Quebec's Law 25, plainly: what it actually requires of a business
“Law 25” is the common name for the Quebec statute adopted in 2021 that rewrote the rules on personal information. For a private business, those rules live in the Act respecting the protection of personal information in the private sector (CQLR, chapter P-39.1). This page summarizes what the text requires, section by section, with a link to the official text for every point. It is not legal advice: it is the summary we had to write for ourselves, published as is.
Read from the official consolidated version, current to 1 April 2026.
Last reviewed:
Four things to know
- What it is
An overhaul, not a new statute
“Law 25” refers to chapter 25 of the 2021 statutes. It did not create a separate regime: it amended existing legislation. For a private business, the text to read is the Act respecting the protection of personal information in the private sector (P-39.1).
- Who is covered
Every business, no threshold
Section 1 covers anyone who collects, holds, uses or communicates to third parties personal information about others in the course of carrying on an enterprise within the meaning of article 1525 of the Civil Code. There is no employee threshold, no revenue threshold and no small-business exemption. The Act does set out a few subject-matter exclusions — notably journalistic, historical or genealogical material released for the legitimate information of the public.
- Since when
In waves, since 2022
The obligations came into force in waves. The person in charge of the protection of personal information and the confidentiality-incident regime (ss. 3.1 and 3.5 to 3.8) have applied since 22 September 2022; most of the rest — impact assessments, communication outside Quebec, rules for service providers, retention, automated decisions — since 22 September 2023; the right to portability since 22 September 2024.
- What it costs
Up to $25M or 4%
Three regimes, not two. Administrative monetary penalty: at most $10,000,000 or 2% of worldwide turnover for the preceding fiscal year, whichever is higher (s. 90.12). Penal prosecution: a fine of $15,000 to $25,000,000 or 4% of that same turnover, whichever is higher (s. 91). And, without going through the Commission, punitive damages of at least $1,000 for unlawful and intentional interference or interference resulting from gross negligence (s. 93.1).
The obligations, section by section
Every line is a summary of our reading, not a quotation — the official text is linked at each point, and it is the official text that is authoritative. Where a section carries a condition or an exception that changes the outcome, we keep it rather than prune it: a summary that lightens the rule is exactly the shortcut that turns on whoever relied on it.
- s. 3.1
Appoint a person in charge — and publish their contact details
The person with the highest authority in the enterprise is by law the person in charge of the protection of personal information. They may delegate the function in writing, in whole or in part. The title and contact details of the person in charge must be published.
- s. 3.2
Governance policies — written, approved, published
The enterprise must establish and implement policies and practices governing its handling of personal information. They must provide a framework for retention and destruction, set out the roles and responsibilities of staff throughout the life cycle of the information, and include a process for dealing with complaints. They must be proportionate to the nature and scope of the enterprise's activities and be approved by the person in charge. Detailed information about them must be published, in clear and simple language, on the enterprise's website — or made available by other means if it has no website.
- s. 8
Say why and how, at collection
Where information is collected from the person concerned, they must be informed — at the time of collection and afterwards on request — of the purposes pursued, the means of collection, their rights of access and rectification, and their right to withdraw consent. Where applicable, they must also be told the name of the third party for whom the collection is made, the third parties or categories of third parties to whom the information will have to be communicated, and the possibility that the information could be communicated outside Quebec. On request, add the information collected, the categories of persons within the enterprise who have access to it, the retention period and the contact details of the person in charge. All of it in clear and simple language, whatever the means of collection.
- s. 14
Valid consent: manifest, free, enlightened — and asked purpose by purpose
Consent must be manifest, free and enlightened, and given for specific purposes. It is requested for each of those purposes, in clear and simple language, and, where it is requested in writing, presented separately from any other information. It is valid only for the time necessary to achieve the purposes for which it was requested. For a minor under 14, it is given by the person having parental authority or by the tutor. Consent that does not meet these requirements is without effect.
- s. 9.1
Confidentiality by default, with nothing for the user to do
Anyone who collects personal information while offering to the public a technological product or service with privacy settings must ensure that, by default, those settings provide the highest level of confidentiality, without any intervention by the person concerned. The privacy settings of a cookie are not covered.
- s. 8.2
A published confidentiality policy — and a notice for every amendment
Anyone who collects personal information through technological means must publish a confidentiality policy on the enterprise's website, where applicable, and disseminate it by any means capable of reaching the persons concerned, drafted in clear and simple language. The same dissemination is required for the notice that must be given of any amendment to that policy.
- s. 10
Security measures in proportion
Measures must be reasonable given the sensitivity of the information, the purpose of its use, its quantity, distribution and medium. This section predates Law 25 and was not amended by it — it already applied.
- s. 12.1
A fully automated decision: say so
Where a decision is based exclusively on automated processing, the person must be informed no later than when the decision is communicated to them. On request, you must also tell them the information used, the reasons and the principal factors and parameters that led to the decision, and their right to have that information corrected. And they must be given the opportunity to submit observations to a member of staff who is in a position to review the decision. This is the section any AI project should read first.
- s. 12
Using information for another purpose: the list is closed
Information may be used within the enterprise only for the purposes for which it was collected, unless the person consents — express consent where the information is sensitive. Only five exceptions allow another use without consent: a consistent purpose, the clear benefit of the person, the prevention and detection of fraud or the assessment and improvement of protection and security measures, the supply of a product or service requested by the person, and study, research or the production of statistics on de-identified information. A purpose is “consistent” only where there is a relevant and direct connection with the purpose of collection, and commercial or philanthropic prospection is never one. De-identified information remains personal information, and whoever uses it must take reasonable measures to limit the risk of re-identification.
- s. 3.3
An impact assessment for any information-system project
A privacy impact assessment is required for any project to acquire, develop or overhaul an information system or an electronic service delivery system that involves the collection, use, communication, keeping or destruction of personal information. The person in charge must be consulted from the outset of the project. The project must also allow computerized personal information collected from the person concerned to be communicated to them in a structured, commonly used technological format. The extent of the assessment must be proportionate to the sensitivity of the information, the purpose of its use, its quantity, distribution and medium.
- s. 17
An impact assessment before anything goes outside Quebec
Before communicating personal information outside Quebec, you must conduct a privacy impact assessment taking into account, in particular, the sensitivity of the information, the purpose of its use, the protection measures — including contractual ones — it would receive, and the legal framework of the receiving state. The Act does not prohibit the transfer, it conditions it: the communication may take place only where the assessment establishes that the information would receive adequate protection, and it must be the subject of a written agreement taking into account the results of the assessment and the mitigation measures agreed on. The SAME applies where a person or body outside Quebec is entrusted with collecting, using, communicating or keeping such information on your behalf — hosting and outsourced operation are therefore covered, even with no “communication” in the ordinary sense. One exception only: a communication made in an emergency that endangers the life, health or safety of the person concerned (s. 18, para. 1, subpara. 7).
- s. 18.3
Outsourcing: a written contract, and named measures
Information may be communicated to a mandatary or a service provider without the consent of the person concerned where it is necessary for performing the mandate or the contract of enterprise or for services. Two conditions: the mandate or contract must be conferred IN WRITING, and it must state the measures the provider is to take to protect the confidentiality of the information, to ensure it is used only in performing the contract, and to ensure it is not kept after the contract expires. The provider, for its part, must notify the person in charge without delay of any violation or attempted violation of those obligations, and must allow any verification relating to confidentiality. That content requirement — the one in the second paragraph, which lists the measures to be stated — does not apply where the mandatary is a public body or a member of a professional order. The obligation to confer the mandate IN WRITING, for its part, remains.
- ss. 3.5 to 3.8
Confidentiality incidents: act, notify, record
As soon as an enterprise has REASONABLE GROUNDS TO BELIEVE that a confidentiality incident has occurred, it must take reasonable measures to reduce the risk of harm being caused and to prevent new incidents of the same nature. To assess the risk it must consider the sensitivity of the information, the anticipated consequences of its use and the likelihood that it will be used for harmful purposes, and it must consult its person in charge of the protection of personal information. Where the incident presents a risk of SERIOUS injury, it must promptly notify the Commission d'accès à l'information, and it must also notify every person concerned. Mind the scope of the deferral: the section suspends ONLY the notice to the persons concerned, “for as long as this would be likely to hinder an investigation” by a body responsible for preventing, detecting or repressing crime. The notice to the Commission is not deferrable. A register of incidents must be kept and sent to the Commission on request; the content of the notices and of the register is prescribed by the Regulation respecting confidentiality incidents, and the register is kept for five years.
- s. 23
Destroy or anonymize when it is over
Once the purposes for which information was collected or used have been achieved, it must be destroyed or anonymized in order to be used for serious and legitimate purposes, subject to any retention period provided for by an Act. The threshold is demanding: information is anonymized only where it is, AT ALL TIMES, reasonably foreseeable in the circumstances that it irreversibly no longer allows the person to be identified DIRECTLY OR INDIRECTLY — and the anonymization must follow generally accepted best practices as well as the criteria and terms of the Regulation respecting the anonymization of personal information (re-identification analysis, supervision by a qualified person, a register). Not to be confused with DE-IDENTIFICATION (s. 12), which removes only direct identification: de-identified information remains personal information subject to the Act, and whoever holds it must limit the risk of someone being re-identified from it. Attempting to re-identify a person from anonymized information is an offence (s. 91, subpara. 5).
