Law 25 Fines: Real Penalties and Amounts Explained (2026)

Reviewed by IT Cares certified technicians · Updated July 2026

Law 25 fines and penalties explained for Quebec businesses — CAI enforcement scale illustration
Law 25 penalties scale with company size through a "flat amount or percentage of turnover" formula — understanding that mechanism matters more than memorizing the headline maximums.
⚖️
Not sure how exposed your business actually is under Law 25? Our certified technicians review your real setup and translate the legal penalty scale into a practical, right-sized action list.
Get a Free Assessment →

Law 25 carries two separate penalty tracks, and the numbers that make headlines — $10 million, $25 million, "4% of worldwide turnover" — are ceilings for the largest organizations and the most serious violations, not the realistic outcome for a small Quebec business's first compliance gap. Understanding the actual structure behind those numbers, rather than just the scary top line, is what lets a business owner make a rational decision about how much time and money to put into compliance.

Quebec's Law 25 (the Act respecting the protection of personal information in the private sector, formerly known as Bill 64) rolled out its provisions in phases between 2022 and 2024, and its penalty regime is genuinely one of the toughest in North America on paper. That toughness is exactly why the topic generates so much anxiety among small business owners who hear "$25 million fine" in a news headline and assume it applies to them the same way it would apply to a bank or a national retailer. It doesn't — and this guide exists to explain precisely why, using the actual mechanics of the penalty structure rather than fear-based generalities.

This article walks through exactly how Law 25 penalties are structured, what specifically triggers them, what's publicly known (and not yet known) about how the CAI has been enforcing the law since it came into force, honest size-adjusted examples that show what exposure actually looks like for a business your size, and a concrete plan for reducing your risk without needing an enterprise compliance budget.

Who wrote this guide

This article was written and reviewed by IT Cares certified technicians who work directly with Quebec small and mid-sized businesses on the practical side of Law 25 compliance — privacy impact assessments, incident response processes, access controls. We're not a law firm and this isn't legal advice; for a specific penalty determination or legal risk opinion, consult a lawyer. What we can offer is an accurate, calibrated explanation of the penalty framework and the practical controls that reduce real-world risk.

The Two-Tier Law 25 Penalty Structure, Explained Precisely

Law 25's monetary penalty regime works on two separate tracks, and mixing them up is the single most common source of confusion when people talk about "Law 25 fines."

Track 1: Administrative Monetary Penalties (AMPs)

Administrative monetary penalties are issued directly by the Commission d'accès à l'information du Québec (CAI) — the provincial privacy regulator — without requiring a criminal prosecution. Think of this track as functioning somewhat like a regulatory fine from a tax authority or a professional order: the CAI investigates, determines a violation occurred, and can impose a penalty directly as part of its regulatory authority. For an organization (as opposed to an individual), the maximum AMP is $10,000,000 CAD or 2% of worldwide turnover for the preceding fiscal year, whichever amount is greater. This is the track most compliance failures — a missed mandatory PIA, an inadequate consent process, a late or absent breach notification — would realistically fall under if the CAI decides to penalize rather than simply order corrective action.

Track 2: Penal Fines

Penal fines are reserved for the most serious offences and require an actual prosecution through Quebec's court system rather than a direct regulatory penalty. This track covers things like knowingly and deliberately misusing personal information, obstructing a CAI investigation, or other conduct that rises to a level Quebec's legislature decided deserved the weight of a criminal-style proceeding rather than a purely administrative one. For an organization, the maximum penal fine is $25,000,000 CAD or 4% of worldwide turnover for the preceding fiscal year, whichever amount is greater. This is the number that generates the scariest headlines, and it is genuinely a large number — but it applies to a narrower, more serious category of violation, prosecuted through a slower, more procedurally protected court process, not a first-offence paperwork gap.

The detail that changes everything for a small business

Both maximums use a "flat dollar amount OR a percentage of worldwide turnover, whichever is greater" formula. For a company with billions in global revenue, the percentage figure (2% or 4%) is what actually applies and can genuinely reach into the tens of millions. For a business with, say, $3 million in annual revenue, 2% of turnover is $60,000 — a meaningful amount, certainly, but nowhere near the $10 million ceiling that headline coverage tends to lead with. Small businesses are not exempt from penalties, but the realistic dollar exposure scales down dramatically with company size, which is the single most important nuance missing from most Law 25 fine coverage.

Want an honest read on your Law 25 exposure?

Our certified technicians review your actual data practices and give you a right-sized compliance plan — from $119.99.

