BLOG

PIPEDA and Quebec Law 25: What Canadian Businesses Actually Need to Do

PIPEDA and Quebec Law 25 business compliance: accountability, consent, PIAs, breach notification, and penalties for Canadian businesses

By David Chernitzky, Co-Founder and CEO, Armour Cybersecurity  |  Serving organizations across Canada, the US, and beyond  |  Last updated August 17, 2026

Quick answer: PIPEDA and Quebec Law 25 business compliance comes down to accountability. PIPEDA requires Canadian businesses handling personal information in commercial activity to be accountable for that information under ten fair information principles, with the accountability principle requiring that the organization be able to demonstrate compliance with documented evidence. Quebec Law 25, which strengthened Quebec’s private sector privacy law significantly across 2022, 2023, and 2024, adds requirements that go beyond PIPEDA in several areas, including mandatory privacy impact assessments, stricter consent, new individual rights, and a stricter breach notification standard that requires prompt reporting to the provincial regulator.

Key Takeaways

  • PIPEDA applies to private sector organizations collecting, using, or disclosing personal information in the course of commercial activity across Canada, with provincial exceptions where substantially similar provincial legislation applies. Quebec, Alberta, and British Columbia have substantially similar legislation, though Quebec Law 25 now exceeds PIPEDA in several requirements.
  • Quebec Law 25 (formerly Bill 64) introduced significant changes in three phases in 2022, 2023, and 2024. The most operationally significant requirements include mandatory appointment of a person in charge of personal information protection, published governance policies, privacy impact assessments for certain processing activities, enhanced consent requirements, new data portability rights, and prompt breach notification to the Commission d’acces a l’information for incidents that present a risk of serious injury.
  • The accountability principle in PIPEDA requires that organizations be able to demonstrate their compliance, not merely assert it. This means documented governance, maintained data inventories, consent records, individual rights response logs, and breach records must exist and be producible when a regulator asks.
  • Breach notification under PIPEDA requires reporting to the Office of the Privacy Commissioner and notifying affected individuals when a breach of security safeguards creates a real risk of significant harm. Under Law 25 the threshold is lower: an organization must promptly notify the CAI and affected individuals of any confidentiality incident that presents a risk of serious injury, and must log every confidentiality incident in a register regardless of severity.
  • Failure to comply with PIPEDA can result in findings of non-compliance, public recommendations, and Federal Court enforcement. Quebec Law 25 penalties are significantly more punitive, with administrative monetary penalties up to $10 million or 2% of worldwide turnover and penal fines up to $25 million or 4% of worldwide turnover for the most serious violations, aligning with GDPR-scale consequences.

PIPEDA: The Baseline Framework

The Personal Information Protection and Electronic Documents Act has governed private sector privacy in Canada since 2001. It applies to any private sector organization that collects, uses, or discloses personal information in the course of commercial activity, subject to provincial exceptions. The law is organized around ten fair information principles derived from the Canadian Standards Association Model Code for the Protection of Personal Information: accountability, identifying purposes, consent, limiting collection, limiting use disclosure and retention, accuracy, safeguards, openness, individual access, and challenging compliance.

The practical obligations these principles create span the entire lifecycle of personal information in the organization. Accountability requires designating a privacy officer and being able to demonstrate compliance with documented evidence, the kind of governance that ultimately feeds board cyber governance reporting. Identifying purposes requires specifying the purposes for which personal information is collected before or at the time of collection. Consent requires obtaining meaningful consent for the collection, use, and disclosure of personal information, with limited exceptions. Limiting collection requires collecting only the information necessary for the identified purposes. Limiting use, disclosure, and retention requires using and disclosing information only for the purposes for which it was collected and retaining it only as long as necessary. Individual access requires providing individuals with access to their personal information and an explanation of how it is used, with a 30-day response window.

Quebec Law 25: Where the Bar Is Higher

Quebec’s Act Respecting the Protection of Personal Information in the Private Sector was comprehensively modernized through Bill 64, which came into force in three phases starting in September 2022. The resulting framework, commonly referred to as Law 25, is more prescriptive than PIPEDA in several important areas and introduces requirements that have no PIPEDA equivalent. Meeting them is the practical difference between a privacy policy and an operational privacy risk management program.

