canada, flag, canadian, national, canada flag, canadian flag, canada, canada flag, canada flag, canada flag, canada flag, canada flag, canadian flag, canadian flag. How PIPEDA and Quebec Law 25 change consent for small Canadian businesses
Photo by TheDigitalArtist on Pixabay

Rules

How PIPEDA and Quebec Law 25 change consent for small Canadian businesses

PIPEDA vs Quebec Law 25: consent, breach reporting and privacy officer duties differ for small businesses in Quebec and the rest of Canada, and here is how.

This article uses Canadian privacy law as a case study in consent and accountability. The site covers practical online privacy and personal data. The PIPEDA versus Quebec Law 25 comparison shows two consent models that appear in online services everywhere.

One model lets a business treat some silence as permission. The other requires a clear opt-in. The rules also differ on naming a privacy contact and reporting breaches.

For readers in the United States and elsewhere, the value is not the Canadian paperwork. It is seeing how consent wording and breach duties shape what happens to your data. Check which model a service uses, and whether it is accountable when data is exposed.

What to take away

  • PIPEDA vs Quebec Law 25 is not a choiceQuebec businesses must meet Law 25's stricter rules, while businesses elsewhere in Canada generally follow PIPEDA.
  • Quebec Law 25 generally requires opt-in consent for collecting, using or disclosing personal information, plus a named privacy officer and breach reporting to the CAI.
  • PIPEDA allows implied consent in some situations and requires breach reporting to the OPC when there is a real risk of significant harm.
  • The CAI can issue administrative monetary penalties; the OPC cannot fine directly but can take matters to Federal Court.
  • A business operating in both Quebec and Ontario must meet the higher standard for Quebec customers.

What this means for personal privacy

This site tracks practical online privacy and personal data. The Canadian rules above matter beyond compliance because they show two different consent defaults. One lets a business treat some silence as permission. The other requires a clear opt-in.

If you use online services, that gap shapes how easily your data can be collected, shared and used for marketing. The breach rules also show what you can expect when your information is exposed. Check whether a service relies on opt-out consent, names a privacy contact, and reports breaches. Those details affect your own data, wherever you live.

Where PIPEDA still sets the baseline for small Canadian businesses

PIPEDA, the Personal Information Protection and Electronic Documents Act, applies to private-sector organizations that collect, use or disclose personal information in the course of commercial activity.

For a small business in Ontario, British Columbia, Alberta or most other provinces, it is the default federal privacy law. It also applies to federally regulated businesses such as banks, airlines and telecoms everywhere in Canada. The OPC's overview of privacy laws in Canada sets out which statute applies where.

The law sets ten fair information principles. The ones small businesses feel most are consent, limited collection, safeguards, openness and individual access.

You must tell customers why you are collecting their information, get their consent, keep it secure, and let them see and correct what you hold. The OPC publishes guidance for businesses on consent, safeguards and complaint handling.

The OPC, the Office of the Privacy Commissioner of Canada, oversees PIPEDA. It publishes guidance, investigates complaints and reports findings.

Its decisions shape what counts as reasonable consent and reasonable security for businesses of all sizes.

PIPEDA does not have a blanket exemption for small business. A corner shop in Halifax that emails a customer list to a marketing tool is handling personal information in commercial activity. So is a Winnipeg contractor storing client addresses in an app.

The law also covers employee personal information in federally regulated workplaces. For provincially regulated employers, employment data usually falls under provincial law, but customer and client data almost always falls under PIPEDA.

Three provinces have their own private-sector laws that the federal government has deemed substantially similar: Quebec, British Columbia and Alberta.

In those provinces, provincially regulated businesses follow the provincial law for most commercial activity. That is why a Quebec bakery follows Law 25, not PIPEDA, for its customer data.

For a plain-language walkthrough of the rules that sit under both statutes, see this personal data privacy guide.

