Resources

Law 25 Fines and Penalties: What Your Organization Actually Risks

Elite Consultation·2026-08-03
Law 25penaltiesfinesCAI

The numbers get quoted constantly: 25 million dollars, 4% of worldwide turnover. They are accurate, but they describe only part of Law 25's sanctions regime, and not the part that will touch most SMEs. This guide presents the full picture: the three sanction mechanisms, how they actually work, the factors the CAI weighs, and what the first years of enforcement teach us.

The Three Sanction Mechanisms

Law 25 created a three-tier regime, each tier with its own rules.

1. Administrative Monetary Penalties (AMPs)

This is the mechanism most likely to touch an SME. The CAI can directly impose, without going through a court, an administrative monetary penalty for failures such as:

  • Failing to inform individuals at the time of collection
  • Collecting, using, or communicating information contrary to the law
  • Failing to report a confidentiality incident to the CAI or to affected individuals
  • Failing to apply the required security measures
  • Breaching the rules on automated decisions

Maximum amounts: $50,000 for an individual, and for an organization, $10 million or 2% of worldwide turnover for the preceding fiscal year, whichever is higher.

The process provides for a prior notice of non-compliance in most cases: the CAI flags the failure and the organization can correct the situation. AMPs target persistent or serious failures, not good-faith errors corrected quickly.

2. Penal Sanctions

For the most serious offences, the CAI can bring penal proceedings. Offences include:

  • Illegally collecting, using, or communicating personal information
  • Failing to report an incident when required
  • Obstructing the CAI's work during an investigation or inspection
  • Retaliating against a whistleblower

Maximum amounts: for an organization, $25 million or 4% of worldwide turnover, whichever is higher. The amounts double for repeat offences.

3. The Private Right of Action and Punitive Damages

The third tier is often forgotten: injured individuals can sue the organization directly. Law 25 provides that when an unlawful infringement of a right under the Act causes injury, punitive damages of at least $1,000 can be awarded where the infringement is intentional or results from gross fault.

This mechanism fuels class actions. A breach affecting 10,000 customers multiplies the $1,000 floor by the size of the class. For many organizations, class action exposure exceeds CAI sanction exposure.

What the CAI Weighs Before Sanctioning

To set the amount of an AMP, the CAI considers factors listed in the Act:

  • The nature, seriousness, repetitiveness, and duration of the failure
  • The sensitivity of the information concerned
  • The number of people affected and the risk of injury
  • The measures the organization took to remedy the failure
  • The organization's ability to pay
  • The benefits the organization drew from the failure

Two practical implications stand out. First, documentation of your efforts matters: an organization that can show a structured program (active privacy officer, maintained registers, published policies, training delivered) sits in a fundamentally different position from one with nothing. Second, the reaction after the failure weighs heavily: correcting quickly, notifying diligently, and cooperating with the CAI reduce exposure.

What the First Years of Enforcement Show

Since the sanction powers came into force in September 2023, the enforcement rhythm has built gradually. The general patterns:

  • The CAI has prioritized guidance and notices of non-compliance before heavy sanctions, particularly for SMEs
  • Inspections are mostly triggered by citizen complaints and publicized incidents
  • Organizations with no designated privacy officer and no published policy are the most exposed, because these failures can be verified in minutes from the website
  • Class actions tied to confidentiality incidents keep advancing through Quebec courts, independently of CAI action

The lesson: the realistic scenario for an SME is not the $25 million fine. It is the complaint from a customer or former employee, the inspection that follows, the discovery of a non-existent compliance program, and the escalation that ensues, with legal costs, leadership time, and reputational damage all adding up.

The Easiest Failures to Verify (and to Fix)

Some failures are publicly visible and form the CAI's basic checks:

  1. Is the privacy officer designated, with contact information published on the website? Verifiable in 30 seconds.
  2. Does a privacy policy exist, and does it reflect Law 25? Verifiable in 5 minutes.
  3. Are cookies and consent handled correctly? Verifiable from any browser.
  4. Do your forms collect more than necessary? Verifiable on every public form.

Fixing these four points does not make you compliant on its own, but it removes the outward signals of neglect that attract attention.

Comparison With Neighboring Regimes

| Regime | Max. administrative penalty | Max. penal sanction | |---|---|---| | Law 25 (Quebec) | $10M or 2% | $25M or 4% | | PIPEDA (federal Canada) | None | $100,000 | | GDPR (Europe) | €20M or 4% | Varies by member state | | California (CCPA/CPRA) | US $7,500 per intentional violation | n/a |

Quebec built the most severe regime in Canada, modeled on the European approach. That was a deliberate choice by the legislator to give the law teeth.

Reducing Your Exposure: The Priorities

In order of impact:

  1. Designate the privacy officer and publish their contact information. The most visible failure and the simplest to fix.
  2. Keep the incident register and notify diligently. Failure to notify is explicitly sanctionable, and it is the most expensive failure during a real incident.
  3. Document your program. Every register maintained, every PIA completed, every training session delivered becomes evidence in your diligence file.
  4. Secure sensitive information. Reasonable security measures are a direct obligation, and their absence aggravates every incident.
  5. Prepare your incident response. The difference between notifying in 3 days and notifying in 3 weeks can determine how the file ends.

How Observantia Reduces This Risk

Observantia structures precisely the documentation the CAI examines: up-to-date registers, archived PIAs, incidents documented with their notification timeline, and reports that demonstrate the overall program. During an inspection, the diligence file is produced in minutes. Start your 14-day free trial.

Related articles


This content is provided for informational purposes only and does not constitute legal advice. For questions specific to your situation, consult a qualified legal professional.

Ready to simplify your compliance?

Try Observantia free for 14 days.