Quebec Law 25 for Real Estate and Proptech
Everything real estate operators and proptech businesses need to understand about Quebec's Law 25, the updated provincial privacy law that governs how personal information is collected, stored, and used in Quebec. Consent, cookies, cross-border transfers, and enforcement.
What this guide answers in five lines.
- 01What Law 25 is and who it applies to.
- 02How Law 25 differs from PIPEDA and GDPR.
- 03The specific implementation obligations under Law 25.
- 04Consent mechanics for cookies, marketing, and data collection.
- 05Cross-border data transfer rules and their impact on cloud vendor choices.
- 06The confidentiality incident (breach) notification rules.
- 07Enforcement, penalties, and the role of the Commission d'accès à l'information.
- 08Practical implementation steps for real estate and proptech businesses.
Executive summary
This guide covers what Law 25 requires, how it differs from PIPEDA (the federal law) and GDPR (the European one), the specific implementation obligations, the cross-border transfer rules that catch many businesses off guard, the consent mechanics for cookies and marketing, and the enforcement regime with penalties of up to CAD 25M or 4% of global revenue. Written for real estate operators, brokerages, developers, and PropTech founders working in Quebec or with Quebec residents.
Built for operators across the stack.
Quebec-based real estate operators
Brokerages, developers, property managers with operations in Quebec. Chapters 3, 5, and 8 map the core obligations.
Non-Quebec businesses with Quebec customers
If you serve Quebec residents from elsewhere in Canada or abroad, Law 25 still applies. Chapters 1, 6, and 9 cover the extraterritorial reach.
PropTech founders
Building products that process Quebec resident data. Chapters 4, 6, and 7 cover consent, cross-border transfers, and the technical implementation.
Marketing and digital teams
Cookie consent, ad targeting, and email marketing all fall under Law 25. Chapters 4, 5, and 10 cover the marketing surface.
01
What is Quebec Law 25?
Quebec Law 25 (formally, Loi modernisant des dispositions législatives en matière de protection des renseignements personnels) is Quebec's updated privacy law, in force since September 2022 with the main obligations taking effect in September 2023. It replaces and strengthens Quebec's previous private-sector privacy regime.
Law 25 applies to any business that collects, uses, or discloses personal information about people in Quebec, regardless of where the business is located. That extraterritorial reach is the first thing many businesses outside Quebec miss. A US-based PropTech that has a Quebec-resident user is subject to Law 25 for that user's data. The law establishes higher consent standards than PIPEDA, mandatory breach notification, cross-border transfer rules, and administrative penalties enforceable by the Commission d'accès à l'information.
Key takeaway
Law 25 applies to any business processing personal information about Quebec residents, wherever the business is located.
02
How Law 25 differs from PIPEDA and GDPR
Law 25 is stricter than PIPEDA (the federal Canadian privacy law) on consent, cross-border transfers, and enforcement, and shares many concepts with GDPR (the European standard) but with Quebec-specific mechanics. Businesses that comply with GDPR generally have a strong starting point for Law 25 compliance.
PIPEDA operates on implied consent for most standard business purposes; Law 25 requires explicit consent for sensitive collection and use. PIPEDA has voluntary breach notification for many scenarios; Law 25 mandates it within 72 hours for confidentiality incidents creating a risk of serious harm. Law 25 introduces a specific cross-border transfer rule requiring impact assessments before sending data outside Quebec. Businesses already GDPR-compliant will find the general obligations familiar; the specific mechanics (consent forms, French language requirements, Commission-approved contracts) still need Quebec-specific implementation.
Key takeaway
Law 25 sits between PIPEDA (weaker) and GDPR (broadly comparable). GDPR-compliant businesses have a head start but still need Quebec-specific implementation.
03
What Law 25 requires businesses to do
Businesses must appoint a Privacy Officer, maintain a public privacy policy, obtain valid consent, respond to access and rectification requests, notify confidentiality incidents within 72 hours, conduct privacy impact assessments for high-risk projects, and follow specific rules for cross-border transfers and automated decision-making.
The obligations are extensive. Appoint a Privacy Officer whose name and contact are publicly listed. Publish a clear, French-first privacy policy. Obtain valid consent (specifically the consent standard depends on the sensitivity and purpose). Give individuals access to their data and the ability to correct or delete it. Notify the Commission and affected individuals of any confidentiality incident creating a risk of serious harm, within 72 hours. Conduct a Privacy Impact Assessment (PIA) before starting high-risk projects. Follow the cross-border transfer rules before sending data outside Quebec. Real estate businesses touch most of these obligations directly.
