ComplianceBy Xavier Peich

PIPEDA or Quebec's Law 25: which one applies to your business (and when both do)

PIPEDA only steps aside for Law 25 on what stays inside Quebec. Sales to Ontario, hosting elsewhere, federal sectors: when your business answers to both.

PIPEDA or Quebec's Law 25: which one applies to your business (and when both do)

"We're in Quebec, so it's Law 25, not PIPEDA." We hear it constantly, and for most of a small business's personal information it's correct. It stops being correct the moment data crosses the provincial line: an order shipped to Ottawa, software hosted in Virginia, a head office in Toronto. Our summary of Law 25 obligations for SMBs assumes the Quebec law applies; this article is about where that assumption ends.

"Which law applies to my business?" is the wrong question anyway. Canadian law doesn't sort businesses into two laws. It sorts flows of information.

The short answer, for the busy

A Quebec business is governed first by the Act respecting the protection of personal information in the private sector, as amended by Law 25. The federal law, PIPEDA, doesn't disappear. A 2003 federal order (SOR/2003-374) exempts Quebec businesses from PIPEDA, but only for the collection, use and disclosure of personal information that occurs within Quebec. PIPEDA therefore still covers personal information that crosses provincial or national borders in the course of commercial activity, and it always applies to federally regulated businesses (banks, airlines, telecommunications, interprovincial transportation), including to their employees' information. In practice, many small businesses have to comply with both laws at once. Law 25 is the stricter of the two on consent, privacy impact assessments and penalties. Bill C-36, the federal government's proposed replacement for PIPEDA, was introduced on June 15, 2026 and is not yet law.

A partial exemption, not a replacement

Paragraph 26(2)(b) of PIPEDA lets Ottawa exempt an organization when a "substantially similar" provincial law applies to it, but only for collection, use or disclosure "that occurs within that province." The Organizations in the Province of Quebec Exemption Order, registered on November 19, 2003, applies that power to any organization, "other than a federal work, undertaking or business," that is subject to the Quebec law.

So the text carries two limits: federal businesses are never exempt, and the exemption stops at Quebec's border. The Office of the Privacy Commissioner of Canada puts it plainly: every business operating in Canada that handles personal information crossing provincial or national borders in the course of commercial activities is subject to PIPEDA, including in provinces with substantially similar legislation. Only Alberta and British Columbia share Quebec's status (Ontario has a recognized law for health information only). And the OPC adds the sentence that sums up this whole article: when more than one law applies, you must comply with both.

The businesses PIPEDA never lets go

For federally regulated organizations the question doesn't arise. The OPC names airports and airlines, banks, interprovincial or international transportation companies, telecommunications companies, offshore drilling and broadcasters. They are always subject to PIPEDA, and the Act also covers their employees' personal information (paragraph 4(1)(b)).

An ordinary small business isn't one of them, but a contract can pull it in. The OPC's own example is a firm providing an employee assistance program to an airline's staff: its contract requires it to follow PIPEDA for those employees, while provincial law governs the rest of its operations.

Three small-business situations, three answers

The Quebec shop that sells into Ontario. For its Quebec customers, it's the Quebec law. When a customer in Kingston places an order, the information crosses a provincial border: PIPEDA is added for that flow, without displacing the Quebec law. You feel the consequence during an incident that affects customers in both provinces: two assessments, and sometimes two notices.

The Ontario firm that opens a Montreal office. For what happens at the Montreal office (its Quebec clients, its Quebec employees), the Quebec law applies in principle. Its Ontario clients fall under PIPEDA. Its Toronto employees fall outside PIPEDA, which only covers the employees of federal businesses. The trap is elsewhere: when the Montreal office sends employee files to HR in Toronto, it is communicating personal information outside Quebec. Section 17 of the Quebec law then requires a privacy impact assessment and a written agreement before the transfer.

The Quebec employer that never leaves Quebec. Its employee records fall under the Quebec law alone.