Violation typePenalty typeMaximum amount (organization)Who issues it
General compliance failures (e.g. missed PIA, inadequate consent, late breach notice)Administrative Monetary Penalty (AMP)$10,000,000 CAD or 2% of worldwide turnover, whichever is greaterCAI directly (no court required)
Most serious offences (e.g. deliberate misuse, obstruction of investigation)Penal fine$25,000,000 CAD or 4% of worldwide turnover, whichever is greaterQuebec courts, following CAI referral/prosecution
For context: EU equivalent regimeGDPR administrative fine€20,000,000 or 4% of global annual turnover, whichever is greaterNational data protection authority (EU)
Individual (non-organization) violations under Law 25AMP or penal fine, individual scaleLower flat-dollar maximums than organizations (no turnover percentage applies to individuals)CAI or Quebec courts depending on track

What Actually Triggers a Law 25 Penalty

Penalties don't appear out of nowhere — they follow specific, identifiable compliance failures. The most common triggers that show up in the law's structure and in how the CAI has publicly described its enforcement priorities include:

📊 IT Cares field note: Almost every Quebec small business we've worked with on Law 25 readiness had at least one clear gap in this list — most commonly a missing or informal privacy officer designation and no PIA process at all for new systems. None of these gaps require expensive infrastructure to close; they require someone to actually own the task and follow a documented process, which is often the real missing piece rather than money.

What's Publicly Known About CAI Enforcement So Far

Here's where it's important to be precise rather than speculative. Law 25's monetary penalty provisions rolled out in phases, with the most significant obligations — including the private right of action and the full AMP framework — reaching full effect over 2023 and 2024. That means the enforcement track record is still relatively young compared to a regime like GDPR, which has been generating publicly reported penalty decisions since 2018.

What can be said with confidence: the CAI has been actively conducting investigations, issuing orders, and publishing guidance since Law 25's provisions came into force, and its public communications signal an intent to use its full toolkit — including monetary penalties — as the enforcement track record matures. This mirrors a pattern seen with essentially every new privacy regime: a period of guidance, warnings, and investigation-driven orders in the earliest phase, followed by a gradual increase in visible monetary penalties as the regulator builds internal capacity and legal precedent. GDPR followed a similar arc — its first several years produced relatively few large fines compared to the pace seen once enforcement matured.

What this article will not do is invent a specific dollar figure and attribute it to a specific named company as though it were a confirmed, published CAI penalty decision — doing so would misinform readers making real compliance decisions. If you're researching this topic for legal or compliance purposes, the CAI's own published decisions and enforcement reports (available through cai.gouv.qc.ca) are the authoritative source for confirmed penalty amounts, and that list will continue to grow over time.

It also helps to understand the phased rollout, because it explains why the enforcement record looks the way it does. Law 25's provisions didn't all take effect on a single date — they came into force in stages between September 2022 and September 2024, starting with the privacy officer designation requirement and confidentiality incident notification obligations, followed later by the mandatory PIA requirement, the private right of action, and the consent and data portability provisions. This staged approach is common in major regulatory overhauls precisely because it gives organizations time to adjust before the full weight of the law, including its toughest penalty provisions, becomes fully enforceable. It also means that penalty activity tied to the newest provisions has had the least time to accumulate into a visible public record, which is part of why so much of the conversation around "real Law 25 fines" remains, for now, more about structure and pattern than a long list of concluded cases.

Beyond the Fine: Other Real Costs of a Law 25 Violation

Monetary penalties are only one part of the financial picture, and in many real-world cases, they aren't even the largest cost a business faces after a serious privacy incident or compliance failure. A complete risk picture should account for several other costs that often dwarf the penalty itself:

Taken together, this is the strongest practical argument for proactive compliance: even in a scenario where the CAI-imposed monetary penalty itself turns out to be modest for a small business, the surrounding costs — legal, remediation, reputational, insurance — are frequently the larger and more painful part of the bill, and none of them are mitigated by the fact that the AMP itself was smaller than the headline maximum.

The Desjardins breach: important context, not a Law 25 case

The 2019 Desjardins data breach — in which the personal information of millions of members was compromised, largely through the actions of a malicious insider — is one of the most significant privacy incidents in Quebec's history and directly helped drive momentum toward Law 25's creation. It's worth understanding as context, but it's important to be accurate: the breach itself substantially predated Law 25's current penalty regime, so the legal and regulatory consequences Desjardins faced were shaped by the privacy law framework that existed at the time, not by Law 25's AMP/penal fine structure. A comparable incident occurring today, under the current regime, would be evaluated against Law 25's mandatory incident reporting requirements and its administrative and penal penalty tracks — which is precisely why the Desjardins case is often cited as an example of the kind of scenario the current penalty structure was designed to address more forcefully.

