🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
CA-QC · run data-protection-2026-08-05 v13-gdpri-1.0.0
content: ai_generated 18 sources retrieved model claude-sonnet-5 ·

Canada – Quebec

CA-QC schema gdpri-v2 trajectory: not recorded

Last updated · 10 categories · 50 claims · 18 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
50Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)
No categories are currently flagged red.

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Comprehensive, fully-in-force omnibus private-sector statute with an active, well-resourced supervisory authority; only minor gaps in extraterritorial-scope statutory clarity.

Primary frameworkAct Respecting the Protection of Personal Information in the Private Sector, CQLR c P-39.1, as amended by Law 25 (SQ 2021, c. 25)
Traffic-light rationale — GreenComprehensive, fully-in-force omnibus private-sector statute with an active, well-resourced supervisory authority; only minor gaps in extraterritorial-scope statutory clarity.

Sub-modules (5)

Regulator And AuthorityGreen

CAI is the sole provincial DPA overseeing the Private Sector Act, with inquiry, order-making and sanctioning powers.

Claims: CLM-CA-QC-a1000001

Act And InstrumentsGreen

Core instrument is the Private Sector Act as amended by Law 25; biometrics and health-sector data carry dedicated overlay instruments.

Claims: CLM-CA-QC-a1000002, CLM-CA-QC-a1000003, CLM-CA-QC-a1000004, CLM-CA-QC-a1000005

Material ScopeGreen

Applies to collection, retention, use, access and transfer of personal information by private enterprises carrying on business in Quebec.

Claims: CLM-CA-QC-a1000006

Territorial ScopeAmber

Statutory extraterritorial reach is not as explicit as GDPR Art. 3, but CAI guidance signals expected application to foreign entities serving Quebec residents.

Claims: CLM-CA-QC-a1000007

Regulator Registration And FilingAmber

No general registration regime, but biometric-database creation must be pre-disclosed to CAI 60 days before deployment.

Claims: CLM-CA-QC-a1000008

Category narrative88 words

Quebec operates a comprehensive, GDPR-influenced private-sector data protection regime under the Act Respecting the Protection of Personal Information in the Private Sector (CQLR c P-39.1), as substantially amended by Law 25 (formerly Bill 64, SQ 2021 c.25), enforced by the Commission d'accès à l'information du Québec (CAI). A parallel Public Sector Act governs government bodies (out of scope here), and sector-specific instruments (biometrics IT Act, LRSSS) overlay the general regime. Law 25 entered into force in three phases from Sept. 2022 through full effect on Sept. 22, 2024.

Sources and claims (8)
  1. ConfirmedDataGuidanceThe Commission d'accès à l'information du Québec (CAI) is Quebec's provincial data protection authority responsible for overseeing compliance with the Act Respecting the Protection of Personal Information in the Private Sector.
  2. ConfirmedDataGuidanceQuebec's data-protection regime is anchored in the Act Respecting the Protection of Personal Information in the Private Sector, CQLR c P-39.1, as substantially amended by An Act to modernize legislative provisions as regards the protection of personal information (SQ 2021, c. 25 / Law 25, formerly Bill 64).
  3. ConfirmedOffice of the Privacy Commissioner of CanadaLaw 25 entered into force in three phases beginning September 22, 2022, with the final phase (data portability) taking effect September 22, 2024, at which point the Act is fully in force.
  4. ConfirmedOffice of the Privacy Commissioner of CanadaBiometric-specific obligations are separately set out in Quebec's Act to Establish a Legal Framework for Information Technology, which Law 25 amended to require 60 days' advance notice to the CAI before a biometric database is brought into service.
  5. ConfirmedDataGuidanceQuebec's Act Respecting Health and Social Services Information (LRSSS) entered into effect July 1, 2024, establishing a health-sector-specific personal information protection regime.
  6. ConfirmedDataGuidanceThe Private Sector Act governs the collection, retention, use, access to, and transfer of personal information by private enterprises carrying on business in Quebec.
  7. ProbableDataGuidanceCAI guidance indicates both Canadian and foreign companies offering goods or services in Quebec are expected to comply with its consent framework, signalling an extraterritorial-facing application of the Private Sector Act to organizations serving Quebec residents.
  8. ConfirmedOffice of the Privacy Commissioner of CanadaOrganizations must disclose to the CAI, at least 60 days in advance, the creation of any database containing biometric characteristics or measurements before it is brought into service.

