DPDPA is now in force in India. Run a free privacy scan on your site. Scan now

Québec, Canada

Quebec Law 25 Compliance with ConsentX

Act respecting the protection of personal information

Quebec Law 25, formally known as An Act to modernize legislative provisions as regards the protection of personal information, significantly strengthened Québec's privacy framework. The law introduced important obligations for organisations that collect, use, disclose or otherwise process personal information in Québec. Its requirements include greater transparency, stronger consent standards, privacy impact assessments, data breach management, individual rights and specific safeguards for personal information transferred outside Québec. The major provisions of Law 25 came into force progressively between 2022 and 2024, with many of the most significant requirements taking effect in September 2023.
Region

Québec, Canada

Status

In force

Group

North America

Who must comply

Law 25 applies to organisations that process personal information in Québec. The private-sector framework applies to persons carrying on an enterprise, while separate provisions apply to Québec public bodies. The law can therefore affect businesses that collect or process personal information from individuals in Québec, depending on their activities and the applicable legal framework.

Penalties

Law 25 introduced significant administrative and criminal sanctions for non-compliance. For private-sector organisations, administrative monetary penalties can reach up to C$10 million or 2% of worldwide turnover for the preceding fiscal year, whichever is greater, in circumstances covered by the legislation. Certain criminal penalties can also reach higher amounts depending on the violation and circumstances.

Key obligations

  • Appoint a person responsible for privacy and make their contact information available
  • Establish and publish privacy policies and practices in clear and simple language
  • Determine the purposes of collection before collecting personal information
  • Collect only information necessary for the purposes identified
  • Provide individuals with clear information about how their personal information is collected and used
  • Obtain consent that is clear, free, informed and specific where consent is required
  • Obtain express consent for sensitive personal information where required
  • Provide additional transparency when technology is used to identify, locate or profile an individual
  • Conduct Privacy Impact Assessments (PIAs) for qualifying projects involving personal information
  • Conduct a PIA before communicating personal information outside Québec
  • Maintain a confidentiality incident register
  • Notify affected individuals and the CAI when a confidentiality incident presents a risk of serious injury, where required
  • Implement appropriate security measures based on the sensitivity of personal information
  • Respect individual rights, including access, correction and other applicable privacy rights
  • Establish retention and destruction practices for personal information
  • Apply appropriate safeguards when using service providers or transferring information outside Québec
  • Respect additional requirements concerning profiling and automated decision-making

These obligations are reflected in Québec's private-sector privacy legislation and the CAI's guidance on Law 25.

Consent requirements under Law 25

Law 25 establishes specific standards for valid consent.

Consent must generally be:

  • Clear
  • Free
  • Informed
  • Specific

Where consent is requested in writing, the request must be presented separately from other information provided to the individual. For sensitive personal information, consent must be express where the law requires it.

For organisations managing websites and digital services, these requirements make clear privacy notices, purpose-specific choices and appropriate consent records important components of a privacy compliance program.

Privacy Impact Assessments

Law 25 requires organisations carrying on an enterprise to conduct a Privacy Impact Assessment (PIA) for projects involving the acquisition, development or overhaul of an information system or electronic service delivery system that involves the collection, use, communication, retention or destruction of personal information.

The assessment must be proportionate to factors such as the sensitivity of the information, the purposes of processing, the quantity and distribution of the information and the medium in which it is stored.

A PIA is also required before personal information is communicated outside Québec. The assessment must consider the sensitivity of the information, the purposes of use, applicable protection measures and the legal framework in the destination jurisdiction.

How ConsentX helps

Geo-aware consent management to provide a Québec-specific privacy experience

Customisable consent banners with clear, purpose-specific choices

Privacy preference management allowing users to manage their choices

Consent and preference receipts to maintain evidence of user choices

Get Law 25 ready with ConsentX

Make your website privacy experience easier to manage across Québec and other jurisdictions.

This page is a plain-English summary for general information and is not legal advice. Confirm your specific obligations with qualified Québec privacy counsel.

How to comply with Law 25 using ConsentX

  1. 1

    Scan your website

    Run a free scan to identify cookies, trackers and other technologies operating on your website. Understand what data is collected and which third parties may receive it.

  2. 2

    Show a geo-aware privacy experience

    Deploy the ConsentX banner to provide visitors with a privacy experience tailored to their region and the applicable requirements.

  3. 3

    Control trackers and scripts

    Use prior-script blocking to help prevent selected non-essential tracking technologies from loading before the applicable user choice or privacy control is provided.

  4. 4

    Record user choices

    Store consent and preference events in tamper-evident receipts, giving your team an auditable record of user choices and privacy interactions.

  5. 5

    Manage privacy requests

    Use the ConsentX request workflow to organise access and correction requests, track deadlines and maintain a central record of request handling.

Soalan lazim