Truvo CyberStats Verified May 2026 · Canadian privacy law
Sources: Osler — Quebec Law 25 enforcement (s. 90.12 / s. 91) · LEGISinfo Bill C-27 · LoP Legislative Summary, C-27 · GDPR Article 83(5) · OPC PIPEDA breach guidance.
Maximum privacy penalty exposure · Canada vs EU
Your maximum privacy penalty exposure in Canada.
Quebec Law 25 sits at GDPR severity. PIPEDA has no direct fining authority. Bill C-27 died at prorogation in January 2025. Enter your organization's annual revenue to see your real exposure under each regime. Maximum ceilings only; actual penalties depend on circumstances and regulatory discretion.
Drag the slider or type a value. Most Quebec Law 25 and CPPA penalties are calculated on global revenue.
CA$ M
Maximum administrative + penal exposure
Each regime shows max(fixed ceiling, percentage of revenue). The binding regime is highlighted.
PIPEDA In force, federal
No direct fining authority. OPC investigates and refers to Federal Court; no administrative monetary penalties available under federal law as of May 2026.
$0
Direct OPC fine
Quebec Law 25 — admin penalty In force
max($10M · 2% of preceding-year worldwide turnover). Imposed by CAI Quebec under s. 90.12.
$10M
Fixed ceiling binding
Quebec Law 25 — penal fine In force
max($25M · 4% of preceding-year worldwide turnover). Penal proceedings under s. 91; min $15K, doubles on subsequent offence; 5-year limitation.
$25M
Fixed ceiling binding
EU GDPR For reference
max(€20M ≈ CA$30M · 4% of global annual turnover). Article 83(5); applies if EU residents are in your data.
CA$30M
Fixed ceiling binding
Bill C-27 / CPPA Died Jan 2025
Would have been max($25M · 5% of global revenue) for indictable offences (s. 128). Tribunal-imposed AMPs would have been max($10M, 3%). Bill died at prorogation.
$25M
Hypothetical · bill never enacted
The binding regime. If any of your data subjects are Quebec residents, Quebec Law 25 is your binding constraint, regardless of where your headquarters are. PIPEDA's reasonable-safeguards standard remains the federal floor, but it has no direct fining authority. Most national Canadian operators now design privacy programs to Law 25 as the floor, not PIPEDA.
What this means for your organization

Designing a privacy program to Law 25 holds up under PIPEDA, GDPR, and any plausible federal successor regime.

The cost of designing a privacy program to GDPR-tier severity is bounded and predictable. The cost of redesigning under enforcement, after a CAI Quebec or OPC investigation finds your safeguards unreasonable, is not. The Desjardins $200.85M settlement is the floor for what high-sensitivity Canadian breach failures actually cost, and it has nothing to do with regulatory penalties at all. It's the class action tail.

An effective security program designed to Law 25 severity is the cheapest version of compliance available. Truvo Cyber builds programs that hold up across regimes.
Talk to Truvo
Citation copied