Law 25 applies to you, whatever your size
There is no employee threshold, no revenue threshold and no small-business exemption. As soon as an enterprise carries on business in Quebec and holds information about natural persons, the Act respecting the protection of personal information in the private sector applies in full. Adopting an AI platform triggers ten specific obligations under that Act, to which are added the penalty regime that comes with them, the Commission's guide and the position it has published on generative AI, federal PIPEDA for whatever crosses the Quebec border, and eight GDPR requirements if you touch Europe. Here they are, in their own words, with what we answer to each and what stays with you.
Last reviewed:
Who regulates you
The bodies whose requirements apply to you.
- CAICommission d'accès à l'information du Québec
Oversees the application of the Act, investigates, issues orders, and imposes monetary administrative penalties. It is the body that receives your incident notifications and that can demand your register.
- P-39.1Act respecting the protection of personal information in the private sector (CQLR c P-39.1)
The applicable statute, deeply amended by Law 25. The last provisions came into force on 22 September 2023, except the right to portability, in force since 22 September 2024.
- OPCOffice of the Privacy Commissioner of Canada
Federal PIPEDA applies in parallel to your interprovincial and international activities. Its accountability principle requires a comparable level of protection at any third party you entrust with information.
- GDPRCompetent supervisory authority (GDPR)
If your business processes data belonging to people located in the European Union or the European Economic Area — customers, remote employees, partners — the GDPR applies alongside Law 25. The one-stop-shop mechanism designates a lead supervisory authority when you have a main establishment in the EU; without an EU establishment, each national authority concerned by the processing can act directly against you.
Requirement by requirement
Each requirement is quoted from its source, then answered.
Act respecting the protection of personal information in the private sector, CQLR c P-39.1, s. 10
Toute personne qui exploite une entreprise doit prendre les mesures de sécurité propres à assurer la protection des renseignements personnels collectés, utilisés, communiqués, conservés ou détruits et qui sont raisonnables compte tenu, notamment, de leur sensibilité, de la finalité de leur utilisation, de leur quantité, de leur répartition et de leur support.- What it means
- The standard is proportionate: the more sensitive the information, the stronger the expected measure. Law 25 didn't touch this section, but it gave it teeth — failing to take those measures became a distinct penal offence (s. 91, para. 4).
- What we answer
- A dedicated instance in Canada, encryption at rest and in transit — the Azure platform's, with Microsoft-managed keys, not a key of your own — a key vault with role-based control for integration secrets, per-object rights, an audit log, and a contract committing to administrative, technical and organisational measures (cl. 14.5). Section 10 asks for reasonable, proportionate measures, not for a certification: the audit right in clause 14.10 lets you check them yourself.
hard law2006, not amended by Law 25Official source
Act respecting the protection of personal information in the private sector, CQLR c P-39.1, s. 3.3
Toute personne qui exploite une entreprise doit procéder à une évaluation des facteurs relatifs à la vie privée de tout projet d'acquisition, de développement et de refonte de système d'information ou de prestation électronique de services impliquant la collecte, l'utilisation, la communication, la conservation ou la destruction de renseignements personnels. […] La personne doit également s'assurer que ce projet permet qu'un renseignement personnel informatisé recueilli auprès de la personne concernée soit communiqué à cette dernière dans un format technologique structuré et couramment utilisé.- What it means
- Adopting an AI platform is the acquisition of an information system: the Commission expressly places the “artificial intelligence system” among the forms an information system takes (PIA Guide v3.1, § 7.2, p. 51). The assessment is therefore mandatory for the project — not “before the project”, but before it goes live, with your privacy officer consulted from the very start of the project (para. 2). The third paragraph, often forgotten, adds a design requirement: at the time you acquire the system, you must make sure it will be able to return to an individual, in a structured, commonly used technological format, the computerized information collected from them.
- What we answer
- The PIA is yours — the Act puts it on the enterprise, not on the vendor. We supply the inputs: description of the data flow, categories transferred outside Quebec, hosting regions, published policies of the model providers, security measures, contractual commitments and this page. The contract expressly provides that we cooperate in documenting those assessments (cl. 14.8). On the third paragraph, though, we do not put you in a position to answer yes: the export exists (conversations, documents, knowledge bases) but is not normalized into a structured interchange format. That is a gap on our side, to be recorded as such in your assessment.
hard lawIn force 22 September 2023Official source
Act respecting the protection of personal information in the private sector, CQLR c P-39.1, s. 17
Avant de communiquer à l'extérieur du Québec un renseignement personnel, la personne qui exploite une entreprise doit procéder à une évaluation des facteurs relatifs à la vie privée. […] La communication peut s'effectuer si l'évaluation démontre que le renseignement bénéficierait d'une protection adéquate […]. Elle doit faire l'objet d'une entente écrite.- What it means
- Contrary to a widespread belief, section 17 does not prohibit data from leaving Quebec and imposes no localization rule. It imposes three things: a prior assessment weighing four factors, a conclusion that protection is adequate, and a written agreement. Its third paragraph expressly covers the case where you entrust a third party outside Quebec with storing or processing on your behalf — which is exactly what a cloud AI platform is.