Illustrative Scenarios: What Realistic Exposure Looks Like by Company Size

To make the "percentage of turnover" mechanism concrete, here are three clearly illustrative, hypothetical scenarios — not real CAI cases — showing how the same category of violation produces very different realistic dollar exposure depending on company size. These are designed to help you reason about your own exposure, not to predict an actual outcome for any real case.

Illustrative scenario 1 — a $2M-revenue Quebec professional services firm

Suppose a small Quebec accounting firm with roughly $2 million in annual revenue launches a new client portal for document sharing and tax filing, without conducting the mandatory PIA that Law 25 requires for any project involving the development of an information system handling personal information. A client later files a complaint after noticing another client's documents briefly visible due to a permissions misconfiguration, and the CAI opens an investigation. It finds the PIA was never done and the permissions issue would likely have been caught had one been conducted. Two percent of $2 million is $40,000 — that's the realistic order of magnitude for the "percentage of turnover" side of the formula, well below the $10 million ceiling, though the CAI could still impose a higher flat-dollar penalty depending on severity, prior history, and cooperation, or could instead issue a corrective order requiring the firm to complete a retroactive PIA and fix its access controls within 60 days. The point: for a business this size, "Law 25 fine" realistically means tens of thousands of dollars in a serious first case, not millions — and a well-handled, cooperative response can shift the outcome toward correction rather than penalty entirely.

Illustrative scenario 2 — a $15M-revenue Quebec retailer

Suppose a mid-sized Quebec retail chain with $15 million in annual revenue detects unusual activity on its e-commerce platform suggesting a credential-stuffing attack may have exposed customer loyalty account data, including partial payment information. Internal IT flags the anomaly within days, but because there's no formal incident response process and no one is clearly designated to make the "does this meet the reporting threshold" call, the assessment and reporting to the CAI happens six weeks later than it should have — well past what would be considered "without unreasonable delay" for an incident presenting a risk of serious injury. Two percent of $15 million is $300,000 — a genuinely painful number for a business this size, illustrating why mid-sized companies with real revenue at stake shouldn't treat Law 25 as a small-business-only concern the way the smallest scenario above might suggest, and why the incident response process itself (not just having good security) is part of what regulators evaluate.

Illustrative scenario 3 — a $500M-revenue national company

Suppose a large national company with $500 million in worldwide turnover is found, through a CAI investigation, to have knowingly sold customer personal information to a third-party data broker without proper consent, over an extended period, despite internal staff raising concerns about the practice — a Track 2 penal-fine-level violation given the knowing and deliberate nature of the conduct. Four percent of $500 million is $20,000,000, approaching the $25 million ceiling. This is the scale of organization and severity of conduct where the eye-catching maximum figures genuinely start to apply as realistic exposure rather than theoretical worst-case numbers, and where the prosecutorial (rather than purely administrative) track becomes the more likely enforcement path given the deliberate nature of the violation.

The consistent pattern across all three: the percentage-of-turnover mechanism means the law's bite scales with the size of the organization being penalized, which is a deliberate and common design choice in modern privacy regulation (GDPR uses the identical logic). It does not mean small businesses are exempt — a genuinely serious violation can still draw a meaningful flat-dollar penalty regardless of size — but it does mean the scariest headline numbers are simply not the realistic baseline for a small Quebec business's first compliance misstep.

It's also worth understanding that the CAI has discretion in how it responds to a given compliance failure, and a monetary penalty is not the only — or even the most common — tool it uses. In many cases, particularly for first-time, non-malicious, and promptly corrected issues, the CAI's typical response is a formal order requiring specific remedial action within a set timeframe, sometimes paired with follow-up monitoring, rather than an immediate monetary penalty. Monetary penalties tend to become more likely when a business ignores an order, repeats a known issue, or shows a pattern of disregard for its obligations rather than an isolated, good-faith mistake. This is precisely why documented compliance effort matters so much — it's evidence that a lapse was an isolated gap in an otherwise serious program, not a symptom of systemic indifference.

Common Misconceptions About Law 25 Penalties

Because Law 25 coverage tends to lead with the largest possible numbers, several misconceptions have taken hold among small business owners that are worth correcting directly.

Misconception: "Law 25 only applies to big companies"

This is false, and it's one of the most consequential misconceptions because it leads directly to inaction. Law 25 applies to any organization that collects, holds, uses, or communicates personal information in the course of carrying on an enterprise in Quebec, with essentially no minimum size threshold. A five-person accounting firm, a solo consultant with a client intake form, and a large retail chain are all subject to the same underlying obligations — the difference is in realistic penalty exposure (as covered above), not in whether the law applies at all.

