· 8 min read

Law 25 and your website: a practical guide for Quebec businesses

Does your website have a contact form? Does it use Google Analytics, a Meta pixel or a newsletter sign-up? Then it collects personal information, and Law 25, Quebec's privacy law, applies to you, whatever the size of your business.

Passed in 2021 as Bill 64, Law 25 (An Act to modernize legislative provisions as regards the protection of personal information) came into force in stages between September 2022 and September 2024. Here is what it changes for your website, in plain English, with a checklist at the end. Please note: this article is general information and does not constitute legal advice.

What is Law 25, and does it apply to my business?

Law 25 modernizes several Quebec statutes, including the Act respecting the protection of personal information in the private sector. It applies to any business that collects, uses or keeps personal information about people in Quebec. Personal information is any information that can identify a person, directly or indirectly: name, email address, phone number, IP address, browsing history tied to an identifier, and so on.

Its application is overseen by the Commission d'accès à l'information du Québec (CAI). The obligations arrived in three waves:

  • September 22, 2022: a person in charge of the protection of personal information, handling of confidentiality incidents and an incident register.
  • September 22, 2023: the biggest wave for websites (stronger consent, privacy policy, privacy by default, profiling technologies, administrative monetary penalties from the CAI).
  • September 22, 2024: the right to data portability.

Who is the privacy officer in my business under Law 25?

By default, it's the person with the highest authority in the business, often the president or the owner. The law calls this role the person in charge of the protection of personal information; most people simply say privacy officer. The role can be delegated, in whole or in part, to someone else, in writing.

For your website, the concrete obligation is simple: this person's title and contact information must be published on the company's website. A dedicated email address (for example privacy@yourbusiness.ca) in your privacy policy and footer does the job nicely.

Do I need a privacy policy on my website?

Yes, as soon as you collect personal information through technological means, which includes a web form. According to the CAI, the policy must be written in clear and simple terms and published on your website.

It should explain, without jargon: what information you collect (forms, cookies, analytics tools), why, who it's shared with (web host, newsletter tool, CRM, etc.), how long you keep it, how it's protected, and how people can exercise their rights of access and correction. The CAI also publishes an explanatory guide (in French) to help businesses write one.

Don't copy another site's policy or an American template: it has to reflect what your site actually does. If you add an advertising pixel next year, the policy needs to follow.

Do I need a cookie banner under Law 25?

Law 25 doesn't mention a “banner” as such, but it sets rules that, in practice, make one necessary for most websites. Two key principles have been in force since September 2023.

First, if you use technology that can identify, locate or profile a person, you must inform them beforehand and give them a way to turn those functions on. According to the CAI, these functions cannot be activated by default: the person has to activate them. Advertising and cross-site tracking cookies (Meta pixel, Google Ads, etc.) are the typical examples.

Second, the privacy settings of a technological product or service offered to the public must provide the highest level of confidentiality by default. The CAI specifies that cookies are excluded from this particular default-settings rule, which is why experts don't all agree on exactly how each type of cookie should be handled.

The cautious conclusion, shared by many practitioners: strictly necessary cookies (cart, session, security) can run without consent, but profiling and targeted advertising cookies should stay off until the visitor accepts them. For analytics, the safest route is to ask for consent as well, or to use a tool configured not to identify or profile visitors.

Are my contact forms and newsletter sign-up compliant with Law 25?

When you collect information, you must tell the person why you're collecting it and inform them of their rights of access and correction. Consent must be manifest, free and informed, and requested for specific purposes, in clear and simple terms. For sensitive information (health, finances, etc.), it must be express.

  • Only ask for what you need: a contact form doesn't need a date of birth.
  • Add a short notice under the form: why you're collecting the data, with a link to your privacy policy.
  • For your newsletter, use a separate checkbox that isn't pre-checked. Requesting a quote isn't the same as subscribing to a newsletter.
  • Check where the data goes: inbox, CRM, spreadsheet. Every third-party tool should be listed in your policy.
  • Set a retention period and delete what you no longer need.

