Back to Blog
Law 25 July 20, 2026 7 min read

When Is a Privacy Impact Assessment Required Under Quebec's Law 25?

Most Quebec businesses think a privacy impact assessment is something only banks and hospitals do. Then they sign a US cloud vendor and trip the wire without realizing it. Here's the actual threshold.

By Valdra Team

When Is a Privacy Impact Assessment Required Under Quebec's Law 25?

A Montreal e-commerce company I spoke with last fall was three weeks from launching a new loyalty program. Slick app, personalized offers, the works. Their developer had picked a US-based analytics platform because it was cheap and the SDK was easy to drop in. Nobody in the building knew that single decision had pulled them into a legal obligation under Quebec's Law 25. They weren't a bank. They weren't a hospital. They sold artisanal kitchenware. And they still owed a documented privacy impact assessment before one byte of customer data crossed the border.

That gap, between who *thinks* they need a PIA and who *actually* does, is where most Quebec organizations get caught. So let's settle the threshold question properly.

When Is a Privacy Impact Assessment Required Under Law 25?

The Act respecting the protection of personal information in the private sector, which everyone calls Law 25 and which started life as Bill 64, creates two distinct triggers. Get these straight and you've answered most of the question.

The first lives in section 3.3. You must conduct a privacy impact assessment, an *évaluation des facteurs relatifs à la vie privée* (ÉFVP), for any project to acquire, develop, or overhaul an information system or electronic service delivery that involves personal information. That's the system-level trigger. A new CRM. A new booking platform. A migration off your old on-prem server onto a SaaS tool. A customer portal built from scratch. Each one is a project that handles personal information, and each one is in scope.

The second trigger is section 17, and it's the one that snares people who'd never otherwise give it a thought. Before you communicate personal information outside Quebec, you must assess whether the information will receive adequate protection, with particular regard to generally recognized data-protection principles. That's a cross-border transfer. In 2026, it captures almost any cloud service whose servers sit in Virginia, or Ireland, or anywhere that isn't Quebec.

Read those two sections together and the answer to *when is a privacy impact assessment required* gets uncomfortably broad. A PIA isn't reserved for high-risk profiling or biometrics. It attaches to ordinary infrastructure decisions that ordinary businesses make every quarter.

The Cross-Border Trap Most Businesses Walk Into

Section 17 is the quiet one, and it's the one I watch hardest. The Commission d'accès à l'information, Quebec's privacy regulator and a more assertive body than most people expect, treats "communication outside Quebec" as including storage or processing by a service provider located elsewhere. You don't have to mail a file to Texas. Letting AWS us-east-1 hold your customer list counts.

Here is what that means in practice. If you use any of the following, a section 17 assessment is owed for that data flow:

  • A US- or EU-hosted CRM such as Salesforce or HubSpot on default infrastructure
  • An email marketing platform with servers outside Quebec
  • A cloud backup or storage provider headquartered abroad
  • A payment or analytics tool that processes data offshore

Not a forty-page enterprise dossier, necessarily. But a documented evaluation of the risks, the destination jurisdiction's protections, and any contractual safeguards you've put in place. The kitchenware company tripped this wire. So do thousands of others who assume "we're too small for this to apply."

The assessment has to weigh the sensitivity of the information, the purpose of the transfer, the protection measures in place (contractual ones included), and the legal regime of the receiving jurisdiction. If the protection isn't adequate, you either fix it with contractual terms or you don't make the transfer. Where the analysis lands favourably, section 17 also requires a written agreement that reflects the assessment's findings. That's the teeth in the section.

Proportionality: The Assessment Scales to the Risk

Before anyone panics and budgets for a consultant on every Mailchimp signup, read section 3.4. The law builds in proportionality. Your PIA must be proportionate to the sensitivity of the information concerned, the purpose for which it is used, its quantity, its distribution, and the medium on which it sits.