Person in charge of personal information protection

Law 25 requires that every enterprise subject to the Act designate a person in charge of the protection of personal information. The name and contact information of this person must be published on the organization’s website. Unlike PIPEDA’s accountability principle, which simply requires designating an accountable individual internally, Law 25 makes the designation a public accountability requirement. Customers, regulators, and complainants can identify the specific person responsible for the organization’s privacy obligations and contact them directly.

Governance policy publication

Law 25 requires enterprises to adopt and publish a policy governing the protection of personal information. The policy must address how personal information is used, the roles and responsibilities of the enterprise’s staff, and the applicable rules and practices. This published governance document is distinct from the privacy notice delivered to individuals: it is an internal governance policy made public, describing how the organization’s privacy program operates, not just what it does with personal information.

Privacy impact assessments

Law 25 requires enterprises to conduct a privacy impact assessment before acquiring, developing, or overhauling any information system or service involving personal information. PIAs are also required before communicating personal information outside Quebec, which ties directly into vendor and supplier risk management. This is a mandatory operational process that must be embedded in project governance, procurement, and vendor management, not a voluntary best practice. The PIA must be documented, the risks identified must be addressed, and the documentation must be maintained.

Enhanced consent requirements

Law 25 strengthens consent requirements beyond PIPEDA in several respects. Consent must be manifested clearly and separately from other information: bundled consent in general terms and conditions is not adequate. Consent for sensitive personal information, including health information, financial information, and information about children, requires explicit rather than implicit consent. Withdrawal of consent must be as easy as giving it. The law also introduces specific rules for personalization and profiling: individuals must be informed of such uses and given an opportunity to object.

New individual rights

Law 25 introduces data portability as a new individual right: individuals have the right to receive personal information collected from them in a structured, commonly used technological format, and to have it communicated to another organization. This right, similar to the portability right under GDPR, requires that organizations have the technical capability to extract and deliver personal information in a portable format on request. Law 25 also strengthens the right to de-indexation, allowing individuals to request the cessation of dissemination of their personal information when dissemination causes them serious injury or the information is used for purposes for which consent was not given.

Breach notification: prompt reporting to the CAI

Under Law 25, an organization that has reason to believe a confidentiality incident involving personal information presents a risk of serious injury must take reasonable measures to reduce the risk and promptly notify both the Commission d’acces a l’information and the affected individuals. The statutory standard is prompt notification, with diligence. Unlike the GDPR, the Quebec Act does not set a fixed 72-hour deadline, though the CAI’s guidance and common practice have made 72 hours the working benchmark most organizations plan against. Separately, every confidentiality incident must be recorded in an incident register regardless of whether it meets the notification threshold. Meeting this standard requires a functioning breach classification and escalation process that can assess whether an incident crosses the risk-of-serious-injury threshold and move quickly, the kind of procedure a structured privacy risk management program puts in place.

What the Penalty Landscape Means for Business Risk

PIPEDA enforcement has historically been limited in its punitive reach: the Office of the Privacy Commissioner can investigate complaints, make findings and recommendations, and refer matters to the Federal Court, but the Commissioner does not have the power to impose fines directly. Bill C-27, which contained the proposed Consumer Privacy Protection Act that would have replaced PIPEDA and introduced significant financial penalties, died on the order paper when Parliament was prorogued in January 2025 and has not been reintroduced. PIPEDA therefore remains the governing federal law, and the OPC still cannot levy fines directly, which means the sharper enforcement pressure today comes from Quebec.

Quebec Law 25 penalties are already in force and are substantial. Administrative monetary penalties of up to $10 million or 2% of worldwide turnover apply for less serious violations. Penal fines of up to $25 million or 4% of worldwide turnover apply for the most serious violations, including failure to conduct required PIAs, unlawful collection or use of personal information, and failure to notify of confidentiality incidents. These are GDPR-scale consequences applied to any enterprise subject to Quebec law, which includes any organization handling personal information about Quebec residents in the context of commercial activity, regardless of where the organization is headquartered. Managing that exposure sits within the organization’s broader governance, risk and compliance function.

