Skip to main content
CIPP/CCIPP/CPrivacyCanadaLaw 25

Quebec Law 25 at Full Force: Portability, Defaults, and Real Penalties

Quebec Law 25 is fully in force: data portability, privacy by default, and CAI penalties up to 2–4% of global turnover reshape Canadian privacy design.

5 min read
ShareLinkedIn

Quebec did not wait for Ottawa to finish a federal privacy rewrite. It built and finished one of North America’s strictest private-sector regimes through Law 25, and the rest of Canada is now living with the consequences of that choice.

The final headline piece—the right to data portability—took effect in September 2024, closing a multi-year implementation arc. For privacy professionals, “full force” is not a ceremonial phrase. It means the easy excuse of transition periods is gone. The Commission d’accès à l’information du Québec (CAI) has a mature mandate, investigative tools, and a penalty framework that corporate counsel cannot wave away as symbolic. Start with the CAI’s own Law 25 / privacy materials rather than second-hand slides.

What full implementation actually changed

Portability forces data architecture conversations that notice policies never did. If a person can demand their information in a structured, commonly used format, you need to know where it lives, how it joins across systems, and which fields are truly personal information versus disposable telemetry.

Privacy by default reverses the old web habit of “everything on until you fight through settings.” Technologies that collect personal information on websites and apps are expected to start restrictive, not permissive. That hits marketing stacks first, then product analytics, then embedded third parties that quietly rebuild profiles.

Governance obligations also moved from best practice to expectation: clear responsibility, policies that operate in real workflows, and supplier management that matches the risk of modern processing. If your only “privacy officer” is a title on an org chart with no budget or escalation path, you are performing compliance theatre.

The enforcement temperature

Law 25’s financial teeth are now part of every serious Canadian risk register. Administrative monetary penalties can reach CAD $10 million or 2% of worldwide turnover, whichever is greater. Penal fines for the most serious violations can reach CAD $25 million or 4% of worldwide turnover. Those figures are not theoretical decoration; they are why board packs in federally regulated companies suddenly care about a provincial statute.

I tell non-Quebec executives the same thing every time: if you market to Quebec, employ in Quebec, or run digital services used in Quebec, pretending the province is optional is a strategy for discovery documents you will hate later.

Federal programs still need PIPEDA hygiene for other Canadian activity. Law 25 is not a substitute for federal law; it is often the stricter design standard that national products should meet once and reuse.

Practical friction I still see in the field

Cookie and SDK sprawl. Teams add tags faster than legal retires them. Privacy by default fails when nobody owns the tag manager.

Portability as a helpdesk script. If your process is “email IT and hope,” you do not have a right; you have a ticket queue.

Vendor lag. Processors promise alignment in security schedules and deliver PIPEDA-era language. Quebec-specific terms need explicit negotiation.

Bilingual transparency. Clear notice is not only a translation exercise. It is content design. People should understand purposes without a law degree in either language.

Cross-border tools. Using global marketing clouds does not reduce Quebec duties. It multiplies the number of contracts that must reflect them.

AI feature creep. A chatbot or recommendation model trained on Quebec customer content is still a Law 25 processing activity. “Innovation” is not an exemption.

How Law 25 reshapes federal conversations

Every time federal reform stalls—including after Bill C-27 died on the Order Paper—Law 25 becomes the working example of modern Canadian privacy: stronger rights, default protections, and penalties large enough to change product roadmaps. When people ask what a PIPEDA replacement might feel like in practice, I point to Quebec operations teams who already run privacy impact assessments, consent redesigns, and portability responses as normal work.

It also creates competitive unevenness. Companies that invested early treat Law 25 as sunk cost and reusable design. Companies that delayed now face compressed remediation while competitors ship.

A note on culture, not only controls

The deepest shift is philosophical. Personal information is not a free raw material with a complaint process taped on top. It is regulated infrastructure. That mindset affects analytics prioritization, AI training proposals, and “quick” data shares between business units.

I have more productive meetings in organizations that accepted that philosophy than in organizations still bargaining for the old normal.

One practical habit helps: treat every new tracking SDK like a vendor onboarding, not a marketing experiment. Demand a data sheet, retention answer, and Quebec-ready consent behaviour before the tag goes live. The same discipline applies to AI features that silently expand collection. Law 25 does not care that the feature is innovative. It cares whether people were respected at the point of collection.

I also recommend a quarterly CAI-and-enforcement scan for your sector, not only a once-a-year legal update. Penalty math concentrates minds, but pattern recognition prevents repeats. If peer organizations are being questioned on consent banners or retention, assume your stack will be next.

Portability done without heroics

A workable portability design usually includes:

  • A data catalogue that marks portable fields by system
  • An orchestration layer that can assemble structured exports
  • Identity verification that is strong enough without becoming a second surveillance system
  • Service levels and exception handling for complex multi-system profiles
  • Vendor clauses so processors return or export on request

If portability still depends on one analyst writing SQL by hand, you have a single point of failure dressed up as a rights process.

Actionable takeaway

Run a Quebec-focused control test this month with three proofs: (1) collection technologies default to off without opt-in where required, (2) a portability request can be fulfilled from mapped systems within a defined service level, and (3) contracts with top adtech and cloud vendors explicitly address Law 25 duties. Use the CAI site as your primary reference for obligations and guidance. Fix whatever fails before you write another high-level “Canada privacy update” slide.

Related services

Practical consulting aligned to this article’s focus—program design, controls, and operational delivery.

Browse all services