🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
CA-QC v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing18 sources retrieved model claude-sonnet-5 · 2026-08-05

Quebec, Canada

CA-QC schema gdpri-v2 trajectory: not yet assessedhybrid regimeoverlaps: AIC

Last updated · 10 categories · 50 claims · 23 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
50Claimsbaseline..claims[]
11Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)
No red categories; 19 sub-modules are flagged red.

Jurisdiction lead brief

Standing brief, as of 4 September 2026.

Lead Signal

Quebec's Commission d'accès à l'information issued a decision this cycle prohibiting Metro Inc. from putting into service a biometric-characteristics database. This is a concrete enforcement precedent rather than a change to the statutory text of Law 25, and it demonstrates that the province's biometric-processing rules carry active supervisory teeth beyond what the statute alone would suggest. The decision is Confirmed via a Tier-1 CAI source and represents this cycle's clearest signal of regulatory activity within Quebec's fully phased-in private-sector data-protection regime.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Comprehensive, fully-in-force omnibus private-sector statute with an active, well-resourced supervisory authority; only minor gaps in extraterritorial-scope statutory clarity.

Primary frameworkAct Respecting the Protection of Personal Information in the Private Sector, CQLR c P-39.1, as amended by Law 25 (SQ 2021, c. 25)
Traffic-light rationale — GreenComprehensive, fully-in-force omnibus private-sector statute with an active, well-resourced supervisory authority; only minor gaps in extraterritorial-scope statutory clarity.

Sub-modules (5)

Regulator And AuthorityGreen

CAI is the sole provincial DPA overseeing the Private Sector Act, with inquiry, order-making and sanctioning powers.

Claims (1):

  • The Commission d'accès à l'information du Québec (CAI) is Quebec's provincial data protection authority responsible for overseeing compliance with the Act Respecting the Protection of Personal Information in the Private Sector.

Act And InstrumentsGreen

Core instrument is the Private Sector Act as amended by Law 25; biometrics and health-sector data carry dedicated overlay instruments.

Claims (4):

  • Quebec's data-protection regime is anchored in the Act Respecting the Protection of Personal Information in the Private Sector, CQLR c P-39.1, as substantially amended by An Act to modernize legislative provisions as regards the protection of personal information (SQ 2021, c. 25 / Law 25, formerly Bill 64).
  • Law 25 entered into force in three phases beginning September 22, 2022, with the final phase (data portability) taking effect September 22, 2024, at which point the Act is fully in force.
  • Biometric-specific obligations are separately set out in Quebec's Act to Establish a Legal Framework for Information Technology, which Law 25 amended to require 60 days' advance notice to the CAI before a biometric database is brought into service.
  • Quebec's Act Respecting Health and Social Services Information (LRSSS) entered into effect July 1, 2024, establishing a health-sector-specific personal information protection regime.

Material ScopeGreen

Applies to collection, retention, use, access and transfer of personal information by private enterprises carrying on business in Quebec.

Claims (1):

  • The Private Sector Act governs the collection, retention, use, access to, and transfer of personal information by private enterprises carrying on business in Quebec.

Territorial ScopeAmber

Statutory extraterritorial reach is not as explicit as GDPR Art. 3, but CAI guidance signals expected application to foreign entities serving Quebec residents.

Claims (1):

  • CAI guidance indicates both Canadian and foreign companies offering goods or services in Quebec are expected to comply with its consent framework, signalling an extraterritorial-facing application of the Private Sector Act to organizations serving Quebec residents.

Regulator Registration And FilingAmber

No general registration regime, but biometric-database creation must be pre-disclosed to CAI 60 days before deployment.

Claims (1):

  • Organizations must disclose to the CAI, at least 60 days in advance, the creation of any database containing biometric characteristics or measurements before it is brought into service.
Category narrative88 words

Quebec operates a comprehensive, GDPR-influenced private-sector data protection regime under the Act Respecting the Protection of Personal Information in the Private Sector (CQLR c P-39.1), as substantially amended by Law 25 (formerly Bill 64, SQ 2021 c.25), enforced by the Commission d'accès à l'information du Québec (CAI). A parallel Public Sector Act governs government bodies (out of scope here), and sector-specific instruments (biometrics IT Act, LRSSS) overlay the general regime. Law 25 entered into force in three phases from Sept. 2022 through full effect on Sept. 22, 2024.