- What we answer
- The hosting itself is already caught, and that is the point most readers miss: your instance runs in the Azure Canada Central region by default, that is, in Toronto — in Canada, but outside Quebec. Entrusting us with storing your information on your behalf therefore falls under the third paragraph, and inference at the model providers, several of them in the United States, under the first. Your assessment, your adequate-protection conclusion and your written agreement have to cover both, not only the model call. What leaves at run time: the content of the request, for the duration of the computation, and the full text of documents added to a knowledge base, sent at indexing time to be embedded. We deploy a Quebec region under private hosting only — but let us be exact, because the opposite sentence used to sit here: that does NOT take hosting out of the scope of section 17. Database backups are geo-replicated to the paired region — Canada East, in Quebec City — therefore inside the province, while the instance itself is in Toronto; the files you upload are not replicated outside your instance's region. The host's residency commitment is to Canada in any case, not to the province. So the third paragraph stays engaged even in Canada East; what the region brings closer is the day-to-day processing, not the legal perimeter. Inference stays in scope too. The written agreement exists: it is clause 14 of the master agreement — but the second paragraph wants one that TAKES ACCOUNT OF THE RESULTS of your assessment, which we cannot know in advance. If yours concludes that particular measures are called for, they are recorded in an addendum; clause 14 on its own does not suffice. The adequate-protection conclusion is yours: we give you the elements, you make the judgment. We do not guarantee by default that inference stays in Canada.
hard lawIn force 22 September 2023Official source
Act respecting the protection of personal information in the private sector, CQLR c P-39.1, s. 18.3
Une personne qui exploite une entreprise peut, sans le consentement de la personne concernée, communiquer un renseignement personnel à toute personne ou à tout organisme si cette communication est nécessaire à l'exercice d'un mandat ou à l'exécution d'un contrat de service ou d'entreprise qu'elle confie à cette personne ou à cet organisme.- What it means
- This is the provision that answers “do I have to redact before using AI”. Read precisely what it does, and nothing more: it sets aside THE CONSENT of the individual concerned for a communication to a mandatary or to the party performing a service or enterprise contract. The rest of the Act stands — section 10 (security), section 12 (the purpose of use within the enterprise), sections 3.3 and 17 (the two assessments) and sections 3.5 to 3.8 (incidents). It also carries its own threshold, in the sentence quoted: the communication is permitted only where it “is necessary for the performance of a mandate or a contract”. That is a minimization requirement, not a blank cheque. In return, the second paragraph requires the mandate or the contract to be conferred in writing and to set out the confidentiality, use-limitation and no-retention-after-expiry measures; the prompt notice of any violation and the audit right, for their part, are imposed on the performing party directly by the Act — it is not for the contract to create them.
- What we answer
- The six elements are in our contract: written and signed; security measures (cl. 14.5, 14.6); use limited to enumerated purposes (cl. 14.2); deletion after the transition period (cl. 14.11); prompt notice to the officer (cl. 14.9); audit right (cl. 14.10). The clause-by-clause mapping is higher up this page. What this really settles: you do not need your clients' or your employees' consent to entrust us with their information — a compliant contract stands in for that consent. What it does not settle: section 12 requires the use to serve the purpose of collection, section 18.3 covers only what is necessary to the mandate, and the Commission, which co-developed the 7 December 2023 Canadian principles on generative AI, asks user organizations to use anonymized or de-identified information in prompts where that is possible and reasonable. The honest conclusion: redacting is not a general obligation, but “redact nothing” is not the rule either — it is a judgement to make request by request, and to write into your internal policy.
hard lawIn force 22 September 2023Official source
Act respecting the protection of personal information in the private sector, CQLR c P-39.1, ss. 3.5 to 3.8
Si l'incident présente un risque qu'un préjudice sérieux soit causé, elle doit, avec diligence, aviser la Commission d'accès à l'information […]. Elle doit également aviser toute personne dont un renseignement personnel est concerné par l'incident, à défaut de quoi la Commission peut lui ordonner de le faire.- What it means
- An incident isn't only a hack: section 3.6 covers any access to, use or communication of information not authorized by law, and the simple loss of information. The notification threshold is the “risk of serious injury”, assessed on the sensitivity of the information, the anticipated consequences of its use and the likelihood that it will be used for a harmful purpose (s. 3.7). The register, by contrast, is unconditional and comes from a different section: “a person carrying on an enterprise must keep a register of confidentiality incidents” (s. 3.8, para. 1), a copy of which is sent to the Commission on request. The operational detail sits in the Regulation respecting confidentiality incidents (CQLR, c. A-2.1, r. 3.1, in force 29 December 2022): eleven mandatory elements in the notice to the Commission (s. 3), the content of the notice to the individuals concerned (s. 5), the eight elements of the register (s. 7) and its retention for at least five years after the incident became known (s. 8).
