Free consultationConsultation
Services
Pricing Savings calculator
Approach
Resources
About Français

Quebec Law 25 and artificial intelligence

Last updated: August 5, 2026

Quebec SMBs should be able to improve their operations with AI without losing control of customer, employee, or business data. “Law 25” is the common name for the Quebec privacy reform whose obligations are now reflected in the Act respecting the protection of personal information in the private sector. Here is how we turn those obligations into project decisions. This page complements our privacy policy and is not legal advice.

How Law 25 applies to an AI project

Law 25 does not regulate every piece of business information or every use of AI. It applies when a private-sector organization collects, uses, shares, keeps, or destroys personal information: information that identifies a person directly or indirectly. An AI project that uses customer records, employee information, emails, recordings, support messages, identifiers, or inferred profiles can therefore be covered. The Commission d’accès à l’information expressly lists an artificial intelligence system as a system that can require a privacy impact assessment when personal information is involved.

Who is responsible

The client SMB

The business remains responsible for personal information it holds, even when Yeevy or a cloud or AI provider processes it. Its privacy officer approves the purpose, necessary data, EFVP/PIA, residual risk, and production use.

Yeevy

Yeevy is directly responsible for information it collects for its own business. In a client mandate, we process only the information required by the written agreement, protect its confidentiality, report any confidentiality breach without delay, and do not keep it after the mandate unless the agreement and law permit it.

The AI provider

An AI or cloud provider is assessed as another service provider. Its location, subprocessors, training use, retention, access, security, incident notice, export, and deletion terms must be known. Processing outside Quebec requires an EFVP/PIA, adequate protection, and a written agreement.

The requirements, in simple terms

For a typical Quebec SMB project involving personal information, the business should be able to show all of the following:

  1. Put someone in charge. Identify the privacy officer, publish their title and contact information, and document any delegation in writing. Maintain governance rules for retention, destruction, staff responsibilities, and complaints.
  2. State the purpose and use only what is necessary. Define the legitimate purpose before collecting data. Use the minimum information needed. Consent does not make unnecessary collection acceptable.
  3. Be transparent and obtain valid consent when required. Explain the purpose, collection method, relevant third parties, possible processing outside Quebec, access and correction rights, and consent withdrawal in clear language. Consent must be clear, free, informed, specific, and requested separately when written.
  4. Complete an EFVP/PIA before the relevant work starts. An EFVP/PIA is required for acquiring, developing, or redesigning an information system involving personal information, including an AI system, and before personal information is processed outside Quebec. The privacy officer participates from the outset.
  5. Use written provider contracts. The contract must restrict the provider to the mandate, require confidentiality safeguards, prevent retention after the mandate, and require prompt notice of any confidentiality violation or attempted violation.
  6. Apply security and access controls proportionate to the risk. Limit access to people who need the information for their work. Use reasonable safeguards based on sensitivity, purpose, quantity, distribution, and storage medium.
  7. Keep people informed about exclusively automated decisions. If a decision is based exclusively on automated processing of personal information, notify the person. On request, provide the information used and the main reasons and factors, allow correction, and offer an opportunity to submit observations to someone able to review the decision.
  8. Manage the full lifecycle. Support access, correction, and applicable portability requests. Keep information only as long as required, then destroy or legally anonymize it. Record every confidentiality incident; contain it, assess the risk, and notify the Commission and affected people promptly when there is a risk of serious injury.

If a project uses only synthetic data or information anonymized according to law, some personal-information obligations may not apply. De-identified information is different: it remains protected, and the business must take reasonable measures against re-identification.

Our rule before confidential data reaches AI

By default, prototypes use synthetic, redacted, or de-identified data. No sensitive personal information, client record, trade secret, or access credential is sent to an external AI service until the need, approved data, provider, applicable privacy impact assessment, contractual safeguards, and client authorization are documented. If the risk cannot be reduced to an acceptable level, we redesign or stop that use of data.

