Three years after Law 25's heaviest wave of obligations took effect, the law is no longer "rolling out" — it is fully in force, and has been since its third and final phase landed on September 22, 2024. There is no new statutory deadline waiting in 2027. And yet, in our work helping Quebec and Canadian businesses stay compliant, we keep running into the same pattern: a company did the work in 2022 or 2023, filed it away as "done," and hasn't touched it since — even as its tools, vendors, and data practices have moved on without it.
This article is a three-years-later assessment, not a rehash of the basics. It covers what's genuinely changed since the law's full rollout, what's publicly known about how the CAI is actually enforcing it, and a concrete roadmap for keeping a compliance program current heading into 2027 — a year that won't bring a new legal phase, but will likely bring a more mature, more tested regulator and a harder-to-ignore federal privacy reform picture for businesses operating outside Quebec. For the mechanics of the penalty scale itself, our Law 25 fines and real cases guide remains the dedicated reference; for the specific overlap with federal privacy law, see our Law 25 vs PIPEDA guide.
Who wrote this guide
This article was written and reviewed by IT Cares certified technicians who work directly with Quebec and Canadian small and mid-sized businesses on the practical side of Law 25 compliance. We're not a law firm and this isn't legal advice; for a specific compliance determination, consult a lawyer. What we offer is an accurate, grounded read on where enforcement actually stands and the practical controls that keep a program current.
The Three-Phase Rollout, Now Complete
To understand where Law 25 stands today, it helps to look back at how it actually arrived. The law (formerly Bill 64) came into force in three deliberate stages, each adding a distinct layer of obligation.
Phase 1 — September 22, 2022: governance foundations
The first wave required organizations to designate a privacy officer (by default the most senior officer, unless formally delegated), maintain a confidentiality incident registry, and notify the CAI and affected individuals of incidents presenting a risk of serious injury. This is the phase that forced most Quebec businesses to name an identifiable, accountable person for the first time.
Phase 2 — September 22, 2023: the heaviest wave
The second phase introduced the bulk of the law's real weight: clear, specific consent separated from general terms of use, a privacy policy written in plain language, mandatory privacy impact assessments (PIAs) before acquiring or overhauling any system handling personal information, a right to de-indexing, transparency requirements for decisions based exclusively on automated processing, mandatory registration of certain biometric databases with the CAI, and — critically — the full administrative and penal penalty framework. This is the phase that turned Law 25 from a theoretical obligation into a genuine financial risk.
Phase 3 — September 22, 2024: the final piece
The third phase introduced the right to data portability, allowing an individual to request that their personal information be transferred to another organization in a structured, commonly used technological format. Since that date, everything currently written into the law has been in force. There is no additional phase scheduled.
"Fully in force" doesn't mean "nothing changes"
This is the trap a lot of small businesses fall into: because the last legal phase landed in September 2024, some conclude the Law 25 file is closed. In practice, the opposite is true. A law that's been fully enforceable for under two years is a law whose enforcement is still actively maturing — building precedent, capacity, and rigor — which is exactly the dynamic we've watched unfold since 2024.
What's Actually Known About CAI Enforcement, Three Years In
Rather than speculate, here's what can be said with a reasonable degree of confidence, based on the CAI's own public information:
- Reporting volume is real and meaningful. The CAI has received several hundred confidentiality incident reports per recent fiscal year — clear evidence that the mandatory notification mechanism, in place since 2022, is being used regularly by Quebec organizations rather than sitting idle.
- CAI decisions are public. When the CAI issues a formal decision — whether it includes a corrective order, an administrative monetary penalty, or both — that decision becomes public, adding reputational exposure on top of any financial penalty.
- A settlement path exists. The law allows an organization facing an administrative monetary penalty to enter into an agreement with the CAI setting out the corrective measures it commits to — another structural incentive that rewards fast, cooperative correction over confrontation.
- Civil recourse remains available independently. Regardless of any CAI action, individuals retain the right to sue for privacy violations, including through class actions — a separate risk track from the regulatory process entirely.
- The penal prosecution window runs five years. The CAI has up to five years from the date of an offence to initiate a penal prosecution, meaning violations from as far back as 2022-2023 remain potentially exposed to prosecution until 2027-2028.
For the most current figures and decisions, the CAI's own site, cai.gouv.qc.ca, remains the only authoritative source — it publishes annual activity reports along with select decisions and public-interest guidance. Our Law 25 fines and real cases guide covers the full penalty scale and the process that leads to one in far more depth, and is worth reading alongside this bilan.
Is your Law 25 program still dated 2022 or 2023?
Our certified technicians run a current-state review — incident registry, privacy policy, security controls — and show you exactly where your business stands before 2027.
