Law 25 vs PIPEDA: What Multi-Province Businesses Need to Know

Reviewed by IT Cares certified technicians · Updated July 2026

Map of Canada with Quebec highlighted illustrating the difference between Law 25 and federal PIPEDA privacy compliance for multi-province businesses
One business, multiple privacy regimes — Law 25 and PIPEDA don't conflict, but they don't map onto each other cleanly either.
🍁
Operating in Quebec and at least one other province? Our certified technicians can review whether your current setup actually satisfies both regimes.
Get a Free Assessment →

A business operating in Quebec and at least one other Canadian province is subject to more than one privacy law at once, and "just follow PIPEDA everywhere" stopped being sufficient the moment Quebec's Law 25 came into force. This isn't a hypothetical edge case for a small slice of Canadian businesses — any company with a Quebec office, Quebec employees (including remote staff), or a meaningful Quebec customer base is affected, alongside whatever privacy obligations apply to its activity in Ontario, British Columbia, Alberta, or elsewhere.

The confusion this creates is genuinely understandable. Canada doesn't have a single, unified private-sector privacy law the way some other jurisdictions do — it has a federal law (PIPEDA) that applies by default, several provinces with their own laws recognized as "substantially similar" to PIPEDA (Quebec's Law 25, British Columbia's PIPA, Alberta's PIPA), and sector-specific overlays in some provinces (like Ontario's PHIPA for health information) layered on top. A business operating across several of these lines at once needs to understand not just each law individually, but how they interact — and, in practice, which one actually sets the bar the business needs to build to.

This guide lays out, in plain language, how Law 25 and PIPEDA actually differ, what the "substantially similar law" designation means in practice, a detailed side-by-side comparison, a practical approach for building one compliance program that satisfies both regimes rather than running two in parallel, real-world scenarios, and realistic Canadian cost ranges for the compliance work involved.

A note before we start

This article is general information to help you understand the landscape and ask better questions of a privacy lawyer — it is not legal advice. Privacy law in Canada continues to evolve, and specific compliance obligations should always be confirmed with a lawyer familiar with both federal and Quebec privacy law before you rely on any general description in this guide.

Law 25, in Plain Language

Quebec's Law 25 (formally the Act respecting the protection of personal information in the private sector, and before that known as Bill 64 during its legislative process) rolled out in three phases, and understanding the phased timeline matters because it explains why some obligations feel newer and less settled than others:

Beyond the phased rollout, a few features of Law 25 are worth understanding as distinct from what many businesses assume a "typical" Canadian privacy law looks like: it requires designating a specific privacy officer whose title and contact information must be published; it requires maintaining a confidentiality incident register (not just reporting the serious incidents — logging all of them internally, retained for a minimum of five years); it has among the highest penalty ceilings of any Canadian privacy law, reaching up to $10 million CAD or 2% of worldwide turnover for administrative penalties, and up to $25 million or 4% for penal offences; and it applies to essentially every private-sector business carrying on activity in Quebec, with no small-business exemption based on size.

PIPEDA, in Plain Language

The federal Personal Information Protection and Electronic Documents Act (PIPEDA) has governed private-sector commercial activity across Canada since the early 2000s, built around ten fair information principles — accountability, identifying purposes, consent, limiting collection, limiting use/disclosure/retention, accuracy, safeguards, openness, individual access, and challenging compliance. It requires an accountable individual within the organization (though, unlike Law 25, it doesn't require that person's title and contact information be published), and it requires breach notification to the Office of the Privacy Commissioner of Canada (OPC) and to affected individuals when there's a "real risk of significant harm" (often abbreviated RROSH) — a threshold assessment the organization itself makes, considering sensitivity of the data and probability of misuse. Organizations must also keep records of every breach, even ones that don't meet the RROSH threshold for external reporting, for a minimum of 24 months.

