Compliance (Law 25)
A Law 25 compliant website: what you actually have to put in place (2026 checklist)
For a website to comply with Quebec's Law 25, it needs four things: a cookie consent banner (free, informed and active consent before any non-essential cookie is set), a clear and accessible privacy policy, a publicly identified person responsible for the protection of personal information, and settings set to the highest level of privacy by default. Every provision of Law 25 has been in force since September 2024 — compliance is no longer optional.
Updated July 1, 2026
Law 25 (formerly Bill 64) applies to every Quebec business that collects personal information, whatever its size. A simple contact form, a newsletter, an advertising pixel or a CRM is enough to bring you within scope. Here is the concrete checklist for your site.
1. The cookie consent banner (section 8)
This is the most visible obligation. Since September 2023, any site accessible in Quebec must obtain express, free and informed consent before setting non-essential cookies — analytics, advertising, social media, remarketing.
In practice, that means:
- No non-essential cookie is set before the click. A purely decorative banner that loads Google Analytics or the Meta pixel on page load is not compliant.
- Refusing must be as easy as accepting. No prominent "Accept" button with "Refuse" buried three submenus deep.
- Consent must be granular: the visitor can distinguish the categories (necessary, statistics, marketing).
- Consent is documented, and the visitor can withdraw it as easily as it was given.
Cookies strictly necessary for the site to work (cart, session, security) do not require prior consent, but must still be described in your policy.
2. The privacy policy
As soon as you collect information by technological means, you must publish a privacy policy written in clear, simple terms. It must explain:
- What data is collected and why (specific purposes);
- How it is protected and how long it is kept;
- Whether any data is transferred outside Quebec;
- How to exercise rights: access, correction, withdrawal of consent, and the new right to de-indexing (right to be forgotten).
The policy must be easy to find — typically a permanent link in the footer.
3. The person responsible for protecting personal information
Every business must designate a person responsible for the protection of personal information. By default this is the person with the highest authority (often the president or CEO), but the role can be delegated in writing. The key point for your site: that person's title and contact details must be made public, ideally in the privacy policy.
4. Privacy by default and privacy impact assessments
Two more technical obligations, often forgotten:
- Privacy by default: the settings of a technological product or service offered to the public must, without any action from the individual, provide the highest level of privacy. Concretely: no pre-checked boxes, no sharing enabled by default.
- Privacy impact assessment (PIA): an assessment is required for any project involving the acquisition, development or redesign of an information system touching personal information, and before any transfer of data outside Quebec. The moment to think about it is while you rebuild your site, not three years later.
What does compliance cost?
The cost depends mostly on what data you handle. Quebec market benchmarks for 2026:
- Compliance audit + basic privacy policy: roughly $100 to $750 (indicative range — to be confirmed for your project).
- Implementing a consent management platform (CMP) with proper cookie categorisation: often $500 to $2,500 in setup, plus a monthly subscription in some cases (indicative range — to be confirmed for your project).
- Full support (PIA, register, internal procedures, training) for an SMB handling sensitive data: $3,000 to $10,000 and up (indicative range — to be confirmed for your project).
Put that against the penalties: administrative penalties from the Commission d'accès à l'information (CAI) can reach $10M or 2 % of worldwide turnover, and penal sanctions up to $25M or 4 % — whichever is higher. In 2026, the CAI has reinforced its inspection resources and the first penalties are starting to land.
Express checklist
- Consent banner that blocks non-essential cookies before the click
- "Refuse" button as accessible as "Accept"
- Clear privacy policy, with purposes and retention periods
- Contact details of the privacy officer published
- Maximum privacy by default (no pre-checked boxes)
- PIA completed before any redesign or transfer of data outside Quebec
- A response procedure in case of a confidentiality incident
We'll make your site compliant
At Bollé Communications, we build Law 25 compliance directly into our website design projects: a functional consent banner, real blocking of non-essential cookies, a privacy policy that matches your actual practices, and settings configured correctly by default. Want to know where your site stands? Let's talk — and have a look at our own privacy policy to see what a compliant example looks like.
This article is provided for information purposes and does not constitute legal advice. For a formal assessment of your compliance, consult a legal professional.
Frequently asked questions
Is my small business really covered by Law 25?
Yes. Law 25 applies to any business that collects personal information, with no size threshold. A contact form or a newsletter is enough.
Is Google Analytics allowed under Law 25?
Yes, but only after valid consent. The script must not load until the visitor has accepted statistics cookies.
Is a privacy policy template found online good enough?
It is a starting point, but it has to reflect your real practices (data actually collected, tools used, transfers outside Quebec). A generic policy that does not match reality offers you no protection.
Who can be the person responsible for protecting personal information?
By default, the person with the highest authority in the business. They can delegate the role in writing, but the title and contact details must remain public.
What are the real risks of non-compliance?
Administrative penalties (up to $10M or 2 % of turnover) or penal sanctions (up to $25M or 4 %), on top of the reputational risk. Directors can be targeted personally under the penal provisions.
Related services
Got a project in mind?
Let's talk it through — a first conversation, no strings attached.
Get in touch