WhatsApp Us

Quebec privacy · cookies, forms and analytics

Law 25 website compliance: cookies, forms and analytics set up the Quebec way

Law 25 website compliance is about what your site does before a visitor clicks anything: which trackers fire, what your forms ask, and whether people can see who handles their data. BtechWaleTech is three freelance developers in India who rebuild that layer for Quebec businesses: tracking off by default, a consent platform with stored choices, a readable privacy page naming your privacy officer, and forms that collect only what they need. Consent fixes on an existing site start at US$150; stores at US$750.

  • Law enforced byCommission d'accès à l'information du Québec
  • Also known asLaw 25, formerly Bill 64
  • Default for trackingOff until the visitor switches it on
  • Consent fixes fromUS$150, often within 1–2 weeks
  • Store consent rebuild fromUS$750
  • Legal sign-offYour own lawyer, not us
  • Trackers off until opt-in
  • Consent platform configured
  • Consent records kept
  • Privacy officer contact published
  • Forms trimmed to purpose
  • Vendor PIA information pack
  • Your accounts, your data

Three freelance developers in India · WhatsApp replies 7 days a week · calls in Eastern mornings

  • 3Freelance developers who build the consent layer
  • 2Working days to an itemised quote
  • 2Months of free maintenance after launch
  • 7Days a week we answer on WhatsApp

The short answer

What does Law 25 website compliance require from a Quebec business website?

Law 25 website compliance means tracking technologies that can identify, locate or profile visitors stay off until people turn them on, your privacy policy is published in clear language, your privacy officer's title and contact details appear on the site, and forms collect only what a stated purpose needs. BtechWaleTech builds this from US$150.

Quebec also expects your site to be in French; the build side of that is on Bill 96 website requirements. For the federal privacy rules that apply outside Quebec, see PIPEDA compliant website.

Last updated

Law 25 on a website, at a glance
Cookies and pixelsNon-essential tags blocked until the visitor opts in
Consent proofEach choice stored with date, banner version and categories
Privacy pagePlain-language policy in French and English
Privacy officerTitle and contact details published on the site
FormsPurpose stated, optional fields marked, no pre-ticked boxes
Data leaving QuebecAssessed by you before hosting or vendor access
PriceConsent fixes from US$150; stores from US$750

What the build covers

Law 25 website compliance work we do, and what stays with you

We handle the technical layer that makes a site behave in line with Quebec's privacy rules. Policies, assessments and legal judgement stay with you and your counsel.

Why choose us

Three ways Quebec businesses handle Law 25 on their websites

The cheapest option often leaves the core problem in place: trackers that load before anyone agrees to them.

Three ways Quebec businesses handle Law 25 on their websites
Question Free cookie plugin, default settings Paid consent platform, self-installed Configured build by BtechWaleTech
Do trackers wait for opt-in? Often not; many only show a notice Only if every tag is mapped correctly Yes, tested tag by tag
Are choices recorded? Rarely, or only in the browser Usually, if the feature is enabled Yes, with date and banner version
French banner and settings Machine-translated or missing Available, but text needs review Your approved French and English text
Forms reviewed for minimisation No No Yes, field by field
Privacy officer contact on site No No Added to footer and privacy page
Hard-coded scripts in the theme Missed Often missed Found and moved behind consent
Upfront cost None Platform subscription From US$150, plus any platform subscription you choose
Who checks it after changes Nobody Whoever remembers Included in care plans

We are developers, not lawyers: we make the site behave as your policy says it does, and your own counsel decides what Law 25 requires of your business and signs off on the wording.

Pricing

What Law 25 website compliance work costs

A consent and forms clean-up on an existing site usually fits within our starting plan at US$150, covering the tracker audit, consent platform configuration, tag wiring, form review and privacy officer block. A store adds checkout pixels, customer accounts and marketing emails, and store work starts at US$750. If the site needs rebuilding anyway, the consent layer is included in the new build. Consent platform subscriptions, if you choose a paid one, are billed to you by that provider. Legal drafting and privacy impact assessments are separate and come from your lawyer or privacy adviser. Quotes are in USD, itemised, and nothing is billed before written approval.

