Skip to content
Insurance of persons and damage insurance

Here the law requires Quebec — not merely Canada

In most cases in Quebec, the law asks for an assessment, not an address. Address rules exist elsewhere too — for the notary, the social worker, the land surveyor — and the insurance rule — section 88 of the Distribution Act — requires Quebec, not merely Canada: the federal rule is satisfied by the country (Bank Act s. 239(1); Insurance Companies Act s. 262(1) for a federally chartered insurer), and the surveyor's is the hardest: the greffe stays in Quebec for an unlimited period, with no dispensation possible. In the distribution of financial products and services, it doesn't: section 88 of the Distribution Act requires a firm to keep its clients' records in Quebec. On top of that come a duty of secrecy paired with a purpose limitation, a five-year minimum retention period, and a compartmentalization requirement between claimants that few AI platforms can demonstrate.

Last reviewed:

Who regulates you

The bodies whose requirements apply to you.

  • LDPSFAct respecting the distribution of financial products and services (CQLR c D-9.2)

    The legal foundation. It is what imposes the keeping of records in Quebec (ss. 88 and 139), the AMF's access, and the limitation of access to relevant purposes (s. 92).

  • ChADChambre de l'assurance

    Created on 4 July 2025 by the merger of the Chambre de la sécurité financière and the Chambre de l'assurance de dommages (S.Q. 2025, c. 16). The codes of ethics have become its operating rules — still enforceable before the disciplinary committee.

  • AMFAutorité des marchés financiers

    Supervises insurers and inspects firms. Two guidelines adopted in March 2026 — one on AI and one on third-party risk — take effect in 2027: they describe what will be expected, and it is better to prepare for them now.

Requirement by requirement

Each requirement is quoted from its source, then answered.

Distribution Act (LDPSF)

Act respecting the distribution of financial products and services, s. 88 (see also s. 139 for the independent representative)

Un cabinet tient au Québec les dossiers de ses clients conformément aux règlements. Il y conserve et rend accessible à l'Autorité, par les moyens que celle-ci indique, tous les documents et tous les renseignements provenant de ses représentants.
What it means
This is a genuine localization requirement, not an assessment. The client record must be KEPT in Quebec — not in Canada, in Quebec — and remain accessible to the AMF. Section 139 imposes the same thing on the independent representative and the independent partnership. The regulation respecting firms (r. 2, s. 15) does, however, allow the information in a record to sit in different places as long as it stays recorded with the firm and can be produced.
What we answer
Two routes exist, and one has to be chosen explicitly. Either your system of record stays in Quebec and the platform is only incidental processing. Beware a common shortcut here: s. 15 of the firm regulation deals with the DISPERSAL of the information in a record across several places and says nothing about its location outside Quebec — so it does not authorize that route, it merely does not forbid it. It is an arrangement you have to be able to justify to the AMF, not a permission written down somewhere. Or you take private hosting, the only arrangement that offers a Quebec region — the shared cloud has only one Canadian region, in Toronto, and no line in the order form moves it. One precision that matters for your file: the host's residency commitment is to Canada, not to the province of Quebec, and it reserves the copying of data between Canadian regions. So we give you the exact fact rather than an assurance s. 88 would not recognize.

hard lawCurrent to 1 April 2026Official source

Distribution Act (LDPSF)

Act respecting the distribution of financial products and services, s. 89 (see also s. 140 for the independent partnership)

À moins d'avoir reçu d'un client le consentement visé à l'article 92, un cabinet inscrit dans une discipline de l'assurance tient, conformément au règlement, ses dossiers d'assurance séparément de ses autres dossiers. L'obligation de tenir des dossiers séparés ne doit pas être interprétée comme obligeant un cabinet à maintenir des systèmes informatiques distincts.
What it means
This is the only provision that bears on the FORM of the compartmentalization, and it settles two questions at once. Good news: the Act says expressly that the separation does not require two computer systems — so you do not need two instances. Real constraint: the insurance record must stay separate from the firm's other records, unless the client consents within the meaning of section 92.
What we answer
Concretely, a single firm-wide knowledge base fails this section by construction: it mixes insurance records in with everything else. The platform allows the right configuration — separate knowledge bases, per-group access lists, assistants dedicated to one discipline — but that is an architecture decision to be taken at the outset, not a default setting. We put it on the table explicitly in the configuration workshop.