Sources and claims (8)
  1. ConfirmedDataGuidance — The Commission d'accès à l'information du Québec (CAI) is Quebec's provincial data protection authority responsible for overseeing compliance with the Act Respecting the Protection of Personal Information in the Private Sector.observed
  2. ConfirmedDataGuidance — Quebec's data-protection regime is anchored in the Act Respecting the Protection of Personal Information in the Private Sector, CQLR c P-39.1, as substantially amended by An Act to modernize legislative provisions as regards the protection of personal information (SQ 2021, c. 25 / Law 25, formerly Bill 64).observed
  3. ConfirmedOffice of the Privacy Commissioner of Canada — Law 25 entered into force in three phases beginning September 22, 2022, with the final phase (data portability) taking effect September 22, 2024, at which point the Act is fully in force.observed
  4. ConfirmedOffice of the Privacy Commissioner of Canada — Biometric-specific obligations are separately set out in Quebec's Act to Establish a Legal Framework for Information Technology, which Law 25 amended to require 60 days' advance notice to the CAI before a biometric database is brought into service.observed
  5. ConfirmedDataGuidance — Quebec's Act Respecting Health and Social Services Information (LRSSS) entered into effect July 1, 2024, establishing a health-sector-specific personal information protection regime.observed
  6. ConfirmedDataGuidance — The Private Sector Act governs the collection, retention, use, access to, and transfer of personal information by private enterprises carrying on business in Quebec.observed
  7. ProbableDataGuidance — CAI guidance indicates both Canadian and foreign companies offering goods or services in Quebec are expected to comply with its consent framework, signalling an extraterritorial-facing application of the Private Sector Act to organizations serving Quebec residents.observed
  8. ConfirmedOffice of the Privacy Commissioner of Canada — Organizations must disclose to the CAI, at least 60 days in advance, the creation of any database containing biometric characteristics or measurements before it is brought into service.observed

#

Consent and sensitive-data rules are mature and CAI has published detailed guidance; lawful-basis enumeration is less granular than GDPR.

Primary frameworkAct Respecting the Protection of Personal Information in the Private Sector, CQLR c P-39.1, as amended by Law 25
Traffic-light rationale — GreenConsent and sensitive-data rules are mature and CAI has published detailed guidance; lawful-basis enumeration is less granular than GDPR.

Sub-modules (4)

Lawful BasesAmber

Purpose determination and necessity are statutory preconditions to collection; consent is the primary basis, with limited non-consent grounds (e.g., contract performance).

Claims (1):

  • Organizations must determine the purposes for collecting personal information and may collect only the information necessary for those purposes.

Special CategoriesGreen

Sensitive information (medical, biometric, intimate, or contextually high-expectation data) triggers express-consent and heightened-safeguard duties.

Claims (2):

  • Sensitive personal information under Quebec law includes medical, biometric, or otherwise intimate information, and information may also become sensitive where the context of its use or communication entails a high reasonable expectation of privacy.
  • Organizations must obtain express consent before using sensitive personal information for secondary purposes.

Pseudonymisation And AnonymisationGreen

Law 25 distinguishes de-identified from anonymised information and conditions anonymisation on legitimacy and best-practice standards.

Claims (2):

  • Under Law 25, personal information is 'de-identified' if it no longer allows direct identification of the person concerned, whereas information is 'anonymized' only if it irreversibly no longer allows the person to be identified directly or indirectly.
  • Anonymization of personal information must be performed for serious and legitimate reasons and according to generally accepted best practices.
Category narrative38 words

Quebec requires purpose-limited collection, clear/free/informed consent (express for sensitive data), and defines de-identification/anonymisation with a legitimacy-and-best-practices standard. There is no enumerated Art.-6-style list of lawful bases; consent is the dominant basis, with narrow statutory exceptions (e.g., contract performance).

Sources and claims (6)
  1. ConfirmedIAPP — Organizations must determine the purposes for collecting personal information and may collect only the information necessary for those purposes.observed
  2. ConfirmedIAPP — Consent requests must be presented separately from other information requests and must be clear, free and informed, with express consent required for sensitive personal information.observed
  3. ConfirmedIAPP — Sensitive personal information under Quebec law includes medical, biometric, or otherwise intimate information, and information may also become sensitive where the context of its use or communication entails a high reasonable expectation of privacy.observed
  4. ConfirmedIAPP — Organizations must obtain express consent before using sensitive personal information for secondary purposes.observed
  5. ConfirmedOffice of the Privacy Commissioner of Canada — Under Law 25, personal information is 'de-identified' if it no longer allows direct identification of the person concerned, whereas information is 'anonymized' only if it irreversibly no longer allows the person to be identified directly or indirectly.observed
  6. ProbableIAPP — Anonymization of personal information must be performed for serious and legitimate reasons and according to generally accepted best practices.observed

#

Full suite of rights now in force including portability as of the final 2024 phase; deadlines are codified.

Primary frameworkAct Respecting the Protection of Personal Information in the Private Sector, CQLR c P-39.1, as amended by Law 25
Traffic-light rationale — GreenFull suite of rights now in force including portability as of the final 2024 phase; deadlines are codified.

Sub-modules (5)

Access RightGreen

Organizations must confirm existence of, communicate, and provide copies of personal information on request.

Claims (1):

  • Organizations must, on request, confirm the existence of personal information, communicate it, and provide a copy to the individual concerned.

Rectification And ErasureGreen

Access/rectification rights plus a de-indexing 'right to be forgotten' subject to a reputational-harm balancing test.

