StructureClerk

Quebec and Canada

Law 25 and cybersecurity compliance for Quebec organizations

Assess your compliance with Quebec and Canadian regulatory frameworks for free.

Free · No credit card required

Regulatory context

Law 25 (Act to modernize legislative provisions respecting the protection of personal information) has been fully in force since September 2024. Quebec organizations must have appointed a personal information protection officer, published a privacy policy, and implemented incident management processes and privacy impact assessments.

Organizations also operating federally must comply with PIPEDA. Bill C-27 (CPPA, AIDA) died on the Order Paper at the January 2025 prorogation — there is no federal AI law in force.

In cybersecurity, the MCN Cybersecurity Framework and Quebec government guidelines add additional requirements.

Key points covered

Law 25 fully in force since September 2024
Mandatory Personal Information Protection Officer
Privacy Impact Assessments (PIAs)
Incident notification to CAI within 72 hours
PIPEDA for interprovincial and federal activities
No federal AI law in force — Bill C-27 (CPPA, AIDA) died on the Order Paper in January 2025

Assessed domains

Data Protection

Law 25, PIPEDA

AI Governance

Law 25 (AI), C-27 (AIDA)

Cybersecurity

NIST, ISO 27001

Assess your Quebec compliance

CISO-level questionnaire. Free PDF report. In minutes.