What Quebec Law 25 adds: consent, privacy officer and breach duties

Quebec Law 25, known in French as Loi 25, modernized the province's private-sector privacy law. It came into force in stages, with the final obligations taking effect in 2024.

It applies to enterprises that carry on business in Quebec, even if they are based elsewhere, when they handle personal information of people in Quebec.

Law 25 raises the bar in several ways. It requires a privacy officer by default, a higher standard for consent, breach reporting to the CAI, privacy impact assessments for certain projects, and new rights such as portability and de-indexing.

The CAI, the Office of the Privacy Commissioner of Quebec, is the regulator. It publishes guidance in French and English, handles complaints, conducts investigations and can impose administrative monetary penalties.

For a small business, the practical change is that consent must be clear, free and informed, and generally opt-in.

You must also be able to show that you obtained consent and that you honoured it.

Law 25 also requires you to designate a person responsible for the protection of personal information. That person's title and contact details must be published on your website.

If you do not name someone, the function falls to the highest-ranking person in the business, whether that is the owner or the CEO.

The Quebec government's business portal is the starting point for enterprises that need to understand their obligations under Law 25, including registration and compliance steps. It links to the CAI's guidance and to the forms you need.

If your customers read French, the OPC's French-language privacy topics hub is a useful companion for federal matters. It covers PIPEDA basics, breach reporting and complaint routes in French.

Consent wording compared: implied opt-out versus Law 25 opt-in

This is where the two regimes diverge most for day-to-day marketing. PIPEDA allows organizations to rely on implied consent in some circumstances, especially where the information is less sensitive and the customer would reasonably expect the collection.

PIPEDA vs Quebec Law 25 consent

PIPEDA (rest of Canada)

Consent model
Express or implied
Pre-checked boxes
May be invalid
Privacy officer
Not required by name
Breach reporting
Report to OPC

Quebec Law 25

Consent model
Express opt-in
Pre-checked boxes
Not valid consent
Privacy officer
Required, published contact
Breach reporting
Report to CAI

Law 25 tightens that: consent must generally be explicit and opt-in.

Under PIPEDA, you can sometimes treat a customer's continued relationship as consent for uses that are obvious and expected. A gym that emails a schedule change to members is a common example.

But implied consent is fragile. If the use is unexpected or the data is sensitive, you need express consent.

Under Law 25, you need clear consent for each purpose, and you need it before you collect or use the information.

Valid consent wording is short and specific. One example: an empty box next to 'Yes, I agree to receive the monthly newsletter from this store. I can unsubscribe at any time.'

Each purpose gets its own box, and no box is ticked in advance. An empty box means no consent for that purpose.

The table below sets out the main differences in plain terms.

Consent wording compared

PIPEDA (rest of Canada)

Default consent model
Express or implied, depending on sensitivity and expectations
Pre-checked boxes
Discouraged, may be invalid
Privacy officer
Not required by name, but accountability principle applies
Breach reporting
Report to OPC if real risk of significant harm
Penalties
OPC cannot fine directly, can seek court order
Portability
Not a general right
De-indexing
Not a general right

Quebec Law 25

Default consent model
Generally express, opt-in, purpose by purpose
Pre-checked boxes
Not valid consent
Privacy officer
Required, with published contact details
Breach reporting
Report to CAI if risk of serious injury
Penalties
CAI can issue administrative monetary penalties
Portability
Right to portability in force
De-indexing
Right to de-indexing in force

For a step-by-step way to map what you collect to what you need, use this personal data lifecycle checklist.

If you operate in Quebec, rewrite your consent language so that each purpose is separate and unticked by default. If you operate in Ontario, keep PIPEDA's flexibility but do not assume it covers Quebec customers.

Breach reporting: OPC versus the CAI and when you must report

Both regimes require you to report certain breaches, but the trigger and the regulator differ. Under PIPEDA, you must report to the OPC any breach of security safeguards that poses a real risk of significant harm to an individual.

