Compliance

Law 25 vs GDPR: what changes when you sell to Europe

August 12, 2026
Xavier PeichBy Xavier Peich

Your Law 25 work covers most of the GDPR. The three gaps that catch a Quebec SMB selling to Europe, and which way the transfers flow.

Law 25 vs GDPR: what changes when you sell to Europe

You did the Law 25 work. Register, privacy policy, designated officer, incident handling. Then a first European customer signs up on your store, or a partner in Paris asks for your "GDPR compliance", and the question lands: do you have to start over? The reassuring answer first: no. Law 25 was largely modelled on the General Data Protection Regulation, so your core Law 25 obligations already cover most of what Europe requires.

But "most" is not "all". Three specific gaps remain, and they are exactly the ones that surprise a Quebec SMB the day it starts selling to Europe.

This article compares the two regimes from the owner's practical angle: what your Quebec compliance already gives you for free, the three differences that need an extra move, and the transfer question, which runs both ways.

The short answer, for the busy

Law 25 and the GDPR share most of their logic: transparency, individual rights, security, incident handling. A Quebec SMB already compliant with Law 25 has done the bulk of the work. Three gaps catch it when it sells to Europe. First, the GDPR recognizes six legal bases for processing (including contract and legitimate interest), whereas Law 25 stays centred on consent: you don't always need the European consent you think you must ask for. Second, GDPR Article 27 requires most non-EU businesses that target European residents to appoint a representative established in the Union. Third, after an incident, the GDPR requires notifying the supervisory authority within 72 hours, while Law 25 requires notice "with diligence", with no fixed deadline. Which way data flows matters too: the EU-Canada adequacy decision, renewed in 2024, covers the federal private sector (PIPEDA), not Law 25 directly.

The core overlaps, and that's good news

Start with what doesn't change, because it's the largest part. Both regimes rest on the same principles: collect only what's necessary, say clearly why, keep data for as long as it's useful then destroy it, secure it, and give the individual rights (access, correction, withdrawal). Both require a readable privacy policy, an identifiable officer, and a structured response to incidents.

The budget consequence is concrete. If you built your Law 25 program seriously, you don't start from scratch for Europe: you adjust. Your personal-information inventory, your register, your collection forms, your agreements with processors: all of it carries over. The GDPR has a few extra documentation requirements (the Article 30 record of processing activities is more detailed than what a small business needs for Law 25), but the raw material is the same.

That's the right mindset: Law 25 is not a Quebec tax you pay on top of the GDPR. It's about 80% of the GDPR, already done, in your local customers' language.

First gap: six legal bases versus a consent logic

Here is the most useful difference in philosophy to grasp, because it often makes you do less work, not more.

Law 25 is consent-centred: the default rule is that you get the person's agreement to collect and use their information, with exceptions. The GDPR, by contrast, explicitly recognizes six legal bases for processing in its Article 6, and consent is only one of them. The others: performance of a contract, a legal obligation, vital interests, a public-interest task, and legitimate interest.

Why does this matter to you? Because many SMBs believe they must ask consent for everything, and clutter their site with pointless checkboxes. If you process a European customer's address to ship their order, the basis isn't consent: it's performance of the contract. Asking for consent where the contract already covers you is redundant, and risky too: consent can be withdrawn, leaving you to justify a basis you never needed to invoke. The correct European practice is to identify, for each processing activity, the strongest basis. Often, it isn't consent.

Legitimate interest, the sixth basis, is the one SMBs underuse. It allows certain processing (fraud prevention, security, measured outreach to an existing customer base) without prior consent, provided you document that your interest doesn't override the person's rights. It's a tool, not a loophole, but it has no direct equivalent in Law 25's logic.

Second gap: the EU representative nobody mentions

This one blindsides exporters, because it has no Quebec equivalent.

