Quebec Law 25 AI Compliance: The Complete 2026 Guide
One guide to Law 25 AI compliance: transparency and consent rules, penalties up to 4% of revenue, tool selection criteria, and priorities for small teams.
Quebec's Law 25 has fundamentally changed how businesses must approach AI systems and data processing. Under sections 12.1 and 14, organizations using AI for automated decision-making must provide explicit transparency about the logic involved and obtain manifestly informed and explicit consent for personal information processing. Administrative monetary penalties can reach 4% of worldwide revenue or C$25 million, making compliance a board-level concern.
This guide consolidates everything Quebec organizations need to know in 2026: what the law requires, how the Commission d'accès à l'information (CAI) enforces it, how to evaluate compliance tooling, and — if you don't have a dedicated privacy team — where to focus first.
What Law 25 requires: the four pillars
Law 25 modernized Quebec's Act respecting the protection of personal information in the private sector through four core sets of obligations. Each creates specific compliance work for organizations handling personal information — with or without AI in the picture.
Consent and transparency. Organizations must obtain clear, informed consent for data collection, publish plain-language privacy policies, and meet enhanced consent standards for sensitive categories such as biometric and health data. Section 14 requires that consent for AI processing be "manifestly informed and explicit."
Data minimization and purpose limitation. Collection is restricted to personal information necessary for identified purposes, and use is limited to those originally stated purposes. This directly impacts AI systems, which often want broad datasets for training and inference. Repurposing personal information for a new AI use case generally means fresh consent.
Individual rights. Quebec residents can request access, rectification, and deletion of their personal information, and Law 25 introduces data portability — organizations must be able to provide personal information in a structured, commonly used format. Under section 27, individuals can also request explanations of automated decisions and challenge AI-driven outcomes.
Breach notification. Organizations must report confidentiality incidents presenting a risk of serious injury to the CAI and notify affected individuals promptly — most compliance teams plan against a 72-hour internal benchmark. Incident registers must be maintained for audit purposes.
Law 25 compliance isn't just about avoiding penalties — it's about building privacy-first operations that meet Quebec's enhanced data protection standards while satisfying concurrent PIPEDA obligations.
Law 25's AI-specific provisions
Beyond the general framework, three provisions directly govern how businesses can deploy and operate AI systems.
Section 12.1 — automated decision transparency. Organizations must inform individuals when a decision is made exclusively through automated processing, including AI systems. This isn't a generic disclosure: you must explain the logic involved and the possible consequences for the individual. The requirement applies to any automated decision that "produces legal effects concerning him or similarly significantly affects him" — hiring algorithms, credit scoring models, insurance underwriting systems, or customer service chatbots making account decisions.
Section 14 — manifestly informed and explicit consent. Individuals must understand not just that you're using AI, but how their personal information will be processed within AI systems. Generic privacy notices cannot satisfy this standard.
Section 3.3 — Privacy Impact Assessments. PIAs are mandatory for processing that presents "high risk to the protection of personal information." AI systems performing automated decision-making typically qualify, particularly those processing sensitive data or making consequential decisions about individuals.
Under section 12.1 of Law 25, organizations must provide meaningful information about AI decision-making logic and consequences — generic privacy notices cannot satisfy Quebec's transparency requirements for automated processing systems.
Real-world compliance scenarios
Consider a Montreal-based insurance company using AI to assess claims. Under sections 12.1 and 14, it must inform claimants that AI is involved in the assessment, explain how the system evaluates claims data, and obtain explicit consent for processing personal information through the AI system.
A Quebec retailer using AI-powered recommendation engines faces similar obligations. If the AI processes purchase history to make product suggestions that could be considered "decisions," transparency requirements under section 12.1 apply.
Financial institutions have additional complexity. A credit union in Quebec City using AI for loan approvals must satisfy Law 25's transparency requirements while also meeting federal banking regulations and PIPEDA's Principle 4.8 on individual access rights.
The key distinction: Law 25 doesn't just require privacy notices — it requires functional transparency about AI decision-making processes.
Penalties and CAI enforcement
The CAI has significant enforcement powers under Law 25's penalty framework in sections 89-93.
Administrative monetary penalties for enterprises range from C$15,000 to C$25,000,000, or up to 4% of worldwide turnover — whichever is higher. For individuals within organizations, penalties range from C$1,000 to C$10,000 per violation. Personal liability extends to executives and employees who participate in or authorize non-compliant practices.
The CAI can also issue compliance orders requiring specific remedial actions and publication orders requiring public disclosure of violations. These non-monetary penalties often carry more reputational impact than fines. When determining amounts, the CAI weighs organization revenue, the number of affected individuals, the sensitivity of the compromised information, the duration of the violation, mitigation measures, and prior compliance history.
The CAI's enforcement approach focuses on systematic compliance failures rather than isolated incidents — organizations with poor AI governance face escalating penalties from compliance orders to maximum monetary sanctions.