A fourth case applies to nearly everyone: cloud software. A CRM hosted in the United States sends your information across a national border, which brings PIPEDA back in, and it triggers section 17 on the Quebec side. Note that section 17 says "outside Québec," not "outside Canada": an Ontario host triggers it too. Our article on AI agent data hosted outside Quebec covers this case in detail, and the privacy impact assessment guide for Quebec businesses explains how to run the assessment.

Where the two laws ask for different things

When both apply, aim for the stricter one on each point. It's almost always the Quebec law.

Consent. PIPEDA requires valid consent, meaning the individual can reasonably understand what they're agreeing to (section 6.1), and its Schedule 1 accepts implied consent for less sensitive information. The Quebec law requires consent that is "clear, free and informed" and "given for specific purposes," requested for each purpose and, if in writing, presented separately from any other information (section 14). For sensitive information it must be express (section 12).

Privacy impact assessments. The Quebec law requires one for any project to acquire, develop or overhaul an information system involving personal information (section 3.3), and before any communication outside Quebec (section 17). PIPEDA requires neither.

Incidents. Both laws require notifying the regulator and the affected individuals, with thresholds that look a lot alike. PIPEDA speaks of a "real risk of significant harm" and a report to the Commissioner "as soon as feasible." The Quebec law speaks of "a risk of serious injury" and notice to the Commission d'accès à l'information given "promptly." The most concrete difference is record retention: 24 months for the federal breach record, at least five years for the Quebec confidentiality incident register. The Quebec regulation even anticipates double reporting: the notice to the Commission must state how many affected individuals reside in Quebec and, where applicable, that a privacy regulator outside Quebec has also been notified.

Penalties: the widest gap

The Quebec law provides administrative monetary penalties of up to $10 million or 2% of worldwide turnover (section 90.12), and penal fines of up to $25 million or 4% (section 91). PIPEDA has no administrative monetary penalties. Its fines, under section 28, cover a handful of knowing offences, including failing to report a breach, and top out at $100,000. Everything else goes through the Federal Court, which can order an organization to correct its practices and award damages.

When four commissioners investigate together

On June 1, 2022, the federal Commissioner, Quebec's Commission d'accès à l'information and the commissioners of Alberta and British Columbia released the findings of a joint investigation into the Tim Hortons app, which tracked its users' location in the background. The report found contraventions of all four laws, each cited section by section. A business active in several provinces doesn't pick its law. It stacks them.

What's coming from Ottawa: Bill C-36

Federal reform is on its third attempt. Bill C-27 died when the parliamentary session ended on January 6, 2025, while it was still in committee. Its successor, Bill C-36, was introduced on June 15, 2026 and sits at second reading in the House of Commons. It would repeal Part 1 of PIPEDA and replace it with a new Protecting Privacy and Consumer Data Act.

Three points matter to a Quebec business. The bill keeps the exemption mechanism for substantially similar provincial laws. It would require a privacy impact assessment before disclosing or transferring personal information outside Canada, logic Quebec already applies. And it would introduce administrative penalties of up to $10 million or 3% of gross global revenue. Ottawa is moving toward Law 25, which leads to the same conclusion as our Law 25 vs GDPR comparison: a business that takes the Quebec law seriously has already done most of the work.

The working rule

Treat Law 25 as your floor everywhere. Then list every flow that leaves Quebec: out-of-province customers, hosting providers, cloud software, head offices and subcontractors. Each one triggers section 17, and probably PIPEDA as well. That's the mapping we do with clients when we build or rebuild a site as part of our services.

→ Let's map your data flows

This article explains legal rules in plain language to help a business ask the right questions; it is not legal advice. Whether the federal or the Quebec law applies is decided case by case, based on your activities and information flows. The texts of PIPEDA, Order SOR/2003-374 and Quebec's Act respecting the protection of personal information in the private sector prevail: for a specific situation, consult a lawyer.

Xavier PeichWritten byXavier Peich