GDPR Article 27 requires most businesses established outside the Union that offer goods or services to European residents, or monitor their behaviour, to appoint a representative established in an EU country. That representative is a contact point for authorities and for individuals. The stinging detail: the obligation doesn't depend on your size. A three-person SMB in Trois-Rivières selling online to French customers is caught the same way a multinational is.

There is an exemption, but it's narrow. It covers "occasional" processing that doesn't involve special-category data on a large scale and poses little risk. "Occasional" doesn't mean "rare": it means processing that is genuinely incidental to your activity. The moment you target the European market regularly (translated site, prices in euros, marketing into the EU), you fall outside the exemption. In other words, if you sell to Europe in earnest, the exemption probably doesn't cover you.

The good news: appointing a representative is a service you can buy. Specialized firms provide the function for a few hundred euros a year. It isn't a hire. But it's a box most Quebec exporters discover too late, usually when a European customer demands to see the representative's name in the privacy policy.

Third gap: 72 hours versus "with diligence"

Both regimes require reacting fast to a confidentiality incident, but they say it differently, and the gap can cost you.

The GDPR puts a number on it. Its Article 33 requires notifying the competent supervisory authority without undue delay and, where feasible, no later than 72 hours after becoming aware of it, unless the incident is unlikely to result in a risk to individuals. Seventy-two hours is not long when you discover a leak on a Friday night.

Law 25 sets no number. Its Article 3.5 requires notifying the Commission d'accès à l'information "with diligence" when an incident presents a risk of serious injury, and notifying the affected individuals as well. "With diligence" is a soft standard: it means quickly, without dragging, but with no fixed clock.

In practice, if you sell to Europe, align on the stricter regime and treat 72 hours as your target everywhere. An incident-response plan built for 72 hours satisfies the GDPR and exceeds the Quebec requirement. Trying to keep two different clocks depending on where the data came from is a complication nobody handles well mid-crisis.

The other direction: data flowing from Europe to you

So far we've looked at your data leaving for Europe. The reverse flow has its own rule, and a Quebec nuance few people know.

For a European business to send you personal information (a partner sharing its contact list, a supplier handing you data), it needs a transfer basis. The simplest mechanism is an adequacy decision: the European Commission recognizes that a country offers "essentially equivalent" protection. Canada holds one, and the Commission renewed it in its review of January 15, 2024. In plain terms, a European partner can transfer data to you without assembling the heavy file of standard contractual clauses.

The nuance: that adequacy covers organizations subject to the federal law, PIPEDA, not Law 25 directly. The decision covers the federally regulated private sector, and the carve-out granted to "substantially similar" provincial laws only applies to processing that stays within the province. In practice, the moment data crosses a provincial or international border, PIPEDA applies, which is exactly what an inbound transfer from Europe is. Most Quebec SMBs receiving EU data are therefore covered. But if your activity is purely intra-Quebec, don't assume the "Canada adequate" label points straight at you: get your situation checked. It's the same flow-traceability reasoning we detail in our article on an AI agent's data hosted outside Quebec.

Where to start

If you already sell to Europe or are about to, the sequence is four moves. First, start from your Law 25 compliance as the foundation: it covers the essentials. Second, for each processing activity, pick the strongest GDPR legal basis rather than defaulting everything to consent. Third, check whether Article 27 forces you to appoint an EU representative: if you're targeting the market seriously, the answer is probably yes. Fourth, set your incident-response plan to 72 hours, the stricter requirement.

That's the kind of scoping we do with a client building a store or site aimed at the European market: aligning the site, the forms and the privacy policy on both regimes at once, rather than patching after a complaint.

→ Let's talk about your compliance, no commitment

This article explains two personal-information regimes to help an SMB ask the right questions; it is not legal advice. Law 25 (the Act respecting the protection of personal information in the private sector, P-39.1) and the European Union's General Data Protection Regulation each carry exceptions and nuances specific to the situation. Validate yours with legal counsel before any decision, especially on appointing an EU representative and choosing legal bases for processing.

Xavier Peich

Written by

Xavier Peich