#

Consent and sensitive-data rules are mature and CAI has published detailed guidance; lawful-basis enumeration is less granular than GDPR.

Primary frameworkAct Respecting the Protection of Personal Information in the Private Sector, CQLR c P-39.1, as amended by Law 25
Traffic-light rationale — GreenConsent and sensitive-data rules are mature and CAI has published detailed guidance; lawful-basis enumeration is less granular than GDPR.

Sub-modules (4)

Lawful BasesAmber

Purpose determination and necessity are statutory preconditions to collection; consent is the primary basis, with limited non-consent grounds (e.g., contract performance).

Claims: CLM-CA-QC-b1000001

Special CategoriesGreen

Sensitive information (medical, biometric, intimate, or contextually high-expectation data) triggers express-consent and heightened-safeguard duties.

Claims: CLM-CA-QC-b1000003, CLM-CA-QC-b1000004

Pseudonymisation And AnonymisationGreen

Law 25 distinguishes de-identified from anonymised information and conditions anonymisation on legitimacy and best-practice standards.

Claims: CLM-CA-QC-b1000005, CLM-CA-QC-b1000006

Category narrative38 words

Quebec requires purpose-limited collection, clear/free/informed consent (express for sensitive data), and defines de-identification/anonymisation with a legitimacy-and-best-practices standard. There is no enumerated Art.-6-style list of lawful bases; consent is the dominant basis, with narrow statutory exceptions (e.g., contract performance).

Sources and claims (6)
  1. ConfirmedIAPPOrganizations must determine the purposes for collecting personal information and may collect only the information necessary for those purposes.
  2. ConfirmedIAPPConsent requests must be presented separately from other information requests and must be clear, free and informed, with express consent required for sensitive personal information.
  3. ConfirmedIAPPSensitive personal information under Quebec law includes medical, biometric, or otherwise intimate information, and information may also become sensitive where the context of its use or communication entails a high reasonable expectation of privacy.
  4. ConfirmedIAPPOrganizations must obtain express consent before using sensitive personal information for secondary purposes.
  5. ConfirmedOffice of the Privacy Commissioner of CanadaUnder Law 25, personal information is 'de-identified' if it no longer allows direct identification of the person concerned, whereas information is 'anonymized' only if it irreversibly no longer allows the person to be identified directly or indirectly.
  6. ProbableIAPPAnonymization of personal information must be performed for serious and legitimate reasons and according to generally accepted best practices.

#

Full suite of rights now in force including portability as of the final 2024 phase; deadlines are codified.

Primary frameworkAct Respecting the Protection of Personal Information in the Private Sector, CQLR c P-39.1, as amended by Law 25
Traffic-light rationale — GreenFull suite of rights now in force including portability as of the final 2024 phase; deadlines are codified.

Sub-modules (5)

Access RightGreen

Organizations must confirm existence of, communicate, and provide copies of personal information on request.

Claims: CLM-CA-QC-c1000001

Rectification And ErasureGreen

Access/rectification rights plus a de-indexing 'right to be forgotten' subject to a reputational-harm balancing test.

Claims: CLM-CA-QC-c1000002, CLM-CA-QC-c1000003

Restriction And ObjectionGreen

Individuals may contest automated decisions and request human review.

Claims: CLM-CA-QC-c1000004

Data PortabilityGreen

Portability right became effective in the final Law 25 implementation phase.

Claims: CLM-CA-QC-c1000005

Deadlines And Response WindowsGreen

Statutory 30-day response window applies to individual rights requests.

Claims: CLM-CA-QC-c1000006

Category narrative35 words

Quebec grants GDPR-adjacent rights of access, rectification, a bespoke 'right to be forgotten' via de-indexing, contestation of automated decisions, and (as of Sept. 2024) data portability, with a 30-day statutory response window for access/rectification requests.