Claims (2):

  • The Private Sector Act provides individuals a right to access and rectification of their personal information.
  • Section 28.1 creates a right to de-indexing ('right to be forgotten') requiring cessation of dissemination or de-indexing of a hyperlink where dissemination causes serious injury to reputation or privacy that outweighs the public interest in the information or freedom of expression.

Restriction And ObjectionGreen

Individuals may contest automated decisions and request human review.

Claims (1):

  • Individuals have a right to contest an automated decision and request human review, analogous to Article 22(3) GDPR.

Data PortabilityGreen

Portability right became effective in the final Law 25 implementation phase.

Claims (1):

  • The right to data portability was the final phase of Law 25 to take effect, entering into force on September 22, 2024.

Deadlines And Response WindowsGreen

Statutory 30-day response window applies to individual rights requests.

Claims (1):

  • An individual's request to exercise access or rectification rights must be responded to within 30 days.
Category narrative35 words

Quebec grants GDPR-adjacent rights of access, rectification, a bespoke 'right to be forgotten' via de-indexing, contestation of automated decisions, and (as of Sept. 2024) data portability, with a 30-day statutory response window for access/rectification requests.

Sources and claims (6)
  1. ConfirmedIAPP — Organizations must, on request, confirm the existence of personal information, communicate it, and provide a copy to the individual concerned.observed
  2. ConfirmedDataGuidance — The Private Sector Act provides individuals a right to access and rectification of their personal information.observed
  3. ConfirmedOffice of the Privacy Commissioner of Canada — Section 28.1 creates a right to de-indexing ('right to be forgotten') requiring cessation of dissemination or de-indexing of a hyperlink where dissemination causes serious injury to reputation or privacy that outweighs the public interest in the information or freedom of expression.observed
  4. ConfirmedOffice of the Privacy Commissioner of Canada — Individuals have a right to contest an automated decision and request human review, analogous to Article 22(3) GDPR.observed
  5. ConfirmedOffice of the Privacy Commissioner of Canada — The right to data portability was the final phase of Law 25 to take effect, entering into force on September 22, 2024.observed
  6. ConfirmedIAPP — An individual's request to exercise access or rectification rights must be responded to within 30 days.observed

#

Strong DPIA/breach/security/retention coverage (green-level), but ROPA and joint-controller concepts are not codified in equivalent GDPR form, warranting an amber overall rating.

Primary frameworkAct Respecting the Protection of Personal Information in the Private Sector, CQLR c P-39.1, as amended by Law 25
Traffic-light rationale — AmberStrong DPIA/breach/security/retention coverage (green-level), but ROPA and joint-controller concepts are not codified in equivalent GDPR form, warranting an amber overall rating.

Sub-modules (7)

Accountability And DpiaGreen

Mandatory PIAs before adopting processing technology or transferring data outside Quebec; published privacy program required.

Claims (2):

  • Organizations must conduct a privacy impact assessment before adopting technology that processes personal information and before transferring personal information outside Quebec.
  • Organizations must adopt and publish privacy governance policies and practices according to prescribed requirements, approved by the person in charge of protecting personal information.

Dpo RequirementsGreen

Default CEO accountability, delegable in writing, with published contact details for the person in charge.

Claims (1):

  • By default, the highest authority (e.g., CEO) of an organization is responsible for compliance with the Private Sector Act, but this responsibility may be delegated in writing to any person, whose name, title and contact information must be published.

Ropa RequirementsRed

No dedicated Article-30-style records-of-processing obligation was identified in this research pass; the nearest analogue is the mandatory confidentiality-incident register (see breach_notification).

Joint Controller ArrangementsRed

No GDPR-style joint-controller regime was located in the Private Sector Act or Law 25 text reviewed.

Security MeasuresGreen

Security obligation is proportionate/contextual (sensitivity, purpose, quantity, medium).

Claims (1):

  • Enterprises must take security measures necessary to protect personal information that are reasonable given the sensitivity of the information, its purposes, quantity, and the medium on which it is stored.

Breach NotificationGreen

Mandatory dual notification (CAI + individuals) on 'risk of serious injury', plus an incident register and remediation review.

Claims (2):

  • Organizations must notify the CAI and affected individuals of any confidentiality incident presenting a 'risk of serious injury,' assessed under real-risk-of-significant-harm factors.
  • Organizations must maintain a register of confidentiality incidents and conduct a lessons-learned/remediation review to help prevent recurrence.

Retention And DisposalGreen

Destruction obligation on purpose-expiry, satisfiable via anonymisation.

Claims (1):

  • Organizations must destroy personal information once it is no longer required for the purposes for which it was collected, a duty that may be satisfied through anonymization.
Category narrative43 words

Law 25 imposes accountability via mandatory PIAs, a designated (default CEO) accountable person, breach-notification and incident-register duties, and destruction/anonymisation on retention expiry. No explicit GDPR-Art.-30-style ROPA or 'joint controller' concept was located; the closest analogues are the confidentiality-incident register and general accountability program.

