Quebec Law 25 vs. PIPEDA

By Rodrigo Lamadrid 25 August, 2026

Quebec Law 25 and PIPEDA both govern how organizations handle personal information in Canada. But businesses often assume they’re interchangeable. They’re not, and the gap between them has real consequences for anyone doing business with Quebec residents.

In this article, we’ll explain what Law 25 and what PIPEDA is, the key differences between the two, who needs to comply with each, and how Mindsec helps you handle both at once.

What is Quebec’s Law 25?

Officially “An Act to modernize legislative provisions as regards the protection of personal information,” this law is the province’s privacy law for the private and public sectors. Quebec francophones and legal documents often refer to it as Loi 25 (its original French name), or simply as Quebec Privacy Law in everyday conversation.

Adopted in September 2021 (formerly known as Bill 64), the law amended the Act respecting the protection of personal information in the private sector, Quebec’s existing privacy statute, and rolled out its new requirements in phases between 2022 and 2024.

This Quebec privacy act applies to any organization “carrying on an enterprise” in Quebec that collects, uses, or discloses the personal information of individuals located in the province (regardless of where the organization itself is based). 

Physical presence in Quebec isn’t required. Digital presence is enough, which is precisely why Quebec Law 25 compliance catches off guard so many out-of-province businesses.

The Commission d’accès à l’information (CAI) oversees enforcement. It’s both an administrative tribunal and an oversight body, with real investigative and sanctioning power, a sharp contrast to how privacy enforcement historically worked in Canada.

What is PIPEDA?

PIPEDA, the Personal Information Protection and Electronic Documents Act, is Canada’s federal private-sector privacy law. It received royal assent in April 2000 and sets the ground rules for how organizations handle personal information during commercial activity across the country.

You can read the full text of PIPEDA on the Justice Laws Website, the Government of Canada’s official legislation repository.

PIPEDA is built around ten fair information principles, covering accountability, consent, limiting collection, and safeguards, among others. The Office of the Privacy Commissioner of Canada (OPC) oversees compliance and investigates complaints.

Here’s the part that matters most for this comparison. PIPEDA applies federally, except where a province has passed its own law deemed “substantially similar.” Where that exception applies, the provincial law governs instead of PIPEDA, which is exactly the situation Quebec Law 25 creates.

Quebec Law 25 vs. PIPEDA: The Key Differences

To frame it simply as a privacy act vs PIPEDA comparison, it all comes down to scope, enforcement, and how prescriptive each law gets about specific obligations.

  • Scope. PIPEDA applies across Canada to commercial activity, except in provinces with substantially similar legislation. Loi 25 applies specifically to anyone doing business with individuals located in Quebec, whether that business is based in Montreal, Toronto, or anywhere else in the world.
  • Enforcement power. This is where the two diverge the most. PIPEDA’s enforcement has historically been limited: the OPC could investigate and recommend, but had little power to issue direct penalties. Quebec Loi 25 gives the CAI real teeth: administrative penalties and penal sanctions.
  • Penalties. Law 25 actually runs two separate penalty tracks. Administrative monetary penalties, issued directly by the CAI without going to court. These can reach $10 million CAD or 2% of worldwide turnover. Penal sanctions, which go through the Court of Québec, can reach $25 million CAD or 4% of worldwide turnover, with a $15,000 minimum fine for corporations.

For Quebec Law 25, PIPEDA’s penalty structure is narrower by comparison. Organizations that knowingly fail to report a breach, notify affected individuals, or maintain breach records can face a fine of up to $100,000 CAD, but only through a criminal prosecution referred to the Attorney General, a process rarely used in practice.