Starting prices in INR and USD
ServiceIndia (INR)Worldwide (USD)Typical timelineWhat is included
Static website from ₹10,000 from US$150 1 to 2 weeks Up to 100 pages, Responsive design, Contact form and enquiry setup, Basic SEO tags and sitemap
SEO website (299+ pages) from ₹20,000 from US$300 3 to 5 weeks 299+ SEO pages, Keyword and page planning, Schema, sitemap, and internal linking, Design to deployment included
Ecommerce store from ₹50,000 from US$750 4 to 8 weeks Product and category pages, Payment gateway setup, Order and inventory basics, Performance tuning
Android & iOS app from ₹40,000 from US$600 6 to 10 weeks Android and iOS app (Flutter or React Native), Login, forms and push notifications, Admin panel and API connection, Google Play and App Store publishing
Custom web app or software from ₹60,000 from US$900 6 to 12 weeks Custom features and APIs, User accounts and roles, Admin panel, Deployment and handover
AI automation from ₹40,000 from US$600 2 to 4 weeks Workflow mapping, Tool and CRM integrations, AI agent or automation build, Testing and handover
Monthly SEO from ₹10,000/mo from US$150/mo Ongoing, monthly Technical fixes, On-page and content work, Local SEO and listings, Search Console reporting
Maintenance and support from ₹8,000/mo from US$120/mo Ongoing, monthly Content updates, Bug fixes, Backups and security checks, Speed and uptime checks

All prices are starting points, quoted in INR for India and USD for international clients, not fixed quotes. Final cost depends on the number of pages, features, integrations, content, and timelines. Share your requirement and you get an itemised estimate with nothing hidden. See full pricing.

What is Law 25, and why does it matter for a website?

Law 25 is the Quebec statute that modernised the province's private-sector privacy law, introduced as Bill 64 and phased in between 2022 and 2024. For a website, it matters because a site is where most businesses collect personal information by technological means, often without noticing: every analytics cookie, chat widget and contact form counts.

The Commission d'accès à l'information du Québec (CAI), which oversees the law, lists the changes on its summary of the main Law 25 changes. The phases ran from September 2022 through September 2023 to 22 September 2024, when the data portability right took effect. By now every obligation is in force.

Law 25 website compliance therefore is not a single banner. It is a set of behaviours: trackers that respect a visitor's choice, forms that ask for no more than they need, a published policy people can read, a named person responsible, and a record showing what visitors agreed to. The rest of this guide takes each piece in turn from the builder's side.

Does Law 25 apply to my website if I am outside Quebec?

If your business is in Quebec, yes: Law 25 website compliance is part of running your site. If you are elsewhere in Canada and collect personal information from people in Quebec, the answer depends on your facts, and it is a question for your lawyer rather than your developer.

What we see in practice is that many Ontario, Maritime and Western businesses selling to Quebec customers choose to meet the Quebec standard across the whole site. It is simpler to run one consent setup than to detect provinces, and the Quebec approach of keeping tracking off by default is at the stricter end of Canadian practice.

Outside Quebec, the federal law usually governing commercial websites is PIPEDA. We explain the build side of that on our PIPEDA compliant website page. A single consent layer can often be configured to satisfy the stricter of the two for each visitor, once your counsel confirms the approach.

  • Quebec-based business: Law 25 website compliance applies to your site
  • Selling into Quebec from another province: ask your lawyer; many choose to comply anyway
  • No Quebec customers at all: federal or other provincial law is the likelier frame

Law 25 cookie consent: why tracking has to start switched off

Law 25 says that when you use technology with functions that can identify, locate or profile a person, you must tell them in advance and give them a way to activate those functions; the CAI states that such technologies cannot be switched on by default. On a website, that points squarely at advertising pixels, cross-site tracking and many analytics setups.