Sources and claims (7)
  1. ConfirmedIAPP — Organizations must conduct a privacy impact assessment before adopting technology that processes personal information and before transferring personal information outside Quebec.observed
  2. ConfirmedIAPP — Organizations must adopt and publish privacy governance policies and practices according to prescribed requirements, approved by the person in charge of protecting personal information.observed
  3. ConfirmedIAPP — By default, the highest authority (e.g., CEO) of an organization is responsible for compliance with the Private Sector Act, but this responsibility may be delegated in writing to any person, whose name, title and contact information must be published.observed
  4. ConfirmedDataGuidance — Enterprises must take security measures necessary to protect personal information that are reasonable given the sensitivity of the information, its purposes, quantity, and the medium on which it is stored.observed
  5. ConfirmedIAPP — Organizations must notify the CAI and affected individuals of any confidentiality incident presenting a 'risk of serious injury,' assessed under real-risk-of-significant-harm factors.observed
  6. ConfirmedIAPP — Organizations must maintain a register of confidentiality incidents and conduct a lessons-learned/remediation review to help prevent recurrence.observed
  7. ConfirmedIAPP — Organizations must destroy personal information once it is no longer required for the purposes for which it was collected, a duty that may be satisfied through anonymization.observed

#

Robust TIA obligation is in force, but the absence of published adequacy lists and localisation clarity leaves cross-border compliance more case-specific than in EU-style regimes.

Primary frameworkAct Respecting the Protection of Personal Information in the Private Sector, CQLR c P-39.1, as amended by Law 25 (Section 17)
Traffic-light rationale — AmberRobust TIA obligation is in force, but the absence of published adequacy lists and localisation clarity leaves cross-border compliance more case-specific than in EU-style regimes.

Sub-modules (6)

Transfer MechanismsAmber

Section 17 requires an outbound transfer assessment rather than reliance on a fixed adequacy list.

Claims (1):

  • Section 17 requires organizations to conduct a transfer/privacy impact assessment before transferring personal information outside Quebec, assessing sensitivity, purpose, and the adequacy of protection at the destination, including equivalent obligations on subsequent third-party recipients.

Adequacy ReceivedRed

No published inbound adequacy determinations affecting Quebec were located in this research pass.

Adequacy GrantedRed

Quebec does not appear to operate a published outbound adequacy-list mechanism; equivalence is assessed case-by-case under Section 17.

Sccs And BcrsAmber

Contractual equivalence obligations function similarly to SCCs but are not a named, standardized instrument.

Claims (1):

  • Organizations relying on contractual safeguards to meet Section 17's outside-Quebec transfer requirement must bind subsequent third-party recipients to equivalent data-protection obligations, functioning similarly to standard contractual clauses.

Transfer Impact AssessmentGreen

TIA must weigh sensitivity, purpose, destination protection, and downstream third-party obligations.

Claims (1):

  • A Quebec transfer impact assessment must consider the sensitivity of the information, the purpose of the transfer, and whether the information will receive adequate protection once transferred, including from third parties who may subsequently access it.

Data LocalisationRed

No absolute or general data-localisation mandate was identified for Quebec's private-sector regime in this pass.

Category narrative38 words

Quebec uses a case-by-case Transfer Impact Assessment model (Section 17) rather than a published adequacy-list mechanism. No formal adequacy decisions received-from or granted-to other regimes were located, and no absolute data-localisation mandate was identified in the private-sector regime.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (3)
  1. ConfirmedIAPP — Section 17 requires organizations to conduct a transfer/privacy impact assessment before transferring personal information outside Quebec, assessing sensitivity, purpose, and the adequacy of protection at the destination, including equivalent obligations on subsequent third-party recipients.observed
  2. ProbableIAPP — Organizations relying on contractual safeguards to meet Section 17's outside-Quebec transfer requirement must bind subsequent third-party recipients to equivalent data-protection obligations, functioning similarly to standard contractual clauses.observed
  3. ConfirmedIAPP — A Quebec transfer impact assessment must consider the sensitivity of the information, the purpose of the transfer, and whether the information will receive adequate protection once transferred, including from third parties who may subsequently access it.observed

#

Health overlay is well-evidenced (green-level); most other sectors carry no confirmed Quebec-specific overlay, driving an overall amber/gap rating.

Primary frameworkAct Respecting Health and Social Services Information (LRSSS); Private Sector Act generally for other sectors
Traffic-light rationale — AmberHealth overlay is well-evidenced (green-level); most other sectors carry no confirmed Quebec-specific overlay, driving an overall amber/gap rating.

Sub-modules (7)

Financial Sector OverlayRed

No Quebec-specific financial-sector privacy overlay (beyond the general Private Sector Act) was located.

Absence provenance: unavailable. Searched: Quebec financial sector data protection AMF overlay, Quebec Law 25 financial institutions.

