If your consent setup was built for the American market, it almost certainly assumes an opt-out model: trackers fire, and visitors can ask you to stop. Quebec's Law 25 inverts that completely. There, tracking must be off by default, and you need the visitor's explicit, informed agreement before a single non-essential cookie or pixel runs. It's the GDPR's logic, applied in North America — and it catches a lot of sites off guard.
Key takeaways
- Law 25 is the only North American law requiring opt-in consent for cookies and tracking.
- It is fully in force — phased in 2022–2024, with the last provisions effective September 2024.
- Privacy by default: tracking technologies must be off until the user actively turns them on.
- Penalties reach CA$25 million or 4% of global revenue, whichever is higher.
What Law 25 is
Law 25 — originally Bill 64 — is Quebec's comprehensive modernization of its private-sector privacy law. It was phased in over three years, with major obligations landing in 2022 and 2023 and the final provisions (including the right to data portability) taking effect in September 2024. It is now fully operative. In substance and rigor it closely tracks the EU's GDPR: express consent, privacy by design and by default, breach notification, mandatory privacy officers, and privacy impact assessments.
Who it applies to
Law 25 applies to any organization that collects, holds, uses, or communicates the personal information of Quebec residents — regardless of where the organization is located. Like the GDPR, its reach is defined by whose data you process, not by your own address. A business outside Quebec — including a US company — that has Quebec visitors and tracks them is within scope. For most websites with any Canadian traffic, that's a realistic possibility rather than an edge case.
The opt-in difference
This is the heart of why Law 25 demands special attention. Under the law's privacy-by-default principle, products and services must be configured for the highest level of privacy by default — which means tracking, locating, and profiling functions must be turned off until the user actively switches them on.
In practical terms:
- You must obtain express, informed consent before deploying non-essential cookies, marketing pixels, or behavioral-analysis tools.
- Consent must be granular — users choose by purpose, not all-or-nothing.
- Declining must be as easy as accepting.
- Users must be able to withdraw consent at any time.
- Strictly necessary cookies are exempt, but only if they don't identify, locate, or profile the individual.
A cookie banner that loads trackers first and asks later — the norm on many US-built sites — is fundamentally incompatible with this. The trackers firing before the click is exactly what Law 25 prohibits.
What websites must do
- Block non-essential tracking until consent — tracking off by default, GDPR-style.
- Present a clear, granular consent interface with equally easy accept/decline and per-purpose choices.
- Publish a plain-language privacy policy served as soon as a visitor arrives, with a link in the consent notice.
- Inform users about tracking, locating, and profiling tools before collection.
- Allow withdrawal of consent and exercise of rights (access, correction) at any time.
How ConsentPixel helps
Law 25's central requirement is also exactly what ConsentPixel is built to do: block trackers until the visitor explicitly consents. Tracking is off by default; cookies, pixels, and profiling tools are held back until the user actively agrees; consent is granular and as easy to refuse as to accept; and it can be withdrawn at any time. Every decision is logged, and Google Consent Mode v2 is supported so Google tags honor the consent state for Quebec visitors.
Because ConsentPixel's whole model is prevention-first — gating trackers rather than cosmetically displaying a banner — it aligns naturally with Law 25's privacy-by-default standard, which is the part US-built consent tools most often fail. It sits alongside ConsentPixel's GDPR support, since the two regimes share the same opt-in logic.
Frequently asked questions
Law 25 (formerly Bill 64) is Quebec's modernized privacy law, phased in between 2022 and 2024 with its final provisions — including data portability — effective September 2024. It substantially overhauls Quebec's privacy regime, bringing it close to the EU's GDPR in rigor, and is widely regarded as the strictest privacy law in Canada.
Yes — and this is what sets it apart. Law 25 is the only North American privacy law that requires explicit, informed opt-in consent before deploying tracking technologies such as cookies, pixels, and profiling tools. Its privacy-by-default principle means tracking features must be off by default until the user actively consents, much like the GDPR and unlike the opt-out model used across the US.
Any organization that collects personal information from Quebec residents — regardless of where the organization is based. A US company with Quebec website visitors can be in scope. It applies based on whose data you process, not where your business sits.
Penalties are severe: administrative monetary penalties and fines can reach up to CA$25 million or 4% of worldwide turnover, whichever is higher. Quebec's privacy regulator (the Commission d'accès à l'information) enforces the law, and individuals can also seek damages.
Yes. Law 25's core technical requirement — explicit opt-in before any non-essential tracking, with tracking off by default — is exactly what ConsentPixel's consent engine does: it blocks cookies, pixels, and profiling tools until the visitor actively consents, supports granular and easily-withdrawn consent, and logs each decision. That maps directly to Law 25's privacy-by-default and express-consent requirements.
See where your site stands
ConsentPixel blocks trackers until consent, monitors every page, and logs every decision — from a single pixel. Find out where your site stands in about 10 seconds.
Scan your site free