Law 25 carries two separate penalty tracks, and the numbers that make headlines — $10 million, $25 million, "4% of worldwide turnover" — are ceilings for the largest organizations and the most serious violations, not the realistic outcome for a small Quebec business's first compliance gap. Understanding the actual structure behind those numbers, rather than just the scary top line, is what lets a business owner make a rational decision about how much time and money to put into compliance.
Quebec's Law 25 (the Act respecting the protection of personal information in the private sector, formerly known as Bill 64) rolled out its provisions in phases between 2022 and 2024, and its penalty regime is genuinely one of the toughest in North America on paper. That toughness is exactly why the topic generates so much anxiety among small business owners who hear "$25 million fine" in a news headline and assume it applies to them the same way it would apply to a bank or a national retailer. It doesn't — and this guide exists to explain precisely why, using the actual mechanics of the penalty structure rather than fear-based generalities.
This article walks through exactly how Law 25 penalties are structured, what specifically triggers them, what's publicly known (and not yet known) about how the CAI has been enforcing the law since it came into force, honest size-adjusted examples that show what exposure actually looks like for a business your size, and a concrete plan for reducing your risk without needing an enterprise compliance budget.
Who wrote this guide
This article was written and reviewed by IT Cares certified technicians who work directly with Quebec small and mid-sized businesses on the practical side of Law 25 compliance — privacy impact assessments, incident response processes, access controls. We're not a law firm and this isn't legal advice; for a specific penalty determination or legal risk opinion, consult a lawyer. What we can offer is an accurate, calibrated explanation of the penalty framework and the practical controls that reduce real-world risk.
The Two-Tier Law 25 Penalty Structure, Explained Precisely
Law 25's monetary penalty regime works on two separate tracks, and mixing them up is the single most common source of confusion when people talk about "Law 25 fines."
Track 1: Administrative Monetary Penalties (AMPs)
Administrative monetary penalties are issued directly by the Commission d'accès à l'information du Québec (CAI) — the provincial privacy regulator — without requiring a criminal prosecution. Think of this track as functioning somewhat like a regulatory fine from a tax authority or a professional order: the CAI investigates, determines a violation occurred, and can impose a penalty directly as part of its regulatory authority. For an organization (as opposed to an individual), the maximum AMP is $10,000,000 CAD or 2% of worldwide turnover for the preceding fiscal year, whichever amount is greater. This is the track most compliance failures — a missed mandatory PIA, an inadequate consent process, a late or absent breach notification — would realistically fall under if the CAI decides to penalize rather than simply order corrective action.
Track 2: Penal Fines
Penal fines are reserved for the most serious offences and require an actual prosecution through Quebec's court system rather than a direct regulatory penalty. This track covers things like knowingly and deliberately misusing personal information, obstructing a CAI investigation, or other conduct that rises to a level Quebec's legislature decided deserved the weight of a criminal-style proceeding rather than a purely administrative one. For an organization, the maximum penal fine is $25,000,000 CAD or 4% of worldwide turnover for the preceding fiscal year, whichever amount is greater. This is the number that generates the scariest headlines, and it is genuinely a large number — but it applies to a narrower, more serious category of violation, prosecuted through a slower, more procedurally protected court process, not a first-offence paperwork gap.
The detail that changes everything for a small business
Both maximums use a "flat dollar amount OR a percentage of worldwide turnover, whichever is greater" formula. For a company with billions in global revenue, the percentage figure (2% or 4%) is what actually applies and can genuinely reach into the tens of millions. For a business with, say, $3 million in annual revenue, 2% of turnover is $60,000 — a meaningful amount, certainly, but nowhere near the $10 million ceiling that headline coverage tends to lead with. Small businesses are not exempt from penalties, but the realistic dollar exposure scales down dramatically with company size, which is the single most important nuance missing from most Law 25 fine coverage.
Want an honest read on your Law 25 exposure?
