Launching a Website in Quebec in 2026: 6 Legal Requirements That Almost No One Follows
A form, analytics, and hosting in the United States: your website is already subject to Law 25. The six actual legal requirements for 2026—and the one that almost no one meets.
A contact form, and suddenly you’re on the hook
A run-of-the-mill showcase website: a homepage, an “About” section, a contact form, Google Analytics to track traffic, maybe a newsletter. Hosted on Vercel, or on a shared server somewhere in Virginia. The owner is convinced they’re in the clear: “I don’t sell anything online, I don’t store any credit card information—compliance is a bank’s problem.”
That’s precisely where the misunderstanding begins. A name and email address entered into a form constitute personal information. An IP address linked to an analytics ID is another example. The moment your site records either of these, the Private Sector Personal Information Protection Act—the one that Bill 25 has completely modernized—applies. Not to your hosting provider, not to your agency: to you, the company operating the site.
And website compliance in 2026 isn’t just about a little cookie banner or a copy-and-paste privacy policy. It’s about six very specific obligations, the most significant of which is precisely the one you can’t see. A quick note before we dive in: I build websites and products; I don’t provide legal advice. What follows is the perspective of a practitioner who must deliver compliant websites—which should be validated by a professional for your specific situation.
The term that applies to you: “controller”
It all starts with vocabulary you need to familiarize yourself with. The European General Data Protection Regulation—the GDPR, in effect since May 25, 2018—distinguishes between the data controller, the entity that decides why and how data is processed, from the processor, which processes data on its behalf. Bill 25 uses different terms to describe the same concept: the company that determines the purposes of processing is responsible, while the entity that carries out the processing on its behalf is an agent or a service provider.
Under both frameworks, the conclusion is the same: you are the controller. Supabase, which hosts your database; Vercel, which serves your web pages; Stripe, which processes payments; your email service provider—these are your processors. And one principle trumps all others: you remain responsible for the information even when you entrust it to a third party. You can’t outsource your responsibility—only the processing.
The first consequence—already overlooked by most small and medium-sized businesses—is that, as of September 2022, your company must have a data protection officer. By default, this is the person with the highest authority—in practice, the owner—unless otherwise delegated in writing. Their contact information must be publicly available. Guess where people expect to find it.
Requirement 1 — A Privacy Policy That Tells the Truth
It’s the storefront, and that’s where everyone starts. The problem isn’t that it’s missing—most sites have one—but that it lies. An online generator spits out three generic paragraphs, you paste them into the footer, and no one checks to see if they describe what the site actually does.
But the policy must reflect the technical reality: what data you collect, for what purposes, with which third parties you share it, how long you retain it, how a person can exercise their rights, and who your data controller is. The GDPR details these requirements in Articles 13 and 14; Bill 25 mandates the same level of transparency. A policy that claims “we don’t share your data with anyone” when your form feeds directly into a CRM and your pages load six third-party scripts, is not protection—it’s written proof of non-compliance.
Requirement 2 — Consent to “témoins” is not just for show
In Quebec, we say “témoins” rather than “cookies,” and the banner that pops up when the page loads isn’t just for decoration: it’s a consent mechanism that must work. A banner that already sets all trackers before a single click, or whose only visible button is “Accept All,” complies with neither the spirit nor the letter of the law.
Bill 25 established a strong principle: privacy settings must offer the highest level of protection by default—in other words, no tracking until the user has consented, with the exception of cookies strictly necessary for the site to function. The GDPR, coupled with the ePrivacy Directive, requires the same prior consent. This is exactly what long placed Google Analytics in violation of the law in the eyes of several European authorities, due to data transfers to the United States—a sword of Damocles that the transatlantic framework adopted in 2023, and upheld in court in 2025, eventually lifted. I’ll come back to this below, because this point dictates the entire architecture of your hosting setup.
Requirement 3 — Overseeing Your Processors: The Contract Nobody Signs
This is the heart of the matter—and the most glaring blind spot. When you entrust personal information to a provider, the law isn’t satisfied with a simple “trust me.” It requires a written contract that governs that processing.
