main logo icon

Published on

September 5, 2026

|

20 min read

Quebec Law 25 and Penetration Testing (2026): Security Measures, PIAs and Auditor Evidence

Law 25 never says test d'intrusion, but section 10 makes reasonable security measures a duty with a penalty attached, and the Commission's own privacy impact assessment guide names penetration testing as report content.

Arafat Afzalzada

Arafat Afzalzada

Founder

Web App SecurityNetwork Security

Summarize with AI

ChatGPTPerplexityGeminiGrokClaude

TL;DR

Quebec's Law 25 does not require a penetration test. Nothing in the Act respecting the protection of personal information in the private sector (CQLR c P-39.1) names one. What section 10 requires is that an enterprise "take the security measures necessary to ensure the protection of the personal information collected, used, communicated, kept or destroyed and that are reasonable given the sensitivity of the information, the purposes for which it is to be used, the quantity and distribution of the information and the medium on which it is stored." Two things make that clause bite harder than it reads. First, section 90.1(4) makes a failure "to take the security measures necessary to ensure the protection of the personal information in accordance with section 10" an express ground for a monetary administrative penalty, and section 91(4) makes the same failure a penal offence. Second, section 10 predates Law 25. Its citation trail reads 1993, c. 17, s. 10; 2006, c. 22, s. 113. Law 25 did not create the duty. It created the enforcement. The Commission d'accès à l'information's own privacy impact assessment guide is the closest thing Quebec has to an official statement on penetration testing. It lists among the annexes a PIA report should carry: "Un résumé des avis de sécurité produits en collaboration avec des fournisseurs ou des partenaires (p. ex. test d'intrusion)." A summary of security assessments produced with suppliers or partners, for example a penetration test. Penalties are large but the entry point is not. Section 90.12 caps a monetary administrative penalty at $10,000,000 or 2% of worldwide turnover for an enterprise, and section 91 sets penal fines up to $25,000,000 or 4%. The Commission's own published framework, however, starts base amounts at $1,000 for a minor failure and $15,000 for a very serious one, then adjusts for aggravating and mitigating factors. The practical answer: annual penetration testing of the systems that hold personal information, plus a test tied to each privacy impact assessment for a new or overhauled information system, is what turns "reasonable security measures" from an assertion into evidence.

Quick answer: Law 25 does not require a penetration test, and no Quebec statute does. The Act respecting the protection of personal information in the private sector (CQLR c P-39.1), the law that Law 25 amended, never uses the phrase. What it requires, at section 10, is that a person carrying on an enterprise "take the security measures necessary to ensure the protection of the personal information collected, used, communicated, kept or destroyed and that are reasonable given the sensitivity of the information, the purposes for which it is to be used, the quantity and distribution of the information and the medium on which it is stored." Two provisions turn that into a compliance obligation with teeth: section 90.1(4) makes a failure to take those measures an express ground for a monetary administrative penalty, and section 91(4) makes the same failure a penal offence. Separately, section 3.3 requires a privacy impact assessment for any project to acquire, develop or overhaul an information system involving personal information, and the Commission d'accès à l'information's own guide to conducting one names "test d'intrusion" among the annexes a PIA report should carry.

Every statutory quotation on this page was read from the Québec Official Publisher's consolidated English text of P-39.1, marked "Updated to April 7 2026" and carrying official status, and every guidance quotation was read from the Commission d'accès à l'information's own published documents, on 5 September 2026. Where a claim could not be traced to the statute or to the Commission, it was dropped rather than softened. This page explains the law and the regulator's published guidance; it is not legal advice, and an enterprise making a compliance determination should consult counsel.

Mots-clés: Loi 25, test d'intrusion, mesures de sécurité raisonnables

This guide is written in English, but the Quebec market searches in both languages and the source documents are largely French. The four terms that matter are: Loi 25 (the modernisation statute, formerly projet de loi 64), test d'intrusion (penetration test), mesures de sécurité raisonnables (the section 10 standard), and évaluation des facteurs relatifs à la vie privée, or EFVP (the privacy impact assessment required by section 3.3). Every French passage quoted below is given in the original with an English rendering marked as our translation, because the Commission publishes its guidance in French and the English rendering carries no official status.

What the statute actually says

Section 10, the whole security obligation

The entire technical security duty in Quebec's private-sector privacy law is one sentence:

10. A person carrying on an enterprise must take the security measures necessary to ensure the protection of the personal information collected, used, communicated, kept or destroyed and that are reasonable given the sensitivity of the information, the purposes for which it is to be used, the quantity and distribution of the information and the medium on which it is stored.

> > 1993, c. 17, s. 10; 2006, c. 22, s. 113.

Read the citation trail at the end. It says 1993 and 2006. Section 10 was not written by Law 25. The reasonable-security-measures duty has been on the Quebec books since the Act's original enactment and was last amended in 2006. Enterprises that reorganised their programmes around Law 25 in 2023 and treated section 10 as new were treating a thirty-year-old obligation as a novelty.

