This guide evolves with Law 25, CAI decisions and the practice we observe at our clients. This page documents the significant changes so you know what has changed since your last visit.
2026-04-20, Initial publication
First full version of the Law 25 guide on the Hilo Tech wiki. Nine chapters covering:
- Scope and definitions
- Consent
- Confidentiality incident notification
- Person in charge of the protection of personal information
- Individual rights
- Transfers outside Quebec
- Sanctions and penalties
- Templates and samples
- Version history (this page)
Legal context at the time of publication:
- PPIPSA (CQLR c. P-39.1) with Law 25 amendments fully in force since September 22, 2024.
- The right to data portability (s. 27 para. 2) has been in force for 19 months at publication.
- The CAI has published its main application guides (privacy officer, incident notification, PIAs).
Legal references cited
The table below summarizes the PPIPSA sections cited in the guide. When in doubt, consult the Commission d'accès à l'information (CAI) directly.
| Section | Topic | Chapter |
|---|---|---|
| s. 1 | Scope | Scope and definitions |
| s. 2 | Definition of personal information | Scope and definitions |
| s. 3.1 | Privacy officer designation | Privacy officer |
| s. 3.2 | Governance policy | Privacy officer |
| s. 3.3 | Privacy impact assessment (PIA) | Cross-border transfers |
| s. 3.5 | Notification obligation | Breach notification |
| s. 3.6 | Definition of confidentiality incident | Breach notification |
| s. 3.7 | Risk-assessment criteria | Breach notification |
| s. 3.8 | Incident register | Breach notification |
| s. 4.1 | Consent of minors | Consent |
| s. 8 para. 3 | Publishing the officer's contact | Privacy officer |
| s. 8.3 | Withdrawal of consent | Consent · Individual rights |
| s. 12 | Consent for sensitive information | Consent |
| s. 12.1 | Automated decisions | Individual rights |
| s. 13 | Performance of a contract | Consent |
| s. 14 | Qualities of consent | Consent |
| s. 17 | Transfers outside Quebec | Cross-border transfers |
| s. 18 | Exceptions (legal obligation, emergency) | Consent |
| s. 21 | Study, research, statistics | Consent |
| s. 27 | Right of access and portability | Individual rights |
| s. 28 | Right of rectification | Individual rights |
| s. 28.1 | De-indexing / cessation of dissemination | Individual rights |
| s. 32 | 30-day response deadline | Individual rights |
| s. 33 | Moderate fees | Individual rights |
| s. 34 | Motivated refusal | Individual rights |
| s. 40 | Recourse to the CAI | Individual rights · Penalties |
| s. 53 | Rectification | Individual rights |
| s. 90.1 | Administrative monetary penalties | Penalties |
| s. 90.3 | Grading criteria | Penalties |
| s. 90.4–90.8 | Sanction process | Penalties |
| s. 91 | Penal fines | Penalties |
| s. 93.1 | Civil recourse and punitive damages | Penalties |
Planned future updates
We update this guide:
- On every entry into force of a Quebec legislative or regulatory change affecting the PPIPSA.
- On every landmark CAI decision that changes the practical reading of the Act.
- On every field insight from clients or peers, when a question recurs, we fold it in.
Major updates will appear at the top of this page with the date and a summary. To be notified of changes, follow our blog.
Corrections and suggestions
A mis-cited section? A CAI decision we should integrate? A missing section? Write to privacy@hilotech.ca: we will review and correct, with credit if you wish.
Limitation of liability
This guide is provided for information. It reflects the interpretation of Hilo Tech and public primary sources (LégisQuébec, CAI) as of the indicated date. It does not constitute legal advice. For any legal decision that binds your enterprise, consult a lawyer.
Question about this guide?
Pascal and Jérémie can answer directly by email or during a discovery call.
Get in touch