Rules

Montreal consent rules under Law 25 compared with the rest of Canada

Privacy scam verification in Montreal runs on Quebec Law 25 consent, notice and identity checks, not PIPEDA or Alberta PIPA. Here is how each works.

What to take away

  • Privacy scam verification in Montreal starts with Quebec Law 25, which sets consent, notice and identity verification duties that differ from the rules elsewhere in Canada.
  • Consent under Law 25 must be clear, free, informed and given for specific purposes, and it must be requested separately from other terms.
  • Privacy notices in Quebec must be plain language, and Montreal businesses must name a person responsible for protecting personal information.
  • Identity verification in Montreal must be proportionate: confirm who you are dealing with, collect only what the check needs, and keep the proof.
  • Outside Quebec, PIPEDA applies to federally regulated and cross-border activity, while Alberta PIPA covers most private-sector organizations in that province.
  • You can complain to the Commission d'acces a l'information du Quebec, the Office of the Privacy Commissioner of Canada, or both, depending on the organization.

How Law 25 consent works for Montreal businesses

Quebec Law 25 amended the Act respecting the protection of personal information in the private sector. It applies to any enterprise carrying on business in Quebec, which catches most Montreal businesses and any platform selling to Montrealers.

The core rule is that consent must be manifest, free, informed and given for specific purposes. Silence does not count. A pre-ticked box does not count. Neither does a clause buried in a service contract that treats agreement to the sale as agreement to data collection.

Law 25 also requires that consent for a purpose be requested separately from any other information given to the person. In practice, that means a Montreal retailer cannot fold marketing consent into a warranty registration form and call it done. The request has to stand on its own.

Consent is not permanent. People can withdraw it, and the business must then stop using the data for that purpose, subject to retention duties elsewhere in the law. Records of consent matter because the burden of showing consent falls on the organization.

For a small Montreal business, the practical work is mapping what data it holds, why, and where consent came from. If a mailing list was built from purchased contacts, that consent is weak under Law 25 and hard to defend.

The Office of the Privacy Commissioner of Canada publishes a plain overview of privacy laws in Canada that sets Law 25, PIPEDA and the provincial statutes side by side.

Privacy notices and plain-language requirements in Quebec

Law 25 requires a privacy notice written in clear and simple language. Quebec's language rules also mean the notice generally has to be available in French, and French must be at least as accessible as any other version.

A workable privacy notice answers a short set of questions. What personal information do you collect? For what purpose? How is it used? Who inside or outside the organization sees it? How long is it kept? Who can be contacted about it?

The notice must be provided when information is collected, not only posted somewhere on a website. For an online merchant, that means the notice belongs at the point of collection, near the form or the checkout, not three clicks away.

Quebec also requires that a person be designated to protect personal information, and that the title and contact details of that person be published. Montreal businesses should treat this as a real role, not a name on a page.

If a privacy breach creates a risk of serious injury, the business must notify the Commission d'acces a l'information du Quebec and affected individuals. Keeping a notice current is part of that duty, because an outdated notice misleads the people you are supposed to inform.

Identity verification duties for Montreal platforms and merchants

Identity verification is where privacy rules and fraud prevention meet. A Montreal platform that checks who its users are has to collect identity data for that purpose and not quietly reuse it for marketing.

The principle is proportionality. If confirming age needs a date of birth, ask for the date of birth, not a full identity document. If confirming a name and address is enough for a transaction, do not demand a scan of a passport.

Government-issued identifiers deserve extra care. Quebec treats a health insurance number and similar identifiers as sensitive, and using them as a general account key is a poor practice that invites both complaints and fraud.

Verification records should be kept only as long as needed to show the check happened. Retaining a copy of an ID document indefinitely creates a target. A confirmation that verification succeeded is often enough.

For anyone weighing which checks are lawful and which are overreach, a plain creator privacy settings guide is a useful starting point before designing a process.

Montreal merchants also face a practical scam problem: impersonation. A fraudster posing as a customer, or as the business itself, can defeat a weak check. Verifying the counterparty is a privacy decision and an anti-fraud decision at the same time.

A worked example

A Montreal gym signs up members online. It collects name, address, date of birth, a photo of a driver's licence and a credit card, and keeps all of it indefinitely in one database.

Under Law 25, the licence photo is likely excessive for a membership. The notice does not say how long records are kept. Consent to marketing is bundled into the membership terms.

A better process: collect name, contact details and payment data; verify age only if a youth rate applies; keep a verification flag rather than the licence image; separate the marketing consent; and set a retention period with a deletion routine.

Montreal compared with PIPEDA outside Quebec

PIPEDA is the federal private-sector law. It applies to organizations engaged in commercial activity in provinces without substantially similar legislation, and to federally regulated businesses such as banks, telecoms and airlines everywhere, including Montreal.

So a Montreal bank answers to PIPEDA and to Quebec Law 25. A Montreal bakery answers to Law 25. That overlap confuses people, and it is the single most common source of bad advice about privacy scam verification in Canada.

PIPEDA consent is also meaningful consent, and it also requires a privacy policy and a designated contact. The difference is in the detail: Law 25 adds separate consent requests, a published privacy officer, breach notification duties and, over time, stronger individual rights.

For a national platform, the safe approach is to build to the strictest standard it faces. In practice that means Law 25 for Quebec users, because complying with it usually satisfies PIPEDA as well, not the reverse.

A useful check for any Montreal business is how much of its risk sits in what users publish themselves, which is why a privacy settings review belongs in the same conversation as a consent audit.

Montreal compared with Alberta PIPA

Alberta has its own private-sector law, the Personal Information Protection Act, known as Alberta PIPA. It is declared substantially similar to PIPEDA, so it governs most private organizations in Alberta instead of the federal statute.

