Law 25 and AI: A Compliance Guide for Quebec SMEs

Law 25 is the Quebec statute governing the collection, use and protection of personal information, fully in force since September 2024. For an SME deploying a chatbot, an AI voice agent or an automation, it imposes precise obligations: a designated privacy officer, a privacy impact assessment, transparency for automated decisions, and rules on where data is hosted.

This article is for information purposes only and does not constitute legal advice. Consult a legal professional for your specific situation.

What exactly is Law 25?

Its full name is the Act to modernize legislative provisions as regards the protection of personal information. Assented to on September 22, 2021, it amends, among others, the Act respecting the protection of personal information in the private sector, the one that applies to SMEs. It is Quebec's equivalent of the modern privacy regimes adopted elsewhere in the world, but with its own rules, deadlines and supervisory body: the Commission d'accès à l'information du Québec (CAI).

One frequently misunderstood point: the law applies to anyone operating a business in Quebec, from a sole proprietor to a multinational. A three-employee clinic recording patient appointments is covered just as much as a large financial institution.

When did Law 25 come into force?

The law was rolled out in three phases, as summarized on the CAI's Main changes introduced by Law 25 page and in the Government of Quebec announcement:

  • September 22, 2022: designation of a person in charge of the protection of personal information, obligation to manage and report confidentiality incidents, incident register.
  • September 22, 2023: privacy policy, stricter consent rules, privacy impact assessment (PIA), transparency for automated decisions, rules for transfers outside Quebec, administrative monetary penalties.
  • September 22, 2024: right to portability of computerized personal information.

In other words, there is no transition period left. An SME launching an artificial intelligence project in 2026 must be compliant from day one.

What are the basic obligations for an SME?

Designate a privacy officer

By default, this is the person with the highest authority in the business (often the owner). The role can be delegated in writing. The officer's title and contact information must be published on the company website.

Publish a privacy policy

Any business collecting personal information through technological means (web form, chatbot, app) must publish a policy written in simple, clear terms and inform people of any changes.

Carry out a PIA

A privacy impact assessment is mandatory for any project to acquire, develop or overhaul an information system involving personal information. The CAI publishes a companion guide; the scope of the assessment must be proportionate to the sensitivity and quantity of the information.

Obtain valid consent

Consent must be requested for each purpose, separately, in simple and clear language. Exceptions to consent must be interpreted restrictively.

Manage confidentiality incidents

If an incident presents a risk of serious harm, the business must notify the CAI and the affected persons. All incidents, even minor ones, must be recorded in a register kept for at least five years.

Honour the right to portability

Since September 2024, a person can ask to receive their computerized personal information in a structured, commonly used technological format, or to have it sent to an authorized third party.

What does Law 25 change for an artificial intelligence project?

Decisions based exclusively on automated processing

This is the obligation most directly tied to AI. When a decision about a person is made without human intervention, the business must, according to the CAI:

  1. inform the person, no later than when the decision is communicated to them;
  2. provide, on request, the personal information used, the reasons and the main factors and parameters that led to the decision, and the person's right to have that information corrected;
  3. give the person the opportunity to submit observations to a staff member who is able to review the decision.

In practice: a chatbot that answers questions or books an appointment does not make a "decision" within the meaning of the law. However, an automation that automatically approves or rejects a credit application, a job application or a claim does fall into that category. The simplest approach for an SME is to keep a human in the loop for any decision with a significant effect on a person.

Hosting and transfers of data outside Quebec

Before communicating personal information outside Quebec (another province or another country), the business must carry out a PIA showing that the information will receive adequate protection, and enter into a written agreement with the recipient. A cloud AI provider whose servers are in the United States is therefore a transfer outside Quebec, even if you do not think of it as one.

This is why the choice of hosting is a compliance decision, not just a technical one.

