Back to Blog
Cybersecurity9 min read

Quebec's Law 25 in 2026: What the AI and Automated Decision-Making Obligations Actually Require

By Anton Kuznetsov

Most Canadian SMB owners know they are covered by PIPEDA. Fewer know about Quebec's *Act Respecting the Protection of Personal Information in the Private Sector* — commonly called Law 25 — and fewer still have mapped what its AI-specific obligations require of them.

Law 25 is Canada's strictest provincial privacy law. Enacted in 2021 as Bill 64 and rolled out in three annual phases, it reached full force on September 22, 2024. Unlike PIPEDA, Law 25 contains explicit rules for automated decision-making, mandatory Privacy Impact Assessments for AI systems, and a data-transfer authorization framework with real teeth. And it applies to any organization doing business with Quebec residents — regardless of where that organization is headquartered.

If your business sells to Quebec customers, employs Quebec residents, or processes personal information about Quebec individuals in any capacity, Law 25 applies to you.

Who Law 25 Applies To

Law 25's extraterritorial scope is the detail most non-Quebec SMBs overlook. The Act applies to any enterprise that collects, uses, or discloses personal information about individuals located in Quebec — including businesses physically based in Ontario, British Columbia, or the United States. Unlike many US state privacy laws, Law 25 sets no minimum revenue threshold and no minimum data-volume threshold.

Quebec accounts for roughly 22.1% of Canada's private sector employment and is home to 228,622 small businesses as of December 2024, according to ISED's Key Small Business Statistics 2025. But the number that matters for Law 25 scope is not how many businesses are in Quebec — it is how many businesses *outside* Quebec do business with Quebec residents. That includes every Canadian e-commerce company that ships to Quebec, every SaaS vendor serving Quebec clients, and every professional services firm with Quebec employees or customers.

As Bryan Cave Leighton Paisner put it bluntly: Quebec Law 25 is "a little-known privacy law with a big reach." Organizations based in Toronto, Vancouver, or Calgary that assumed Law 25 was a Quebec-only concern are now in scope and, in many cases, non-compliant.

The Three Phases — All Now in Force

Law 25 was introduced in three annual tranches. All obligations are active:

PhaseDateKey obligations
Phase 1September 22, 2022Privacy incident reporting, confidentiality incident register, data subject access rights
Phase 2September 22, 2023PIAs for information system projects, informed consent framework, automated decision transparency, cross-border transfer authorizations
Phase 3September 22, 2024Right to data portability, data destruction and anonymization obligations

Phase 2 introduced the most operationally demanding requirements — including the AI and automated-decision rules — and represents the compliance gap most likely to exist in SMB environments that have not run a formal Law 25 audit.

The AI Obligation Most Businesses Miss: Section 12.1

Section 12.1 of Law 25 is the provision that creates the most significant compliance risk for organizations deploying AI tools in 2026. It applies whenever a decision is made exclusively by automated means, using personal information, and that decision significantly affects the exercise of a person's rights.

As Torys LLP's analysis of the provision explains, when both conditions are met, the organization must:

  • Inform the individual that the decision was made by automated means
  • Explain the factors that influenced the decision, on request
  • Provide a right to human review — the individual can submit observations to a person with genuine authority to change the outcome

The "exclusively by automated means" threshold is lower than it sounds. A credit pre-qualification result, a job application screening score, a content-moderation decision, or a risk tier assigned in a CRM — if personal information was used and no meaningful human review occurred before the decision was finalized, Section 12.1 applies.

The right to human review has a genuine authority requirement: the reviewer must be able to actually change the outcome, not merely re-explain the system's result. An audit log or a supervisor acknowledgement does not satisfy the obligation. For a small business, the CAI's guidance indicates this can be a named contact or a form that routes review requests to someone empowered to override the system — but the channel must be real and functional.

For organizations using AI tools to score leads, filter job applications, categorize customer risk, or price services dynamically, this obligation may already be active and unaddressed.

Privacy Impact Assessments for AI Tools

Section 3.3 of Law 25 requires a Privacy Impact Assessment before deploying any information system that presents elevated risks to privacy. AI tools that process personal information about individuals — particularly those used for profiling, scoring, or automated decision-making — typically qualify.

On September 22, 2023, the Commission d'accès à l'information du Québec (CAI) released its guide on conducting Law 25-compliant PIAs, providing a four-step methodology: identify the personal information involved, assess its sensitivity and necessity, evaluate privacy risks, and implement mitigating controls.

A PIA is not a one-time filing. If an AI tool's capabilities expand, its data inputs change, or a significant new use case is introduced, the PIA must be updated. For SMBs deploying SaaS AI tools — Microsoft 365 Copilot, HubSpot, an AI-powered ATS, a dynamic pricing engine — this means your supplier agreements need to include information about the tool's data practices in enough detail to support a PIA. Vendor privacy documentation that amounts to a generic privacy policy does not satisfy the requirement.

