Join our Newsletter — 33% off our NHI Course

Bill 64

Quebec Bill 64 is a privacy law that modernises how organisations in Quebec must protect personal information. It expands obligations around governance, privacy impact assessments, data subject rights, and breach reporting, while introducing stronger enforcement and penalties for non-compliance. The law pushes privacy from a policy issue into an operational control framework.

What Bill 64 Changes for Privacy Governance

Bill 64 moves privacy out of a policy-only posture and into an operational governance model. For organisations handling Quebec personal information, that means ownership, accountability, and documented decision-making become part of the control surface, not just compliance paperwork.

The law matters because it changes the way privacy is managed day to day. Organisations need clearer internal roles, traceable approvals, and repeatable processes for handling personal information across collection, use, retention, and disclosure.

Core Obligations Introduced by Bill 64

Bill 64 expands the obligations that organisations must support with real controls. The most important themes are governance, privacy impact assessments, individual rights handling, and breach response, all of which require coordination between legal, security, and operational teams.

Privacy impact assessments are especially important because they force organisations to evaluate privacy risk before launching or changing processing activities. That makes privacy design an upstream control, not a cleanup step after deployment.

What Bill 64 Means for Data Rights and Incident Response

Bill 64 also strengthens how organisations must respond when people exercise privacy rights or when an incident affects personal information. Requests for access, correction, portability, or deletion need defined workflows, while breach reporting requires timely judgment and documented escalation.

These requirements often expose weak recordkeeping, unclear ownership, or fragmented systems. The law is therefore as much about operational readiness as it is about legal compliance, because the organisation must be able to locate information, assess impact, and act consistently.

How Bill 64 Changes Operational Controls

For practitioners, Bill 64 is best understood as a control framework that turns privacy into a managed process. Organisations need policies, evidence, and execution that line up, otherwise the law becomes difficult to satisfy in practice even if the written policy looks complete.

That shift also affects third-party oversight, retention discipline, and approval chains for new data uses. In practice, Bill 64 rewards organisations that can prove how privacy decisions are made, who owns them, and how exceptions are tracked.

Risk and Threat Considerations

Bill 64 raises the cost of weak governance because failures are no longer limited to poor privacy practice, they can become reportable incidents, enforcement exposure, and reputational damage. The main risk is not just mishandling personal information, but failing to demonstrate that the organisation had a defensible process for protecting it.

Failure mechanism: Gaps usually appear when organisations lack clear ownership, inventory, impact assessment discipline, or breach triage. In that situation, the organisation may miss legal obligations, delay response, or be unable to show that privacy decisions were made with appropriate control.

Impact: The result can be regulatory penalties, delayed notification, weakened trust, and broader exposure if the underlying data handling weakness affects multiple systems or business processes.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 sets the technical controls, while GDPR and ISO/IEC 27001:2022 define the regulatory obligations.

Framework Control / Reference Relevance
GDPR Art. 25 — Data protection by design and by default Bill 64 similarly pushes privacy into design-time governance and controls
Art. 32 — Security of processing Bill 64's breach and protection duties align with operational security measures for personal data
Art. 35 — Data protection impact assessment Bill 64 elevates privacy impact assessment as a core governance control
Recommendation — Build privacy into processing decisions before deployment and document default-minimising settings. Apply appropriate technical and organisational measures to protect personal information in operation. Perform impact assessments before introducing high-risk personal data processing.
NIST SP 800-53 Rev 5 RA-3 — Risk Assessment Bill 64 requires structured privacy risk evaluation for processing changes and controls
IR-6 — Incident Reporting Bill 64's breach notification duties map to incident escalation and reporting
Recommendation — Assess privacy risk before approving new or changed personal data processing. Define breach escalation and reporting triggers for personal information incidents.
ISO/IEC 27001:2022 A.5.31 — Legal, statutory, regulatory and contractual requirements Bill 64 is a statutory privacy obligation that must be tracked in governance
A.5.34 — Privacy and protection of PII Bill 64 directly concerns organisational controls for personal information protection
A.5.24 — Information security incident management planning and preparation Bill 64 breach handling depends on prepared incident workflows and decision rights
Recommendation — Track Bill 64 obligations in the compliance register and assign accountable owners. Implement privacy controls that cover collection, use, retention, disclosure and handling of personal information. Predefine incident roles and escalation paths for privacy-related events.

Practitioner Guidance

Why practitioners should care: Bill 64 is not a static legal reference, it is a prompt to operationalise privacy. Teams should treat it as a driver for accountable governance, evidence-based assessments, and repeatable handling of rights and incidents.

Practitioner takeaway: If your privacy programme cannot show who owns each obligation and how each control is executed, it is not yet mature enough for this kind of law.