Law / Canada / Quebec

Quebec

Canada law applies in Quebec Quebec is a state of Canada, whose 16 researched instruments are listed on the Canada page, not here. The law of Quebec, described on this page below, applies here too.

All 6 named instruments researched to a stage, across one of the six areas of law we track: 6 in force. As of 24 September 2026.

  1. AI law not researched
  2. Privacy law 6
  3. Scraping law not researched
  4. Cybersecurity law not researched
  5. Age gating law not researched
  6. News aggregation law not researched

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law6 instruments, 6 in force

Research summary (211 words)

Québec's private-sector personal-information regime is the Act respecting the protection of personal information in the private sector (CQLR c P-39.1), rebuilt by the Act to modernize legislative provisions as regards the protection of personal information (S.Q. 2021, c. 25, known as Law 25), assented to September 22, 2021.

Law 25 phased in its private-sector amendments in three stages under its own section 175: the duty to designate a person in charge of protection and the confidentiality-incident notification and register regime took effect September 22, 2022; the bulk of the modernized regime, including consent, privacy impact assessments, the profiling-technology notice, the automated-decision notice and review right, cross-border transfer assessment, administrative monetary penalties, penal offences and the punitive-damages action, took effect September 22, 2023; and the right to data portability (s. 27, third paragraph) took effect September 22, 2024, completing the rollout.

The federal Personal Information Protection and Electronic Documents Act (PIPEDA) has long recognized this Québec statute as substantially similar legislation, so an organization's handling of personal information within Québec in the course of commercial activity is governed by this Act rather than by PIPEDA's own Part 1.

Biometric identifiers are reached through the sensitive personal information category and its express-consent duty rather than through a dedicated biometric-specific statute or retention schedule.

Breach notification

Confidentiality incident notification and register

CQLR c P-39.1, ss. 3.5-3.8official consolidated statute text, LégisQuébec (Éditeur officiel du Québec)

In force since 22 September 2022. Binds private bodies.

What this law does

A person carrying on an enterprise who has cause to believe that a confidentiality incident involving personal information the person holds has occurred must take reasonable measures to reduce the risk of injury and to prevent further incidents of the same nature. A confidentiality incident is access, use or communication of personal information not authorized by law, or the loss of personal information, or any other breach of its protection.

Where the incident presents a risk of serious injury, judged by the sensitivity of the information, the anticipated consequences and the likelihood of injurious use, the enterprise must promptly notify the Commission d’accès à l’information and each affected person, and must keep a register of confidentiality incidents, a copy of which must be sent to the Commission on request.

What it requires

Comprehensive regime

Act respecting the protection of personal information in the private sector, comprehensive regime

CQLR c P-39.1, ss. 3.1-3.4, 8.1, 12-14official consolidated statute text, LégisQuébec (Éditeur officiel du Québec)

In force since 22 September 2023. Binds private bodies.

What this law does

Any person carrying on an enterprise in Québec must designate a person in charge of the protection of personal information, by default the enterprise's own highest-ranking officer, and publish that person's title and contact information.

The enterprise must establish and implement governance policies and practices for personal information, covering retention and destruction, and must conduct a privacy impact assessment before acquiring, developing or overhauling an information system or electronic service delivery system that collects, uses, communicates, keeps or destroys personal information.

Consent to use or communicate personal information for a new purpose must be clear, free, informed, requested for each specific purpose and given expressly where the information is sensitive. A person who collects personal information using technology that can identify, locate or profile the individual must first disclose the use of that technology and how to activate its identifying, locating or profiling functions.

The duty to designate a person in charge took effect a year earlier than the rest of this row, on September 22, 2022; the governance-policy, privacy impact assessment, technology-notice and consent duties took effect September 22, 2023. The consent and use rules of this row do not reach personal information that is public by law.

What it requires

Cross border transfer

Privacy impact assessment before communicating personal information outside Québec

CQLR c P-39.1, s. 17official consolidated statute text, LégisQuébec (Éditeur officiel du Québec)

In force since 22 September 2023. Binds private bodies.

