What is Law 25, and why does it matter for a website?
Law 25 is the Quebec statute that modernised the province's private-sector privacy law, introduced as Bill 64 and phased in between 2022 and 2024. For a website, it matters because a site is where most businesses collect personal information by technological means, often without noticing: every analytics cookie, chat widget and contact form counts.
The Commission d'accès à l'information du Québec (CAI), which oversees the law, lists the changes on its summary of the main Law 25 changes. The phases ran from September 2022 through September 2023 to 22 September 2024, when the data portability right took effect. By now every obligation is in force.
Law 25 website compliance therefore is not a single banner. It is a set of behaviours: trackers that respect a visitor's choice, forms that ask for no more than they need, a published policy people can read, a named person responsible, and a record showing what visitors agreed to. The rest of this guide takes each piece in turn from the builder's side.
Does Law 25 apply to my website if I am outside Quebec?
If your business is in Quebec, yes: Law 25 website compliance is part of running your site. If you are elsewhere in Canada and collect personal information from people in Quebec, the answer depends on your facts, and it is a question for your lawyer rather than your developer.
What we see in practice is that many Ontario, Maritime and Western businesses selling to Quebec customers choose to meet the Quebec standard across the whole site. It is simpler to run one consent setup than to detect provinces, and the Quebec approach of keeping tracking off by default is at the stricter end of Canadian practice.
Outside Quebec, the federal law usually governing commercial websites is PIPEDA. We explain the build side of that on our PIPEDA compliant website page. A single consent layer can often be configured to satisfy the stricter of the two for each visitor, once your counsel confirms the approach.
- Quebec-based business: Law 25 website compliance applies to your site
- Selling into Quebec from another province: ask your lawyer; many choose to comply anyway
- No Quebec customers at all: federal or other provincial law is the likelier frame
Law 25 cookie consent: why tracking has to start switched off
Law 25 says that when you use technology with functions that can identify, locate or profile a person, you must tell them in advance and give them a way to activate those functions; the CAI states that such technologies cannot be switched on by default. On a website, that points squarely at advertising pixels, cross-site tracking and many analytics setups.
Which cookies fall into that category is a legal judgement. The cautious and common approach is to treat analytics, advertising, session recording, heatmaps and most third-party embeds as opt-in, and to let only strictly necessary cookies (cart, login, security, load balancing, the consent cookie itself) run without a choice.
The build question is whether the site actually behaves that way. A banner that appears while tags fire underneath is decoration, not consent. We test with a fresh browser profile and the network panel open: before a choice, no requests to analytics or ad domains; after "accept analytics", only analytics; after "reject all", nothing new. That test is the core of our Law 25 website compliance work.
Is an accept-only banner acceptable?
A banner with only an "OK" button does not give a real choice. We build banners where accepting and refusing are equally easy, with a settings panel for individual categories.
What about embedded videos and maps?
Embeds from video and map providers can set their own cookies. We replace them with a click-to-load placeholder until the visitor consents to that category.
How do you set up a consent management platform for Law 25 website compliance?
Pick a consent management platform that supports opt-in by default, French and English text, category-level choices, a way to reopen settings, and a stored record of each choice. Then connect every tag to it; the platform does nothing for tags it does not know about.
Our setup order is always the same. First, the inventory: every cookie and script found in the audit, grouped into categories with a one-line purpose. Second, the platform configuration: categories, banner text, default state set to denied for everything non-essential, and the settings link placed in the footer. Third, the wiring: tags in Google Tag Manager set to fire only on the matching consent state, and hard-coded scripts in the theme moved behind the same gate. Fourth, the test pass in a clean browser.
We work with the platform you already pay for if it can do the job, or recommend options suited to your site's platform (WordPress, Shopify, a custom build). We never lock you into a tool on our own account; the subscription, if any, is in your name.
Can I still use Google Analytics under Law 25?
Yes. Law 25 website compliance and Google Analytics can coexist, provided it runs only after the visitor agrees, or your lawyer is satisfied your configuration falls outside the identification and profiling functions the law targets. Most Quebec businesses we talk to simply make Analytics an opt-in category.
Google's consent mode lets tags adjust their behaviour to the visitor's choice, and we wire it so the default state is denied for analytics and advertising storage. When a visitor accepts, the tags update; when they refuse, Analytics and Ads receive nothing that relies on cookies.
Expect your reported traffic to drop once tracking waits for consent. That is not a fault in the build; it is the share of visitors who decline. We suggest adding server-side counts that do not identify anyone (such as form submissions and orders from your own database) so you still have reliable conversion numbers. Our technical SEO service can then work from Search Console data, which does not depend on on-site cookies at all.