What Has Actually Changed for Businesses Since 2023
Beyond the statute itself, our technicians see real behavioural shifts among the businesses we work with:
Consent forms have gotten more professional
In 2022, pre-checked boxes and consent buried inside ten-page terms of service were still common. By 2026, most of the businesses we work with present distinct, purpose-specific, plain-language consent requests — as much a cultural shift as a legal one.
PIAs went from exception to routine — unevenly
The most advanced businesses now build a privacy impact assessment into their standard process for adopting any new tool, including AI tools. Others still treat the PIA as a one-time box checked in 2023, never repeated for anything adopted since.
Incidents are detected better, not necessarily handled better
Greater staff awareness has meant more minor incidents get caught early — a genuine sign of organizational maturity. But many businesses still lack a clear process for quickly assessing whether an incident meets the "risk of serious injury" threshold that triggers mandatory notification, which remains the most common source of problematic delay.
Comparison Table: In Force Today vs. What to Watch for 2027
The table below separates what's already fully applicable from the trends and emerging pressures a business should actively watch heading into 2027 — not because a new legal deadline is scheduled, but because the enforcement and regulatory context keeps shifting.
| Obligation or issue | Status today (2026) | What to watch for 2027 |
|---|---|---|
| Privacy officer designation | Mandatory since Sept. 2022 | Increasingly scrutinized during CAI investigations; ongoing training expected, not just an initial appointment |
| Confidentiality incident registry | Mandatory since Sept. 2022 | CAI increasingly checks completeness and quality, not just formal existence |
| Clear, separate consent | Mandatory since Sept. 2023 | Generic banners and pre-checked boxes drawing less tolerance in investigations |
| Mandatory PIAs for new projects | Mandatory since Sept. 2023 | Ongoing obligation for every new tool or system (including AI), not a one-time exercise |
| Plain-language privacy policy | Mandatory since Sept. 2023 | Expected to be updated with every real change in practice, not just a symbolic annual review |
| Right to data portability | Mandatory since Sept. 2024 | More frequent requests as consumer awareness of the right grows |
| AMPs and penal fines | In force since Sept. 2023 | Administrative case history still building; penalty frequency and amounts likely to rise as the CAI matures |
| Federal privacy law harmonization (PIPEDA reform) | Not directly required for Quebec-only businesses | Growing pressure for multi-province businesses as federal reform evolves |
| AI-driven decision systems | Transparency obligations already apply to fully automated decisions | Scrutiny expected to sharpen as SMB adoption of AI tools accelerates |
Three Canadian Businesses, Three Trajectories Since 2022
The following are clearly illustrative, hypothetical scenarios — not real CAI cases — built to show three typical trajectories our technicians have observed since the law's full rollout. They don't represent any real business and are no substitute for the CAI's own published decisions at cai.gouv.qc.ca.
Illustrative scenario — Ottawa: compliance treated as a living process
Suppose a professional services firm in Ottawa with about 30 staff, serving clients in both Ontario and Quebec, built out its Law 25 program in 2022 — privacy officer, incident registry, updated policy. Rather than treating that as finished, the firm folded an annual review into its governance calendar, including a fresh PIA every time it evaluates a new AI tool for client intake. In 2026, when a minor complaint arrives about data retention, the firm can show a continuous documented trail back to 2022 — the kind of factor that, under the CAI's public criteria, weighs heavily toward a corrective resolution rather than a monetary penalty.
Illustrative scenario — Calgary: a compliance program frozen in 2023
Suppose a 15-person retailer in Calgary, selling online to customers across Canada including Quebec, completed its core Law 25 obligations during the heaviest 2023 wave and hasn't revisited them since. In this scenario, the company later adopts a new third-party loyalty-program platform without ever running a PIA for it or updating its privacy policy to reflect the change. A data exposure tied to that new platform in 2026 surfaces this governance gap during the CAI's review, which treats the case more seriously than an isolated lapse — specifically because a clear change in practice was never reflected in an updated compliance record.
Illustrative scenario — Halifax: getting ahead of multi-province harmonization
Suppose a 20-person software company based in Halifax serves clients across Atlantic Canada and Quebec. In this scenario, rather than running two separate compliance tracks, the company built its program from the start around Law 25's stricter requirements — the highest bar among the regimes its clients fall under — so that it can absorb future federal privacy reform changes without rebuilding its governance framework each time a different province's rules shift.
What these three trajectories have in common
It isn't the 2022 or 2023 starting point that separates these three businesses by 2026 — it's how consistently each one kept its program current against how its actual tools and practices evolved. That gap is exactly what this roadmap is meant to close.
The Roadmap: What to Still Do Before 2027
Run a current-state compliance review, not a recap of 2022-2023
An audit of what you actually do today — not what was documented three years ago — surfaces the gaps that accumulate silently, especially any new tool, vendor, or AI system adopted since your original compliance work.