- What we answer
- The contract obliges us to notify your designated officer without delay, with the nature of the incident, the persons concerned, the period and the measures taken (cl. 14.9) — with no commitment expressed in hours. Notifying the Commission, notifying the individuals concerned and keeping the register remain your obligations. One nuance that matters: your obligations stay yours, but ours do not disappear for that. We ourselves carry on an enterprise subject to Law 25 for the information we hold, and section 1 of the Regulation respecting confidentiality incidents covers “any person carrying on an enterprise who is subject to the Act respecting the protection of personal information in the private sector”: our own notification and register obligations stack with yours instead of replacing them. Our response plan exists but has never been exercised, and we say so.
hard lawIn force 22 September 2022Official source
Act respecting the protection of personal information in the private sector, CQLR c P-39.1, s. 12.1
Toute personne qui exploite une entreprise et qui utilise des renseignements personnels afin que soit rendue une décision fondée exclusivement sur un traitement automatisé de ceux-ci doit en informer la personne concernée au plus tard au moment où elle l'informe de cette décision.- What it means
- The trigger is the word “exclusively”. An AI that drafts a letter, suggests a classification or summarizes a file renders no decision: a human decides. An AI wired into an automation that denies, prices or sorts with no human intervention, yes. What the individual gets then is narrower than is commonly said. As of right: to be informed that the decision exists, no later than when it is announced to them (para. 1), and to be given “the opportunity to submit observations to a member of the personnel of the enterprise who is in a position to review the decision” (para. 3) — a right to be heard, not a right to have the decision reviewed. On request only (para. 2): the information used, the reasons as well as the principal factors and parameters, and the right to have that information corrected. Read it with section 11: information used to make a decision must be up to date and accurate when it is used, and is kept for at least one year after the decision.
- What we answer
- The platform drafts, summarizes and suggests; it doesn't render decisions on its own. But it can automate, and you're the one building those automations. If one of them decides on its own, section 12.1 applies to you. The contract says so in its own words: no generated output may be a final automated decision without appropriate human validation (cl. 17 of the contract).
hard lawIn force 22 September 2023Official source
Act respecting the protection of personal information in the private sector, CQLR c P-39.1, s. 23
Lorsque les fins auxquelles un renseignement personnel a été recueilli ou utilisé sont accomplies, la personne qui exploite une entreprise doit le détruire ou l'anonymiser pour l'utiliser à des fins sérieuses et légitimes, sous réserve d'un délai de conservation prévu par une loi. […] un renseignement concernant une personne physique est anonymisé lorsqu'il est, en tout temps, raisonnable de prévoir dans les circonstances qu'il ne permet plus, de façon irréversible, d'identifier directement ou indirectement cette personne.- What it means
- Keeping information isn't neutral: once the purpose is achieved, it must be destroyed or anonymized. Two turns of phrase that are often skipped change everything, though. “To use it for serious and legitimate purposes”: you don't anonymize for the sake of anonymizing — the intended use has to be established before the process is started (Regulation respecting the anonymization of personal information, O.C. 783-2024, s. 3). “Subject to a retention period provided for by an Act”: section 11, para. 2, for instance requires information used to make a decision to be kept for at least one year — deleting too fast is a failure too. And anonymization is a formal process, not a checkbox: supervision by a competent person (s. 4), removal of direct identifiers then a preliminary analysis of re-identification risk against the individualization, correlation and inference criteria (s. 5), a post-process analysis demonstrating “very low” residual risk (s. 7), periodic re-assessment (s. 8) and a register (s. 9). Information that is merely de-identified is not anonymized: it remains personal information (s. 12, para. 4, subpara. 1).
- What we answer
- You can delete conversations, documents and knowledge bases, and confidentiality mode makes a conversation ephemeral. Three of the product's timers that cannot be switched off bound what lingers (30 days, 7 days, 48 hours), but there is no configurable retention: you cannot set “destroy at 24 months” per workspace. We issue no certificate of destruction, and we document no purge delay for backups — and this must not be confused with the 30-day restore window or the 14-day snapshots mentioned elsewhere: those are recovery capabilities, not a commitment to destroy, and section 23 bears precisely on what survives in a backup — ask us before you commit to a destruction schedule, because an incomplete destruction within the meaning of section 23 is the one that survives in a backup. The platform anonymizes nothing within the meaning of section 23: the compliance scans retrospectively surface exchanges containing personal information so you can act on them, which is a signal, not an anonymization process. Those are the timers that reach a record; other clocks exist elsewhere in the product, and the Confidentiality and compliance page publishes the full inventory.