PIPEDA's penalty regime, while it has been strengthened over time, remains more limited than Law 25's — which is one of the most consequential practical differences between the two laws for a business weighing where to focus its compliance effort.

The "Substantially Similar Law" Concept — Why This Actually Matters

Here's the mechanism that determines which law actually governs a given piece of your business's activity. PIPEDA includes a provision allowing provinces to have their own private-sector privacy legislation recognized as "substantially similar" to PIPEDA — and where a province's law has that designation, PIPEDA effectively steps back and the provincial law governs commercial activity within that province instead. Quebec's Law 25 has been recognized as substantially similar (following in the footsteps of its predecessor legislation), as has British Columbia's Personal Information Protection Act (PIPA) and Alberta's equivalent PIPA.

What this means practically: a business's Quebec-based commercial activity is governed by Law 25, not PIPEDA directly. Its British Columbia-based activity is governed by BC's PIPA. Its Alberta-based activity is governed by Alberta's PIPA. And its activity in provinces without their own substantially similar law — Ontario prominent among them for general private-sector activity — falls under PIPEDA by default. Interprovincial and international data flows (data moving between provinces, or between Canada and another country) generally remain subject to PIPEDA regardless of where the data originates, layered on top of whichever provincial law also applies.

📊 IT Cares field note: The most common misunderstanding we see isn't about which law applies in the abstract — most business owners can recite "Quebec has Law 25, the rest of Canada has PIPEDA" without difficulty. The mistake is underestimating how little Quebec-based activity is actually needed to trigger Law 25. A single remote employee working from Quebec, or a modest but real base of Quebec customers for an Ontario-headquartered online business, is enough. Businesses that assume Law 25 only applies if they have a physical Quebec office are working from an outdated and inaccurate mental model.

Not sure which privacy regime actually applies to your business?

Our certified technicians can map your data flows and flag where your current setup may fall short — from $119.99.

Law 25 vs PIPEDA: Full Comparison

Category Quebec Law 25 Federal PIPEDA
Scope / who it governs Private-sector commercial activity carried on in Quebec, involving personal information of individuals in Quebec — no small-business exemption Private-sector commercial activity in provinces without their own substantially similar law (e.g. Ontario), plus interprovincial/international data flows
Breach notification trigger “Confidentiality incident” presenting a risk of serious injury — notify the CAI and affected individuals “without delay” “Real risk of significant harm” (RROSH) — notify the OPC and affected individuals as soon as feasible
Internal incident record-keeping Mandatory confidentiality incident register logging ALL incidents (not just reportable ones), retained minimum 5 years Record of every breach of security safeguards, retained minimum 24 months
Privacy officer requirement Mandatory designated “person in charge of the protection of personal information”; title and contact info must be published Accountable individual required under the Accountability principle; no publication requirement
Consent standard Consent must be clear, free, and informed, given for specific purposes; separate consent required for sensitive information Meaningful consent required, calibrated to sensitivity of information and reasonable expectations
Privacy Impact Assessments Mandatory for certain information system projects and for any cross-border transfer of personal information Not formally mandated by statute, though recommended as best practice and expected in some regulatory guidance
Data subject rights Access, rectification, de-indexing/erasure (as of Sept 2023), data portability (as of Sept 2024) Access and correction rights; more limited erasure/portability rights than Law 25
Penalties Administrative penalties up to $10M CAD or 2% of worldwide turnover; penal offences up to $25M or 4% More limited penalty regime, though it has been strengthened over recent amendments
Cross-border transfer rules Requires an assessment (via PIA) of whether the destination provides adequate protection before transferring data outside Quebec Requires comparable safeguards for data transferred to third parties, including outside Canada, generally via contractual means

Reading across the table, one pattern is consistent: on nearly every dimension, Law 25 sets a higher, more specific, and more rigorously enforced bar than PIPEDA currently does. That's the single most useful takeaway for a multi-province business trying to decide where to focus its compliance effort — building to Law 25's standard organization-wide will, in practice, satisfy PIPEDA's requirements as well, while the reverse is not true.

