Quebec Law 25 in 2027: What Businesses Still Need to Do

Reviewed by IT Cares certified technicians · Updated August 2026

Quebec Law 25 three years later — compliance roadmap for businesses heading into 2027
Law 25's phased rollout is complete — the work now is keeping an existing compliance program current, not starting from zero.
⚖️
Not sure if your Law 25 program still matches what your business actually does? Our certified technicians review your current setup against the law's current requirements — not the requirements from whenever you first got compliant.
Book a Review →

Three years after Law 25's heaviest wave of obligations took effect, the law is no longer "rolling out" — it is fully in force, and has been since its third and final phase landed on September 22, 2024. There is no new statutory deadline waiting in 2027. And yet, in our work helping Quebec and Canadian businesses stay compliant, we keep running into the same pattern: a company did the work in 2022 or 2023, filed it away as "done," and hasn't touched it since — even as its tools, vendors, and data practices have moved on without it.

This article is a three-years-later assessment, not a rehash of the basics. It covers what's genuinely changed since the law's full rollout, what's publicly known about how the CAI is actually enforcing it, and a concrete roadmap for keeping a compliance program current heading into 2027 — a year that won't bring a new legal phase, but will likely bring a more mature, more tested regulator and a harder-to-ignore federal privacy reform picture for businesses operating outside Quebec. For the mechanics of the penalty scale itself, our Law 25 fines and real cases guide remains the dedicated reference; for the specific overlap with federal privacy law, see our Law 25 vs PIPEDA guide.

Who wrote this guide

This article was written and reviewed by IT Cares certified technicians who work directly with Quebec and Canadian small and mid-sized businesses on the practical side of Law 25 compliance. We're not a law firm and this isn't legal advice; for a specific compliance determination, consult a lawyer. What we offer is an accurate, grounded read on where enforcement actually stands and the practical controls that keep a program current.

The Three-Phase Rollout, Now Complete

To understand where Law 25 stands today, it helps to look back at how it actually arrived. The law (formerly Bill 64) came into force in three deliberate stages, each adding a distinct layer of obligation.

Phase 1 — September 22, 2022: governance foundations

The first wave required organizations to designate a privacy officer (by default the most senior officer, unless formally delegated), maintain a confidentiality incident registry, and notify the CAI and affected individuals of incidents presenting a risk of serious injury. This is the phase that forced most Quebec businesses to name an identifiable, accountable person for the first time.

Phase 2 — September 22, 2023: the heaviest wave

The second phase introduced the bulk of the law's real weight: clear, specific consent separated from general terms of use, a privacy policy written in plain language, mandatory privacy impact assessments (PIAs) before acquiring or overhauling any system handling personal information, a right to de-indexing, transparency requirements for decisions based exclusively on automated processing, mandatory registration of certain biometric databases with the CAI, and — critically — the full administrative and penal penalty framework. This is the phase that turned Law 25 from a theoretical obligation into a genuine financial risk.

Phase 3 — September 22, 2024: the final piece

The third phase introduced the right to data portability, allowing an individual to request that their personal information be transferred to another organization in a structured, commonly used technological format. Since that date, everything currently written into the law has been in force. There is no additional phase scheduled.

"Fully in force" doesn't mean "nothing changes"

This is the trap a lot of small businesses fall into: because the last legal phase landed in September 2024, some conclude the Law 25 file is closed. In practice, the opposite is true. A law that's been fully enforceable for under two years is a law whose enforcement is still actively maturing — building precedent, capacity, and rigor — which is exactly the dynamic we've watched unfold since 2024.

What's Actually Known About CAI Enforcement, Three Years In

Rather than speculate, here's what can be said with a reasonable degree of confidence, based on the CAI's own public information:

For the most current figures and decisions, the CAI's own site, cai.gouv.qc.ca, remains the only authoritative source — it publishes annual activity reports along with select decisions and public-interest guidance. Our Law 25 fines and real cases guide covers the full penalty scale and the process that leads to one in far more depth, and is worth reading alongside this bilan.