hard law1998, c. 37, s. 89; current to 1 April 2026Official source

Distribution Act (LDPSF)

Act respecting the distribution of financial products and services, s. 92 (am. 2024, c. 15, s. 98); see also ss. 91 and 93

Un cabinet ne peut, même s'il possède, le 1er octobre 1999, un consentement d'un client pour utiliser les renseignements qu'il détient sur celui-ci à des fins non pertinentes à l'objet du dossier pour lequel ils ont été recueillis, permettre à un de ses représentants ou employés d'avoir accès à ceux-ci que s'il obtient de ce client un consentement particulier à cet effet.
What it means
A firm may not allow a representative or an employee to access a client's information for purposes that are not relevant to the object of the record for which it was collected, absent a specific consent given on a form used solely for that purpose. This is the hard-law anchor of purpose limitation, and it targets internal access as much as external.
What we answer
Access is set by role, by group and by named user, on every shareable object. An elevation policy makes it possible to restrict what an administrator can do, and impersonation windows are read-only, time-limited and logged. That's the tooling; mapping who should see which record remains your decision.

hard lawCurrent to 1 April 2026Official source

Chambre de l'assurance

Code of ethics of damage insurance representatives, s. 2 (wording identical to s. 2 of the Code of ethics of claims adjusters); see also ss. 80, 85 and 86 of the Distribution Act

Le représentant en assurance de dommages doit s'assurer que lui-même, ses mandataires et ses employés respectent les dispositions de la Loi sur la distribution de produits et services financiers (chapitre D-9.2) et celles de ses règlements d'application.
What it means
This is the “people under your responsibility” provision, and it changes the nature of the buying decision. Deploying an AI platform in a firm is not deciding for yourself: it is answering for whatever your entire staff types into it. Sections 80, 85 and 86 of the Distribution Act extend that responsibility to the firm and to its officers.
What we answer
What the tooling lets you demonstrate: named accounts — never a shared account —, groups and roles, a model catalogue restricted by the administrator, an audit log of who did what, and the ability to cut off a user's access immediately. What stays on you: the usage policy, the training, and the supervision — none of those three can be bought. One caveat: this restriction binds the models the user picks, not the calls the server makes on its own — so it is not, on its own, a residency control.

hard lawO.C. 1041-99, s. 2; operating rule of the Chambre de l'assurance, rev. 2 October 2025Official source

Chambre de l'assurance

Code of ethics of damage insurance representatives, s. 23 (formerly CQLR c D-9.2, r. 5); provision equivalent to s. 26 of the Code of ethics of the Chambre de la sécurité financière (formerly CQLR c D-9.2, r. 3)

Le représentant en assurance de dommages doit respecter le secret de tous renseignements personnels qu'il obtient sur un client et les utiliser aux fins pour lesquelles il les obtient, à moins qu'une disposition d'une loi ou d'une ordonnance d'un tribunal compétent ne le relève de cette obligation.
What it means
Two obligations in one sentence, and it is the second one that bites: the information may be used only for the purpose for which it was obtained. Training a model, improving a product or running analytics on the contents of a record are foreign purposes — regardless of any security question.
What we answer
The contract prohibits using your confidential information to train a public model without your written authorization, and limits processing to a closed list of purposes (ss. 14.2 and 14.7). The preamble sent to the provider identifies the author: their name and email, plus whichever directory fields are filled in. A service key changes nothing here: the preamble carries the record of the administrator who created it. The name given to the key serves to group reports together, not the identity transmitted to the provider. The console displays, provider by provider, the published training and retention policy. A note on the source: since 15 July 2025 these codes are no longer regulations and LégisQuébec displays them as “Repealed”; the text that binds you is the one the Chambre publishes as an operating rule, and that is the one we link to.

