to an IP address or purchase history, depending on context. Québec law phrases it as information that relates to a natural person and allows that person to be identified. It does not cover business contact details used for business purposes.
Personal information banks are Treasury Board's standardized descriptions of the personal information holdings of each federal institution, published so people can find records about themselves. They describe what is collected, why, and how long it is kept. When you file a Privacy Act access request, the relevant bank tells you where to look.
This Nova Scotia statute limits the storage of and access to personal information by public bodies outside Canada. It requires public bodies to ensure their data stays under Canadian protection unless strict conditions are met. It is one of the strongest data-residency rules for a provincial public sector in the country.
Phased implementation (Law 25)#
Law 25's obligations came into force in three stages, phased in over 2022 to 2024, giving organizations time to adjust. Early measures included appointing a privacy officer and reporting serious incidents; later stages added rules on automated decisions, the right to portability, and express consent for sensitive information. Knowing which phase a rule belongs to explains why some obligations still feel new.
PHIA (Manitoba)#
Manitoba's Personal Health Information Act governs personal health information held by trustees like regional health authorities, hospitals, and health professionals. It sets rules for collection, use, and disclosure, and gives individuals access and correction rights. Manitoba's ombudsman and the Information and Privacy Adjudicator handle oversight.
PHIA (Newfoundland and Labrador)#
Newfoundland and Labrador's Personal Health Information Act covers personal health information held by custodians across the health system. It sets rules for collection, use, and disclosure, with access and correction rights for individuals. Oversight rests with the province's Information and Privacy Commissioner.
PHIA (Nova Scotia)#
Nova Scotia's Personal Health Information Act governs personal health information held by custodians across the health system. It gives individuals access and correction rights and restricts disclosure outside the circle of care. Oversight sits with the Office of the Information and Privacy Commissioner for Nova Scotia.
PHIPA (Ontario)#
PHIPA is Ontario's Personal Health Information Protection Act, governing personal health information held by health information custodians like hospitals, physicians, and labs. Patients have rights of access and correction, and custodians must keep audit logs of who viewed a record. Breaches posing risk require notification to the patient and, in serious cases, to the IPC.
PHIPAA (New Brunswick)#
PHIPAA is New Brunswick's Personal Health Information Privacy and Access Act, covering personal health information in the hands of custodians. Patients can access their records and request corrections, and custodians must safeguard the information. New Brunswick's Integrity Commissioner handles complaints.
Phishing#
Phishing is a scam in which an attacker impersonates a trusted sender, usually by email or text, to trick someone into handing over credentials or clicking a malicious link. It remains the most common way breaches begin, because one rushed click can bypass technical defenses. Training people to verify before acting is the main defense.
PIA / EIVP#
A privacy impact assessment (évaluation d'impact sur la vie privée) is a structured review of a new project or system to spot privacy risks before launch. Under Law 25, enterprises must conduct one before acquiring, developing, or overhauling an information system or electronic service involving personal information, and before communicating personal information outside Québec. The assessment must be proportionate to the sensitivity of the data and the risks involved.
PIA for technological products (Law 25)#
A privacy impact assessment is a structured review an organization does before a project that affects personal information. Under Law 25 it is mandatory for any technological product or service offered to the public that collects, uses, or communicates personal information. It is also required before communicating information outside Quebec, which makes PIAs a recurring discipline rather than a one-time form.
PIPEDA#
PIPEDA (the Personal Information Protection and Electronic Documents Act) is Canada's federal private-sector privacy law, built on ten fair information principles. It applies wherever provinces lack “substantially similar” legislation, Québec, B.C., and Alberta have their own. It requires meaningful consent, limits collection and retention, and gives individuals access rights; proposed reforms would modernize it.
PIPL (China)#
China's PIPL is the country's comprehensive privacy law, in force since 2021. It echoes the GDPR on consent, purpose limits, and individual rights, but it pairs those duties with strict rules on moving data out of China. Multinationals operating in China often face the hardest compliance puzzle of any market there.
Prescribed entity#
A prescribed entity is an organization designated by regulation under PHIPA to collect and use personal health information for health system planning, evaluation, or resource allocation without individual consent. Ontario Health and ICES are examples. Prescribed entities face strict review requirements and must have their information practices approved by the Information and Privacy Commissioner.
Prescribed person#
A prescribed person is designated by regulation under PHIPA to compile and maintain specific health registries, such as cancer or cardiac registries, using personal health information without individual consent. The designation comes with conditions on collection, use, disclosure, and security. It is a narrower role than a prescribed entity, tied to a specific registry purpose.
Privacy Act (federal)#
The Privacy Act governs how federal government institutions collect, use, and disclose personal information about individuals. It gives people the right to access their own records held by institutions and to request corrections. Complaints go to the Privacy Commissioner of Canada, and unresolved refusals can be taken to Federal Court.
Privacy Act complaint (OPC)#
A Privacy Act complaint is filed with the Office of the Privacy Commissioner when a federal institution mishandles personal information or mishandles an access request. The OPC investigates and issues findings and recommendations, which are not binding orders. If the institution refuses access, the complainant can escalate to the Federal Court.