Is your Law 25 program still dated 2022 or 2023?

Our certified technicians run a current-state review — incident registry, privacy policy, security controls — and show you exactly where your business stands before 2027.

What Has Actually Changed for Businesses Since 2023

Beyond the statute itself, our technicians see real behavioural shifts among the businesses we work with:

Consent forms have gotten more professional

In 2022, pre-checked boxes and consent buried inside ten-page terms of service were still common. By 2026, most of the businesses we work with present distinct, purpose-specific, plain-language consent requests — as much a cultural shift as a legal one.

PIAs went from exception to routine — unevenly

The most advanced businesses now build a privacy impact assessment into their standard process for adopting any new tool, including AI tools. Others still treat the PIA as a one-time box checked in 2023, never repeated for anything adopted since.

Incidents are detected better, not necessarily handled better

Greater staff awareness has meant more minor incidents get caught early — a genuine sign of organizational maturity. But many businesses still lack a clear process for quickly assessing whether an incident meets the "risk of serious injury" threshold that triggers mandatory notification, which remains the most common source of problematic delay.

Comparison Table: In Force Today vs. What to Watch for 2027

The table below separates what's already fully applicable from the trends and emerging pressures a business should actively watch heading into 2027 — not because a new legal deadline is scheduled, but because the enforcement and regulatory context keeps shifting.

Obligation or issueStatus today (2026)What to watch for 2027
Privacy officer designationMandatory since Sept. 2022Increasingly scrutinized during CAI investigations; ongoing training expected, not just an initial appointment
Confidentiality incident registryMandatory since Sept. 2022CAI increasingly checks completeness and quality, not just formal existence
Clear, separate consentMandatory since Sept. 2023Generic banners and pre-checked boxes drawing less tolerance in investigations
Mandatory PIAs for new projectsMandatory since Sept. 2023Ongoing obligation for every new tool or system (including AI), not a one-time exercise
Plain-language privacy policyMandatory since Sept. 2023Expected to be updated with every real change in practice, not just a symbolic annual review
Right to data portabilityMandatory since Sept. 2024More frequent requests as consumer awareness of the right grows
AMPs and penal finesIn force since Sept. 2023Administrative case history still building; penalty frequency and amounts likely to rise as the CAI matures
Federal privacy law harmonization (PIPEDA reform)Not directly required for Quebec-only businessesGrowing pressure for multi-province businesses as federal reform evolves
AI-driven decision systemsTransparency obligations already apply to fully automated decisionsScrutiny expected to sharpen as SMB adoption of AI tools accelerates

Three Canadian Businesses, Three Trajectories Since 2022

The following are clearly illustrative, hypothetical scenarios — not real CAI cases — built to show three typical trajectories our technicians have observed since the law's full rollout. They don't represent any real business and are no substitute for the CAI's own published decisions at cai.gouv.qc.ca.

Illustrative scenario — Ottawa: compliance treated as a living process

Suppose a professional services firm in Ottawa with about 30 staff, serving clients in both Ontario and Quebec, built out its Law 25 program in 2022 — privacy officer, incident registry, updated policy. Rather than treating that as finished, the firm folded an annual review into its governance calendar, including a fresh PIA every time it evaluates a new AI tool for client intake. In 2026, when a minor complaint arrives about data retention, the firm can show a continuous documented trail back to 2022 — the kind of factor that, under the CAI's public criteria, weighs heavily toward a corrective resolution rather than a monetary penalty.

Illustrative scenario — Calgary: a compliance program frozen in 2023

Suppose a 15-person retailer in Calgary, selling online to customers across Canada including Quebec, completed its core Law 25 obligations during the heaviest 2023 wave and hasn't revisited them since. In this scenario, the company later adopts a new third-party loyalty-program platform without ever running a PIA for it or updating its privacy policy to reflect the change. A data exposure tied to that new platform in 2026 surfaces this governance gap during the CAI's review, which treats the case more seriously than an isolated lapse — specifically because a clear change in practice was never reflected in an updated compliance record.

