In most small and mid-sized businesses in Quebec, AI is already in the building. Not through a project approved by the executive team. Through an employee who pasted a contract into a free tool to get a quick summary.
This article isn’t about banning AI. It’s about what you need to decide first, and the internal policy framework that goes with it.
Quick answer: Bill 25 doesn’t contain the words “artificial intelligence,” and it doesn’t need to. It governs what you do with personal information. Four provisions do the work: Section 17 on processing outside Quebec, Section 12 on the purpose of collection, Section 12.1 on automated decisions, and Section 10 on reasonable security measures.
1. The law doesn’t mention AI, and that’s fine
Quebec’s Act respecting the protection of personal information in the private sector, as amended by Bill 25, governs the handling of personal information regardless of the tool used. When you feed a client file, a resume, or an employee record into an AI tool, that tool is processing personal information. The rules apply as-is.
- Section 17, on disclosing information outside Quebec and on entrusting someone outside Quebec with collecting, using, communicating, or storing information on your behalf.
- Section 12, which prohibits using personal information for any purpose other than the one for which it was collected, unless consent is given or an exception applies.
- Section 12.1, on decisions based exclusively on automated processing.
- Section 10, which requires reasonable security measures based on factors including the sensitivity of the information, its intended use, the quantity involved, its distribution, and the medium.
2. Decision 1: where the data goes, and under what contract
Section 17 is the starting point because it almost always applies. Before disclosing personal information outside Quebec, the organization must conduct a privacy impact assessment, taking into account the sensitivity of the data, the purpose, protective measures including contractual ones, and the legal framework of the destination jurisdiction. The disclosure must be covered by a written agreement.
The fourth paragraph clarifies that the same rule applies when you entrust the processing or storage of information to someone outside Quebec. That’s exactly what a cloud-based AI service does.
Two points tend to catch people off guard. The law says “outside Quebec”: a service with servers in another province is covered just as much as an overseas service. And the assessment is your obligation, not the vendor’s.
For each service, you should be able to write the following on a single page:
- which personal information is submitted to the tool, and which types are prohibited;
- the country where data is processed and stored;
- how long the data is retained;
- whether submitted content can be used for model training;
- which contract applies, and which clauses cover personal information protection;
- who within your organization authorized the use and on what date.
Keep this in mind: the consumer version of a service and its enterprise offering are not governed by the same contract. Read the one that applies to your specific subscription.

3. Decision 2: which data is allowed in
This is the most practical decision and the easiest one to communicate. Three categories are enough.
Prohibited. Sensitive information as defined in Section 12: medical data, biometric data, anything otherwise intimate or that, given its context, carries a high reasonable expectation of privacy. Add to that social insurance numbers, banking data, login credentials, disciplinary records, documents covered by professional secrecy, and anything a client contract prohibits you from sharing.
Permitted with an approved tool only. Common personal information: names, contact details, service history, client correspondence, internal non-public documents.
Permitted everywhere. Public content, generic content, text you’d be comfortable publishing.
Write out these three lists with examples from your own business. An abstract rule doesn’t change behavior; “don’t paste employee file content” does.
4. Decision 3: automated decisions
Section 12.1 applies to organizations that use personal information for decisions made exclusively through automated processing. The organization must notify the person of this automated nature no later than when it communicates the decision. On request, it must provide the information used, the reasons, and the main factors and parameters behind the decision, along with the person’s right to have that information corrected. The person must also be given the opportunity to present their views to a staff member capable of reviewing the decision.
The key word is “exclusively.” If a person genuinely reviews the file and makes the call, the section doesn’t apply. If the system decides and the human just passes the result along, it does.
Small business scenarios that fall under this: automatic screening of job applications, credit approvals or denials, personalized pricing, decisions to cancel a service. The practical implication is a design constraint. A tool that provides no explanation puts you in violation by default. Two ways out: preserve genuine human decision-making, or choose a mechanism with criteria that are explicit and documentable.