Building One Compliance Program for Both Regimes

Rather than maintaining separate, lighter-touch compliance processes for each province a business operates in, most multi-province businesses find it simpler — and ultimately safer — to build a single program calibrated to the stricter regime (Law 25) and apply it organization-wide. Here's the practical sequence.

1

Map exactly where your data collection actually happens

Identify every province where you have employees (including fully remote staff), customers, or data storage/processing activity. Many businesses discover, once they actually map it, more Quebec-subject activity than they assumed going in.

2

Designate one privacy officer for the whole organization

A single person or small team can typically fulfill both Law 25's designated-officer requirement and PIPEDA's accountable-individual principle at once, provided their title and contact information are published in a way that satisfies Law 25's specific publication requirement.

3

Build one incident register that satisfies the stricter bar

Design your internal breach/incident logging process around Law 25's more demanding requirements (log every incident, retain 5 years) rather than maintaining two separate systems — this single register then satisfies PIPEDA's 24-month retention requirement automatically, since 5 years exceeds 24 months.

4

Align consent language to the stricter standard everywhere

Rather than drafting province-specific consent language, use Law 25-compliant consent practices (clear, free, informed, purpose-specific, with separate consent for sensitive data) across your whole customer base — it satisfies PIPEDA's meaningful consent standard as well and avoids the complexity of maintaining multiple versions.

5

Build a breach response process that satisfies both notification timelines

Design your incident response plan to trigger notification fast enough to satisfy Law 25's “without delay” standard for Quebec-affected individuals, and route notification to both the CAI and OPC as applicable based on which individuals were affected and where.

6

Review cross-border and interprovincial data transfer contracts

Confirm vendor and processor contracts include adequate safeguard language for any data crossing provincial or international lines, and complete a Privacy Impact Assessment for any project involving a cross-border transfer of Quebec residents' personal information.

Multi-Province Compliance Checklist

Work through this to confirm your organization is actually built to the standard that applies everywhere you operate, not just where you assumed it mattered most.

☐ Mapped every province where you have employees, customers, or data processing activity

☐ Designated a single privacy officer for the whole organization

☐ Published the privacy officer's title and contact information (required if Quebec-subject)

☐ Built one confidentiality incident register meeting Law 25's 5-year retention standard

☐ Aligned consent language to Law 25's stricter standard across all provinces

☐ Confirmed breach notification workflow covers both CAI and OPC timelines and formats

☐ Reviewed vendor/processor contracts for cross-border and interprovincial transfer safeguards

☐ Completed or scheduled a Privacy Impact Assessment for any project involving cross-border data transfer

Real-World Scenarios: How This Plays Out

The following case studies are composite, fictional scenarios built from patterns common across multi-province businesses — they illustrate how these compliance gaps actually surface, not a specific real company.

Case study: a retailer with stores in Quebec and Ontario

A home goods retailer with 14 stores — 9 in Ontario, 5 in Quebec — had built its loyalty program privacy policy around PIPEDA, assuming a single national policy would cover the whole chain. During a routine review triggered by a new e-commerce platform launch, the retailer's newly engaged privacy consultant flagged that its Quebec stores' loyalty program had never designated or published a privacy officer, and its incident logging process retained records for only 12 months, well short of Law 25's 5-year minimum. The retailer restructured to a single national privacy officer role (assigned to its existing director of customer experience, with contact information added to its website footer) and extended its incident register retention to 5 years across the board, at a one-time setup cost of roughly $6,500 CAD in consultant time plus ongoing minimal administrative overhead.