Misconception: "If we've never had a breach, we're not at risk"

A significant share of Law 25's obligations — the mandatory PIA requirement, the privacy officer designation, consent standards — apply regardless of whether a confidentiality incident has ever occurred. A business can be fully compliant on the breach-response side and still be in violation for skipping a mandatory PIA on a new system, or for having consent language that doesn't meet the law's specificity requirement. Penalty risk isn't only about what happens after something goes wrong; it's also about ongoing process obligations that apply from day one of a qualifying project.

Misconception: "Our lawyer/accountant handles this"

Unless a business has specifically engaged legal or compliance counsel to review its Law 25 posture — as opposed to general legal or accounting services — this is usually an assumption rather than a fact. Privacy compliance under Law 25 touches IT systems, data flows, consent mechanisms, and operational processes in ways that fall outside the scope of routine legal or accounting engagements unless explicitly scoped in. It's worth confirming directly rather than assuming coverage exists.

Misconception: "The maximum fine is what we'd actually pay"

As covered in detail above, the maximum figures are ceilings for the worst violations by the largest organizations. A more realistic mental model for a small business is to think in terms of the percentage-of-turnover math applied to your actual revenue, combined with the CAI's stated tendency to weigh severity, intent, and cooperation — which for a first-time, promptly corrected, non-malicious gap often points toward a corrective order rather than a large monetary penalty at all.

How to Avoid a Law 25 Penalty

None of the following requires a large compliance department. It requires ownership, documentation, and a handful of processes most small businesses can build in a matter of weeks.

1

Appoint a privacy officer

Formally designate who is responsible for personal information protection at your organization — by law this defaults to your most senior officer unless you delegate it in writing. Make sure this person (or their contact info) is identifiable to the public, typically via your privacy policy.

2

Conduct mandatory PIAs for relevant projects

Before acquiring, developing, or overhauling any system or electronic service involving personal information, run a documented privacy impact assessment. This is a hard legal trigger under Law 25, not a "nice to have."

3

Build a confidentiality incident response process

Have a written, tested process for detecting, assessing, and reporting a confidentiality incident presenting a risk of serious injury — to the CAI and to affected individuals — without unreasonable delay. Not having a process in place is itself a risk factor when an incident does occur.

4

Update your privacy policy and consent mechanisms

Consent requests need to be clear, specific to their purpose, and separated from general terms of service — bundled, vague, or buried consent doesn't meet Law 25's standard.

5

Train staff on personal information handling

Employees who handle personal information should know what a reportable incident looks like and how to escalate one internally the moment it's suspected, not weeks later.

6

Document compliance efforts as evidence of good faith

Keep dated records of PIAs, policy updates, and training sessions. Regulators applying penalty frameworks like this one generally consider demonstrated good-faith effort — and undocumented effort is functionally invisible during an investigation.

A ☐ checklist to work through, whether you're starting from zero or tightening up an existing program:

What This Means for Your Compliance Budget (CAD)

Rather than fine amounts, the more useful number for planning purposes is what prevention actually costs — since prevention is squarely within your control and fine exposure isn't.

Compliance activityDIY (in-house time)With outside help (CAD)
Privacy officer designation + policy updateA few hours of owner/manager time$500 – $1,500 one-time
PIA for a single new project1–3 days of internal time$1,500 – $5,000 per assessment
Incident response process documentation1–2 days of internal time$1,000 – $3,000 one-time
Staff training sessionFree to low-cost (internal presentation)$500 – $2,000 for a facilitated session
Full Law 25 readiness review (all of the above)1–2 weeks of dedicated internal effort$3,000 – $8,000 for a small business, more for complex data operations

Compared against even the smallest illustrative exposure scenario above ($40,000), a complete Law 25 readiness program for a small business is typically a fraction of the cost of a single serious violation — which is the actual argument for doing this proactively rather than reactively.

Canadian Government Resources

If your business is evaluating whether outside help makes sense for closing these gaps, our IT security audit checklist and PIPEDA compliance guide for accounting and law firms cover adjacent ground that often overlaps directly with Law 25 readiness work.

One detail worth flagging for any business operating outside Quebec as well as inside it: Law 25 applies based on where the personal information subject is located and where the enterprise carries on activities, not simply where a company's head office sits. A business based in Ontario or Alberta that serves Quebec clients, or a Quebec business with customers across Canada, needs to think about both Law 25 and the federal PIPEDA framework simultaneously, since the two regimes can apply concurrently depending on the nature of the business and the data involved. This overlap is common enough, and confusing enough, that it's covered as its own dedicated topic in our Law 25 vs PIPEDA multi-province guide, which walks through exactly which rules apply when a business operates across provincial lines.

