Private-sector act, s. 3.3
Privacy impact assessment before acquiring or deploying tech that processes personal information
An enterprise must conduct a privacy impact assessment (PIA) for any project to acquire, develop, or overhaul an information system or electronic service delivery project involving personal information, proportionate to the sensitivity and volume of the information.
Rolling out an AI assistant, or discovering employees already use one with customer data, is exactly the kind of project s. 3.3 was written for. The PIA must happen before deployment, not after an incident, and must consider what personal information the tool will receive and how it is protected. Shadow AI makes this impossible to satisfy: LayerX found in 2025 that organizations have no insight into roughly 89% of AI usage, and you cannot assess a system you do not know exists.
Private-sector act, s. 17
Assessment before communicating personal information outside Quebec
Before communicating personal information outside Quebec, an enterprise must conduct a privacy impact assessment considering the sensitivity of the information, the purposes, the protections in place, and the legal regime of the receiving jurisdiction, and may proceed only if the assessment establishes adequate protection, with a written agreement.
Most popular AI tools are hosted in the United States, so a prompt containing personal information typed by an employee in Montreal is a communication outside Quebec that s. 17 requires you to have assessed in advance. An organization that has never run this assessment but whose staff use US-hosted chatbots with client data is out of compliance on every such prompt. Redacting personal information before submission removes the communication that triggers the section.
Private-sector act, s. 12.1
Transparency for decisions based exclusively on automated processing
When an enterprise uses personal information to render a decision based exclusively on automated processing, it must inform the person at the time of or before the decision, and on request tell them what information was used, the reasons and principal factors behind the decision, and their right to have it corrected. Observations from a person able to review the decision must be possible.
If AI screens resumes, scores credit or insurance applications, or triages customers without a human meaningfully in the loop, s. 12.1 obligations attach. Organizations need to know which of their processes have quietly become automated decisions as teams adopt AI, and to keep a human review path open. This is one of the few automated-decision transparency rules actually in force in North America, in effect since September 2023.
Private-sector act, s. 9.1
Confidentiality by default for technology products and services
An enterprise that collects personal information when offering a technological product or service to the public must ensure the privacy settings provide the highest level of confidentiality by default, without any intervention by the person concerned.
For organizations building AI-enabled products for Quebec users, privacy-protective defaults are mandatory, not a design preference. Internally, the same philosophy is the sensible reading of the whole act: the default state of employee AI use should be that personal information does not flow out, with exceptions deliberately opened rather than leaks deliberately closed after the fact.
Private-sector act, ss. 12 and 14
Consent: new purposes need new, specific consent
Personal information may be used within the enterprise only for the purposes for which it was collected, unless the person consents or a narrow exception applies (such as certain de-identified uses for study or statistics). Consent must be clear, free, informed, given for specific purposes, and requested in clear and simple language, separately from other terms.
Feeding customer records to an external AI tool is almost never among the purposes consented to at collection, so it needs fresh, specific consent or must fit a narrow exception. Law 25's consent standard is demanding enough that consent-based fixes are fragile for AI use. De-identification before the data enters the tool is the more robust path, since properly de-identified information used within permitted bounds sidesteps the consent problem.