A business operating in Quebec and at least one other Canadian province is subject to more than one privacy law at once, and "just follow PIPEDA everywhere" stopped being sufficient the moment Quebec's Law 25 came into force. This isn't a hypothetical edge case for a small slice of Canadian businesses — any company with a Quebec office, Quebec employees (including remote staff), or a meaningful Quebec customer base is affected, alongside whatever privacy obligations apply to its activity in Ontario, British Columbia, Alberta, or elsewhere.
The confusion this creates is genuinely understandable. Canada doesn't have a single, unified private-sector privacy law the way some other jurisdictions do — it has a federal law (PIPEDA) that applies by default, several provinces with their own laws recognized as "substantially similar" to PIPEDA (Quebec's Law 25, British Columbia's PIPA, Alberta's PIPA), and sector-specific overlays in some provinces (like Ontario's PHIPA for health information) layered on top. A business operating across several of these lines at once needs to understand not just each law individually, but how they interact — and, in practice, which one actually sets the bar the business needs to build to.
This guide lays out, in plain language, how Law 25 and PIPEDA actually differ, what the "substantially similar law" designation means in practice, a detailed side-by-side comparison, a practical approach for building one compliance program that satisfies both regimes rather than running two in parallel, real-world scenarios, and realistic Canadian cost ranges for the compliance work involved.
A note before we start
This article is general information to help you understand the landscape and ask better questions of a privacy lawyer — it is not legal advice. Privacy law in Canada continues to evolve, and specific compliance obligations should always be confirmed with a lawyer familiar with both federal and Quebec privacy law before you rely on any general description in this guide.
Law 25, in Plain Language
Quebec's Law 25 (formally the Act respecting the protection of personal information in the private sector, and before that known as Bill 64 during its legislative process) rolled out in three phases, and understanding the phased timeline matters because it explains why some obligations feel newer and less settled than others:
- September 2022: Governance rules took effect, along with mandatory notification of "confidentiality incidents" presenting a risk of serious injury — both to the Commission d'accès à l'information (CAI), Quebec's privacy regulator, and to the affected individuals themselves.
- September 2023: Updated consent requirements, mandatory privacy policy disclosures, mandatory Privacy Impact Assessments for certain projects and for any transfer of personal information outside Quebec, and a right to de-indexing/erasure in certain circumstances all came into force.
- September 2024: A right to data portability — allowing individuals to request their personal information be transferred to them or to another organization in a structured format — took effect as the final phase.
Beyond the phased rollout, a few features of Law 25 are worth understanding as distinct from what many businesses assume a "typical" Canadian privacy law looks like: it requires designating a specific privacy officer whose title and contact information must be published; it requires maintaining a confidentiality incident register (not just reporting the serious incidents — logging all of them internally, retained for a minimum of five years); it has among the highest penalty ceilings of any Canadian privacy law, reaching up to $10 million CAD or 2% of worldwide turnover for administrative penalties, and up to $25 million or 4% for penal offences; and it applies to essentially every private-sector business carrying on activity in Quebec, with no small-business exemption based on size.
PIPEDA, in Plain Language
The federal Personal Information Protection and Electronic Documents Act (PIPEDA) has governed private-sector commercial activity across Canada since the early 2000s, built around ten fair information principles — accountability, identifying purposes, consent, limiting collection, limiting use/disclosure/retention, accuracy, safeguards, openness, individual access, and challenging compliance. It requires an accountable individual within the organization (though, unlike Law 25, it doesn't require that person's title and contact information be published), and it requires breach notification to the Office of the Privacy Commissioner of Canada (OPC) and to affected individuals when there's a "real risk of significant harm" (often abbreviated RROSH) — a threshold assessment the organization itself makes, considering sensitivity of the data and probability of misuse. Organizations must also keep records of every breach, even ones that don't meet the RROSH threshold for external reporting, for a minimum of 24 months.
PIPEDA's penalty regime, while it has been strengthened over time, remains more limited than Law 25's — which is one of the most consequential practical differences between the two laws for a business weighing where to focus its compliance effort.