What Law 25 did change is what happens when you fail it. That is covered below under enforcement.

The clause is a proportionality test with four named variables. Every scoping decision you make should be traceable to one of them:

Variable in section 10

What it drives in a testing programme

"the sensitivity of the information"

Depth. A system holding health, biometric or financial records earns manual authorisation testing; a marketing site with no personal information earns exclusion. Section 12 of the Act treats personal information as sensitive "if, due to its nature, in particular its medical, biometric or otherwise intimate nature, or the context of its use or communication, it entails a high level of reasonable expectation of privacy."

"the purposes for which it is to be used"

Which flows to test. Profiling, automated decision-making and secondary use raise the stakes on the systems performing them.

"the quantity and distribution of the information"

Breadth. A multi-tenant platform holding records for hundreds of client organisations is a different scope from a single-tenant internal system.

"the medium on which it is stored"

Where to test. Cloud object storage, on-premises databases, mobile devices and third-party processors each need their own coverage.

Nothing in that list mentions a frequency, a technique or a tester. That is why no honest reading of Quebec law produces "Law 25 requires an annual penetration test." What it produces instead is a burden of proof: you must be able to show that the measures you took were reasonable, given four specific variables, at the time.

Section 3.3, privacy impact assessments

This is the provision that pulls testing into the project lifecycle, and it took effect on 22 September 2023:

3.3. Any person carrying on an enterprise must conduct a privacy impact assessment for any project to acquire, develop or overhaul an information system or electronic service delivery system involving the collection, use, communication, keeping or destruction of personal information.

> > For the purposes of such an assessment, the person must consult the person in charge of the protection of personal information within the enterprise from the outset of the project. > > The person must also ensure that the project allows computerized personal information collected from the person concerned to be communicated to him in a structured, commonly used technological format. > > The conduct of a privacy impact assessment under this Act must be proportionate to the sensitivity of the information concerned, the purposes for which it is to be used, the quantity and distribution of the information and the medium on which it is stored.

Note the fourth paragraph. It is the same proportionality formula as section 10, word for word. The legislature deliberately tied the depth of your assessment to the same four variables that govern the depth of your security measures. A PIA that concludes "measures are reasonable" without any technical evidence has not applied the formula; it has asserted the answer.

Section 3.4 then allows the person in charge to "suggest personal information protection measures applicable to the project," and section 17 adds a second PIA trigger, in force on the same date, before communicating personal information outside Quebec.

Sections 3.1, 3.2, 3.5 to 3.8, and 9.1

The surrounding obligations matter because they are where a penetration test report gets consumed.

Section 3.1, the person in charge. "Any person carrying on an enterprise is responsible for protecting the personal information held by the person. Within the enterprise, the person exercising the highest authority shall see to ensuring that this Act is implemented and complied with. That person shall exercise the function of person in charge of the protection of personal information; he may delegate all or part of that function in writing to any person." The title and contact details must be published on the enterprise's website. Accountability sits with the highest authority by default, which is why test results that never reach that person are a governance problem as well as a security one.

Section 3.2, governance policies and practices. Enterprises must "establish and implement governance policies and practices regarding personal information that ensure the protection of such information," which "must, in particular, provide a framework for the keeping and destruction of the information, define the roles and responsibilities of the members of its personnel throughout the life cycle of the information and provide a process for dealing with complaints." Those policies "must also be proportionate to the nature and scope of the enterprise's activities and be approved by the person in charge," and detailed information about them must be published in simple and clear language.

Sections 3.5 to 3.8, confidentiality incidents. Section 3.6 defines a confidentiality incident as "(1) access not authorized by law to personal information; (2) use not authorized by law of personal information; (3) communication not authorized by law of personal information; or (4) loss of personal information or any other breach of the protection of such information." Section 3.5 requires an enterprise with cause to believe an incident has occurred to "take reasonable measures to reduce the risk of injury and to prevent new incidents of the same nature," and, where the incident presents a risk of serious injury, to "promptly notify the Commission d'accès à l'information" and the individuals concerned. Section 3.7 sets the injury-assessment factors: "the sensitivity of the information concerned, the anticipated consequences of its use and the likelihood that such information will be used for injurious purposes." Section 3.8 requires a register of confidentiality incidents, a copy of which "must be sent to the Commission at its request."

Read section 3.5 next to an unauthorised-access finding from a penetration test and the connection is obvious. "Prevent new incidents of the same nature" is a remediation obligation with a testing programme sitting behind it.

Section 9.1, privacy by default. "Any person carrying on an enterprise who collects personal information when offering to the public a technological product or service having privacy settings must ensure that those settings provide the highest level of confidentiality by default, without any intervention by the person concerned." The clause does not apply to browser cookie settings. This is a testable control: default settings on a new account are exactly the sort of assertion an application test verifies in minutes.

What the Commission actually says about penetration testing

Here is the part almost no vendor page covers, because it requires reading a French-language regulator PDF rather than another blog.

