Truvo CyberStats Verified May 2026 · Canadian privacy law
Sources: Canada Gazette SI/2018-32 · Osler — Law 25 enforcement · McCarthy Tétrault · LEGISinfo Bill C-27 · Library of Parliament summary.
PIPEDA · Quebec Law 25 · Bill C-27 · 2018–today
Federal reform took eight years and stalled. Quebec did it in three.
Canada's privacy regime hardened faster between 2018 and 2024 than at any point in its history. Quebec moved through three phases of Law 25 in 24 months. Then federal reform died at prorogation. As of May 2026, Quebec is the de facto national privacy regulator for any company operating in Canada.
Federal · PIPEDA
Quebec · Law 25
Federal · died at prorogation
Pending / no replacement
Nov 1
2018
Federal
PIPEDA · Mandatory breach reporting
PIPEDA mandatory breach reporting in force
Sections 10, 11, 14, 17(1)–(4), 19, 22–25 of the Digital Privacy Act activated. Canadian businesses must now report breaches of security safeguards to the Office of the Privacy Commissioner and notify affected individuals where there is a real risk of significant harm.

What changed

Mandatory breach reporting and notification became federal law for all PIPEDA-regulated organizations on November 1, 2018, per the Order Fixing November 1, 2018 (SI/2018-32, Canada Gazette Part II). The Order activated specific sections of the 2015 Digital Privacy Act amendments to PIPEDA.

Enforcement model

The OPC investigates complaints, issues findings and reports, and may apply to Federal Court for binding orders. The OPC has no authority to issue administrative monetary penalties under PIPEDA. This gap was the central rationale for Bill C-27's CPPA, which died at prorogation in January 2025.

Source

Canada Gazette, Part II — SI/2018-32 · OPC breach reporting guidance

Sep 22
2022
Quebec
Law 25 · Phase 1
Quebec Law 25 Phase 1 in force
Privacy officer designation, mandatory breach reporting to the Commission d'accès à l'information du Québec, and disclosure rules for biometric data activate first.

What changed

Bill 64 (formally An Act to modernize legislative provisions as regards the protection of personal information) was assented to in September 2021 and rolled out in three phases. Phase 1 took effect on September 22, 2022.

  • Designation of a privacy officer with public-facing accountability
  • Mandatory reporting of confidentiality incidents to the CAI Quebec and affected individuals
  • Mandatory disclosure when biometric data is being collected or used

Why it mattered

Phase 1 alone forced thousands of Quebec organizations, and any organization with Quebec residents in their data, to designate a named privacy officer for the first time. The CAI Quebec became operationally able to receive and investigate breach reports within months.

Source

Osler analysis: Law 25 enforcement scheme

Sep 22
2023
Quebec
Law 25 · Phase 2 · Penalty regime activates
PIAs, consent, right to erasure, and the new penalty ceiling
Privacy impact assessments become mandatory. New consent and transparency rules. Right to erasure. And the headline number: penal fines up to $25M or 4% of global revenue.

What changed

  • Privacy policy publication requirements
  • Mandatory privacy impact assessments (PIAs) for transfers of personal information out of Quebec or before launching projects involving personal information
  • Stricter consent rules; granular, separate consent for each purpose
  • Right to anonymization and right to erasure (the right to be forgotten in Quebec)
  • Penalty regime activated

Penalty ceilings

Administrative monetary penalty (s. 90.12): up to CA$10M or 2% of preceding-fiscal-year worldwide turnover, whichever is greater. Imposed by the CAI Quebec.

Penal fine (s. 91): up to CA$25M or 4% of preceding-fiscal-year worldwide turnover, whichever is greater. Minimum CA$15,000 for corporations; doubles on a subsequent offence. Five-year limitation period.

Source

McCarthy Tétrault: Law 25 obligations September 2023 · Osler: Law 25 enforcement scheme

Sep 22
2024
Quebec
Law 25 · Phase 3 · Fully in force
Quebec Law 25 fully in force. Quebec now matches GDPR.
Data portability is the headline new obligation. With the full law in force, Quebec's $25M / 4% penal ceiling sits in the same severity tier as GDPR's €20M / 4%.