The "Substantially Similar Law" Concept — Why This Actually Matters
Here's the mechanism that determines which law actually governs a given piece of your business's activity. PIPEDA includes a provision allowing provinces to have their own private-sector privacy legislation recognized as "substantially similar" to PIPEDA — and where a province's law has that designation, PIPEDA effectively steps back and the provincial law governs commercial activity within that province instead. Quebec's Law 25 has been recognized as substantially similar (following in the footsteps of its predecessor legislation), as has British Columbia's Personal Information Protection Act (PIPA) and Alberta's equivalent PIPA.
What this means practically: a business's Quebec-based commercial activity is governed by Law 25, not PIPEDA directly. Its British Columbia-based activity is governed by BC's PIPA. Its Alberta-based activity is governed by Alberta's PIPA. And its activity in provinces without their own substantially similar law — Ontario prominent among them for general private-sector activity — falls under PIPEDA by default. Interprovincial and international data flows (data moving between provinces, or between Canada and another country) generally remain subject to PIPEDA regardless of where the data originates, layered on top of whichever provincial law also applies.
📊 IT Cares field note: The most common misunderstanding we see isn't about which law applies in the abstract — most business owners can recite "Quebec has Law 25, the rest of Canada has PIPEDA" without difficulty. The mistake is underestimating how little Quebec-based activity is actually needed to trigger Law 25. A single remote employee working from Quebec, or a modest but real base of Quebec customers for an Ontario-headquartered online business, is enough. Businesses that assume Law 25 only applies if they have a physical Quebec office are working from an outdated and inaccurate mental model.
Not sure which privacy regime actually applies to your business?
Our certified technicians can map your data flows and flag where your current setup may fall short — from $119.99.
Law 25 vs PIPEDA: Full Comparison
| Category | Quebec Law 25 | Federal PIPEDA |
|---|---|---|
| Scope / who it governs | Private-sector commercial activity carried on in Quebec, involving personal information of individuals in Quebec — no small-business exemption | Private-sector commercial activity in provinces without their own substantially similar law (e.g. Ontario), plus interprovincial/international data flows |
| Breach notification trigger | “Confidentiality incident” presenting a risk of serious injury — notify the CAI and affected individuals “without delay” | “Real risk of significant harm” (RROSH) — notify the OPC and affected individuals as soon as feasible |
| Internal incident record-keeping | Mandatory confidentiality incident register logging ALL incidents (not just reportable ones), retained minimum 5 years | Record of every breach of security safeguards, retained minimum 24 months |
| Privacy officer requirement | Mandatory designated “person in charge of the protection of personal information”; title and contact info must be published | Accountable individual required under the Accountability principle; no publication requirement |
| Consent standard | Consent must be clear, free, and informed, given for specific purposes; separate consent required for sensitive information | Meaningful consent required, calibrated to sensitivity of information and reasonable expectations |
| Privacy Impact Assessments | Mandatory for certain information system projects and for any cross-border transfer of personal information | Not formally mandated by statute, though recommended as best practice and expected in some regulatory guidance |
| Data subject rights | Access, rectification, de-indexing/erasure (as of Sept 2023), data portability (as of Sept 2024) | Access and correction rights; more limited erasure/portability rights than Law 25 |
| Penalties | Administrative penalties up to $10M CAD or 2% of worldwide turnover; penal offences up to $25M or 4% | More limited penalty regime, though it has been strengthened over recent amendments |
| Cross-border transfer rules | Requires an assessment (via PIA) of whether the destination provides adequate protection before transferring data outside Quebec | Requires comparable safeguards for data transferred to third parties, including outside Canada, generally via contractual means |
Reading across the table, one pattern is consistent: on nearly every dimension, Law 25 sets a higher, more specific, and more rigorously enforced bar than PIPEDA currently does. That's the single most useful takeaway for a multi-province business trying to decide where to focus its compliance effort — building to Law 25's standard organization-wide will, in practice, satisfy PIPEDA's requirements as well, while the reverse is not true.