The Commission d'accès à l'information publishes Réaliser une évaluation des facteurs relatifs à la vie privée: Guide d'accompagnement à la démarche et à sa documentation, version 3.1, April 2024. In section 5.2, "Que devrait contenir le rapport?", the guide lists the annexes a PIA report should carry. The second item reads:

Un résumé des avis de sécurité produits en collaboration avec des fournisseurs ou des partenaires (p. ex. test d'intrusion)

Our translation: a summary of the security assessments produced in collaboration with suppliers or partners (for example, a penetration test).

That single line is the most direct statement any Quebec authority has published about where penetration testing fits into Law 25 compliance. It is not a mandate. It is the regulator describing, in its own guidance, what a well-documented privacy impact assessment contains, and naming the penetration test as an example.

The guide reinforces the point earlier, in the risk identification step:

Votre organisation a peut-être déjà en main des avis juridiques ou les résultats d'analyses de sécurité informatique. Si des risques de non-conformité ou des risques en matière de sécurité de l'information ont été abordés dans ces documents, nous vous recommandons de vous en inspirer pour produire votre EFVP.

Our translation: your organisation may already hold legal opinions or the results of information security analyses. If risks of non-compliance or information security risks were addressed in those documents, we recommend you draw on them in producing your PIA.

Two structural notes from the same guide. It records that section 3.3 and section 17 both came into force on 22 September 2023, while the research and statistics PIA trigger at section 21 came into force on 22 September 2022. And it sets out when a PIA is required beyond a brand-new project: "Vous commencez un nouveau projet; Votre projet n'était pas finalisé quand l'obligation de réaliser une EFVP est entrée en vigueur; Vous modifiez un projet (p. ex. modification de l'entente, refonte du système, etc.)." A modification, including a system overhaul, triggers the obligation afresh. That is your testing trigger, written by the regulator.

Enforcement: what Law 25 actually added

Section 10 is old. The consequences are new, and they are the reason Quebec suddenly became a testing market.

Monetary administrative penalties, section 90.1. A penalty "may be imposed by a person designated by the Commission, but who is not a member of any of its divisions, on anyone who," among five other grounds, at paragraph (4), "does not take the security measures necessary to ensure the protection of the personal information in accordance with section 10." Section 10 is named in the penalty provision by number. Paragraph (3) covers a failure to report a confidentiality incident.

The cap, section 90.12. "The maximum amount of the monetary administrative penalty is $50,000 in the case of a natural person and, in all other cases, $10,000,000 or, if greater, the amount corresponding to 2% of worldwide turnover for the preceding fiscal year."

Penal offences, section 91. The same failure appears again as an offence. Anyone who, at paragraph (4), "does not take the security measures necessary to ensure the protection of the personal information in accordance with section 10" among the listed acts, "commits an offence and is liable to a fine of $5,000 to $100,000 in the case of a natural person and, in all other cases, of $15,000 to $25,000,000, or, if greater, the amount corresponding to 4% of worldwide turnover for the preceding fiscal year."

Punitive damages, section 93.1. "Where the unlawful infringement of a right conferred by this Act or by articles 35 to 40 of the Civil Code causes an injury and the infringement is intentional or results from a gross fault, the court shall award punitive damages of not less than $1,000." Note "shall," and note that this is a floor, per claimant.

The number nobody quotes: the Commission's own base amounts

Base monetary administrative penalty amounts for enterprises under the Commission's published framework

Section 90.2 requires the Commission to publish a general framework for applying monetary administrative penalties, and it has: the Cadre général d'application des sanctions administratives pécuniaires, dated 11 May 2023. Reading it materially changes the risk picture, in both directions.

The designated person first categorises the severity of the failure against six criteria: "La nature du manquement; La gravité objective du manquement; Le caractère répétitif et la durée du manquement; La sensibilité des renseignements personnels concernés par le manquement; Le nombre de personnes concernées par le manquement; Le risque de préjudice sérieux auquel ces personnes sont exposées." The nature of the failure, its objective seriousness, whether it is repeated and how long it lasted, the sensitivity of the information, the number of people affected, and the risk of serious injury to them.

That produces one of four categories, and each category carries a predetermined base amount:

Category

Description in the framework (our translation)

Base amount, natural person

Base amount, all other cases

A

Minor failure, generally administrative in nature, whose anticipated consequence is nil or minor

$500

$1,000

B

Moderate failure relating to non-compliance with the rules governing the protection of personal information, whose anticipated consequence is moderate

$1,500

$4,000

C

Serious failure which, by its nature, is prejudicial to the general objectives of personal information protection, whose anticipated consequence is major

$3,000

$8,000

D

Very serious failure that undermines the integrity of personal information protection, whose anticipated consequence is major, real and/or irreparable

$5,000

$15,000

The designated person then raises or lowers the base amount using aggravating and mitigating factors, which the framework lists as: repetition and duration, sensitivity of the information, number of people affected, risk of serious injury, "Les mesures prises par la personne en défaut pour remédier au manquement ou en atténuer les conséquences," the degree of cooperation offered to the Commission, any compensation offered to affected individuals, and ability to pay. The result may not exceed the statutory maximum.