hard lawIn force 22 September 2023Official source
Act respecting the protection of personal information in the private sector, CQLR c P-39.1, s. 12
Un renseignement personnel ne peut être utilisé au sein de l'entreprise qu'aux fins pour lesquelles il a été recueilli, à moins du consentement de la personne concernée. Ce consentement doit être manifesté de façon expresse dès qu'il s'agit d'un renseignement personnel sensible. Un renseignement personnel peut toutefois être utilisé à une autre fin sans le consentement de la personne concernée dans les seuls cas suivants: 1° lorsque son utilisation est à des fins compatibles avec celles pour lesquelles il a été recueilli; […]- What it means
- Section 18.3 settles the COMMUNICATION to the vendor; section 12 settles the USE inside the enterprise, and it is the one that decides whether you may put a client file or an employee file into an assistant. The rule is the purpose of collection. Departing from it is allowed only in five exhaustively listed cases — a consistent purpose, the clear benefit of the individual, the prevention and detection of fraud or the improvement of security measures, the supply of a product or the provision of a service requested, and study or research on de-identified information — or with the individual's consent, express if the information is sensitive. And a purpose is only “consistent” if it has a direct and relevant connection with the purpose of collection (para. 3). It is this section, more than section 18.3, that answers “can I put this file into the tool”.
- What we answer
- That characterization is structurally yours: we have no visibility on the purpose for which you collected a file. What the platform gives you are the means to enforce it — per-user and per-group access, knowledge-base partitioning, confidentiality mode, an audit log, and the Law 25 detection that flags message by message the presence of personal information (a paid option, off by default, and itself an outbound call to a model). Those are instruments of control and of proof, not compliance: if the intended use does not serve the purpose of collection and falls into no exception, no setting on our side makes it lawful. Deciding which kinds of files are allowed into the tool is an internal policy, written down, not a parameter.
hard lawIn force 22 September 2023Official source
Act respecting the protection of personal information in the private sector, CQLR c P-39.1, s. 8, para. 2
Le cas échéant, la personne concernée est informée du nom du tiers pour qui la collecte est faite, du nom des tiers ou des catégories de tiers à qui il est nécessaire de communiquer les renseignements aux fins visées au paragraphe 1° du premier alinéa et de la possibilité que les renseignements soient communiqués à l'extérieur du Québec.- What it means
- The timing of that information is what makes it binding: it is given AT THE TIME OF COLLECTION, and afterwards on request. A business that plugs its files into a platform whose hosting and inference leave Quebec therefore had to have announced, in its collection notice and its privacy policy, the categories of third-party recipients and the possibility that the information be communicated outside Quebec. A flawless contract signed after the fact and a complete assessment do not repair information that was never given: these are two distinct obligations, and this one is judged as at the date of collection.
- What we answer
- We cannot do anything about this in your place, and it is the kind of gap that gets discovered late. What we provide so you can fix your texts: the list of our hosting and inference subprocessors, the regions where they operate, and the categories of information that leave Quebec. It is up to you to revisit the collection notice, the privacy policy and, for your employees, the hiring documentation, so that they name the categories of third parties and the possibility of a communication outside Quebec. For information already collected under a notice that was silent on the point, whether the intended use is still possible is a question under section 12, not under section 18.3.
hard lawIn force 22 September 2023Official source
Act respecting the protection of personal information in the private sector, CQLR c P-39.1, s. 27, para. 3 and s. 3.3, para. 3
À moins que cela ne soulève des difficultés pratiques sérieuses, un renseignement personnel informatisé recueilli auprès du requérant, et non pas créé ou inféré à partir d'un renseignement personnel le concernant, lui est, à sa demande, communiqué dans un format technologique structuré et couramment utilisé.- What it means
- The right to portability is not a European peculiarity: it has been in force in Quebec since 22 September 2024 and is exercised with no European dimension at all, by any client or employee. Its scope is bounded — it covers what was collected FROM the individual, not what was created or inferred about them, so an AI output concerning them falls outside it (it stays accessible under paragraph 1, as a plain copy). And section 3.3, para. 3, turns it into a design requirement: it is before you sign, at the time of acquisition, that you must make sure the system will allow it.
- What we answer
- We do not meet this requirement today, and it is better read here than discovered on an access request. Conversations, documents and knowledge bases export in full, per user — but the export is not normalized into a structured, commonly used interchange format. In practice you would answer with an intelligible transcription (which paragraph 2 allows), not with a structured file. It is the same gap named on the GDPR side at article 20; we count it once, not twice, and we do not announce it as solved.
hard lawIn force 22 September 2024 (s. 27, para. 3); 22 September 2023 (s. 3.3, para. 3)Official source
Act respecting the protection of personal information in the private sector, CQLR c P-39.1, ss. 90.1, 90.12, 91 and 93.1
Le montant maximal de la sanction administrative pécuniaire est de 50 000 $ dans le cas d'une personne physique et, dans les autres cas, de 10 000 000 $ ou du montant correspondant à 2% du chiffre d'affaires mondial de l'exercice financier précédent si ce dernier montant est plus élevé.- What it means
- The failures described on this page are exactly the ones section 90.1 makes liable to a monetary administrative penalty: failing to inform individuals in accordance with sections 7 and 8, collecting or using information in contravention of the Act, failing to report an incident, failing to take the security measures of section 10, failing to inform the person subject to an automated decision or to give them the opportunity to submit observations (s. 12.1). The ceiling is the one in the sentence quoted. Alongside it, the penal route in section 91 runs from $5,000 to $100,000 for a natural person and from $15,000 to $25,000,000 — or 4% of worldwide turnover if that is higher — in other cases, with the amounts doubled for a repeat offence (s. 92.1). And section 93.1 opens punitive damages of at least $1,000 where an unlawful infringement is intentional or results from gross fault: that is the lever behind class actions, and often the most concrete line of risk for a business whose clients number in the thousands.
