The Consent Question Small Businesses Keep Getting Wrong
Under Law 25 and PIPEDA, most Canadian small businesses need clear consent before collecting personal data. What actually requires it — and what doesn't.
Quebec's Commission d'accès à l'information opened 33 files related to Law 25 complaints in its first full year of enforcement, according to the regulator's 2023-2024 annual report. Most did not involve large corporations. Dental offices, property managers, gyms — the kind of business that collects a name, an email, sometimes a health note, and never thought to ask whether that counted as something requiring consent.
It usually does. The rule of thumb under both Law 25 in Quebec and the federal Personal Information Protection and Electronic Documents Act (PIPEDA) is simple to state and harder to apply. If personal information is being collected, used, or disclosed for a purpose the person would not reasonably expect, consent is required, and it has to be meaningful. Not buried in a terms-of-service link nobody opens.
What Actually Triggers Consent
Not everything does. A customer who buys a chair and gives an email address for a delivery confirmation has implicitly consented to that specific use. Using the same email six months later for a marketing newsletter is a different purpose, and under PIPEDA that generally requires a fresh, explicit opt-in. Not a pre-checked box, not an assumption of interest because the person is already a customer.
Quebec's Law 25 goes further than PIPEDA in a few concrete ways. It requires a privacy impact assessment before transferring personal information outside Quebec. It gives Quebec residents a right to data portability. It requires consent to be sought separately from other information, in clear and simple language, not folded into a sixteen-page agreement.
The businesses most exposed are the ones that never wrote any of this down. A hair salon booking system that stores phone numbers and appointment history is processing personal information whether or not the owner has ever used that phrase. A property manager running background checks through a third-party service is disclosing information to that vendor, which triggers its own set of obligations.
Consent must be requested for each purpose, in clear and simple language, and separately from any other information provided, according to the Commission d'accès à l'information's guidance on valid consent under Law 25. That single requirement, separate and purpose-specific consent, is the one most small business intake forms fail first.
There is a narrower exception that trips people up in the other direction. Law 25 does not require consent when the collection, use, or disclosure is necessary to provide a service the person has requested, or to fulfill a legal obligation — a bookkeeper does not need fresh consent to hand a client's T4 slips to the Canada Revenue Agency, because that disclosure is required by statute, not chosen by the business. The same carve-out covers a landlord passing tenant information to an insurer after a fire, when the lease itself requires it. The exception is narrow by design. It covers what the law or the specific service contract compels, not what would simply be convenient or profitable for the business to do next.
The AI Wrinkle Nobody Budgeted For
Small businesses adopting AI tools have added a new category of consent risk without necessarily realizing it. A law firm pasting a client's settlement details into a general-purpose chatbot to summarize them is transferring personal information to whatever company runs that chatbot, and to whatever jurisdiction that company's servers sit in. If the tool is US-hosted, that transfer needs the same scrutiny as sending a file to an offshore call centre.
This is where the phrase Canadian AI has started showing up in procurement conversations that, two years ago, would have just been about price. A growing number of small and mid-sized Canadian organizations now ask vendors a jurisdiction question before a features question: where the data lives, who can compel access to it, and whether the answer changes under foreign law.
Augure, a Vancouver-based platform aimed at regulated Canadian organizations, is one vendor built around that question rather than treating it as an afterthought. Customer data is stored in Canada. Inference, the actual processing that generates a chat response or reviews a contract, runs on Canadian infrastructure for some model tiers, with vetted EU partners under zero-data-retention agreements serving others and providing failover capacity. None of it goes to US providers. Augure has no US corporate parent and no US investors, according to the company, which means customer conversations, documents, and AI inference are not handled by US-jurisdiction providers, narrowing the CLOUD Act's reach over that customer content specifically. Email delivery and payment processing still touch US-based networks, a fact Augure discloses in its privacy policy rather than glossing over. It matters to any business doing its own transfer assessment.
None of that makes a business's own consent practices compliant on its own. A Canadian-hosted AI tool doesn't collect valid consent on a business's behalf, and it can't waive the requirement to tell a customer, in plain language, that their inquiry might be processed by an AI system at all. But choosing infrastructure that keeps inference and customer content within Canada and the EU rather than the US removes one branch of the compliance tree. The cross-border transfer assessment a business would otherwise run for every US tool in its stack.
