SuperQuanti
Contact us
Quebec market

Law 25 and digital marketing: what do you actually need to do?

Benoit Arlabosse, Principal Strategist and FounderUpdated 9 min read

Quebec’s Law 25, the province’s modernized private-sector privacy law, imposes four obligations that directly affect digital marketing: appoint a privacy officer and publish their contact information, publish a clear privacy policy, obtain manifest, free and informed consent for non-essential purposes (including advertising and analytics cookies), and run a privacy impact assessment (PIA) before certain system projects or before sending personal information outside Quebec. What the law does not do is ban targeted advertising, analytics tools or remarketing: it regulates how you use them. Many marketing teams burn energy on imaginary requirements while the real obligations sit unaddressed. This article sorts one from the other.

In this article
  1. Law 25 arrived in three waves, and all of them are in force
  2. Four obligations touch your marketing directly
  3. Valid cookie consent rests on specific conditions
  4. The PIA applies in defined cases, not to every campaign
  5. Three common over-interpretations cost you data and time
  6. A marketing compliance plan fits in five workstreams
  7. Sources and references

Since September 2023, most provisions of Law 25 apply to every business that handles personal information in Quebec. Every one. The twelve-person firm and the multinational alike. If you sell into Quebec from elsewhere in Canada, it applies to you too. Yet three years on, confusion still reigns: some marketing teams have no working consent banner, while others have blocked half their site out of caution, convinced that a single measurement tag invites fines. Both postures are expensive. The first creates real legal exposure; the second destroys measurement data with no legal benefit in return. Here is how to separate obligation from overkill.

Infographic – Law 25 and digital marketing: three waves in force (September 2022, 2023, 2024) and four obligations for marketing teams: privacy officer, clear privacy policy, manifest consent, targeted PIA. Law 25 regulates measurement and targeting, it does not ban them.

To apply this approach to campaigns, our marketing measurement and data governance service connects marketing decisions with the engagement’s goals and available data.

Law 25 arrived in three waves, and all of them are in force

Law 25 (formally, an act to modernize legislative provisions respecting the protection of personal information) rewrote Quebec’s private-sector privacy statute. It rolled out in three phases. September 2022: mandatory reporting of confidentiality incidents presenting a serious risk of injury to the Commission d’accès à l’information (CAI), Quebec’s privacy regulator, and to affected individuals. September 2023: the core regime, meaning consent, transparency, the privacy policy, default settings and the PIA. September 2024: the right to data portability.

In other words, the grace period is over. According to the CAI, administrative monetary penalties can reach 10 million dollars or 2 percent of worldwide turnover. Those ceilings target serious breaches, not a good-faith SMB that documents its efforts, but they signal the legislator’s intent clearly enough. Compliance is no longer a project. It is an operating state.

Four obligations touch your marketing directly

First: the privacy officer. By default, the law assigns the role to the person with the highest authority in the company, who may delegate it in writing. The officer’s title and contact information must be published on your website. It is simple, fast, and surprisingly often missing from Quebec sites. Of the last Quebec B2B sites we ran through a diagnostic, close to one in two displayed no privacy officer at all, or pointed to a generic inbox with no name or title.

Second: transparency. If you collect personal information through technology, you must publish a privacy policy written in clear and simple terms, and tell people the purposes of collection, how to withdraw consent, and their rights of access and correction. A generic policy copied from a competitor does not describe your actual processing. It protects no one, least of all you.

Third: consent. It must be manifest, free, informed and given for specific purposes, in the CAI’s own words. For marketing, that covers advertising and analytics cookies, profiling and personalization. Section 8.1 of the act requires you to inform people when a technology can identify them, locate them or profile them, and to tell them how those functions can be activated: in the CAI’s reading, profiling is something a person switches on, not something done to them by default.

Fourth: the PIA. It is required for any project to acquire, develop or overhaul an information system involving personal information, and before communicating personal information outside Quebec. Four workstreams. Not forty.

In practice, following the CAI’s consent guidelines, a marketing site needs a consent management platform (CMP) that blocks non-essential cookies until the user chooses, presents refusal as easily as acceptance, and documents the choices. Pre-ticked boxes are not manifest consent. Neither is a banner that says “by continuing to browse, you accept.”

One nuance is widely missed: the requirement that privacy settings default to the highest level of confidentiality (section 9.1) contains an explicit carve-out for browser cookies. That does not remove the consent requirement for tracking cookies, but it shows the legislator distinguished necessary technical mechanisms from advertising profiling. Strictly necessary cookies (cart, session, security, language preference) do not require consent. Blocking them out of excess caution degrades the user experience with zero legal upside.

The table below sums up the split.