Which cookies fall into that category is a legal judgement. The cautious and common approach is to treat analytics, advertising, session recording, heatmaps and most third-party embeds as opt-in, and to let only strictly necessary cookies (cart, login, security, load balancing, the consent cookie itself) run without a choice.

The build question is whether the site actually behaves that way. A banner that appears while tags fire underneath is decoration, not consent. We test with a fresh browser profile and the network panel open: before a choice, no requests to analytics or ad domains; after "accept analytics", only analytics; after "reject all", nothing new. That test is the core of our Law 25 website compliance work.

Is an accept-only banner acceptable?

A banner with only an "OK" button does not give a real choice. We build banners where accepting and refusing are equally easy, with a settings panel for individual categories.

What about embedded videos and maps?

Embeds from video and map providers can set their own cookies. We replace them with a click-to-load placeholder until the visitor consents to that category.

How do you set up a consent management platform for Law 25 website compliance?

Pick a consent management platform that supports opt-in by default, French and English text, category-level choices, a way to reopen settings, and a stored record of each choice. Then connect every tag to it; the platform does nothing for tags it does not know about.

Our setup order is always the same. First, the inventory: every cookie and script found in the audit, grouped into categories with a one-line purpose. Second, the platform configuration: categories, banner text, default state set to denied for everything non-essential, and the settings link placed in the footer. Third, the wiring: tags in Google Tag Manager set to fire only on the matching consent state, and hard-coded scripts in the theme moved behind the same gate. Fourth, the test pass in a clean browser.

We work with the platform you already pay for if it can do the job, or recommend options suited to your site's platform (WordPress, Shopify, a custom build). We never lock you into a tool on our own account; the subscription, if any, is in your name.

Can I still use Google Analytics under Law 25?

Yes. Law 25 website compliance and Google Analytics can coexist, provided it runs only after the visitor agrees, or your lawyer is satisfied your configuration falls outside the identification and profiling functions the law targets. Most Quebec businesses we talk to simply make Analytics an opt-in category.

Google's consent mode lets tags adjust their behaviour to the visitor's choice, and we wire it so the default state is denied for analytics and advertising storage. When a visitor accepts, the tags update; when they refuse, Analytics and Ads receive nothing that relies on cookies.

Expect your reported traffic to drop once tracking waits for consent. That is not a fault in the build; it is the share of visitors who decline. We suggest adding server-side counts that do not identify anyone (such as form submissions and orders from your own database) so you still have reliable conversion numbers. Our technical SEO service can then work from Search Console data, which does not depend on on-site cookies at all.

What does Law 25 mean for contact forms, quote forms and signups?

For Law 25 website compliance, forms should collect only what the stated purpose needs, say what that purpose is at the point of collection, and never bundle separate consents into one checkbox. The CAI describes valid consent as manifest, free, enlightened and given for specific purposes.

In practice we go through every form on the site and ask of each field: what happens if we remove it? A quote form for a renovation job needs a name, a way to reply and the job details; it rarely needs a date of birth or a home address at the first step. Optional fields are labelled as optional, and the purpose appears in one sentence above the button.

Newsletter signups get their own unticked checkbox, separate from the enquiry itself, because agreeing to be contacted about a quote is not agreeing to marketing email. Canada's anti-spam law points the same way for commercial messages. Submitted data goes to a place you control, with access limited to the staff who need it.

  • One purpose sentence above each submit button
  • Optional fields labelled, required fields justified
  • No pre-ticked boxes; marketing consent separate
  • Link to the privacy policy beside the form
  • Submissions stored in your account, not a random form service

What goes on a Law 25 privacy policy page?

The CAI says businesses that collect personal information by technological means must publish a privacy policy written in clear and simple terms, on their website or by other appropriate means. Your lawyer drafts or approves the words; our Law 25 website compliance job is to give them a page people can actually read and find.

We build the policy as a proper web page, not a PDF, in French and English, with headings for what you collect, why, who it is shared with, how long you keep it, where it is stored, how to reach the privacy officer and how to withdraw consent or request access. A table of contents at the top helps, because most visitors arrive looking for one answer.