Sources and claims (6)
  1. ConfirmedIAPPOrganizations must, on request, confirm the existence of personal information, communicate it, and provide a copy to the individual concerned.
  2. ConfirmedDataGuidanceThe Private Sector Act provides individuals a right to access and rectification of their personal information.
  3. ConfirmedOffice of the Privacy Commissioner of CanadaSection 28.1 creates a right to de-indexing ('right to be forgotten') requiring cessation of dissemination or de-indexing of a hyperlink where dissemination causes serious injury to reputation or privacy that outweighs the public interest in the information or freedom of expression.
  4. ConfirmedOffice of the Privacy Commissioner of CanadaIndividuals have a right to contest an automated decision and request human review, analogous to Article 22(3) GDPR.
  5. ConfirmedOffice of the Privacy Commissioner of CanadaThe right to data portability was the final phase of Law 25 to take effect, entering into force on September 22, 2024.
  6. ConfirmedIAPPAn individual's request to exercise access or rectification rights must be responded to within 30 days.

#

Strong DPIA/breach/security/retention coverage (green-level), but ROPA and joint-controller concepts are not codified in equivalent GDPR form, warranting an amber overall rating.

Primary frameworkAct Respecting the Protection of Personal Information in the Private Sector, CQLR c P-39.1, as amended by Law 25
Traffic-light rationale — AmberStrong DPIA/breach/security/retention coverage (green-level), but ROPA and joint-controller concepts are not codified in equivalent GDPR form, warranting an amber overall rating.

Sub-modules (7)

Accountability And DpiaGreen

Mandatory PIAs before adopting processing technology or transferring data outside Quebec; published privacy program required.

Claims: CLM-CA-QC-d1000001, CLM-CA-QC-d1000002

Dpo RequirementsGreen

Default CEO accountability, delegable in writing, with published contact details for the person in charge.

Claims: CLM-CA-QC-d1000003

Ropa RequirementsRed

No dedicated Article-30-style records-of-processing obligation was identified in this research pass; the nearest analogue is the mandatory confidentiality-incident register (see breach_notification).

Joint Controller ArrangementsRed

No GDPR-style joint-controller regime was located in the Private Sector Act or Law 25 text reviewed.

Security MeasuresGreen

Security obligation is proportionate/contextual (sensitivity, purpose, quantity, medium).

Claims: CLM-CA-QC-d1000004

Breach NotificationGreen

Mandatory dual notification (CAI + individuals) on 'risk of serious injury', plus an incident register and remediation review.

Claims: CLM-CA-QC-d1000005, CLM-CA-QC-d1000006

Retention And DisposalGreen

Destruction obligation on purpose-expiry, satisfiable via anonymisation.

Claims: CLM-CA-QC-d1000007

Category narrative43 words

Law 25 imposes accountability via mandatory PIAs, a designated (default CEO) accountable person, breach-notification and incident-register duties, and destruction/anonymisation on retention expiry. No explicit GDPR-Art.-30-style ROPA or 'joint controller' concept was located; the closest analogues are the confidentiality-incident register and general accountability program.

Sources and claims (7)
  1. ConfirmedIAPPOrganizations must conduct a privacy impact assessment before adopting technology that processes personal information and before transferring personal information outside Quebec.
  2. ConfirmedIAPPOrganizations must adopt and publish privacy governance policies and practices according to prescribed requirements, approved by the person in charge of protecting personal information.
  3. ConfirmedIAPPBy default, the highest authority (e.g., CEO) of an organization is responsible for compliance with the Private Sector Act, but this responsibility may be delegated in writing to any person, whose name, title and contact information must be published.
  4. ConfirmedDataGuidanceEnterprises must take security measures necessary to protect personal information that are reasonable given the sensitivity of the information, its purposes, quantity, and the medium on which it is stored.
  5. ConfirmedIAPPOrganizations must notify the CAI and affected individuals of any confidentiality incident presenting a 'risk of serious injury,' assessed under real-risk-of-significant-harm factors.
  6. ConfirmedIAPPOrganizations must maintain a register of confidentiality incidents and conduct a lessons-learned/remediation review to help prevent recurrence.
  7. ConfirmedIAPPOrganizations must destroy personal information once it is no longer required for the purposes for which it was collected, a duty that may be satisfied through anonymization.

#

Robust TIA obligation is in force, but the absence of published adequacy lists and localisation clarity leaves cross-border compliance more case-specific than in EU-style regimes.

Primary frameworkAct Respecting the Protection of Personal Information in the Private Sector, CQLR c P-39.1, as amended by Law 25 (Section 17)
Traffic-light rationale — AmberRobust TIA obligation is in force, but the absence of published adequacy lists and localisation clarity leaves cross-border compliance more case-specific than in EU-style regimes.