Recent CAI guidance suggests particular focus on organizations that implement AI systems without conducting proper privacy impact assessments under section 3.3 or obtaining appropriate consent for automated decision-making under section 14. Healthcare AI, financial services algorithms, and HR technology face the closest scrutiny.
How Law 25 interacts with PIPEDA
Quebec businesses must navigate both Law 25 and federal privacy law, and many organizations fall under both frameworks simultaneously. PIPEDA applies to federally regulated organizations and interprovincial commerce, while Law 25 covers Quebec-based private sector organizations.
The Privacy Commissioner of Canada has issued guidance on AI and automated decision-making under PIPEDA's accountability principle (4.1.3) and individual access principle (4.8). However, Law 25's section 12.1 requirements are more prescriptive and stringent.
In practice, this means:
- Conducting privacy impact assessments that satisfy both PIPEDA's accountability principle and Law 25's section 3.3
- Implementing consent mechanisms that meet Law 25's "manifestly informed and explicit" standard under section 14
- Maintaining documentation that demonstrates compliance with both frameworks
Organizations subject to both laws must implement the higher standard where requirements differ — and for AI processing, that standard is almost always Law 25's.
Cross-border transfers, the CLOUD Act, and data residency
Law 25's section 17 restricts transfers of personal information outside Quebec unless adequate protection exists, assessed through transfer impact analysis. While the law doesn't mandate in-province storage, the cross-border provisions create practical compliance advantages for keeping personal information in Canada.
Many popular AI services process data through US-based infrastructure or corporate entities, creating additional disclosure obligations and consent requirements. The US CLOUD Act adds a harder problem: US-based providers can be compelled to disclose data to US authorities regardless of where it's stored, which is difficult to reconcile with section 17's equivalent-protection standard. Contractual safeguards alone may not protect against foreign government surveillance powers.
For small teams, this is also an operational problem. Data flows change constantly as software updates, acquisitions, and infrastructure changes modify where your information is processed — manually evaluating every vendor's data practices against adequacy standards doesn't scale.
Infrastructure choices directly impact compliance obligations under section 17 of Law 25 — AI systems with US-based data processing require extensive consent mechanisms and cross-border transfer disclosures that Canadian sovereign infrastructure eliminates entirely.
Businesses increasingly recognize that sovereign AI infrastructure simplifies compliance by removing cross-border transfer analysis and foreign legal exposure from the equation. Augure's approach reflects this: 100% Canadian data residency with no US corporate structures that trigger CLOUD Act exposure.
How to evaluate Law 25 compliance tools
Most compliance tools built for American or European markets miss Quebec-specific requirements entirely. They lack required bilingual documentation capabilities, don't reflect the CAI's interpretation guidelines, and often store data in jurisdictions that complicate section 17 transfers. Here's what to look for instead.
Data mapping and inventory
Effective compliance starts with knowing what personal information you collect, process, and store. Your tool should discover and classify personal information across systems, map data flows, identify third-party processors, and maintain current inventories that satisfy CAI audit requirements. It should distinguish basic personal information from sensitive personal information — health data, biometric identifiers, and location information carry enhanced protections.
Consent management
Law 25's consent requirements are more granular than PIPEDA's. Look for tools that generate compliant consent forms in both French and English, track consent records for CAI audits, handle purpose-specific consent, and process withdrawal requests within required timelines.
Consent under Law 25 isn't a one-time checkbox — it's an ongoing relationship requiring proper documentation, easy withdrawal mechanisms, and compliance with Quebec's specific consent validity requirements that exceed PIPEDA standards.
Breach notification workflows
Your platform should provide automated breach assessment aligned with CAI guidance, template notifications for both the CAI and affected individuals, built-in timelines against statutory deadlines, and a breach register for audits.
Privacy impact assessment templates
Choose tools with Quebec-specific PIA templates that follow CAI guidance — not generic GDPR DPIA forms. Templates should walk through risk assessment, mitigation strategies, and the documentation the CAI expects during reviews. The best implementations trigger the PIA process automatically when your team evaluates new software or launches new services.
Selection criteria that separate contenders
Data residency and sovereignty. American-owned compliance platforms create unnecessary section 17 complexity: their terms typically allow US government access under the CLOUD Act, and their breach procedures prioritize US regulatory requirements over CAI reporting. Enterprise suites like OneTrust and TrustArc offer Law 25 modules, but treat Quebec privacy law as an add-on to a GDPR core, and enterprise licensing often starts around $30,000 annually — out of reach for smaller Quebec organizations that still carry full Law 25 obligations. Canadian-controlled platforms eliminate the jurisdictional problem at the architecture level.
Bilingual capability and Quebec context. Privacy policies must be available in French, consent forms need Quebec-appropriate language, and breach notifications must meet the CAI's formatting expectations. Most international platforms treat this as a translation exercise; look for native French capability with Quebec legal context built in.