The policy is linked from the footer of every page, from each form, and from the consent banner's settings panel. When your lawyer updates it, the page shows a "last updated" date so visitors and the CAI can see it is maintained. If your site is bilingual, the French and English versions are kept in step; our bilingual website build handles that structure.

Do I need to publish my privacy officer's contact details on my website?

Yes. The CAI's guidance on the person in charge of the protection of personal information says the title and contact information of that person must be published on the business's website, or made available by other appropriate means if there is no website.

By default the person with the highest authority in the business holds the role, and they can delegate it in writing, in whole or in part. The website does not need their personal phone number; a title such as "Privacy Officer" and a dedicated email address are what we usually add.

We place the officer block in two spots: the privacy policy page and the site footer. We set up a role-based email address (for example, a privacy@ alias on your domain) so the contact survives staff changes. That small detail is one of the most commonly missing Law 25 website compliance items when we audit Quebec sites, and it takes minutes to fix once you have chosen who holds the role.

Privacy impact assessments before data leaves Quebec, including to a remote developer

Before personal information is communicated outside Quebec, the CAI says a business must assess the privacy impact and be satisfied the information will be adequately protected. That covers foreign hosting, cloud tools and outside service providers, which includes a remote development team like us if we can see your customers' data.

So we say it plainly, because Law 25 website compliance applies to your suppliers too: if you hire BtechWaleTech for work that exposes personal information, that is data leaving Quebec, and your assessment should cover it. We make it easier with a written information pack describing what we would access, from where, on which systems, for how long, and how access ends.

We also design the work to need as little access as possible. Most Law 25 website compliance work can be done on a staging copy with personal data removed or replaced by dummy records. Where we do need production access, it is through named accounts you create and can revoke, never shared passwords. Hosting can stay in a Canadian data region if your assessment calls for it. Your privacy adviser decides whether the protections are adequate; we supply the facts.

  • What data the developer could see (and what is masked)
  • Where the data is hosted and in which country
  • Who on our team has access, through which accounts
  • How and when access is removed at the end of the job
  • What happens if we notice a security problem

For Law 25 website compliance, record enough to show what a visitor agreed to, when and on which version of the banner, without storing more personal information than the log needs. A consent log that holds full IP addresses and browsing history defeats its own purpose.

Most consent platforms keep a record per choice: a random consent ID, timestamp, categories accepted or refused, banner or policy version, and sometimes a truncated IP address. We check that the feature is switched on, that records are retained for the period your lawyer sets, and that you can export them if the CAI or a customer asks.

For custom builds we can store consent records in your own database instead, with the same fields. Form consents (such as a newsletter opt-in) are logged beside the submission itself: the checkbox text shown, the time, and the page. When the banner or policy wording changes, we bump the version number so older consents can be told apart, and your team decides whether to ask visitors again.

What if there is a data breach on the website?

Law 25 calls it a confidentiality incident, and the CAI says businesses must keep a register of such incidents and communicate it to the Commission when required. Serious incidents trigger notification duties that your lawyer will walk you through.

In Law 25 website compliance terms, the website's part is to make incidents less likely and easier to understand. We keep plugins and themes updated, limit admin accounts to named people with two-factor login, store form submissions encrypted where the platform allows, and turn on logging so you can later tell what was accessed and when.

If we spot something suspicious while working on your site, such as an unknown admin account or injected script, we tell you straight away with what we saw. We do not decide whether it is a reportable incident; that is for you and your adviser. During the two free months after launch, security patches are included; after that, care plans start at US$120/mo.

How much does Law 25 website compliance cost?

With us, Law 25 website compliance work on an existing site starts at US$150. Stores start at US$750 because checkout, accounts and marketing pixels add work. A paid consent platform, if you choose one, has its own subscription, and legal drafting is separate.