Case study: a professional services firm with remote staff in BC and Quebec

A 28-person marketing and design consultancy headquartered in Toronto had grown its remote team to include 4 employees in British Columbia and 3 in Quebec. The firm's HR data handling — payroll, benefits enrollment, performance records — had never been reviewed against either BC's PIPA or Law 25, having been set up years earlier under a PIPEDA-only assumption when the firm was Ontario-only. An HR systems upgrade project prompted a compliance review that identified the Quebec employees' data required a completed Privacy Impact Assessment given the new HR platform involved a cross-border transfer (the new vendor's servers were in the United States). The firm completed the PIA with support from an outsourced privacy consultant over three weeks, at a cost of approximately $3,200 CAD, before finalizing the platform migration.

Case study: a SaaS company headquartered in Toronto with a Montreal office

A 55-employee software company opened a 12-person Montreal engineering office as part of a talent expansion strategy. The company's existing privacy program, built to PIPEDA's standard for its Ontario headquarters, required a substantial update once the Montreal office triggered Law 25 obligations for both its employees and any Quebec-based customers acquired going forward. The company engaged a privacy lawyer to update its privacy policy, designate and publish a privacy officer, and build a Law 25-compliant incident register, at a combined legal and implementation cost of roughly $11,000 CAD — a cost the company's leadership noted would have been avoided almost entirely had the compliance review happened before the Montreal office opened rather than three months after.

Budget Reality Check: What Multi-Province Compliance Actually Costs

Compliance costs scale with organizational complexity — number of provinces involved, data volume, whether existing systems need to be reworked or just documented — but here's how it typically breaks down by rough business size:

These are directional ranges for budgeting conversations, not fixed quotes — actual cost depends heavily on how much existing infrastructure needs to be reworked versus simply documented. What's consistent across every size: the cost of building compliance proactively is consistently smaller than the cost of a rushed, reactive compliance project triggered by a new office opening, a new province of customers, or — worse — an actual incident that reveals the gap for the first time.

For a deeper look at the specific privacy officer role this whole structure depends on, see our guide on appointing a privacy officer for SMBs, and for the incident register specifically, our guide on confidentiality incident register obligations under Law 25.

Canadian Government Resources

A few Canadian regulatory and institutional resources are worth bookmarking for ongoing reference:

Want a clear picture of where your business actually stands?

IT Cares' security audits include a review of your data handling practices against Law 25 and PIPEDA, translated into a concrete, right-sized action plan. For ongoing support keeping your privacy program current as your business grows across provinces, our cybersecurity services and managed IT services can help maintain it rather than leaving it as a one-time project.