Understanding the laws is only half the task. The other half is building the operational program that makes compliance demonstrable, which is the difference explained in why a privacy policy is not a privacy risk management program.

PIPEDA compliance requirements vs Quebec Law 25 obligations: privacy officer, PIAs, consent, portability, and breach notification

Frequently Asked Questions

Does PIPEDA apply to my business if we are based outside Canada but serve Canadian customers?

PIPEDA applies to the collection, use, and disclosure of personal information in the course of commercial activity in Canada. The Office of the Privacy Commissioner has taken the position that the Act can apply to foreign organizations that collect personal information from Canadians in connection with commercial activity, even if the organization does not have a physical presence in Canada. Quebec Law 25 similarly applies to any enterprise that collects personal information from Quebec residents in the course of commercial activity in Quebec. Organizations that sell to Canadian customers should obtain legal advice on the applicability of Canadian privacy law to their operations.

What counts as personal information under PIPEDA?

PIPEDA defines personal information as information about an identifiable individual. This is a broad definition that includes name, address, email, phone number, financial information, health information, employee records, purchasing history, IP addresses, and any other information that, alone or in combination with other information, can be used to identify a specific person. Business contact information used for business-to-business purposes, such as a job title and work email, is excluded from PIPEDA in most circumstances. Quebec Law 25 uses a similarly broad definition but adds explicit reference to biometric characteristics as a category of sensitive personal information subject to stricter requirements.

How does PIPEDA interact with sector-specific privacy legislation?

Several sectors are subject to privacy legislation that sits alongside or supplements PIPEDA. The Personal Health Information Protection Act in Ontario governs health information custodians including hospitals, physicians, and pharmacies. The Health Information Act in Alberta covers health information custodians in that province. Financial sector organizations may be subject to OSFI guidance alongside PIPEDA obligations. The applicable framework for a specific organization depends on its sector, the nature of the personal information it handles, and the provinces in which it operates. Where sector-specific legislation applies to specific categories of information or specific activities, it typically governs those matters, with PIPEDA applying to the residual personal information not covered by the sector-specific law.

What is the Office of the Privacy Commissioner complaint process?

An individual who believes an organization has violated their privacy rights under PIPEDA can file a complaint with the Office of the Privacy Commissioner. The OPC investigates the complaint by gathering information from both the complainant and the organization, reviewing documentation, and in some cases conducting interviews. If a breach is found, the Commissioner issues a report with findings and may make recommendations. If the organization does not implement the recommendations, the Commissioner can apply to the Federal Court for a court order. The Federal Court can order compliance and award damages to the complainant. The OPC also initiates Commissioner-initiated complaints where it has reason to believe an organization may be in non-compliance, independent of individual complaints.

How do we document compliance for a PIPEDA or Law 25 audit?

Compliance documentation for a privacy audit covers eight categories of evidence: the governance structure including the designated privacy officer or person in charge and their mandate; the personal information inventory documenting what is collected, for what purposes, and where it flows; the consent records for processing activities that require consent; the individual rights request logs showing receipt, handling, and response for all requests in the period; the vendor contracts and data processing agreements for all third parties with access to personal information; the training records showing which employees received privacy training and when; the PIA documentation for new or changed processing activities; and the breach records including all incidents assessed and the notification decisions made. Organizations that maintain these records in an organized, accessible way are significantly better positioned in an audit than those who must reconstruct them.

The Bottom Line

PIPEDA and Quebec Law 25 business compliance is not satisfied by a privacy policy on your website. PIPEDA requires demonstrable accountability across ten principles, and Law 25 raises the bar with a public privacy officer, published governance, mandatory PIAs, stricter consent, new portability and de-indexation rights, prompt breach notification, and penalties that reach $25 million or 4% of worldwide turnover. Meeting both means operational infrastructure, not documentation alone. A structured privacy risk management program builds it. Start with a current-state assessment against both frameworks, then close the gaps the assessment finds.

Leave the first comment