Short answer: Law 25 is Quebec's own private-sector privacy law, stricter than the federal PIPEDA baseline, and it applies to any business handling a Quebec resident's personal information, regardless of where that business is located. It requires a named privacy officer, mandatory breach notification, privacy impact assessments for many data transfers, and gives individuals a private right of action. Penalties reach up to 25 million dollars or 4 percent of worldwide turnover for the most serious violations, and it is separate from Bill 96, which is about French-language content, not privacy.
Most Canadian merchants outside Quebec have heard of Bill 96 and know it means a French storefront. Far fewer have registered that Quebec also passed a separate, stricter privacy law, and that the two obligations do not overlap. Law 25 does not ask what language your site is in. It asks what happens to a customer's name, email, and order history the moment they check out, and in 2026 the province's privacy regulator has been answering that question for merchants who never asked it themselves.
This matters even if your business has never set foot in Quebec. If a customer with a Quebec billing address buys from your Shopify store, checks in on your HubSpot chatbot, or opens a marketing email you sent through Klaviyo, you are handling that person's personal information under a law that follows the customer, not your head office.
01. What Law 25 Actually Requires
Law 25, passed as Bill 64 and phased in through three effective dates between September 2022 and September 2024, rewrote Quebec's private-sector privacy rules and is now fully in force. The Canadian Bar Association's privacy section has called it the strictest private-sector privacy law in the country, and in some respects it goes further than most North American equivalents.
The core obligations that matter to a commerce business are consistent across every summary of the law: designate a privacy officer, get genuine informed consent before collecting personal information, notify both the regulator and affected individuals when a breach creates a risk of serious injury, complete a privacy impact assessment before certain data transfers, and honour a customer's right to access, correct, or request the deletion of their own data. Individuals can also sue directly for a violation, separate from anything the regulator decides to pursue.
Why it matters: none of these obligations are optional add-ons for larger companies. The law applies by default to any organization, and a small Shopify business with no privacy officer and a stock cookie banner is not exempt just because it has never been asked about Law 25 before.
02. Law 25 vs PIPEDA vs Bill 96
These three laws get confused constantly because they all touch a Shopify store selling into Quebec, and merchants who have already handled one assume the others are covered too. They are not the same law, do not share an enforcement body, and do not share a compliance checklist.
| Law | What it governs | Enforced by | Applies when |
|---|---|---|---|
| PIPEDA | Baseline personal information rules for commercial activity across Canada | Office of the Privacy Commissioner of Canada | Federally, except where a substantially similar provincial law applies |
| Quebec Law 25 | Stricter personal information rules: privacy officer, breach notice, impact assessments, private right of action | Commission d'acces a l'information (CAI) | Any organization handling a Quebec resident's personal information |
| Quebec Bill 96 | French-language requirements for commercial websites and communications | Office quebecois de la langue francaise (OQLF) | Any business selling to or communicating with Quebec consumers |
A merchant who has already built a French storefront for Bill 96 has solved a language problem, not a privacy problem. A merchant who is PIPEDA-compliant has met the federal floor, not Quebec's higher bar. Both projects are worth doing. Neither one finishes the other.
Why it matters: treating any one of these three as a stand-in for the others is the single most common reason a Quebec-facing business assumes it is covered when it is not.
03. Where Shopify Stores Usually Fall Short
The gaps are rarely dramatic. They are usually the accumulated result of a store built quickly, with apps and pixels added one at a time, and a privacy policy nobody has revisited since launch.
- No named privacy officer. Most SMBs have never formally designated one, which means the law defaults that role to the CEO or owner without them knowing it.
- A generic cookie banner. A banner built for CASL or a US-style notice rarely gives the granular, opt-in choice Law 25 expects before tracking scripts fire.
- Unreviewed apps and pixels. Meta Pixel, Google Analytics, TikTok Pixel, and third-party Shopify apps often send customer data to processors outside Quebec, which is exactly the kind of transfer Law 25 expects a privacy impact assessment to consider first.
- No breach response plan. Law 25 requires notifying both the CAI and affected individuals when there is a risk of serious injury, on a timeline that is hard to meet if the process is being invented during the incident itself.
- HubSpot workflows collecting more than they need. Forms and chat workflows that capture personal information for marketing automation are a common blind spot, since the marketing team, not IT, usually owns them.
Why it matters: every one of these gaps is fixable without a full platform rebuild. They are governance and configuration problems, not development problems, which is exactly why they tend to go unaddressed until a regulator or a customer's lawyer raises them first.