- s. 32
Answer within 30 days — silence counts as a refusal
The person in charge must answer an access or rectification request in writing, with diligence and no later than 30 days after receiving it; failing to answer within that period, they are deemed to have refused it. Two neighbouring sections complete the mechanism and are not what this one says: section 30 requires the request to be made in writing and obliges the person in charge to assist when it is not sufficiently precise; section 33 makes access free of charge, subject to reasonable fees for transcription, reproduction or transmission whose approximate amount must be given before proceeding.
- ss. 27 and 28
Access and rectification
On request, the business must confirm that information exists and communicate it, allowing a copy to be obtained. Section 27 goes further than access: computerised information collected FROM the applicant — not created or inferred from information concerning them — must, on request, be communicated “in a structured, commonly used technological format”, unless this raises serious practical difficulties. That is the portability right, and it is the clause that bears most directly on a tool vendor. Section 28 adds rectification of information that is inaccurate, incomplete or equivocal, or whose collection, communication or retention is not authorized by law.
- Guide de la CAI
How to document an impact assessment
The statute requires the assessment but does not dictate its form. The Commission d'accès à l'information publishes a companion guide to the exercise and its documentation — that is the regulator's expectation, and the document we follow.
This page is a reading summary, not legal advice, and it replaces neither the official text nor your own counsel. Every point links to the source so you can verify rather than take our word for it.
What changes when you add AI
Adopting an AI platform creates no new obligations: it triggers the ones that already existed, all at once. It is an information-system project (s. 3.3), so an impact assessment applies. The request is usually computed outside Quebec, so section 17 applies. The vendor is a service provider, so section 18.3 requires a written contract naming the measures. And if the model's output decides anything on its own, section 12.1 applies.
- An AI project is an information-system project — the s. 3.3 assessment is not optional.
- Location is not prohibited by the statute; what is required is the s. 17 assessment, and documenting it.
- The AI vendor is a service provider under s. 18.3: written contract, measures stated.
- A decision made exclusively by the machine triggers the notice obligation in s. 12.1.
- Training on your content is not a purpose the person consented to — check the clause.
And concretely, with us?
The rest of this page answers requirement by requirement for an ordinary business: the text quoted, what it imposes, what we deliver, and the gap where there is one. If a regulator sits on top of that — finance, insurance, law, health, accounting, the public sector, the professional orders — its own page runs the same exercise with its own requirements.
Federally, there is no AI statute
This is the question that comes right after "do we have to host in Québec". The answer, as of 5 September 2026: no federal law governs artificial intelligence in Canada. What binds you is Law 25 if you operate in Québec, PIPEDA federally, your sector regulator if you have one — and, if your outputs are used in the European Union, the EU AI Act. The absence of a federal statute is not an absence of rules; it is a reason to read the four points below rather than a headline.
AIDA died on the Order Paper
Bill C-27, the Digital Charter Implementation Act, 2022, contained the Artificial Intelligence and Data Act. It never got past committee study and it died on the Order Paper when Parliament was prorogued on 6 January 2025. It has not been reintroduced, and no federal AI bill has replaced it since.
Bill C-36 reforms privacy, not AI
Tabled on 15 June 2026 by the Minister of Artificial Intelligence and Digital Innovation, C-36 would enact the Protecting Privacy and Consumer Data Act and replace parts of PIPEDA. Two things to hold on to: it is not an AI statute, and it is not yet law — it stands at second reading in the House.
PIPEDA applies, but little of it in Québec
The federal private-sector privacy act remains in force. A 2003 exemption order nonetheless lifts its application from Québec organisations for their activities within the province, Law 25 being considered substantially similar. What stays federal: information crossing a provincial or national border, and federally regulated businesses — banks, telecommunications, interprovincial transport.
The ISED code is voluntary
The Voluntary Code of Conduct on the Responsible Development and Management of Advanced Generative AI Systems, launched in September 2023, binds its signatories by adherence, not by law. Signing it creates no enforceable obligation; not signing it is not an offence. It is a useful reference in a tender, and it must not be presented to a regulator as compliance.
The European regulation can reach you from Québec
Regulation (EU) 2024/1689 applies to providers and deployers established in a third country where the output of the system is used in the Union. A Québec SMB with no European office can therefore fall within it purely because a deliverable produced with AI goes to a European client. The corresponding requirements appear further down this page.
A federal AI statute has been announced since 2022 with no text in force. We date this reading rather than presenting it as settled: check the status of the bills on LEGISinfo before relying on it.
Who regulates you
The bodies whose requirements apply to you.
- CAICommission d'accès à l'information du Québec
Oversees the application of the Act, investigates, issues orders, and imposes monetary administrative penalties. It is the body that receives your incident notifications and that can demand your register.
- P-39.1Act respecting the protection of personal information in the private sector (CQLR c P-39.1)
The applicable statute, deeply amended by Law 25. The last provisions came into force on 22 September 2023, except the right to portability, in force since 22 September 2024.
- OPCOffice of the Privacy Commissioner of Canada
Federal PIPEDA applies in parallel to your interprovincial and international activities. Its accountability principle requires a comparable level of protection at any third party you entrust with information.
- GDPRCompetent supervisory authority (GDPR)
If your business processes data belonging to people located in the European Union or the European Economic Area — customers, remote employees, partners — the GDPR applies alongside Law 25. The one-stop-shop mechanism designates a lead supervisory authority when you have a main establishment in the EU; without an EU establishment, each national authority concerned by the processing can act directly against you.
Requirement by requirement
Each requirement is quoted from its source, then answered.
Act respecting the protection of personal information in the private sector, CQLR c P-39.1, s. 10
Toute personne qui exploite une entreprise doit prendre les mesures de sécurité propres à assurer la protection des renseignements personnels collectés, utilisés, communiqués, conservés ou détruits et qui sont raisonnables compte tenu, notamment, de leur sensibilité, de la finalité de leur utilisation, de leur quantité, de leur répartition et de leur support.- What it means
- The standard is proportionate: the more sensitive the information, the stronger the expected measure. Law 25 didn't touch this section, but it gave it teeth — failing to take those measures became a distinct penal offence (s. 91, para. 4).
- What we answer
- A dedicated instance in Canada, encryption at rest and in transit — the Azure platform's, with Microsoft-managed keys, not a key of your own — a key vault with role-based control for integration secrets, per-object rights, an audit log, and a contract committing to administrative, technical and organisational measures (cl. 14.5). Section 10 asks for reasonable, proportionate measures, not for a certification: the audit right in clause 14.10 lets you check them yourself.
hard law2006, not amended by Law 25Official source
Act respecting the protection of personal information in the private sector, CQLR c P-39.1, s. 3.3
Toute personne qui exploite une entreprise doit procéder à une évaluation des facteurs relatifs à la vie privée de tout projet d'acquisition, de développement et de refonte de système d'information ou de prestation électronique de services impliquant la collecte, l'utilisation, la communication, la conservation ou la destruction de renseignements personnels. […] La personne doit également s'assurer que ce projet permet qu'un renseignement personnel informatisé recueilli auprès de la personne concernée soit communiqué à cette dernière dans un format technologique structuré et couramment utilisé.- What it means
- Adopting an AI platform is the acquisition of an information system: the Commission expressly places the “artificial intelligence system” among the forms an information system takes (PIA Guide v3.1, § 7.2, p. 51). The assessment is therefore mandatory for the project — not “before the project”, but before it goes live, with your privacy officer consulted from the very start of the project (para. 2). The third paragraph, often forgotten, adds a design requirement: at the time you acquire the system, you must make sure it will be able to return to an individual, in a structured, commonly used technological format, the computerized information collected from them.
- What we answer
- The PIA is yours — the Act puts it on the enterprise, not on the vendor. We supply the inputs: description of the data flow, categories transferred outside Quebec, hosting regions, published policies of the model providers, security measures, contractual commitments and this page. The contract expressly provides that we cooperate in documenting those assessments (cl. 14.8). On the third paragraph, though, we do not put you in a position to answer yes: the export exists (conversations, documents, knowledge bases) but is not normalized into a structured interchange format. That is a gap on our side, to be recorded as such in your assessment.
hard lawIn force 22 September 2023Official source
Act respecting the protection of personal information in the private sector, CQLR c P-39.1, s. 17
Avant de communiquer à l'extérieur du Québec un renseignement personnel, la personne qui exploite une entreprise doit procéder à une évaluation des facteurs relatifs à la vie privée. […] La communication peut s'effectuer si l'évaluation démontre que le renseignement bénéficierait d'une protection adéquate […]. Elle doit faire l'objet d'une entente écrite.- What it means
- Contrary to a widespread belief, section 17 does not prohibit data from leaving Quebec and imposes no localization rule. It imposes three things: a prior assessment weighing four factors, a conclusion that protection is adequate, and a written agreement. Its third paragraph expressly covers the case where you entrust a third party outside Quebec with storing or processing on your behalf — which is exactly what a cloud AI platform is.