Key takeaway
Law 25 is not one obligation but a package: Privacy Officer, policy, consent, access, breach notification, PIAs, cross-border rules. Every one applies to real estate.
04
Consent and cookies under Law 25
Law 25 requires that consent be free, informed, given for specific purposes, granular, and evidenceable. For cookies and marketing tracking, this typically means an opt-in consent banner (not opt-out), with granular controls over tracking categories, and a clear record that consent was given.
The consent standard is materially higher than what most Canadian sites currently implement. Implied consent through continued site use is not sufficient for most non-essential tracking under Law 25. Practical implementation: a cookie banner that defaults to no non-essential tracking, categories the user can enable individually (functional, analytics, advertising), a persistent way to review and withdraw consent, and audit logs that record what each user consented to and when. Failing to implement this properly is one of the most common Law 25 compliance gaps at real estate sites operating in Quebec.
Key takeaway
Opt-in consent for non-essential tracking, with granular category controls and audit logs. Implied consent is not sufficient under Law 25.
05
Cross-border data transfers
Before sending personal information outside Quebec (which includes most cloud services), Law 25 requires a privacy impact assessment considering the destination's privacy regime and the sensitivity of the data. Cloud vendors located in the US, EU, or elsewhere are all technically cross-border transfers.
This provision catches many businesses off guard because standard cloud infrastructure (AWS, Google Cloud, Azure) typically involves cross-border data flows even for Canadian operations. Practical implications: audit where each system stores and processes Quebec resident data, choose Canadian-region hosting where possible (AWS Canada Central, GCP Montreal, Azure Canada East), document the impact assessments, and use Commission-approved contractual clauses when transfers are necessary. Vendors should be evaluated on their Quebec compliance posture, not just their security posture.
Key takeaway
Every cloud vendor and third-party processor is a potential cross-border transfer. Audit, assess, and prefer Canadian-region hosting for Quebec resident data.
06
Confidentiality incidents and breach notification
Law 25 requires organisations to notify the Commission d'accès à l'information and affected individuals of any confidentiality incident creating a risk of serious harm, within 72 hours of becoming aware of it. Records of all incidents must be maintained regardless of whether notification is required.
A confidentiality incident is any unauthorised access, use, disclosure, or loss of personal information. The 72-hour clock starts when the business becomes aware, which in practice means having an incident response process that identifies and evaluates incidents quickly. The threshold for external notification is 'risk of serious harm,' which considers the sensitivity of the data, the ease of identification, and the probable use. All incidents must be logged in a register regardless of whether they meet the notification threshold, and the register can be requested by the Commission.
Key takeaway
72-hour notification for high-risk incidents; internal register for all incidents. Both require an incident-response process built and tested before an incident occurs.
07
Privacy impact assessments (PIAs)
Law 25 requires organisations to conduct a Privacy Impact Assessment before starting any project that involves acquiring, developing, or overhauling an information system or electronic service delivery, when it involves personal information. PIAs must be documented and made available on request.
For real estate businesses, this catches most technology projects: launching a new CRM, migrating from one PMS to another, deploying an AI tool that processes tenant data, integrating a new payment processor. The PIA process examines the necessity of the personal information, the proportionality of the collection, the security measures, the retention period, and the cross-border transfers involved. It is not just a form; it's a documented analysis that has to be defensible if the Commission asks.
Key takeaway
Any material technology change involving personal information triggers a PIA. Build the PIA process into your project intake, not just as a compliance afterthought.
08
Automated decision-making
When personal information is used solely for automated decision-making, individuals must be informed of that fact, given the reasons for the decision, and offered the opportunity to submit observations to a human reviewer. This includes AI-driven tenant screening, credit assessment, or lease approval.
This provision applies squarely to any AI or algorithmic tool that makes decisions about individuals without human involvement. Automated tenant screening, credit decisions, mortgage prequalification tools, and AI-driven lease approvals all fall under this requirement. Practical implication: any such system needs a disclosure to affected individuals, a way to explain the decision, and a human review path. Systems that operate as pure automated decisions without human oversight are non-compliant.
Key takeaway
Fully automated decisions about individuals require disclosure and a human review path. Build this into the workflow, not as an appeal process bolted on later.
09
Enforcement and penalties
The Commission d'accès à l'information enforces Law 25. Administrative penalties can reach CAD 25 million or 4% of global annual turnover, whichever is higher. Criminal penalties apply for the most serious violations. Private rights of action allow individuals to sue for damages.