Health Sector OverlayGreen

LRSSS establishes a dedicated health/social-services information regime, in effect since July 1, 2024.

Claims (1):

  • The Act Respecting Health and Social Services Information (LRSSS), effective July 1, 2024, establishes a health-and-social-services-specific personal information regime intended to protect such information while enabling its use to improve service quality.

Telecoms And EprivacyRed

No Quebec-specific telecoms/ePrivacy instrument distinct from the general Private Sector Act was located.

Absence provenance: unavailable. Searched: Quebec telecoms ePrivacy cookies law.

Employment DataAmber

CAI has issued guidance on personal-data handling in recruitment, including responsible AI use.

Claims (1):

  • The CAI has issued guidance advising employers on best practices for handling personal information in recruitment, including responsible use of AI tools in hiring.

Credit And ScoringRed

No Quebec-specific credit-scoring overlay was located beyond general Private Sector Act obligations.

Absence provenance: unavailable. Searched: Quebec credit scoring privacy law.

EducationRed

No Quebec-specific education-sector data protection overlay was located in this pass.

Absence provenance: unavailable. Searched: Quebec education sector student data privacy law.

InsuranceRed

No Quebec-specific insurance-sector data protection overlay was located in this pass.

Absence provenance: unavailable. Searched: Quebec insurance sector privacy overlay.

Category narrative47 words

A dedicated health-and-social-services overlay (LRSSS) is confirmed in force since July 2024. CAI has issued recruitment/AI-hiring guidance touching employment data. No Quebec-specific financial-sector, telecoms/ePrivacy, credit-scoring, education, or insurance overlay instruments were surfaced in this research pass; searches covered CAI guidance pages, LRSSS coverage, and DataGuidance/IAPP sectoral commentary.

Sources and claims (2)
  1. ConfirmedDataGuidance — The Act Respecting Health and Social Services Information (LRSSS), effective July 1, 2024, establishes a health-and-social-services-specific personal information regime intended to protect such information while enabling its use to improve service quality.observed
  2. ProbableDataGuidance — The CAI has issued guidance advising employers on best practices for handling personal information in recruitment, including responsible use of AI tools in hiring.observed

#

Strong privacy-by-default and marketing-consent coverage, but no evidence of signal-based opt-out or cross-context-advertising-specific rules.

Primary frameworkAct Respecting the Protection of Personal Information in the Private Sector, CQLR c P-39.1, as amended by Law 25
Traffic-light rationale — AmberStrong privacy-by-default and marketing-consent coverage, but no evidence of signal-based opt-out or cross-context-advertising-specific rules.

Sub-modules (6)

Cookies And TrackersGreen

Default configuration must deactivate identification/location/profiling functions absent opt-in.

Claims (1):

  • By default, organizations must configure products and services so that functions enabling identification, location, or profiling of an individual are deactivated unless the individual actively opts in.

Dark PatternsAmber

Canadian regulators, including CAI, flag manipulative design (oversized opt-in buttons, addictive engagement incentives) as inconsistent with privacy-by-default and best-interest-of-minors principles.

Claims (1):

  • Manipulative design patterns such as oversized opt-in buttons and addictive engagement incentives are flagged by Canadian privacy regulators, including Quebec's CAI, as inconsistent with privacy-by-default and best-interest-of-young-persons principles.

Opt Out SignalsRed

No Quebec-specific recognition of Global Privacy Control or equivalent browser-based opt-out signals was located.

Absence provenance: unavailable. Searched: Quebec Law 25 Global Privacy Control opt-out signal.

Clean Rooms And DcrRed

No Quebec-specific clean-room/data-collaboration-room rules were located.

Absence provenance: unavailable. Searched: Quebec data clean room privacy rules.

Cross Context AdvertisingRed

Quebec's regime does not define CPRA-style 'sale'/'share' categories for cross-context advertising.

Absence provenance: unavailable. Searched: Quebec Law 25 sale share personal information cross-context advertising.

Direct MarketingGreen

Marketing uses require identity disclosure and a consent-withdrawal mechanism.

Claims (1):

  • Where personal information is used for marketing ('prospection') purposes, the organization must communicate the identity of the party using the information and inform individuals of their right to withdraw consent.
Category narrative34 words

Privacy-by-default rules require deactivation of identification/location/profiling functions absent opt-in, and marketing/'prospection' uses require identity disclosure and consent-withdrawal rights. No Quebec-specific recognition of Global-Privacy-Control-style opt-out signals, clean rooms, or CPRA-style 'sale/share' cross-context-advertising categories was located.

