Loi 25 Automatisation
Quebec Law 25 automation rules: consent, algorithmic transparency, and automated decision-making rules for Canadian organizations.
Quebec's Law 25 automation requirements impose specific obligations on organizations using automated decision-making that significantly affects individuals. Law 25 automation rules require disclosure of automated processing logic, meaningful information about decision-making criteria, and a path to human review. These requirements apply to AI systems, algorithmic screening tools, and automated scoring mechanisms used by Quebec organizations or processing Quebec residents' data — and they sit alongside broader algorithmic transparency expectations that regulators across Canada are converging on.
The compliance burden extends beyond simple disclosure.
Organizations must demonstrate that automated systems provide explainable outcomes and maintain human oversight capabilities for contested decisions, and they need to do so continuously rather than as a one-time exercise at launch.
Law 25 automation: the automated decision-making framework
Quebec's private sector privacy statute establishes three core obligations for automated decision-making systems. Organizations must inform individuals when automated processing significantly affects them. They must provide meaningful information about the logic involved in automated decisions. They must give individuals a way to obtain human review and contest automated decisions.
"Significantly affects" isn't defined with precision in the statute, but guidance from the Commission d'accès à l'information du Québec points toward employment decisions, credit approvals, insurance underwriting, and benefit determinations as clear examples. Organizations should treat the threshold as at least as broad as, and possibly broader than, comparable "legal or similarly significant effects" language used in other privacy frameworks, rather than assume a narrow reading.
Law 25 mandates proactive disclosure, explainable logic, and human oversight mechanisms built into automated systems from deployment. Organizations cannot simply automate decisions without these compliance safeguards, as violations can trigger administrative monetary penalties up to C$25 million.
Meaningful information means organizations must explain decision-making criteria in accessible language.
Technical specifications or raw algorithm descriptions alone don't satisfy this obligation — individuals need a plain-language account of how their personal information influenced the automated outcome affecting them, delivered in a way a non-technical person could actually act on, not a data flow diagram buried in an appendix.
AI compliance in practice
Automated decision-making compliance requires documentation before deployment. Organizations need policies describing their automated decision-making systems, the purposes those systems serve, and the logic behind them. These policies must identify when human review is available and how individuals can request it.
AI chat systems with persistent memory, like those used for customer service or employee support, can fall under these requirements when they influence service delivery or employment decisions without meaningful human involvement. Our related guide on AI tools that comply with Quebec's Law 25 walks through vendor selection criteria in more detail.
For Quebec-based organizations, or those processing Quebec residents' data, Law 25 automation compliance generally means:
• Documenting all automated systems that could significantly affect individuals • Creating explainable AI processes that can articulate decision-making logic • Establishing human review procedures for contested automated decisions • Training staff on automated decision-making disclosure requirements • Implementing audit trails for automated decisions, consistent with the statute's broader record-keeping expectations
Financial institutions and insurers are among the organizations most exposed here, since mortgage pre-approval, underwriting, and claims-scoring systems are the kinds of tools regulators are most likely to scrutinize when a complaint arises. Rather than pointing to a specific enforcement action, the more useful exercise is asking whether your own automated screening tools would survive that scrutiny today.
Where consent and design rules intersect
Automated decision-making requirements integrate with Law 25's consent framework. When automated processing relies on consent, organizations must specify automated decision-making purposes clearly in the consent request itself, rather than folding them into general-purpose language. This creates a higher practical bar than organizations may be used to under federal privacy law, where consent obligations are less specific about automated processing.
Law 25's privacy-by-design expectations also apply to automated systems.
Organizations must build in privacy protections from system design through deployment, not retrofit them once a regulator asks questions.
Law 25's privacy-by-design principle requires organizations to build automated decision-making transparency and human oversight capabilities into AI systems from initial deployment. Retrofitting these capabilities after deployment undermines the privacy-by-design principle and increases exposure to enforcement action.
Data minimization requirements affect automated decision-making systems too. Organizations can only collect personal information necessary for their stated automated processing purposes. AI systems that analyze extensive personal information to make decisions need to demonstrate that broad data collection serves specified, legitimate purposes. For a deeper look at how governance platforms handle this, see our post on AI governance platforms and Law 25 Quebec compliance.
Machine learning models that adapt over time raise a harder question: static explanations from deployment don't satisfy ongoing disclosure obligations. Explainability has to persist as the model changes, which means documentation needs a refresh cycle, not a one-time sign-off.
Penalties and enforcement
Section 102 of Law 25 establishes administrative monetary penalties of up to C$25 million or 4% of worldwide turnover for the most serious violations. Automated decision-making failures — inadequate disclosure, missing human review pathways, or opaque decision logic — can expose organizations to this range depending on the scale and severity of the failure.