Privacy by default#
Privacy by default means the most privacy-protective settings apply automatically, without the user having to change anything. It is a companion to privacy by design: the system should not require people to opt out of data collection they never asked for. Both PIPEDA guidance and Law 25 expect organizations to think this way.
Privacy by design#
Privacy by design means building privacy into products and processes from the start rather than bolting it on later. The concept, seven foundational principles from Ontario's former commissioner Ann Cavoukian, calls for proactive, default-private, embedded safeguards. Law 25's mandatory PIAs before new systems are, in effect, privacy-by-design requirements with teeth.
Privacy management program (OPC)#
A privacy management program is the OPC's framework for building accountability into an organization, with named leadership, policies, training, and monitoring scaled to the organization's size and risk. The Commissioner has said a documented program is the expected evidence of compliance, not an optional extra. It is the backbone that due-diligence questionnaires and investigations both ask to see.
Privacy notice vs. privacy policy#
A privacy notice is the point-of-collection explanation: what you're collecting right now, why, and what choices the person has. A privacy policy is the organization's overall governance document covering all its practices. Law 25 goes further, requiring published governance rules (roles, retention, complaint handling, security). Notices face the user; policies face the auditor.
Privacy officer (responsable de la protection des renseignements personnels)#
The privacy officer is the person accountable for an organization's privacy program. Under Law 25, the default is the person with the highest authority in the enterprise, who may delegate the role in writing; the title and contact details must be published. This person oversees the governance framework, handles access requests, and approves PIAs.
Privacy paradox#
The privacy paradox is the gap between what people say about privacy and what they do: surveys show deep concern, yet people routinely trade data for small conveniences. It does not mean people do not care; it usually means the choices are designed badly or the costs are hidden. Regulators use it to justify stronger defaults rather than relying on informed consent alone.
Privacy risk reviews (federal)#
Privacy risk reviews are the federal government's scaled assessments for initiatives that touch personal information, ranging from checklists to full privacy impact assessments. TBS requires them before launching new programs, systems, or data-sharing arrangements. The review must identify risks and mitigations and be updated when the initiative changes materially.
Private right of action#
A private right of action lets individuals sue directly for privacy violations instead of relying on a regulator. Law 25 gives Québecers this right, including minimum damages (commonly cited as $1,000 per person) and the possibility of class actions. It turns privacy rights into courtroom leverage.
Proactive disclosure#
Proactive disclosure is the federal practice of publishing certain government records automatically, without waiting for access requests: travel and hospitality expenses, contracts, grants, and briefing note titles. It is required by the Access to Information Act for institutions and ministers' offices. The goal is transparency by default rather than transparency on demand.
Processor / agent / service provider#
A processor is a third party that handles personal information on an organization's behalf, a cloud host, payroll provider, or analytics vendor. Québec's Law 25 calls this party an agent or mandatary acting under a written agreement with required safeguards. The key rule everywhere: the organization stays accountable, and the vendor may only use the data for the contracted purpose.
Productivity monitoring#
Productivity monitoring is software that measures how employees work: active hours, application usage, task completion rates, and idle time. Privacy regulators view it as high-risk surveillance that needs a demonstrable business purpose, clear notice, and the least intrusive means available. Continuous screenshots or keystroke logging for all staff, without justification, is the pattern that draws enforcement.
Professional secrecy (Quebec)#
In Quebec, professional secrecy is the duty of members of regulated professions to keep client confidences. It is broader than common-law solicitor-client privilege because it covers many professions, from accountants to physicians. When it conflicts with disclosure demands, overriding it normally requires a legal basis.
Profiling#
Profiling is using personal information to evaluate characteristics or behavior, credit scoring, ad targeting, employee risk flags. Law 25 requires organizations to inform people when technology identifies, locates, or profiles them and to provide a way to deactivate profiling functions. Profiling that feeds automated decisions gets extra transparency duties.
Pseudonymization#
Pseudonymization replaces identifiers with codes or tokens so data can't be linked to a person without a separate key. It reduces risk and is good security hygiene, but the data can still count as personal information because re-identification is possible. Don't confuse it with anonymization, which is meant to be irreversible.
Publication of CAI decisions#
The CAI publishes its decisions and orders, building a public record of how the law is interpreted. For practitioners, these rulings are the most useful guidance available: they show what the regulator actually penalizes and orders. Watching them is how organizations learn the practical boundaries of Law 25.
Publicly available information is personal information the law excludes from consent requirements because it is public by law, land registry entries, court records, professional directories. Québec's Law 25 keeps a narrow statutory list, and “publicly available” does not mean “anything you can find online.” Scraping the web is not a consent strategy.
Every organization subject to Law 25 must designate a person responsible for protecting personal information and publish their title and contact information, typically on the website. By default that person is the head of the enterprise, unless the role is formally delegated. Regulators treat a missing contact line as an early sign the privacy program is thin.
Purpose limitation#
Purpose limitation means using personal information only for the purposes you identified when collecting it, unless you get fresh consent or the law allows otherwise. Law 25 requires purposes to be established before collection; PIPEDA mirrors this in its principles. New purpose, new consent.