Our certified technicians review your actual data practices and give you a right-sized compliance plan — from $119.99.
| Violation type | Penalty type | Maximum amount (organization) | Who issues it |
|---|---|---|---|
| General compliance failures (e.g. missed PIA, inadequate consent, late breach notice) | Administrative Monetary Penalty (AMP) | $10,000,000 CAD or 2% of worldwide turnover, whichever is greater | CAI directly (no court required) |
| Most serious offences (e.g. deliberate misuse, obstruction of investigation) | Penal fine | $25,000,000 CAD or 4% of worldwide turnover, whichever is greater | Quebec courts, following CAI referral/prosecution |
| For context: EU equivalent regime | GDPR administrative fine | €20,000,000 or 4% of global annual turnover, whichever is greater | National data protection authority (EU) |
| Individual (non-organization) violations under Law 25 | AMP or penal fine, individual scale | Lower flat-dollar maximums than organizations (no turnover percentage applies to individuals) | CAI or Quebec courts depending on track |
What Actually Triggers a Law 25 Penalty
Penalties don't appear out of nowhere — they follow specific, identifiable compliance failures. The most common triggers that show up in the law's structure and in how the CAI has publicly described its enforcement priorities include:
- Failure to report a confidentiality incident presenting a risk of serious injury. Law 25 requires organizations to notify the CAI and affected individuals of a "confidentiality incident" — a breach, unauthorized access, or loss of personal information — when it presents a risk of serious injury, without unreasonable delay. Sitting on a known incident, or failing to assess whether one meets the reporting threshold at all, is one of the most direct penalty triggers.
- Failure to conduct a mandatory Privacy Impact Assessment (PIA). Any project involving the acquisition, development, or overhaul of an information system or electronic service delivery project that involves personal information legally requires a PIA under Law 25. Skipping this step on a qualifying project is a documented, relatively easy-to-establish compliance gap. Our Law 25 vs PIPEDA comparison guide covers this mandatory-PIA trigger in more detail.
- Failure to obtain valid, specific consent. Consent that's buried in general terms of service, bundled with unrelated permissions, or not clearly separated from other agreements doesn't meet Law 25's standard, which requires consent to be clear, free, and informed, and given for specific purposes.
- Non-compliance with a CAI order. If the CAI investigates and issues a formal order — to correct a practice, provide information, or take a specific remedial action — failing to comply with that order is itself a separate and serious violation, often treated more severely than the underlying issue that triggered the investigation.
- Failure to designate a privacy officer. Law 25 requires organizations to have a person responsible for the protection of personal information — by default, this falls to the most senior officer in the organization unless formally delegated elsewhere, and the role (and how to reach that person) must be identifiable.
- Selling or communicating personal information without proper authority. Improperly transferring, selling, or disclosing personal information outside what the law and the individual's consent permit is treated as a serious violation, particularly when done knowingly.
📊 IT Cares field note: Almost every Quebec small business we've worked with on Law 25 readiness had at least one clear gap in this list — most commonly a missing or informal privacy officer designation and no PIA process at all for new systems. None of these gaps require expensive infrastructure to close; they require someone to actually own the task and follow a documented process, which is often the real missing piece rather than money.
What's Publicly Known About CAI Enforcement So Far
Here's where it's important to be precise rather than speculative. Law 25's monetary penalty provisions rolled out in phases, with the most significant obligations — including the private right of action and the full AMP framework — reaching full effect over 2023 and 2024. That means the enforcement track record is still relatively young compared to a regime like GDPR, which has been generating publicly reported penalty decisions since 2018.
What can be said with confidence: the CAI has been actively conducting investigations, issuing orders, and publishing guidance since Law 25's provisions came into force, and its public communications signal an intent to use its full toolkit — including monetary penalties — as the enforcement track record matures. This mirrors a pattern seen with essentially every new privacy regime: a period of guidance, warnings, and investigation-driven orders in the earliest phase, followed by a gradual increase in visible monetary penalties as the regulator builds internal capacity and legal precedent. GDPR followed a similar arc — its first several years produced relatively few large fines compared to the pace seen once enforcement matured.