Two conclusions follow, and both are useful in a budget conversation.

The $10,000,000 headline is a ceiling, not a starting point. A designated person begins at $1,000 to $15,000 for an enterprise and works upward. Anyone selling you testing on the strength of a ten-million-dollar number is quoting the statutory maximum, not the framework.

Remediation evidence is an explicit mitigating factor. "Les mesures prises par la personne en défaut pour remédier au manquement ou en atténuer les conséquences," meaning the measures taken by the defaulting party to remedy the failure or mitigate its consequences, is on the Commission's own list. A documented finding, a documented fix and a retest are exactly that evidence. The value of a testing programme in Quebec is not only that it prevents the failure. It is that it demonstrably reduces the penalty if one occurs.

The framework also records that after a failure, "une personne peut s'engager auprès de la Commission à prendre les mesures nécessaires pour y remédier ou en atténuer les conséquences," an undertaking mechanism that, if approved and respected, bars a monetary administrative penalty for the acts the Commission identified. That undertaking has to contain a credible remediation plan, and a remediation plan without technical evidence behind it is a promise.

What "reasonable security measures" looks like as evidence

Quebec publishes no control catalogue. There is no Quebec equivalent of PCI DSS Requirement 11.4 or NYDFS 500.5(a)(1) telling you what to buy. So the defensible position is built from the wording of section 10 itself: you need to show that the measures were chosen against sensitivity, purpose, quantity and distribution, and medium, and that they were verified rather than assumed.

Nine artefacts do that work.

  1. A data inventory mapped to the section 10 variables. Which systems hold personal information, how sensitive, how much, distributed to whom, on what medium. Everything downstream is scoped from this, and without it your PIA proportionality analysis has no inputs.

  2. The privacy impact assessment itself, for each project to acquire, develop or overhaul an information system, with the record of consultation with the person in charge "from the outset of the project" that section 3.3 requires.

  3. The scope statement for the test, naming applications, APIs, IP ranges, cloud accounts and roles, with exclusions and the reason for each, traced back to the inventory. A documented exclusion is a proportionality decision; a silent one is a gap.

  4. The technical report, with reproduction steps, affected assets, severity ratings and a stated rating methodology. Our penetration testing report sample shows the structure, and how to evaluate a penetration test report covers what separates a usable report from a scanner export.

  5. The PIA annex the Commission's guide asks for: the summary of security assessments produced with suppliers or partners, "p. ex. test d'intrusion." This is the single most quotable artefact in a Quebec compliance file, because the regulator named it.

  6. The remediation record, with owners, dates and accepted risks with a written rationale. This is the mitigating factor in the penalty framework.

  7. The retest report confirming closure. An unretested fix is an assertion, and section 3.5's "prevent new incidents of the same nature" duty is not discharged by intent.

  8. The reporting line to the person in charge, showing that findings reached the accountable individual under section 3.1 and fed the governance policies under section 3.2.

  9. The confidentiality incident register under section 3.8, kept current and ready to send to the Commission on request, with the distinction between a test finding and an actual incident clearly maintained.

One caution worth stating plainly. A penetration test finding is not automatically a confidentiality incident. Section 3.6 defines an incident by unauthorised access, use or communication, or loss. An authorised test conducted under written rules of engagement is, by definition, authorised. Where a test discovers evidence that unauthorised access previously occurred, that is a different matter and the section 3.5 assessment starts. Get that distinction written into the rules of engagement before the engagement begins.

Scoping a Law 25 test: follow the personal information

Because section 10 is proportionality-driven, scoping starts with data rather than with assets.

Customer-facing applications and their APIs. Portals, mobile back ends, account management, and any endpoint that returns records belonging to an identified individual. Authorisation is the class that matters most here, because a well-formed request that returns another customer's record is precisely a "communication not authorized by law of personal information" under section 3.6(3). Our analysis of why API scanners miss BOLA and IDOR covers why this class needs manual testing.

Multi-tenant boundaries. Tenancy separation on a platform serving many client organisations directly engages the "quantity and distribution" variable in section 10. This is the single highest-value test for a Quebec SaaS company.

Default privacy settings. Section 9.1 requires the highest level of confidentiality by default on public-facing technological products. Testing what a fresh account actually gets, rather than what the settings page claims, is a fifteen-minute check that closes a statutory obligation.

Cloud storage and processing. The "medium on which it is stored" variable makes object storage exposure, identity and access configuration, and workload isolation directly relevant. Our cloud penetration testing services guide sets out how those scopes are bounded.

Internal network and directory services, where employee access to personal information is granted and revoked. Section 3.2 asks you to "define the roles and responsibilities of the members of its personnel throughout the life cycle of the information," and an internal test is what checks whether those role definitions survive contact with the access model.

Cross-border flows. Section 17 requires a PIA before communicating personal information outside Quebec. The technical half of that assessment is knowing which integrations actually move records across the border, which is a finding a test frequently surfaces and an architecture diagram frequently misses.