Under the GDPR, this is Article 28(3), which is unambiguous: a Data Processing Agreement—a DPA—that must include at least seven elements: processing solely in accordance with your documented instructions; staff confidentiality; security measures; your prior authorization for any subsequent subcontracting; assistance in responding to individuals’ rights; the deletion or return of data at the end of the contract; and a right to audit. As for Act 25, this is specifically covered by Section 18.3 of the Private Sector Act: Disclosing information to a service provider is permitted without the individuals’ consent, provided that a written contract specifies the purposes, the categories of individuals who will have access to the information, and the confidentiality and security measures. Two laws, two names, but one fundamental requirement: establish written agreements with each of your service providers.
The good news is that reputable providers have done their part. Supabase publishes its DPA and has you sign it electronically; in it, they list their own entities—Supabase Inc. in the United States, Supabase Pte Ltd in Singapore—and their list of subcontractors. Vercel publishes its own, along with its list of subprocessors. Stripe is certified under the EU-US Data Privacy Framework and incorporates the European Standard Contractual Clauses (Decision 2021/914), with 30 days’ notice before adding a processor. The bad news: no one will sign these documents for you. It’s up to you to retrieve them from each tool’s dashboard, accept them, and—most importantly—check who their processors are—because the chain never ends with your direct provider.
| Concept | GDPR (Europe) | Bill 25 (Quebec) |
|---|---|---|
| Decision-maker | Data controller | Responsible person or company |
| Your supplier | Processor | Agent / service provider |
| Mandatory contract | DPA (Article 28) | Written framework (Article 18.3) |
| Before a transfer | Adequacy or standard contractual clauses | PIA before transfer outside Quebec |
| Highest penalty | €20 million or 4% of global revenue | $25 million or 4% of global revenue |
Requirement 4 — Assessment Before Sending Data Outside Quebec
This is the pitfall I encounter most often, and it stems directly from your tech stack. A modern Quebec developer almost never hosts anything in Quebec: their database runs on Supabase, their website on Vercel, their payments through Stripe, and their emails with a U.S. service. In other words, 100% of your customers’ information leaves Quebec from the very first request.
Bill 25 doesn’t prohibit this, but it requires a step that almost no one takes.
Hosting your database on Supabase or your website on Vercel already constitutes “disclosing” personal information outside Quebec. Bill 25 requires a Privacy Impact Assessment (PIA) before this transfer—not on the day of the audit. Almost no one conducts one, and this is exactly the document the Commission may ask you to produce.
This PIA is an analysis, proportionate to the sensitivity of the data, that verifies that the protection provided elsewhere is adequate. The European mechanism is similar: a transfer outside the EU must be based on an adequacy decision or on standard contractual clauses. Good news for Canada: federal law (PIPEDA) retains its EU adequacy decision for commercial organizations, and the EU-US Data Privacy Framework survived its first appeal before the General Court of the European Union in September 2025. But none of these decisions exempts you from conducting your own PIA: it’s your document, not Supabase’s.
Requirement 5 — The Incident Response Plan, Before the Incident
A website is a constant attack surface. Bill 25 anticipated this: since September 2022, as soon as a privacy incident poses a risk of serious harm, you must report it to the Commission d’accès à l’information and to the individuals concerned, and maintain a record of all incidents—even those that do not meet this threshold. The GDPR, for its part, requires notification to the authority within 72 hours.
What you need to understand is that these obligations require preparation in advance, not in the panic of a data breach. Having a log ready, knowing who notifies whom and by when, is just as much a part of organizational architecture as your backups. The day a table that’s poorly protected by an access policy is exposed, the reflex must already be in place.
Obligation 6 — Individuals’ Rights, Including Data Portability
An individual whose data you hold has rights, and these rights carry technical weight. Access, rectification, withdrawal of consent, cessation of dissemination, and de-indexing—this Quebec-style “right to be forgotten,” in effect since September 2023—and above all, portability: as of September 22, 2024, you must be able to provide an individual with their information in a structured, commonly used technological format.