Breach reporting: OPC vs CAI

PIPEDA (OPC)

Trigger
Real risk of significant harm
Deadline
As soon as feasible
Notify individuals
Yes, if risk
Records
Every breach

Quebec Law 25 (CAI)

Trigger
Risk of serious injury
Deadline
Prompt notification
Notify individuals
Yes, if risk
Records
Register of incidents

You must also notify affected individuals and keep records of every breach, even those you do not report.

The factors to weigh include the sensitivity of the information, the probability of misuse, and whether the information could be used for identity theft or fraud. You report using the OPC's online breach report form.

There is no fixed 72-hour deadline in PIPEDA, but you must report as soon as feasible after you determine a breach occurred.

Under Law 25, you must report to the CAI any breach that presents a risk of serious injury. The CAI expects prompt notification, and the law requires you to notify affected individuals with a risk of serious injury as well.

The CAI publishes its own breach reporting guidance and form.

Quebec's law also requires you to keep a register of breaches, including those that do not meet the reporting threshold. The CAI can ask to see it. This is a record-keeping duty that many small businesses miss.

For a business operating in both Quebec and Ontario, the safe approach is to report to both regulators when a breach affects residents of both provinces. The thresholds are similar but not identical.

A breach that meets one may not meet the other. When in doubt, report.

The OPC's actions and decisions page is where you can see how the regulator has handled past files, including breach reports and findings. Reading a few decisions is a fast way to calibrate what counts as significant harm in practice.

If a breach involves account takeover, phishing or identity theft, a structured response matters. This browser privacy checklist covers breach notices, containment and recovery in a Canadian context.

Naming a privacy officer and keeping records in each regime

PIPEDA does not require you to name a privacy officer, but it does require accountability. In practice, the OPC expects someone to be responsible for compliance.

For a small business, that is often the owner. The title does not matter as much as the function: someone must know the law, handle complaints and oversee security.

Law 25 goes further. It requires you to designate a person responsible for the protection of personal information and to publish that person's title and contact details on your website.

If you do not designate anyone, the function falls to the highest-ranking person in the enterprise.

The privacy officer's duties under Law 25 include approving privacy policies, handling access requests, managing breach response, and acting as the contact for the CAI.

The role is not ceremonial. The CAI can ask what the privacy officer did and whether they had the authority and resources to do it.

Record-keeping differs too. Under PIPEDA, you must keep a record of every breach of security safeguards involving personal information, whether or not you report it.

Under Law 25, you must keep a register of confidentiality incidents, including those that do not meet the reporting threshold.

Both regimes require you to be able to show what you collected, why, who saw it, how long you kept it and when you deleted it. A simple spreadsheet or a records tool is enough for most small businesses.

The point is to have the record before a complaint arrives, not after.

If you handle access, correction, deletion, objection or portability requests, this browser privacy guide explains the notices and records involved.

Penalties, enforcement and the CAI's administrative monetary penalties

PIPEDA is enforced through complaints, audits and investigations by the OPC. The OPC can make findings and recommendations.

Enforcement powers compared

PIPEDA (OPC)

Fines
No direct fines
Orders
Via Federal Court
Personal liability
Rare

Quebec Law 25 (CAI)

Fines
Administrative penalties
Orders
Direct orders
Personal liability
Directors may be liable

If an organization does not comply, the OPC can apply to the Federal Court for an order, and the court can award damages. The OPC itself cannot issue fines under PIPEDA.

PIPEDA sets no administrative penalty schedule, so the amount of any damages is left to the court on the facts of the case.

Law 25 gives the CAI stronger direct powers. The CAI can conduct investigations, issue orders and impose administrative monetary penalties.

The ceiling on a CAI administrative monetary penalty is CAD 50,000 for an enterprise and CAD 20,000 for an individual. The CAI sets the amount within that ceiling, based on the number of people affected, the sensitivity of the information and whether the failure was repeated.

