Cookie Consent Quebec Law 25: The Death of Silent Tracking
Most Canadian websites fire analytics and ad pixels before anyone clicks "accept" — already a documented liability under Quebec Law 25. Here's what a genuinely compliant cookie banner needs, and why silent tracking is finished.
By Valdra Team
A Montreal e-commerce shop I looked at last year ran a cookie banner that said "By using this site you accept cookies" with a single blue OK button. Behind it, before anyone clicked anything, the site had already fired Google Analytics, a Meta Pixel, a TikTok tag, and two ad-retargeting scripts. The owner thought a banner made him compliant. What he actually had was the opposite: timestamped, automatic proof that he was tracking Quebecers without consent, generated on every page load.
That gap between having a banner and having consent is where most Canadian businesses sit right now. And it is getting expensive.
Why the old cookie banner is dead
For years the Canadian playbook was simple. Drop a banner that says "we use cookies," let people keep browsing, and treat continued use as agreement. That approach was always shaky under PIPEDA. Quebec's Law 25 has made it indefensible for any business with users in the province.
The core problem is implied consent. PIPEDA does allow implied consent in some situations, but the Office of the Privacy Commissioner of Canada has been clear for years that the sensitivity of the information and the reasonable expectations of the individual decide what is acceptable. Tracking someone across the web, building a behavioural profile, and feeding it to advertising networks is not what a reasonable person expects when they land on your homepage to read a blog post. The OPC's guidance on online behavioural advertising has long held that this kind of tracking generally calls for express, opt-in consent, with a genuine ability to decline.
Law 25 sharpens this to a point. Section 8.1 of Quebec's Act respecting the protection of personal information in the private sector requires that any technology allowing a person to be identified, located, or profiled be deactivated by default. Read that again. By default. The user has to be told the technology exists and given the means to switch it on. That is the legal death certificate for silent tracking. You cannot load a profiling cookie and ask permission afterward. The script sits dormant until the person says yes.
What cookie consent under Quebec Law 25 actually requires
When people search for cookie consent Quebec Law 25, they are usually hoping for a checklist. Here is the honest version, and it is stricter than the GDPR cookie habits a lot of agencies copy-paste from Europe.
A compliant setup under Law 25 and PIPEDA needs to do the following:
- Block non-essential trackers before consent. Analytics, advertising pixels, session-replay tools, social embeds that phone home — none of them fire on page load. Strictly necessary cookies (your shopping cart, security tokens, load balancing) can run, because they deliver the service the user actually asked for.
- Make "Reject" as easy as "Accept." A banner with a prominent Accept button and a buried "manage preferences" link that takes four clicks to refuse is not free consent. The Commission d'accès à l'information (CAI), Quebec's regulator, expects symmetry: one click to accept, one click to refuse.
- Use granular categories. Consent has to be specific. Lumping analytics, advertising, and personalization into a single "accept all" toggle is not specific consent under Law 25. People should be able to say yes to analytics and no to ad targeting.
- Render it in plain-language French. Quebec's Charter of the French language and Law 25's transparency requirements both apply. A banner that only loads in English for a Quebec audience fails on two fronts at once.
- Log it. Keep a record of who consented, to what, and when, plus an equally easy way to withdraw consent later. If the CAI asks you to demonstrate consent, "the banner was there" is not evidence. The consent record is.
That last point trips up the businesses that think they are done. Consent is not a moment. It is a state you have to prove and let people exit.
The regulators are not bluffing
People assume privacy enforcement in Canada is toothless. That used to be closer to true. Not anymore.
Law 25's administrative monetary penalties, imposed by the CAI, reach up to $10 million or 2% of worldwide turnover, whichever is higher. The separate penal provisions go up to $25 million or 4%, and can be doubled for repeat offences. Law 25 also created a private right of action with statutory damages starting at $1,000 per person, plus punitive damages for intentional or grossly negligent breaches. This is not the old stern-letter-from-a-commissioner regime.
A banner is a cost. A consent record is an asset. The difference is whether you can prove what happened when someone asks.
On the federal side, the OPC has been investigating ad-tech and tracking practices directly, including its work on facial recognition and on the use of in-store analytics by major retailers. The proposed Consumer Privacy Protection Act, if it passes, would let the Privacy Commissioner recommend administrative penalties of up to the greater of $10 million and 3% of global revenue, with penal fines reaching 5% for the most serious offences. The direction of travel runs one way. Silent tracking is becoming a documented liability that sits in your own server logs.
Here is the part owners underrate: the evidence against you is generated automatically. Every page load that fires a pixel before consent is a logged event. You are building the case file. A single French-language complaint to the CAI from one annoyed Montrealer can start the whole thing.
Most Canadian businesses don't know what's on their own site
This is the practical heart of it. I have yet to audit a small or mid-sized Canadian website where the owner could name every tracker running on it. Tag managers make it trivial for a marketing contractor to add a script, and those scripts pull in other scripts. A single Google Tag Manager container can quietly load a dozen third-party trackers the business never agreed to host. WordPress plugins ship analytics you never asked for. An embedded YouTube video sets cookies from doubleclick.net.
You cannot get consent for tracking you do not know is happening. So step one is never the banner. Step one is the inventory: a full scan of what your site actually loads, what category each cookie and tracker falls into, who it sends data to, and whether it fires before or after consent. Until you have that map, any banner you put up is decoration.
A realistic path to compliance
You do not need a half-million-dollar consultant for this, whatever some firms tell you. The work is concrete and it has an order.
Start by scanning your live site and listing every cookie and tracker, including the third parties they call. Sort them into strictly necessary versus everything else. Wire up a consent management tool that genuinely blocks the "everything else" bucket until the user opts in, with a Reject button as visible as Accept, rendered properly in French for your Quebec traffic. Then keep the consent logs so you can prove what happened and honour withdrawals. Re-run the scan on a schedule, because your marketing team will add new tags and quietly break the setup.
This is the gap Valdra was built to close for the 95% of Canadian businesses that were priced out of enterprise privacy tooling. The whole stack is bilingual and hosted in Canada, which matters the moment you have to explain data residency to a Quebec customer.
The Montreal shop owner fixed his banner in an afternoon, once he could see the actual list of what his site was loading. The seeing was the hard part. If you want to know what is really firing on your pages before a visitor consents, scan your site for cookies and trackers and start from the truth instead of a guess.
AI governance and privacy compliance, simplified.
Valdra helps Canadian companies govern AI and meet PIPEDA and Law 25 — hosted in Canada.
Try Valdra