Frequently Asked Questions

If my business is federally incorporated, does PIPEDA override Law 25 in Quebec?
No — incorporation status doesn't determine which privacy law applies. What matters is where the commercial activity actually takes place and involves personal information. A federally incorporated business operating in Quebec is still subject to Law 25 for its Quebec-based commercial activities, because Quebec's Law 25 has been recognized as substantially similar to PIPEDA, meaning it governs in place of PIPEDA for that provincial activity. PIPEDA remains relevant for interprovincial or international data flows and for activity in provinces without their own substantially similar law. Most multi-province businesses end up subject to a blend of regimes depending on where each part of their data collection and use actually happens.
Do I need a separate privacy officer for Quebec and for the rest of Canada?
Not necessarily — a single person or team can typically fulfill both roles, but the specific Law 25 requirement (publishing the privacy officer's title and contact information) applies specifically because of your Quebec-subject activity. Many multi-province businesses designate one privacy officer for the whole organization and simply ensure that person's contact information is published in a way that satisfies Law 25's publication requirement, while also fulfilling PIPEDA's more general "accountable individual" principle for the rest of the business. The key is making sure the stricter Quebec-specific obligations are actually met, not assuming a PIPEDA-level accountability structure automatically satisfies Law 25.
What happens if a data breach affects customers in both Quebec and Ontario?
You'll likely need to notify both regulators — the CAI for the Quebec-based individuals affected and the OPC for individuals affected under PIPEDA (which, for private-sector activity, generally covers activity in provinces without their own substantially similar law, including Ontario) — along with notifying every affected individual directly, regardless of province. The notification content and timeline expectations differ slightly between the two regimes, so many multi-province businesses build a single incident response process calibrated to the stricter of the two requirements, then execute both notifications from that one process rather than running two entirely separate response tracks.
Are British Columbia and Alberta's privacy laws the same as PIPEDA?
Not identical, but both provinces have their own private-sector privacy legislation — commonly referred to as PIPA in each case — that has been recognized as substantially similar to PIPEDA, similar to Quebec's Law 25. This means businesses operating primarily within BC or Alberta are generally governed by that province's PIPA rather than PIPEDA directly for their in-province commercial activity, though the practical requirements are broadly comparable to PIPEDA's. Ontario, by contrast, does not have its own general private-sector privacy law (aside from sector-specific laws like PHIPA for health information), so PIPEDA applies by default there for private-sector commercial activity.
Is Law 25 really stricter than PIPEDA, or just different?
In several concrete respects, Law 25 is meaningfully stricter, not just differently structured. It mandates a designated and published privacy officer (PIPEDA only requires an accountable individual, with no publication requirement), it requires a confidentiality incident register retained for a minimum of five years, it mandates privacy impact assessments for certain projects and for cross-border data transfers, and its penalty regime — up to $10 million CAD or 2% of worldwide turnover for administrative penalties, up to $25 million or 4% for penal offences — is substantially higher than what PIPEDA currently provides for. A business that builds its compliance program to Law 25's standard will, in practice, exceed what PIPEDA requires almost everywhere else in Canada.
Can a small business with under 20 employees be exempt from Law 25?
No — Law 25 does not include a small-business exemption based on employee count or revenue. Any private-sector organization carrying on business in Quebec and handling personal information is subject to it, regardless of size. This is a common misconception carried over from other regulatory contexts where small businesses are exempted, and it catches sole proprietors and small partnerships off guard when they assume their size puts them outside the law's scope.
Does Law 25 apply to a business with no physical office in Quebec but Quebec customers?
Generally, yes, if the business is carrying on commercial activity involving the personal information of individuals in Quebec — a physical office in the province is not the determining factor. An e-commerce business based in Ontario that regularly sells to and collects personal information from Quebec residents can be subject to Law 25's requirements for that portion of its activity, similar to how GDPR can apply to a Canadian business with no EU office. This is a frequently overlooked trigger for online and multi-province businesses that assume physical presence is what matters.
What's the single most practical step for a multi-province business to take first?
Map exactly where your personal information collection actually happens — which provinces your customers, employees, and data storage/processing touch — before building or updating any compliance program. Many businesses discover, once they actually map it, that they have more Quebec-subject activity than assumed (a single Quebec-based remote employee or a modest but real base of Quebec customers is enough to trigger Law 25), which changes the entire compliance approach. Building to the strictest applicable standard (in practice, Law 25) across the whole organization, rather than maintaining separate lighter-touch processes per province, is usually simpler to execute and audit consistently.

Want a Clear Read on Which Privacy Rules Actually Apply to Your Business?

IT Cares reviews your data handling across every province you operate in and gives you a concrete, right-sized compliance plan — not a generic checklist.

Comments (3)

JB
Julie B., Ottawa
July 23, 2026

We have staff in both Ontario and Quebec and honestly assumed one privacy policy covered everyone. The privacy officer publication requirement for Quebec was news to us — fixed it this week.

MT
Marc T., Vancouver
July 22, 2026

Didn't realize BC's PIPA was its own separate substantially similar law rather than just PIPEDA by another name. The comparison table made the whole landscape click.

CS
Chantal S., Gatineau
July 20, 2026

The point about building to Law 25's standard everywhere rather than juggling separate processes per province is exactly the advice our lawyer gave us too. Good to see it laid out this clearly.

Leave a Comment

Need Help?