Translated into developer speak: your underlying schema must allow you to extract all of an individual’s data and delete it cleanly, upon request, within a reasonable timeframe. If you’ve scattered personal data across logs, CSV exports, three third-party tools, and two tables without a common key, the task becomes a nightmare. This is precisely the kind of constraint you need to consider when modeling the database—as I detail for a management app designed in Quebec—not something you patch together two years later.
Why 2026 Is Different from 2021
For years, we talked about Bill 25 in the future tense. That’s over now. Implementation was completed on September 22, 2024, and the game-changing aspect is the sanctions regime, which is now fully operational. The Commission d’accès à l’information can impose administrative sanctions of up to $10 million or 2% of global revenue; under criminal law, fines can reach up to 25 million or 4%. Most importantly, since September 2024, an aggrieved individual has the right to bring a private lawsuit: they may seek damages, either individually or through a class action, with punitive damages of at least $1,000 in cases of willful misconduct or gross negligence. The GDPR, for its part, caps its fines at 20 million euros or 4% of global revenue.
Two related issues are worth mentioning, as they follow the same logic: the sending of commercial emails, regulated by the Canadian Anti-Spam Act and by the deliverability requirements I’ve detailed elsewhere, and accessibility, which isn’t just a matter of design but a growing obligation with its own deadlines. A website’s compliance is never just a single box to check.
How This Changes the Way I Build
To sum it up: a website’s legal compliance isn’t a document you add at the end—it’s a process you design from the very beginning. The form that collects only what’s strictly necessary, the basic schema capable of adding and removing a person, the DPA forms collected and signed before the site goes live, the EFVP completed for each vendor outside Quebec, the ready-to-use incident log. Taken individually, each element is simple. The trap is treating them as last-minute legal formalities when they are actually architectural decisions.
That’s the difference between a site you hope is compliant and one that is compliant by design. And in 2026, with a private right of action that turns every dissatisfied customer into a potential lawsuit, this distinction is no longer merely theoretical.
Official Sources
- Bill 25 and the Private Sector Act (Quebec) — text of Bill 25 (CanLII), Private Sector Privacy Protection Act, P-39.1 (LégisQuébec), Commission for Access to Information — Key Changes and penalty system.
- GDPR (Europe) — Regulation (EU) 2016/679 — full text (EUR-Lex) and Article 28 on data processors.
- International Transfers — EU-U.S. Data Privacy Framework (U.S. Department of Commerce) and PIPEDA — Office of the Privacy Commissioner of Canada.
- Suppliers’ Privacy Policies — Supabase, Vercel, Stripe.
- Commercial Emails — Canadian Anti-Spam Act (CRTC).
Are you launching a website or a SaaS product and want compliance to be built into the architecture from the start, rather than patched together afterward? That’s exactly the kind of project I love to help shape.
Accessibility doesn't restrict your design, it enhances it - and the ADA deadline has just moved.
Accessible design doesn't impose any aesthetic compromises - it's the opposite. The thresholds that count in 2026, what is really mandatory (EAA, ADA), and the deadline that has just been extended.
AI email pipeline: copywriting is not the problem - since November 2025, Gmail has been rejecting your non-compliant mailings
Automating the writing of an email is easy. What decides whether it happens is compliance - and Gmail now definitively rejects out-of-standard senders. The complete architecture of a passing IA email pipeline.
Anatomy of a landing page that converts: structure, UX, CTA and CRM integrations
From hero-to-CTA structure to HubSpot, Salesforce and Pipedrive integrations: the complete technical guide to building landing pages that turn traffic into qualified leads.
Building an expense management app in Quebec with Claude Code: from PRD to deployment
Complete guide to creating a Next.js income and expense tracking application with automatic GST/QST calculation, AI invoice scanning and monthly reports - all generated with Claude Code.