Quebec Law 25 for SaaS: The Privacy Law Startups Ignore Until Procurement Asks
By Laith Sarhan
Data Protection & Cybersecurity Product Counsel
Every SaaS privacy roadmap has the same blind spot: the team builds for GDPR and CCPA, assumes Canada means PIPEDA, and discovers Quebec's Law 25 for the first time inside a procurement questionnaire — usually phrased as "confirm your compliance with Quebec's Act respecting the protection of personal information in the private sector, as modernized." By then the scramble is expensive, because Law 25 is not a lighter Canadian GDPR or a provincial footnote. It's the strictest private-sector privacy law in North America on several dimensions, it's fully in force as of September 2024, and it has no revenue or data-volume thresholds. If a Quebec resident's personal information flows through your product in the course of carrying on an enterprise, you're in scope.
Why Law 25 Keeps Ambushing US and Canadian SaaS Companies
Three reasons it gets missed. First, the naming: you'll see it called Bill 64, Law 25, Act 25, and "the modernized Private Sector Act" — often in the same document. Second, the phased rollout meant companies checked in 2022 or 2023, saw partial obligations, and never came back for the rest. Third, the substantially-similar confusion: because Quebec's law is deemed substantially similar to PIPEDA, teams assume "PIPEDA-compliant" covers Quebec. It doesn't — Law 25 is stricter than PIPEDA on almost every operational point, and it applies directly to you, not as an overlay.
The rollout is complete: Phase 1 (September 22, 2022) brought the privacy officer requirement, breach notification, and foundational obligations; Phase 2 (September 22, 2023) brought the majority — enhanced consent, privacy impact assessments, individual rights, transparency, automated-decision rules, enforcement powers, and the private right of action; Phase 3 (September 22, 2024) switched on data portability. All of it applies now.
The Seven Provisions That Hit SaaS Companies Hardest
1. Privacy officer by default (s. 3.1). Every organization in scope has a designated "person in charge of the protection of personal information" — and by default, it's the person with the highest authority. Your CEO, unless the responsibility is formally delegated in writing. The officer's title and contact information must be published on your website. For a ten-person startup this is a minor administrative task; for a company that ignored it, it's the first thing a CAI (the Quebec regulator) checklist flags.
2. Privacy impact assessments (s. 3.3). A PIA is mandatory before any project to acquire, develop, or redesign an information system or electronic service delivery that involves personal information — which for a SaaS company means your product roadmap, not just internal IT. PIAs are also required before communicating personal information outside Quebec (including entrusting it to a processor outside Quebec). If you're shipping AI features on Quebec user data without a PIA, this is the provision that names you.
3. Consent that's actually granular (ss. 8–9). Law 25 consent must be clear, free, informed, and given for specific purposes — presented separately from other information, in simple language. Bundled consent ("by using our service you agree to everything in this policy") fails the standard. So does the US pattern of notice-and-opt-out: the default is opt-in, and for sensitive information, consent must be express.
4. Automated decision transparency (s. 12.1). If you use personal information to make a decision exclusively through automated processing — credit-style scoring, automated eligibility, algorithmic gating with no human in the loop — you must inform the individual, and on request tell them the personal information used, the reasons, and the principal factors that led to the decision, plus give them a chance to submit observations. Any SaaS product with fully automated user-affecting decisions needs this workflow.
5. Breach notification with teeth (s. 3.5). "Confidentiality incidents" that present a risk of serious injury must be reported promptly to the CAI, and affected individuals must be notified, with reasonable measures taken to reduce harm and prevent recurrence. "Promptly" is deliberately undefined — sit on it and you're arguing about reasonableness after the fact.
6. Data portability (s. 27). Individuals can demand their personal information in a structured, commonly used technological format. If your product can't export a user's data in a usable format, this is now a legal gap, not a product nicety.
7. Cross-border assessment before data leaves Quebec (s. 17). Before communicating personal information outside Quebec — including to your own US infrastructure or a US processor — you must conduct a PIA that considers whether the information will receive adequate protection where it's going, and the transfer must be governed by a written agreement. US CLOUD Act exposure is the standard issue raised here, and Quebec enterprise buyers ask about it explicitly.
The Enforcement Stack
Law 25's penalty architecture is the most aggressive in Canada:
- Administrative monetary penalties: up to $10M or 2% of worldwide turnover (whichever is greater)
- Penal fines: up to $25M or 4% of worldwide turnover
- Private right of action: individuals can sue directly, with a $1,000 statutory minimum in damages per person — no proof of actual harm required for the floor
That third item is what makes Law 25 structurally different from PIPEDA for risk purposes. PIPEDA exposure runs primarily through the regulator; Law 25 lets a class of users come to you directly, with a statutory floor that makes small claims aggregate into real numbers fast.
What Procurement Actually Asks
Quebec enterprise buyers — and national buyers with Quebec operations — now ask, in roughly this order: who is your designated privacy officer; have you conducted PIAs covering the processing you'll do for us; what are your consent mechanisms for end-users; where is data hosted and has a cross-border assessment been done for any processing outside Quebec; what's your incident notification commitment; and can individuals exercise access, rectification, deletion, and portability rights through defined workflows. A SaaS company that can answer with documents closes faster than one drafting answers live in a questionnaire.
The Practical Build Order
- Designate (in writing) and publish your privacy officer — a day of work.
- Stand up a PIA process keyed to your product roadmap — a template, an owner, and a rule that no feature ships without one where personal information is involved.
- Rebuild consent flows to Law 25 granularity for Quebec users (or adopt the Law 25 standard globally — it's usually cheaper than geo-fencing consent).
- Add an automated-decision disclosure and response workflow if any feature makes exclusively automated user-affecting decisions.
- Add portability export if you don't have it.
- Run the s. 17 cross-border assessment for your hosting/processor map and paper the agreements.
- Update your DPA template to reference Law 25 explicitly — Quebec buyers look for it by name.
Last updated: August 2026. This article is educational and does not constitute legal advice. Law 25's application is fact-specific; the CAI's guidance (much of it in French) is the authoritative interpretive source.
FAQ
Does Quebec Law 25 apply to companies outside Quebec?
Yes. Law 25 applies to any private-sector organization — including those outside Quebec and outside Canada — that collects, holds, uses, or communicates personal information of individuals in Quebec in the course of carrying on an enterprise. There are no revenue, employee-count, or data-volume thresholds. A SaaS company with Quebec users is generally in scope.
What is the Law 25 privacy officer requirement?
Section 3.1 designates the person with the highest authority in the organization (e.g., the CEO) as the default "person in charge of the protection of personal information." The role can be delegated in writing, wholly or partly, to another person. The officer's title and contact information must be published on the organization's website.
What are the penalties under Law 25?
Administrative monetary penalties up to $10M or 2% of worldwide turnover; penal fines up to $25M or 4% of worldwide turnover; and a private right of action with a $1,000 statutory minimum in damages per individual — the most aggressive privacy enforcement stack in Canada.
Do I need a privacy impact assessment under Law 25?
Yes, in defined cases: before any project to acquire, develop, or redesign an information system or electronic service delivery involving personal information (s. 3.3), and before communicating personal information outside Quebec (s. 17), which requires assessing whether the destination provides adequate protection and papering the transfer with a written agreement.