Sources and claims (3)
  1. ConfirmedIAPP — By default, organizations must configure products and services so that functions enabling identification, location, or profiling of an individual are deactivated unless the individual actively opts in.observed
  2. ProbableOffice of the Privacy Commissioner of Canada — Manipulative design patterns such as oversized opt-in buttons and addictive engagement incentives are flagged by Canadian privacy regulators, including Quebec's CAI, as inconsistent with privacy-by-default and best-interest-of-young-persons principles.observed
  3. ConfirmedIAPP — Where personal information is used for marketing ('prospection') purposes, the organization must communicate the identity of the party using the information and inform individuals of their right to withdraw consent.observed

#

Biometric and profiling/ADM transparency rules are mature (green-level) but AI-specific risk-assessment obligations for the private sector and surveillance carveouts remain unconfirmed.

Primary frameworkAct Respecting the Protection of Personal Information in the Private Sector, CQLR c P-39.1, as amended by Law 25; Act to Establish a Legal Framework for Information Technology (biometrics)
Traffic-light rationale — AmberBiometric and profiling/ADM transparency rules are mature (green-level) but AI-specific risk-assessment obligations for the private sector and surveillance carveouts remain unconfirmed.

Sub-modules (6)

Profiling RestrictionsGreen

Profiling is defined and requires advance notice plus a deactivation mechanism where available.

Claims (1):

  • Profiling is a defined concept under Law 25, requiring organizations to give advance notice of technology that creates a profile of an individual and the means to deactivate that function where available.

Automated Decision Making TransparencyGreen

Notice, principal-reasons disclosure, and contestation/human-review rights apply to solely-automated decisions; no outright Art.-22-style prohibition.

Claims (2):

  • Individuals subject to a decision based exclusively on automated processing of their personal information must be informed of the information used, the principal reasons and factors, and their right to have the decision reviewed, with a right to contest and request human review.
  • Unlike Article 22 GDPR, Law 25 does not prohibit solely automated decision-making outright; it instead imposes a notification and contestation requirement.

Ai Risk AssessmentsAmber

Public-sector AI principles (MCN) exist; private-sector AI-specific risk-assessment mandate beyond general PIA duty is unconfirmed.

Claims (1):

  • Quebec's public-sector AI framework (the 'MCN') sets out ten principles for responsible AI use by public bodies covering compliance, equity, security and transparency.

Biometric RegimeGreen

Express consent, minimisation, and CAI pre-notification apply to biometric identity verification and database creation.

Claims (1):

  • Quebec's Act to Establish a Legal Framework for Information Technology requires express consent to verify identity using biometric measurements, limits collection to minimum necessary characteristics, and restricts decisions based on other information revealed via biometric processing.

Genetic DataAmber

CAI has proactively addressed genetic-data risk in the 23andMe bankruptcy context.

Claims (1):

  • Following 23andMe's bankruptcy, the CAI publicly reminded Quebec residents of their rights over genetic data and urged individuals to manage consent or request deletion of their genetic information.

State Surveillance CarveoutsRed

No specific state-surveillance carveout provisions were located in this research pass.

Absence provenance: unavailable. Searched: Quebec Law 25 national security exemption surveillance carveout.

Key findings (1)

  • CAI prohibited Metro Inc. from putting into service a biometric-characteristics database. — source on file
Category narrative65 words

Law 25 defines profiling and imposes notice/deactivation duties, and requires notice-plus-contestation (not an outright prohibition, unlike GDPR Art. 22) for solely-automated decisions. Biometric processing carries express-consent and pre-notification duties. CAI has actively addressed genetic-data risk (23andMe) and AI use in recruitment; public-sector AI principles (the 'MCN') exist but are adjacent to (not squarely within) the private-sector DP regime. No specific state-surveillance carveout evidence was located.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (6)
  1. ConfirmedIAPP — Profiling is a defined concept under Law 25, requiring organizations to give advance notice of technology that creates a profile of an individual and the means to deactivate that function where available.observed
  2. ConfirmedIAPP — Individuals subject to a decision based exclusively on automated processing of their personal information must be informed of the information used, the principal reasons and factors, and their right to have the decision reviewed, with a right to contest and request human review.observed
  3. ConfirmedOffice of the Privacy Commissioner of Canada — Unlike Article 22 GDPR, Law 25 does not prohibit solely automated decision-making outright; it instead imposes a notification and contestation requirement.observed
  4. ProbableDataGuidance — Quebec's public-sector AI framework (the 'MCN') sets out ten principles for responsible AI use by public bodies covering compliance, equity, security and transparency.observed
  5. ConfirmedOffice of the Privacy Commissioner of Canada — Quebec's Act to Establish a Legal Framework for Information Technology requires express consent to verify identity using biometric measurements, limits collection to minimum necessary characteristics, and restricts decisions based on other information revealed via biometric processing.observed
  6. ProbableDataGuidance — Following 23andMe's bankruptcy, the CAI publicly reminded Quebec residents of their rights over genetic data and urged individuals to manage consent or request deletion of their genetic information.observed

#

Parental consent threshold is well-evidenced (green-level) but age-verification, education-settings, and dependent-adults sub-modules are unconfirmed gaps.