What this law does

Before communicating personal information outside Québec, or entrusting a person or body outside Québec with collecting, using, communicating or keeping personal information on its behalf, a person carrying on an enterprise must conduct a privacy impact assessment weighing the sensitivity of the information, the purposes for which it will be used, the protection measures that would apply including contractual ones, and the legal framework applicable in the destination jurisdiction.

The communication must be the subject of a written agreement reflecting the assessment's results and any risk-mitigation terms. This duty does not reach personal information that is public by law.

What it requires

Data subject rights

Automated decision-making notice and review right

CQLR c P-39.1, s. 12.1official consolidated statute text, LégisQuébec (Éditeur officiel du Québec)

In force since 22 September 2023. Binds private bodies.

What this law does

A person carrying on an enterprise who uses personal information to render a decision based exclusively on automated processing of that information must inform the person concerned of that fact no later than when the decision itself is communicated.

On request, the enterprise must also disclose the personal information used to render the decision, the reasons and the principal factors and parameters that led to it, and the person's right to have that personal information corrected, and must give the person an opportunity to submit observations to a staff member able to review the decision. This right was newly created by Law 25 and did not exist in the Act before September 22, 2023.

What it requires

Enforcement supervision

Commission d’accès à l’information supervision, administrative and penal sanctions, punitive damages

CQLR c P-39.1, ss. 90.1-90.17, 91-93, 93.1official consolidated statute text, LégisQuébec (Éditeur officiel du Québec)

In force since 22 September 2023. Binds private bodies.

What this law does

The Commission d’accès à l’information, the same body established under the Act respecting Access to documents held by public bodies and the Protection of personal information, oversees and enforces this Act.

A person designated by the Commission may impose a monetary administrative penalty of up to $50,000 on a natural person and, in any other case, up to $10,000,000 or, if greater, 2% of worldwide turnover for the preceding fiscal year, for a failure such as not informing persons concerned as required, unlawfully collecting, using, communicating, keeping or destroying personal information, or not reporting a confidentiality incident.

The same conduct, prosecuted as a penal offence, carries a fine of $5,000 to $100,000 for a natural person and, in any other case, $15,000 to $25,000,000 or, if greater, 4% of worldwide turnover for the preceding fiscal year. Separately, a court that finds an unlawful infringement of a right under this Act, or under articles 35 to 40 of the Civil Code, causing injury and either intentional or resulting from gross fault, must award punitive damages of not less than $1,000.

What it requires

Sensitive categories

Express consent for sensitive personal information

CQLR c P-39.1, ss. 12-13official consolidated statute text, LégisQuébec (Éditeur officiel du Québec)

In force since 22 September 2023. Binds private bodies.

What this law does

Personal information is sensitive, for the purposes of this Act, if due to its nature, in particular its medical, biometric or otherwise intimate nature, or the context of its use or communication, it entails a high level of reasonable expectation of privacy.

Consent to use sensitive personal information for a purpose other than the one for which it was collected, and consent to communicate sensitive personal information to a third person, must each be given expressly rather than being inferred from conduct or a general privacy notice.

What it requires

Reporting clocks that run here2 instruments

The instruments whose obligation lines set a deadline for reporting an incident, a vulnerability or a personal-data breach, each deadline read from the sentence that carries it and listed shortest first. The law of Quebec comes first, then the law of the bodies above it that applies here.

The law of Quebec

promptly

Confidentiality incident notification and register

CQLR c P-39.1, ss. 3.5-3.8privacy law, in force since 22 September 2022

The sentence the clocks are read from

Where the incident presents a risk of serious injury, judged by the sensitivity of the information, the anticipated consequences and the likelihood of injurious use, promptly notify the Commission d’accès à l’information and each person whose personal information is concerned.

The law of Canada, which applies in Quebec

as soon as feasible

PIPEDA breach of security safeguards regime

S.C. 2000, c. 5, ss. 10.1-10.3privacy law, in force since 1 November 2018

The sentence the clocks are read from

Report any breach of security safeguards involving personal information under the organization's control to the Privacy Commissioner as soon as feasible, if it is reasonable to believe the breach creates a real risk of significant harm to an individual.

Which of these one incident starts turns on the facts: the incident method works that through. The clocks document draws every clock in the corpus on one axis, with the sentence beside every rung.

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.