This guide is an informational aid, not legal advice. Veille's Law 25 obligations are drafts anchored to the official statutory text, pending review by independent Canadian counsel (0 of 146 obligations are lawyer-signed to date). Article references and dates below are drawn from the published text; confirm anything you rely on with your own counsel.
Overview
What is Law 25?
Law 25: An Act to modernize legislative provisions respecting the protection of personal information (formerly Bill 64), is Québec's comprehensive update to its 1994 privacy regime. It applies to any private-sector organization that collects, uses, or communicates personal information about individuals in Québec, regardless of where the organization is headquartered.
For organizations using AI systems, Law 25 adds explicit obligations around automated decision-making, Privacy Impact Assessments for new technology projects, transparency notices, and the right of individuals not to be subject to exclusively automated decisions.
Timeline
Three phases, all now in force.
Key obligations for AI
Articles that directly govern AI systems.
Scope
What counts as an automated decision?
For the purposes of s. 12.1, an automated decision is one based exclusively on automated processing of personal information, where any human involvement is a rubber stamp rather than a genuine, documented assessment.
In scope: credit scoring models, fraud detection systems that trigger automatic account suspensions, HR resume screening tools, underwriting engines, pricing optimizers, content moderation systems, customer segmentation affecting service access.
Borderline: systems that generate a recommendation that a human explicitly accepts or overrides with documented reasoning are potentially outside scope, but the documentation of that review must exist and be auditable.
Privacy Impact Assessments
What a compliant PIA must contain.
A compliant PIA under Law 25 must include:
- Description of the personal information collected and its purpose
- Identification of all parties accessing the information (including third-party AI vendors)
- Privacy risks identified and measures taken to mitigate them
- Retention schedule and destruction procedures
- For AI-specific PIAs: the model's decision logic, personal information used as input, and the human-review mechanism
PIAs must be completed before deployment. The CAI may request access to PIAs in the event of an incident or complaint. Failure to have a PIA on record is itself an offence, independent of whether a privacy breach occurred.
Most organizations starting with Veille don't have a complete PIA on file, and that's exactly the gap the agent is built to close. When it detects a missing assessment, it drafts the document itself: full bilingual content, structured to the criteria above, citing Art. 3.3 directly. It lands in the vault as a draft_pending_review record, and the platform won't count it toward your Law 25 score in that state. Your DPO reviews it against your real operations, adjusts what needs adjusting, and validates it through the vault, that one action is what flips the record to validated and turns the draft into evidence the agent (and a regulator) can rely on.
Penalties
The cost of non-compliance.
How Veille helps
Law 25 coverage in Veille AI.
Veille encodes Law 25 obligations article by article, mapped to the specific AI systems you register. Veille evaluates whether each obligation is met, flags gaps, and generates the required documentation.
Veille's Law 25 coverage is focused on obligations that apply to AI systems and automated decision systems. It does not replace a comprehensive privacy audit covering all organizational data practices. For a complete assessment, pair Veille with a qualified privacy counsel, we can introduce you to our legal reviewer partners.