Personal information and confidential business data are both protected

Law 25 protects information about an identifiable person. For an SMB, that can include customer and employee files, emails, recordings, support conversations, financial information, health information, identifiers, and information inferred by an AI system. De-identifying information reduces risk but does not automatically make it anonymous or remove it from privacy obligations.

Contracts, pricing, processes, source code, forecasts, and business strategy may be confidential even when they do not identify a person. Law 25 may not apply to that information in the same way, but we still protect it through the project agreement, access restrictions, provider controls, and an explicit list of information that is allowed or prohibited in the AI system.

Our six-gate process for an SMB AI project

Each project passes the following gates before production data is enabled. A failed gate means the data stays out while we change the design, choose another provider, or stop that part of the project.

  1. Map and classify the data

    We identify each source, field, data owner, affected group, destination, user, and retention need. We classify personal, sensitive, regulated, and confidential business information and identify credentials or secrets that must never be included in prompts or training material.

    What you receive: a data-flow map and a permitted/prohibited data register.

  2. Prove necessity and minimize

    We test whether the objective can be achieved without personal or confidential information, with fewer fields, or with synthetic, aggregated, redacted, or locally processed data. Consent does not replace the requirement that personal information be necessary for the stated purpose.

    What you receive: a documented purpose, minimum dataset, and lawful-use assumptions for the client to confirm.

  3. Complete the privacy impact assessment

    The client’s privacy officer is involved from the beginning. For an acquisition, development, or redesign of an information system involving personal information—including an AI system—a privacy impact assessment (PIA; EFVP in French) documents legal compliance, the data flow, affected people, risks, severity and likelihood, safeguards, residual risk, and approval. The assessment is also completed before personal information is communicated outside Quebec or entrusted to a person or organization outside Quebec to collect, use, communicate, or retain it. It is updated if the purpose, data, model, provider, or location changes.

    What you receive: an EFVP/PIA decision record stating proceed, modify, or stop, with risks, owners, safeguards, and review dates.

  4. Approve the AI provider and contract

    We verify hosting and processing locations, subprocessors, model-training terms, prompt and output retention, security controls, access, incident notice, export, and deletion. Shared-model training is disabled by configuration and contract unless the client expressly authorizes it in writing and has a lawful basis. Any applicable transfer outside Quebec must provide adequate protection and be governed by a written agreement reflecting the EFVP.

    What you receive: a provider assessment, required settings, and contractual control checklist.

  5. Build and test in a protected environment

    We begin with synthetic or redacted data in an isolated environment. Access follows least privilege. Depending on the risk, controls include encryption, separation of environments, pseudonymization, audit logs, output filtering, and testing for data leakage, prompt injection, incorrect results, and inappropriate bias. Production data is enabled only after the controls are verified and approved.

    What you receive: test evidence, an access matrix, and a production-readiness decision.

  6. Operate, monitor, and delete

    In production, we monitor access, failures, data leakage, and changes to the provider or model. Human review remains in the workflow for decisions that can significantly affect a person. Inputs, outputs, logs, provider copies, and backups follow the approved retention schedule, then are returned, deleted, or lawfully anonymized. The incident plan identifies who contains, assesses, records, and gives required notices for a privacy incident.

    What you receive: a retention and deletion schedule, monitoring plan, incident procedure, and handover documentation.

Human review and automated decisions

Our default is that AI assists a person; it does not replace accountable human judgment for a decision that significantly affects someone.

If a client chooses a decision based exclusively on automated processing of personal information, we design the workflow so the client can give the required notice, explain on request the information and main factors used, correct inaccurate information, receive the person’s observations, and provide meaningful human review.

Who is responsible

The SMB remains responsible for the personal information it holds and approves the purpose, data, residual risk, and production use through its privacy officer. Yeevy supplies the technical facts, performs the agreed controls, documents recommendations, and supports access, correction, consent-withdrawal, and incident obligations as a service provider. Legal counsel should validate novel, sensitive, regulated, or high-impact uses.

For information collected directly by Yeevy, contact Oleg Hmelevschi, Yeevy’s Privacy Officer — info@yeevy.ai · 514 346-2956.

Official Quebec references

Read Yeevy’s privacy policy