What changed

The right to data portability activated on September 22, 2024. Individuals may request that personal information collected from them be communicated to them or, where technically possible, transferred to another organization in a structured and commonly used format.

The convergence with GDPR

With the entire Law 25 framework in force, Quebec's penalty severity sits in the same tier as the EU's GDPR (Article 83(5): €20M or 4% of global turnover). The penal regime is structurally similar, and Canadian organizations operating in Quebec face penalty exposure that mirrors EU enforcement.

Source

Osler analysis: Law 25 phases

Jan 6
2025
Federal
Bill C-27 · Died at prorogation
Bill C-27 dies. Federal privacy reform stalls.
Parliament prorogued. Bill C-27, which would have replaced PIPEDA's enforcement model with a tribunal-imposed penalty regime up to 5% of global revenue, died on the Order Paper. A snap federal election followed in April 2025.

What happened

Parliament was prorogued on January 6, 2025. Bill C-27, the Digital Charter Implementation Act, 2022 — which contained the Consumer Privacy Protection Act (CPPA), the Personal Information and Data Protection Tribunal Act, and the Artificial Intelligence and Data Act (AIDA) — died on the Order Paper without ever reaching Report stage or any Senate proceeding. Last committee meeting was September 26, 2024.

What it would have done

The CPPA would have established Canada's first direct administrative monetary penalty regime for federal privacy law. Penalties of up to 3% of global revenue or $10M for AMPs (s. 95(4)) and 5% of global revenue or $25M for indictable offences (s. 128). Important nuance frequently misstated: AMPs would have been imposed by a new Personal Information and Data Protection Tribunal on the Privacy Commissioner's recommendation, not by the OPC directly.

What happens next

A snap federal election was called for April 2025. As of May 2026, no successor bill has been confirmed under a numbered designation. The 2025 federal budget signalled a new privacy statute with a tribunal companion bill expected late 2025 or early 2026, but nothing has been formally introduced.

Source

LEGISinfo, Bill C-27 (44-1) · Library of Parliament Legislative Summary, Bill C-27

TodayFederal
2026 forward · No replacement
Federal reform stalled. Quebec is now the floor.
PIPEDA still has no direct OPC fining authority. Quebec Law 25 sits at GDPR severity. Any organization with Canadian residents in its data effectively defaults to Quebec's penalty regime as the binding constraint.

The de facto situation

For any organization holding personal information of Canadian residents, the federal floor is PIPEDA's reasonable-safeguards standard with no direct fining authority. The provincial floor in Quebec is Law 25's $25M / 4% penal ceiling. In practice, any breach affecting Quebec residents triggers the harder regime.

Most Canadian privacy lawyers and law firm analysts now advise designing privacy programs to Quebec Law 25 as the floor, not PIPEDA, for any organization with national operations. This is a meaningful shift in the centre of gravity of Canadian privacy compliance.

Watch for

The 2025 federal budget signalled a new privacy statute and tribunal companion bill expected late 2025 / early 2026. As of May 2026, no successor bill has been formally introduced under a numbered designation. Any new federal bill would likely continue the C-27 architecture: a Commissioner who investigates and recommends, with penalties imposed by a separate tribunal.

What this means for your organization

If you operate nationally, your binding privacy constraint is now Quebec, not Ottawa.

Most Canadian privacy programs were designed against PIPEDA's reasonable-safeguards standard. With C-27 dead and Law 25 fully in force at GDPR severity, any organization with Quebec residents in its data faces a regime an order of magnitude harder than PIPEDA. The cost of designing for that regime up front is bounded. The cost of redesigning under enforcement is not.

An effective security program designed to Quebec Law 25 holds up under PIPEDA, GDPR, and any successor federal regime. Truvo Cyber builds programs that scale across all three.
Talk to Truvo
Citation copied