- What we answer
- This risk does not transfer by contract: an administrative penalty or a fine strikes the party in default, and no vendor indemnity clause erases it. What we can act on is probability and proof: encryption in transit and at rest, per-user and per-group access, an audit log — whose console CSV export covers only the 50-row page on screen, personal-information detection message by message (a paid option, off by default, and itself an outbound call to a model), prompt notice in the event of an incident (cl. 14.9) and an annual audit right (cl. 14.10) — enough to document the diligence the Commission examines under its general framework for applying penalties. We do not sell compliance insurance, and you should be wary of anyone who does.
hard lawIn force 22 September 2023Official source
Réaliser une évaluation des facteurs relatifs à la vie privée — Guide d'accompagnement à la démarche et à sa documentation, version 3.1
Dans les autres cas, il n'est pas nécessaire de transmettre proactivement un rapport d'EFVP à la Commission. Celle-ci pourrait toutefois demander à en prendre connaissance dans le cadre de ses activités de surveillance.- What it means
- The Commission publishes a sixty-page guide that structures the PIA and, above all, its documentation. It's the reference an investigator will rely on to judge whether your assessment held up. § 1.1 (p. 11) lists the situations where the assessment is mandatory; § 7.1 (p. 49) deals with information leaving Quebec; § 7.2 (p. 51) places the “artificial intelligence system” among the forms an information system takes. The report itself does not have to be filed with the Commission outside the cases where the assessment precedes an agreement (p. 43 and § 5.4), but the process must exist and be producible.
- What we answer
- Two PIAs trigger at the same time when you adopt an AI platform: the section 3.3 one for acquiring the system, and the section 17 one for hosting and processing outside Quebec. They can live in a single document. If the GDPR covers you as well, count three: its article 35 impact assessment adds itself, with its own requirements. Ask us for the input kit: data flow, categories transferred, regions, provider policies, matching contractual clauses.
regulator expectationApril 2024Official source
Principles for responsible, trustworthy and privacy-protective generative AI technologies — federal, provincial and territorial privacy authorities of Canada, including the Commission d'accès à l'information, section 7
lorsque possible et raisonnable, utiliser des renseignements anonymisés ou dépersonnalisés dans les requêtes d'un système d'IA générative plutôt que des renseignements personnels; lorsque des renseignements personnels (et, en particulier, des renseignements sensibles ou confidentiels) doivent être entrés dans une requête, ne le faire que si cela est autorisé- What it means
- It is the only published document that bears directly on the subject of this page, and the Commission co-developed it: its own PIA Guide points to it as the “principles document developed by the Commission and its Canadian counterparts”. It is not hard law — the document says “should” — but it is the position an investigator will confront you with. Read the recommendation as it is written: neither “redact everything”, nor “redact nothing”. It asks you to use anonymized or de-identified information in the prompts sent to a generative AI system where that is possible and reasonable, and to enter personal information into a prompt only where doing so is authorized. The same section asks you to treat inferences produced about an identifiable individual as personal information, and not to retain prompts for secondary purposes.
- What we answer
- We do not de-identify your prompts: there is no pseudonymization gateway between your users and the model, and that is a choice we would rather state than let you guess. What the platform offers to apply this expectation: confidentiality mode, which makes a conversation ephemeral; the Law 25 detection, which flags message by message the presence of personal information and gives you the measure of the phenomenon rather than an impression — but you have to see what it costs here: it is a paid option, off by default, and the detection is itself an outbound call that sends the text of the message to a model. As a minimization measure, it increases exposure before measuring it; per-user and per-group access, which limits who can submit what; and three of the product's timers that cannot be switched off (30 days, 7 days, 48 hours) which bound how long traces live — but no configurable retention and no certificate of destruction. The act of de-identifying, where it is possible and reasonable, stays with your users; we supply the signal and the log that let you verify they are doing it. Those are the timers that reach a record; other clocks exist elsewhere in the product, and the Confidentiality and compliance page publishes the full inventory.
regulator expectation7 December 2023Official source
Personal Information Protection and Electronic Documents Act (S.C. 2000, c. 5), Schedule 1, principle 4.1.3; Organizations in the Province of Quebec Exemption Order (SOR/2003-374)
Une organisation est responsable des renseignements personnels qu'elle a en sa possession ou sous sa garde, y compris les renseignements confiés à une tierce partie aux fins de traitement. L'organisation doit, par voie contractuelle ou autre, fournir un degré comparable de protection aux renseignements qui sont en cours de traitement par une tierce partie.- What it means
- PIPEDA does not disappear because you are in Quebec: order SOR/2003-374 exempts a Quebec business only “with respect to the collection, use and disclosure of personal information that occurs within the Province of Quebec”, and never covers federal works and undertakings. Flows that cross the provincial border — hosting in Toronto, inference in the United States, a client or an employee in another province — stay within federal scope, in parallel with Law 25. What the principle quoted adds is simple and demanding: entrusting information to a third party for processing does not transfer accountability, and you must provide a COMPARABLE level of protection, by contractual or other means. The contract is therefore the means, not the end.