  • Specific obligations. Law 25 introduces requirements that PIPEDA doesn’t spell out as explicitly: a mandatory privacy officer (by default, the CEO, unless someone else is designated), privacy impact assessments (PIAs) before certain data transfers or disclosures, an incident register for confidentiality breaches, and a right to data portability (in effect since September 22, 2024).
  • Breach notification. Both laws require notification when a breach poses a real risk of harm, but Law 25 is more prescriptive about the process, including notifying the CAI directly. Law 25 also requires keeping the incident register for five years, compared to two years under PIPEDA.
  • Cross-border data transfers. PIPEDA requires “comparable protection” when data moves to a third-party processor, but doesn’t mandate a formal review process.

Quebec Law 25 goes further: before communicating personal information outside Quebec (not just outside Canada), you need a documented PIA confirming the receiving jurisdiction offers adequate protection. The CAI can request that assessment at any time.

  • Private right of action. PIPEDA complaints go through the OPC. Law 25 gives individuals a direct path to court: minimum punitive damages of $1,000 CAD per person for intentional or grossly negligent violations, and class actions are explicitly permitted.

Who Needs To Comply With Each?

If your organization collects, uses, or discloses personal information of people located in Quebec in the course of business, this law applies to you. It doesn’t matter where your company is headquartered.

PIPEDA applies to commercial activity across Canada, except where a substantially similar provincial law takes over. Quebec, Alberta, and British Columbia all have laws recognized as substantially similar for parts of their private-sector activity, meaning PIPEDA takes a back seat for organizations operating strictly within those provinces.

In practice, for anyone weighing Quebec Law 25 against PIPEDA, most businesses that operate across multiple provinces end up needing to understand both frameworks: PIPEDA as the federal baseline, and Quebec’s law as the stricter standard the moment Quebec residents are involved.

Frequently Asked Questions

Does Law 25 replace PIPEDA?

Not entirely. Law 25 takes precedence over PIPEDA specifically for activity involving Quebec residents. PIPEDA still applies to any commercial activity outside Quebec that isn’t covered by another substantially similar provincial law.

Is Quebec Loi 25 stricter than PIPEDA?

Yes, on most fronts: it has a stronger regulator, higher penalties, and more prescriptive obligations, like the mandatory privacy officer and PIAs.

Does PIPEDA still apply if I comply with Law 25?

If your organization operates only within Quebec, complying with Law 25 generally covers you. If you also process personal information outside Quebec, PIPEDA still applies to that portion of your activity.

What happens if a company outside Quebec sells to Quebec residents?

Quebec’s privacy rules still apply. Location of your headquarters doesn’t matter, what matters is whether you’re processing personal information of individuals located in Quebec.

Is PIPEDA changing to match Quebec Law 25?

Possibly. The federal government has proposed the Protecting Privacy and Consumer Data Act (PPCDA) under Bill C-36, which would raise PIPEDA’s penalties and add individual rights closer to what Law 25 already requires. Until it passes, PIPEDA’s current rules remain in effect.

Mindsec Makes Quebec Law 25 and PIPEDA Compliance Easy

Trying to track both laws as two separate compliance projects usually means duplicating a lot of the same work: consent processes, breach procedures, documentation, twice over.

Mindsec centralizes compliance with both frameworks from a single platform, thanks to our cross-mapping and compliance automation technology.

With Mindsec, you can:

  • Determine which framework applies to each part of your business, based on where your data subjects are actually located.
  • Automate your privacy officer’s documentation, incident register, and breach notification workflows.
  • Use our pre-mapping of PIPEDA’s ten fair information principles directly against Loi 25’s requirements, so you’re not rebuilding the same controls twice.
  • Centralize your PIAs and keep them audit-ready for the CAI or the OPC.
  • Manage your compliance alongside other frameworks like SOC 2, ISO 27001, and GDPR, all from one platform.

Don’t wait for a complaint to find out which law actually applies to your business. Book a 15-minute demo and see how Mindsec keeps you compliant with both laws at the same time.

Rodrigo Lamadrid

Mindsec staff

Why Stall? Book A Call

Want to comply with Quebec Law 25, PIPEDA, and other regulations? Book a call with our team and learn how we streamline this for you.

See Mindsec In Action