What moves the number: how many third-party tags and embeds the site loads, how many are hard-coded in the theme rather than in a tag manager, the number of forms, whether the site is bilingual, and whether you want consent logs in your own database. A ten-page brochure site with one analytics tag is quick; a store with ad pixels, reviews, chat, loyalty and email tools is not.

Other developers and consultants quote this work very differently, often because some include legal drafting or assessments and others only install a plugin. Ask exactly what is included. Our quote lists each item separately, arrives in about two working days, and is in USD.

What are the penalties for getting Law 25 wrong?

The CAI can impose administrative monetary penalties on businesses of up to 10 million dollars or 2% of worldwide turnover, according to its summary of the Law 25 changes. Your lawyer can explain how the CAI applies them and what other consequences exist.

Most small businesses doing Law 25 website compliance work will never be near those figures, but the size of the maximums tells you how seriously the province takes it. The more practical risk is a complaint from a customer who notices a pixel firing after they clicked "reject", or an enquiry from a larger client whose procurement team checks your site before signing.

A tidy consent layer, a readable policy and a visible privacy contact answer most of those questions before they are asked. None of this is legal advice, and we never describe a site as "certified" compliant; we build what your counsel decides is needed.

Working with our team in India on Quebec privacy fixes

Our hours overlap with Eastern mornings, so a 9 am call in Montreal lands in our evening. Messages on WhatsApp get answers seven days a week, and we work in English; French banner and policy text comes from you or your translator, and we place it exactly.

Because Law 25 website compliance work touches your data, we start differently from a normal build. Before any access, you get the vendor information pack described above so your assessment can include us. Then we ask for a staging copy or read-only access to your tag manager, not the keys to everything.

Quotes are in USD, invoices are issued from India, and payment is by Wise, bank wire or PayPal. Nothing is billed before you approve the written quote. You keep ownership of the site, the consent platform account and all records.

First week

Tracker audit on the live site, form inventory, a written list of what fires before consent, and a proposed category map for your lawyer to review.

Second week

Consent platform configured on staging, tags rewired, forms trimmed, privacy officer block added, then the clean-browser test and go-live once you approve.

Worked example: a hypothetical online boutique in Sherbrooke

Say a small clothing boutique in Sherbrooke sells online through WooCommerce. Its site loads an analytics tag, an advertising pixel, a chat widget, an embedded video on the home page and a review widget, all before the visitor does anything. The footer has a two-year-old privacy policy PDF in English only, and the newsletter checkbox on checkout is pre-ticked.

A reasonable plan: audit and categorise every tag; configure a consent platform with French and English text from the owner; move the pixel, analytics and chat behind opt-in; replace the video with click-to-load; untick and separate the newsletter box; publish the lawyer-approved policy as a bilingual page; add the owner's title and a privacy@ address as the privacy contact; switch on consent records. Store work of this size falls under our ecommerce plan from US$750; if only the consent layer were needed on a simpler site, it would start at US$150.

This Law 25 website compliance example is hypothetical, not a client story. The point is the order: inventory first, then configuration, then testing. Our WooCommerce developer page covers the store side in more depth.

Law 25 website compliance checklist

Use this list to check your own site, or send it to your developer. Each line is something you can verify in a browser in a few minutes.

  • With a fresh browser, no analytics or ad requests fire before a choice
  • Accept and refuse are equally easy on the banner
  • Visitors can reopen consent settings from every page
  • Consent records are switched on and exportable
  • Privacy policy is a readable web page in French and English, dated
  • Privacy officer title and contact appear on the site
  • Every form states its purpose and marks optional fields
  • Marketing consent is a separate, unticked box
  • Embedded video, maps and chat wait for consent
  • Your assessment covers foreign hosting and remote vendors

If you run a Montreal business and want the whole site reviewed rather than just privacy, our page for web development in Montreal covers broader work.

Site element by site element

Law 25 website compliance by site element

This maps common website parts to the related Law 25 point and what the build does. It is a planning aid, not legal advice. Source for the obligations: the CAI's Law 25 summary.