- What we answer
- The hosting itself is already caught, and that is the point most readers miss: your instance runs in the Azure Canada Central region by default, that is, in Toronto — in Canada, but outside Quebec. Entrusting us with storing your information on your behalf therefore falls under the third paragraph, and inference at the model providers, several of them in the United States, under the first. Your assessment, your adequate-protection conclusion and your written agreement have to cover both, not only the model call. What leaves at run time: the content of the request, for the duration of the computation, and the full text of documents added to a knowledge base, sent at indexing time to be embedded. We deploy a Quebec region under private hosting only — but let us be exact, because the opposite sentence used to sit here: that does NOT take hosting out of the scope of section 17. Database backups are geo-replicated to the paired region — Canada East, in Quebec City — therefore inside the province, while the instance itself is in Toronto; the files you upload are not replicated outside your instance's region. The host's residency commitment is to Canada in any case, not to the province. So the third paragraph stays engaged even in Canada East; what the region brings closer is the day-to-day processing, not the legal perimeter. Inference stays in scope too. The written agreement exists: it is clause 14 of the master agreement — but the second paragraph wants one that TAKES ACCOUNT OF THE RESULTS of your assessment, which we cannot know in advance. If yours concludes that particular measures are called for, they are recorded in an addendum; clause 14 on its own does not suffice. The adequate-protection conclusion is yours: we give you the elements, you make the judgment. We do not guarantee by default that inference stays in Canada.
hard lawIn force 22 September 2023Official source
Act respecting the protection of personal information in the private sector, CQLR c P-39.1, s. 18.3
Une personne qui exploite une entreprise peut, sans le consentement de la personne concernée, communiquer un renseignement personnel à toute personne ou à tout organisme si cette communication est nécessaire à l'exercice d'un mandat ou à l'exécution d'un contrat de service ou d'entreprise qu'elle confie à cette personne ou à cet organisme.- What it means
- This is the provision that answers “do I have to redact before using AI”. Read precisely what it does, and nothing more: it sets aside THE CONSENT of the individual concerned for a communication to a mandatary or to the party performing a service or enterprise contract. The rest of the Act stands — section 10 (security), section 12 (the purpose of use within the enterprise), sections 3.3 and 17 (the two assessments) and sections 3.5 to 3.8 (incidents). It also carries its own threshold, in the sentence quoted: the communication is permitted only where it “is necessary for the performance of a mandate or a contract”. That is a minimization requirement, not a blank cheque. In return, the second paragraph requires the mandate or the contract to be conferred in writing and to set out the confidentiality, use-limitation and no-retention-after-expiry measures; the prompt notice of any violation and the audit right, for their part, are imposed on the performing party directly by the Act — it is not for the contract to create them.
- What we answer
- The six elements are in our contract: written and signed; security measures (cl. 14.5, 14.6); use limited to enumerated purposes (cl. 14.2); deletion after the transition period (cl. 14.11); prompt notice to the officer (cl. 14.9); audit right (cl. 14.10). The clause-by-clause mapping is higher up this page. What this really settles: you do not need your clients' or your employees' consent to entrust us with their information — a compliant contract stands in for that consent. What it does not settle: section 12 requires the use to serve the purpose of collection, section 18.3 covers only what is necessary to the mandate, and the Commission, which co-developed the 7 December 2023 Canadian principles on generative AI, asks user organizations to use anonymized or de-identified information in prompts where that is possible and reasonable. The honest conclusion: redacting is not a general obligation, but “redact nothing” is not the rule either — it is a judgement to make request by request, and to write into your internal policy.
hard lawIn force 22 September 2023Official source
Act respecting the protection of personal information in the private sector, CQLR c P-39.1, ss. 3.5 to 3.8
Si l'incident présente un risque qu'un préjudice sérieux soit causé, elle doit, avec diligence, aviser la Commission d'accès à l'information […]. Elle doit également aviser toute personne dont un renseignement personnel est concerné par l'incident, à défaut de quoi la Commission peut lui ordonner de le faire.- What it means
- An incident isn't only a hack: section 3.6 covers any access to, use or communication of information not authorized by law, and the simple loss of information. The notification threshold is the “risk of serious injury”, assessed on the sensitivity of the information, the anticipated consequences of its use and the likelihood that it will be used for a harmful purpose (s. 3.7). The register, by contrast, is unconditional and comes from a different section: “a person carrying on an enterprise must keep a register of confidentiality incidents” (s. 3.8, para. 1), a copy of which is sent to the Commission on request. The operational detail sits in the Regulation respecting confidentiality incidents (CQLR, c. A-2.1, r. 3.1, in force 29 December 2022): eleven mandatory elements in the notice to the Commission (s. 3), the content of the notice to the individuals concerned (s. 5), the eight elements of the register (s. 7) and its retention for at least five years after the incident became known (s. 8).
- What we answer
- The contract obliges us to notify your designated officer without delay, with the nature of the incident, the persons concerned, the period and the measures taken (cl. 14.9) — with no commitment expressed in hours. Notifying the Commission, notifying the individuals concerned and keeping the register remain your obligations. One nuance that matters: your obligations stay yours, but ours do not disappear for that. We ourselves carry on an enterprise subject to Law 25 for the information we hold, and section 1 of the Regulation respecting confidentiality incidents covers “any person carrying on an enterprise who is subject to the Act respecting the protection of personal information in the private sector”: our own notification and register obligations stack with yours instead of replacing them. Our response plan exists but has never been exercised, and we say so.
hard lawIn force 22 September 2022Official source
Act respecting the protection of personal information in the private sector, CQLR c P-39.1, s. 12.1
Toute personne qui exploite une entreprise et qui utilise des renseignements personnels afin que soit rendue une décision fondée exclusivement sur un traitement automatisé de ceux-ci doit en informer la personne concernée au plus tard au moment où elle l'informe de cette décision.- What it means
- The trigger is the word “exclusively”. An AI that drafts a letter, suggests a classification or summarizes a file renders no decision: a human decides. An AI wired into an automation that denies, prices or sorts with no human intervention, yes. What the individual gets then is narrower than is commonly said. As of right: to be informed that the decision exists, no later than when it is announced to them (para. 1), and to be given “the opportunity to submit observations to a member of the personnel of the enterprise who is in a position to review the decision” (para. 3) — a right to be heard, not a right to have the decision reviewed. On request only (para. 2): the information used, the reasons as well as the principal factors and parameters, and the right to have that information corrected. Read it with section 11: information used to make a decision must be up to date and accurate when it is used, and is kept for at least one year after the decision.
- What we answer
- The platform drafts, summarizes and suggests; it doesn't render decisions on its own. But it can automate, and you're the one building those automations. If one of them decides on its own, section 12.1 applies to you. The contract says so in its own words: no generated output may be a final automated decision without appropriate human validation (cl. 17 of the contract).
hard lawIn force 22 September 2023Official source
Act respecting the protection of personal information in the private sector, CQLR c P-39.1, s. 23
Lorsque les fins auxquelles un renseignement personnel a été recueilli ou utilisé sont accomplies, la personne qui exploite une entreprise doit le détruire ou l'anonymiser pour l'utiliser à des fins sérieuses et légitimes, sous réserve d'un délai de conservation prévu par une loi. […] un renseignement concernant une personne physique est anonymisé lorsqu'il est, en tout temps, raisonnable de prévoir dans les circonstances qu'il ne permet plus, de façon irréversible, d'identifier directement ou indirectement cette personne.- What it means
- Keeping information isn't neutral: once the purpose is achieved, it must be destroyed or anonymized. Two turns of phrase that are often skipped change everything, though. “To use it for serious and legitimate purposes”: you don't anonymize for the sake of anonymizing — the intended use has to be established before the process is started (Regulation respecting the anonymization of personal information, O.C. 783-2024, s. 3). “Subject to a retention period provided for by an Act”: section 11, para. 2, for instance requires information used to make a decision to be kept for at least one year — deleting too fast is a failure too. And anonymization is a formal process, not a checkbox: supervision by a competent person (s. 4), removal of direct identifiers then a preliminary analysis of re-identification risk against the individualization, correlation and inference criteria (s. 5), a post-process analysis demonstrating “very low” residual risk (s. 7), periodic re-assessment (s. 8) and a register (s. 9). Information that is merely de-identified is not anonymized: it remains personal information (s. 12, para. 4, subpara. 1).
