Learn
PIPEDA vs Quebec Law 25
Which statute applies, where the tests diverge, and why a GDPR template with the names swapped will fail both offices.
Last reviewed 2026-08-13. Vendor-neutral. Not Canadian legal advice.
1. Start with geography and activity, not with a GDPR template
PIPEDA is the Personal Information Protection and Electronic Documents Act. It applies to organisations that collect, use, or disclose personal information in the course of commercial activities, and it is administered by the Office of the Privacy Commissioner of Canada. Quebec, Alberta, and British Columbia have their own private-sector statutes. Those statutes are deemed substantially similar under PIPEDA s. 26(2)(b). That phrase is doing real work: for activity that stays inside the province, the provincial Act is usually the one that governs. PIPEDA remains the statute for inter-provincial and international commercial activity, and for provinces that never passed a substantially similar law.
2. Loi 25 is not PIPEDA with French headings
Loi 25is the common name for the 2021 amendments to Quebec's private-sector privacy Act. The CAI (Commission d'accès à l'information) enforces it. The statute now requires a privacy governance policy (s. 3.2), privacy impact assessments for certain projects (s. 3.3), confidentiality-incident response (s. 3.5 to 3.8), transfer assessments before sending personal information outside Quebec (s. 17), automated-decision transparency (s. 12.1), and rights that look more like GDPR (access, rectification, de-indexation, portability) than like PIPEDA Schedule 1. Pasting a PIPEDA consent form into a Quebec file is how teams fail a CAI review.
3. Consent is the shared word and the different test
Both statutes care about consent. They do not use the same test. PIPEDA s. 6.1 asks whether consent was meaningful: did the person understand the nature, purpose, and consequences. The OPC has published detailed guidance on that test. Loi 25 s. 14 is closer to a GDPR-shaped consent rule: manifest, free, informed, and given for specific purposes. A Canadian SaaS product that uses one consent banner for every province will usually fail the stricter of the two. Write the Quebec flow first if Quebec residents are in scope, then confirm the federal flow still satisfies s. 6.1.
4. Incidents: 'real risk of significant harm' is not the Quebec test
Under PIPEDA, a breach that poses a real risk of significant harm must be reported to the OPC (s. 10.1), individuals must be notified (s. 10.2), and every breach must be recorded (s. 10.3). Under Loi 25, a confidentiality incident that presents a risk of serious injury has its own assessment, CAI notification, and individual-notice path. The words are close. The office, the clock, and the form are not. Keep one incident procedure that branches: OPC questions for PIPEDA-scope data, CAI questions for Quebec-scope data, both when the same incident hits both.
5. Fines and PIAs are why Quebec cannot be an afterthought
Loi 25 is the statute with the GDPR-shaped stick. Administrative monetary penalties under s. 90.12 can reach, for an organisation, the greater of $10,000,000 or 2% of worldwide turnover. Subsequent-offence penal fines under s. 91 / s. 92.1 can reach the greater of $25,000,000 or 4% of worldwide turnover. PIPEDA enforcement historically ran through the OPC's investigation-and-recommendation model, with later federal amendments adding stronger tools. They are still not the same regime. Loi 25 also requires privacy impact assessments for certain projects (s. 3.3). PIPEDA does not have an equivalent general PIA mandate. If Quebec is in scope, treat Loi 25 as a first-class programme, not a translation of the PIPEDA binder.
Side-by-side, without pretending they are the same
| Topic | PIPEDA | Loi 25 |
|---|---|---|
| Who enforces | OPC (federal) | CAI (Quebec) |
| Typical trigger | Commercial activity; inter-provincial / international | Intra-Quebec private-sector activity; Quebec residents / establishment |
| Consent | Meaningful consent, s. 6.1 | Manifest, free, informed, specific, s. 14 |
| Incidents | Real risk of significant harm, Division 1.1 | Confidentiality incidents, s. 3.5 to 3.8 |
| PIAs | Not a general statutory mandate | Required for certain projects, s. 3.3 |
For the Canadian product hub, see ISMS Copilot for Canada. For SaaS-shaped buying, see Canadian SaaS companies. Framework pages: PIPEDA and Loi 25.
Frequently asked questions
If we only have customers in Ontario, do we need Loi 25?
Usually no, if you have no establishment in Quebec and you do not collect personal information from Quebec residents. PIPEDA still applies to commercial activity in Ontario. Confirm with Canadian privacy counsel before you treat 'no Quebec customers' as a forever fact. Product telemetry, job applicants, and a single Quebec employee change the answer.
Does a Quebec establishment pull all of our data under Loi 25?
An establishment in Quebec brings Loi 25 into the picture for the personal information that statute covers. It does not automatically delete PIPEDA for inter-provincial or international commercial activity. Dual-jurisdiction teams keep both analyses. See /frameworks/ca-qc-law-25 and /frameworks/ca-pipeda.
Is this the same split as GDPR vs UK GDPR?
No. UK GDPR is a retained-and-amended copy of EU GDPR with a new supervisor. PIPEDA and Loi 25 are different statutes with different tests, different offices (OPC vs CAI), and different penalty designs. Cross-mapping is useful. Equating them is how programmes go stale.
Can ISMS Copilot replace Canadian privacy counsel?
No. The Copilot drafts policies, PIAs, incident records, and consent language against the statutes. A Quebec or federal determination that turns on establishment, commercial activity, or a CAI file is legal advice. Use the Copilot for the documentation. Use counsel for the call.
Where does SOC 2 fit?
SOC 2 is not a privacy statute. Canadian SaaS that sells into US or Canadian enterprise still gets asked for a SOC 2 report. Treat it as the commercial attestation sitting on top of PIPEDA and, if in scope, Loi 25. See /for/canadian-saas.
Primary sources
- Personal Information Protection and Electronic Documents Act, S.C. 2000, c. 5 (Justice Laws). laws-lois.justice.gc.ca (checked 2026-08-13).
- Office of the Privacy Commissioner of Canada, PIPEDA legislation and guidance. www.priv.gc.ca (checked 2026-08-13).
- Act respecting the protection of personal information in the private sector, CQLR c. P-39.1 (LégisQuébec). www.legisquebec.gouv.qc.ca (checked 2026-08-13).
- Commission d'accès à l'information du Québec. www.cai.gouv.qc.ca (checked 2026-08-13).
Written and maintained by the ISMS Copilot team. Last reviewed 2026-08-13.
PIPEDA and CQLR c. P-39.1 are official statutes. This guide paraphrases in original wording and cites sections. It is educational content, not legal advice, not an OPC or CAI determination, and not a substitute for Canadian privacy counsel.
Ready to do compliance work faster?
Built for speed, accuracy, and audit-ready output.