hard lawO.C. 1041-99; became an operating rule of the Chambre de l'assurance under S.Q. 2025, c. 16, s. 39, on 15 July 2025; the Chambre's operative version, rev. 2 October 2025Official source

Chambre de l'assurance

Code of ethics of claims adjusters, s. 24 (see also s. 22 on secrecy) — formerly CQLR c D-9.2, r. 4

L'expert en sinistre ne peut accepter un mandat ou en continuer l'exécution s'il comporte ou peut comporter la divulgation ou l'usage de renseignements ou de documents confidentiels obtenus d'un autre sinistré à moins que ce dernier n'y consente.
What it means
Section 22 sets out ordinary secrecy; section 24 goes further, and it is the one that bears on an AI platform: an adjuster may neither accept nor continue a mandate that would involve the use of information obtained from ANOTHER claimant, without that person's consent. This is a compartmentalization requirement, and it reaches straight into shared memories, common knowledge bases and firm-wide indexes.
What we answer
Every knowledge base, every assistant and every conversation carries its own access lists (a folder created inside a project is shared with the project's members from the outset, and its creator keeps no particular authority over it; a personal folder cannot be converted into a shared folder), by user and by group: nothing is visible organization-wide by default. Content can feed an answer only if it has been explicitly attached to the conversation or to a base the user is entitled to. So the compartmentalization is yours to configure, file by file — the platform makes it possible, it does not guess it.

hard lawO.C. 1143-2007; became an operating rule of the Chambre de l'assurance on 15 July 2025; the Chambre's operative version, rev. 2 October 2025Official source

Regulation

Regulation respecting the keeping and preservation of books and registers, CQLR c D-9.2, r. 19, s. 15 (see also ss. 16 and 18)

Tout cabinet, représentant autonome ou société autonome doit conserver ses dossiers clients pour une période d'au moins 5 ans à compter du dernier des événements suivants: 1° la fermeture définitive du dossier du client; 2° la date de prestation du dernier service rendu au client;
What it means
Five years at minimum, counted from the LAST of the three events — the third being the expiry, without renewal or replacement, of the last product sold. Destruction is permitted after that, but section 18 requires that it respect the confidential nature of the information.
What we answer
No purge you can configure breaks your five-year clock, and conversations, documents and attachments export for your archive. Three automatic deletions apply all the same. Three timers are hard-coded and reach a record directly — transcripts at 30 days, tool-produced files at 7 days, attachments uploaded but never sent at 48 hours — and if one of them holds a piece of your file — the document a client uploaded in a message that stayed unsent, the recording of a meeting nobody filed anywhere else — it destroys it without regard to your five-year clock, and with no certificate of destruction. You have to export it before the deadline; that is the only remedy. As with any working tool, the master copy of the file belongs in your archiving system: that is what carries the five years. Those are the timers that reach a record; other clocks exist elsewhere in the product, and the Confidentiality and compliance page publishes the full inventory.

hard lawCurrent to 1 April 2026; am. M.O. 2023-09Official source

Regulation

Regulation respecting firms, independent representatives and independent partnerships, CQLR c D-9.2, r. 2, s. 13 (see also s. 15)

