Comprehensive, fully-in-force omnibus private-sector statute with an active, well-resourced supervisory authority; only minor gaps in extraterritorial-scope statutory clarity.
Primary frameworkAct Respecting the Protection of Personal Information in the Private Sector, CQLR c P-39.1, as amended by Law 25 (SQ 2021, c. 25)
Traffic-light rationale — GreenComprehensive, fully-in-force omnibus private-sector statute with an active, well-resourced supervisory authority; only minor gaps in extraterritorial-scope statutory clarity.
Sub-modules (5)
Regulator And AuthorityGreen
CAI is the sole provincial DPA overseeing the Private Sector Act, with inquiry, order-making and sanctioning powers.
Claims: CLM-CA-QC-a1000001
Act And InstrumentsGreen
Core instrument is the Private Sector Act as amended by Law 25; biometrics and health-sector data carry dedicated overlay instruments.
Applies to collection, retention, use, access and transfer of personal information by private enterprises carrying on business in Quebec.
Claims: CLM-CA-QC-a1000006
Territorial ScopeAmber
Statutory extraterritorial reach is not as explicit as GDPR Art. 3, but CAI guidance signals expected application to foreign entities serving Quebec residents.
Claims: CLM-CA-QC-a1000007
Regulator Registration And FilingAmber
No general registration regime, but biometric-database creation must be pre-disclosed to CAI 60 days before deployment.
Claims: CLM-CA-QC-a1000008
Category narrative88 words
Quebec operates a comprehensive, GDPR-influenced private-sector data protection regime under the Act Respecting the Protection of Personal Information in the Private Sector (CQLR c P-39.1), as substantially amended by Law 25 (formerly Bill 64, SQ 2021 c.25), enforced by the Commission d'accès à l'information du Québec (CAI). A parallel Public Sector Act governs government bodies (out of scope here), and sector-specific instruments (biometrics IT Act, LRSSS) overlay the general regime. Law 25 entered into force in three phases from Sept. 2022 through full effect on Sept. 22, 2024.
Sources and claims (8)
ConfirmedDataGuidance — The Commission d'accès à l'information du Québec (CAI) is Quebec's provincial data protection authority responsible for overseeing compliance with the Act Respecting the Protection of Personal Information in the Private Sector.
ConfirmedDataGuidance — Quebec's data-protection regime is anchored in the Act Respecting the Protection of Personal Information in the Private Sector, CQLR c P-39.1, as substantially amended by An Act to modernize legislative provisions as regards the protection of personal information (SQ 2021, c. 25 / Law 25, formerly Bill 64).
ConfirmedOffice of the Privacy Commissioner of Canada — Law 25 entered into force in three phases beginning September 22, 2022, with the final phase (data portability) taking effect September 22, 2024, at which point the Act is fully in force.
ConfirmedOffice of the Privacy Commissioner of Canada — Biometric-specific obligations are separately set out in Quebec's Act to Establish a Legal Framework for Information Technology, which Law 25 amended to require 60 days' advance notice to the CAI before a biometric database is brought into service.
ConfirmedDataGuidance — Quebec's Act Respecting Health and Social Services Information (LRSSS) entered into effect July 1, 2024, establishing a health-sector-specific personal information protection regime.
ConfirmedDataGuidance — The Private Sector Act governs the collection, retention, use, access to, and transfer of personal information by private enterprises carrying on business in Quebec.
ProbableDataGuidance — CAI guidance indicates both Canadian and foreign companies offering goods or services in Quebec are expected to comply with its consent framework, signalling an extraterritorial-facing application of the Private Sector Act to organizations serving Quebec residents.
ConfirmedOffice of the Privacy Commissioner of Canada — Organizations must disclose to the CAI, at least 60 days in advance, the creation of any database containing biometric characteristics or measurements before it is brought into service.
Traffic-light rationale — GreenConsent and sensitive-data rules are mature and CAI has published detailed guidance; lawful-basis enumeration is less granular than GDPR.
