veille Resource, Regulatory Guide
Law 25, Québec

Law 25 and AI Systems: what organizations in Québec need to know.

Law 25 is fully in force as of September 2024. For organizations using AI systems that process personal data or make automated decisions, the obligations are specific, and the penalties are not symbolic.

StatusFully in force, Sept. 2024
Max penalty$25M or 4% worldwide revenue
RegulatorCommission d'accès à l'information (CAI)
Read this first, our honesty note

This guide is an informational aid, not legal advice. Veille's Law 25 obligations are drafts anchored to the official statutory text, pending review by independent Canadian counsel (0 of 146 obligations are lawyer-signed to date). Article references and dates below are drawn from the published text; confirm anything you rely on with your own counsel.

Overview

What is Law 25?

Law 25: An Act to modernize legislative provisions respecting the protection of personal information (formerly Bill 64), is Québec's comprehensive update to its 1994 privacy regime. It applies to any private-sector organization that collects, uses, or communicates personal information about individuals in Québec, regardless of where the organization is headquartered.

For organizations using AI systems, Law 25 adds explicit obligations around automated decision-making, Privacy Impact Assessments for new technology projects, transparency notices, and the right of individuals not to be subject to exclusively automated decisions.

Timeline

Three phases, all now in force.

Sept. 2022
Phase 1: Privacy officer designation mandatory. Incident registry required. Data governance policy publication.
Sept. 2023
Phase 2: Privacy Impact Assessments required. Automated decision transparency notices. Consent rules. Cross-border transfer rules.
Sept. 2024
Phase 3, Full force: Right to de-indexing. Right to data portability (Art. 27, para. 3) in force. Right not to be subject to exclusively automated decisions. All provisions in effect. CAI enforcement active.

Key obligations for AI

Articles that directly govern AI systems.

Art. 3.1 Person in charge of personal information (RPRP)
By default, the person exercising the highest authority in the organization is responsible for the protection of personal information and acts as the person in charge (responsable), a role they may delegate in writing. For AI systems specifically: that person must be identifiable to individuals whose data is processed. Unregistered AI systems with no designated owner are an immediate exposure under this article.
Art. 12.1 Automated decision transparency
Organizations using personal information to render a decision based exclusively on automated processing must inform the individual: (1) that a decision will be made by automation; (2) the personal information used; (3) the factors leading to the decision; and (4) their right to have the decision reviewed by a human. This applies to credit scoring, HR screening, fraud flagging, pricing optimization, and any system that makes a decision without meaningful human review.
Art. 3.3, 17 Privacy Impact Assessment (EFVP / PIA), Art. 3.3
Under Art. 3.3, a PIA is mandatory before any project involving the acquisition, development, or redesign of an information system that collects, uses, or communicates personal information. Where the project involves communicating personal information outside Québec, Art. 17 requires that the assessment also evaluate whether the information would receive adequate protection. Every new model in production, every major update to an existing model, and any system integrated with a third-party AI component requires a documented PIA, completed before implementation. Retroactive assessments are not compliant.
Art. 12.1 Right to human review of an automated decision
The same provision, s. 12.1, gives the individual the right, on request, to be informed of the personal information used and the principal factors and parameters that led to the decision, and to submit observations to a member of personnel who is in a position to review it. Organizations must implement a human-review pathway for every exclusively automated decision system. This right is not a separate article, it lives inside s. 12.1 alongside the transparency notice above.

Scope

What counts as an automated decision?

For the purposes of s. 12.1, an automated decision is one based exclusively on automated processing of personal information, where any human involvement is a rubber stamp rather than a genuine, documented assessment.

In scope: credit scoring models, fraud detection systems that trigger automatic account suspensions, HR resume screening tools, underwriting engines, pricing optimizers, content moderation systems, customer segmentation affecting service access.

Borderline: systems that generate a recommendation that a human explicitly accepts or overrides with documented reasoning are potentially outside scope, but the documentation of that review must exist and be auditable.

Privacy Impact Assessments

What a compliant PIA must contain.

A compliant PIA under Law 25 must include:

  • Description of the personal information collected and its purpose
  • Identification of all parties accessing the information (including third-party AI vendors)
  • Privacy risks identified and measures taken to mitigate them
  • Retention schedule and destruction procedures
  • For AI-specific PIAs: the model's decision logic, personal information used as input, and the human-review mechanism
Important

PIAs must be completed before deployment. The CAI may request access to PIAs in the event of an incident or complaint. Failure to have a PIA on record is itself an offence, independent of whether a privacy breach occurred.

Don't have one yet?

Most organizations starting with Veille don't have a complete PIA on file, and that's exactly the gap the agent is built to close. When it detects a missing assessment, it drafts the document itself: full bilingual content, structured to the criteria above, citing Art. 3.3 directly. It lands in the vault as a draft_pending_review record, and the platform won't count it toward your Law 25 score in that state. Your DPO reviews it against your real operations, adjusts what needs adjusting, and validates it through the vault, that one action is what flips the record to validated and turns the draft into evidence the agent (and a regulator) can rely on.

Penalties

The cost of non-compliance.

$25M or 4%
Penal offences: fines up to $25M, or 4% of worldwide turnover, whichever is greater. The most serious track, prosecutable by the CAI since September 2023.
$10M or 2%
Administrative monetary penalties: up to $10M, or 2% of worldwide turnover, whichever is greater. Imposed by the CAI for breaches such as failing to keep a PIA on file, designate a person in charge, or meet automated-decision transparency.

How Veille helps

Law 25 coverage in Veille AI.

Veille encodes Law 25 obligations article by article, mapped to the specific AI systems you register. Veille evaluates whether each obligation is met, flags gaps, and generates the required documentation.

Scope note

Veille's Law 25 coverage is focused on obligations that apply to AI systems and automated decision systems. It does not replace a comprehensive privacy audit covering all organizational data practices. For a complete assessment, pair Veille with a qualified privacy counsel, we can introduce you to our legal reviewer partners.

Audit

See your Law 25 posture in 48 hours.

We'll map your AI systems against Law 25 obligations and deliver a written gap report, no commitment required.

Request your free audit