Suppliers and partners. The Commission's PIA guide expressly contemplates security assessments "produits en collaboration avec des fournisseurs ou des partenaires." Testing a supplier's environment normally requires the supplier's authorisation, so the mechanism is contractual: name the cadence and a right to review results, then collect what you are entitled to.

How Law 25 compares to the frameworks you are also running

Most Quebec enterprises are running Law 25 alongside at least one framework that does name testing. The overlap is high enough that one well-scoped engagement can feed several evidence sets.

Requirement

Penetration testing position

Frequency named

Notes for a Quebec enterprise

Quebec Law 25, P-39.1 s. 10

Not named in the statute. Named as PIA report content in the Commission's own guide

None

Proportionality drives depth: sensitivity, purpose, quantity and distribution, medium

Quebec Law 25, P-39.1 s. 3.3

Not named. The Commission's guide names it as an annex to the PIA report

Per project, and again on modification or overhaul

Project-triggered rather than calendar-triggered

PCI DSS v4.0 Requirement 11.4

Named expressly, internal and external, with a documented methodology

At least once every 12 months and after significant change

Applies to card-handling scope. See our PCI DSS guide

SOC 2 (TSC)

Not named as a control. Testing is evidence for the monitoring criteria

Not specified. Annual is the market convention

Common for Quebec SaaS selling into the United States. See our SOC 2 guide

ISO/IEC 27001:2022

Not named as a clause requirement. Annex A 8.8 and 8.29 are where testing lands

Not specified. Driven by the risk treatment plan

Results feed the risk treatment plan and Statement of Applicability

OSFI Guideline B-13

Named expressly at section 3.1.2, with red teaming

None. The institution sets triggers and minimum frequencies

Applies to federally regulated financial institutions. See our OSFI B-13 guide

NYDFS 23 NYCRR 500.5(a)(1)

Named expressly, from inside and outside the boundaries

At least annually

Bites any Quebec group with a New York licensed entity. See our NYDFS guide

HIPAA Security Rule

Not named in the rule in force. A 2025 proposal would require testing every 12 months

None today

Relevant to Quebec health technology vendors serving United States customers. See our HIPAA guide

Quebec TGV certification

Security testing is part of the certification evidence for health information technology products

Set by the certification cycle

The health-sector counterpart for a Quebec vendor. See our TGV certification guide

The practical pattern is that Law 25 is the least prescriptive instrument in the list and the most consequence-heavy. Build the engagement to whichever prescriptive regime applies to your business, and Law 25 is normally satisfied inside it, provided you also produce the proportionality reasoning and the PIA linkage that Law 25 asks for and the others do not. Our guide to the pentest evidence auditors accept across SOC 2, ISO 27001, PCI DSS and CMMC covers the shared package.

What the tests actually find

Stingrai's State of Penetration Testing 2026 analysed 1,206 verified findings from 55 penetration tests, and four of its numbers speak directly to the Quebec obligations above.

92.7% of tests surfaced at least one High or Critical finding. That is the number to put next to a privacy impact assessment that concluded security measures were reasonable without anyone attacking the system. Section 10 asks whether the measures were reasonable; an untested system produces an opinion about that, not a measurement.

The false positive rate across the dataset was 0.74%. If a report becomes an annex to a PIA and, potentially, a document the Commission reads, its credibility is the whole point. A file padded with unvalidated scanner output devalues the findings that matter.

The median Critical took 10.5 days to fix. Remediation speed is an explicit mitigating factor in the Commission's penalty framework, which lists "les mesures prises par la personne en défaut pour remédier au manquement ou en atténuer les conséquences." A measured median is something you can point to.

Authorisation and authentication failures concentrate in application testing. Those are the findings that map directly onto section 3.6's definition of a confidentiality incident, and they are the class automated scanning is worst at, because the request is well formed and the response is a valid 200. Only a tester who knows which record belongs to which individual can tell that it should not have been returned.

What a Law 25 penetration test costs

There is no Quebec rate card, and any figure presented as one is invented. What can be said honestly is which variables move the number, and section 10 has helpfully named most of them already.

Sensitivity of the data. Health, biometric and financial scopes attract deeper manual testing and more conservative rules of engagement.

Role and tenancy complexity. Authorisation testing scales with role pairs, not page count. A platform with client, administrator, agent, operations and support roles has an authorisation matrix several times larger than a single-role product, and multi-tenancy multiplies it again.

System count in the PIA pipeline. Section 3.3 is project-triggered, so an enterprise shipping several system overhauls a year has several testing triggers a year. That is the argument for a continuous programme over a single annual purchase.

Cross-border integrations. Section 17 PIA work adds scope on the integration surface.

Retesting. The mitigating factor in the penalty framework is remediation, and remediation without a retest is unevidenced. A quote that excludes retesting is not comparable to one that includes it.

Our penetration testing cost guide for 2026 breaks pricing structures down by engagement type, the pentest cost calculator produces a scoped estimate from asset counts, and the average cost of a pentest in Canada covers the domestic market specifically. For buyers sourcing locally, our roundup of penetration testing companies in Montreal covers the Quebec supplier market.