- What we answer
- The commitments in clause 14 of the master agreement are precisely the “contractual means” principle 4.1.3 calls for: enumerated purposes, subprocessors, security measures, incident notice, an annual audit right. Two limits to state. First, “comparable” is argued on the contract and not on the legal regime when inference happens at foreign providers, several of them in the United States: that is a conclusion you must be able to defend, not a box ticked. Second, we produce no third-party attestation; the audit right in clause 14.10 is what you have instead, and it is worth nothing unless you exercise it.
hard lawPIPEDA assented to in 2000; exemption order in force 19 November 2003Official source
Regulation (EU) 2016/679 (GDPR), art. 28
Processing by a processor shall be governed by a contract or other legal act under Union or Member State law, that is binding on the processor with regard to the controller...- What it means
- If you process data belonging to people in the EU/EEA and entrust that processing to us, a data processing agreement (DPA) separate from our master agreement is required: documented instructions, staff confidentiality, the article 32 security measures, authorized use of sub-processors, assistance with data subject rights, breach notification, and deletion or return of data at the end of the contract.
- What we answer
- We do not yet offer a GDPR-compliant DPA (article 28 clauses) in our standard catalogue. That is a gap we name rather than pretend otherwise. If your use touches data belonging to people in the EU or the EEA, tell us before you sign: we will assess with you whether an addendum can be negotiated, with no commitment on our part until it is signed. They are negotiated at the order form, case by case; productising them is not scheduled.
hard lawIn force since 25 May 2018Official source
Regulation (EU) 2016/679 (GDPR), art. 32
Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the controller and the processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including inter alia as appropriate: (a) the pseudonymisation and encryption of personal data […]- What it means
- Article 32 explicitly names encryption, the ability to restore availability after an incident, and a process for regularly testing security measures. The expected level depends on the risk to the individuals concerned, not on a single fixed standard.
- What we answer
- Encryption at rest and in transit, role-based access control, an audit log and a continuity plan are part of the architecture described on this page — the same measures assessed for Law 25. Article 32 asks for measures appropriate to the risk, and the audit right in clause 14.10 lets you audit them rather than believe them. But article 32 names a fourth element we do not satisfy: “a process for regularly testing, assessing and evaluating the effectiveness” of the measures. Our incident-response plan is written and publishes its severity tiers, but it has never been exercised; nor do we have documented recovery time and recovery point objectives proven by a restore drill. A plan never exercised is a hypothesis, and the audit right in s. 14.10 lets you establish that — it does not stand in for the testing the article requires of us.
hard lawIn force since 25 May 2018Official source
Regulation (EU) 2016/679 (GDPR), arts. 15 to 21
The data subject shall have the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed...- What it means
- Access, rectification, erasure, restriction, portability and objection: six distinct rights, each with its own conditions and deadlines — objection sits in article 21, outside the 15-to-20 range, and article 19, which is inside it, adds the duty to communicate any rectification, erasure or restriction to each of the recipients. As the controller, you are the one who answers the data subject — but you need your processor to be able to locate and produce their data.
- What we answer
- Conversations, documents and knowledge bases export and delete, per user, and a message can be corrected in place with an entry in the audit log. The export serves the article 20 portability right; it is not normalized into a structured interchange format. Do not file this gap on the European side alone: the same failing touches Quebec law — section 27, para. 3 of Law 25, in force since 22 September 2024, and section 3.3, para. 3, which asks you to make sure of it before you even acquire the system.
hard lawIn force since 25 May 2018Official source
Regulation (EU) 2016/679 (GDPR), Chapter V, arts. 44 to 49; standard contractual clauses (Commission Implementing Decision (EU) 2021/914)
Any transfer of personal data which are undergoing processing or are intended for processing after transfer to a third country or to an international organisation shall take place only if, subject to the other provisions of this Regulation, the conditions laid down in this Chapter are complied with by the controller and processor, including for onward transfers of personal data from the third country or an international organisation to another third country or to another international organisation.- What it means
- The end of the sentence quoted is the rule that matters here: Chapter V follows ONWARD transfers, not only the first hop. Canada holds a PARTIAL European Commission adequacy decision (Decision 2002/2/EC, maintained at the January 2024 review): it covers only private organizations actually subject to PIPEDA, which, for a Quebec host, does not go without saying and is verified rather than presumed — order SOR/2003-374 exempts from PIPEDA the collection, use and disclosure that occur within Quebec. The next hop, to a model provider outside the EU, needs its own basis: standard contractual clauses, or, for a certified US provider, the EU–US adequacy decision (Data Privacy Framework) of 10 July 2023.
