Quebec Law 25 Compliance for Websites: What It Requires and Where Your Data Has to Live
Quebec’s Law 25 is now fully in force, and it reaches any business that handles the personal information of Quebec residents — not just companies based in Quebec. A plain-language breakdown of the obligations, the cross-border transfer rules, and what they mean for your hosting.
Law 25 Is Not "Quebec’s Version of PIPEDA" — It Goes Further
Quebec’s Law 25 (formerly Bill 64, formally An Act to modernize legislative provisions as regards the protection of personal information) rolled out in three phases from 2022 to 2024 and is now fully in force. It is the most demanding privacy regime in Canada, and it is frequently underestimated by businesses outside Quebec who assume it doesn’t apply to them.
It does. Law 25 applies to any private-sector organization that collects, holds, uses, or communicates the personal information of people in Quebec — regardless of where the business itself is located. If you run an online store in Toronto that ships to Montreal, a SaaS product in Calgary with Quebec users, or a booking site in Vancouver that takes appointments from Quebec residents, Law 25 reaches your business.
The penalties are what make it impossible to ignore: administrative monetary penalties up to $10 million or 2% of worldwide turnover, and penal fines up to $25 million or 4% of worldwide turnover — whichever is greater. These are the highest privacy penalties in Canada and are modelled on the EU’s GDPR.
The Obligations That Affect Your Website Directly
Law 25 introduced a long list of requirements. These are the ones that touch how your website and hosting are actually built:
1. A designated Privacy Officer. By default this is the person with the highest authority in the organization, but the role can be delegated. Their contact information must be published on your website.
2. Privacy by default. Any product or service with privacy settings must default to the most privacy-protective setting without the user doing anything. For a website, that means analytics, tracking, and non-essential cookies cannot be on by default — the user opts in, not out.
3. Clear, granular consent. Consent must be requested separately for each purpose, in clear and simple language, distinct from other information. Bundled or pre-checked consent is invalid — the same standard as CASL, applied to all personal information handling.
4. Transparency on collection. At the point of collection you must disclose the purposes, the means of collection, the rights of the individual, and — critically — whether the information will be communicated outside Quebec.
5. Mandatory breach reporting. Any confidentiality incident presenting a risk of serious injury must be reported to the Commission d’accès à l’information (CAI) and to affected individuals, and logged in a mandatory incident register.
6. Data portability and the right to be forgotten. Individuals can request their data in a structured, commonly used technological format, and can request de-indexing or deletion.
The Cross-Border Transfer Rule — The Part That Affects Hosting
This is the requirement most directly tied to where you host, and the one most businesses miss.
Before communicating personal information outside Quebec — which includes storing it on a server in another province or country — Law 25 requires the organization to conduct a Privacy Impact Assessment (PIA). The assessment must consider:
- the sensitivity of the information
- the purposes for which it will be used
- the protection measures (including contractual) that would apply to it
- the legal framework of the destination jurisdiction, including whether it provides protection equivalent to Quebec’s
That last point is the crux. If your Quebec users’ personal information is stored on a US server — or on a Canadian server operated by a US-headquartered company subject to the CLOUD Act — you must be able to document, in a formal assessment, that the data receives equivalent protection despite being reachable by a foreign government’s legal process.
For most small and mid-sized businesses, producing and defending that assessment for a US destination is difficult. The pragmatic answer the law effectively pushes you toward: keep the data in Quebec, or at least in Canada, under a Canadian provider not subject to foreign compulsion. When there is no cross-border transfer, the equivalency analysis becomes far simpler.
How Law 25 Interacts With PIPEDA and CASL
If you operate across Canada, you are likely subject to more than one regime at once:
- PIPEDA (federal) governs personal information handled in the course of commercial activity in most of Canada. It requires safeguards "appropriate to the sensitivity" of the data, and the Privacy Commissioner treats data residency as relevant to that assessment.
- CASL governs commercial electronic messages and the consent records behind them.
- Law 25 (Quebec) layers the strictest consent, transparency, and cross-border rules on top for any Quebec resident’s data.
Practically, you comply with the highest common denominator. If your consent flows, breach process, and hosting satisfy Law 25, they will generally satisfy PIPEDA and the data-handling side of CASL as well. Building to Law 25 is the efficient strategy for a business serving customers across the whole country.
A Practical Compliance Checklist for Your Website
### Consent and transparency
- [ ] Non-essential cookies / analytics / tracking default to off until the user opts in
- [ ] Consent requested separately per purpose, in plain language, never pre-checked
- [ ] Privacy policy discloses purposes, retention, individual rights, and whether data leaves Quebec
- [ ] Privacy Officer named with published contact details
### Data handling
- [ ] Inventory of what personal information you collect and where it is stored
- [ ] Retention schedule — data destroyed or anonymized once the purpose is fulfilled
- [ ] Process for access, correction, portability, and deletion requests
- [ ] A completed Privacy Impact Assessment for any transfer of personal information outside Quebec
### Breach readiness
- [ ] Incident response plan with roles and timelines
- [ ] Mandatory incident register maintained
- [ ] Ability to notify the CAI and affected individuals promptly
### Hosting and infrastructure
- [ ] Personal information stored on servers whose jurisdiction you can document
- [ ] Backups stored in the same jurisdiction (many providers silently replicate to US regions)
- [ ] Provider not subject to foreign legal compulsion over Canadian-stored data
- [ ] Access controls and encryption appropriate to the sensitivity of the data
Where Hosting Fits
Law 25 does not say "you must host in Quebec." What it says is that if personal information leaves Quebec, you carry the burden of assessing and documenting equivalent protection — and that becomes materially harder when the destination is the United States or a US-controlled provider.
Hosting Quebec residents’ data on Canadian infrastructure operated by a Canadian company removes the hardest part of that analysis. There is no cross-border communication to assess, no foreign-jurisdiction equivalency to defend, and no CLOUD Act exposure to disclose.
TransPark Technology operates exclusively in AWS’s Montreal region (ca-central-1). Production data, backups, and disaster recovery all remain within Canada. TransPark Technology Inc. is a Canadian corporation, not a subsidiary of a US parent — so no foreign jurisdiction has legal claim to data stored on our infrastructure. For a business working through its Law 25 cross-border assessment, that turns one of the hardest questions into a straightforward one.
Where to Start
Law 25 compliance is a governance project, not a hosting purchase — the consent flows, the Privacy Officer, the breach register, and the impact assessments are yours to build. But the data-residency question underpins several of those obligations at once, and it is the one piece you can settle decisively with an infrastructure decision.
Start by mapping what personal information you collect and where it currently lives. If any of it belongs to Quebec residents and sits on US infrastructure, that is your first and highest-leverage finding to address.
Canadian data. Canadian servers. Canadian law.
This article is general information, not legal advice. For obligations specific to your organization, consult a privacy lawyer or your Privacy Officer.