Le cabinet, le représentant autonome ou la société autonome qui utilise l'informatique ou toute autre technique de traitement de données doit prendre toutes les mesures nécessaires pour en empêcher la perte, la destruction ou la falsification des écritures.
What it means
Computerization is expressly permitted, on three conditions: preventing the loss, destruction and falsification of entries; being able to provide the information in each record within a reasonable time, in a precise and intelligible form, to any auditor authorized by the Act; and, under section 15, keeping records in different places remains possible as long as the record can still be produced.
What we answer
Timestamped audit log of authentications, impersonations and administrative changes, with the authentication log sealed by cryptographic chaining. Authorisation denials feed a daily counter per role and per capability, kept 30 days. Conversations, documents and attachments export in a readable form for an AMF inspection. On the section's three verbs, let us be exact, because we cover only one of them cleanly. Falsification: changes leave an audit entry, but we do not seal the CONTENT — an exported output is not tamper-evident and nothing marks it as model-produced. Destruction: three of the product's hard-coded clocks reach a record and cannot be turned off — transcriptions at 30 days, tool-produced files at 7 days, attachments never sent at 48 hours — and we issue no attestation of destruction. Loss: the database backups are geo-redundant, but the files you upload are backed up only by daily block snapshots kept 14 days, in your instance's region. And the export is by conversation and by document, not by file number: the retrieval an inspector needs stays your work.

hard lawCurrent to 1 April 2026; am. M.O. 2025-10Official source

Chambre de l'assurance (ChAD)

Your professional and ethical obligations in the age of AI — A guide, section 2 “Duty of confidentiality and protection of personal information”

La transmission de renseignements personnels doit être limitée aux SIA privés, autorisés et validés par votre employeur.
What it means
The Chambre reasons in terms of control, not hosting country. A public generative AI system, or one that does not offer satisfactory guarantees of confidentiality, security and retention, must receive no personal, sensitive, confidential or privileged information. It further requires an independent human review of generated content and transparency toward the client.
What we answer
That is precisely the configuration we deliver: an instance dedicated to your firm, not a shared consumer service, with each model provider's policies displayed so that your employer's authorization rests on verifiable facts rather than on an impression. Human review of generated content remains yours, and the contract says so expressly.

regulator expectationNovember 2024Official source

Chambre de l'assurance (ChAD)

Advice sheet — Best practices: artificial intelligence in your professional practice, point 5

Informez les consommateurs, par un moyen approprié (par exemple, une mention ou un tatouage numérique), qu'un contenu publié par un intervenant financier a été créé, en tout ou en partie, par une IA générative. Sur demande, fournissez la liste des renseignements personnels et confidentiels concernant le client qui ont été utilisés par le SIA, et assurez-vous d'être en mesure de les rectifier ou de les mettre à jour s'ils sont erronés.
What it means
Two expectations that no policy can settle: the tool has to make it possible to hold them. The first: informing consumers, by a mention or a digital watermark, that published content was created, in whole or in part, by generative AI. The second: for a given answer, being able to list on request the client information that fed it — prompt, attachments, excerpts from bases — and to be in a position to correct or update it. Both are addressed to the representative, in the imperative, and not to the vendor: the Chambre states no expectation toward us, but neither of the two can be held without a product that lends itself to it. This is not a future expectation: the Chambre has been stating it since November 2024, independently of the AMF guidelines that only take effect in 2027.
What we answer
An honest answer, point by point. Reconstructing what fed an answer: that is possible — the conversation keeps the prompt, the attachments and the attached bases, and the cited sources are shown under the answer — but it is a manual read, not a “list of information used” report you export in one click. Correcting: a message can be edited, a document can be replaced in a base, and the trace stays in the log. Labelling generated content: the platform puts no mention and no watermark on text you copy out of the tool — the labelling is on you today, and the tooling is on our roadmap.

regulator expectationNovember 2024 (published 4 December 2024)Official source

Autorité des marchés financiers

Guideline on the use of artificial intelligence, sections 8.2 and 8.3; and Guideline on third-party risk management, section 9.8