04. The Compliance Checklist
This is the sequence that closes the gap for a typical Shopify or HubSpot-connected business selling into Quebec, in the order it is worth doing it.
- 1. Name and document a privacy officer. Publish who holds the role, even if it is the owner, and make it findable in the privacy policy rather than assumed.
- 2. Inventory every app, pixel, and integration touching customer data. List each Shopify app, ad pixel, and HubSpot workflow that collects or transfers personal information, and note where that data goes.
- 3. Rewrite the privacy policy for Law 25 disclosures. Cover what is collected, why, how long it is kept, who it is shared with, and how a customer exercises their access, correction, portability, and deletion rights.
- 4. Replace a generic cookie banner with granular, opt-in consent. Tracking and marketing pixels should not fire before a visitor makes an affirmative choice, not just closes a notice.
- 5. Put a breach notification process in writing. Define who decides whether a risk of serious injury exists, and the steps to notify the CAI and affected customers on time.
- 6. Build a lightweight privacy impact assessment habit. Any new app, integration, or cross-border data transfer gets a short, documented review before it goes live, not after.
Why it matters: the businesses that struggle with Law 25 are almost never the ones that treated it as a single project. They are the ones that fixed the cookie banner and stopped, leaving the privacy officer, the app inventory, and the breach plan undone.
05. Privacy Impact Assessments, in Practice
The privacy impact assessment, or PIA, is the part of Law 25 that sounds the most intimidating and causes the most SMBs to quietly skip it. In practice, for a commerce business, it does not need to be a formal legal document produced by outside counsel for every change.
A PIA is triggered most often by acquiring, developing, or overhauling a system that handles personal information, and by any project that transfers personal information outside Quebec, which covers most third-party Shopify apps, ad platforms, and cloud-hosted marketing tools by default. The assessment itself can be a short, structured internal review: what data moves, where it goes, what safeguards the receiving party has, and what happens if something goes wrong.
The practical rule that holds up:
Before adding a new Shopify app, ad pixel, or HubSpot integration that touches customer data, spend fifteen minutes documenting what it collects, where the vendor processes it, and why it is worth the exposure. That short habit, done consistently, is what a PIA actually looks like for a business this size, and it is far cheaper than reconstructing that history after a breach.
Why it matters: a documented, if informal, review process is the difference between being able to show due diligence to the CAI and having no record at all of why a given app was ever installed.
06. What Happens If the CAI Comes Calling
Law 25 is not a law that exists only on paper. Through 2026, the CAI has published enforcement decisions, issued administrative monetary penalties, and in some cases publicly named non-compliant organizations, which privacy counsel consistently note carries a reputational cost that outlasts the fine itself.
The penalty structure has two tiers. Administrative monetary penalties, the more common enforcement path, can reach 10 million dollars or 2 percent of worldwide turnover, whichever is higher. Penal provisions, reserved for the most serious and deliberate violations, reach 25 million dollars or 4 percent of worldwide turnover. Separately, an individual whose privacy was violated can sue directly, without waiting on the regulator to act at all.
Why it matters: for a small or mid-sized business, the realistic exposure is rarely the maximum penalty. It is the cost of a public finding, a customer lawsuit, or the operational disruption of responding to a CAI inquiry with no documentation to show, all of which are avoidable with the checklist above completed before it is needed.
07. What This Means for Atlantic Canadian Sellers
A manufacturer or wholesaler based in New Brunswick, Nova Scotia, or elsewhere in Atlantic Canada that ships to Quebec accounts, or a DTC brand running national ads that reach Quebec shoppers, is squarely inside Law 25's scope the moment a Quebec customer's data enters the Shopify checkout or a HubSpot form. Being based outside the province changes nothing about that obligation.
This sits alongside two other compliance obligations many of the same businesses are already working through. Our guide to Quebec's Bill 96 language requirements covers the separate French-language project, and our PIPEDA compliance guide covers the federal privacy baseline every Canadian Shopify store needs regardless of which provinces it sells into. A business selling nationally is realistically running all three in parallel, and the app inventory and privacy officer designation built for Law 25 make the PIPEDA review faster, not redundant.
Why it matters: Atlantic Canadian businesses selling into Quebec do not get a distance exemption, but they do get an efficiency: doing the privacy officer designation, the app inventory, and the consent banner once, correctly, covers the hardest parts of Law 25, Bill 96's separate language obligation, and the PIPEDA baseline at the same time.
08. Key Takeaways
- Law 25 applies based on whose personal information you handle, not where your business is registered, so a Shopify store outside Quebec selling to Quebec customers is covered.