Illustrative scenario — Halifax: getting ahead of multi-province harmonization

Suppose a 20-person software company based in Halifax serves clients across Atlantic Canada and Quebec. In this scenario, rather than running two separate compliance tracks, the company built its program from the start around Law 25's stricter requirements — the highest bar among the regimes its clients fall under — so that it can absorb future federal privacy reform changes without rebuilding its governance framework each time a different province's rules shift.

What these three trajectories have in common

It isn't the 2022 or 2023 starting point that separates these three businesses by 2026 — it's how consistently each one kept its program current against how its actual tools and practices evolved. That gap is exactly what this roadmap is meant to close.

The Roadmap: What to Still Do Before 2027

1

Run a current-state compliance review, not a recap of 2022-2023

An audit of what you actually do today — not what was documented three years ago — surfaces the gaps that accumulate silently, especially any new tool, vendor, or AI system adopted since your original compliance work.

2

Re-run PIAs for every tool adopted since your last review

If your business has adopted a new CRM, AI tool, or cloud platform since 2023, it needs its own privacy impact assessment — not a cosmetic update tacked onto the old one.

3

Document everything, continuously

The scenarios above make the point clearly: continuous documentation of your compliance effort is your strongest protection in an investigation. A business that can show an unbroken trail since 2022 is treated very differently than one reconstructing its history after the fact.

4

Retrain staff, not just new hires

Initial training from 2022 or 2023 fades and doesn't reach employees hired since. An annual refresher, even brief, keeps the vigilance needed to catch an incident early.

5

Watch CAI guidance and federal reform actively

As the CAI publishes new decisions and federal privacy law reform evolves, concrete expectations for businesses will keep sharpening. A light but continuous watch avoids unpleasant surprises.

Checklist: Is Your Law 25 Program Still Alive?

A ☐ checklist for leadership, not just IT

  • ☐ Your confidentiality incident registry covers every year since 2022 without gaps
  • ☐ Every new tool or system adopted since your original compliance work (including AI) has had its own PIA
  • ☐ Your privacy policy has been revised at least once since its original 2023 publication
  • ☐ Your data portability process (in force since 2024) is documented, tested, and known to your team
  • ☐ A Law 25 compliance review is scheduled annually, not just once at initial setup
  • ☐ Someone is actively watching CAI published decisions and federal privacy reform developments
  • ☐ Leadership understands the settlement option available if a gap is identified by the CAI
  • ☐ Your privacy officer receives ongoing training, not just an initial designation
  • ☐ Employees hired after your original 2022-2023 training have received their own Law 25 training

What Maintaining Compliance Costs in 2026-2027 (CAD)

Unlike initial compliance work, which is usually more expensive because it starts from zero, maintaining Law 25 compliance is typically a smaller, recurring investment — as long as gaps aren't left to accumulate. The ranges below reflect indicative 2026 market pricing from Quebec and Canadian compliance and IT security providers, not an official rate card.

Maintenance activityIndicative 2026 range (CAD)Recommended frequency
Current-state Law 25 compliance review$500 – $2,500Annual
Privacy policy refresh (existing policy)$300 – $1,500With every practice change, or annual
New PIA for a recently adopted tool or project$400 – $3,000 depending on complexityEvery new system or AI tool
Staff refresher training$200 – $1,200Annual, plus at hiring
Incident response and portability process test$300 – $1,500Annual
Regulatory watch (in-house or outsourced)Varies by arrangementOngoing

This level of investment is typically far lower than the real cost of a compliance gap discovered late — before even factoring in indirect costs like lost client trust or the time spent on crisis management. It's the same cost-benefit logic that makes cyber insurance for small business worth pairing with an ongoing compliance program rather than a one-time project.