- What we answer
- You can delete conversations, documents and knowledge bases, and confidentiality mode makes a conversation ephemeral. Three of the product's timers that cannot be switched off bound what lingers (30 days, 7 days, 48 hours), but there is no configurable retention: you cannot set “destroy at 24 months” per workspace. We issue no certificate of destruction, and we document no purge delay for backups — and this must not be confused with the 30-day restore window or the 14-day snapshots mentioned elsewhere: those are recovery capabilities, not a commitment to destroy, and section 23 bears precisely on what survives in a backup — ask us before you commit to a destruction schedule, because an incomplete destruction within the meaning of section 23 is the one that survives in a backup. The platform anonymizes nothing within the meaning of section 23: the compliance scans retrospectively surface exchanges containing personal information so you can act on them, which is a signal, not an anonymization process. Those are the timers that reach a record; other clocks exist elsewhere in the product, and the Confidentiality and compliance page publishes the full inventory.
hard lawIn force 22 September 2023Official source
Act respecting the protection of personal information in the private sector, CQLR c P-39.1, s. 12
Un renseignement personnel ne peut être utilisé au sein de l'entreprise qu'aux fins pour lesquelles il a été recueilli, à moins du consentement de la personne concernée. Ce consentement doit être manifesté de façon expresse dès qu'il s'agit d'un renseignement personnel sensible. Un renseignement personnel peut toutefois être utilisé à une autre fin sans le consentement de la personne concernée dans les seuls cas suivants: 1° lorsque son utilisation est à des fins compatibles avec celles pour lesquelles il a été recueilli; […]- What it means
- Section 18.3 settles the COMMUNICATION to the vendor; section 12 settles the USE inside the enterprise, and it is the one that decides whether you may put a client file or an employee file into an assistant. The rule is the purpose of collection. Departing from it is allowed only in five exhaustively listed cases — a consistent purpose, the clear benefit of the individual, the prevention and detection of fraud or the improvement of security measures, the supply of a product or the provision of a service requested, and study or research on de-identified information — or with the individual's consent, express if the information is sensitive. And a purpose is only “consistent” if it has a direct and relevant connection with the purpose of collection (para. 3). It is this section, more than section 18.3, that answers “can I put this file into the tool”.
- What we answer
- That characterization is structurally yours: we have no visibility on the purpose for which you collected a file. What the platform gives you are the means to enforce it — per-user and per-group access, knowledge-base partitioning, confidentiality mode, an audit log, and the Law 25 detection that flags message by message the presence of personal information (a paid option, off by default, and itself an outbound call to a model). Those are instruments of control and of proof, not compliance: if the intended use does not serve the purpose of collection and falls into no exception, no setting on our side makes it lawful. Deciding which kinds of files are allowed into the tool is an internal policy, written down, not a parameter.
hard lawIn force 22 September 2023Official source
Act respecting the protection of personal information in the private sector, CQLR c P-39.1, s. 8, para. 2
Le cas échéant, la personne concernée est informée du nom du tiers pour qui la collecte est faite, du nom des tiers ou des catégories de tiers à qui il est nécessaire de communiquer les renseignements aux fins visées au paragraphe 1° du premier alinéa et de la possibilité que les renseignements soient communiqués à l'extérieur du Québec.- What it means
- The timing of that information is what makes it binding: it is given AT THE TIME OF COLLECTION, and afterwards on request. A business that plugs its files into a platform whose hosting and inference leave Quebec therefore had to have announced, in its collection notice and its privacy policy, the categories of third-party recipients and the possibility that the information be communicated outside Quebec. A flawless contract signed after the fact and a complete assessment do not repair information that was never given: these are two distinct obligations, and this one is judged as at the date of collection.
- What we answer
- We cannot do anything about this in your place, and it is the kind of gap that gets discovered late. What we provide so you can fix your texts: the list of our hosting and inference subprocessors, the regions where they operate, and the categories of information that leave Quebec. It is up to you to revisit the collection notice, the privacy policy and, for your employees, the hiring documentation, so that they name the categories of third parties and the possibility of a communication outside Quebec. For information already collected under a notice that was silent on the point, whether the intended use is still possible is a question under section 12, not under section 18.3.
hard lawIn force 22 September 2023Official source
Act respecting the protection of personal information in the private sector, CQLR c P-39.1, s. 27, para. 3 and s. 3.3, para. 3
À moins que cela ne soulève des difficultés pratiques sérieuses, un renseignement personnel informatisé recueilli auprès du requérant, et non pas créé ou inféré à partir d'un renseignement personnel le concernant, lui est, à sa demande, communiqué dans un format technologique structuré et couramment utilisé.- What it means
- The right to portability is not a European peculiarity: it has been in force in Quebec since 22 September 2024 and is exercised with no European dimension at all, by any client or employee. Its scope is bounded — it covers what was collected FROM the individual, not what was created or inferred about them, so an AI output concerning them falls outside it (it stays accessible under paragraph 1, as a plain copy). And section 3.3, para. 3, turns it into a design requirement: it is before you sign, at the time of acquisition, that you must make sure the system will allow it.
- What we answer
- We do not meet this requirement today, and it is better read here than discovered on an access request. Conversations, documents and knowledge bases export in full, per user — but the export is not normalized into a structured, commonly used interchange format. In practice you would answer with an intelligible transcription (which paragraph 2 allows), not with a structured file. It is the same gap named on the GDPR side at article 20; we count it once, not twice, and we do not announce it as solved.
hard lawIn force 22 September 2024 (s. 27, para. 3); 22 September 2023 (s. 3.3, para. 3)Official source
Act respecting the protection of personal information in the private sector, CQLR c P-39.1, ss. 90.1, 90.12, 91 and 93.1
Le montant maximal de la sanction administrative pécuniaire est de 50 000 $ dans le cas d'une personne physique et, dans les autres cas, de 10 000 000 $ ou du montant correspondant à 2% du chiffre d'affaires mondial de l'exercice financier précédent si ce dernier montant est plus élevé.- What it means
- The failures described on this page are exactly the ones section 90.1 makes liable to a monetary administrative penalty: failing to inform individuals in accordance with sections 7 and 8, collecting or using information in contravention of the Act, failing to report an incident, failing to take the security measures of section 10, failing to inform the person subject to an automated decision or to give them the opportunity to submit observations (s. 12.1). The ceiling is the one in the sentence quoted. Alongside it, the penal route in section 91 runs from $5,000 to $100,000 for a natural person and from $15,000 to $25,000,000 — or 4% of worldwide turnover if that is higher — in other cases, with the amounts doubled for a repeat offence (s. 92.1). And section 93.1 opens punitive damages of at least $1,000 where an unlawful infringement is intentional or results from gross fault: that is the lever behind class actions, and often the most concrete line of risk for a business whose clients number in the thousands.
- What we answer
- This risk does not transfer by contract: an administrative penalty or a fine strikes the party in default, and no vendor indemnity clause erases it. What we can act on is probability and proof: encryption in transit and at rest, per-user and per-group access, an audit log — whose console CSV export covers only the 50-row page on screen, personal-information detection message by message (a paid option, off by default, and itself an outbound call to a model), prompt notice in the event of an incident (cl. 14.9) and an annual audit right (cl. 14.10) — enough to document the diligence the Commission examines under its general framework for applying penalties. We do not sell compliance insurance, and you should be wary of anyone who does.
hard lawIn force 22 September 2023Official source
Réaliser une évaluation des facteurs relatifs à la vie privée — Guide d'accompagnement à la démarche et à sa documentation, version 3.1
Dans les autres cas, il n'est pas nécessaire de transmettre proactivement un rapport d'EFVP à la Commission. Celle-ci pourrait toutefois demander à en prendre connaissance dans le cadre de ses activités de surveillance.- What it means
- The Commission publishes a sixty-page guide that structures the PIA and, above all, its documentation. It's the reference an investigator will rely on to judge whether your assessment held up. § 1.1 (p. 11) lists the situations where the assessment is mandatory; § 7.1 (p. 49) deals with information leaving Quebec; § 7.2 (p. 51) places the “artificial intelligence system” among the forms an information system takes. The report itself does not have to be filed with the Commission outside the cases where the assessment precedes an agreement (p. 43 and § 5.4), but the process must exist and be producible.
- What we answer
- Two PIAs trigger at the same time when you adopt an AI platform: the section 3.3 one for acquiring the system, and the section 17 one for hosting and processing outside Quebec. They can live in a single document. If the GDPR covers you as well, count three: its article 35 impact assessment adds itself, with its own requirements. Ask us for the input kit: data flow, categories transferred, regions, provider policies, matching contractual clauses.
regulator expectationApril 2024Official source
Principles for responsible, trustworthy and privacy-protective generative AI technologies — federal, provincial and territorial privacy authorities of Canada, including the Commission d'accès à l'information, section 7
lorsque possible et raisonnable, utiliser des renseignements anonymisés ou dépersonnalisés dans les requêtes d'un système d'IA générative plutôt que des renseignements personnels; lorsque des renseignements personnels (et, en particulier, des renseignements sensibles ou confidentiels) doivent être entrés dans une requête, ne le faire que si cela est autorisé- What it means
- It is the only published document that bears directly on the subject of this page, and the Commission co-developed it: its own PIA Guide points to it as the “principles document developed by the Commission and its Canadian counterparts”. It is not hard law — the document says “should” — but it is the position an investigator will confront you with. Read the recommendation as it is written: neither “redact everything”, nor “redact nothing”. It asks you to use anonymized or de-identified information in the prompts sent to a generative AI system where that is possible and reasonable, and to enter personal information into a prompt only where doing so is authorized. The same section asks you to treat inferences produced about an identifiable individual as personal information, and not to retain prompts for secondary purposes.