What this article will not do is invent a specific dollar figure and attribute it to a specific named company as though it were a confirmed, published CAI penalty decision — doing so would misinform readers making real compliance decisions. If you're researching this topic for legal or compliance purposes, the CAI's own published decisions and enforcement reports (available through cai.gouv.qc.ca) are the authoritative source for confirmed penalty amounts, and that list will continue to grow over time.
It also helps to understand the phased rollout, because it explains why the enforcement record looks the way it does. Law 25's provisions didn't all take effect on a single date — they came into force in stages between September 2022 and September 2024, starting with the privacy officer designation requirement and confidentiality incident notification obligations, followed later by the mandatory PIA requirement, the private right of action, and the consent and data portability provisions. This staged approach is common in major regulatory overhauls precisely because it gives organizations time to adjust before the full weight of the law, including its toughest penalty provisions, becomes fully enforceable. It also means that penalty activity tied to the newest provisions has had the least time to accumulate into a visible public record, which is part of why so much of the conversation around "real Law 25 fines" remains, for now, more about structure and pattern than a long list of concluded cases.
Beyond the Fine: Other Real Costs of a Law 25 Violation
Monetary penalties are only one part of the financial picture, and in many real-world cases, they aren't even the largest cost a business faces after a serious privacy incident or compliance failure. A complete risk picture should account for several other costs that often dwarf the penalty itself:
- The private right of action. Law 25 created a private right of action allowing individuals to sue for damages resulting from a violation of the law, including a statutory minimum for cases involving an unlawful infringement of a right conferred by the Act. This opens the door to civil claims entirely separate from any CAI-imposed penalty, and Quebec's class action framework makes it realistic for a widescale incident to become a class proceeding rather than a series of individual claims.
- Breach notification and remediation costs. Notifying affected individuals, offering credit monitoring where appropriate, forensic investigation to determine the scope of an incident, and legal counsel fees during an investigation routinely cost more than a modest AMP for a small or mid-sized business, even before any penalty is factored in.
- Reputational damage and client attrition. For a professional services firm, a clinic, or any business built on client trust, a publicized privacy failure can cost far more in lost business over the following year than any single fine — this is especially true in tight-knit local and professional communities where word travels fast.
- Cyber insurance implications. A documented Law 25 compliance failure can affect a business's ability to renew cyber insurance coverage on favourable terms, or at all — insurers increasingly ask about privacy compliance posture directly during underwriting, a topic covered in more depth in our cyber insurance guide for small business.
Taken together, this is the strongest practical argument for proactive compliance: even in a scenario where the CAI-imposed monetary penalty itself turns out to be modest for a small business, the surrounding costs — legal, remediation, reputational, insurance — are frequently the larger and more painful part of the bill, and none of them are mitigated by the fact that the AMP itself was smaller than the headline maximum.
The Desjardins breach: important context, not a Law 25 case
The 2019 Desjardins data breach — in which the personal information of millions of members was compromised, largely through the actions of a malicious insider — is one of the most significant privacy incidents in Quebec's history and directly helped drive momentum toward Law 25's creation. It's worth understanding as context, but it's important to be accurate: the breach itself substantially predated Law 25's current penalty regime, so the legal and regulatory consequences Desjardins faced were shaped by the privacy law framework that existed at the time, not by Law 25's AMP/penal fine structure. A comparable incident occurring today, under the current regime, would be evaluated against Law 25's mandatory incident reporting requirements and its administrative and penal penalty tracks — which is precisely why the Desjardins case is often cited as an example of the kind of scenario the current penalty structure was designed to address more forcefully.
Illustrative Scenarios: What Realistic Exposure Looks Like by Company Size
To make the "percentage of turnover" mechanism concrete, here are three clearly illustrative, hypothetical scenarios — not real CAI cases — showing how the same category of violation produces very different realistic dollar exposure depending on company size. These are designed to help you reason about your own exposure, not to predict an actual outcome for any real case.
