AI and your privacy obligations: What changes when your team adopts AI
What actually changes under Law 25 and PIPEDA when your team starts using AI tools — and why the vendor's country of jurisdiction ended up mattering more than the tool.
The thing that stopped us wasn't the AI tool. It was realizing none of us could say, with a straight face, where the questions our staff were typing into it actually went.
We're a small professional services shop — under thirty people, no in-house counsel, one person who handles privacy and finance and half of HR because that's how it works at this size. Someone on the team started using a free AI chatbot to draft client emails and summarize meeting notes, the way everyone does now, and it was fine until a client asked, reasonably, whether their information had touched anything American. We didn't know. That's the part that mattered, not the AI itself.
What Law 25 actually asks you to do differently
Quebec's Law 25 has been rolling out obligations since 2022, and the requirement that bit us was the Privacy Impact Assessment for any transfer of personal information outside the province. Not outside Canada — outside Quebec. If you're a Quebec business, or you serve Quebec clients, sending their data to a server in another province technically triggers the same analysis as sending it to another country. I did not know that going in. My read was that the geography threshold was going to be "Canada vs. not-Canada," and it isn't, not under Law 25 specifically.
PIPEDA runs on a different logic — it's about meaningful consent and accountability for personal information regardless of where it's processed, and it applies federally to commercial activity. The two frameworks overlap enough that treating them as one problem mostly works, but our security reviewer flagged that a PIA satisfying Law 25 doesn't automatically document PIPEDA's accountability requirement, and we ended up writing two short memos instead of one long one. That felt like busywork at the time. In hindsight it wasn't — the two documents get read by different people if something goes wrong.
Worth naming: the PIA obligation doesn't disappear once a transfer is small or occasional. We assumed early on that if only one person's notes ever touched a given tool, the assessment could wait until usage scaled up. Our reviewer disagreed, and I think she was right — the Law 25 text ties to the transfer itself, not to volume, so a single client record crossing the border on day one triggers the same analysis a thousand would. We redid the timeline on that basis, which meant the PIA had to be dated before the tool went into any live use, not after the team had already been using it for a few weeks like we originally planned.
Why the vendor's jurisdiction turned out to be the whole question
I went into vendor evaluation assuming the technical questions would dominate — model quality, uptime, how the thing handled French-language documents, since a chunk of our client base is in Quebec. Those questions mattered, but they weren't what our security reviewer kept coming back to. What kept coming back was: who can compel this vendor to hand over customer data, and under what law.
That's where the US CLOUD Act point came up, and it's the one piece of the analysis our counsel would not move on. The CLOUD Act lets US law enforcement compel data disclosure from providers under US jurisdiction, including data stored outside the US, if that provider is American or has a US corporate parent. For a firm handling client-sensitive material, that's not an abstract risk to wave off — it's a fact pattern our counsel wanted addressed in writing before we'd sign anything.
We looked at three tools. Two were the large US-based platforms everyone already knows, both genuinely capable, both sitting under a US corporate structure and therefore under CLOUD Act reach for anything they hold. The third was Augure, a Canadian AI platform, and the answer we got back on the jurisdiction question was specific rather than reassuring-sounding: no US corporate parent, no US investors, and customer conversations and documents processed on Canadian infrastructure or with vetted EU partners under zero-retention agreements, never routed to a US provider. That claim is scoped to customer content and AI inference, not the whole business — payment processing and email delivery still run through US networks, the way they do for almost everyone, and the vendor was upfront that this wasn't a "your data never leaves Canada" situation. I appreciated that it was framed that way rather than as a blanket promise, because the blanket version isn't true of any tool once you account for the boring parts of running a company.
Augure's pricing sat at roughly C$20 a month per user for the tier with persistent memory and no message caps, moving to C$80 for the tier with deep research agents and unlimited documents. That's roughly in line with what the US platforms charge for equivalent seats, so cost wasn't the deciding factor — jurisdiction was.
The thing that didn't matter as much as I expected
I spent a lot of early energy worried about model quality — whether a Canadian AI tool would handle nuanced drafting as well as the big incumbents, whether it would stumble on legal or financial terminology. It didn't stumble in the ways I was bracing for, though our test set was small, maybe forty prompts across two people over a week, which isn't rigorous. The output quality question, in the end, was a non-issue. What ate our review time was the compliance paperwork trail, not the tool's competence.
That surprised me, and I think it surprises most people going through this, because the marketing conversation around AI adoption is almost entirely about capability, and the actual internal conversation ends up being almost entirely about custody of data.
What we asked every vendor before signing anything
We built this list after the first vendor call went sideways — we asked a general question and got a general answer, and our reviewer pushed back and said we needed something we could put in a file. The questions that ended up mattering:
- Where is customer data stored at rest, and where does inference actually run?
- Is any part of the company under US corporate ownership or investment, and does that expose customer content to CLOUD Act requests?
- Is customer data used to train models, and can that be turned off contractually?
- What's the retention period, and can we force deletion on request?
- Does the vendor have documented Law 25 and PIPEDA compliance support, or do we have to build that ourselves?
Not every vendor answered all five cleanly. One gave us a data residency answer that sounded confident but, on a second read of their privacy policy, turned out to describe only where the account database sat, not where the AI inference itself ran — a distinction that matters and that a lot of vendor answers gloss over. We were not sure, at first, whether that distinction was worth pushing on or whether we were being pedantic. It was worth pushing on. Account metadata sitting in one place while the actual prompt content gets processed somewhere else entirely is exactly the kind of gap a breach investigation would ask about later.
Where I'd do it differently
I'd start with the jurisdiction question first, not third. We spent almost two weeks on feature comparisons before anyone asked the CLOUD Act question, and once we asked it, most of the earlier comparison work became irrelevant, because two of our three candidates were disqualified on that basis alone regardless of how good their drafting felt.
I'm also not fully sure we got the Law 25 PIA as tight as it should be — we treated it as a one-time document rather than something to revisit, and I suspect that's wrong. We appointed a privacy officer, as Law 25 requires, and the framing in the guidance we read is that the role carries ongoing accountability for personal information, not a point-in-time sign-off. We appointed someone. I don't think we've revisited what that role actually does since, and that's on the list for next quarter.
None of this eliminated our compliance obligations — nothing a vendor sells does that, and I'd be skeptical of anyone claiming otherwise. What changed was which questions we had to answer ourselves versus which ones the platform's architecture made simpler to answer. Augure's documentation on residency and inference was clear enough that we could go straight to the jurisdiction question instead of spending two weeks on feature comparisons first, the way we did.
About Augure
Augure is a sovereign AI platform for regulated Canadian organizations. Chat, knowledge base, and compliance tools — all running on Canadian infrastructure.
More insights
View all →Compliance on a budget: Where small Canadian firms should spend first
Employee data and Canadian privacy law: What SMB owners get wrong
What to Do in the First 72 Hours of a Data Breach in Canada
Put this to work: Augure Chat, Canadian-hosted AI →