For Law 25 website compliance, forms should collect only what the stated purpose needs, say what that purpose is at the point of collection, and never bundle separate consents into one checkbox. The CAI describes valid consent as manifest, free, enlightened and given for specific purposes.
In practice we go through every form on the site and ask of each field: what happens if we remove it? A quote form for a renovation job needs a name, a way to reply and the job details; it rarely needs a date of birth or a home address at the first step. Optional fields are labelled as optional, and the purpose appears in one sentence above the button.
Newsletter signups get their own unticked checkbox, separate from the enquiry itself, because agreeing to be contacted about a quote is not agreeing to marketing email. Canada's anti-spam law points the same way for commercial messages. Submitted data goes to a place you control, with access limited to the staff who need it.
- One purpose sentence above each submit button
- Optional fields labelled, required fields justified
- No pre-ticked boxes; marketing consent separate
- Link to the privacy policy beside the form
- Submissions stored in your account, not a random form service
What goes on a Law 25 privacy policy page?
The CAI says businesses that collect personal information by technological means must publish a privacy policy written in clear and simple terms, on their website or by other appropriate means. Your lawyer drafts or approves the words; our Law 25 website compliance job is to give them a page people can actually read and find.
We build the policy as a proper web page, not a PDF, in French and English, with headings for what you collect, why, who it is shared with, how long you keep it, where it is stored, how to reach the privacy officer and how to withdraw consent or request access. A table of contents at the top helps, because most visitors arrive looking for one answer.
The policy is linked from the footer of every page, from each form, and from the consent banner's settings panel. When your lawyer updates it, the page shows a "last updated" date so visitors and the CAI can see it is maintained. If your site is bilingual, the French and English versions are kept in step; our bilingual website build handles that structure.
Do I need to publish my privacy officer's contact details on my website?
Yes. The CAI's guidance on the person in charge of the protection of personal information says the title and contact information of that person must be published on the business's website, or made available by other appropriate means if there is no website.
By default the person with the highest authority in the business holds the role, and they can delegate it in writing, in whole or in part. The website does not need their personal phone number; a title such as "Privacy Officer" and a dedicated email address are what we usually add.
We place the officer block in two spots: the privacy policy page and the site footer. We set up a role-based email address (for example, a privacy@ alias on your domain) so the contact survives staff changes. That small detail is one of the most commonly missing Law 25 website compliance items when we audit Quebec sites, and it takes minutes to fix once you have chosen who holds the role.
Privacy impact assessments before data leaves Quebec, including to a remote developer
Before personal information is communicated outside Quebec, the CAI says a business must assess the privacy impact and be satisfied the information will be adequately protected. That covers foreign hosting, cloud tools and outside service providers, which includes a remote development team like us if we can see your customers' data.
So we say it plainly, because Law 25 website compliance applies to your suppliers too: if you hire BtechWaleTech for work that exposes personal information, that is data leaving Quebec, and your assessment should cover it. We make it easier with a written information pack describing what we would access, from where, on which systems, for how long, and how access ends.
We also design the work to need as little access as possible. Most Law 25 website compliance work can be done on a staging copy with personal data removed or replaced by dummy records. Where we do need production access, it is through named accounts you create and can revoke, never shared passwords. Hosting can stay in a Canadian data region if your assessment calls for it. Your privacy adviser decides whether the protections are adequate; we supply the facts.
- What data the developer could see (and what is masked)
- Where the data is hosted and in which country
- Who on our team has access, through which accounts
- How and when access is removed at the end of the job
- What happens if we notice a security problem
Law 25 consent logs: what to record and where to keep it
For Law 25 website compliance, record enough to show what a visitor agreed to, when and on which version of the banner, without storing more personal information than the log needs. A consent log that holds full IP addresses and browsing history defeats its own purpose.
Most consent platforms keep a record per choice: a random consent ID, timestamp, categories accepted or refused, banner or policy version, and sometimes a truncated IP address. We check that the feature is switched on, that records are retained for the period your lawyer sets, and that you can export them if the CAI or a customer asks.
For custom builds we can store consent records in your own database instead, with the same fields. Form consents (such as a newsletter opt-in) are logged beside the submission itself: the checkbox text shown, the time, and the page. When the banner or policy wording changes, we bump the version number so older consents can be told apart, and your team decides whether to ask visitors again.
What if there is a data breach on the website?
Law 25 calls it a confidentiality incident, and the CAI says businesses must keep a register of such incidents and communicate it to the Commission when required. Serious incidents trigger notification duties that your lawyer will walk you through.