Illustrative scenario 1 — a $2M-revenue Quebec professional services firm
Suppose a small Quebec accounting firm with roughly $2 million in annual revenue launches a new client portal for document sharing and tax filing, without conducting the mandatory PIA that Law 25 requires for any project involving the development of an information system handling personal information. A client later files a complaint after noticing another client's documents briefly visible due to a permissions misconfiguration, and the CAI opens an investigation. It finds the PIA was never done and the permissions issue would likely have been caught had one been conducted. Two percent of $2 million is $40,000 — that's the realistic order of magnitude for the "percentage of turnover" side of the formula, well below the $10 million ceiling, though the CAI could still impose a higher flat-dollar penalty depending on severity, prior history, and cooperation, or could instead issue a corrective order requiring the firm to complete a retroactive PIA and fix its access controls within 60 days. The point: for a business this size, "Law 25 fine" realistically means tens of thousands of dollars in a serious first case, not millions — and a well-handled, cooperative response can shift the outcome toward correction rather than penalty entirely.
Illustrative scenario 2 — a $15M-revenue Quebec retailer
Suppose a mid-sized Quebec retail chain with $15 million in annual revenue detects unusual activity on its e-commerce platform suggesting a credential-stuffing attack may have exposed customer loyalty account data, including partial payment information. Internal IT flags the anomaly within days, but because there's no formal incident response process and no one is clearly designated to make the "does this meet the reporting threshold" call, the assessment and reporting to the CAI happens six weeks later than it should have — well past what would be considered "without unreasonable delay" for an incident presenting a risk of serious injury. Two percent of $15 million is $300,000 — a genuinely painful number for a business this size, illustrating why mid-sized companies with real revenue at stake shouldn't treat Law 25 as a small-business-only concern the way the smallest scenario above might suggest, and why the incident response process itself (not just having good security) is part of what regulators evaluate.
Illustrative scenario 3 — a $500M-revenue national company
Suppose a large national company with $500 million in worldwide turnover is found, through a CAI investigation, to have knowingly sold customer personal information to a third-party data broker without proper consent, over an extended period, despite internal staff raising concerns about the practice — a Track 2 penal-fine-level violation given the knowing and deliberate nature of the conduct. Four percent of $500 million is $20,000,000, approaching the $25 million ceiling. This is the scale of organization and severity of conduct where the eye-catching maximum figures genuinely start to apply as realistic exposure rather than theoretical worst-case numbers, and where the prosecutorial (rather than purely administrative) track becomes the more likely enforcement path given the deliberate nature of the violation.
The consistent pattern across all three: the percentage-of-turnover mechanism means the law's bite scales with the size of the organization being penalized, which is a deliberate and common design choice in modern privacy regulation (GDPR uses the identical logic). It does not mean small businesses are exempt — a genuinely serious violation can still draw a meaningful flat-dollar penalty regardless of size — but it does mean the scariest headline numbers are simply not the realistic baseline for a small Quebec business's first compliance misstep.
It's also worth understanding that the CAI has discretion in how it responds to a given compliance failure, and a monetary penalty is not the only — or even the most common — tool it uses. In many cases, particularly for first-time, non-malicious, and promptly corrected issues, the CAI's typical response is a formal order requiring specific remedial action within a set timeframe, sometimes paired with follow-up monitoring, rather than an immediate monetary penalty. Monetary penalties tend to become more likely when a business ignores an order, repeats a known issue, or shows a pattern of disregard for its obligations rather than an isolated, good-faith mistake. This is precisely why documented compliance effort matters so much — it's evidence that a lapse was an isolated gap in an otherwise serious program, not a symptom of systemic indifference.
Common Misconceptions About Law 25 Penalties
Because Law 25 coverage tends to lead with the largest possible numbers, several misconceptions have taken hold among small business owners that are worth correcting directly.
