Someone in procurement at a customer, or a lawyer you pay by the hour, has said the words "Law 25," and now there is a knot in your stomach. This is more manageable than the panic makes it feel, so you can unclench a little. The one thing that will not save you here is being small, since "we are too small for this" is not the exit most people assume it is.
Let me lay it out in plain language, with the legalese left to one side.
Two laws, and which one is watching you
Canada has a federal privacy law, PIPEDA, that covers how most businesses handle personal information across the country. Quebec has its own version, recently overhauled into what everyone now calls Law 25. If you have customers or employees in Quebec, Law 25 reaches you no matter where your office sits. A Toronto company with a few Montreal clients ends up answering to both.
The two laws mostly rhyme with each other, and the place they part ways is narrow but important. It comes down to what data you are allowed to move out of the province, and what you have to do before you move it.
PIPEDA: moving data is fine, hiding it is not
PIPEDA does not require you to keep Canadian data inside Canada. You can use a US cloud or a European sub-processor, whatever the job actually needs. When you hand personal information to a service provider to process on your behalf, for the same purpose you collected it, you do not need to gather fresh consent for the trip. It also does not matter which country that provider sits in. Canada runs on an accountability model between organizations, so you stay responsible for the data even when it sits in someone else's hands, and you cover that with a proper contract.
There is one obligation that people skip, and it happens to be the cheap one, which is simply being transparent. You tell people that their information may be handled outside Canada, and that foreign authorities could therefore reach it. That is essentially the whole federal story for most small businesses, and honestly it is not that frightening.
Law 25: the step almost nobody actually does
Quebec adds a requirement that trips up small companies all the time. Before personal information leaves the province, even when it is only heading as far as Ontario, you are expected to run a privacy impact assessment first. This is not a quick gut check over coffee. It is a documented assessment that weighs how sensitive the data is, what it is for, the safeguards around it, and the legal regime of wherever the data is going.
If that assessment shows the data will get protection equivalent to Quebec's, you can go ahead, backed by a written agreement with whoever is receiving it. Equivalent does not have to mean identical here. It means the person's core rights survive the trip, so they can still access and correct their data, an independent regulator is watching, real remedies exist, and any onward transfers are kept in check.
That last point is worth sitting with, because it is where people get caught. Sending data to another Canadian province can trigger the whole requirement. The cloud region matters, and so does the question of who actually runs it.
Why "it's in our Canadian region" isn't the closed answer
Picture a provider that stores everything in a Toronto data centre, which certainly feels compliant on the surface. If that provider is US-headquartered, the data can still be compelled out under the US CLOUD Act, regardless of which region the bytes physically sit in. Your data can be resident in Canada and reachable from Washington at the same moment.
This is the residency-versus-sovereignty distinction, and it is the single most useful idea to hold onto here. Residency is simply where the data physically lives, while sovereignty is about whose laws can actually reach it. You can easily have the first without the second, and a Law 25 assessment is exactly where that gap is meant to get caught. It is also why US hosting is a hard sell for Quebec personal data, no matter how tidy the paperwork looks.
What it costs to get this wrong
Law 25 has teeth that PIPEDA historically lacked, and this is the part worth reading slowly. The regulator can levy administrative penalties of up to C$10 million or 2% of worldwide turnover, whichever is greater. Offences pursued through penal proceedings run higher, up to C$25 million or 4% of worldwide turnover, again whichever is greater. Law 25 also gives individuals a private right of action, which neither PIPEDA nor even the GDPR offers, with damages starting at a floor of C$1,000 per person. A single misstep can turn into a class action rather than a stern letter from a regulator.
For a company doing a few million in revenue, 2% of turnover is not a rounding error, it is a genuinely bad quarter.
What this looks like for a small business
You do not need a privacy department to handle this, you need three things.
First, know whether you touch Quebec personal data at all. Most small businesses assume they do not, and a good share of them are wrong.
Second, before you move that data anywhere, including to a Canadian cloud outside Quebec, run the privacy impact assessment and keep the record. This is the step everyone skips, and it is the one a regulator asks about.
Third, keep an eye on where your most sensitive material actually lives, and lean toward keeping it on infrastructure you control and can point to on a map. That last part is why we build our own tools to run self-hosted. Your compliance evidence and gap analysis map out precisely where you are weak. That is the last thing you want sitting in a US SaaS tool while you explain to a Quebec regulator whose laws can reach it. If you would rather have a person walk you through the Quebec side, that is what our team does.
None of this makes Law 25 an emergency, it makes it a checklist. The companies that come through it clean are the ones that did the boring assessment before a customer's security team asked, rather than during.
This is general information, not legal advice. For a specific Law 25 obligation, talk to a Quebec privacy lawyer.