Law 25 website compliance by site element
Site elementRelated Law 25 pointWhat we buildWho decides
Analytics and ad tags Identification or profiling technology off by defaultTags gated behind opt-in categoriesYour lawyer sets categories
Cookie banner Consent that is manifest, free, informed and specificEqual accept/refuse, settings panelYou approve the text
Contact and quote forms Collect only what the purpose needsTrimmed fields, purpose lineYou confirm needed fields
Privacy policy page Clear, simple policy when collecting by technological meansReadable bilingual web pageYour lawyer writes it
Footer contact block Privacy officer title and contact publishedFooter and policy block, role emailYou name the officer
Hosting and vendors Assessment before data leaves QuebecVendor pack, minimal access, region optionsYou and your adviser
Security and logs Incident register and responseUpdates, 2FA, access logsYou report if needed

Tool comparison

We work with whatever platform your site runs on. Features vary by vendor and plan, so we check them against your needs before recommending one.

Consent setup options by site platform
PlatformTypical consent approachTag gatingWatch out for
WordPress Consent plugin or external platform scriptVia Tag Manager or plugin blockingTheme and plugin scripts that bypass the gate
WooCommerce Same as WordPress, plus checkout reviewTag Manager plus pixel plugin settingsMarketing plugins adding pixels on checkout
Shopify Shopify's privacy settings or an appApp-level and theme-levelApps that inject their own scripts
Custom build External platform or our own lightweight bannerDirect gating in codeConsent state not passed to server-side tools
Site builder (Wix, Squarespace) Built-in banner, limited optionsPartialHard to block some built-in trackers
Mobile app In-app consent screenSDK initialised only after consentAnalytics SDKs that start on launch

Remote vendor

What goes in our vendor information pack for your assessment

You receive this before we get any access. It supports your privacy impact assessment; it does not replace it.

What goes in our vendor information pack for your assessment
TopicWhat we describeTypical answer for consent work
Data in scope Which personal information we could seeUsually none: staging copy with dummy data
Location Where the team works and where data sitsTeam in India; data stays on your hosting
Access method How we log inNamed accounts you create and can revoke
Duration How long access lastsThe project window, then removed
Security Devices, passwords, two-factor login2FA on every account we use
End of work What we keep afterwardsNo copies of personal data kept

Where we help

Law 25 website work for businesses across Quebec and beyond

We work remotely for Quebec businesses and for companies elsewhere in Canada that serve Quebec customers.

  • Montreal

    Retailers, clinics, SaaS firms and professional services in Montreal run many third-party tools, so a full tag inventory is usually the first step towards opt-in consent.

  • Quebec City

    Tourism operators, insurers and public-facing businesses in the capital often collect bookings and quotes online, which puts form minimisation and a clear privacy contact at the top of the list.

  • Laval

    Suburban retailers and service companies in Laval commonly advertise with pixels, so gating advertising tags behind consent is where most of the work sits.

  • Gatineau

    Businesses in Gatineau serve customers on both sides of the Ottawa River and often want one consent setup that works for Quebec and Ontario visitors.

  • Longueuil and the South Shore

    Contractors, clinics and family businesses on the South Shore usually need a straightforward banner, trimmed quote forms and a published privacy officer contact.

  • Sherbrooke

    Online shops and education-related businesses in the Eastern Townships often run WooCommerce or Shopify, where checkout pixels and newsletter boxes need attention.

  • Trois-Rivières

    Manufacturers and service firms in Mauricie collecting RFQs and job applications online need forms that ask only what each purpose requires.

  • Saguenay

    Regional retailers and industrial suppliers in Saguenay often have older sites with hard-coded tracking scripts that must be moved behind consent.

  • Lévis

    Financial services and insurance-related businesses near Lévis handle sensitive enquiries, so careful form design and access control matter most here.

  • Terrebonne and Laurentides

    Growing service businesses north of Montreal frequently add chat, booking and review widgets, each of which needs a consent category.

  • Drummondville

    Manufacturers and distributors in the Centre-du-Québec region with dealer or supplier portals need consent and access rules on logged-in areas too.