Stingrai publishes fixed package prices rather than a metered rate. The pricing page lists an Autonomous Pentest from US$3,000 one-time driven by Snipe, and a Hybrid Pentest at US$6,800 one-time where certified penetration testers work alongside Snipe throughout the engagement, both covering one web application and its APIs. The same two tiers run continuously at US$450 and US$1,275 per month on a 12-month engagement, which is the model that fits a section 3.3 obligation, because PIAs arrive when projects ship rather than when the annual budget cycle allows. A wider scope covering internal network, multiple applications and cloud is quoted rather than listed, through Get a Quote.

What Stingrai delivers against a Law 25 scope

Stingrai is headquartered in Toronto, Ontario, with a London office, and has been operating since 2021. It is a CREST-accredited penetration testing service provider at the firm level, holds 18 published CVEs across the team, and is rated 5.0 out of 5.0 across 19 Clutch reviews. Team certifications include OSCE3, OSCP, OSWE, OSED, OSEP, CREST CRT, CISSP, CRTO, GCPN, CRTE and eWPTX. Stingrai's penetration testing supports Law 25 programmes, along with SOC 2, ISO 27001, PCI DSS 4.0, NIST SP 800-53 and 800-171, DORA and NIS2, by producing the technical evidence those programmes consume.

Annual or continuous, both available. An enterprise can buy a one-time annual test of the systems holding personal information, or run continuous testing so that each section 3.3 project trigger is covered without a new procurement. Both are published offerings. Our explainer on continuous PTaaS sets out where each model fits.

Certified penetration testers and Snipe work concurrently. Snipe is Stingrai's autonomous AI agent for web application penetration testing, custom-trained on more than 6,000 HackerOne Hacktivity disclosure reports and on methodology distilled from Stingrai's own penetration testers. It hunts the complex classes that generic scanners miss, including IDOR, business logic flaws and broken authorisation, performs both black-box dynamic testing and white-box source review, generates AutoFix pull requests, and can run as a pull-request gating check, which is how a testing programme keeps pace with a PIA pipeline driven by system overhauls. Stingrai's penetration testers test at the same time throughout the engagement, direct Snipe's focus, extend its attack paths and pursue what it surfaces. Both contribute findings across all severities.

Retest included, which is what turns a remediation claim into the mitigating evidence the Commission's framework recognises.

Guarantee. On the Autonomous tier, "No High or Critical Finding = Don't Pay." That guarantee applies to the Autonomous tier only; other tiers and scopes are quoted through Get a Quote.

What this means for Quebec enterprises

  • Stop looking for the testing clause. There isn't one. Build the file that proves your measures were reasonable against the four variables in section 10, and the absence of a named technique stops mattering.

  • Attach a test to the PIA, not just to the calendar. Section 3.3 fires on acquisition, development and overhaul, and the Commission's guide confirms that modifying a project triggers the obligation again. A project-triggered testing programme matches the statute better than an annual one.

  • Use the Commission's own words in your file. The PIA guide names "test d'intrusion" as report content. Quote it in your assessment methodology and your annex is doing regulatory work rather than sitting there.

  • Argue budget from the framework, not the ceiling. Base amounts start at $1,000 to $15,000 for an enterprise. The compelling argument is not the $10,000,000 maximum; it is that remediation evidence is a named mitigating factor and punitive damages under section 93.1 are a floor of $1,000 per claimant with no ceiling.

  • Keep the incident register and the test findings separate and both current. An authorised test is not a confidentiality incident. Write that into the rules of engagement so nobody has to argue it later.

Frequently Asked Questions

Does Quebec Law 25 require penetration testing?

No. Neither Law 25 nor the Act respecting the protection of personal information in the private sector (CQLR c P-39.1) names penetration testing. Section 10 requires an enterprise to "take the security measures necessary to ensure the protection of the personal information ... and that are reasonable given the sensitivity of the information, the purposes for which it is to be used, the quantity and distribution of the information and the medium on which it is stored." Penetration testing is one of the strongest ways to evidence that those measures are in fact reasonable, and the Commission d'accès à l'information's own privacy impact assessment guide names "test d'intrusion" as an example of the security assessments a PIA report should summarise, but no provision compels it.

La Loi 25 exige-t-elle un test d'intrusion?

Non. Aucune disposition de la Loi sur la protection des renseignements personnels dans le secteur privé n'exige un test d'intrusion. L'article 10 exige des "mesures de sécurité propres à assurer la protection des renseignements personnels ... raisonnables compte tenu, notamment, de leur sensibilité, de la finalité de leur utilisation, de leur quantité, de leur répartition et de leur support." Le guide de la Commission d'accès à l'information sur l'évaluation des facteurs relatifs à la vie privée mentionne toutefois le test d'intrusion comme exemple d'avis de sécurité à résumer en annexe du rapport d'EFVP. The English discussion of both provisions is set out above.