Integration and portability. The tool needs API connections to your existing stack, automated data discovery in your file storage, and clean data export — compliance tools that lock documentation into proprietary formats create long-term risk as CAI guidance evolves.
Compliance without a big privacy team
Small Quebec organizations face the same Law 25 obligations as enterprises, without enterprise compliance staff. The solution isn't hiring more people — it's choosing tools that automate compliance decisions rather than just documenting them.
Most privacy tools market themselves as "compliance platforms" but function as expensive spreadsheets: they track what happened after privacy decisions were made. Penalties apply per violation, so a tracking tool that documents your consent management failures won't prevent the violations that trigger them. For teams of two to five people, you need tools that prevent compliance gaps before they occur.
Consider a typical scenario: your marketing team wants to email prospects who downloaded a whitepaper six months ago. A tracking tool shows you collected email addresses but doesn't verify current consent status under section 14. An automation tool blocks the email until valid consent is confirmed.
A phased roadmap for small teams:
- Core compliance automation. Implement automated consent management and breach response first. These address Law 25's most severe penalty risks and consume the most manual effort. Real-time consent verification before processing, automatic expiry enforcement, and breach assessment with statutory-deadline tracking.
- Operational integration. Add automated PIA workflows and vendor management that plug into existing business processes — standardized processor questionnaires, contract clause libraries for data processing agreements, and renewal reminders.
- Advanced monitoring. Deploy continuous data flow monitoring and cross-border transfer controls under section 17 once the basics are stable.
The results are measurable. A Montréal marketing agency reduced Law 25 compliance overhead from 15 hours weekly to 2 by implementing automated consent verification — its email platform now blocks campaigns targeting contacts without current, specific consent. A Québec City software company cut PIA completion time from 3 days to 4 hours with automated workflows and consistent evaluation criteria. Neither hired additional privacy staff.
Law 25 requires a designated privacy officer, but small organizations can assign privacy responsibilities to existing staff — provided routine tasks are automated so those people can focus on the strategic decisions the law actually requires humans to make.
Sector-specific considerations
Different industries face distinct Law 25 challenges layered on top of the general framework.
Legal services must balance Law 25 with professional confidentiality obligations under the Professional Code. The Barreau du Québec provides specific guidance on privacy compliance for law firms, particularly regarding client information and cross-border transfers.
Healthcare organizations navigate overlapping regimes including Law 25 and Quebec's health services legislation. AI systems processing health data require enhanced safeguards for sensitive information and explicit consent mechanisms.
Financial services add federal banking regulation to the mix. Anti-money laundering obligations create tension with data minimization principles, and AI-driven credit decisions sit squarely inside section 12.1's transparency requirements.
Government contractors must meet both Law 25 and public sector privacy standards, often including stricter data residency requirements and security controls than private sector minimums.
A practical implementation roadmap
Building Law 25 compliance into AI operations requires systematic work across legal, technical, and operational domains.
- Start with a privacy impact assessment under section 3.3 that specifically addresses AI decision-making processes.
- Implement consent mechanisms under section 14 that clearly explain AI involvement — with specific disclosures about logic and consequences as required by section 12.1.
- Build individual-rights procedures for AI systems: under section 27, individuals can request explanations of automated decisions and challenge AI-driven outcomes.
- Document your AI governance. The CAI's enforcement approach emphasizes accountability — organizations that can demonstrate proactive compliance face better regulatory outcomes.
- Train the team on Law 25 specifically — consent management, breach response, and individual rights fulfillment — not generic privacy awareness.
- Audit quarterly. Review consent withdrawal patterns, breach response times, and processing activities that might require updated PIAs. The CAI has signalled more compliance audits, particularly for organizations that experienced breaches or complaints.
Proactive compliance with sections 12.1, 14, and 3.3 of Law 25 demonstrates good faith to the CAI — organizations that wait for enforcement action face penalties up to 4% of worldwide revenue and more prescriptive remedial requirements.
The regulatory environment continues evolving as the CAI issues new guidance, but the fundamentals are stable: transparency about automated decisions, explicit consent, mandatory PIAs, and careful handling of cross-border transfers. Organizations that build compliance into their AI infrastructure — rather than bolting it on afterward — turn Law 25 from a risk into a durable competitive advantage.
For businesses serious about Quebec compliance, the path forward involves choosing AI infrastructure that supports rather than complicates regulatory obligations. Augure provides AI capabilities built for regulated Canadian organizations, with 100% Canadian data residency that eliminates Law 25 cross-border transfer analysis and CLOUD Act exposure entirely. Learn more at augureai.ca.
About Augure
Augure is a sovereign AI platform for regulated Canadian organizations. Chat, knowledge base, and compliance tools — all running on Canadian infrastructure.