Canadian Government Resources

Don't let a 2022-2023 compliance program quietly fall behind

IT Cares' security audits compare your actual current data practices against what Law 25 requires today, close the gaps that have accumulated since your original compliance work, and document your ongoing diligence. If ongoing maintenance makes sense for your business, our managed IT services can help keep these controls current year over year.

Frequently Asked Questions

Is Law 25 fully in force yet?
Yes. Law 25 rolled out in three phases: September 22, 2022 (privacy officer, incident registry, mandatory breach notification), September 22, 2023 (consent, privacy policy, mandatory PIAs, the penalty framework), and September 22, 2024 (data portability). Since September 2024, every provision currently on the books is in force — there is no further phase-in scheduled.
If Law 25 is already fully in force, what actually changes for 2027?
There's no new statutory deadline set for 2027 in the current text of the law — every obligation has applied since September 2024. What's changing instead is the CAI's enforcement maturity as it builds case history and investigative capacity, the ongoing pressure from federal privacy law reform for businesses operating across provinces, and growing scrutiny of AI-driven decision systems. A business that treated compliance as a project finished in 2024 risks quietly falling behind these shifts.
Has the CAI actually issued penalties since Law 25 took effect?
The CAI has had the power to issue administrative monetary penalties since September 2023 and publishes some of its decisions publicly. Its investigative activity is real — hundreds of confidentiality incident reports are filed with it each year. For the current, authoritative record of published decisions and penalties, the CAI's own site (cai.gouv.qc.ca) remains the only reliable source, rather than generic estimates.
How is this article different from your Law 25 fines guide?
Our Law 25 fines guide (law25-fines-real-cases-amounts.html) focuses specifically on the penalty scale itself, what triggers a fine, and size-adjusted exposure scenarios. This article takes a different, forward-looking angle: a three-years-later assessment of what's actually changed since the law took full effect, and a practical roadmap for staying current heading into 2027, including emerging issues like AI and multi-province harmonization.
Do we need to redo our Law 25 compliance work from 2022 or 2023?
Not necessarily from scratch, but a review is strongly recommended. A privacy policy, incident registry, or privacy impact assessment completed in 2022 may no longer reflect what your business actually does in 2026, especially if you've adopted new tools, vendors, or AI systems since. Law 25 compliance is an ongoing practice, not a project you finish once and file away.
Does Law 25 apply to businesses outside Quebec?
Law 25 applies based on where the individual whose data is involved is located and where the business carries on activities, not simply where a company's head office sits. A business based in Ontario or Alberta serving Quebec clients still needs to comply, often alongside the federal PIPEDA framework. Our Law 25 vs PIPEDA guide covers this multi-province overlap in detail.
Where can businesses get help staying current with Law 25?
The CAI (cai.gouv.qc.ca) publishes interpretation guidance and compliance tools. The Office of the Privacy Commissioner of Canada (opc.gc.ca) is useful for the federal side of multi-province compliance. The Business Development Bank of Canada (bdc.ca) offers advisory support that can include financing for compliance-related technology upgrades.

Turn This Into a Concrete 2027 Action Plan

IT Cares reviews your current data practices against what Law 25 actually requires today, closes the gaps that accumulated since your original compliance work, and helps you document ongoing diligence heading into 2027.

Comments (3)

RT
Ryan T., Ottawa
August 4, 2026

We assumed we were done since 2023. Turns out our new CRM never got a PIA. Fixing that this month.

AK
Amina K., Calgary
August 1, 2026

The point about documentation being continuous, not a one-time file, was the wake-up call we needed. We have good practices but nothing written down.

MD
Marc D., Halifax
July 29, 2026

Good to see this framed as ongoing rather than a checkbox. We serve clients in three provinces so the harmonization angle is exactly what we needed to think through.

Leave a Comment

Need Help?