Canadian Privacy & AI Law

Quebec Law 25

Law 25: An Act to modernize legislative provisions as regards the protection of personal information (formerly Bill 64)

Quebec's modernized privacy law, the strictest in North America, with fines up to C$25M or 4% of worldwide turnover. Explained here as it applies to AI tools: mandatory privacy impact assessments, automated-decision transparency, and data leaving Quebec.

Quebec, Canada (private and public sectors)Fully in force; final phase (data portability) effective September 2024Verified 2026-08-31

What it means for AI and data privacy

Law 25 is the closest thing North America has to the GDPR, and it reaches AI use directly. Before acquiring or deploying any technology that processes personal information, which includes an AI tool employees will paste customer data into, organizations must conduct a privacy impact assessment, and another one before communicating personal information outside Quebec, which most US-hosted AI vendors trigger. Section 12.1 requires telling individuals when a decision about them is based exclusively on automated processing. Confidentiality by default, strict consent rules for secondary uses, and fines up to C$25 million or 4% of worldwide turnover make Quebec the jurisdiction where unmanaged employee AI use is most expensive. The CAI is an active regulator with audit and order powers, not a paper tiger.

Who it applies to

  • Any enterprise carrying on business in Quebec that collects, holds, uses, or communicates personal information, regardless of where it is headquartered
  • Quebec public bodies under the parallel public-sector act
  • Organizations outside Quebec that receive personal information about people in Quebec
  • Any AI tool, procured or shadow, that processes personal information of Quebec residents

Enforcement and penalties

Law 25 gave the CAI real teeth. Administrative monetary penalties reach C$10 million or 2% of worldwide turnover, whichever is greater, imposed directly by the CAI without going to court. Penal offences, such as unlawful collection or communication of personal information or obstructing the CAI, carry fines up to C$25 million or 4% of worldwide turnover, whichever is greater. The law also created a private right of action with minimum punitive damages of C$1,000 for intentional or grossly negligent violations. The CAI can order an organization to stop communicating personal information, including to a technology vendor, and has been actively investigating since the core provisions took effect in September 2023.

Key provisions for AI and data privacy

Private-sector act, s. 3.3

Privacy impact assessment before acquiring or deploying tech that processes personal information

An enterprise must conduct a privacy impact assessment (PIA) for any project to acquire, develop, or overhaul an information system or electronic service delivery project involving personal information, proportionate to the sensitivity and volume of the information.

Rolling out an AI assistant, or discovering employees already use one with customer data, is exactly the kind of project s. 3.3 was written for. The PIA must happen before deployment, not after an incident, and must consider what personal information the tool will receive and how it is protected. Shadow AI makes this impossible to satisfy: LayerX found in 2025 that organizations have no insight into roughly 89% of AI usage, and you cannot assess a system you do not know exists.

Private-sector act, s. 17

Assessment before communicating personal information outside Quebec

Before communicating personal information outside Quebec, an enterprise must conduct a privacy impact assessment considering the sensitivity of the information, the purposes, the protections in place, and the legal regime of the receiving jurisdiction, and may proceed only if the assessment establishes adequate protection, with a written agreement.

Most popular AI tools are hosted in the United States, so a prompt containing personal information typed by an employee in Montreal is a communication outside Quebec that s. 17 requires you to have assessed in advance. An organization that has never run this assessment but whose staff use US-hosted chatbots with client data is out of compliance on every such prompt. Redacting personal information before submission removes the communication that triggers the section.

Private-sector act, s. 12.1

Transparency for decisions based exclusively on automated processing

When an enterprise uses personal information to render a decision based exclusively on automated processing, it must inform the person at the time of or before the decision, and on request tell them what information was used, the reasons and principal factors behind the decision, and their right to have it corrected. Observations from a person able to review the decision must be possible.

If AI screens resumes, scores credit or insurance applications, or triages customers without a human meaningfully in the loop, s. 12.1 obligations attach. Organizations need to know which of their processes have quietly become automated decisions as teams adopt AI, and to keep a human review path open. This is one of the few automated-decision transparency rules actually in force in North America, in effect since September 2023.

Private-sector act, s. 9.1

Confidentiality by default for technology products and services

An enterprise that collects personal information when offering a technological product or service to the public must ensure the privacy settings provide the highest level of confidentiality by default, without any intervention by the person concerned.

For organizations building AI-enabled products for Quebec users, privacy-protective defaults are mandatory, not a design preference. Internally, the same philosophy is the sensible reading of the whole act: the default state of employee AI use should be that personal information does not flow out, with exceptions deliberately opened rather than leaks deliberately closed after the fact.