Sub-modules (6)

Transfer MechanismsAmber

Section 17 requires an outbound transfer assessment rather than reliance on a fixed adequacy list.

Claims: CLM-CA-QC-e1000001

Adequacy ReceivedRed

No published inbound adequacy determinations affecting Quebec were located in this research pass.

Adequacy GrantedRed

Quebec does not appear to operate a published outbound adequacy-list mechanism; equivalence is assessed case-by-case under Section 17.

Sccs And BcrsAmber

Contractual equivalence obligations function similarly to SCCs but are not a named, standardized instrument.

Claims: CLM-CA-QC-e1000002

Transfer Impact AssessmentGreen

TIA must weigh sensitivity, purpose, destination protection, and downstream third-party obligations.

Claims: CLM-CA-QC-e1000003

Data LocalisationRed

No absolute or general data-localisation mandate was identified for Quebec's private-sector regime in this pass.

Category narrative38 words

Quebec uses a case-by-case Transfer Impact Assessment model (Section 17) rather than a published adequacy-list mechanism. No formal adequacy decisions received-from or granted-to other regimes were located, and no absolute data-localisation mandate was identified in the private-sector regime.

Sources and claims (3)
  1. ConfirmedIAPPSection 17 requires organizations to conduct a transfer/privacy impact assessment before transferring personal information outside Quebec, assessing sensitivity, purpose, and the adequacy of protection at the destination, including equivalent obligations on subsequent third-party recipients.
  2. ProbableIAPPOrganizations relying on contractual safeguards to meet Section 17's outside-Quebec transfer requirement must bind subsequent third-party recipients to equivalent data-protection obligations, functioning similarly to standard contractual clauses.
  3. ConfirmedIAPPA Quebec transfer impact assessment must consider the sensitivity of the information, the purpose of the transfer, and whether the information will receive adequate protection once transferred, including from third parties who may subsequently access it.

#

Health overlay is well-evidenced (green-level); most other sectors carry no confirmed Quebec-specific overlay, driving an overall amber/gap rating.

Primary frameworkAct Respecting Health and Social Services Information (LRSSS); Private Sector Act generally for other sectors
Traffic-light rationale — AmberHealth overlay is well-evidenced (green-level); most other sectors carry no confirmed Quebec-specific overlay, driving an overall amber/gap rating.

Sub-modules (7)

Financial Sector OverlayRed

No Quebec-specific financial-sector privacy overlay (beyond the general Private Sector Act) was located.

Absence provenance: not recorded. Searched: Quebec financial sector data protection AMF overlay, Quebec Law 25 financial institutions.

Health Sector OverlayGreen

LRSSS establishes a dedicated health/social-services information regime, in effect since July 1, 2024.

Claims: CLM-CA-QC-f1000001

Telecoms And EprivacyRed

No Quebec-specific telecoms/ePrivacy instrument distinct from the general Private Sector Act was located.

Absence provenance: not recorded. Searched: Quebec telecoms ePrivacy cookies law.

Employment DataAmber

CAI has issued guidance on personal-data handling in recruitment, including responsible AI use.

Claims: CLM-CA-QC-f1000002

Credit And ScoringRed

No Quebec-specific credit-scoring overlay was located beyond general Private Sector Act obligations.

Absence provenance: not recorded. Searched: Quebec credit scoring privacy law.

EducationRed

No Quebec-specific education-sector data protection overlay was located in this pass.

Absence provenance: not recorded. Searched: Quebec education sector student data privacy law.

InsuranceRed

No Quebec-specific insurance-sector data protection overlay was located in this pass.

Absence provenance: not recorded. Searched: Quebec insurance sector privacy overlay.

Category narrative47 words

A dedicated health-and-social-services overlay (LRSSS) is confirmed in force since July 2024. CAI has issued recruitment/AI-hiring guidance touching employment data. No Quebec-specific financial-sector, telecoms/ePrivacy, credit-scoring, education, or insurance overlay instruments were surfaced in this research pass; searches covered CAI guidance pages, LRSSS coverage, and DataGuidance/IAPP sectoral commentary.