- What we answer
- We do not de-identify your prompts: there is no pseudonymization gateway between your users and the model, and that is a choice we would rather state than let you guess. What the platform offers to apply this expectation: confidentiality mode, which makes a conversation ephemeral; the Law 25 detection, which flags message by message the presence of personal information and gives you the measure of the phenomenon rather than an impression — but you have to see what it costs here: it is a paid option, off by default, and the detection is itself an outbound call that sends the text of the message to a model. As a minimization measure, it increases exposure before measuring it; per-user and per-group access, which limits who can submit what; and three of the product's timers that cannot be switched off (30 days, 7 days, 48 hours) which bound how long traces live — but no configurable retention and no certificate of destruction. The act of de-identifying, where it is possible and reasonable, stays with your users; we supply the signal and the log that let you verify they are doing it. Those are the timers that reach a record; other clocks exist elsewhere in the product, and the Confidentiality and compliance page publishes the full inventory.
regulator expectation7 December 2023Official source
Personal Information Protection and Electronic Documents Act (S.C. 2000, c. 5), Schedule 1, principle 4.1.3; Organizations in the Province of Quebec Exemption Order (SOR/2003-374)
Une organisation est responsable des renseignements personnels qu'elle a en sa possession ou sous sa garde, y compris les renseignements confiés à une tierce partie aux fins de traitement. L'organisation doit, par voie contractuelle ou autre, fournir un degré comparable de protection aux renseignements qui sont en cours de traitement par une tierce partie.- What it means
- PIPEDA does not disappear because you are in Quebec: order SOR/2003-374 exempts a Quebec business only “with respect to the collection, use and disclosure of personal information that occurs within the Province of Quebec”, and never covers federal works and undertakings. Flows that cross the provincial border — hosting in Toronto, inference in the United States, a client or an employee in another province — stay within federal scope, in parallel with Law 25. What the principle quoted adds is simple and demanding: entrusting information to a third party for processing does not transfer accountability, and you must provide a COMPARABLE level of protection, by contractual or other means. The contract is therefore the means, not the end.
- What we answer
- The commitments in clause 14 of the master agreement are precisely the “contractual means” principle 4.1.3 calls for: enumerated purposes, subprocessors, security measures, incident notice, an annual audit right. Two limits to state. First, “comparable” is argued on the contract and not on the legal regime when inference happens at providers established outside Quebec, several of them in the United States: that is a conclusion you must be able to defend, not a box ticked. Second, we produce no third-party attestation; the audit right in clause 14.10 is what you have instead, and it is worth nothing unless you exercise it.
hard lawPIPEDA assented to in 2000; exemption order in force 19 November 2003Official source
Regulation (EU) 2016/679 (GDPR), art. 28
Processing by a processor shall be governed by a contract or other legal act under Union or Member State law, that is binding on the processor with regard to the controller...- What it means
- If you process data belonging to people in the EU/EEA and entrust that processing to us, a data processing agreement (DPA) separate from our master agreement is required: documented instructions, staff confidentiality, the article 32 security measures, authorized use of sub-processors, assistance with data subject rights, breach notification, and deletion or return of data at the end of the contract.
- What we answer
- We do not yet offer a GDPR-compliant DPA (article 28 clauses) in our standard catalogue. That is a gap we name rather than pretend otherwise. If your use touches data belonging to people in the EU or the EEA, tell us before you sign: we will assess with you whether an addendum can be negotiated, with no commitment on our part until it is signed. They are negotiated at the order form, case by case; productising them is not scheduled.
hard lawIn force since 25 May 2018Official source
Regulation (EU) 2016/679 (GDPR), art. 32
Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the controller and the processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including inter alia as appropriate: (a) the pseudonymisation and encryption of personal data […]- What it means
- Article 32 explicitly names encryption, the ability to restore availability after an incident, and a process for regularly testing security measures. The expected level depends on the risk to the individuals concerned, not on a single fixed standard.
- What we answer
- Encryption at rest and in transit, role-based access control, an audit log and a continuity plan are part of the architecture described on this page — the same measures assessed for Law 25. Article 32 asks for measures appropriate to the risk, and the audit right in clause 14.10 lets you audit them rather than believe them. But article 32 names a fourth element we do not satisfy: “a process for regularly testing, assessing and evaluating the effectiveness” of the measures. Our incident-response plan is written and publishes its severity tiers, but it has never been exercised; nor do we have documented recovery time and recovery point objectives proven by a restore drill. A plan never exercised is a hypothesis, and the audit right in s. 14.10 lets you establish that — it does not stand in for the testing the article requires of us.
hard lawIn force since 25 May 2018Official source
Regulation (EU) 2016/679 (GDPR), arts. 15 to 21
The data subject shall have the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed...- What it means
- Access, rectification, erasure, restriction, portability and objection: six distinct rights, each with its own conditions and deadlines — objection sits in article 21, outside the 15-to-20 range, and article 19, which is inside it, adds the duty to communicate any rectification, erasure or restriction to each of the recipients. As the controller, you are the one who answers the data subject — but you need your processor to be able to locate and produce their data.
- What we answer
- Conversations, documents and knowledge bases export and delete, per user, and a message can be corrected in place with an entry in the audit log. The export serves the article 20 portability right; it is not normalized into a structured interchange format. Do not file this gap on the European side alone: the same failing touches Quebec law — section 27, para. 3 of Law 25, in force since 22 September 2024, and section 3.3, para. 3, which asks you to make sure of it before you even acquire the system.
hard lawIn force since 25 May 2018Official source
Regulation (EU) 2016/679 (GDPR), Chapter V, arts. 44 to 49; standard contractual clauses (Commission Implementing Decision (EU) 2021/914)
Any transfer of personal data which are undergoing processing or are intended for processing after transfer to a third country or to an international organisation shall take place only if, subject to the other provisions of this Regulation, the conditions laid down in this Chapter are complied with by the controller and processor, including for onward transfers of personal data from the third country or an international organisation to another third country or to another international organisation.- What it means
- The end of the sentence quoted is the rule that matters here: Chapter V follows ONWARD transfers, not only the first hop. Canada holds a PARTIAL European Commission adequacy decision (Decision 2002/2/EC, maintained at the January 2024 review): it covers only private organizations actually subject to PIPEDA, which, for a Quebec host, does not go without saying and is verified rather than presumed — order SOR/2003-374 exempts from PIPEDA the collection, use and disclosure that occur within Quebec. The next hop, to a model provider outside the EU, needs its own basis: standard contractual clauses, or, for a certified US provider, the EU–US adequacy decision (Data Privacy Framework) of 10 July 2023.
- What we answer
- We do not yet offer signed standard contractual clauses in our standard catalogue. This is a direct gap for any EU/EEA personal data passing through our platform, and we would rather tell you now than have you find out in due diligence. Talk to us about your specific need: the solution depends on the nature of the transfer.
hard lawIn force since 25 May 2018; standard clauses of 4 June 2021Official source
Regulation (EU) 2016/679 (GDPR), art. 33
In the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the supervisory authority competent in accordance with Article 55, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where the notification to the supervisory authority is not made within 72 hours, it shall be accompanied by reasons for the delay.- What it means
- Seventy-two hours, but not an unconditional deadline: the obligation falls away if the breach is unlikely to result in a risk to rights and freedoms, and a late notification must be accompanied by the reasons for the delay. Compared with section 3.5 of Law 25, on this same page, the GDPR is stricter twice over: on the deadline (72 hours against “with diligence”) and on the threshold (a mere risk, against a “risk of serious injury”). The processor, for its part, notifies the controller “without undue delay” (para. 2), which lets the controller's clock start on time. And article 33 is only the first move: if the risk is HIGH, article 34 additionally requires the breach to be communicated to the data subjects, without undue delay.
- What we answer
- The contract obliges us to notify you without delay, with the nature of the incident, the people affected, the period and the measures taken (cl. 14.9) — but with no stated number of hours. For processing subject to the GDPR, this is a clause to negotiate explicitly in the order form: a commitment measured in hours, not just “without delay”.
hard lawIn force since 25 May 2018Official source
Regulation (EU) 2016/679 (GDPR), art. 35 and art. 30
Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data.- What it means
- If the GDPR covers you, it is not two assessments that trigger but three: the two Quebec PIAs, plus the article 35 impact assessment. A generative AI platform applied to client or employee files is the textbook case — new technologies and high risk — and paragraph 3 of the same article targets in particular systematic evaluation based on automated processing and large-scale processing of special categories of data. Its permanent counterpart is article 30: a record of processing activities, kept up to date, in which adding the platform creates an entry — purposes, categories of data subjects and of data, recipients, transfers outside the EU, erasure deadlines. It is the first document a supervisory authority asks for.