A loyalty app handling names, emails, and purchase history does not carry the same risk as a clinic moving 50,000 patient records, and the statute doesn't pretend otherwise. For a low-sensitivity, low-volume flow, a proportionate assessment might be a one- or two-page record: what data, where it's going, why, what safeguards apply, what residual risk remains, and the decision you reached. For sensitive data at scale, for profiling, or for anything touching health or financial information, you're looking at something far more rigorous, with mitigation measures and sign-off from your privacy officer.

The mistake cuts both ways. Some organizations over-engineer a trivial transfer into months of paralysis. Others wave away a genuinely sensitive project because "it's just a small app." Proportionality is not an excuse to skip the assessment. It's a dial that controls how deep the assessment goes.

The Projects That Almost Always Trigger One

Want a working shortlist? Here are the situations where I'd treat a PIA as mandatory and stop arguing about it.

Launching or replacing any system that collects, stores, or uses personal information counts. A new HR platform, a patient portal, a customer database, a booking engine. That's section 3.3, full stop.

Sending personal information to a service provider outside Quebec covers most cloud adoption. That's section 17.

Deploying technology with profiling, geolocation, or identification capability is another. Section 8.1 gives individuals the right to be told when such technology is in use, and the right to switch off the identification, location, or profiling functions. If your project includes any of those, you're not just running a PIA, you're wiring disclosure and opt-out into the product.

So is any project involving sensitive personal information: health, biometric, financial, or anything that becomes sensitive because of its context. Here the question of whether to bother answers itself.

One note for the regulated crowd. This duty is distinct from your federal obligations under PIPEDA, which the Office of the Privacy Commissioner of Canada enforces, and from PHIPA in Ontario, which falls under the Information and Privacy Commissioner of Ontario, and from FINTRAC's anti-money-laundering recordkeeping rules. Quebec's regime stands on its own. Being PIPEDA-compliant federally does not discharge your Law 25 PIA duty. Operate across provinces and you carry both.

What Happens If You Skip It

The CAI can impose administrative monetary penalties of up to $10 million or 2% of worldwide turnover, whichever is higher. Penal prosecution before the Court of Québec climbs to $25 million or 4%. Law 25 also created a private right of action for harm caused by an unlawful infringement, with punitive damages of at least $1,000 per person where the breach involves intentional fault or gross negligence. For an incident affecting thousands of customers, the arithmetic turns ugly fast.

I'm not going to fearmonger with maximums that mostly land on flagrant, repeated conduct. But the absence of a PIA isn't a passive omission. It's documentary evidence that you didn't assess a known risk. If a transfer goes wrong, or a system you stood up leaks, the missing assessment is the first thing the CAI asks for and the first thing a plaintiff's lawyer points to.

The quieter reality is that the assessment usually *prevents* the bad outcome. Forcing yourself to write down where data goes and what protects it surfaces the analytics SDK nobody vetted, the vendor contract with no data-protection clause, the backup quietly replicating to another continent. That isn't paperwork. That's the control doing its job.

So, the honest answer to the threshold question: if your project builds or buys a system that touches personal information, or moves any of it outside Quebec, assume a PIA is owed and let proportionality decide how heavy it needs to be. Knowing *whether* was never the hard part. The hard part is having a repeatable way to actually run them without a $500K consultant on retainer.

That's the part we built. Run your project through Valdra's guided PIA wizard and get a proportionate, CAI-ready assessment without the consulting bill.

privacy impact assessment Law 25when is a PIA required QuebecLaw 25 PIA thresholdCAI privacy assessmentQuebec Law 25 compliancePIA cross-border transfer

AI governance and privacy compliance, simplified.

Valdra helps Canadian companies govern AI and meet PIPEDA and Law 25 — hosted in Canada.

Try Valdra

Our own compliance

We run our own compliance programme inside Valdra — the product we sell. Our SOC 2, ISO 27001 and ISO 42001 programmes are actively in progress; we do not claim certifications we do not yet hold.

Valdra compliance badge — click to verify
  • PIPEDA
  • Law 25 (Quebec)
  • CASL
  • Data hosted in Canada 🇨🇦
  • AI governance
View our Trust Centre

Self-declared, not audited by a third party. Click the badge to verify it is genuine and see what it covers.

When Is a Privacy Impact Assessment Required Under Law 25 | Valdra