Sources and claims (2)
  1. ConfirmedDataGuidanceThe Act Respecting Health and Social Services Information (LRSSS), effective July 1, 2024, establishes a health-and-social-services-specific personal information regime intended to protect such information while enabling its use to improve service quality.
  2. ProbableDataGuidanceThe CAI has issued guidance advising employers on best practices for handling personal information in recruitment, including responsible use of AI tools in hiring.

#

Strong privacy-by-default and marketing-consent coverage, but no evidence of signal-based opt-out or cross-context-advertising-specific rules.

Primary frameworkAct Respecting the Protection of Personal Information in the Private Sector, CQLR c P-39.1, as amended by Law 25
Traffic-light rationale — AmberStrong privacy-by-default and marketing-consent coverage, but no evidence of signal-based opt-out or cross-context-advertising-specific rules.

Sub-modules (6)

Cookies And TrackersGreen

Default configuration must deactivate identification/location/profiling functions absent opt-in.

Claims: CLM-CA-QC-g1000001

Dark PatternsAmber

Canadian regulators, including CAI, flag manipulative design (oversized opt-in buttons, addictive engagement incentives) as inconsistent with privacy-by-default and best-interest-of-minors principles.

Claims: CLM-CA-QC-g1000002

Opt Out SignalsRed

No Quebec-specific recognition of Global Privacy Control or equivalent browser-based opt-out signals was located.

Absence provenance: not recorded. Searched: Quebec Law 25 Global Privacy Control opt-out signal.

Clean Rooms And DcrRed

No Quebec-specific clean-room/data-collaboration-room rules were located.

Absence provenance: not recorded. Searched: Quebec data clean room privacy rules.

Cross Context AdvertisingRed

Quebec's regime does not define CPRA-style 'sale'/'share' categories for cross-context advertising.

Absence provenance: not recorded. Searched: Quebec Law 25 sale share personal information cross-context advertising.

Direct MarketingGreen

Marketing uses require identity disclosure and a consent-withdrawal mechanism.

Claims: CLM-CA-QC-g1000003

Category narrative34 words

Privacy-by-default rules require deactivation of identification/location/profiling functions absent opt-in, and marketing/'prospection' uses require identity disclosure and consent-withdrawal rights. No Quebec-specific recognition of Global-Privacy-Control-style opt-out signals, clean rooms, or CPRA-style 'sale/share' cross-context-advertising categories was located.

Sources and claims (3)
  1. ConfirmedIAPPBy default, organizations must configure products and services so that functions enabling identification, location, or profiling of an individual are deactivated unless the individual actively opts in.
  2. ProbableOffice of the Privacy Commissioner of CanadaManipulative design patterns such as oversized opt-in buttons and addictive engagement incentives are flagged by Canadian privacy regulators, including Quebec's CAI, as inconsistent with privacy-by-default and best-interest-of-young-persons principles.
  3. ConfirmedIAPPWhere personal information is used for marketing ('prospection') purposes, the organization must communicate the identity of the party using the information and inform individuals of their right to withdraw consent.

#

Biometric and profiling/ADM transparency rules are mature (green-level) but AI-specific risk-assessment obligations for the private sector and surveillance carveouts remain unconfirmed.

Primary frameworkAct Respecting the Protection of Personal Information in the Private Sector, CQLR c P-39.1, as amended by Law 25; Act to Establish a Legal Framework for Information Technology (biometrics)
Traffic-light rationale — AmberBiometric and profiling/ADM transparency rules are mature (green-level) but AI-specific risk-assessment obligations for the private sector and surveillance carveouts remain unconfirmed.

Sub-modules (6)

Profiling RestrictionsGreen

Profiling is defined and requires advance notice plus a deactivation mechanism where available.

Claims: CLM-CA-QC-h1000001

Automated Decision Making TransparencyGreen

Notice, principal-reasons disclosure, and contestation/human-review rights apply to solely-automated decisions; no outright Art.-22-style prohibition.

Claims: CLM-CA-QC-h1000002, CLM-CA-QC-h1000003

Ai Risk AssessmentsAmber

Public-sector AI principles (MCN) exist; private-sector AI-specific risk-assessment mandate beyond general PIA duty is unconfirmed.

Claims: CLM-CA-QC-h1000004

Biometric RegimeGreen

Express consent, minimisation, and CAI pre-notification apply to biometric identity verification and database creation.