Penalties can be significant for businesses, and they can be imposed for failures such as collecting information without valid consent or failing to report a breach.

Quebec's law also creates penal offences for certain conduct, including obstructing the CAI and failing to comply with its orders. Directors and officers can, in some circumstances, be held personally liable.

That is a real difference from PIPEDA, where personal liability is rare.

The CAI publishes its decisions and penalty notices. Reading them shows what the regulator treats as serious: dark patterns in consent, missing privacy officers, and slow breach response come up repeatedly.

For a small business, the practical takeaway is that Quebec is the higher-risk jurisdiction. If you operate there, invest in consent records, a named officer and a breach register.

Those three things cover most of what the CAI looks for first.

If you want to compare rights across regimes, this browser privacy problems article sets out access, correction, deletion, portability and objection side by side.

Practical compliance checklist for a business operating in both Quebec and Ontario

A business with customers in both provinces has to meet two standards at once. The simplest approach is to build to Law 25, because it is the stricter of the two, and then confirm that your practices also satisfy PIPEDA.

Use the checklist below as a starting point. It is written for a small business without a dedicated legal team.

Practical compliance checklist

  • Name a person responsible for personal information, and publish their title and contact details on your website.
  • Rewrite consent so each purpose has its own box, unticked by default and written in everyday words.
  • Keep records that show when and how each customer consented, and to what.
  • Keep a breach register, and report to the CAI or the OPC when the threshold is met.
  • Publish a privacy policy that explains collection, use, retention and deletion.
  • Set out how you handle access, correction, deletion and portability requests.
  • Review the policy and train staff at least once a year.

Compliance checklist for both provinces

  • Name privacy officer, publish contact details
  • Rewrite consent language, unticked by default
  • Record when and how consent was given
  • Map where personal information is stored
  • Set retention periods and delete unneeded data
  • Keep breach register, report to OPC and CAI
  • Post privacy policy, review vendor contracts

The order matters less than the coverage. Start with the privacy officer and consent, because those are the two items regulators ask about first.

A worked example helps. Suppose a Montreal retailer sells online to customers in Quebec and Ontario. It collects email addresses for a newsletter, shipping addresses for delivery, and purchase history for recommendations.

Under Law 25, the retailer needs opt-in consent for the newsletter and for recommendations, and a published privacy officer. Under PIPEDA, the shipping address collection is covered by implied consent because it is obvious and necessary.

It keeps a breach register and reports to the CAI if a Quebec customer is affected.

It reports to the OPC if an Ontario customer faces a real risk of significant harm.

Common questions

Does PIPEDA still apply to my business if I am in Quebec?
For provincially regulated businesses in Quebec, Law 25 applies to most commercial activity. PIPEDA still applies to federally regulated businesses and to some cross-border activities. In practice, most Quebec small businesses follow Law 25.
Do I need a privacy officer if I am a sole proprietor in Quebec?
Yes. Law 25 requires an enterprise to designate a person responsible for the protection of personal information. If you do not name someone, the function falls to the highest-ranking person, which for a sole proprietor is you.
What is the deadline for reporting a breach under PIPEDA?
PIPEDA requires you to report to the OPC as soon as feasible after you determine a breach occurred, when there is a real risk of significant harm. There is no fixed 72-hour clock in the federal law, but delay is risky.
Can the CAI fine my small business directly?
Yes. The CAI can impose administrative monetary penalties under Law 25. The OPC cannot fine directly under PIPEDA; it can seek a court order instead.
Do I need separate privacy policies for Quebec and Ontario customers?
Not necessarily. One policy can cover both markets, as long as the consent language is opt-in and purpose-specific.
Where can I read the regulators' own guidance?
The OPC publishes privacy laws in Canada and guidance for businesses, while the CAI publishes Law 25 guidance in French and English. The Quebec government's business portal links to the CAI's materials.

More in Rules

Latest from Guides Desk