The Commission d'accès à l'information du Québec has broad investigative powers and has signalled that transparency around automated processing is a compliance area it is watching closely, though organizations should confirm current enforcement priorities directly with the regulator rather than rely on past guidance. Organizations handling breach scenarios tied to automated systems should also review our guide on AI data breach notification requirements in Canada.
Penalty calculations generally consider the scope of harm and the number of individuals affected by non-compliant automated decision-making. AI systems processing large volumes of decisions without proper transparency protections carry proportionally higher exposure.
Federal and international comparisons
Law 25's automated decision-making requirements are more prescriptive than PIPEDA's general accountability principles. PIPEDA requires organizations to be responsible for personal information under their control but doesn't specify automated decision-making disclosure requirements the way Quebec privacy law does.
Bill C-27's proposed Consumer Privacy Protection Act included automated decision-making provisions that would have aligned more closely with Law 25's approach, requiring meaningful explanations and a review pathway for decisions with significant impact. That bill died on the order paper when Parliament was prorogued, and its replacement legislation remains under discussion. Organizations can track current status on the Parliament of Canada's legislative website.
Quebec's automated decision-making framework anticipates the direction federal privacy law reform is likely to take. Organizations implementing compliance now position themselves ahead of broader Canadian regulatory requirements, since prior federal proposals mirrored Quebec's meaningful explanation and human review standards.
International frameworks like the EU's GDPR provide broader rights to object to automated decision-making in some respects, but Law 25's meaningful information requirement is comparably specific about explanation quality. Quebec's approach focuses on practical understanding for the individual rather than abstract procedural rights.
For multi-jurisdictional Canadian organizations, Law 25 often becomes the effective compliance standard because it's more stringent than other provincial privacy legislation and current federal requirements.
Building Law 25 automation-compliant systems
Compliant automated decision-making systems require specific technical capabilities. Organizations need AI platforms that can provide decision explanations, maintain audit trails, and facilitate human review when individuals contest automated outcomes. Our overview of CPCSC requirements for AI tooling covers adjacent procurement standards worth reviewing alongside this framework.
Augure's sovereign AI platform addresses these requirements through Canadian-built models designed for Quebec regulatory compliance. Augure maintains audit trails for automated decisions while providing explainable AI capabilities aimed at satisfying Law 25's meaningful information requirements.
Key technical requirements include:
• Explainable AI models that can articulate decision-making logic in accessible language • Human oversight interfaces for reviewing and overriding automated decisions • Audit logging that documents automated decision-making processes • Data residency controls that keep automated decision-making systems within Canadian jurisdiction • Privacy-by-design architecture that integrates Law 25 requirements from deployment
Cloud-based AI systems need particular attention to data residency. Automated decision-making involving Quebec personal information triggers Law 25's cross-border transfer rules, which often makes US-based AI platforms harder to defend without additional contractual and assessment work. Teams managing documentation for these assessments may also find our piece on the "PIA Documentation" collaboration tool useful.
Building explainable systems is straightforward. Keeping them explainable as models retrain and adapt is where most organizations struggle, and it's the piece that ongoing compliance actually hinges on.
Rollout: assessment, design, operation
Compliance requires systematic implementation across three phases: assessment, design, and operation.
Assessment identifies all automated systems that significantly affect individuals, evaluates the significance of those effects, and documents current explanation and human review capabilities. Many organizations discover a broader automated decision-making footprint than initially expected — legacy scoring tools and vendor-supplied features are common blind spots.
Design implements technical and procedural controls for transparency and human oversight, and integrates automated decision-making requirements into privacy policies and consent frameworks. Technical architecture decisions made during this phase determine long-term compliance sustainability, since retrofitting explainability into a black-box model later is far more expensive than designing for it up front.
Operation maintains compliance through staff training, system monitoring, and regular audits of automated decision-making explanations. Organizations need processes for updating explanations as AI systems evolve and for handling individual requests for human review. This is also where governance platforms earn their cost, since manual tracking of explanation freshness across dozens of models doesn't scale.
For organizations seeking Canadian-sovereign AI capabilities that address Law 25 automation requirements, Augure provides Canadian-hosted infrastructure with built-in explainability and audit capabilities, designed to minimize unnecessary cross-border data exposure. Learn more about sovereignty-first AI compliance at augureai.ca.
About Augure
Augure is a sovereign AI platform for regulated Canadian organizations. Chat, knowledge base, and compliance tools — all running on Canadian infrastructure.