Claims: CLM-CA-QC-h1000005

Genetic DataAmber

CAI has proactively addressed genetic-data risk in the 23andMe bankruptcy context.

Claims: CLM-CA-QC-h1000006

State Surveillance CarveoutsRed

No specific state-surveillance carveout provisions were located in this research pass.

Absence provenance: not recorded. Searched: Quebec Law 25 national security exemption surveillance carveout.

Category narrative65 words

Law 25 defines profiling and imposes notice/deactivation duties, and requires notice-plus-contestation (not an outright prohibition, unlike GDPR Art. 22) for solely-automated decisions. Biometric processing carries express-consent and pre-notification duties. CAI has actively addressed genetic-data risk (23andMe) and AI use in recruitment; public-sector AI principles (the 'MCN') exist but are adjacent to (not squarely within) the private-sector DP regime. No specific state-surveillance carveout evidence was located.

Sources and claims (6)
  1. ConfirmedIAPPProfiling is a defined concept under Law 25, requiring organizations to give advance notice of technology that creates a profile of an individual and the means to deactivate that function where available.
  2. ConfirmedIAPPIndividuals subject to a decision based exclusively on automated processing of their personal information must be informed of the information used, the principal reasons and factors, and their right to have the decision reviewed, with a right to contest and request human review.
  3. ConfirmedOffice of the Privacy Commissioner of CanadaUnlike Article 22 GDPR, Law 25 does not prohibit solely automated decision-making outright; it instead imposes a notification and contestation requirement.
  4. ProbableDataGuidanceQuebec's public-sector AI framework (the 'MCN') sets out ten principles for responsible AI use by public bodies covering compliance, equity, security and transparency.
  5. ConfirmedOffice of the Privacy Commissioner of CanadaQuebec's Act to Establish a Legal Framework for Information Technology requires express consent to verify identity using biometric measurements, limits collection to minimum necessary characteristics, and restricts decisions based on other information revealed via biometric processing.
  6. ProbableDataGuidanceFollowing 23andMe's bankruptcy, the CAI publicly reminded Quebec residents of their rights over genetic data and urged individuals to manage consent or request deletion of their genetic information.

#

Parental consent threshold is well-evidenced (green-level) but age-verification, education-settings, and dependent-adults sub-modules are unconfirmed gaps.

Primary frameworkAct Respecting the Protection of Personal Information in the Private Sector, CQLR c P-39.1, as amended by Law 25
Traffic-light rationale — AmberParental consent threshold is well-evidenced (green-level) but age-verification, education-settings, and dependent-adults sub-modules are unconfirmed gaps.

Sub-modules (5)

Age VerificationRed

No Quebec-specific age-verification mandate was located in this research pass.

Absence provenance: not recorded. Searched: Quebec Law 25 age verification requirement.

Minor Profiling BansAmber

CAI has urged (not yet codified) stricter minors' data rules including a commercial-use prohibition.

Claims: CLM-CA-QC-i1000002

Education SettingsRed

No Quebec-specific education-settings data protection rule was located.

Absence provenance: not recorded. Searched: Quebec student data privacy education settings.

Dependent AdultsRed

No Quebec-specific dependent-adults data protection provision was located.

Absence provenance: not recorded. Searched: Quebec dependent adults elderly privacy protection.

Category narrative42 words

Quebec sets a parental-consent threshold at under-14 (differing from the federal PIPEDA/OPC-suggested under-13 benchmark), with a minor's-benefit exception, and CAI has advocated for stricter minors' data rules including a commercial-use prohibition. No Quebec-specific age-verification mandate, education-settings rule, or dependent-adults provision was located.

Sources and claims (2)
  1. ConfirmedIAPPPersonal information concerning a minor under 14 may not be collected without the consent of a parent or legal guardian, unless collection is clearly for the minor's benefit.
  2. ProbableDataGuidanceThe CAI has urged stricter rules to protect minors' personal information, including prohibiting its commercial use and prioritizing children's best interests in data-processing decisions.

#

Active, uniquely well-empowered regulator with recent (within-180-day) enforcement activity and a codified private right of action; funding/capacity and collective-redress specifics remain unconfirmed gaps.