Building One Compliance Program for Both Regimes
Rather than maintaining separate, lighter-touch compliance processes for each province a business operates in, most multi-province businesses find it simpler — and ultimately safer — to build a single program calibrated to the stricter regime (Law 25) and apply it organization-wide. Here's the practical sequence.
Map exactly where your data collection actually happens
Identify every province where you have employees (including fully remote staff), customers, or data storage/processing activity. Many businesses discover, once they actually map it, more Quebec-subject activity than they assumed going in.
Designate one privacy officer for the whole organization
A single person or small team can typically fulfill both Law 25's designated-officer requirement and PIPEDA's accountable-individual principle at once, provided their title and contact information are published in a way that satisfies Law 25's specific publication requirement.
Build one incident register that satisfies the stricter bar
Design your internal breach/incident logging process around Law 25's more demanding requirements (log every incident, retain 5 years) rather than maintaining two separate systems — this single register then satisfies PIPEDA's 24-month retention requirement automatically, since 5 years exceeds 24 months.
Align consent language to the stricter standard everywhere
Rather than drafting province-specific consent language, use Law 25-compliant consent practices (clear, free, informed, purpose-specific, with separate consent for sensitive data) across your whole customer base — it satisfies PIPEDA's meaningful consent standard as well and avoids the complexity of maintaining multiple versions.
Build a breach response process that satisfies both notification timelines
Design your incident response plan to trigger notification fast enough to satisfy Law 25's “without delay” standard for Quebec-affected individuals, and route notification to both the CAI and OPC as applicable based on which individuals were affected and where.
Review cross-border and interprovincial data transfer contracts
Confirm vendor and processor contracts include adequate safeguard language for any data crossing provincial or international lines, and complete a Privacy Impact Assessment for any project involving a cross-border transfer of Quebec residents' personal information.
Multi-Province Compliance Checklist
Work through this to confirm your organization is actually built to the standard that applies everywhere you operate, not just where you assumed it mattered most.
☐ Mapped every province where you have employees, customers, or data processing activity
☐ Designated a single privacy officer for the whole organization
☐ Published the privacy officer's title and contact information (required if Quebec-subject)
☐ Built one confidentiality incident register meeting Law 25's 5-year retention standard
☐ Aligned consent language to Law 25's stricter standard across all provinces
☐ Confirmed breach notification workflow covers both CAI and OPC timelines and formats
☐ Reviewed vendor/processor contracts for cross-border and interprovincial transfer safeguards
☐ Completed or scheduled a Privacy Impact Assessment for any project involving cross-border data transfer
Real-World Scenarios: How This Plays Out
The following case studies are composite, fictional scenarios built from patterns common across multi-province businesses — they illustrate how these compliance gaps actually surface, not a specific real company.
Case study: a retailer with stores in Quebec and Ontario
A home goods retailer with 14 stores — 9 in Ontario, 5 in Quebec — had built its loyalty program privacy policy around PIPEDA, assuming a single national policy would cover the whole chain. During a routine review triggered by a new e-commerce platform launch, the retailer's newly engaged privacy consultant flagged that its Quebec stores' loyalty program had never designated or published a privacy officer, and its incident logging process retained records for only 12 months, well short of Law 25's 5-year minimum. The retailer restructured to a single national privacy officer role (assigned to its existing director of customer experience, with contact information added to its website footer) and extended its incident register retention to 5 years across the board, at a one-time setup cost of roughly $6,500 CAD in consultant time plus ongoing minimal administrative overhead.
Case study: a professional services firm with remote staff in BC and Quebec
A 28-person marketing and design consultancy headquartered in Toronto had grown its remote team to include 4 employees in British Columbia and 3 in Quebec. The firm's HR data handling — payroll, benefits enrollment, performance records — had never been reviewed against either BC's PIPA or Law 25, having been set up years earlier under a PIPEDA-only assumption when the firm was Ontario-only. An HR systems upgrade project prompted a compliance review that identified the Quebec employees' data required a completed Privacy Impact Assessment given the new HR platform involved a cross-border transfer (the new vendor's servers were in the United States). The firm completed the PIA with support from an outsourced privacy consultant over three weeks, at a cost of approximately $3,200 CAD, before finalizing the platform migration.