Misconception: "Law 25 only applies to big companies"
This is false, and it's one of the most consequential misconceptions because it leads directly to inaction. Law 25 applies to any organization that collects, holds, uses, or communicates personal information in the course of carrying on an enterprise in Quebec, with essentially no minimum size threshold. A five-person accounting firm, a solo consultant with a client intake form, and a large retail chain are all subject to the same underlying obligations — the difference is in realistic penalty exposure (as covered above), not in whether the law applies at all.
Misconception: "If we've never had a breach, we're not at risk"
A significant share of Law 25's obligations — the mandatory PIA requirement, the privacy officer designation, consent standards — apply regardless of whether a confidentiality incident has ever occurred. A business can be fully compliant on the breach-response side and still be in violation for skipping a mandatory PIA on a new system, or for having consent language that doesn't meet the law's specificity requirement. Penalty risk isn't only about what happens after something goes wrong; it's also about ongoing process obligations that apply from day one of a qualifying project.
Misconception: "Our lawyer/accountant handles this"
Unless a business has specifically engaged legal or compliance counsel to review its Law 25 posture — as opposed to general legal or accounting services — this is usually an assumption rather than a fact. Privacy compliance under Law 25 touches IT systems, data flows, consent mechanisms, and operational processes in ways that fall outside the scope of routine legal or accounting engagements unless explicitly scoped in. It's worth confirming directly rather than assuming coverage exists.
Misconception: "The maximum fine is what we'd actually pay"
As covered in detail above, the maximum figures are ceilings for the worst violations by the largest organizations. A more realistic mental model for a small business is to think in terms of the percentage-of-turnover math applied to your actual revenue, combined with the CAI's stated tendency to weigh severity, intent, and cooperation — which for a first-time, promptly corrected, non-malicious gap often points toward a corrective order rather than a large monetary penalty at all.
How to Avoid a Law 25 Penalty
None of the following requires a large compliance department. It requires ownership, documentation, and a handful of processes most small businesses can build in a matter of weeks.
Appoint a privacy officer
Formally designate who is responsible for personal information protection at your organization — by law this defaults to your most senior officer unless you delegate it in writing. Make sure this person (or their contact info) is identifiable to the public, typically via your privacy policy.
Conduct mandatory PIAs for relevant projects
Before acquiring, developing, or overhauling any system or electronic service involving personal information, run a documented privacy impact assessment. This is a hard legal trigger under Law 25, not a "nice to have."
Build a confidentiality incident response process
Have a written, tested process for detecting, assessing, and reporting a confidentiality incident presenting a risk of serious injury — to the CAI and to affected individuals — without unreasonable delay. Not having a process in place is itself a risk factor when an incident does occur.
Update your privacy policy and consent mechanisms
Consent requests need to be clear, specific to their purpose, and separated from general terms of service — bundled, vague, or buried consent doesn't meet Law 25's standard.
Train staff on personal information handling
Employees who handle personal information should know what a reportable incident looks like and how to escalate one internally the moment it's suspected, not weeks later.
Document compliance efforts as evidence of good faith
Keep dated records of PIAs, policy updates, and training sessions. Regulators applying penalty frameworks like this one generally consider demonstrated good-faith effort — and undocumented effort is functionally invisible during an investigation.
A ☐ checklist to work through, whether you're starting from zero or tightening up an existing program:
- ☐ Formally designate a privacy officer and publish their contact info in your privacy policy
- ☐ Identify every current or upcoming project that legally requires a PIA and schedule them
- ☐ Write (or update) a documented confidentiality incident response process with clear escalation steps
- ☐ Review your consent language across all forms, sign-ups, and cookie banners for clarity and specificity
- ☐ Confirm your privacy policy discloses what Law 25 requires in plain language, not just legal boilerplate
- ☐ Maintain a data inventory of what personal information you collect, where it's stored, and who can access it
- ☐ Train staff who handle personal information on incident recognition and escalation
- ☐ Review vendor and third-party data-sharing agreements for Law 25-compliant terms
- ☐ Set a recurring calendar reminder to review and refresh your compliance documentation annually
- ☐ Keep dated records of every PIA, policy update, and training session completed
- ☐ Confirm you have a process for responding to individual access/rectification requests within required timelines
- ☐ If you experienced a past incident, confirm it was assessed against the "risk of serious injury" reporting threshold
What This Means for Your Compliance Budget (CAD)
Rather than fine amounts, the more useful number for planning purposes is what prevention actually costs — since prevention is squarely within your control and fine exposure isn't.
