Skip to content
← All guides

Guide · Privacy & AI

AI tools and client data: what Québec's Law 25 means for solo businesses

Québec's private-sector privacy law applies to a business of one. What that means when your CRM, analytics and AI tools live outside Québec — privacy officer, policy, impact assessments, incident register and penalties, backed by the statute and the CAI.

Verified against official sources · Last updated: July 2026

Yes, it applies to a business of one

Québec's Law 25 (the Act respecting the protection of personal information in the private sector) applies to any organization that collects, holds, uses or communicates personal information in the course of carrying on business in Québec — even if the organization is located outside Québec. The CAI confirms this covers SMEs, self-employed workers and non-profits carrying on an enterprise (CAI; P-39.1). A client list, an inbox full of client emails, session notes about a coaching client — that is personal information.

You are your own privacy officer

Every enterprise must have a person in charge of the protection of personal information. By default it's the person with the highest authority — in a solo business, you — who may delegate the function in writing, in whole or in part, to anyone. The title and contact information of the privacy officer must be published on the enterprise's website, or made accessible by other appropriate means if there is no website (P-39.1, s. 3.1; CAI). Note the detail: the statute requires the officer's title and contact information — not their name.

Your website, your privacy policy, your cookies

If you collect personal information by technological means (a contact form, a booking tool, analytics), you must publish a privacy policy written in clear and simple language on your website. Any technology with functions allowing identification, geolocation or profiling requires informing the person first, with those functions deactivated by default (opt-in activation). Per CAI guidance, non-essential cookies — analytics, advertising — require prior consent, requested separately for each purpose; strictly necessary cookies (session, cart, language) don't (P-39.1, ss. 8.1, 8.2, 9.1, 14; CAI).

The AI clause nobody reads: data leaving Québec

This is where AI tools meet the statute. A privacy impact assessment (PIA — EFVP in French) is mandatory (1) before communicating personal information outside Québec — the communication may proceed only if the assessment shows the information would receive adequate protection — and (2) for any project to acquire, develop or overhaul an information system or electronic service delivery system involving personal information (P-39.1, ss. 3.3 and 17).

In practice, this catches common solo-business tooling hosted outside Québec — US-hosted CRMs, analytics, cloud storage, and AI assistants that process client data on servers outside the province. The assessment must weigh the sensitivity of the information, the purposes, the protection measures (including contractual ones) and the legal regime of the destination. It must be proportionate — for a solo business, a short documented assessment beats no assessment at all.

The habit that follows: before adopting any tool that touches client data — AI or not — ask where the data is stored and processed. If the answer is "outside Québec" (it usually is), a documented impact assessment is a legal prerequisite, not a nice-to-have.

When something leaks: the incident register

Every enterprise must keep a register of all confidentiality incidents — even those without risk of serious injury. If an incident presents a risk of serious injury, you must promptly notify the CAI and the affected individuals, and take reasonable measures to reduce harm and prevent recurrence. Register entries must be kept at least 5 years (P-39.1, ss. 3.5–3.8; CAI).

Defaults, retention, portability

If you offer a technological product or service to the public, its privacy settings must provide the highest level of confidentiality by default (login/session cookies excluded). Governance policies must frame retention and destruction of personal information, which must be destroyed or anonymized once its purposes are fulfilled. Since September 22, 2024, individuals also have a right to data portability — their computerized personal information in a structured, commonly used technological format — and can demand cessation of dissemination or de-indexation of hyperlinks in defined circumstances (P-39.1, ss. 9.1, 3.2, 23, 27, 28.1; CAI).

What non-compliance costs

Law 25 has real teeth: administrative monetary penalties (imposed by the CAI) up to $50,000 for natural persons and, for enterprises, up to $10,000,000 or 2% of worldwide turnover for the preceding fiscal year, whichever is greater; penal fines of $5,000–$100,000 for natural persons and, for enterprises, $15,000–$25,000,000 or 4% of worldwide turnover, whichever is greater; plus a private right of action for unlawful infringement causing injury, with punitive damages of at least $1,000 when the infringement is intentional or results from gross fault (P-39.1, ss. 90.12, 91, 93.1). Fines are doubled on recidivism.

Practical habits for a solo business using AI

These are working habits, not legal requirements — the obligations above are the law; this is how a one-person shop can live with them:

  • Inventory your tools. List every tool that touches client data (CRM, email, notes, AI assistants) and where each stores it.
  • Minimize what you feed AI tools. Strip names and identifying details from prompts unless you have assessed the tool's data handling.
  • Write the short version first. A one-page privacy policy in plain language, your title and contact info as privacy officer, a simple incident log — done is better than perfect.
  • Prefer tools that answer the question. If a vendor can't tell you where data lives and how it's protected, that's your answer.

Quick answers

I'm a one-person business. Does Law 25 really apply to me?

Yes. The Act applies to any organization that collects, holds, uses or communicates personal information in the course of carrying on business in Québec — the CAI confirms this covers SMEs, self-employed workers and NPOs carrying on an enterprise. There is no small-business exemption.

Can I paste client emails into an AI chatbot?

Treat that as a data transfer, not a shortcut. If the tool stores or processes personal information outside Québec, a privacy impact assessment (PIA/EFVP) is required before the communication, and it may proceed only if the assessment shows the information would receive adequate protection (P-39.1, s. 17). The safest habit for a solo business: strip identifying details before using any AI tool that processes data outside Québec, or use tools whose data handling you have actually assessed.

What happens if client data leaks from a tool I use?

You must record the incident in your confidentiality-incident register (mandatory even for incidents without risk of serious injury; entries kept at least 5 years). If it presents a risk of serious injury, you must promptly notify the CAI and the affected individuals, and take reasonable measures to reduce harm and prevent recurrence (P-39.1, ss. 3.5–3.8).

Sources

Every claim in this guide traces to one of these official sources. Check the source before acting — rules and deadlines change.

Where to go from here

Check-Up Conformité — Quebec Compliance Snapshot

The deep, personalized version of this guide: answer 16 questions (about 3 minutes) and get a prioritized action list for YOUR business — readiness scores, red/amber/green status per obligation, a deadline calendar, in French and English, with official sources cited.

Get your personalized report — $39

Free business read by U

U is the AI operator for one-person businesses. Answer a short interview and it prepares a personalized read — your bottleneck, your scores, your next three moves. No card required.

Get your free business read