Private-sector act, ss. 12 and 14

Consent: new purposes need new, specific consent

Personal information may be used within the enterprise only for the purposes for which it was collected, unless the person consents or a narrow exception applies (such as certain de-identified uses for study or statistics). Consent must be clear, free, informed, given for specific purposes, and requested in clear and simple language, separately from other terms.

Feeding customer records to an external AI tool is almost never among the purposes consented to at collection, so it needs fresh, specific consent or must fit a narrow exception. Law 25's consent standard is demanding enough that consent-based fixes are fragile for AI use. De-identification before the data enters the tool is the more robust path, since properly de-identified information used within permitted bounds sidesteps the consent problem.

Practical compliance steps

  1. 1Inventory every AI tool in use across the organization, including unapproved browser-based tools, before the CAI or an incident does it for you
  2. 2Run a privacy impact assessment under s. 3.3 for AI tools that will process personal information, and document proportionality
  3. 3Run the s. 17 assessment for any AI vendor hosted outside Quebec, and put the required written agreement in place
  4. 4Identify processes where AI decisions have no meaningful human involvement and build the s. 12.1 notice and review path
  5. 5Set the internal default that personal information does not enter AI prompts, and enforce it with a technical control that redacts identifiers before submission
  6. 6Train Quebec staff on what counts as personal information in a prompt: names, addresses, SINs, health details, financial identifiers
  7. 7Record interception and usage evidence so PIAs and CAI inquiries can be answered with data rather than estimates

How Sanitized AI maps to this

s. 17 (communication outside Quebec)

Personal identifiers are caught and redacted in prompts before submission, so what reaches a US-hosted AI vendor carries far less personal information, shrinking the scope of the cross-border communication the assessment must justify.

s. 3.3 (privacy impact assessment)

Admin dashboards show which AI tools employees actually use and what categories of personal data were caught, giving the PIA a factual inventory to assess instead of guesswork.

Confidentiality by default (s. 9.1 philosophy)

Redaction at the point of entry makes 'personal information stays in' the default state of employee AI use, with exceptions a deliberate administrative choice rather than an accident.

Accountability to the CAI

Interception logs and usage reporting give the privacy officer documented evidence of controls in operation, the kind of record that distinguishes a defensible position from a penalty case after an incident.

Frequently asked questions

Does Quebec Law 25 apply to companies outside Quebec?

Yes, if they handle personal information about people in Quebec in the course of carrying on business there. A Toronto or US company serving Quebec customers is subject to the private-sector act for that information, including its rules on cross-border communication and its penalty regime.

Do we need a privacy impact assessment before using AI tools in Quebec?

If the tool processes personal information, yes. Section 3.3 requires a PIA for any project to acquire, develop, or overhaul an information system involving personal information, and an AI tool that receives customer or employee data in prompts qualifies. A second assessment under s. 17 is required before personal information is communicated outside Quebec, which US-hosted AI vendors trigger.

Can Quebec employees use ChatGPT with customer data?

Not with identifiable customer data, absent specific consent, a completed s. 17 assessment for the cross-border communication, and a purpose covered at collection, which together almost never line up for casual chatbot use. The workable approach is to let employees use AI tools while stripping personal information from prompts, so the activity no longer involves communicating personal information at all.

What are the penalties under Quebec Law 25?

The CAI can impose administrative monetary penalties up to C$10 million or 2% of worldwide turnover, and penal offences carry fines up to C$25 million or 4% of worldwide turnover, whichever is greater. There is also a private right of action with minimum punitive damages of C$1,000. These are the heaviest privacy penalties in North America.

What does Law 25 say about automated decision-making?

Section 12.1 requires informing individuals when a decision about them is based exclusively on automated processing, and on request explaining what information was used and the principal factors behind the decision, with an opportunity to make observations to someone who can review it. It has been in force since September 2023 and covers AI-driven screening, scoring, and triage without meaningful human involvement.

Is Quebec Law 25 the same as Bill 64?

Yes. Bill 64 was the bill number; once adopted in September 2021 it became Law 25 (Loi 25). It amended Quebec's existing private-sector and public-sector privacy acts in three phases, September 2022, September 2023 (the bulk, including PIAs, penalties, and automated-decision transparency), and September 2024 (data portability).

Primary sources

This guide summarizes the cited primary sources as of the verification date. It is general information, not legal advice.

The gap in every framework is the prompt box.

Sanitized AI catches sensitive data in prompts before it leaves and shows administrators which AI tools employees actually use.

Get a demo

Related standards