← Back to Insights
Compliance

Law 25 compliance checklist for AI tools in 2026

Law 25 compliance for AI tools: data residency, consent, privacy impact assessments, and vendor due diligence checklist for Quebec organizations.

By Augure·
Business professionals collaborating around a conference table.

Law 25 compliance for AI tools requires specific attention to data residency, consent mechanisms, privacy impact assessments, and vendor due diligence. Organizations using AI tools Quebec teams rely on to process residents' personal information must meet heightened privacy requirements under Quebec's private sector privacy law, with administrative monetary penalties reaching $10 million or 2% of worldwide turnover for enterprises.

This checklist reflects current guidance from Quebec's Commission d'accès à l'information (CAI), the province's actual privacy regulator, and outlines what compliance teams should verify before deploying AI tools in 2026.

Data residency: where does your AI actually process data?

Law 25 establishes requirements for personal information transferred outside Quebec. AI tools hosted on foreign infrastructure must be assessed for adequate protection before that data leaves the province, and organizations must document the assessment.

The CAI has signalled that AI model training, inference processing, and persistent memory features all constitute "processing" of personal information. Organizations cannot rely on contract language alone when using AI tools hosted in jurisdictions with broad government surveillance powers, including under the US CLOUD Act, which permits US authorities to compel disclosure of data held by American companies regardless of where it's stored.

"Law 25's cross-border transfer requirements apply to AI processing activities, including model inference, training data, and conversation histories. Organizations must verify where their AI provider processes Quebec residents' data and assess whether protections in that jurisdiction are equivalent."

Key compliance requirements include:

  • Document the geographic location of all AI processing activities
  • Assess the adequacy of privacy protections in the destination jurisdiction before transfer
  • Put contractual safeguards in place for transfers to jurisdictions without equivalent protection
  • Apply extra safeguards when sensitive personal information is involved

Platforms like Augure, which maintain 100% Canadian data residency with no US corporate exposure, help Quebec organizations avoid complex transfer impact assessments altogether. For a broader look at platforms built around this constraint, see our review of AI tools that comply with Quebec's Law 25.

Consent and transparency: specificity, not boilerplate

Law 25 requires clear, specific consent for processing that goes beyond the original collection purpose. Generic privacy policies don't satisfy this standard when AI tools analyze personal information for new uses.

Organizations should provide specific information about AI processing activities, covering:

  • The nature and purpose of AI analysis
  • Categories of personal information processed
  • Identity of AI service providers
  • Data retention periods for training and inference

"AI for productivity" is not a sufficient purpose description. Organizations must explain specific functionalities, such as document analysis, pattern recognition, or automated decision-making, in language a reasonable person can understand.

"Consent for AI processing needs to be specific to the AI functionality involved. General consent for 'improving services' doesn't cover document analysis, automated decision-making, or predictive analytics that exceed the original collection purpose."

For AI tools with learning capabilities, disclose whether personal information contributes to model training or shared knowledge bases. This includes chatbots with persistent memory, document analysis tools, and collaborative AI platforms. Our guide to AI governance platforms for Law 25 compliance covers governance structures that support this kind of disclosure at scale.

Privacy impact assessments

Law 25 requires privacy impact assessments for projects involving the acquisition, development, or significant overhaul of information systems processing personal information, and for cross-border transfers. Most substantive AI deployments meet this threshold, particularly those involving:

  • Automated decision-making affecting individuals
  • Analysis of sensitive personal information
  • Profiling or behavioural analysis
  • Cross-border data processing

Your assessment should address AI-specific risks:

  • Model training on personal information
  • Inference accuracy and bias potential
  • Data minimization compliance
  • Security of AI-generated insights

Document your AI tool's data flow from input through processing to output, including training data sources, model update frequencies, and retention periods for prompts and responses. If you're building this documentation from scratch, our team's approach to "PIA documentation" as a collaboration exercise is a useful starting template. Demonstrating necessity and proportionality matters here — generic productivity benefits don't justify extensive personal information processing through AI tools.

Vendor due diligence: two words, one obligation — verify

Quebec organizations remain responsible for their AI service providers' compliance. Due diligence extends beyond contractual terms to actual processing practices and infrastructure controls.