- It is stricter than PIPEDA and separate from Bill 96: PIPEDA is the federal privacy baseline, Bill 96 is a French-language law, and Law 25 is Quebec's own privacy regime enforced by the CAI.
- Core requirements include a named privacy officer, informed opt-in consent, mandatory breach notification, privacy impact assessments for many data transfers, and a private right of action for individuals.
- Penalties reach up to 25 million dollars or 4 percent of worldwide turnover for the most serious violations, and the CAI has been actively enforcing and publicly naming non-compliant organizations in 2026.
- The most common gaps are governance problems, not development problems: no named privacy officer, a generic cookie banner, and an unreviewed list of apps and pixels moving customer data outside Quebec.
- A short, consistent privacy impact assessment habit for new apps and integrations is far cheaper than reconstructing that review after a breach or a regulator inquiry.
09. Frequently Asked Questions
What is Quebec's Law 25?
Law 25, formerly known as Bill 64, is Quebec's private-sector privacy law, phased in between 2022 and 2024. It sets out how any organization must collect, use, store, and disclose the personal information of Quebec residents, and it is widely described by privacy lawyers as the strictest private-sector privacy law in Canada. It requires a named privacy officer, mandatory breach notification, privacy impact assessments for many projects, and gives individuals a private right of action separate from regulator enforcement.
Does Law 25 apply to businesses outside Quebec?
Yes. Law 25 applies based on whose personal information is being handled, not where the business is located. A Shopify store based in New Brunswick, Ontario, or anywhere else that sells to customers in Quebec and collects their name, email, address, or payment details is handling personal information covered by the law, the same extraterritorial approach GDPR takes in Europe. Location does not create an exemption.
What are the penalties for non-compliance with Law 25?
Quebec's privacy regulator, the Commission d'acces a l'information (CAI), can levy administrative monetary penalties of up to 10 million dollars or 2 percent of worldwide turnover, whichever is higher, for the most serious violations. Penal provisions for the gravest offences reach up to 25 million dollars or 4 percent of worldwide turnover. The CAI has been actively enforcing in 2026, publishing decisions and naming non-compliant organizations, and individuals also have a private right of action to sue directly for a privacy violation.
Do I need to name a privacy officer under Law 25?
Yes. Law 25 requires every organization it covers to designate a person responsible for the protection of personal information. If no one is formally named, the law defaults that responsibility to the organization's most senior officer, typically the CEO or owner. For a small Shopify business, this is often the owner or a marketing lead, but the designation needs to be documented and published, not just assumed.
How is Law 25 different from PIPEDA?
PIPEDA is the federal privacy law that applies as a baseline across Canada. Law 25 is Quebec's own provincial law, and where it applies to Quebec residents' data it goes further than PIPEDA in several ways: it mandates a named privacy officer, requires privacy impact assessments before certain data transfers, adds a private right of action for individuals, and carries substantially higher penalties. A business already compliant with PIPEDA is not automatically compliant with Law 25 for its Quebec customers, the two require a separate review.
Is Law 25 the same as Quebec's Bill 96?
No, and this is a common point of confusion. Bill 96 is Quebec's French-language law, which requires a genuine French version of a Shopify store selling to Quebec customers and is enforced by the Office quebecois de la langue francaise. Law 25 is a privacy law, enforced by a different regulator, the CAI, and it governs how personal information is collected and protected, not what language a site is published in. A Shopify business selling into Quebec typically needs to address both, but they are separate compliance projects with separate checklists.
What should a Shopify store do first to comply with Law 25?
Start by naming and documenting a privacy officer, then inventory every app, pixel, and integration on the store that touches customer data, including analytics, ad pixels, and HubSpot workflows, since many of these send personal information to processors outside Quebec and can trigger a privacy impact assessment requirement. From there, update the privacy policy with Law 25-specific disclosures, implement a compliant, opt-in cookie and tracking consent banner, and put a breach notification process in writing before an incident forces you to build one under pressure.
Related Resources
The federal privacy baseline every Canadian Shopify store needs to meet
What a genuine French storefront requires, and where the deadline stands
Express versus implied consent, and how to audit a HubSpot or Klaviyo setup
What Ontario's accessibility law requires from a Canadian ecommerce site
Not sure where your store stands on Law 25?
AtlanticWorks helps Canadian manufacturers, wholesalers, and DTC brands audit their Shopify and HubSpot data flows, close privacy compliance gaps, and keep selling into Quebec without the guesswork. The free assessment shows exactly what to fix first.
Start the Assessment