  • Ottawa

    Ottawa firms with Quebec clients often choose to meet the Quebec standard sitewide, alongside federal privacy expectations, rather than run two consent setups.

  • Toronto

    Toronto online retailers shipping to Quebec customers frequently ask whether Law 25 applies to them; we build the consent layer once their lawyer answers.

  • Moncton

    Bilingual businesses in New Brunswick serving francophone customers in Quebec often want French consent text and a single privacy setup across regions.

How it works

How a Law 25 website compliance project runs

  1. Send the vendor pack first

    Before any access, you receive our written description of data exposure, access method and duration, so your assessment can cover the engagement.

  2. Audit what fires today

    We load the live site in a clean browser, record every cookie, pixel and script, and list the forms and fields they collect.

  3. Agree the category map

    You and your lawyer confirm which tools are essential and which need opt-in; we turn that into consent categories and banner text slots.

  4. Configure on staging

    Consent platform set up, tags rewired through Tag Manager, hard-coded scripts gated, forms trimmed and privacy officer details added.

  5. Test with a fresh browser

    Every consent path tested (accept all, reject all, partial) with network requests checked, and consent records confirmed as stored.

  6. Launch and hand back

    Changes go live, access we used is removed, and you receive a short note of what was changed and how to check new tags later.

Questions

Law 25 website compliance: frequent questions

What is Law 25 website compliance?

Law 25 website compliance is making a website behave in line with Quebec's modernised private-sector privacy law. On a site, that usually means tracking technologies stay off until visitors opt in, forms collect only what their purpose needs, a clear privacy policy is published, the privacy officer's title and contact details appear, and consent choices are recorded. Your lawyer confirms what applies to your business.

Does Law 25 website compliance require a cookie banner?

The law does not mention banners by name, but it requires that technologies able to identify, locate or profile people be off by default, with a way for people to switch them on. For most websites a consent banner with real accept and refuse options is the practical way to do that. The banner only works if tags are actually blocked until a choice is made.

Is Law 25 opt-in or opt-out for cookies?

For tracking that can identify, locate or profile a visitor, the CAI says such technologies cannot be activated by default, which in practice means opt-in. Strictly necessary cookies such as cart, login and security cookies can run without a choice. Which tools fall into which group is a legal call; many Quebec businesses treat analytics and advertising as opt-in to be safe.

How much does Law 25 website compliance cost?

With BtechWaleTech, consent and form fixes on an existing site start at US$150, and stores start at US$750 because checkout and marketing tools add work. A paid consent platform subscription, if you use one, is billed by that provider, and legal drafting is separate. You get an itemised quote in USD within about two working days.

How long does it take to make a website Law 25 compliant?

The technical work on a typical business site takes one to two weeks: a few days for the audit and category map, then configuration, testing and launch. Stores with many marketing tools take longer. The step that most often adds time is waiting for legal review of the categories and privacy policy text, so we start the audit while your lawyer drafts.

Can I use Google Analytics and still follow Law 25?

Yes, if Analytics runs only after the visitor opts in, or your lawyer is satisfied your setup does not involve the identification or profiling functions the law targets. We wire Google's consent mode so analytics and advertising storage default to denied and update after a choice. Expect lower reported traffic because some visitors decline; your own order and form counts fill that gap.

Do I need a privacy officer listed on my website?

Yes. The CAI says the title and contact details of the person in charge of protecting personal information must be published on the business's website. By default that is the person with the highest authority, who can delegate the role in writing. We add a footer and policy block with a role title and a dedicated email address so it survives staff changes.

What should a Law 25 privacy policy include?

Your lawyer decides the content, but policies typically explain what you collect, why, who it is shared with, where it is stored, how long you keep it, how to contact the privacy officer, and how to access, correct or withdraw consent. The CAI expects it written in clear and simple terms. We publish it as a readable, dated web page in French and English.

Does Law 25 apply to businesses outside Quebec?