What do I do after a data breach, and what is data portability?

Since September 2022, a confidentiality incident (unauthorized access, loss, information sent by mistake) must be dealt with promptly to reduce the risks. If the incident presents a risk of serious injury, you must notify the CAI and the people affected.

Every business must also keep a register of confidentiality incidents, even minor ones, and provide it to the CAI on request. For a website, think of a hacked contact-form inbox, an exposed newsletter database or a vulnerable WordPress plugin. Regular updates and backups are part of prevention.

Since September 22, 2024, people can ask that the computerized personal information they provided to you be released to them, or transferred to another organization, in a structured, commonly used technological format. For a small business, this mostly means knowing where your customers' data is stored (CRM, online store, newsletter tool) and being able to export it, for example as a CSV file.

What are the fines under Law 25?

The CAI can impose administrative monetary penalties of up to $10 million or 2% of worldwide turnover. Penal proceedings are also possible: according to the CAI, fines for a business range from $15,000 up to $25 million or 4% of worldwide turnover, whichever is greater, and they are doubled for repeat offences. These maximums are aimed at serious cases, but the CAI can also require corrective measures.

For a small business, the real risk is more often a customer complaint, an investigation or damage to your reputation. The good news: bringing a simple brochure website into compliance usually takes just a few steps.

Law 25 checklist: where do I start with my website?

Here are the priority steps to bring a small business website into compliance.

  • Designate the person in charge and publish their title and contact information on the site.
  • Publish a clear, up-to-date privacy policy, in French (and in English if your site is bilingual).
  • Install a consent tool that blocks profiling and advertising cookies until the visitor accepts them.
  • Review your forms: minimum data, stated purposes, newsletter checkbox left unchecked.
  • Keep a register of confidentiality incidents, even if it's empty.
  • Keep your site, plugins and backups up to date.

Who can help make my website Law 25 compliant?

For a more complex case (sensitive data, transfers outside Quebec, a large online store), talk to a lawyer. The checklist above covers the website basics, not every situation.

At Situs Digital, we build fast, bilingual, compliant websites in Montréal and Lausanne, delivered with cookie consent management, lean forms and a structure ready for Law 25. If you'd like us to take a look at your current site, just write to us.

Frequently asked questions

Does Law 25 apply to freelancers and small businesses?

Yes. It applies to any business that collects personal information, whatever its size. A simple contact form is enough for it to apply.

Can I use Google Analytics under Law 25?

Yes, with precautions. Tell visitors about it in your privacy policy and, to be safe, only activate analytics cookies after consent, or configure the tool to limit identification. Advertising and profiling features must be turned off by default.

Is a “By continuing to browse, you accept cookies” banner enough?

Probably not. Law 25 requires manifest consent and prohibits turning on profiling functions by default. Simply continuing to browse isn't a clear choice; a banner with Accept and Decline buttons is safer.

Does my privacy policy have to be in French?

Yes. On top of Law 25, the Charter of the French Language requires your website content, including legal pages, to be available in French, alongside any English version.

Sources

  1. CAI – Main changes introduced by Law 25 (in French)
  2. CAI – Identification, location and profiling technology (in French)
  3. CAI – Collection of personal information by private businesses (in French)
  4. CAI – Penalties and prosecutions for businesses (in French)
  5. CAI – Writing a privacy policy: explanatory guide for businesses (PDF, in French)
  6. Gouvernement du Québec – New Law 25 provisions come into force (in French)
  7. Dubé Latreille Avocats – Law 25 and appointing a person in charge of the protection of personal information (in French)
  8. LégisQuébec – Act respecting the protection of personal information in the private sector (P-39.1)

Services

Read the article →

nFADP and your website: a practical guide for SMEs in French-speaking Switzerland

Read the article →

Bill 96 and your website: what Quebec businesses need to know in 2026

Read the article →

How much does a website cost in Quebec in 2026?

Let's talk about your project

Tell us about your business. We'll reply with a clear plan and a working demo early in the project.