Primary frameworkAct Respecting the Protection of Personal Information in the Private Sector, CQLR c P-39.1, as amended by Law 25
Traffic-light rationale — AmberParental consent threshold is well-evidenced (green-level) but age-verification, education-settings, and dependent-adults sub-modules are unconfirmed gaps.

Sub-modules (5)

Age VerificationRed

No Quebec-specific age-verification mandate was located in this research pass.

Absence provenance: unavailable. Searched: Quebec Law 25 age verification requirement.

Minor Profiling BansAmber

CAI has urged (not yet codified) stricter minors' data rules including a commercial-use prohibition.

Claims (1):

  • The CAI has urged stricter rules to protect minors' personal information, including prohibiting its commercial use and prioritizing children's best interests in data-processing decisions.

Education SettingsRed

No Quebec-specific education-settings data protection rule was located.

Absence provenance: unavailable. Searched: Quebec student data privacy education settings.

Dependent AdultsRed

No Quebec-specific dependent-adults data protection provision was located.

Absence provenance: unavailable. Searched: Quebec dependent adults elderly privacy protection.

Category narrative42 words

Quebec sets a parental-consent threshold at under-14 (differing from the federal PIPEDA/OPC-suggested under-13 benchmark), with a minor's-benefit exception, and CAI has advocated for stricter minors' data rules including a commercial-use prohibition. No Quebec-specific age-verification mandate, education-settings rule, or dependent-adults provision was located.

Sources and claims (2)
  1. ConfirmedIAPP — Personal information concerning a minor under 14 may not be collected without the consent of a parent or legal guardian, unless collection is clearly for the minor's benefit.observed
  2. ProbableDataGuidance — The CAI has urged stricter rules to protect minors' personal information, including prohibiting its commercial use and prioritizing children's best interests in data-processing decisions.observed

#

Active, uniquely well-empowered regulator with recent (within-180-day) enforcement activity and a codified private right of action; funding/capacity and collective-redress specifics remain unconfirmed gaps.

Primary frameworkAct Respecting the Protection of Personal Information in the Private Sector, CQLR c P-39.1, as amended by Law 25
Traffic-light rationale — GreenActive, uniquely well-empowered regulator with recent (within-180-day) enforcement activity and a codified private right of action; funding/capacity and collective-redress specifics remain unconfirmed gaps.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

CAI can impose AMPs up to $25M/4% turnover (orgs) or $50,000 (individuals), plus lesser $10M/2% administrative sanctions, and is the only Canadian regulator with such power.

Claims (2):

  • The CAI may issue notices of noncompliance and impose administrative monetary penalties of up to $25 million or, if greater, 4% of worldwide turnover for the preceding year for organizations (or up to $50,000 for individuals), with lesser administrative sanctions of $10 million or 2% of turnover for other violations.
  • Quebec's CAI is currently the only Canadian privacy regulator empowered to impose administrative monetary penalties, and it can proactively verify organizational compliance.

Enforcement Activity IndexGreen

May 2026 joint OpenAI investigation is CAI's most significant recent enforcement action, finding consent/transparency/default-settings deficiencies.

Claims (2):

  • In a joint investigation with the federal OPC and the BC and Alberta privacy commissioners, the CAI found that OpenAI had not adequately documented how it fulfilled the duty to inform or obtained consent from individuals in connection with ChatGPT training data, and that disclosures for the free web version were insufficient.
  • The CAI found that, under Quebec's Private Sector Act, default privacy settings for OpenAI's models should have provided the most privacy-protective option, i.e., that user chats would not be used for model training by default.

Regulator Funding And CapacityRed

No specific CAI budget/headcount figures were located in this research pass.

Absence provenance: unavailable. Searched: CAI Quebec budget headcount funding 2026.

Collective Redress And Class ActionsRed

No Quebec-specific class-action mechanism data tied to the Private Sector Act was located; general Quebec class-action procedure exists under the Code of Civil Procedure but was not specifically evidenced for privacy claims in this pass.

Absence provenance: unavailable. Searched: Quebec Law 25 class action privacy lawsuit.

Private Right Of ActionGreen

Law 25 creates a statutory private right of action with punitive damages for intentional/gross-fault infringements.

Claims (1):

  • Law 25 creates a private right of action allowing individuals to seek compensation for unlawful infringement of a right conferred by the Private Sector Act or the privacy provisions of the Civil Code of Québec, with punitive damages of at least $1,000 available for intentional or grossly-faulty infringements.

Recent Developments 180DGreen

Within the last 180 days: the May 6, 2026 joint OpenAI/ChatGPT report of findings and the February 23, 2026 multinational joint statement on AI-generated imagery, both involving CAI.