5. Decision 4: shadow AI
This is the most common risk, and one that no policy alone can solve. An employee uses a personal tool on a work computer, through a browser extension, or on their phone. Data goes out. Nobody knows. There’s no assessment, no written agreement, no log.
If a breach follows, you can’t assess the risk of harm or show what left. But Section 3.7 requires you to evaluate the sensitivity of the information, the anticipated consequences of its use, and the likelihood it will be used for harmful purposes.
Three measures that work together:
- Make the approved tool more convenient than the prohibited one. This is the most effective measure. People bypass restrictions when following them takes longer.
- Apply technical controls. Restrict browser extensions, filter access to unapproved services, manage devices, and enable data loss prevention in email and cloud storage. These are infrastructure settings, not guidelines.
- Make reporting easy. An employee who pasted the wrong thing needs to be able to say so without fear, otherwise the incident never makes it into the log.
![]()
6. Decision 5: permissions before the assistant
An AI assistant connected to your office environment respects, in principle, the permissions already in place. That’s exactly where the problem shows up.
In many small businesses, a shared folder has been open to everyone for years. Nobody noticed because you had to know where to look. An assistant that indexes content and answers questions makes that openness visible instantly. The assistant doesn’t create the gap, it exposes it.
Do this before deployment, not after: audit broad share permissions, remove generic access, apply role-based permissions, review external sharing links and public links, and check mailboxes and sites left behind by former employees. It’s unglamorous cleanup work, and it determines whether your deployment goes smoothly or becomes an incident. Our managed IT services cover exactly this kind of cleanup.
7. Decision 6: the paper trail, and a realistic action plan
Section 3.8 requires organizations to maintain a privacy incident log, and Section 3.5 requires reasonable action as soon as there are grounds to believe an incident has occurred. For AI use, a useful record includes the list of approved tools and their approval dates, the assessment done for each, the written agreements, the list of authorized users, access logs for the data the tool touches, and training records with attendance.
An action plan that fits in six weeks:
- Inventory what’s already being used, without looking for someone to blame.
- Decide on the three data categories and the list of approved tools.
- Complete a privacy impact assessment for each approved tool, and confirm which contract applies.
- Clean up sharing permissions before any assistant deployment.
- Publish the policy, walk the team through it in thirty minutes, and record attendance.
- Review twice a year and with every new tool.
The policy itself fits on a double-sided page: scope, who it applies to, approved tools as an appendix, prohibited data, permitted data with an approved tool, human review of results, decisions affecting individuals, reporting, ownership and confidentiality, consequences of non-compliance, and annual review.
Frequently Asked Questions
Does Bill 25 prohibit using AI tools at work?
No. No provision prohibits a specific tool. The general obligations apply: an assessment before any processing outside Quebec, a written agreement, limitation to the stated purpose, and reasonable security measures.
Is an AI tool hosted in Canada but outside Quebec a problem?
Section 17 covers disclosures outside Quebec, not outside Canada. An assessment is therefore required even for hosting in another province. That doesn’t make the use prohibited, it makes it something you need to document.
What should you do if an employee has already submitted sensitive data to a consumer tool?
Treat it as a presumed privacy incident: take reasonable steps to reduce the risk, log it, assess the risk of serious injury with your privacy officer using the factors in Section 3.7, and notify if the threshold is met.
Governing AI before you deploy it, in Quebec
The two actions that reduce risk the most don’t require a project: inventorying the tools already in use and writing out the list of prohibited data. The rest is infrastructure work, including permission cleanup, logging, and endpoint controls, all covered by our managed IT services for businesses in Trois-Rivieres and the Mauricie region. To prepare your policy and your deployment, use the contact form or call 450-231-3836.
This guide simplifies legal obligations. It is not legal advice and does not replace reading the legislation itself or consulting a legal professional. Legal references point to the Act respecting the protection of personal information in the private sector (CQLR, chapter P-39.1), as amended by Bill 25.