- What we answer
- We do not yet offer signed standard contractual clauses in our standard catalogue. This is a direct gap for any EU/EEA personal data passing through our platform, and we would rather tell you now than have you find out in due diligence. Talk to us about your specific need: the solution depends on the nature of the transfer.
hard lawIn force since 25 May 2018; standard clauses of 4 June 2021Official source
Regulation (EU) 2016/679 (GDPR), art. 33
In the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the supervisory authority competent in accordance with Article 55, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where the notification to the supervisory authority is not made within 72 hours, it shall be accompanied by reasons for the delay.- What it means
- Seventy-two hours, but not an unconditional deadline: the obligation falls away if the breach is unlikely to result in a risk to rights and freedoms, and a late notification must be accompanied by the reasons for the delay. Compared with section 3.5 of Law 25, on this same page, the GDPR is stricter twice over: on the deadline (72 hours against “with diligence”) and on the threshold (a mere risk, against a “risk of serious injury”). The processor, for its part, notifies the controller “without undue delay” (para. 2), which lets the controller's clock start on time. And article 33 is only the first move: if the risk is HIGH, article 34 additionally requires the breach to be communicated to the data subjects, without undue delay.
- What we answer
- The contract obliges us to notify you without delay, with the nature of the incident, the people affected, the period and the measures taken (cl. 14.9) — but with no stated number of hours. For processing subject to the GDPR, this is a clause to negotiate explicitly in the order form: a commitment measured in hours, not just “without delay”.
hard lawIn force since 25 May 2018Official source
Regulation (EU) 2016/679 (GDPR), art. 35 and art. 30
Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data.- What it means
- If the GDPR covers you, it is not two assessments that trigger but three: the two Quebec PIAs, plus the article 35 impact assessment. A generative AI platform applied to client or employee files is the textbook case — new technologies and high risk — and paragraph 3 of the same article targets in particular systematic evaluation based on automated processing and large-scale processing of special categories of data. Its permanent counterpart is article 30: a record of processing activities, kept up to date, in which adding the platform creates an entry — purposes, categories of data subjects and of data, recipients, transfers outside the EU, erasure deadlines. It is the first document a supervisory authority asks for.
- What we answer
- The impact assessment and the record are yours; we supply the same inputs as for the Quebec PIA — data flow, categories transferred, hosting regions, inference subprocessors and their published policies, security measures, matching contractual clauses. Three facts to enter as such in your record, because they are counter-intuitive: the retention timers (30 days, 7 days, 48 hours) cannot be switched off, there is no configurable retention beyond them, and the export is not normalized into a structured interchange format. A useful reminder: without a processing agreement compliant with article 28, the impact assessment will conclude to a gap — we name it elsewhere on this page rather than let it slip here. Those are the timers that reach a record; other clocks exist elsewhere in the product, and the Confidentiality and compliance page publishes the full inventory.
hard lawIn force since 25 May 2018Official source
Regulation (EU) 2016/679 (GDPR), art. 22
The data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her.- What it means
- Do not read this article as a twin of section 12.1 of Law 25. Section 12.1 is an INFORMATION obligation: it presupposes that the decision may be made. Article 22 is a prohibition in principle, escaped only through one of the three exceptions in paragraph 2 — contractual necessity, authorization by Union or Member State law, explicit consent — and, in the contractual and consent cases, by putting in place safeguards including at least human intervention on the controller's part, the expression of the data subject's point of view and the ability to contest the decision. Paragraph 4 closes the door almost entirely on special categories of data. The question is therefore not “did I inform?” but “am I allowed to make this decision this way?”.
- What we answer
- The platform drafts, summarizes and suggests; it doesn't render decisions on its own. But it can automate, and you're the one building those automations — if one of them decides on its own about a person located in the EU, you must first establish your basis under paragraph 2, then demonstrate the safeguards of paragraph 3. On that last point, be warned: we offer no tooled “human intervention” workflow — no review queue, no standardized trace of a human re-examination. What the contract sets is a legal guardrail, not a technical one: no generated output may be a final automated decision without appropriate human validation (cl. 17 of the contract).
hard lawIn force since 25 May 2018Official source
Regulation (EU) 2016/679 (GDPR), art. 27
Where Article 3(2) applies, the controller or the processor shall designate in writing a representative in the Union.- What it means
- This is the immediate consequence of the situation described elsewhere on this page — being caught by the GDPR without an establishment in the Union. The designation is IN WRITING, the representative is established in one of the Member States where the data subjects are, and you must have one before the processing, not after a first request. The exception in paragraph 2 is narrow: occasional processing, with no large-scale processing of special categories and no risk to rights and freedoms. Putting European client files into an AI platform is nothing like occasional. The obligation bears on the controller and on the processor alike, so on you and on us, each for ourselves.