The enforcement regime is aggressive by Canadian standards and comparable to GDPR by financial impact. The Commission has audit powers, can issue orders, impose administrative monetary penalties, and refer serious matters for criminal prosecution. Individuals can bring civil actions for damages. Real estate businesses should expect increased Commission activity as the regime matures, particularly in areas the Commission has flagged as priorities: consent, cross-border transfers, and automated decision-making.
Key takeaway
Penalties are material and enforcement is real. Treat Law 25 as an active compliance regime, not a paper exercise.
10
Practical implementation for real estate
A Law 25 compliance programme for a real estate business typically has 10 workstreams: Privacy Officer appointment, privacy policy update, consent banner and forms, access request process, incident register and response, PIA template and process, cross-border transfer audit, automated decision review, vendor management, and staff training.
The programme is a sustained effort, not a one-time fix. Start with the highest-risk gaps: consent and cross-border transfers are the most common enforcement targets. Update the privacy policy and appoint the Privacy Officer. Implement the cookie consent banner. Audit vendor contracts and add Commission-approved transfer clauses where needed. Build the incident response process before you need it. Train staff on the basics. Then loop back for continuous improvement. Businesses that treat Law 25 as an integrated programme rather than a checklist stay ahead of enforcement risk.
Key takeaway
Law 25 is a programme, not a checklist. Prioritise consent and cross-border transfers first, then work through the remaining workstreams over 6 to 12 months.
Frequently asked questions.
Does Law 25 apply to businesses outside Quebec?
Yes, if you collect, use, or process personal information about people in Quebec. A US or Ontario business with Quebec-resident customers is subject to Law 25 for that data.
What is the penalty for non-compliance?
Administrative penalties up to CAD 25 million or 4% of global annual turnover, whichever is higher. Criminal penalties for serious violations. Private civil actions for damages.
Do we need to appoint a Privacy Officer?
Yes. Every organisation subject to Law 25 must appoint a Privacy Officer whose name and contact information are publicly available.
How does Law 25 handle cookies?
Non-essential cookies (analytics, advertising, tracking) require explicit, granular opt-in consent. Implied consent through continued site use is generally not sufficient.
Can we use AWS or Google Cloud for Quebec data?
Yes, but the cross-border transfer must be assessed and documented via a Privacy Impact Assessment. Prefer Canadian regions (AWS Canada Central, GCP Montreal, Azure Canada East) where available.
Quebec Law 25 is a substantive privacy regime with real enforcement teeth and extraterritorial reach that affects any real estate or proptech business touching Quebec resident data. The compliance path is a programme, not a checklist: appoint the Privacy Officer, update the privacy policy, implement opt-in consent, audit cross-border transfers, build the incident response process, and train staff. Businesses that treat Law 25 as an integrated compliance function stay ahead of the enforcement curve; those that treat it as a paper exercise get caught at the first Commission audit or complaint.
Glossary
Key terms, defined.Law 25
Quebec's updated private-sector privacy law, in force since 2022 with main obligations effective 2023.
Commission d'accès à l'information
The Quebec regulator responsible for enforcing Law 25.
Privacy Officer
The named individual responsible for privacy compliance within the organisation, whose contact must be public.
Privacy Impact Assessment (PIA)
A documented analysis of the privacy implications of a project, required before any material system involving personal information is deployed.
Confidentiality incident
Any unauthorised access, use, disclosure, or loss of personal information. High-risk incidents require 72-hour notification.
Cross-border transfer
Any transfer of personal information outside Quebec, including to cloud vendors located elsewhere. Requires impact assessment and documented safeguards.
What to do next
Four pathways out of this guide.- 01
See the Canada real estate hub
Our full Canadian real estate and proptech agency page, with Law 25 built in.
- 02
See the Montreal city guide
Quebec-specific real estate agency delivery, bilingual, Law 25 compliant.
- 03
Book a scoping call
30-minute conversation on your Law 25 compliance posture and priority gaps.
When you're ready to ship
Often shipped togetherSources
Loi 25, Assemblée nationale du Québec, official text
Commission d'accès à l'information du Québec, published guidance 2023-2026
OPC (Office of the Privacy Commissioner) comparative analysis Law 25 vs PIPEDA
Noseberry Digitals Law 25 engagement data across Quebec real estate operators
Want this framework applied to your operator stack
Book a strategy call. We'll walk through your specific operator profile, audit where you are today, and map this guide's framework onto a costed 18-month roadmap.