What Law 25 Is
Law 25 modernized Quebec's private-sector privacy law in three phases between 2022 and 2024, bringing it close to Europe's GDPR in strictness. It applies to any organization that collects or handles the personal information of people in Quebec — including small businesses based elsewhere in Canada that serve Quebec customers.
Unlike some privacy laws, Law 25 carries real teeth. Administrative monetary penalties can reach up to $10 million or 2% of worldwide turnover, and penal fines can reach up to $25 million or 4% of worldwide turnover for serious violations. Those ceilings exist to deter large enterprises, but the obligations apply to everyone.
The Core Obligations
Several requirements matter most for a typical small business. You must designate a person responsible for the protection of personal information (by default, the most senior person in the business) and publish their contact details. You must obtain clear, specific consent — bundled "agree to everything" consent is not enough. You must give individuals the right to access, correct, and in some cases port or delete their data.
Law 25 also requires "privacy by default": when you offer a product or service with privacy settings, the most privacy-protective settings must be on automatically. And you must conduct a privacy impact assessment before transferring personal information outside Quebec or implementing systems that handle it at scale.
Pro tip: Quebec's default-consent rule is why well-built Canadian tools ask Quebec users for explicit analytics consent rather than assuming it. If your cookie banner treats Quebec the same as everywhere else, that is a red flag.
Consent Is Stricter Here
Under Law 25, consent must be clear, free, and informed, and given for specific purposes. For sensitive information, it must be express. You cannot hide consent in a wall of terms, and you cannot treat continued use of your service as automatic agreement to non-essential data processing.
In practice, this changes how customer-facing technology behaves for Quebec residents. Analytics cookies, marketing tracking, and profiling all require a genuine opt-in. Tools that detect a Quebec locale and ask for explicit consent — rather than defaulting it on — are doing exactly what the law intends.
Data Transfers and Residency
Law 25 requires a privacy impact assessment before personal information is communicated outside Quebec, weighing the sensitivity of the data, the purpose, and the protections in the destination jurisdiction. This makes where your data physically lives a compliance question, not just an IT preference.
Keeping Quebec residents' data within Canadian data centres simplifies this analysis considerably. It is one of the reasons data residency has become a deciding factor for Quebec businesses choosing POS, payment, and analytics vendors.
Handling POS and Customer Data Under Law 25
Your POS system is a Law 25 surface: it holds transaction records, customer profiles, and often payment metadata for Quebec residents. The analytics layer on top of it inherits the same obligations. The safest approach is to minimize what identifiable data you process, keep it in Canada, apply explicit consent for anything beyond running your business, and work with vendors who understand Quebec's regime specifically.
Meridian was built to support Law 25 — described on its Canadian portal as aligned with the strictest provincial privacy legislation in Canada. It applies Quebec-specific explicit (opt-in) consent handling, is transparent about where data is stored (its infrastructure runs on major cloud providers in US regions, with appropriate cross-border data-transfer safeguards), and treats privacy-by-default as a design principle rather than a checkbox. As one of the earliest POS-analytics platforms to adapt for Canada, it was built around these requirements rather than patched to meet them later.
Pro tip: This is general information, not legal advice. Law 25 obligations vary by how you handle data — consult a Quebec privacy professional for your specific situation.