- What we answer
- The impact assessment and the record are yours; we supply the same inputs as for the Quebec PIA — data flow, categories transferred, hosting regions, inference subprocessors and their published policies, security measures, matching contractual clauses. Three facts to enter as such in your record, because they are counter-intuitive: the retention timers (30 days, 7 days, 48 hours) cannot be switched off, there is no configurable retention beyond them, and the export is not normalized into a structured interchange format. A useful reminder: without a processing agreement compliant with article 28, the impact assessment will conclude to a gap — we name it elsewhere on this page rather than let it slip here. Those are the timers that reach a record; other clocks exist elsewhere in the product, and the Confidentiality and compliance page publishes the full inventory.
hard lawIn force since 25 May 2018Official source
Regulation (EU) 2016/679 (GDPR), art. 22
The data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her.- What it means
- Do not read this article as a twin of section 12.1 of Law 25. Section 12.1 is an INFORMATION obligation: it presupposes that the decision may be made. Article 22 is a prohibition in principle, escaped only through one of the three exceptions in paragraph 2 — contractual necessity, authorization by Union or Member State law, explicit consent — and, in the contractual and consent cases, by putting in place safeguards including at least human intervention on the controller's part, the expression of the data subject's point of view and the ability to contest the decision. Paragraph 4 closes the door almost entirely on special categories of data. The question is therefore not “did I inform?” but “am I allowed to make this decision this way?”.
- What we answer
- The platform drafts, summarizes and suggests; it doesn't render decisions on its own. But it can automate, and you're the one building those automations — if one of them decides on its own about a person located in the EU, you must first establish your basis under paragraph 2, then demonstrate the safeguards of paragraph 3. On that last point, be warned: we offer no tooled “human intervention” workflow — no review queue, no standardized trace of a human re-examination. What the contract sets is a legal guardrail, not a technical one: no generated output may be a final automated decision without appropriate human validation (cl. 17 of the contract).
hard lawIn force since 25 May 2018Official source
Regulation (EU) 2016/679 (GDPR), art. 27
Where Article 3(2) applies, the controller or the processor shall designate in writing a representative in the Union.- What it means
- This is the immediate consequence of the situation described elsewhere on this page — being caught by the GDPR without an establishment in the Union. The designation is IN WRITING, the representative is established in one of the Member States where the data subjects are, and you must have one before the processing, not after a first request. The exception in paragraph 2 is narrow: occasional processing, with no large-scale processing of special categories and no risk to rights and freedoms. Putting European client files into an AI platform is nothing like occasional. The obligation bears on the controller and on the processor alike, so on you and on us, each for ourselves.
- What we answer
- We have no establishment in the Union and we have designated no representative within the meaning of article 27. That is a gap on our side, and it joins the two others we already name: no article 28-compliant processing agreement in the catalogue, no signed standard contractual clauses. If your use touches people located in the EU or the EEA, treat those three shortfalls as one and the same project and talk to us about it before you sign, not after. On your side, designating a representative is a separate step, which is yours and which nobody can take for you.
hard lawIn force since 25 May 2018Official source
Act respecting the protection of personal information in the private sector, CQLR c P-39.1, s. 5
La personne qui recueille des renseignements personnels sur autrui ne doit recueillir que les renseignements nécessaires aux fins déterminées avant la collecte. Ces renseignements doivent être recueillis par des moyens licites.- What it means
- This is the counterweight the redaction question needs. Section 18.3 removes the duty to redact before handing information to a service provider; it does not remove the duty to collect less. The two sections answer different questions — 18.3 is about COMMUNICATION to a third party, section 5 is about COLLECTION — and the purposes must be determined BEFORE collection, not justified afterwards.
- What we answer
- Beware a common shortcut: “you do not have to redact” does not mean “put everything in.” What the platform offers at the margin: the Law 25 detector flags personal information, secrets and passwords message by message, and confidentiality mode makes an exchange ephemeral. Two reservations that matter here: the detector is a paid option, off by default, and it is itself an outbound call to a model chosen by price. Above all, nothing in the product decides what is necessary for your purpose. That judgement is yours, and it comes before the tool.
hard lawText read current to 1 April 2026Official source
Act respecting the protection of personal information in the private sector, CQLR c P-39.1, s. 11
Toute personne qui exploite une entreprise doit veiller à ce que les renseignements personnels qu'elle détient sur autrui soient à jour et exacts au moment où elle les utilise pour prendre une décision relative à la personne concernée. Les renseignements utilisés pour prendre une telle décision sont conservés pendant au moins un an suivant la décision.- What it means
- Two duties in a single section, and the second surprises almost everyone. The first targets accuracy AT THE MOMENT of the decision: if a generative model invents a detail and that detail lands in the record behind a decision about the person, the section is breached — it bears on accuracy at the point of decision, not on the tool that produced the text. The second is a retention FLOOR: information used to make such a decision is kept for at least one year after it. That is a minimum duration, running the opposite way from the destruction rules found elsewhere in the Act.
- What we answer
- Accuracy is yours — we validate no content, and a model can state something false with confidence. What we supply so you can establish it: the conversation keeps the prompt, the attachments, the linked knowledge bases, the cited sources and the exact model, timestamped and attributed to an account, and all of it exports. The one-year floor, though, runs head-on into our product and it has to be said plainly: our clocks go the other way. Three hardcoded, non-disableable timers touch a record — transcriptions at 30 days, tool-produced files at 7 days, attachments uploaded but never sent at 48 hours — and none of them comes near twelve months. If a decision rested on a transcription, section 11 requires you to keep it for a year and our timer erases it on the thirtieth day. Export what founds a decision at the moment you make it: no setting extends these delays.
hard lawText read current to 1 April 2026Official source
Act respecting the protection of personal information in the private sector, CQLR c P-39.1, s. 16
Une personne qui détient des renseignements personnels pour le compte d'une personne qui exploite une entreprise peut, lorsqu'elle est saisie d'une demande d'accès ou de rectification par une personne concernée, référer la demande à la personne pour le compte de qui elle agit.- What it means
- This is the one section of the Act that describes OUR position rather than yours: that of someone holding information on another's behalf. It is permissive, not exculpatory — it settles WHO answers the request, not whether an answer is owed. The individual's right of access remains whole, and the section 32 deadline keeps running at your end.
- What we answer
- That is exactly our posture, and we would rather write it than leave it to be inferred: an access or rectification request that reached us is referred to your privacy officer, with our assistance — we do not answer in your place, and we will not pretend that entrusting the data to us discharges you. The means are there: conversations, documents and attachments export; a message is corrected in place and the change leaves an audit-log entry. What we do not have: a workflow tying a request to its correction and keeping proof of it. Over thirty days that is workable by hand, but the compliance trail is yours to build.
hard lawText read current to 1 April 2026Official source
Act respecting the protection of personal information in the private sector, CQLR c P-39.1, s. 20
Dans l'exploitation d'une entreprise, un renseignement personnel n'est accessible, sans le consentement de la personne concernée, à tout préposé ou agent de l'exploitant qui a qualité pour le connaître qu'à la condition que ce renseignement soit nécessaire à l'exercice de ses fonctions.- What it means
- Need-to-know, INSIDE the enterprise. The section is not about communication to a third party but about your own staff: access without consent presupposes two cumulative conditions — being qualified to know the information, and that information being necessary to the exercise of one's functions. A workspace where everyone sees everything does not satisfy it, even with no leak whatsoever to the outside.
- What we answer
- This is a section the product answers well, bar two settings. Every knowledge base, prompt, tool, form, automation and assistant carries its own rights, by user and by group, and nothing is visible organisation-wide by default. The defaults to correct at deployment: sharing OUTSIDE your organisation is on by default, with no domain list imposed at the outset — anonymous public links, for their part, are off — so set the ceiling and the invitable domains. And one limit of the log, because it bears precisely on this section: administrative acts, impersonations and administrator peeks are logged, but no READ route on a conversation, a document or a knowledge base writes to the log. So you can demonstrate who COULD see a piece of content, and who administered it — not who read it.
hard lawText read current to 1 April 2026Official source
Act respecting the protection of personal information in the private sector, CQLR c P-39.1, s. 8.1
En plus des informations devant être fournies suivant l'article 8, la personne qui recueille des renseignements personnels auprès de la personne concernée en ayant recours à une technologie comprenant des fonctions permettant de l'identifier, de la localiser ou d'effectuer un profilage de celle-ci doit, au préalable, l'informer: 1° du recours à une telle technologie; 2° des moyens offerts pour activer les fonctions permettant d'identifier, de localiser ou d'effectuer un profilage.- What it means
- The section almost nobody applies to an AI platform, and its own definition is why they should. Profiling here means “the collection and use of personal information to assess certain characteristics of a natural person, in particular for the purpose of analysing that person's work performance, economic situation, health, personal preferences, interests or behaviour.” Having a model summarise an employee's reviews, screening job applications, drawing out a client's behaviour from their file — all of it falls inside the definition. And the notice is owed BEFOREHAND, on two things: that the technology is being used, and the means offered to activate the function.
