Quebec's Law 25 is the strictest private-sector privacy law in Canada, and it applies to any organisation that handles the personal information of Quebec residents, wherever that organisation is based. For a company that outsources work touching that data, whether customer service, back-office processing, collections or data annotation, the law changed several things that a procurement or risk team now has to address directly rather than assume.
This article sets out what actually moved. It is general information for buyers evaluating outsourced delivery, not legal advice, and a company with Quebec exposure should take its own counsel.
What the law is, and when it landed
Law 25, which began life as Bill 64, overhauled Quebec's private-sector privacy regime. Its requirements came into force in three annual stages on 22 September 2022, 2023 and 2024, according to Quebec's Commission d'acces a l'information. The first stage required organisations to appoint a person responsible for the protection of personal information and to report serious breaches. The second, the largest, brought in transparency, consent, governance and privacy-impact requirements. The third added the right to data portability.
The reason it matters to outsourcing specifically is that it raised the standard of accountability for personal information and made an organisation answerable for what its service providers do with data on its behalf.
Accountability now follows the data to the provider
The most consequential change for a buyer is that outsourcing a function no longer outsources responsibility for the data inside it. Under Law 25 the organisation that collects the personal information remains accountable for it, including when a third party processes it. That means the choice of provider, and the terms it operates under, are now a privacy-compliance decision, not only a commercial one.
In practice a risk team can no longer treat a service provider as a black box. It has to be able to describe what the provider does with the data, on what basis, and under what controls, because the organisation itself is answerable for those answers.
Breach reporting compresses the timeline
Law 25 requires organisations to report a confidentiality incident that presents a risk of serious injury to the Commission and to affected individuals, and to keep a register of incidents. For an outsourced operation this reshapes the contract. The provider has to detect and escalate incidents fast enough for the client to meet its own obligation, which means a defined notification window measured in hours, a named contact on both sides, and a rehearsed process that exists before an incident rather than being improvised during one.
A provider that cannot commit to a specific escalation timeline is a provider that can put the client in breach through inaction. That is now a selection criterion.
Consent, purpose and transparency reach into the operation
The law tightened consent and purpose limitation and strengthened individuals' rights over their own data, including access, correction and portability. For an outsourced operation those rights have to be operable through the provider. If a Quebec resident exercises a right, the client needs the provider to be able to locate, produce, correct or delete the relevant record within the required timeframe. A support or processing operation designed without those workflows cannot support a compliant response.
Cross-border transfers require an assessment
Law 25 requires an organisation to conduct a privacy assessment before communicating personal information outside Quebec, weighing the sensitivity of the data, the purpose, the protections in place and the legal regime of the destination. For a buyer this makes the physical location of delivery a documented decision. Where the work happens, what leaves the province, what is merely accessed in session versus stored, and under which country's law it sits are questions the assessment has to answer.
This is the change that most favours Canadian and near-Canadian delivery. Keeping Quebec residents' data under Canadian governance, processed by staff under Canadian law, shortens and simplifies the transfer assessment rather than complicating it.
What buyers should now require of a provider
Law 25 turns several things that used to be optional into baseline requirements for any provider handling Quebec residents' data:
- A named person accountable for privacy within the provider's account team
- A documented incident-response protocol with a notification window fast enough to meet the client's reporting obligation
- The ability to action individual rights requests, including access, correction and portability, within the statutory timeframe
- Clarity on where data physically resides and what crosses a border, to support the client's transfer assessment
- A control environment the client can actually inspect, not merely an assurance that controls exist
None of this is exotic. It is the standard a competent provider handling Canadian data should already meet, and a provider that treats these as unusual is telling a buyer where it sits.
The penalties raised the stakes
Law 25 did not only add obligations, it added teeth. The regime introduced administrative monetary penalties and a higher ceiling for penal sanctions, along with a private right of action for damages, and it gave Quebec's Commission d'acces a l'information a stronger supervisory role. The exact figures are set out in the statute and are best confirmed with counsel, but the direction is unambiguous: the cost of getting this wrong went up.
For a buyer, that changes the internal conversation. Data protection in an outsourcing arrangement is no longer a matter a procurement team can wave through on the provider's assurance. It is a board-level exposure, because a serious failure by a provider can now produce a penalty and a claim that land on the accountable organisation. That is precisely why the diligence in this article stopped being optional the day the law came into force, and why a provider that makes the diligence easy is worth more than one that makes it cheap.
Where Corpshore Canada fits
Corpshore Canada delivers from Canadian operations under Toronto governance, in compliance with PIPEDA and Quebec's Law 25, bilingually in English and Canadian French. For a buyer with Quebec exposure, that combination, Canadian delivery, Canadian legal footing and an accountable Toronto structure, is designed to keep the privacy assessment simple and the accountability chain short. Law 25 did not make outsourcing harder. It made the choice of provider a decision a risk committee now has to defend on the record, and it rewarded providers who were already built to be inspected.