Claims (2):

  • On May 6, 2026, the CAI joined the federal OPC and the BC and Alberta privacy commissioners in releasing a joint report of findings concluding that OpenAI's early ChatGPT models were not compliant with their respective privacy laws, leading OpenAI to implement new safeguards.
  • On February 23, 2026, the CAI joined a multinational joint statement of data protection and privacy authorities addressing AI-generated imagery and its implications for privacy.
Category narrative72 words

CAI holds the only administrative-monetary-penalty (AMP) power among Canadian privacy regulators (up to CAD $25M/4% global turnover for organizations), plus notice-of-noncompliance powers, alongside a statutory private right of action. Recent enforcement activity includes the May 2026 joint OpenAI/ChatGPT investigation finding non-compliance with Quebec's consent/transparency duties, and CAI's February 2026 participation in a multinational joint statement on AI-generated imagery. No Quebec-specific class-action mechanism data or regulator funding/headcount figures were located in this pass.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (7)
  1. ConfirmedIAPP — The CAI may issue notices of noncompliance and impose administrative monetary penalties of up to $25 million or, if greater, 4% of worldwide turnover for the preceding year for organizations (or up to $50,000 for individuals), with lesser administrative sanctions of $10 million or 2% of turnover for other violations.observed
  2. ConfirmedOffice of the Privacy Commissioner of Canada — Quebec's CAI is currently the only Canadian privacy regulator empowered to impose administrative monetary penalties, and it can proactively verify organizational compliance.observed
  3. ConfirmedOffice of the Privacy Commissioner of Canada — In a joint investigation with the federal OPC and the BC and Alberta privacy commissioners, the CAI found that OpenAI had not adequately documented how it fulfilled the duty to inform or obtained consent from individuals in connection with ChatGPT training data, and that disclosures for the free web version were insufficient.observed
  4. ConfirmedOffice of the Privacy Commissioner of Canada — The CAI found that, under Quebec's Private Sector Act, default privacy settings for OpenAI's models should have provided the most privacy-protective option, i.e., that user chats would not be used for model training by default.observed
  5. ConfirmedOffice of the Privacy Commissioner of Canada — Law 25 creates a private right of action allowing individuals to seek compensation for unlawful infringement of a right conferred by the Private Sector Act or the privacy provisions of the Civil Code of Québec, with punitive damages of at least $1,000 available for intentional or grossly-faulty infringements.observed
  6. ConfirmedOffice of the Privacy Commissioner of Canada — On May 6, 2026, the CAI joined the federal OPC and the BC and Alberta privacy commissioners in releasing a joint report of findings concluding that OpenAI's early ChatGPT models were not compliant with their respective privacy laws, leading OpenAI to implement new safeguards.observed
  7. ProbableOffice of the Privacy Commissioner of Canada (hosting joint statement) — On February 23, 2026, the CAI joined a multinational joint statement of data protection and privacy authorities addressing AI-generated imagery and its implications for privacy.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metn/a — no subject in this jurisdiction
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct61.11
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Quebec, Canada
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 50 claim(s) (50 category placement(s)), 23 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsdeadlines and response windows
Art. 14Data Subject Rightsdeadlines and response windows
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer mechanisms
Art. 49Cross-Border & Adequacytransfer impact assessment
Art. 77Enforcement & Redressregulator powers and penalties
Art. 78Enforcement & Redressregulator powers and penalties
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 81Enforcement & Redressregulator powers and penalties
Art. 82Enforcement & Redressprivate right of action
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

Regulator/framework, lawful-processing, data-subject-rights, controller/processor duties (excl. ROPA/joint-controller), cross-border TIA, adtech privacy-by-default/marketing, algorithmic/biometric governance, children's parental-consent, and enforcement/redress modules are supported by a mix of T2 (OPC/CAI joint regulator materials) and T3 (IAPP, DataGuidance) secondary sources, with core statutory anchors (S1-S3) as T1 grounding. No direct T1 full-text pull of Private Sector Act sections was performed in this pass (relied on T2/T3 summaries of specific section numbers); this should be verified against LegisQuébec primary text before final publication. Sectoral_watch (financial, telecoms, credit, education, insurance), several cross_border sub-modules (adequacy_received/granted, data_localisation), several adtech sub-modules (opt_out_signals, clean_rooms_and_dcr, cross_context_advertising), children's age_verification/education_settings/dependent_adults, and enforcement's regulator_funding_and_capacity/collective_redress carry explicit absent_field_provenance rather than fabricated findings.

Unresolved questions (6):

  • Does the Private Sector Act contain any GDPR-Article-30-style records-of-processing (ROPA) obligation, or is the confidentiality-incident register the sole analogue?
  • Is there a Quebec-specific 'joint controller' concept, or does Quebec rely solely on contractual allocation of responsibility between parties?
  • Does Quebec recognize or plan to recognize browser-based opt-out signals (e.g., Global Privacy Control) for adtech purposes?
  • Are there AMF (Autorité des marchés financiers) or other financial-sector-specific privacy overlays applicable to Quebec entities beyond the general Private Sector Act?
  • What are current CAI budget/headcount figures for capacity assessment purposes?
  • Has the CAI initiated any Quebec-specific class-action privacy litigation or certified any collective redress case under the amended Private Sector Act?

Escalate to primary-source review: yes