In Law 25 website compliance terms, the website's part is to make incidents less likely and easier to understand. We keep plugins and themes updated, limit admin accounts to named people with two-factor login, store form submissions encrypted where the platform allows, and turn on logging so you can later tell what was accessed and when.
If we spot something suspicious while working on your site, such as an unknown admin account or injected script, we tell you straight away with what we saw. We do not decide whether it is a reportable incident; that is for you and your adviser. During the two free months after launch, security patches are included; after that, care plans start at US$120/mo.
How much does Law 25 website compliance cost?
With us, Law 25 website compliance work on an existing site starts at US$150. Stores start at US$750 because checkout, accounts and marketing pixels add work. A paid consent platform, if you choose one, has its own subscription, and legal drafting is separate.
What moves the number: how many third-party tags and embeds the site loads, how many are hard-coded in the theme rather than in a tag manager, the number of forms, whether the site is bilingual, and whether you want consent logs in your own database. A ten-page brochure site with one analytics tag is quick; a store with ad pixels, reviews, chat, loyalty and email tools is not.
Other developers and consultants quote this work very differently, often because some include legal drafting or assessments and others only install a plugin. Ask exactly what is included. Our quote lists each item separately, arrives in about two working days, and is in USD.
What are the penalties for getting Law 25 wrong?
The CAI can impose administrative monetary penalties on businesses of up to 10 million dollars or 2% of worldwide turnover, according to its summary of the Law 25 changes. Your lawyer can explain how the CAI applies them and what other consequences exist.
Most small businesses doing Law 25 website compliance work will never be near those figures, but the size of the maximums tells you how seriously the province takes it. The more practical risk is a complaint from a customer who notices a pixel firing after they clicked "reject", or an enquiry from a larger client whose procurement team checks your site before signing.
A tidy consent layer, a readable policy and a visible privacy contact answer most of those questions before they are asked. None of this is legal advice, and we never describe a site as "certified" compliant; we build what your counsel decides is needed.
Working with our team in India on Quebec privacy fixes
Our hours overlap with Eastern mornings, so a 9 am call in Montreal lands in our evening. Messages on WhatsApp get answers seven days a week, and we work in English; French banner and policy text comes from you or your translator, and we place it exactly.
Because Law 25 website compliance work touches your data, we start differently from a normal build. Before any access, you get the vendor information pack described above so your assessment can include us. Then we ask for a staging copy or read-only access to your tag manager, not the keys to everything.
Quotes are in USD, invoices are issued from India, and payment is by Wise, bank wire or PayPal. Nothing is billed before you approve the written quote. You keep ownership of the site, the consent platform account and all records.
First week
Tracker audit on the live site, form inventory, a written list of what fires before consent, and a proposed category map for your lawyer to review.
Second week
Consent platform configured on staging, tags rewired, forms trimmed, privacy officer block added, then the clean-browser test and go-live once you approve.
Worked example: a hypothetical online boutique in Sherbrooke
Say a small clothing boutique in Sherbrooke sells online through WooCommerce. Its site loads an analytics tag, an advertising pixel, a chat widget, an embedded video on the home page and a review widget, all before the visitor does anything. The footer has a two-year-old privacy policy PDF in English only, and the newsletter checkbox on checkout is pre-ticked.
A reasonable plan: audit and categorise every tag; configure a consent platform with French and English text from the owner; move the pixel, analytics and chat behind opt-in; replace the video with click-to-load; untick and separate the newsletter box; publish the lawyer-approved policy as a bilingual page; add the owner's title and a privacy@ address as the privacy contact; switch on consent records. Store work of this size falls under our ecommerce plan from US$750; if only the consent layer were needed on a simpler site, it would start at US$150.
This Law 25 website compliance example is hypothetical, not a client story. The point is the order: inventory first, then configuration, then testing. Our WooCommerce developer page covers the store side in more depth.
Law 25 website compliance checklist
Use this list to check your own site, or send it to your developer. Each line is something you can verify in a browser in a few minutes.
- With a fresh browser, no analytics or ad requests fire before a choice
- Accept and refuse are equally easy on the banner
- Visitors can reopen consent settings from every page
- Consent records are switched on and exportable
- Privacy policy is a readable web page in French and English, dated
- Privacy officer title and contact appear on the site
- Every form states its purpose and marks optional fields
- Marketing consent is a separate, unticked box
- Embedded video, maps and chat wait for consent
- Your assessment covers foreign hosting and remote vendors
If you run a Montreal business and want the whole site reviewed rather than just privacy, our page for web development in Montreal covers broader work.