Guide
Law 25 and AI: what a Québec business needs to settle before it automates
Law 25 was not written about AI, but it governs almost everything a Québec business wants to automate: intake, chatbots and voice agents, follow-up sequences, lead qualification, the dashboards that pull it all together. This guide covers what the law actually requires, where the real risk sits in an automation project, and what has to be decided before anything is connected. It is a plain-language guide for operators, not legal advice.
Last updated 2026-08-03. Free to read, nothing gated.
Contents
- What Law 25 requires, in plain terms
- The timeline, and where you stand today
- Chatbots, voice agents and automated decisions
- Data residency, cloud services and the CLOUD Act
- Privacy impact assessments, and when your project needs one
- Law 25 or PIPEDA: which one applies to you
- Penalties, the CAI and what customers can do
- A checklist before launching an AI system
What Law 25 requires, in plain terms
Law 25, formally the Act to modernize legislative provisions as regards the protection of personal information, is Québec's overhaul of private-sector privacy law. It applies to any business that collects, uses, discloses or holds personal information in Québec, regardless of size. There is no employee threshold, no revenue threshold and no small business exemption.
Personal information is any information that allows a natural person to be identified, directly or indirectly. In a small business that means most of what arrives through a form: a name, an email, a phone number, an address, a licence plate, an appointment history, a service file, a support conversation. That an individual field looks harmless on its own does not matter; what matters is whether someone can be identified.
The obligations that hit an SME hardest come down to six things. You must designate a person responsible for the protection of personal information and publish their title and contact details. If nobody is designated, it defaults to the person with the highest authority in the business, which surprises most owners. You must publish a privacy policy in clear language and make it easy to find. You must obtain valid consent before collecting, and that consent has to be clear, free, informed and given for specific purposes. You must limit collection to what is necessary for those stated purposes. You must keep a register of confidentiality incidents and report to the Commission d'accès à l'information any incident presenting a risk of serious injury. And you must be able to honour individual rights: access, correction, withdrawal of consent, de-indexing and portability.
None of that is heavy for an ordinary business. What becomes heavy is retrofitting it into a system that is already in production with customers inside it. That is precisely why these questions belong in the scoping conversation rather than the launch checklist.
The timeline, and where you stand today
The law was assented to in September 2021 and came into force in stages. The first block, in September 2022, made the designated privacy officer, incident handling and reporting, and disclosure of biometric databases to the CAI mandatory.
The bulk of the regime landed in September 2023: modern consent requirements, the privacy policy, privacy impact assessments for information system projects, the framework for disclosing information outside Québec, transparency about automated decision-making, privacy by default for technological products and services offered to the public, and the right to have dissemination ceased and information de-indexed.
The last block, in September 2024, added data portability: on request, a person can obtain the computerized information they provided you, in a structured, commonly used technological format.
In other words, all of it is already in force. If you have never done anything about it, you are not behind on an upcoming deadline. You are already non-compliant, and the first place that shows is your website.
Chatbots, voice agents and automated decisions
This is where AI meets the law most directly, and it is the section most solution vendors skip.
Transparency about what the system is. When someone interacts with a chatbot or a voice agent, they should know what they are talking to. This is more than good manners: consent cannot be informed if the person is mistaken about what they are doing and who is collecting the information. An agent that passes itself off as an employee weakens every consent obtained during that conversation.
Collection during the conversation. An agent that asks for a name, a number and a description of the problem is collecting personal information. The purposes have to be stated, collection has to be limited to what is necessary, and the person needs to know where it goes. An agent that asks twelve questions because the answers might be useful someday fails the necessity principle.
Recording and transcription. A recorded or transcribed call is a collection, and usually a broader one than the stated purpose justifies. Decide before launch whether you record, what you do with it, how long you keep it and who can see it. The default on most platforms, keep everything forever, is not defensible.
Decisions based exclusively on automated processing. This is the least known obligation and the most relevant to AI builds. When a decision about a person is made solely by automated processing, you must inform them at the time of the decision or before. On request, you must tell them what personal information was used, the principal reasons and factors that led to the decision, and allow them to have that information corrected and to submit observations to a person able to review the decision.
The practical question for an operator is whether your system decides or prepares a decision. A qualification system that sorts inquiries and presents them to a human who chooses is not an exclusively automated decision. A system that automatically declines a request, excludes a prospect from an offer or sets a condition with no human involvement is. That difference is an architecture choice, and it is worth making deliberately. In the systems we build, for example AI lead response and qualification, the final judgment stays human, which simplifies compliance and happens to be a better way to sell.
Profiling and location. If you use technology that allows a person to be identified, located or profiled, you must inform them and offer the means to deactivate those functions. In practice that covers tracking pixels, retargeting audiences and behavioural personalisation, and a cookie banner that merely says you use cookies does not discharge it.
Data residency, cloud services and the CLOUD Act
Law 25 does not prohibit hosting data outside Québec. It requires something more demanding than a prohibition: that you have assessed the question and can show your work.
Before disclosing personal information outside Québec, you must conduct a privacy impact assessment. It has to consider the sensitivity of the information, the purpose of its use, the protection measures it would receive, and the legal framework applicable in the destination jurisdiction, including the privacy principles that apply there. The disclosure may proceed only if the assessment shows the information would receive adequate protection, and it must be the subject of a written agreement.