- What we answer
- This duty bears on your use, not on our code: you decide whether an assistant is being used to assess a person. We cannot detect that for you and we will not pretend otherwise — nothing in the product classifies an assistant as “profiling,” and nothing triggers a notice to the individual. What we supply so you can meet the duty: assistants, prompts and automations are named, described and listed in the console with their access rights, so the inventory of what runs at your place is legible; the audit log keeps which model answered, to which request and for which account. Two practical consequences. If a use falls inside the definition, the prior notice and the description of the activation means are yours to write, before go-live. And do not conflate this section with s. 12.1: you can profile without a fully automated decision, and make an automated decision without profiling. The two duties are handled separately.
hard lawText read current to 1 April 2026Official source
Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (AI Act), Art. 2(1)(c)
providers and deployers of AI systems that have their place of establishment or are located in a third country, where the output produced by the AI system is used in the Union;- What it means
- The Regulation does not stop at the Union's borders. A Québec company with no European establishment falls within it as soon as the OUTPUT of the system is used in the Union — a report drafted here and handed to a European client, a text published on a site read from the Union. The test is the use of the output, not where the server sits or what nationality the provider holds. You would then be the "deployer" and we the "provider": two roles, two distinct sets of obligations.
- What we answer
- That analysis is yours, not ours: we do not know where your outputs end up. What we can establish is factual — the platform is a general-purpose AI system within the meaning of the Regulation, and if your outputs are used in the Union, the next two requirements apply, yours and ours alike. If nothing leaves Canada, the Regulation does not reach you and the next two entries do not concern you. We have no authorised representative established in the Union within the meaning of Article 22, and we will not pretend otherwise.
hard lawIn force 1 August 2024, applicable since 2 August 2026Official source
Regulation (EU) 2024/1689 (AI Act), Art. 4
Providers and deployers of AI systems shall take measures to ensure, to their best extent, a sufficient level of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, education and training and the context the AI systems are to be used in, and considering the persons or groups of persons on whom the AI systems are to be used.- What it means
- The duty binds the deployer as much as the provider, it has applied since February 2025, and it carries no size threshold. It does not require a certification: it requires measures proportionate to your teams' knowledge and to the context of use — and it expressly covers the people who operate the tool ON YOUR BEHALF, so your contractors and freelancers, not only your employees.
- What we answer
- The platform includes a learning centre where an administrator publishes courses and paths for their teams: that is material for documenting your measures, and it is the only thing we contribute here. The duty stays yours. We do not train your staff, we attest to no level of literacy, and we do not supply an off-the-shelf programme written against Article 4.
hard lawApplicable since 2 February 2025Official source
Regulation (EU) 2024/1689 (AI Act), Art. 50(2), and Art. 111(4) as inserted by Regulation (EU) 2026/1744
Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content, shall ensure that the outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated.- What it means
- The duty falls on the PROVIDER — on us, not on you. Regulation (EU) 2026/1744 of 8 July 2026, the AI "digital omnibus", did not defer this article: it deferred high-risk systems, and it inserted into Article 111 a paragraph 4 giving systems placed on the market before 2 August 2026 until 2 December 2026 to comply. The marking it requires is machine-readable, which is more than a notice shown on screen.
- What we answer
- We do not do it. The platform applies no machine-readable marking to the text, images, audio and video it generates, and nothing identifies an output as AI-produced once it has left the tool. This is a provider gap, it is ours, it now carries a date that is not of our making, and we have no delivery date to announce. It reaches you only if your outputs are used in the Union — but in that case it is your compliance chain that carries our shortfall, and it is a question to put to us in writing before you sign.
hard lawApplicable since 2 August 2026; 2 December 2026 for systems placed on the market before that dateOfficial source
Regulation (EU) 2016/679 (GDPR), Art. 5(1)(d)
accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay (‘accuracy’);- What it means
- The accuracy principle is not about our database being right; it is about the personal data YOU process being right. A model that fabricates a fact about a named person produces inaccurate personal data, and the article then requires every reasonable step to erase or rectify it without delay. It is the European counterpart of Law 25 s. 11 cited above: the Québec text ties accuracy to the moment of a decision, the GDPR ties it to the processing itself, which is broader.
- What we answer
- What the platform gives you: a message can be edited, a document replaced in a knowledge base, the sources consulted are shown under the answer, and the trace stays in the audit log. What it does not give you, and this is the point: no detection of a fabricated statement about a person, and no mechanism that would flag an inaccurate output once it has left the tool. The accuracy of what a model writes about someone is not a control we can sell you; checking it before acting on it remains a human step, at your end.
hard lawIn force since 25 May 2018Official source
Regulation (EU) 2016/679 (GDPR), Art. 25
Taking into account the state of the art, the cost of implementation and the nature, scope, context and purposes of processing as well as the risks of varying likelihood and severity for rights and freedoms of natural persons posed by the processing, the controller shall, both at the time of the determination of the means for processing and at the time of the processing itself, implement appropriate technical and organisational measures, such as pseudonymisation, which are designed to implement data-protection principles, such as data minimisation, in an effective manner- What it means
- The duty binds the controller — you — and it bites AT THE MOMENT YOU DETERMINE THE MEANS, that is when you select a platform and configure it, not afterwards. Paragraph 2 adds protection by default: only the personal data necessary for each purpose should be processed, without the data subject having to act.
- What we answer
- What works in your favour by default: a dedicated instance, per-object rights on every knowledge base, prompt, tool and assistant, anonymous public links off, a restrictable model catalogue, privacy mode. What works against it, and it is precisely the "by default" half: there is no retention setting at all. Conversations, documents and knowledge bases have no clock and stay until someone deletes them; the product's nine timers are hardcoded and not configurable; and the catalogue restriction does not bind the calls the server makes on its own. A controller who has to demonstrate minimisation by default will not find the setting that would produce it here.
hard lawIn force since 25 May 2018Official source
Regulation (EU) 2016/679 (GDPR), Art. 34
When the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall communicate the personal data breach to the data subject without undue delay.- What it means
- To be distinguished from Article 33, already cited above, which covers notification to the supervisory authority within 72 hours. Article 34 covers telling the PEOPLE when the risk is high. It is a controller's duty, not a processor's — but it can only be met if the processor gave notice in time.
- What we answer
- The contract owes you notice "without delay" to your privacy officer, with the nature of the incident, the people concerned, the period and the measures taken (s. 14.9). What it does not owe you is a number of hours: no figure appears in it and we have announced none. Your own duty towards the people concerned, by contrast, is measured in real elapsed time. That mismatch is our gap, not yours, and it is the same one that sits on your Québec clocks. It is fixed at signature, by writing a number of hours into the agreement.
hard lawIn force since 25 May 2018Official source
Regulation (EU) 2024/1689 (AI Act), Art. 5(1)(f), and Art. 99(3)
the placing on the market, the putting into service for this specific purpose, or the use of AI systems to infer emotions of a natural person in the areas of workplace and education institutions, except where the use of the AI system is intended to be put in place or into the market for medical or safety reasons;- What it means
- This is not a risk tier to be documented: it is a PROHIBITION, and it carries the highest penalties in the Regulation. Inferring a person's emotions in the workplace or in an education institution is banned, save for medical or safety reasons. It has applied since February 2025 and it catches the use, so the deployer, not only the maker. Article 99(3) puts a figure on it: non-compliance with the Article 5 prohibitions carries an administrative fine of up to EUR 35 000 000 or 7 % of total worldwide annual turnover, whichever is higher — the highest ceiling in the Regulation.
- What we answer
- The platform ships no emotion-recognition feature and we sell none. But it is a general-purpose tool: nothing stops an administrator from writing a prompt or an assistant that asks a model to assess an employee's tone, morale or attitude from their messages, and the product will not refuse that request. We do not detect that use and we do not block it. If your outputs are used in the Union, such a configuration is a prohibited practice and the exposure is yours. The catalogue restriction and the audit log are what you have; neither is a control for this.
hard lawApplicable since 2 February 2025Official source
Regulation (EU) 2016/679 (GDPR), Art. 6
Processing shall be lawful only if and to the extent that at least one of the following applies: (a) the data subject has given consent to the processing of his or her personal data for one or more specific purposes; (b) processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract;- What it means
- This is the most important structural difference between the GDPR and Law 25, and it catches Québec companies out. Québec law starts from consent and provides exceptions; the GDPR requires one of six legal bases, of which consent is only one — and often the weakest in an employment context, where it is rarely freely given. Feeding a model with European employee records therefore assumes you chose and documented a basis — legitimate interests, contract, legal obligation — BEFORE the processing, not after.
- What we answer
- Nothing in the product picks or documents a legal basis: it is not a feature, it is a decision that is yours and that is taken outside the tool. What we supply to support it: the architecture description, the table of calls the server makes on its own, the timer inventory and the provider table — that is, the factual material for a legitimate-interests assessment. We do not opine on your legal basis and we presume none.
hard lawIn force since 25 May 2018Official source
Regulation (EU) 2016/679 (GDPR), Art. 83
Each supervisory authority shall ensure that the imposition of administrative fines pursuant to this Article in respect of infringements of this Regulation referred to in paragraphs 4, 5 and 6 shall in each individual case be effective, proportionate and dissuasive.- What it means
- Two ceilings, not one. Paragraph 4 covers security and processor obligations among others: EUR 10 000 000 or 2 % of total worldwide annual turnover. Paragraph 5 covers the principles, the legal bases, data subject rights and transfers: EUR 20 000 000 or 4 %, whichever is higher. The order of magnitude exceeds the Québec administrative monetary penalty, and the fine is addressed to the controller — you — even where the technical failure came from the processor.