Case study: a SaaS company headquartered in Toronto with a Montreal office
A 55-employee software company opened a 12-person Montreal engineering office as part of a talent expansion strategy. The company's existing privacy program, built to PIPEDA's standard for its Ontario headquarters, required a substantial update once the Montreal office triggered Law 25 obligations for both its employees and any Quebec-based customers acquired going forward. The company engaged a privacy lawyer to update its privacy policy, designate and publish a privacy officer, and build a Law 25-compliant incident register, at a combined legal and implementation cost of roughly $11,000 CAD — a cost the company's leadership noted would have been avoided almost entirely had the compliance review happened before the Montreal office opened rather than three months after.
Budget Reality Check: What Multi-Province Compliance Actually Costs
Compliance costs scale with organizational complexity — number of provinces involved, data volume, whether existing systems need to be reworked or just documented — but here's how it typically breaks down by rough business size:
- Small business (under 20 employees, Quebec plus one other province): Often achievable in the $2,000-$6,000 CAD range for an initial compliance review, privacy officer designation, and incident register setup, using a combination of templates and limited legal review.
- Growing SMB (20-75 employees, multiple provinces): Typically lands in the $6,000-$20,000 CAD range for a fuller privacy policy overhaul, PIA completion for any cross-border data flows, and staff training, often involving both a privacy lawyer and an IT provider to implement technical safeguards.
- Larger multi-province organization (75+ employees): Costs generally scale into the $20,000-$50,000+ CAD range for comprehensive compliance programs, particularly where multiple legacy systems need to be reviewed and updated, though ongoing maintenance costs (via an outsourced privacy officer retainer or internal role allocation) are typically much lower than the initial build-out.
These are directional ranges for budgeting conversations, not fixed quotes — actual cost depends heavily on how much existing infrastructure needs to be reworked versus simply documented. What's consistent across every size: the cost of building compliance proactively is consistently smaller than the cost of a rushed, reactive compliance project triggered by a new office opening, a new province of customers, or — worse — an actual incident that reveals the gap for the first time.
For a deeper look at the specific privacy officer role this whole structure depends on, see our guide on appointing a privacy officer for SMBs, and for the incident register specifically, our guide on confidentiality incident register obligations under Law 25.
Canadian Government Resources
A few Canadian regulatory and institutional resources are worth bookmarking for ongoing reference:
- Commission d'accès à l'information du Québec (CAI, cai.gouv.qc.ca): Quebec's privacy regulator and the authority responsible for Law 25 enforcement, guidance, and confidentiality incident reporting.
- Office of the Privacy Commissioner of Canada (OPC, priv.gc.ca): The federal regulator overseeing PIPEDA compliance and breach reporting for organizations subject to the federal law.
- Business Development Bank of Canada (BDC): Publishes cybersecurity and risk management resources for Canadian SMBs, including guidance relevant to building out a compliant data handling program.
- Innovation, Science and Economic Development Canada (ISED): Provides broader cybersecurity and digital compliance guidance for Canadian businesses operating across provincial lines.
Want a clear picture of where your business actually stands?
IT Cares' security audits include a review of your data handling practices against Law 25 and PIPEDA, translated into a concrete, right-sized action plan. For ongoing support keeping your privacy program current as your business grows across provinces, our cybersecurity services and managed IT services can help maintain it rather than leaving it as a one-time project.
Frequently Asked Questions
Want a Clear Read on Which Privacy Rules Actually Apply to Your Business?
IT Cares reviews your data handling across every province you operate in and gives you a concrete, right-sized compliance plan — not a generic checklist.
Comments (3)
We have staff in both Ontario and Quebec and honestly assumed one privacy policy covered everyone. The privacy officer publication requirement for Quebec was news to us — fixed it this week.
Didn't realize BC's PIPA was its own separate substantially similar law rather than just PIPEDA by another name. The comparison table made the whole landscape click.
The point about building to Law 25's standard everywhere rather than juggling separate processes per province is exactly the advice our lawyer gave us too. Good to see it laid out this clearly.
Leave a Comment