Primary frameworkAct Respecting the Protection of Personal Information in the Private Sector, CQLR c P-39.1, as amended by Law 25
Traffic-light rationale — GreenActive, uniquely well-empowered regulator with recent (within-180-day) enforcement activity and a codified private right of action; funding/capacity and collective-redress specifics remain unconfirmed gaps.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

CAI can impose AMPs up to $25M/4% turnover (orgs) or $50,000 (individuals), plus lesser $10M/2% administrative sanctions, and is the only Canadian regulator with such power.

Claims: CLM-CA-QC-j1000001, CLM-CA-QC-j1000002

Enforcement Activity IndexGreen

May 2026 joint OpenAI investigation is CAI's most significant recent enforcement action, finding consent/transparency/default-settings deficiencies.

Claims: CLM-CA-QC-j1000003, CLM-CA-QC-j1000004

Regulator Funding And CapacityRed

No specific CAI budget/headcount figures were located in this research pass.

Absence provenance: not recorded. Searched: CAI Quebec budget headcount funding 2026.

Collective Redress And Class ActionsRed

No Quebec-specific class-action mechanism data tied to the Private Sector Act was located; general Quebec class-action procedure exists under the Code of Civil Procedure but was not specifically evidenced for privacy claims in this pass.

Absence provenance: not recorded. Searched: Quebec Law 25 class action privacy lawsuit.

Private Right Of ActionGreen

Law 25 creates a statutory private right of action with punitive damages for intentional/gross-fault infringements.

Claims: CLM-CA-QC-j1000005

Recent Developments 180DGreen

Within the last 180 days: the May 6, 2026 joint OpenAI/ChatGPT report of findings and the February 23, 2026 multinational joint statement on AI-generated imagery, both involving CAI.

Claims: CLM-CA-QC-j1000006, CLM-CA-QC-j1000007

Category narrative72 words

CAI holds the only administrative-monetary-penalty (AMP) power among Canadian privacy regulators (up to CAD $25M/4% global turnover for organizations), plus notice-of-noncompliance powers, alongside a statutory private right of action. Recent enforcement activity includes the May 2026 joint OpenAI/ChatGPT investigation finding non-compliance with Quebec's consent/transparency duties, and CAI's February 2026 participation in a multinational joint statement on AI-generated imagery. No Quebec-specific class-action mechanism data or regulator funding/headcount figures were located in this pass.

Sources and claims (7)
  1. ConfirmedIAPPThe CAI may issue notices of noncompliance and impose administrative monetary penalties of up to $25 million or, if greater, 4% of worldwide turnover for the preceding year for organizations (or up to $50,000 for individuals), with lesser administrative sanctions of $10 million or 2% of turnover for other violations.
  2. ConfirmedOffice of the Privacy Commissioner of CanadaQuebec's CAI is currently the only Canadian privacy regulator empowered to impose administrative monetary penalties, and it can proactively verify organizational compliance.
  3. ConfirmedOffice of the Privacy Commissioner of CanadaIn a joint investigation with the federal OPC and the BC and Alberta privacy commissioners, the CAI found that OpenAI had not adequately documented how it fulfilled the duty to inform or obtained consent from individuals in connection with ChatGPT training data, and that disclosures for the free web version were insufficient.
  4. ConfirmedOffice of the Privacy Commissioner of CanadaThe CAI found that, under Quebec's Private Sector Act, default privacy settings for OpenAI's models should have provided the most privacy-protective option, i.e., that user chats would not be used for model training by default.
  5. ConfirmedOffice of the Privacy Commissioner of CanadaLaw 25 creates a private right of action allowing individuals to seek compensation for unlawful infringement of a right conferred by the Private Sector Act or the privacy provisions of the Civil Code of Québec, with punitive damages of at least $1,000 available for intentional or grossly-faulty infringements.
  6. ConfirmedOffice of the Privacy Commissioner of CanadaOn May 6, 2026, the CAI joined the federal OPC and the BC and Alberta privacy commissioners in releasing a joint report of findings concluding that OpenAI's early ChatGPT models were not compliant with their respective privacy laws, leading OpenAI to implement new safeguards.
  7. ProbableOffice of the Privacy Commissioner of Canada (hosting joint statement)On February 23, 2026, the CAI joined a multinational joint statement of data protection and privacy authorities addressing AI-generated imagery and its implications for privacy.
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Canada – Quebec
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 50 claim(s), 18 source(s) in the cumulative register.