- What we answer
- The fine is not addressed to us, and that is precisely why it appears here: our failure becomes your exposure. The contract provides measures, an annual audit right and incident notice, but it carries no indemnity that would hold you harmless from a fine imposed because of us. If that risk matters to your organisation, it is a clause to negotiate before signature; we will not pretend it is already there.
hard lawIn force since 25 May 2018Official source
What stays yours to do
No vendor can carry these obligations for you.
- Designate a person in charge of the protection of personal information and publish their title and contact information on your website (s. 3.1).
- Publish your governance policies and practices, including your retention and destruction rules (s. 3.2).
- Carry out and document the PIA before deploying the platform, and keep it — two obligations stack here, section 3.3 and section 17.
- Don't mistake the section 18.3 exception for a general dispensation: it sets aside consent, not the purpose requirement of section 12. Decide, request by request, what is genuinely necessary — and document that judgement rather than concluding there is nothing left to redact.
- Keep the register of confidentiality incidents and retain its entries for at least five years, even with no incident to report.
- Decide what your teams are allowed to put into the tool, write it down, and enforce it — that's an internal policy, not a setting.
- Train your users: most incidents start with a careless paste, not with a technical breach.
- Verify every year that the configuration of permitted models still matches the analysis you started from.
- If you process data belonging to people in the EU or the EEA, determine whether the GDPR applies to you directly (an EU establishment) or by targeting (offering goods or services, monitoring behaviour), and document that analysis.
- Negotiate a data processing agreement (DPA) compliant with article 28 and a transfer mechanism (standard contractual clauses) before entrusting data belonging to people in the EU or the EEA to the platform.
- Keep the article 30 GDPR record of processing activities if you are subject to it, and designate a representative in the Union within the meaning of article 27 if you have no establishment there.
- Ask the section 3.3, para. 3 design question before you sign: the system must be able to hand an individual, in a structured, commonly used technological format, the computerized information collected from them.
Questions to ask any AI vendor
Including us.
- Which categories of data leave Quebec, and for exactly how long?
- Can your platform hand me an individual's information in a structured, commonly used format, as section 27, para. 3 and section 3.3, para. 3 require?
- Do you provide me with a written agreement that meets the conditions of section 18.3, clause by clause?
- Who are your hosting and AI subprocessors, and will you notify me before changing them? Within what contractual notice period?
- Can I technically restrict which models are used, and does the refusal apply at call time or only in the interface?
- What exactly does the model provider see: my employee's name, their email address, or a technical identifier?
- What happens at the end of the contract: what export, what deadline for permanent deletion, and what will remain in your backups?
- Can you sign a data processing agreement (DPA) compliant with article 28 of the GDPR, and standard contractual clauses for transfers outside the EU or the EEA?
- What is your contractual deadline for notifying me of a data breach, given that I must meet the 72 hours of article 33 of the GDPR?
- Has an independent third party penetration-tested your platform, and may I see the report or its summary?
- Are the at-rest encryption keys managed by your host, or can I supply and revoke my own?
A vendor that answers yes to everything without evidence deserves more suspicion than one that names its limits.
What people ask us about Law 25
- What is Law 25, in one sentence?
- It is the Quebec statute adopted in 2021 (chapter 25 of that year's statutes) that modernized the protection of personal information. It did not replace the existing regime: it amended legislation already in place, including the Act respecting the protection of personal information in the private sector (P-39.1), which is the text a private business needs to read.
- When did Law 25 come into force?
- In stages, and section 175 of the 2021 Act sets them out one by one. The person in charge of the protection of personal information and the confidentiality-incident obligations (ss. 3.1 and 3.5 to 3.8) have applied since 22 September 2022. Most of the others — impact assessments, communication outside Quebec, rules for service providers, retention and destruction, automated decisions — since 22 September 2023. The right to portability arrived on 22 September 2024.
- My business is small. Am I really covered?
- Yes. Section 1 sets no threshold: not headcount, not revenue — size is never a criterion. As soon as a person collects, holds, uses or communicates to third parties personal information about others in the course of carrying on an enterprise, they are covered. What scales with size is the proportionality of the measures expected — not whether the Act applies.
- Does Law 25 require data to be hosted in Quebec?
- No, and this is the most widespread misunderstanding — but “no” does not mean “unconditionally”. Section 17 does not prohibit communication outside Quebec: it requires you to assess it beforehand, taking into account, in particular, the sensitivity of the information, the purpose, contractual protection measures and the legal framework of the receiving state. The communication may then take place only where the assessment establishes adequate protection, and it must be the subject of a written agreement. And the section is not limited to sending data out: its third paragraph expressly reaches entrusting a person or body outside Quebec with collecting, using, communicating or keeping information on your behalf — so hosting itself, and not only a transfer. Some sectors do add a genuine localisation requirement: that is the case for the distribution of financial products and services, including insurance, where section 88 of the Act respecting the distribution of financial products and services requires a firm to keep its clients' records in Quebec.
- Do I need an impact assessment to adopt an AI tool?
- Section 3.3 requires a privacy impact assessment for any project to acquire, develop or overhaul an information system involving personal information. An AI platform your teams feed with your documents fits that description. And if the requests leave Quebec, section 17 imposes a second assessment on that specific point.
- What are the penalties?
- Three regimes. The administrative monetary penalty, imposed by a person designated by the Commission d'accès à l'information, is capped at $10,000,000 or 2% of the previous year's worldwide turnover, whichever is higher (s. 90.12). Penal prosecution exposes a business to a fine of $15,000 to $25,000,000 or 4% of that same turnover, whichever is higher (s. 91). For a natural person the figures are $50,000 and $5,000 to $100,000 respectively. A third regime exists as well, and it does not go through the Commission: unlawful and intentional interference, or interference resulting from gross negligence, gives rise to punitive damages of at least $1,000 (s. 93.1).
- What if an AI makes a decision about someone?
- Section 12.1 applies as soon as the decision is based exclusively on automated processing. You must inform the person no later than when the decision is communicated, provide on request the information used, the reasons and the principal factors and parameters, along with their right of rectification — and give them the opportunity to submit observations to a member of staff in a position to review the decision. If a human genuinely decides, the section does not apply. The Act does not define “exclusively”: our reading — and the one privacy authorities generally take — is that a purely formal human intervention, with no real capacity to change the outcome, does not turn an automated decision into a human one. That is an interpretation, not the text.
- Is there a Canadian AI law?
- No. As of 5 September 2026, no federal statute governs AI in Canada. The Artificial Intelligence and Data Act was part of Bill C-27, which died on the Order Paper at the 6 January 2025 prorogation; it has not been reintroduced. Bill C-36, tabled in June 2026, reforms privacy rather than AI, and it is only at second reading. What actually applies to an AI project in Québec: Law 25, PIPEDA for anything crossing a border, your sector regulator, and the EU AI Act if your outputs are used in the Union. The ISED code of conduct exists but is voluntary — signing it is not compliance.
- Is there a threshold below which Law 25 does not apply?
- No. No employee threshold, no revenue threshold, no small-business exemption. As soon as a business operates in Quebec and holds personal information about others, it is covered.
- Does adopting an AI platform create new obligations?
- No: it triggers the ones that already existed, all at once. The s. 3.3 impact assessment, the s. 17 assessment if the request leaves Quebec, the written contract in s. 18.3, and s. 12.1 if a decision is made exclusively by the machine.
- Does the GDPR apply to me as well?
- If you process information about people located in the European Union, yes, and it adds its own requirements — including the chapter V framework for transfers outside the EU. This page names what we do not cover on that side.
Bottom line
- Law 25 does not ban AI for you
- A contract compliant with section 18.3 really does stand in for your clients' and your employees' consent.
- But that is all it stands in for
- Section 12 requires the use to serve the purpose of collection, section 18.3 covers only what is necessary to the mandate, and section 8 wants any departure from Quebec to have been announced at collection.
- Redacting: neither required nor optional
- It is not a general obligation, but “redact nothing” is not the rule either. It is a judgement to make request by request, and to document.
- The rest comes down to four moves
- Know where the data goes, have assessed it in writing before you start, have a contract that holds up, and be able to demonstrate it.
- The split of roles
- Our part is done and verifiable, with one exception we name above: the export is not in a common structured format (s. 27, para. 3), and that belongs in your assessment as written. The PIA, the register and the internal policy stay yours.
Compliance is not something you buy with software
No platform makes you compliant with Law 25 — the statute binds the business, not the tool. What a vendor can do is give you something to answer with: an architecture described, a contract that names the measures, and an honest list of what it does not cover. That is what we publish.