Cross-Border Data Transfers

Law 25 requires an authorization before personal information about Quebec residents is communicated to a person or system outside Quebec — including to infrastructure in Ontario, to a US-based SaaS vendor, or to a hyperscaler processing data in US-region capacity.

The authorization requirement is satisfied by completing a PIA that assesses whether the receiving jurisdiction provides adequate protection. As GetLimina's Law 25 data transfer guide notes, for transfers to US-based service providers, organizations must assess whether US government access mechanisms — including the CLOUD Act — could expose Quebec resident data to foreign government access.

This obligation is operative now. If your organization uses any cloud service, CRM, or SaaS tool that routes Quebec resident data through US-based infrastructure — which covers nearly every Canadian SMB with a modern software stack — a documented transfer authorization is part of your mandatory compliance posture.

The Privacy Officer Requirement

Every organization subject to Law 25 must designate a Privacy Officer. If no one is formally designated, the CEO is automatically considered the Privacy Officer and bears personal responsibility for compliance. Organizations that designate someone other than the CEO must publish that person's name, title, and contact information on their website.

The Privacy Officer oversees PIAs, manages data subject access requests, coordinates breach reporting to the CAI, and maintains the records Law 25 requires. For SMBs without a dedicated privacy function, this role is typically assigned to a senior operations or IT leader, or outsourced to an external privacy consultant.

The public-posting requirement is frequently missed: many SMBs have completed the internal designation but have not posted the officer's contact information on their website, leaving them technically non-compliant on a simple and visible requirement.

The Penalty Structure

Law 25's administrative penalties mirror the GDPR's scale:

  • Up to $10 million CAD or 2% of worldwide turnover for less severe violations
  • Up to $25 million CAD or 4% of worldwide turnover for the most serious violations — whichever is greater

No size threshold applies. A three-person startup and a publicly traded corporation face the same maximum exposure. The CAI received expanded investigative authority under Law 25, including the power to compel document production within five business days of opening a confirmed breach investigation.

CAI Enforcement in Action

The CAI published its first formal enforcement decision under the Law 25 amendments in September 2024, ordering Transcontinental Printing Inc. to cease using facial recognition technology for employee access control. As Stikeman Elliott's analysis of the decision explains, the CAI found that collection of facial biometric data was not sufficiently necessary or proportionate — even though the company had registered the system with the CAI as required under Quebec law, and even though employees had consented to its use.

The Transcontinental decision established a precedent with broad implications: consent alone does not validate an automated system. The CAI will scrutinize the necessity and proportionality of the personal information collected, the existence of less privacy-invasive alternatives, and whether the organization can articulate a clear legitimate purpose that justifies the collection. For SMBs considering AI tools that use biometric, behavioural, or sensitive personal data, this threshold is the relevant benchmark.

The CAI has indicated that systematic compliance audits — not just complaint-response investigations — will increase through 2026. Waiting for a complaint before assessing compliance is not a viable posture.

The Six-Item Compliance Checklist

If your organization handles personal information about Quebec residents and has not yet formalized its Law 25 compliance position:

1. Designate a Privacy Officer and publish their name and contact information on your website.

2. Inventory your AI and automated tools for any that make decisions significantly affecting individuals using their personal information.

3. Build a human review channel for each automated decision system: a named contact with genuine authority to change outcomes, reachable within a documented timeframe.

4. Complete PIAs for each AI system that profiles, scores, or makes decisions about individuals, before deployment and updated when the tool changes.

5. Map data transfers outside Quebec and document the PIA-backed authorization for each, including assessments of US CLOUD Act exposure for US-hosted services.

6. Review your privacy policy for Law 25-required disclosures: what information you collect, the purpose, retention period, and how individuals can exercise their access, correction, and portability rights.


Sources


Law 25 is fully in force, its AI obligations are specific, and the CAI has made clear it will pursue systematic compliance audits rather than waiting for complaints. Cloud Forces helps Canadian businesses assess their Law 25 exposure, structure Privacy Impact Assessments for AI tools, and implement the automated-decision disclosure frameworks the law requires — without building a compliance program from scratch. Explore our AI Advisory services or contact us to discuss where your current AI deployments stand under Quebec's privacy framework.

Anton Kuznetsov
Founder & Principal Engineer

Anton Kuznetsov is the founder and principal engineer of Cloud Forces, the Toronto firm he started in 2018 to make custom software and AI practical and affordable for Canadian SMEs. He works hands-on across application development, cloud architecture, and the production systems Cloud Forces runs for its clients.

Ready to bring AI to your business?

Book a free AI Readiness Consultation — no commitment required.

Book Free Consultation