Alberta PIPA also requires consent, but it allows implied consent in more situations than Quebec does. That is a real difference for a Montreal business comparing notes with a Calgary counterpart.

Alberta PIPA sets its own breach notification duties and its own commissioner. Quebec Law 25 sets a separate threshold, a separate regulator and separate notice content rules.

British Columbia has a PIPA of its own, and other provinces cover health information or public bodies rather than the private sector generally. Canada does not have one privacy law. It has a patchwork.

Feature Quebec Law 25 PIPEDA Alberta PIPA
Main regulator Commission d'acces a l'information du Quebec Office of the Privacy Commissioner of Canada Office of the Information and Privacy Commissioner of Alberta
Consent model Manifest, free, informed, purpose-specific, requested separately Meaningful consent Consent, express or implied in defined cases
Privacy notice Required, clear and simple, French available Required policy and contact Required policy and contact
Privacy officer Named and published Designated contact Designated contact
Breach notification To the regulator and affected people on serious injury risk To the regulator on real risk of significant harm To the commissioner where there is a risk of harm

Quebec's justice and civil status services set out how civil identity documents are issued and replaced, which matters when a verification record is disputed.

What Montreal consumers can demand, and from whom

If a Montreal business holds your personal information, you can ask what it has, why it has it, who it has been shared with, and how long it will be kept. You can ask for a copy in a structured, commonly used format.

You can withdraw consent for a purpose and ask the business to stop using your data for it. You can ask for correction of inaccurate information, and you can ask for deletion where retention is no longer justified.

You can ask who the person responsible for privacy is. That person's title and contact details must be published, so the request should not be hard to route.

For identity checks, you can ask what is being verified, what document or data is needed, how long the proof is kept, and whether a less intrusive option exists. A business that cannot answer those questions has a process problem.

If a company loses your data, the steps you can take, including complaint routes and what to ask for, are set out in this PIPEDA steps to take walkthrough.

Before trusting any service that asks for identity documents, it is worth running your own social media privacy audit to see what is already public and could be used to impersonate you.

Filing a complaint about a Montreal business

  1. Write to the business first. Ask for the information it holds, the purpose, and the correction or deletion you want. Keep the request in writing and note the date.
  2. Give a reasonable deadline. If you get no answer or an unsatisfactory one, keep the reply as evidence for the next step.
  3. Complain to the Commission d'acces a l'information du Quebec if the organization is provincially regulated and carries on business in Quebec.
  4. Complain to the Office of the Privacy Commissioner of Canada if the organization is federally regulated, or if the matter crosses provincial lines.
  5. Report fraud separately. The Canadian Anti-Fraud Centre takes reports of identity fraud, and the Competition Bureau handles deceptive marketing.
  • Name the organization and the exact data at issue
  • Note the date you gave or refused consent
  • Keep copies of every message sent and received
  • State the outcome you want: access, correction, deletion or an explanation
  • Report any fraudulent use of your identity to the police and the CAFC

Quebec employment records held by a Montreal employer fall under the same law, so workplace privacy complaints follow the same route as consumer ones.

Identity theft losses are also a tax and consumer matter, and Quebec's finance and tax services explain how to flag fraudulent filings made in your name.

Common questions

Does Law 25 apply to a small Montreal business? Yes, if it carries on business in Quebec and holds personal information, regardless of size. There is no small-business exemption of the kind some people assume exists.

Can a Montreal store ask for my driver's licence to verify me? It can ask, but the request must be proportionate to the purpose. For a routine purchase, a licence scan is usually excessive, and you can ask for a less intrusive check.

What is the difference between PIPEDA and Alberta PIPA? PIPEDA is the federal law and applies where no substantially similar provincial law governs. Alberta PIPA is that provincial law for most private organizations in Alberta, and it permits implied consent in more cases.

Where do I complain about a Montreal platform? Start with the platform's privacy contact. If that fails, the Quebec regulator handles provincially regulated businesses, and the OPC handles federally regulated ones. Some matters can go to both.

How long can a Montreal business keep my identity documents? Only as long as the purpose requires. Ask for the retention period in writing, and ask whether a verification record could replace a stored copy of the document itself.

More in Rules

Rules

How PIPEDA and Quebec Law 25 change consent for Canadian social media users

Privacy scam verification starts with knowing how PIPEDA, Quebec Law 25, Alberta PIPA and BC PIPA treat consent, access requests and ID checks.

Rules

Calgary identity verification under Alberta PIPA, a practical overview

Scam verification in Calgary runs on Alberta PIPA: what employers and energy contractors may request, how long to keep it, and where workers complain.

Rules

Background checks in Ontario, what employers can ask under privacy law

A background check policy in Ontario must respect privacy law. Here is what employers can ask, what you can refuse, and where to complain in Ontario.

Rules

Scam calls and texts in Canada, how CRTC rules and the do not call list work

Scam verification in Canada: how CRTC telemarketing rules, caller ID spoofing enforcement and the National Do Not Call List work, and how to report a scam call.

Latest from Planning Desk

Guides

7 lessons worth learning about marketplace scams risks

Marketplace risk mapped by what you actually lose: money, account access, physical safety, identity data, and the slower exposure that arrives afterwards.

Costs

Canadian Anti-Fraud Centre: What Happens After You Report a Scam

What a Canadian Anti-Fraud Centre report scam costs across Canada, what the CAFC does with your file, and what happens next after you submit it.

Features

7 pointers on marketplace scams rules that hold up

Marketplace rules you set before a deal starts, why pre-commitment beats judgment under pressure, and how to write a version a household will keep.

Industry

Social Security Number Stolen? Steps US Residents Should Take First

A stolen SSN needs a fast, ordered response: report at IdentityTheft.gov, freeze all three credit files, and tell the IRS. Timelines for each stage, in order.