Cross-Border Data Transfers After Quebec Law 25
If personal information leaves Quebec — and with US cloud tools it almost always does — Law 25 expects you to assess the transfer first. Here's what that actually asks of you.
Before you send personal information outside Quebec, Law 25 expects a privacy impact assessment — weighing the sensitivity of the data, the purposes, the contractual and technical safeguards, and the destination's legal framework — plus a written agreement covering the transfer. It doesn't ban transfers or keep a list of approved countries; it asks for diligence and documentation before the data leaves.
Almost every Quebec business moves personal information out of the province, usually without giving it a second's thought. Your email runs on servers in the United States. Your CRM, your accounting software, your support tool, your AI assistant — a lot of them are hosted by companies whose infrastructure sits well past Quebec's borders. Law 25 asks you to notice that, and to do something about it before the data goes.
What Law 25 actually expects
Under Law 25, before you communicate personal information outside Quebec, you're expected to run a privacy impact assessment — in French, an évaluation des facteurs relatifs à la vie privée, or ÉFVP. It has to weigh, among other things, the sensitivity of the information, the purposes it'll be used for, the protection measures — contractual ones included — that would apply, and the legal framework of the place it's headed, including whether that framework offers protection comparable to Quebec's.
The transfer can go ahead if the assessment shows the information would get adequate protection, particularly in light of generally recognized privacy principles. And it has to be covered by a written agreement that takes the assessment's findings into account — the analysis and the contract are built to work as a pair.
Notice what this isn't. Law 25 keeps no government list of "approved" countries the way some regimes do. It doesn't forbid transfers to the United States or anywhere else. It asks you to look before you leap, write down what you found, and put contractual protection in place. The duty is one of diligence and documentation, not prohibition.
What "adequate protection" means in practice
This is the part that makes people nervous, because it sounds like you'd need to become an expert in the privacy law of every country your vendors touch. In practice it's more manageable than that.
The test isn't whether the destination's law is identical to Quebec's — few laws anywhere are — but whether the information will, in fact, get protection comparable to what Quebec principles require, contractual and technical measures included. That last part carries a lot of weight: a solid data processing agreement, encryption, access controls, and a reputable vendor with recognized certifications can do most of the lifting. You're judging the whole picture — the legal framework plus the safeguards you and the vendor wrap around the data — not the destination's statute standing alone.
What does the privacy impact assessment cover?
At its core, the assessment weighs a handful of factors together:
- Sensitivity of the personal information being transferred
- Purposes for which it will be used at the destination
- Protection measures, including contractual and technical safeguards
- Legal framework of the destination and whether it offers comparable protection
- The written agreement that must reflect the assessment's findings
How do you work through the assessment in practice?
Start with an inventory of your transfers. You can't assess what you haven't mapped. A data discovery pass across the tools and vendors that hold or process personal information — noting where the data physically lives and what kind it is — tends to surface transfers most businesses never realized they were making.
Triage by sensitivity. A transfer of health information, financial details, or biometric data earns a much closer look than a transfer of business contact details. Put your effort where the potential harm is greatest. Law 25 treats sensitive information with particular seriousness, and your assessment should too.
Look at the safeguards, not just the geography. For each meaningful transfer, examine the vendor's security posture, its certifications (SOC 2, ISO 27001, and increasingly ISO 42001 for AI tools), encryption, access controls, and its commitments around onward transfers to sub-processors. A living vendor inventory keeps that detail in one place instead of scattered across a dozen contracts. These are the measures that pull the protection up to a comparable standard.
Get the written agreement right. The contract should mirror what your assessment concluded: purpose limitation, security obligations, breach notification, limits on further transfers, and deletion or return of the information at the end. A vendor used to selling into Quebec will often already have terms built for exactly this.
Document and date the assessment. It isn't only a decision — it's a record. If the Commission d'accès à l'information ever asks why you were comfortable sending personal information to a given provider, your dated assessment is the answer. Revisit it when the vendor changes its infrastructure, adds sub-processors, or when you start sending more sensitive data.
Where AI tools raise the stakes
AI tools deserve a closer look here. When staff paste customer information into a chat window, that data may be processed on servers outside Quebec, routed through several jurisdictions, and — depending on the vendor's terms — potentially kept or used to improve models. That's a cross-border transfer, and often an undocumented one. Before you roll out an AI tool that touches personal information, treat it like any other transfer: assess it, confirm the vendor's data-use and residency terms, and paper it.
The reasonable posture
Law 25's transfer rule isn't a wall — it's a discipline. Most of the transfers Quebec businesses make are perfectly defensible once assessed; what draws regulatory attention isn't the transfer itself but the total absence of thought behind it. A business that can produce a dated assessment and a matching agreement for its meaningful transfers stands in a fundamentally different place from one that just hoped the question would never come up.
Do the inventory, focus on the sensitive flows, weigh safeguards alongside geography, and keep the paperwork. That's really the whole of it.
*This article is general information, not legal advice; consult a qualified professional about your specific situation.*
At Canuckt we build privacy-first tools for Canadian businesses, and Valdra turns the transfer assessment above into a guided, repeatable workflow — pairing data discovery with a documented vendor inventory, your records hosted in Canada — so a regulator's question already has an answer waiting.
Frequently asked questions
Does Law 25 require a privacy impact assessment before transferring data outside Quebec?+
Yes. Before you communicate personal information outside Quebec, Law 25 expects a privacy impact assessment. It weighs the sensitivity of the data, the purposes, the protection measures including contractual ones, and whether the destination offers protection comparable to Quebec's.
Does Law 25 ban transferring data to the United States?+
No. Law 25 doesn't ban transfers to the US or anywhere else, and it keeps no list of approved countries. It asks you to assess whether the information will get adequate protection, document that analysis, and put the transfer under a written agreement.
What does "adequate protection" mean under Law 25?+
It means the information will actually get protection comparable to what Quebec's principles require — judged on the whole picture, the destination's legal framework plus contractual and technical safeguards like a solid data processing agreement, encryption, and access controls, not the foreign statute on its own.
Is using a US cloud tool a cross-border transfer under Law 25?+
Usually yes. If personal information is stored or processed on servers outside Quebec — which most US-based cloud, CRM, and AI tools involve — that's a transfer outside Quebec, and it triggers the assessment expectation. Plenty of transfers are perfectly defensible once you've assessed and documented them.
Does a written agreement replace the privacy impact assessment?+
No — they work together. The assessment analyzes whether the transfer is appropriate; the written agreement then has to reflect what the assessment found and bind the recipient to purpose limitation, security, and limits on onward transfers. You need both, and you should date and keep the assessment.
AI governance and privacy compliance, simplified.
Valdra helps Canadian companies govern AI and meet PIPEDA and Law 25 — hosted in Canada.
Explore Valdra