- What we answer
- We have no establishment in the Union and we have designated no representative within the meaning of article 27. That is a gap on our side, and it joins the two others we already name: no article 28-compliant processing agreement in the catalogue, no signed standard contractual clauses. If your use touches people located in the EU or the EEA, treat those three shortfalls as one and the same project and talk to us about it before you sign, not after. On your side, designating a representative is a separate step, which is yours and which nobody can take for you.
hard lawIn force since 25 May 2018Official source
What stays yours to do
No vendor can carry these obligations for you.
- Designate a person in charge of the protection of personal information and publish their title and contact information on your website (s. 3.1).
- Publish your governance policies and practices, including your retention and destruction rules (s. 3.2).
- Carry out and document the PIA before deploying the platform, and keep it — two obligations stack here, section 3.3 and section 17.
- Don't mistake the section 18.3 exception for a general dispensation: it sets aside consent, not the purpose requirement of section 12. Decide, request by request, what is genuinely necessary — and document that judgement rather than concluding there is nothing left to redact.
- Keep the register of confidentiality incidents and retain its entries for at least five years, even with no incident to report.
- Decide what your teams are allowed to put into the tool, write it down, and enforce it — that's an internal policy, not a setting.
- Train your users: most incidents start with a careless paste, not with a technical breach.
- Verify every year that the configuration of permitted models still matches the analysis you started from.
- If you process data belonging to people in the EU or the EEA, determine whether the GDPR applies to you directly (an EU establishment) or by targeting (offering goods or services, monitoring behaviour), and document that analysis.
- Negotiate a data processing agreement (DPA) compliant with article 28 and a transfer mechanism (standard contractual clauses) before entrusting data belonging to people in the EU or the EEA to the platform.
- Keep the article 30 GDPR record of processing activities if you are subject to it, and designate a representative in the Union within the meaning of article 27 if you have no establishment there.
- Ask the section 3.3, para. 3 design question before you sign: the system must be able to hand an individual, in a structured, commonly used technological format, the computerized information collected from them.
Questions to ask any AI vendor
Including us.
- Which categories of data leave Quebec, and for exactly how long?
- Can your platform hand me an individual's information in a structured, commonly used format, as section 27, para. 3 and section 3.3, para. 3 require?
- Do you provide me with a written agreement that meets the conditions of section 18.3, clause by clause?
- Who are your hosting and AI subprocessors, and will you notify me before changing them? Within what contractual notice period?
- Can I technically restrict which models are used, and does the refusal apply at call time or only in the interface?
- What exactly does the model provider see: my employee's name, their email address, or a technical identifier?
- What happens at the end of the contract: what export, what deadline for permanent deletion, and what will remain in your backups?
- Can you sign a data processing agreement (DPA) compliant with article 28 of the GDPR, and standard contractual clauses for transfers outside the EU or the EEA?
- What is your contractual deadline for notifying me of a data breach, given that I must meet the 72 hours of article 33 of the GDPR?
- Has an independent third party penetration-tested your platform, and may I see the report or its summary?
- Are the at-rest encryption keys managed by your host, or can I supply and revoke my own?
A vendor that answers yes to everything without evidence deserves more suspicion than one that names its limits.
Frequently asked questions
- Is there a threshold below which Law 25 does not apply?
- No. No employee threshold, no revenue threshold, no small-business exemption. As soon as a business operates in Quebec and holds personal information about others, it is covered.
- Does adopting an AI platform create new obligations?
- No: it triggers the ones that already existed, all at once. The s. 3.3 impact assessment, the s. 17 assessment if the request leaves Quebec, the written contract in s. 18.3, and s. 12.1 if a decision is made exclusively by the machine.
- Does the GDPR apply to me as well?
- If you process information about people located in the European Union, yes, and it adds its own requirements — including the chapter V framework for transfers outside the EU. This page names what we do not cover on that side.
Bottom line
- Law 25 does not ban AI for you
- A contract compliant with section 18.3 really does stand in for your clients' and your employees' consent.
- But that is all it stands in for
- Section 12 requires the use to serve the purpose of collection, section 18.3 covers only what is necessary to the mandate, and section 8 wants any departure from Quebec to have been announced at collection.
- Redacting: neither required nor optional
- It is not a general obligation, but “redact nothing” is not the rule either. It is a judgement to make request by request, and to document.
- The rest comes down to four moves
- Know where the data goes, have assessed it in writing before you start, have a contract that holds up, and be able to demonstrate it.
- The split of roles
- Our part is done and verifiable, with one exception we name above: the export is not in a common structured format (s. 27, para. 3), and that belongs in your assessment as written. The PIA, the register and the internal policy stay yours.
Other sectors
Financial services
AMF · CIRO · CSA · OSFI
Insurance and distribution
Distribution Act · Chambre de l'assurance · AMF
Law and notarial practice
Barreau · Chambre des notaires · Courts
Health and social services
Law 5 · Santé Québec · fifteen orders
Accounting and tax
CPA Québec · Professional Code
Public sector
Access Act · CAI · MCN · Public Contracts Act · BAnQ
Professional orders
Professional Code · CIQ · the orders