What are the "reasonable security measures" required by section 10?

The Act does not list them. It sets a proportionality test with four variables: the sensitivity of the information, the purposes for which it is to be used, the quantity and distribution of the information, and the medium on which it is stored. A defensible programme documents how each control decision maps to those variables, and verifies rather than assumes the result. Note that section 10 predates Law 25: its citation trail reads 1993, c. 17, s. 10; 2006, c. 22, s. 113. What Law 25 added was enforcement, at sections 90.1(4) and 91(4).

When does Law 25 require a privacy impact assessment?

Section 3.3 requires one "for any project to acquire, develop or overhaul an information system or electronic service delivery system involving the collection, use, communication, keeping or destruction of personal information," and section 17 requires one before communicating personal information outside Quebec. Both took effect on 22 September 2023, per the Commission's PIA guide. The guide also confirms that a PIA is required where you start a new project, where a project was unfinished when the obligation came into force, and where you modify a project, including a system overhaul.

Does a penetration test belong in a Quebec privacy impact assessment?

Yes, according to the Commission's own guidance. In section 5.2 of Réaliser une évaluation des facteurs relatifs à la vie privée, version 3.1 dated April 2024, the annexes a PIA report should carry include "Un résumé des avis de sécurité produits en collaboration avec des fournisseurs ou des partenaires (p. ex. test d'intrusion)," which we render as a summary of the security assessments produced in collaboration with suppliers or partners, for example a penetration test. The guide also recommends drawing on existing information security analyses when identifying risks.

What are the penalties for failing to secure personal information in Quebec?

Two regimes run in parallel and both name section 10 directly. Section 90.1(4) makes a failure to take the necessary security measures a ground for a monetary administrative penalty, capped by section 90.12 at $50,000 for a natural person and, in all other cases, "$10,000,000 or, if greater, the amount corresponding to 2% of worldwide turnover for the preceding fiscal year." Section 91(4) makes the same failure a penal offence carrying a fine of $5,000 to $100,000 for a natural person and, in all other cases, "$15,000 to $25,000,000, or, if greater, the amount corresponding to 4% of worldwide turnover." Section 93.1 adds punitive damages of not less than $1,000 where an intentional infringement or gross fault causes injury.

How does the Commission actually calculate a monetary administrative penalty?

Through the Cadre général d'application des sanctions administratives pécuniaires, dated 11 May 2023 and published as section 90.2 requires. The designated person categorises the failure as A, B, C or D against six criteria including the nature and objective seriousness of the failure, whether it was repeated and how long it lasted, the sensitivity of the information, the number of people affected, and the risk of serious injury. Each category carries a predetermined base amount, which for an enterprise is $1,000, $4,000, $8,000 and $15,000 respectively. That base is then raised or lowered using aggravating and mitigating factors, one of which is the measures taken to remedy the failure or mitigate its consequences, and it may not exceed the statutory maximum.

Is a penetration test finding a confidentiality incident under Law 25?

No, not in itself. Section 3.6 defines a confidentiality incident as access, use or communication of personal information not authorised by law, or loss of personal information or any other breach of its protection. A penetration test conducted under written authorisation is authorised by the enterprise, so a finding is a discovered weakness rather than an incident. If the test uncovers evidence that unauthorised access actually occurred, that is a different matter and the section 3.5 assessment begins, using the section 3.7 factors. Write the distinction into the rules of engagement before the engagement starts.

Who is accountable for security measures under Law 25?

Section 3.1 puts responsibility on the enterprise and then names an individual: "the person exercising the highest authority shall see to ensuring that this Act is implemented and complied with. That person shall exercise the function of person in charge of the protection of personal information," with written delegation permitted. The title and contact details of the person in charge must be published on the enterprise's website, or made available by another appropriate means. Section 3.2 requires governance policies and practices approved by that person, so a penetration test report that never reaches them has not closed the loop.

Does Law 25 apply to my business if I am not based in Quebec?

The Act applies to a person carrying on an enterprise who collects, holds, uses or communicates personal information about other persons in the course of carrying on an enterprise within the meaning of the Civil Code of Québec. In practice, enterprises outside Quebec that offer goods or services to Quebec residents and handle their personal information are routinely treated as in scope, and section 17 imposes an obligation before personal information is communicated outside Quebec, which pushes Quebec requirements down the supply chain to processors elsewhere. Whether a specific out-of-province business is caught is a legal question for counsel, not a technical one.

Where can I read the actual law and the Commission's guidance?

The consolidated statute is published by the Québec Official Publisher: Act respecting the protection of personal information in the private sector, CQLR c P-39.1. The Commission d'accès à l'information's overview of what changed is at Principaux changements apportés par la Loi 25. The PIA guide is Réaliser une évaluation des facteurs relatifs à la vie privée, and the penalty framework is the Cadre général d'application des sanctions administratives pécuniaires.

