What Law 25 changes for AI systems
Quebec's Act to modernize legislative provisions as regards the protection of personal information — universally referred to as Law 25 — came into force in phases between 2022 and 2023. It amends the Act respecting the protection of personal information in the private sector (LPRPSP) and imposes new obligations that directly affect organizations operating AI systems.
Law 25 is not an AI law. But its requirements on transparency, risk assessment, and automated decision-making create real operational obligations for any system that processes personal information in the course of its functions — which covers the large majority of AI systems deployed in Quebec.
If an AI system processes personal information to make or prepare a decision about a person, Law 25 applies. This is not a question of sector or organization size — it is a question of processing.
Law 25 obligations that apply to AI: an overview
Law 25 introduces several obligations with direct impact on AI systems. They fall into four operational blocks.
| Obligation | Trigger | Status |
|---|---|---|
| Automated decision transparency | Decision made exclusively by automated means affecting a person | Required |
| Right to human review | Automated decision affecting access, employment, or substantive rights | Required |
| Privacy Impact Assessment (PIA) | New system or substantial modification processing personal information | Required |
| Current privacy policy publication | Processing of personal information — no exception | Required |
| Explicit consent and stated purposes | Collection or secondary use of personal information | Required |
| Privacy officer designation | All organizations within scope | Required |
| Cross-border transfer assessment | Data processed outside Quebec (e.g., foreign cloud provider) | Conditional |
Automated decision systems: what Law 25 requires exactly
Section 12.1 of the amended act is the provision that creates the most operational obligations for AI teams. It applies when a decision is made exclusively by automated means using personal information and affects the exercise of a person's right.
Obligation 1 — Inform the person
The organization must inform the person concerned that the decision is made by automated means. This information must be provided before or at the time the decision is communicated. It cannot be buried in terms of service or in a twenty-page privacy policy.
In practice: if an AI system generates a credit decision, a hiring decision, a service access decision, or a risk score that determines an outcome, the person must know that an algorithm — not a human — decided.
Obligation 2 — Disclose the personal information used
The organization must also be able to inform the person of the personal information used to make the decision and the principal factors that influenced it. This is not a requirement for full algorithmic explainability, but it goes beyond a simple acknowledgment.
Many organizations use commercial models provided by third parties without being able to identify the principal decision factors. Law 25 does not accept "the vendor won't tell us" as a sufficient answer. Accountability stays with the organization that makes the decision.
Obligation 3 — Allow human review
The person has the right to request that a decision be reviewed by a human being. This right must be real and operational: it is not sufficient to state that a review is possible if the process does not exist, or if a human does nothing more than mechanically validate the system's output.
The concrete governance question is: who is accountable for this review, at what point, with what authority to change the decision, and what documentary record is produced?
Privacy Impact Assessments (PIA) for AI systems
The PIA is the obligation that generates the most operational work for teams deploying new AI systems. It is required before a system goes live when it collects, uses, or communicates personal information for new or substantially modified purposes.
For AI systems, this means concretely:
- Documenting which personal information is used as training or inference data.
- Assessing risks related to the collection, storage, transmission, and secondary use of that data.
- Identifying protective measures in place and gaps that remain.
- Retaining the PIA and updating it when the system is substantially modified.
A PIA is not a generic compliance document filled out once. It is a risk assessment specific to the system, the processing, and the use context. A copy-pasted template with no real analysis of the actual system does not satisfy the obligation.
Law 25 and the EU AI Act: convergence for Canadian organizations
Canadian organizations doing business with European companies or using systems developed in Europe face dual regulatory pressure: Law 25 on one side, the EU AI Act on the other.
Both regimes share several central concerns:
- Automated decision transparency: the EU AI Act imposes explainability requirements for high-risk systems; Law 25 requires disclosure of decision factors.
- Human oversight: the EU AI Act requires effective human oversight for high-risk systems; Law 25 requires the right to human review.
- Documentation and traceability: both regimes require documentation of systems, data used, and decisions made.
The primary difference is scope: the EU AI Act classifies systems by risk level and imposes proportionate obligations. Law 25 applies whenever personal information is processed, without risk classification — but with less extensive requirements on system design and testing.
For Canadian organizations, the convergence creates an opportunity: controls built to satisfy the EU AI Act (data documentation, decision registers, human oversight) are generally sufficient to cover Law 25 requirements on the same systems. Build once, cover both.
What organizations miss most often
In practice, four gaps recur in AI governance reviews conducted under Law 25.
Gap 1 — The "automated decision" threshold is undefined
Many organizations do not know precisely which systems trigger the obligations of section 12.1. Is a recommendation engine that ranks job applications an automated decision? A credit risk scoring tool used by an advisor who makes the final call? The line is not always clear, and failing to define it creates undocumented exposure.
Gap 2 — Human review is not operational
The obligation to offer human review exists on paper but not in process. No one has named accountability, timelines are undefined, and no documentary record is produced. In a regulatory review or audit, this gap is the hardest to defend.
Gap 3 — The PIA is generic or absent
The assessment was done once, for the original system, without being updated when modifications occurred. Or it was completed with a generic template with no specific analysis of the system's actual data flows.
Gap 4 — The privacy officer has no real authority
Law 25 requires a designated privacy officer. In many organizations, the role is named but has no mandate, no resources, and no decisions to make. Nominal accountability without real authority does not satisfy the spirit of the obligation.
A deterministic governance approach to Law 25
Compliance with Law 25 is not built with general statements about commitment to privacy protection. It is built by naming precise thresholds, explicit decision rights, and reconstructible evidence paths.
For each AI system within Law 25's scope, this means documenting:
- Which personal information is used, for what purpose, and on what legal basis.
- Whether the system makes automated decisions within the meaning of section 12.1, and which ones.
- How human review is exercised: who, when, with what authority, and what record is produced.
- Where the PIA is and when it was last reviewed.
- Who the privacy officer is, with what mandate, and how review requests reach them.
This work is not symbolic compliance. It is the construction of a record that any external reviewer — the Commission d'accès à l'information, an institutional buyer, a partner conducting due diligence — can follow and reconstruct.
An AI governance system that cannot be reconstructed by an outside observer is not a governance system — it is a statement of intent. Law 25 rewards the first and exposes the second.
Is your organization ready for a Law 25 review on its AI systems?
PHAROS structures AI governance reviews that translate Law 25 obligations into verifiable operational controls — explicit thresholds, named decision rights, and reconstructible documentation for the CAI, your buyers, or your auditors.