De plus, lorsque les clients font l'objet d'une décision prise par un SIA ou qui a été recommandée par un SIA à une personne qui agit pour son compte, l'institution devrait expliquer clairement et simplement la décision aux clients.
What it means
These two guidelines are NOT yet in force — we say so because many vendors already present them as applicable law. They signal what will be expected: explainability of decisions made or recommended by an AI system, informing the client, access to a human being, bias monitoring, and protection of data at the third party equivalent to that at the institution.
What we answer
What already exists on our side and serves that preparation: per-user attribution, audit log, restriction of the model catalogue, and provider policies on display. What is missing and will still be missing in 2027 if nothing changes: prompt and model versioning exposed to the client, and bias-detection tooling. Neither is on our roadmap. What is on it — the labelling of generated content — answers a different expectation, not the 2027 one. One important precision about labelling generated content: do not wait for 2027. The Chambre has been asking for it since November 2024 — that is a current expectation, not a future one, and the gap is ours.

regulator expectationMarch 2026 — takes effect on 1 May 2027 for AI; the third-party guideline takes effect in 2027, on a date we could not verify at sourceOfficial source

What stays yours to do

No vendor can carry these obligations for you.

  • Determine where the master client record is kept and be able to demonstrate it — section 88 targets the firm, not the vendor.
  • Obtain your employer's authorization for each AI system used, and document it, as the ChAD guide requires.
  • Map who has access to which record, and open access only for purposes relevant to the object of the record (s. 92 of the Distribution Act).
  • Have a human review any generated content before filing it in the record or sending it to the client — AI relieves no one of their duty to advise.
  • Run the five-year calculation from the last of the three events, including the replacement of a product, and not from the date of the last conversation.
  • Label published content that was created, in whole or in part, by generative AI — the ChAD has been asking for this since November 2024, not starting in 2027.
  • Tell the client when AI is involved in the service being provided to them.

Questions to ask any AI vendor

Including us.

  • Can the master client record stay kept in Quebec, and if your hosting is elsewhere, how do you organize my compliance with section 88 of the Distribution Act?
  • Will you commit in writing to using my content for no purpose other than delivering the service — no training, no model improvement, no analytics?
  • How do you guarantee that one claim file can never feed the answer generated for another claimant?
  • For a given answer, can you give me the list of the client information that fed it, and let me correct it?
  • Can I export an entire record, in a precise and intelligible form, within a reasonable time, for an AMF inspection?
  • Do you provide a certificate of confidential destruction at the five-year mark, covering copies, backups, indexes and logs?
  • Who are your subprocessors, including model providers, in which countries, and will you notify me before changing them?

A vendor that answers yes to everything without evidence deserves more suspicion than one that names its limits.

Frequently asked questions

Does the client record really have to be kept in Quebec?
Yes. Section 88 of the Distribution Act requires it, and it requires Quebec, not merely Canada: the federal rule is satisfied by the country (Bank Act s. 239(1); Insurance Companies Act s. 262(1) for a federally chartered insurer). Other address rules do exist elsewhere in the professional system: the notary must keep their records at the office, their étude (N-3, r. 17, s. 23), the social worker at the place where they practise (C-26, r. 297) — and the hardest of them all is the land surveyor's greffe, which must stay in Quebec with no dispensation possible. Our default hosting region is in Canada, outside the province of Quebec — a point to settle explicitly before signing.
How is that point actually settled?
On the order form, or through the organization of your system of record. What we refuse to do is let you sign assuming the default configuration answers it: it does not.
What about the sector's other obligations?
Professional secrecy, purpose limitation and partitioning are covered or tooled. The five-year retention, though, is tooled but not guaranteed: three automatic deletions that cannot be switched off can carry off a piece of the file, and the only remedy is to export it before the deadline. Three gaps remain and we name them: no configurable retention, no certificate of destruction, and no automatic labelling of generated content — which the Chambre, for its part, has been asking for since November 2024.

Bottom line

A location rule that requires Quebec
Section 88 imposes Quebec; our default hosting is in Canada, outside Quebec. To be settled explicitly before signing.
Covered or tooled
Professional secrecy, purpose limitation, compartmentalization.
Five years: tooled, not guaranteed
Automatic deletions can carry off a piece of the file. Export it before the deadline.
The gaps we name
No configurable retention, no certificate of destruction, no automatic labelling of generated content.

Other sectors

Back to the security pageRead the Law 25 guide