References

  1. Québec Official Publisher. Act respecting the protection of personal information in the private sector, CQLR c P-39.1. Consolidated English text, updated to 7 April 2026, carrying official status. https://www.legisquebec.gouv.qc.ca/en/pdf/cs/P-39.1.pdf. Source of every statutory quotation on this page, including sections 3.1, 3.2, 3.3, 3.4, 3.5, 3.6, 3.7, 3.8, 9.1, 10, 90.1, 90.12, 91 and 93.1.

  2. Commission d'accès à l'information du Québec. Réaliser une évaluation des facteurs relatifs à la vie privée: Guide d'accompagnement à la démarche et à sa documentation. Version 3.1, April 2024. https://www.cai.gouv.qc.ca/uploads/pdfs/CAI_GU_EFVP.pdf. The Commission's own PIA guide, which names "test d'intrusion" among the security assessments a PIA report should summarise, recommends drawing on existing information security analyses, and records the 22 September 2023 in-force date for the section 3.3 and section 17 assessment obligations.

  3. Commission d'accès à l'information du Québec. Cadre général d'application des sanctions administratives pécuniaires. 11 May 2023. https://www.cai.gouv.qc.ca/uploads/pdfs/CAI_Cadre_Sanct_Pecun.pdf. The framework required by section 90.2, containing the four failure categories, their base amounts, and the aggravating and mitigating factors applied to them.

  4. Commission d'accès à l'information du Québec. Principaux changements apportés par la Loi 25. https://www.cai.gouv.qc.ca/protection-renseignements-personnels/sujets-et-domaines-dinteret/principaux-changements-loi-25. The Commission's own summary of what Law 25 changed, including the PIA triggers, the governance policy obligations, the person in charge, confidentiality incidents, data portability from 22 September 2024, and the monetary administrative penalty regime.

  5. Stingrai. The State of Penetration Testing 2026. https://www.stingrai.io/blog/state-of-penetration-testing-2026. 1,206 verified findings across 55 penetration tests, severity mix, false positive rate and remediation timing.

  6. Stingrai. Penetration Testing Cost 2026. https://www.stingrai.io/blog/penetration-testing-cost-2026. Pricing structures by engagement type and the variables that move a quote.

  7. Stingrai. Average Cost of a Penetration Test in Canada 2026. https://www.stingrai.io/blog/average-cost-of-pentest-canada-2026. Domestic Canadian pricing context.

  8. Stingrai. Penetration Testing Report Sample 2026. https://www.stingrai.io/blog/penetration-testing-report-sample-2026. A worked example of the report structure that can be annexed to a privacy impact assessment.

  9. Stingrai. Pentest Evidence Auditors Accept: SOC 2, ISO 27001, PCI DSS and CMMC. https://www.stingrai.io/blog/pentest-evidence-auditors-accept-soc2-iso27001-pci-cmmc. The shared evidence package across frameworks.

  10. Stingrai. Pricing. https://www.stingrai.io/pricing. Published one-time and continuous package prices for one web application and its APIs.


Ready to scope a Law 25 penetration test?

Section 10 asks one question: were your security measures reasonable, given the sensitivity, purpose, quantity, distribution and medium of the personal information you hold. A test is how that question gets an answer instead of an assertion, and the Commission's own privacy impact assessment guide already names the penetration test as report content. Stingrai is a Canadian, CREST-accredited penetration testing service provider whose penetration testing supports Law 25 programmes by producing the scope statement, technical report, remediation record and retest evidence a privacy impact assessment consumes, as a one-time annual engagement or as continuous coverage across a pipeline of system overhauls. Certified penetration testers work alongside Snipe, our autonomous AI agent for web application penetration testing, throughout the engagement, hunting the broken authorization and business logic flaws that put one individual's records on another individual's screen. Book a free scoping call, get a quote for a multi-application or cloud scope, or read the published package prices on the pricing page.

0 views

0

X

Related reading

Best Healthcare Penetration Testing Companies (2026): HIPAA, HITRUST and Medical Device Testing Compared
Web App SecurityNetwork Security

Best Healthcare Penetration Testing Companies (2026): HIPAA, HITRUST and Medical Device Testing Compared

Best healthcare penetration testing companies in 2026, ranked, with what HIPAA, HITRUST and FDA 524B really require of a pentest.

20 min read

Best BreachLock Alternatives (2026): PTaaS Platforms Compared on Testers, Evidence and Pricing
Web App SecurityNetwork Security

Best BreachLock Alternatives (2026): PTaaS Platforms Compared on Testers, Evidence and Pricing

Compare 8 BreachLock alternatives for 2026 on who tests, what the AI does, retest terms and published pricing, plus BreachLock vs Cobalt and Astra.

13 min read

Best Bugcrowd Alternatives for Penetration Testing (2026): Pentest as a Service vs Crowdsourced
Web App SecurityNetwork Security

Best Bugcrowd Alternatives for Penetration Testing (2026): Pentest as a Service vs Crowdsourced

Compare 8 Bugcrowd alternatives for penetration testing in 2026 on delivery model, compliance fit and published pricing, plus where Bugcrowd still wins.

14 min read

Contents

X