Want a right-sized Law 25 readiness plan, not a scare tactic?

IT Cares' security audits look at your actual data practices — consent flows, access controls, incident readiness — and translate them into a concrete, appropriately scaled compliance plan. If ongoing management makes sense for your business, our managed IT services can help maintain these controls over time.

Frequently Asked Questions

What is the maximum fine under Law 25?
There are two separate penalty tracks with different maximums. Administrative monetary penalties (AMPs), issued directly by the CAI without going to court, top out at $10,000,000 or 2% of worldwide turnover for the preceding fiscal year, whichever amount is greater, for an organization. Penal fines, which require a prosecution through the courts for the most serious offences, top out at $25,000,000 or 4% of worldwide turnover for the preceding fiscal year, whichever is greater. Both maximums are ceilings for the worst violations by the largest organizations, not typical outcomes for a small business's first compliance gap.
Who enforces Law 25 penalties — the CAI?
Yes. The Commission d'accès à l'information du Québec (CAI) is the regulator responsible for overseeing Law 25 compliance in the private sector, investigating complaints and incidents, issuing orders, and imposing administrative monetary penalties. Penal fines for the most serious offences are prosecuted through Quebec's regular court system rather than issued directly by the CAI, though the CAI's investigations are typically what triggers a referral for prosecution.
What's the difference between an administrative monetary penalty and a penal fine under Law 25?
An administrative monetary penalty (AMP) is issued directly by the CAI as a regulator, similar to how a tax authority might issue a penalty, without a criminal court process — it's generally used for compliance failures that don't rise to the level of a prosecutable offence. A penal fine requires an actual prosecution in court, applies to the most serious violations (such as knowingly and deliberately misusing personal information), carries a higher maximum, and follows the procedural protections of the criminal justice system.
Has the CAI actually issued fines yet?
Law 25's monetary penalty provisions are still relatively young, and the CAI's enforcement track record continues to develop as more investigations conclude. The CAI has been active in investigations, orders, and public guidance since the law's provisions came into force in phases, and enforcement activity — including penalties — is expected to become more visible over time as the regulator builds precedent, similar to how other new privacy regimes typically ramp up enforcement gradually rather than immediately upon taking effect.
Can a small business really be fined the maximum amount?
In practice, no — the maximum figures ($10M/2% and $25M/4%) are ceilings calibrated for the largest organizations and the most serious violations, and the "or a percentage of worldwide turnover" mechanism means the realistic dollar exposure scales down substantially for a small business with modest revenue. That said, the CAI can still impose meaningful flat-dollar penalties well below the ceiling, and a small business isn't automatically protected just because the headline maximum doesn't apply to it in practice.
What factors affect the size of a Law 25 penalty?
Regulators applying this kind of penalty framework typically weigh factors such as the severity and duration of the violation, whether it was a first-time or repeat issue, whether the organization cooperated with the investigation, whether reasonable security and privacy measures were in place beforehand, the size and resources of the organization, and whether the violation caused actual harm to individuals. Demonstrated good-faith compliance efforts — documented PIAs, training records, a privacy policy that was actually followed — tend to work in an organization's favour during this kind of assessment.
How does Law 25's penalty scale compare to GDPR fines?
The structures are similar in concept — both use a "flat amount or percentage of global turnover, whichever is greater" formula — but the specific numbers differ. GDPR's maximum for the most serious violations is €20 million or 4% of global annual turnover. Law 25's penal fine maximum is $25 million CAD or 4% of worldwide turnover, a comparable percentage figure but a different currency and flat-dollar ceiling. The underlying design philosophy, scaling penalties to company size through the turnover percentage, is essentially the same idea both regimes borrowed from the same general trend in modern privacy law.

Want This Turned Into a Concrete Action Plan?

IT Cares reviews your real data practices and gives you a right-sized Law 25 readiness plan — the controls that actually reduce risk, without the enterprise price tag.

Comments (3)

JR
Julie R., Trois-Rivières
July 22, 2026

The breakdown of the percentage-of-turnover math finally made this make sense. I was assuming a $10M fine was on the table for our little shop, which was keeping me up at night for no reason.

DL
Daniel L., Longueuil
July 20, 2026

Appreciated that this didn't just throw around scary numbers without explaining the mechanism behind them. We're now working through the checklist with our office manager.

MP
Marie-Pier T., Gatineau
July 18, 2026

Good honest article. Didn't realize a missed PIA specifically was one of the clearest triggers — we have a new client portal launching next quarter and never thought to check.

Leave a Comment

Need Help?