Framework · Law 25
Law 25: PIAs, incidents, access and portability, documented
Québec's private-sector privacy law, in full force since September 2023: privacy impact assessments, confidentiality incidents, access rights and portability.
Law 25, the Act to modernize legislative provisions as regards the protection of personal information, introduced the most significant overhaul of provincial privacy legislation in Canada in decades. It has been in full force since September 2023 and the Commission d'accès à l'information (CAI) has issued its first enforcement actions. It applies to enterprises collecting personal information in Québec, and its obligations differ meaningfully from federal PIPEDA obligations.
Key facts
- September 2023: full enforcement; all obligations, including PIAs, incident notification and portability, apply.
- 30 days: response deadline for access and rectification requests.
- PIA: privacy impact assessment required before any project involving personal information and before any communication outside Québec.
- CAI: notification of confidentiality incidents presenting a risk of serious injury, with diligence, and an incident register.
What Law 25 requires
Law 25 introduced some of the most stringent privacy obligations in Canada.
- Designation of a person in charge of the protection of personal information, whose title and contact information are published
- Privacy impact assessment before any project involving personal information and before any communication outside Québec
- Consent: collection, use and withdrawal documented; privacy by default and collection limited to what is necessary
- Confidentiality incidents: notification to the CAI and affected individuals where there is a risk of serious injury, incident register
- Individual rights: access and rectification within 30 days, withdrawal of consent, cessation of dissemination
- Portability: computerized personal information collected from the individual, communicated in a structured technological format
What Sentrix provides for Law 25
Privacy impact assessment (PIA)
Sentrix provides bilingual PIA templates aligned with CAI guidance, routes assessments to the appropriate reviewers, captures sign-off, tracks remediation of identified risks and retains every assessment as audit evidence. An alert fires when a new project triggers a PIA.
Confidentiality incident response
CAI notification workflow, affected person letter templates in French and English, incident register maintained automatically and documentation stored in the format the CAI expects. Built-in severity scoring evaluates each incident against the criteria of the Act.
Data subject request management
Access, rectification, and portability requests tracked with a 30-day response deadline. Request log maintained as evidence, reminders before deadlines, response documentation archived.
Privacy by default
Sentrix monitors your data collection practices, flags integrations that collect unnecessary personal information, and documents your privacy-by-default settings.
Bilingual documentation
All PIAs, policies, incident notices and audit packages are available in French and English, as required for Québec organizations and public bodies governed by the Act.
Accountability to the CAI
The CAI has broad powers to investigate, audit, and sanction. Sentrix provides the evidence repository, audit trails, and dashboards the person in charge needs to demonstrate accountability on demand.
Crosswalks
- PIPEDA: crosswalk between Law 25 obligations and the ten federal principles, for organizations subject to both regimes.
- GDPR: significant overlap (consent, PIA and DPIA, incident notification, data subject rights) for organizations with EU customers.
- TGV: TGV's PRP domain shares Law 25 requirements for health network suppliers.
- HIPAA: incident classification for healthcare organizations operating in Québec and the United States.
- ISO 27001: many Annex A controls address the personal information protection outcomes of the Act.
Further reading
Article: Law 25, the review. Public body or municipality: public sector solution.
See your Law 25 compliance posture in real time.
Frequently asked questions
- What is Law 25?
- Law 25, the Act to modernize legislative provisions as regards the protection of personal information, reformed Québec's private-sector privacy law. In full force since September 2023, it requires a designated person in charge, privacy impact assessments, confidentiality incident management, privacy by default and new rights for individuals, under the oversight of the Commission d'accès à l'information (CAI).
- When is a privacy impact assessment required?
- A PIA is required before any project to acquire, develop or redesign a system involving personal information, and before any communication of personal information outside Québec. Sentrix provides bilingual PIA templates aligned with CAI guidance, routes assessments to the right reviewers, records sign-off and keeps every assessment as audit evidence.
- What must be done after a confidentiality incident?
- When a confidentiality incident presents a risk of serious injury, the organization must notify the CAI and the affected individuals with diligence, and keep a register of all incidents. Sentrix automates the workflow from detection through risk assessment, notice drafting and communication to affected individuals, with letter templates in French and English and a register maintained automatically.
Related pages
Framework · PIPEDA
PIPEDA: ten principles, enforceable obligations
Canada's federal private-sector privacy law: ten fair information principles, breach reporting to the Privacy Commissioner and the bridge to GDPR adequacy.
Framework · GDPR
GDPR: Article 32, DPIAs and data subject rights, all mapped
The EU regulation for any organization processing data of EU residents: lawful basis, DPIAs, data subject rights, Article 32 measures and processor contracts.
Framework · TGV
TGV: four domains, one BCH certification dossier
The BCH/MSSS Trousse globale de vérification for technological products and services in Québec's health and social services network: four evaluation domains.
Framework · HIPAA
HIPAA continuous. Not HIPAA compliant once a year.
The Security Rule, Privacy Rule and Breach Notification Rule of the US HIPAA law, for covered entities and their business associates, monitored continuously.
Framework · ISO 27001:2022
ISO 27001:2022: from ISMS to certification in one program
The international standard for information security management systems: clauses 4 to 10, 93 Annex A controls, and a two-stage certification audit.
Let's talk about your compliance program.
Last updated: 2026-09-17