Re-run PIAs for every tool adopted since your last review
If your business has adopted a new CRM, AI tool, or cloud platform since 2023, it needs its own privacy impact assessment — not a cosmetic update tacked onto the old one.
Document everything, continuously
The scenarios above make the point clearly: continuous documentation of your compliance effort is your strongest protection in an investigation. A business that can show an unbroken trail since 2022 is treated very differently than one reconstructing its history after the fact.
Retrain staff, not just new hires
Initial training from 2022 or 2023 fades and doesn't reach employees hired since. An annual refresher, even brief, keeps the vigilance needed to catch an incident early.
Watch CAI guidance and federal reform actively
As the CAI publishes new decisions and federal privacy law reform evolves, concrete expectations for businesses will keep sharpening. A light but continuous watch avoids unpleasant surprises.
Checklist: Is Your Law 25 Program Still Alive?
A ☐ checklist for leadership, not just IT
- ☐ Your confidentiality incident registry covers every year since 2022 without gaps
- ☐ Every new tool or system adopted since your original compliance work (including AI) has had its own PIA
- ☐ Your privacy policy has been revised at least once since its original 2023 publication
- ☐ Your data portability process (in force since 2024) is documented, tested, and known to your team
- ☐ A Law 25 compliance review is scheduled annually, not just once at initial setup
- ☐ Someone is actively watching CAI published decisions and federal privacy reform developments
- ☐ Leadership understands the settlement option available if a gap is identified by the CAI
- ☐ Your privacy officer receives ongoing training, not just an initial designation
- ☐ Employees hired after your original 2022-2023 training have received their own Law 25 training
What Maintaining Compliance Costs in 2026-2027 (CAD)
Unlike initial compliance work, which is usually more expensive because it starts from zero, maintaining Law 25 compliance is typically a smaller, recurring investment — as long as gaps aren't left to accumulate. The ranges below reflect indicative 2026 market pricing from Quebec and Canadian compliance and IT security providers, not an official rate card.
| Maintenance activity | Indicative 2026 range (CAD) | Recommended frequency |
|---|---|---|
| Current-state Law 25 compliance review | $500 – $2,500 | Annual |
| Privacy policy refresh (existing policy) | $300 – $1,500 | With every practice change, or annual |
| New PIA for a recently adopted tool or project | $400 – $3,000 depending on complexity | Every new system or AI tool |
| Staff refresher training | $200 – $1,200 | Annual, plus at hiring |
| Incident response and portability process test | $300 – $1,500 | Annual |
| Regulatory watch (in-house or outsourced) | Varies by arrangement | Ongoing |
This level of investment is typically far lower than the real cost of a compliance gap discovered late — before even factoring in indirect costs like lost client trust or the time spent on crisis management. It's the same cost-benefit logic that makes cyber insurance for small business worth pairing with an ongoing compliance program rather than a one-time project.
Canadian Government Resources
- CAI — Commission d'accès à l'information du Québec (cai.gouv.qc.ca): The regulator enforcing Law 25. Publishes interpretation guidance, decision summaries, and practical tools for organizations, updated regularly — worth checking periodically, not just once during initial compliance.
- OPC — Office of the Privacy Commissioner of Canada (opc.gc.ca): The federal privacy regulator, useful for businesses operating outside Quebec or across multiple provinces navigating how Law 25 interacts with PIPEDA — see our Law 25 vs PIPEDA guide for the full picture.
- ISED — Innovation, Science and Economic Development Canada (ised-isde.canada.ca): General SMB-focused digital and privacy resources that complement provincial-specific guidance.
- BDC — Business Development Bank of Canada (bdc.ca): Advisory support that can include financing for compliance-related technology upgrades, particularly relevant when new tools adopted since your last review require fresh PIAs and security controls.
Don't let a 2022-2023 compliance program quietly fall behind
IT Cares' security audits compare your actual current data practices against what Law 25 requires today, close the gaps that have accumulated since your original compliance work, and document your ongoing diligence. If ongoing maintenance makes sense for your business, our managed IT services can help keep these controls current year over year.
Frequently Asked Questions
Turn This Into a Concrete 2027 Action Plan
IT Cares reviews your current data practices against what Law 25 actually requires today, closes the gaps that accumulated since your original compliance work, and helps you document ongoing diligence heading into 2027.

Comments (3)
We assumed we were done since 2023. Turns out our new CRM never got a PIA. Fixing that this month.
The point about documentation being continuous, not a one-time file, was the wake-up call we needed. We have good practices but nothing written down.
Good to see this framed as ongoing rather than a checkbox. We serve clients in three provinces so the harmonization angle is exactly what we needed to think through.
Leave a Comment