| Compliance activity | DIY (in-house time) | With outside help (CAD) |
|---|---|---|
| Privacy officer designation + policy update | A few hours of owner/manager time | $500 – $1,500 one-time |
| PIA for a single new project | 1–3 days of internal time | $1,500 – $5,000 per assessment |
| Incident response process documentation | 1–2 days of internal time | $1,000 – $3,000 one-time |
| Staff training session | Free to low-cost (internal presentation) | $500 – $2,000 for a facilitated session |
| Full Law 25 readiness review (all of the above) | 1–2 weeks of dedicated internal effort | $3,000 – $8,000 for a small business, more for complex data operations |
Compared against even the smallest illustrative exposure scenario above ($40,000), a complete Law 25 readiness program for a small business is typically a fraction of the cost of a single serious violation — which is the actual argument for doing this proactively rather than reactively.
Canadian Government Resources
- CAI — Commission d'accès à l'information du Québec (cai.gouv.qc.ca): The regulator enforcing Law 25. Publishes guidance documents, decision summaries, and tools specifically for helping organizations understand PIA obligations, incident reporting thresholds, and consent requirements.
- OPC — Office of the Privacy Commissioner of Canada (opc.gc.ca): The federal privacy regulator. Useful for businesses operating outside Quebec or across multiple provinces who need to understand how Law 25 interacts with PIPEDA — see our Law 25 vs PIPEDA guide for the multi-province picture.
- ISED — Innovation, Science and Economic Development Canada (ised-isde.canada.ca): Offers general SMB-focused digital and privacy resources that complement provincial-specific guidance.
- BDC — Business Development Bank of Canada (bdc.ca): Provides SMB advisory support that can include help planning and financing compliance-related upgrades to systems and processes.
If your business is evaluating whether outside help makes sense for closing these gaps, our IT security audit checklist and PIPEDA compliance guide for accounting and law firms cover adjacent ground that often overlaps directly with Law 25 readiness work.
One detail worth flagging for any business operating outside Quebec as well as inside it: Law 25 applies based on where the personal information subject is located and where the enterprise carries on activities, not simply where a company's head office sits. A business based in Ontario or Alberta that serves Quebec clients, or a Quebec business with customers across Canada, needs to think about both Law 25 and the federal PIPEDA framework simultaneously, since the two regimes can apply concurrently depending on the nature of the business and the data involved. This overlap is common enough, and confusing enough, that it's covered as its own dedicated topic in our Law 25 vs PIPEDA multi-province guide, which walks through exactly which rules apply when a business operates across provincial lines.
Want a right-sized Law 25 readiness plan, not a scare tactic?
IT Cares' security audits look at your actual data practices — consent flows, access controls, incident readiness — and translate them into a concrete, appropriately scaled compliance plan. If ongoing management makes sense for your business, our managed IT services can help maintain these controls over time.
Frequently Asked Questions
Want This Turned Into a Concrete Action Plan?
IT Cares reviews your real data practices and gives you a right-sized Law 25 readiness plan — the controls that actually reduce risk, without the enterprise price tag.
Comments (3)
The breakdown of the percentage-of-turnover math finally made this make sense. I was assuming a $10M fine was on the table for our little shop, which was keeping me up at night for no reason.
Appreciated that this didn't just throw around scary numbers without explaining the mechanism behind them. We're now working through the checklist with our office manager.
Good honest article. Didn't realize a missed PIA specifically was one of the clearest triggers — we have a new client portal launching next quarter and never thought to check.
Leave a Comment