It clearly applies to businesses in Quebec. Whether it reaches a business elsewhere in Canada that collects information from Quebec residents depends on the facts and is a legal question for your counsel. Many businesses selling into Quebec choose to meet the Quebec standard across the whole site because it is simpler than running different consent rules for each province.

Do I need a privacy impact assessment to hire a developer in India?

If the developer will see personal information, the CAI says you must assess the privacy impact before that information is communicated outside Quebec. We make that easier: you receive a written pack describing what we could access and how, and we design the job to use staging copies with dummy data wherever possible. Your adviser decides whether protections are adequate.

What is a consent log and do I need one?

A consent log records each visitor's choice: a random ID, timestamp, categories accepted or refused, and the banner version shown. It lets you show what someone agreed to if they or the CAI ask. Most consent platforms offer it, but it is often switched off. We turn it on, set retention to what your lawyer advises, and check you can export records.

What are the fines under Law 25?

According to the CAI, administrative monetary penalties for businesses can reach 10 million dollars or 2% of worldwide turnover. Your lawyer can explain the other enforcement routes. For most small businesses the practical risk is a customer complaint or a client's procurement check rather than a maximum penalty, but the ceiling shows how seriously Quebec treats privacy.

Is a free cookie plugin enough for Law 25 website compliance?

Sometimes, if it can block scripts until consent, offer equal accept and refuse options, show French text and keep records. Many free plugins only display a notice while tracking keeps running underneath. The test is simple: open your site in a fresh browser, watch the network requests, and check nothing from analytics or ad domains loads before you choose.

Does Law 25 affect my Shopify or WooCommerce store?

Yes, stores usually carry more tracking than brochure sites: advertising pixels, review and loyalty apps, chat and abandoned-cart emails. Each one needs a consent category, and newsletter boxes at checkout must be separate and unticked. We review checkout, customer accounts and marketing apps as part of store work, which starts at our ecommerce plan price.

Can a remote developer handle Law 25 website compliance correctly?

The technical work is the same wherever the developer sits: auditing tags, configuring consent, gating scripts, trimming forms and testing. What differs is that using a vendor outside Quebec is itself a data communication you should assess if personal information is exposed. We keep access minimal and documented, and your lawyer supplies the French legal wording and sign-off.

What happens to my analytics numbers after Law 25 consent is added?

Reported sessions usually fall because visitors who refuse tracking are no longer counted. Your real traffic has not changed. We suggest tracking key outcomes such as form submissions and orders from your own systems, which do not need cookies, and using Google Search Console for search performance, which is measured on Google's side.

Does Law 25 cover chat widgets and embedded videos?

Anything that sets cookies or sends visitor data to a third party needs a look. Chat widgets, video embeds, maps and social feeds often set tracking cookies as soon as the page loads. We replace embeds with click-to-load placeholders and load chat only after consent for its category, unless your lawyer decides a particular tool is strictly necessary.

Who owns the consent platform account and records?

You do. Any consent platform subscription is set up in your business's name, and consent records sit in that account or your own database. We work through named access you grant and remove it when the job ends. If you change developers later, nothing needs to be transferred from us.

Do you write the privacy policy?

No. The policy is a legal document and should come from your lawyer or privacy adviser. We give them a list of what the site actually collects and which tools receive data, which makes drafting faster and more accurate, and then we publish their text as a clean, bilingual web page linked from the footer, forms and banner.

How do you keep a site compliant after new tools are added?

New marketing tools are the most common way sites drift out of line. During the two free months after launch we check any tag you add; after that, care plans from US$120/mo include reviewing new scripts before they go live and re-running the clean-browser test. You can also use the checklist on this page yourself.

How do payments and approvals work?

You receive an itemised quote in USD, and no work or billing starts until you approve it in writing. Payment is by Wise, bank wire or PayPal, with invoices issued from India. Payment stages are set out in your quote, and our terms and refund policy pages describe the general conditions.

Next step

Send us your site URL for a tracker check

Share your website on WhatsApp and we will list what fires before consent, then send an itemised USD quote for the fixes within about two working days.