A skeptical owner might reasonably ask what the EU inference tier actually means for a Quebec-based transfer assessment, given that the EU is still outside Quebec's borders. Law 25's privacy impact assessment for cross-border transfers does not stop at the Canadian border specifically — it applies to any transfer outside Quebec, EU included. What changes is the analysis, not whether one is required. The assessment for an EU processor operating under the GDPR's own consent and retention framework, with a zero-data-retention agreement layered on top, looks different from the assessment for a US processor subject to the CLOUD Act. Different does not mean simpler, and it does not mean the business gets to skip the paperwork. It means the paperwork has a more favourable starting point.
Consent That Actually Holds Up
A few categories come up constantly in CAI enforcement actions and OPC guidance, and they are worth naming directly.
- Marketing emails and texts require opt-in consent under Canada's Anti-Spam Legislation (CASL), separate from any privacy consent, with a functioning unsubscribe mechanism.
- Employee monitoring — keystroke logging, location tracking, camera footage — requires notice and, in most cases, consent, even though employees are a captive audience.
- Biometric data, including fingerprint time clocks, triggers Law 25's heightened consent and registration requirements in Quebec specifically, because biometric identifiers are treated as sensitive by default.
- Sharing customer lists with a partner business, even a friendly one, counts as disclosure to a third party and needs its own consent basis.
- Security camera footage of customers, if used for anything beyond basic loss prevention, such as behavioural analytics, moves into territory requiring disclosure.
Most small businesses get the first purchase right and never revisit the list as they add tools. A booking app here, a loyalty program there, an AI assistant for customer service. Each one is a new purpose, and consent obtained for the original does not automatically stretch to cover it.
Cost of Getting It Wrong Versus Cost of Doing It Right
The federal Office of the Privacy Commissioner does not currently have the power to levy fines directly under PIPEDA, though Bill C-27, which died on the order paper when Parliament prorogued in January 2025, would have introduced penalties up to 5% of global revenue for the most serious violations. Quebec's Law 25 already has teeth: administrative monetary penalties up to $10 million or 2% of worldwide turnover, whichever is greater, for the most serious cases. Most CAI actions to date against small operators have resulted in corrective orders rather than maximum fines.
The more common cost is smaller and more corrosive. A breach notification requirement, a client who finds out their information went somewhere they didn't expect, a reputational hit in a town where everyone talks. Fixing consent practices proactively costs a fraction of what a formal CAI investigation costs in staff time alone, before any fine gets assessed.
The mechanics of a CAI investigation are worth spelling out, because most owners have never seen one described. A complaint or a self-reported breach triggers a file opening, followed by a written request for documentation — the privacy policy, the consent language used at collection, a record of who accessed the affected data and when. The business has a set window to respond, typically weeks rather than days. If the CAI finds a deficiency, the first outcome is usually a corrective order: fix the consent language, notify affected individuals, report back within a deadline. A monetary penalty is reserved for cases involving repeat violations, bad faith, or a refusal to comply with the corrective order itself. The staff time cost sits mostly in that document-gathering stage, which is exactly the stage a business skips if the paperwork already exists before a complaint arrives.
A basic compliance pass, updated consent language, a privacy policy that actually describes current data flows, a review of which vendors touch personal information and where they sit jurisdictionally, is work an owner or office manager can finish in a few afternoons using CAI and OPC template guidance, without hiring outside counsel. Paying for tools or advice starts to make sense once a business handles health data, biometric data, or high volumes of cross-border transfers, where a wrong call carries real exposure.
Software costs factor in too. A Canadian AI platform priced for small teams, Augure's paid tier runs $20 a month per user, with a free tier capped at 50 messages a day, sits on a different budget line than enterprise compliance software built for national retailers. Businesses evaluating AI tools for anything touching customer data should price the jurisdiction question alongside the feature list, not after it.
More detail on how Augure's infrastructure and pricing map to Law 25 and PIPEDA is at augureai.ca.
About Augure
Augure is a sovereign AI platform for regulated Canadian organizations. Chat, knowledge base, and compliance tools — all running on Canadian infrastructure.
More insights
View all →Law 25 penalties: will a C$25M fine actually hit a nine-person business?
PIPEDA in plain language: what Canadian business owners actually owe their customers
Your employees are already using AI: A manager's response plan
Put this to work: Augure Chat, Canadian-hosted AI →