Essential due diligence elements include:

  • Verification of data processing locations
  • Assessment of the provider's privacy governance maturity
  • Review of security controls and incident response procedures
  • Evaluation of how data subject rights (access, correction, deletion) are actually implemented

Ask your AI provider direct questions. Where are servers located? Who has administrative access? How is data encrypted in transit and at rest? For a deeper walkthrough of what regulators expect from AI vendors specifically, see CPCSC requirements for AI tooling — note that despite the naming overlap, this refers to cybersecurity certification requirements distinct from CAI's privacy mandate, and both can apply to the same vendor.

"Organizations remain liable for their AI service providers' compliance under Law 25. Due diligence requires verifying actual processing practices, not just reviewing vendor privacy policies, particularly for cross-border transfers."

Pay particular attention to AI providers with US parent companies or investors. The CLOUD Act creates disclosure obligations that may sit in tension with Law 25's transfer standards, often requiring additional safeguards or a documented adequacy assessment.

Data minimization and purpose limitation

Law 25 requires processing personal information only to the extent necessary for the stated purpose. AI tools often encourage extensive data input that exceeds what's actually needed.

Apply data minimization principles in practice:

  • Limit AI processing to necessary personal information
  • Configure tools to exclude unnecessary personal details
  • Review data retention in AI systems on a regular schedule
  • Segregate AI processing by sensitivity level

Many AI productivity tools accept unlimited document uploads or retain full conversation histories by default. Evaluate whether this broad collection serves a specific, documented business purpose. AI efficiency gains alone don't justify collecting additional personal information — organizations must show that expanded AI processing serves the original collection purpose or that new consent was obtained.

Employee training and governance

Law 25 expects organizations to ensure staff understand privacy obligations when using AI tools. This includes both privacy professionals and end-users who interact with AI systems processing personal information day to day.

Training should cover:

  • Identifying personal information in AI inputs
  • Understanding when consent is required for AI processing
  • Recognizing when a privacy impact assessment is needed
  • Reporting AI-related privacy incidents promptly

Establish governance around AI tool procurement and deployment. Require a privacy review before implementing new AI capabilities, particularly those processing Quebec residents' personal information. Keep a record of your decision-making process for AI tool selection, including the privacy considerations weighed — regulators expect to see systematic protection, not ad-hoc compliance efforts assembled after the fact.

Incident response and breach notification

AI tools create distinct incident response challenges. Breaches may involve training data exposure, model inversion attacks, or unauthorized access to AI-generated insights containing personal information.

Your incident response plan should address:

  • Detection of AI-related privacy incidents
  • Assessment of personal information exposure through AI systems
  • Notification obligations when an AI service provider experiences a breach
  • Remediation steps for compromised AI systems

Document AI-specific incident scenarios in your response procedures, including contact information for your AI providers' security teams and escalation paths for cross-border incidents. Law 25 requires notifying the CAI and affected individuals of breaches presenting a risk of serious injury, and organizations should treat this as a tight timeline rather than an open-ended one. For a practical walkthrough of notification obligations across Canadian regimes, see AI data breach notification requirements in Canada.

Putting it together

Law 25 compliance for AI tools requires systematic attention to data residency, consent mechanisms, and vendor oversight. Organizations processing Quebec residents' personal information through AI must demonstrate adequate protection throughout the entire processing lifecycle — from intake to retention to eventual deletion.

Start with a comprehensive inventory of your current AI tools and their data processing practices. Prioritize compliance efforts based on the sensitivity of personal information involved and the scope of AI processing activity. For official guidance, the CAI publishes updated interpretation bulletins and organizational guidance directly at cai.gouv.qc.ca, which should be your first reference point over any third-party summary, including this one.

Augure's Canadian-hosted AI platform helps organizations meet Law 25 requirements by eliminating cross-border transfer concerns and providing transparent data governance for Quebec compliance. Explore our product page for details on how Augure's architecture maps to these requirements, or browse further compliance resources on our blog.

A

About Augure

Augure is a sovereign AI platform for regulated Canadian organizations. Chat, knowledge base, and compliance tools — all running on Canadian infrastructure.

Ready to try sovereign AI?

Start free. No credit card required.

Get Started