Cookie or processing type Consent required? What to do
Essential cookies (session, cart, security, language) No Document them in the privacy policy
Analytics cookies (GA4, heatmaps) Yes CMP blocks them until consent, then activates
Advertising and remarketing cookies Yes Prior blocking, with distinct and specific consent
Precise geolocation, profiling Yes, with distinct notice Clear notice (section 8.1) and user-activated functions

Once the CMP is live, wire it properly into your tags: our guide to Google Consent Mode and how to implement it covers the mechanics. Consent is not a banner. It is plumbing.

The PIA applies in defined cases, not to every campaign

The privacy impact assessment scares people, usually for the wrong reasons. The law prescribes it in specific situations: a project to acquire, develop or redesign an information system or electronic service delivery involving personal information, and any communication of personal information outside Quebec. For a marketing team, that covers structural decisions: adopting a new CRM, migrating to a US email platform, deploying a CDP, plugging in a data enrichment tool.

It does not cover the day-to-day. Launching a campaign on a channel you have already assessed, publishing a landing page, A/B testing an existing form: none of that triggers a PIA. The assessment must be proportionate to the sensitivity of the information and the purpose of the project; for a common marketing tool, it can be a few structured pages. The useful reflex is to build the PIA into your MarTech procurement process, with the privacy officer consulted from the start. Once per tool. Not once per newsletter. At a professional-services client, the first PIA for a US-hosted newsletter tool ran four pages and one meeting with the privacy officer; subsequent tools reused the same template in under half a day each.

Three common over-interpretations cost you data and time

First over-interpretation: “Law 25 bans Google Analytics and targeted advertising.” False. It requires valid consent and transparency about those uses. The distinction matters enormously: regulation is not prohibition, and a company equipped with a proper CMP and an accurate policy can keep measuring, targeting and remarketing in full compliance, at volumes reduced by refusals, which is exactly how the regime is meant to work. The broader story of third-party cookies and their decline matters at least as much as the law for your signal loss.

Second over-interpretation: “we need a PIA for every campaign and written consent for everything.” No. The PIA targets system projects and cross-border transfers. Consent must be manifest and specific, which does not mean a signature.

Third over-interpretation: “block everything, including essential cookies, just in case.” That zeal breaks purchase journeys, distorts measurement and adds no legal protection whatsoever. Misplaced caution has a real cost. Legal risk is managed through documentation and governance, not amputation. A real example: an industrial distributor had configured its CMP to block the session cookie until consent. Visitors who declined lost their cart on every page change, and quote requests had dropped by roughly a third in two months. No legal requirement justified the block; restoring it took an hour.

A marketing compliance plan fits in five workstreams

Here is the sequence we recommend to Quebec marketing teams, in order. One, appoint and publish the privacy officer. Two, inventory your marketing processing: tags, cookies, forms, platforms, data flows, destinations outside Quebec. Three, deploy a compliant CMP and connect it technically to your tags, with documented tests. Four, rewrite the privacy policy so it describes the reality of that inventory, in plain language, in French and English. Five, embed the PIA into tool procurement and document the assessments you have already done.

The plan has a happy side effect: the inventory of tags and data flows is the exact same exercise as a measurement audit. Solid UTM governance and solid compliance rest on the same foundation: knowing what is collected, by what, and why. Compliance done well improves data quality. Not enough people say so.

FAQ

Does Law 25 require a cookie banner?

The law never uses the word “banner,” but it requires manifest, free, informed and specific consent for non-essential purposes, which in practice makes a consent mechanism indispensable before analytics and advertising cookies fire. A properly configured CMP is the standard way to get there. Strictly necessary cookies are exempt.

Who should be the privacy officer?

By default, the person with the highest authority in the company, typically the president or CEO. The function can be delegated in writing to anyone, including an external provider. The officer’s title and contact information must be published on the company website.

Do we need a PIA to use a US cloud tool?

Yes, insofar as personal information is communicated outside Quebec: the law requires an assessment that considers, among other things, the sensitivity of the information and the legal regime of the receiving jurisdiction. The assessment is proportionate to the project and can stay short for a common marketing tool. It is done once per tool or data flow, not per campaign.

What are the penalties for non-compliance?

According to the Commission d’accès à l’information, administrative monetary penalties can reach 10 million dollars or 2 percent of worldwide turnover. The regulator also favours corrective measures and undertakings. Documented good faith, with an inventory, a CMP and a current policy, remains your best protection.

Sources and references

This article offers a marketing-oriented reading of Law 25 for general information purposes; it is not legal advice. For your specific situation, consult legal counsel specialized in privacy law.

Want to know whether your marketing stack is compliant without gutting your measurement? Our senior team reviews your CMP, tags and data flows in a single diagnostic: tell us about your situation.