That is where the American CLOUD Act enters. It allows US authorities to compel a provider subject to US law to produce data in its control, including data physically stored abroad. Choosing a provider's Canadian region therefore settles a latency and physical sovereignty question, but does not by itself settle which legal regime applies to the provider. That does not make US tools unusable, and the overwhelming majority of Québec businesses use them daily. It means the reasoning has to be done, written down, and proportionate to the sensitivity of what you are handing over.
For an automation project the questions to settle are: which data actually leaves Québec, and which could stay? Do the AI providers involved use your data to train their models, and does your commercial configuration exclude that? What is the retention period at each provider? Is there a written agreement covering the processing? A well-scoped project answers those four before the first line of code, not after the first incident.
Privacy impact assessments, and when your project needs one
The privacy impact assessment, known in Québec by its French acronym ÉFVP, is the central instrument of Law 25 and the one SMEs most often skip because it sounds like enterprise paperwork. It is not.
It is mandatory in two situations that bear directly on automation work. First, for any project to acquire, develop or overhaul an information system or electronic service delivery involving personal information. A new CRM, a new intake form, a chatbot, a dashboard that consolidates customer data: all of it fits the definition. Second, before any disclosure of personal information outside Québec, as described above.
A proportionate assessment for a small business is not a hundred-page document. It is a structured exercise answering: what data, why, where it comes from, where it goes, who has access, how long it is kept, what the realistic risks are, and what measures are in place. The deliverable is often a few pages. The value is not the document, it is having been forced to answer those questions before building, while the answers are still free to change.
The law also requires privacy by default: technological products or services offered to the public that have privacy settings must provide the highest level of confidentiality by default, without any action from the user. If your project includes a customer portal, an app or a member area, that default is a design decision rather than a launch-day checkbox.
Law 25 or PIPEDA: which one applies to you
This question comes up constantly, and the short answer for most Québec businesses is Law 25.
Québec has its own private-sector privacy statute, which has been recognized as substantially similar to the federal law. The consequence is that for commercial activity taking place within Québec, the provincial regime governs and Québec organizations are exempt from PIPEDA for those activities.
The federal law still applies in two situations. First, to federal works and undertakings: banks, telecommunications, interprovincial air and rail transport and the like. Second, to personal information disclosed across provincial or national borders in the course of commercial activity.
For a Montréal online retailer selling into Ontario and the United States, the practical conclusion is that both regimes are in play depending on the transaction. That is less complicated than it sounds, because Law 25 is generally the more demanding of the two: an organization that takes it seriously satisfies most federal expectations along the way. Build to the Québec standard and treat the rest as a subset.
Penalties, the CAI and what customers can do
The Commission d'accès à l'information du Québec is the supervisory authority. It receives incident reports, handles complaints, conducts investigations, can order corrective measures and can impose administrative monetary penalties.
The penalty regime introduced by Law 25 is among the most severe in Canada, and it is calibrated to bite large and small organizations alike: administrative penalties can reach a percentage of worldwide turnover, and penal sanctions imposed by a court a higher percentage still. The exact statutory maximums are set out in the legislation. For an SME the useful reading is not the theoretical ceiling. It is that the law now has teeth, and that the CAI can order corrective measures that cost time and credibility long before any penalty is discussed.
There is also a private right of action. An unlawful infringement of a right conferred by the law opens the door to punitive damages, with a statutory floor where the infringement is intentional or results from a gross fault. In practice that makes class actions viable for incidents that previously would not have justified a file.
The realistic scenario for a small business is almost never a regulator at the door. It is an unhappy customer exercising their right of access and getting no reply, or a confidentiality incident handled badly enough to become a complaint. Both are prevented by ordinary process: knowing where the data is, knowing who is responsible, and being able to respond within the deadlines.
A checklist before launching an AI system
This is what we work through before putting a system that touches customer data into production. It is not a full assessment; it is the practicable minimum for an SME project.
1. Map the data. What comes in, through which channel, where it is stored, which providers see it, how long it stays. Almost nobody can answer that from memory, and the exercise usually turns up two or three surprises.
2. Justify every field. Each field on a form has to serve the stated purpose. The ones that exist just in case are risk with no upside.
3. Write the purposes in plain language. If a purpose does not fit in one understandable sentence, the consent obtained on it is fragile.
4. Make consent granular. Consent to answer someone's question is not consent to market to them. Ask separately.
5. Decide recording and retention. For each system: do we record, do we transcribe, for how long, and what deletes automatically.
6. Fix the human-machine boundary. Does the system decide, or prepare a decision? Where it decides, transparency and the right to review apply and have to be built.
7. Check the AI providers' configuration. Confirm in writing that your data is not used to train models, and document retention on the provider's side.
8. Plan for the incident. A register, a responsible person, a reporting threshold and a communication template. Working those out during an incident is the worst possible time.
That is the list we apply to what we build, whether it is a bilingual voice agent, an AI support agent or a dashboard that consolidates customer data. If you want to talk it through for your operation, we are based in Montréal and it is the kind of question that comes up on the first call.
Disclaimer: this guide is a plain-language summary for business owners and managers. It is not legal advice. For a specific situation, consult legal counsel and refer to the official text of the legislation and the guidance published by the Commission d'accès à l'information.