Skip to content

Quebec Law 25: The Automated Decision Rights, Section by Section

9 min read · updated August 11, 2026

Quebec is the only Canadian jurisdiction with a statutory right to an explanation of an automated decision. The provision is short, it is in force, and it is drafted differently enough from GDPR Article 22 that copying a European implementation will leave you non-compliant in both directions.

What Law 25 amended, and when

“Law 25” is shorthand for the Act to modernize legislative provisions as regards the protection of personal information, S.Q. 2021, c. 25, assented to on 22 September 2021. It is an amending statute: the operative provisions for private-sector organisations live in the Act respecting the protection of personal information in the private sector, CQLR c. P-39.1, which is where you should be reading and citing from. The text is on LégisQuébec, which publishes an official English version.

The amendments came into force in three tranches, on 22 September in 2022, 2023 and 2024. The AI-relevant provisions — sections 8.1 and 12.1, along with the impact assessment and transfer requirements — took effect on 22 September 2023. Data portability under section 27 followed on 22 September 2024. The Act applies to any person carrying on an enterprise in Quebec, which turns on activity in the province rather than on incorporation there.

This describes statutory provisions in general terms and is not legal advice. The English text on LégisQuébec is a translation of a statute enacted in French, and where the two differ the French version governs. If a decision pipeline is close to the line, take Quebec advice.

Section 12.1: exclusively automated decisions

The provision applies where an enterprise uses personal information to render a decision based exclusively on an automated processing of that information. Two obligations follow.

  1. Inform at the time of the decision. The enterprise must inform the person concerned that the decision was based exclusively on automated processing, no later than when it informs them of the decision itself. This is unconditional and does not require a request.
  2. Explain on request. At the person’s request, the enterprise must inform them of the personal information used to render the decision, of the reasons and the principal factors and parameters that led to it, and of their right to have the personal information used to render the decision corrected. It must also give the person the opportunity to submit observations to a member of the enterprise’s personnel who is in a position to review the decision.

Three details in that drafting matter more than they look. The “principal factors and parameters” formulation asks for something specific to the individual decision, not for a general description of the system: naming the features that drove this outcome is what is being asked, and a model card does not do it. The correction right is bolted directly onto the explanation, which means the explanation has to be granular enough for the person to identify what to correct — an explanation that cannot be acted on has not satisfied the section. And the review is by a person “in a position to review the decision”, which is an authority requirement: routing observations to a support queue that cannot change the outcome does not discharge it.

Note also what “exclusively” does. Insert a human who genuinely exercises judgement and section 12.1 does not apply — but the same human has to be doing real work, and a reviewer who approves every recommendation is evidence that the decision was exclusively automated in substance. This is the same analytical problem as the “solely” test in the GDPR, and the answers travel between the two.

Section 8.1: profiling, locating and identifying

Section 8.1 is the provision most often missed. Where an enterprise collects personal information from the person concerned using technology that includes functions allowing the person to be identified, located or profiled, it must inform them of the use of such technology and of the means available to deactivate those functions. The Act defines profiling as the collection and use of personal information to assess certain characteristics of a natural person, in particular for the purpose of analysing that person’s work performance, economic situation, health, personal preferences, interests or behaviour.

The deactivation limb is the demanding one and it has no GDPR analogue in this form. It is not a right to object that the enterprise weighs; it is a requirement that the means to switch the function off exist and are disclosed. A recommendation system, a behavioural scoring feature or an in-product analytics function that builds a preference profile needs an off switch and a notice pointing to it. Section 9.1 reinforces the direction by requiring that privacy settings for a technological product or service ensure the highest level of confidentiality by default, other than for cookies.

Impact assessments and transfers

Section 3.3 requires a privacy impact assessment for any project to acquire, develop or overhaul an information system or electronic service delivery involving personal information, and the assessment must be proportionate to the sensitivity, purposes, quantity, distribution and medium of the information. Deploying a model that processes personal information is such a project.

Section 17 requires a separate assessment before communicating personal information outside Quebec, considering the sensitivity of the information, the purposes, the protection measures including contractual ones, and the legal framework applicable in the receiving jurisdiction. The communication may proceed only if the assessment establishes that the information would receive adequate protection, in light of generally recognised principles, and the transfer must be the subject of a written agreement. For a Quebec enterprise calling a model hosted in the United States or Europe, that is a per-destination analysis with a written artefact at the end — and it is the requirement most likely to be outstanding when a regulator asks.

How it differs from Article 22

The structures are genuinely different and the difference runs in both directions.

  • No prohibition. GDPR Article 22(1) states a prohibition subject to exceptions. Quebec has no prohibition at all: you may make exclusively automated decisions, provided you tell the person and explain on request. Quebec is more permissive here.
  • No significance threshold. Article 22 applies only to decisions producing legal effects or similarly significantly affecting the person. Section 12.1 has no such qualifier — it applies to any decision rendered exclusively by automated processing of personal information. Quebec is broader here, and by some margin.
  • A more specific explanation. The GDPR’s explanation duties are assembled from Articles 13(2)(f), 14(2)(g), 15(1)(h) and Recital 71, and refer to meaningful information about the logic involved. Quebec asks for the reasons and the principal factors and parameters that led to the decision, which reads as more individualised.
  • Enforcement differs. The Commission d’accès à l’information may impose administrative monetary penalties, and penal proceedings carry higher maxima, both expressed as the greater of a fixed amount and a percentage of worldwide turnover. Law 25 also created a private right of action with punitive damages available for intentional or grossly negligent infringement, which is unusual in Canadian privacy law and is the part that changes an organisation’s risk calculation.

The practical consequence for a business operating across Canada is that Quebec sets the design floor. Since PIPEDA gives no explanation right at all, a single pipeline built to section 12.1 satisfies both, whereas a PIPEDA-shaped pipeline fails in Quebec. Build the notice, the factor record and the human review path once.