Skip to main content
Dark green background, "Weak Application Security Can Cost You Millions," 3 slanted images of fingers pointing to digital locks, and a "Learn the Basics" button
Quebec's Law 25 Rollout: What Went Wrong in Year OneLaws and Regulations
4 min readFor Compliance Managers

Quebec's Law 25 Rollout: What Went Wrong in Year One

Between September 2022 and September 2023, Quebec's Law 25 transitioned from statute to enforcement. Despite clear deadlines, many organizations missed foundational requirements in the first year. Here's what happened, which controls failed, and what your team needs to do differently.

What Happened

Quebec enacted Law 25 in September 2021 with a three-year rollout. The first compliance deadline in September 2022 required three actions: appoint a Data Protection Officer (DPO), disclose biometric data processing to the Quebec data protection commission, and implement an incident response plan.

Many enterprises treated these as administrative tasks rather than operational mandates. By September 2023, when the second wave of requirements took effect, organizations faced a compounding problem: they hadn't built the governance infrastructure needed for data subject requests, privacy impact assessments, or cross-border transfer controls.

The penalty structure is costly. Administrative fines can reach $10 million CAD or 2% of worldwide turnover, whichever is greater. Penal fines range from $15,000 CAD to $25 million CAD or 4% of worldwide turnover.

Timeline

September 2021: Law 25 enacted with phased implementation schedule

September 2022: First compliance deadline

  • DPO appointment required
  • Biometric data disclosure to commission required
  • Incident response plan required

September 2023: Second compliance deadline

  • Legal basis documentation required
  • Public privacy policy required
  • Internal data protection governance policies required
  • Data subject request response procedures required
  • Privacy impact assessments required
  • Cross-border transfer controls required

September 2024: Final compliance deadline

  • Right to portability required

Which Controls Failed or Were Missing

The most common failure wasn't technical. Organizations appointed someone with a "DPO" title but didn't give them authority, resources, or cross-functional access. Section 3.1 requires a real DPO function, not just a renamed compliance analyst.

The incident response requirement under Section 3.5 exposed another gap. Many teams had breach notification procedures but lacked the confidentiality incident framework Quebec requires. A confidentiality incident under Law 25 triggers when personal information is accessed, used, or communicated without authorization, whether or not it constitutes a "breach" under other frameworks.

Biometric disclosure under Section 45 caught organizations off guard. If you verify identity using biometric characteristics or maintain a biometric database, you must notify the commission. Several enterprises discovered in year two that their authentication systems fell within scope.

By September 2023, the governance gap became critical. Section 3.2 requires documented data protection governance policies, not just a privacy policy for users, but internal policies governing how your organization handles personal information. Organizations that skipped the DPO appointment in year one had no one driving this documentation.

What the Relevant Standard Requires

Law 25 doesn't distinguish between controllers and processors. Instead, it uses three terms: "persons carrying on an enterprise," "person," and "person or body." Each provision specifies which term applies, changing who must comply.

The DPO requirement under Section 3.1 applies to "any person carrying on an enterprise." That DPO must ensure compliance with the Law. This isn't a ceremonial role, it's an accountability function.

Personal information is broadly defined under Section 2: "any information which relates to a natural person and allows that person to be identified." This sweeps wider than GDPR's definition and includes identifiers many organizations treat as pseudonymous.

The data subject request provisions in Sections 30, 32, 33, 34, 35, and 39 require response mechanisms for access, correction, and deletion. Section 27 adds portability rights effective September 2024. These are mandatory operational capabilities.

Cross-border transfers under Section 17 require compliance with Law and regulations when personal information leaves Quebec. This intersects with privacy impact assessment requirements in Sections 3.2 and 17, creating a documentation burden many teams underestimated.

Lessons and Action Items for Your Team

Treat the DPO appointment as infrastructure, not paperwork. Your DPO needs budget, cross-functional authority, and executive access. If you appointed someone in 2022 but they can't convene legal, IT, and business stakeholders, you haven't met the requirement.

Build a confidentiality incident taxonomy. Don't assume your existing breach response plan covers Section 3.5. Map out what constitutes unauthorized access, use, or communication of personal information in your environment. Document escalation paths and commission notification triggers.

Audit biometric processing now. Section 45 disclosure isn't one-and-done. If you've added authentication methods, identity verification systems, or employee monitoring tools since September 2022, review whether they trigger disclosure obligations.

Document your governance policies before the next audit cycle. Section 3.2 requires policies governing data protection practices. This means written procedures for collection, retention, deletion, access controls, and vendor management. If your DPO can't produce these on request, you're non-compliant.

Map your data subject request workflow. Sections 30-39 create multiple request types with different response obligations. Build a triage system that routes access requests, correction requests, and deletion requests to the right team with the right SLA.

Prepare for portability by September 2024. Section 27 requires you to communicate personal information to the individual or to a third party they designate. This isn't the same as providing a data export, it requires structured, machine-readable formats. Start designing this capability now.

Use Quebec as a compliance baseline, not an exception. Law 25's penalty structure mirrors GDPR. Its requirements overlap with CPRA, LGPD, and PIPEDA. If you build governance infrastructure to meet Quebec's standard, you're building transferable compliance capabilities.

The three-year rollout was meant to ease implementation. Instead, it revealed how many organizations lack basic data protection infrastructure. If you missed deadlines in years one or two, the September 2024 portability requirement won't be easier, it'll be harder, because it depends on the governance foundation you should have built in 2022.

Promotional banner for the Penetration Report Template Kit

You Might Also Like