Table: Law 25 obligation and what it means for an AI project

Obligation What it means for a chatbot, AI voice agent or automation project
Designated officer The officer must be involved from project scoping and their contact details published on the website.
Privacy policy Update the policy to describe the AI tool, the information collected and its purpose.
PIA Document the project's risks (data, hosting, access) before going live.
Consent Tell users they are interacting with an AI and obtain clear consent for each purpose.
Automated decisions Provide a human review mechanism and an explanation of the main factors.
Transfers outside Quebec Choose Canadian hosting or sign a written agreement after a PIA.
Incidents Log conversations and access so incidents can be detected and reported quickly.
Portability Be able to export a person's data in a structured format (e.g. JSON, CSV).
Minimization Collect only the information needed for the purpose, and delete it once that purpose is met.

What are the penalties for non-compliance?

According to the CAI's official page on penalties:

  • Administrative monetary penalties: up to 10 million dollars or 2% of worldwide turnover, whichever is higher. A business can, however, commit to corrective measures with the Commission; if that commitment is honoured, it cannot receive a monetary penalty for the violations covered.
  • Penal fines: from 15,000 dollars to 25 million dollars or 4% of worldwide turnover for a business; from 5,000 to 100,000 dollars for an individual. Fines are doubled for repeat offences, and proceedings can be brought within five years of the offence.

Beyond the amounts, the real risk for an SME is often reputational: a publicly reported confidentiality incident is expensive in lost trust.

Compliance checklist for a chatbot, AI voice agent or automation project

  1. Map the information: what does the tool collect, why, and for how long?
  2. Apply minimization: an appointment-booking chatbot does not need a health insurance number.
  3. Carry out a proportionate PIA, involving the designated officer.
  4. Check the hosting of every component (language model, database, telephony, automation tool) and document any transfer outside Quebec.
  5. Write the notices: state that the user is talking to an AI, list the purposes, access and correction rights, and link to the privacy policy.
  6. Identify automated decisions and plan human review.
  7. Configure logging and retention: keep what is useful, delete the rest automatically.
  8. Plan for portability and deletion on request.
  9. Update the incident register and reporting procedure.
  10. Train the team: AI training for businesses is often what turns a paper policy into real practice.

How does Zenidata design Law 25-compliant solutions?

At Zenidata, compliance is built in from the design stage rather than bolted on at the end:

  • 100% Canadian hosting for our business chatbots, AI voice agents and AI agents, which in most cases avoids the outside-Quebec transfer process altogether.
  • Data minimization: every project starts with a map of the information that is actually needed.
  • Human in the loop for any process automation that touches a decision about a person.
  • Logging, retention and deletion configured to your policies, including for intelligent document processing and invoice processing.
  • PIA documentation delivered to support your compliance file.

Planning a chatbot, AI voice agent or automation project and want to launch it without unpleasant surprises? Request your free AI audit: we review your use case, your data flows and your Law 25 obligations before writing a single line of code.

Last updated: August 23, 2026

Frequently asked questions

Does Law 25 apply to a small business that uses a chatbot?

Yes. Law 25 applies to anyone operating a business in Quebec that collects, uses or retains personal information, regardless of size. A chatbot that collects a name, an email address or a phone number falls within its scope.

Do I need a privacy impact assessment (PIA) before deploying an AI voice agent?

A PIA is required for any project to acquire, develop or overhaul an information system involving personal information, and before any transfer of that information outside Quebec. An AI voice agent that records calls or sends data to an out-of-province provider is a typical case.

What is a decision based exclusively on automated processing?

It is a decision about a person made without human intervention, for example a credit refusal computed by an algorithm. Law 25 then requires the business to inform the person, explain on request the main factors behind the decision, and let the person submit observations to a staff member who can review it.

Can my data be hosted in the United States?

Law 25 does not prohibit it, but it requires a PIA showing the information will receive adequate protection, plus a written agreement with the recipient. Hosting in Canada greatly simplifies this process, which is why Zenidata favours 100% Canadian hosting.

What are the penalties for non-compliance?

The Commission d'accès à l'information can impose administrative monetary penalties of up to 10 million dollars or 2% of worldwide turnover. Penal fines can reach 25 million dollars or 4% of worldwide turnover, and are doubled for repeat offences.