Sub-modules (4)
Lawful BasesAmber
Purpose determination and necessity are statutory preconditions to collection; consent is the primary basis, with limited non-consent grounds (e.g., contract performance).
Claims: CLM-CA-QC-b1000001
Consent ThresholdsGreen
Consent must be separate, clear, free and informed, with express consent mandatory for sensitive personal information.
Claims: CLM-CA-QC-b1000002
Special CategoriesGreen
Sensitive information (medical, biometric, intimate, or contextually high-expectation data) triggers express-consent and heightened-safeguard duties.
Claims: CLM-CA-QC-b1000003, CLM-CA-QC-b1000004
Pseudonymisation And AnonymisationGreen
Law 25 distinguishes de-identified from anonymised information and conditions anonymisation on legitimacy and best-practice standards.
Claims: CLM-CA-QC-b1000005, CLM-CA-QC-b1000006
Category narrative38 words
Quebec requires purpose-limited collection, clear/free/informed consent (express for sensitive data), and defines de-identification/anonymisation with a legitimacy-and-best-practices standard. There is no enumerated Art.-6-style list of lawful bases; consent is the dominant basis, with narrow statutory exceptions (e.g., contract performance).
Sources and claims (6)
ConfirmedIAPP — Organizations must determine the purposes for collecting personal information and may collect only the information necessary for those purposes.
ConfirmedIAPP — Consent requests must be presented separately from other information requests and must be clear, free and informed, with express consent required for sensitive personal information.
ConfirmedIAPP — Sensitive personal information under Quebec law includes medical, biometric, or otherwise intimate information, and information may also become sensitive where the context of its use or communication entails a high reasonable expectation of privacy.
ConfirmedIAPP — Organizations must obtain express consent before using sensitive personal information for secondary purposes.
ConfirmedOffice of the Privacy Commissioner of Canada — Under Law 25, personal information is 'de-identified' if it no longer allows direct identification of the person concerned, whereas information is 'anonymized' only if it irreversibly no longer allows the person to be identified directly or indirectly.
ProbableIAPP — Anonymization of personal information must be performed for serious and legitimate reasons and according to generally accepted best practices.
Traffic-light rationale — GreenFull suite of rights now in force including portability as of the final 2024 phase; deadlines are codified.
Sub-modules (5)
Access RightGreen
Organizations must confirm existence of, communicate, and provide copies of personal information on request.
Claims: CLM-CA-QC-c1000001
Rectification And ErasureGreen
Access/rectification rights plus a de-indexing 'right to be forgotten' subject to a reputational-harm balancing test.
Claims: CLM-CA-QC-c1000002, CLM-CA-QC-c1000003
Restriction And ObjectionGreen
Individuals may contest automated decisions and request human review.
Claims: CLM-CA-QC-c1000004
Data PortabilityGreen
Portability right became effective in the final Law 25 implementation phase.
Claims: CLM-CA-QC-c1000005
Deadlines And Response WindowsGreen
Statutory 30-day response window applies to individual rights requests.
Claims: CLM-CA-QC-c1000006
Category narrative35 words
Quebec grants GDPR-adjacent rights of access, rectification, a bespoke 'right to be forgotten' via de-indexing, contestation of automated decisions, and (as of Sept. 2024) data portability, with a 30-day statutory response window for access/rectification requests.
Sources and claims (6)
ConfirmedIAPP — Organizations must, on request, confirm the existence of personal information, communicate it, and provide a copy to the individual concerned.
ConfirmedDataGuidance — The Private Sector Act provides individuals a right to access and rectification of their personal information.
ConfirmedOffice of the Privacy Commissioner of Canada — Section 28.1 creates a right to de-indexing ('right to be forgotten') requiring cessation of dissemination or de-indexing of a hyperlink where dissemination causes serious injury to reputation or privacy that outweighs the public interest in the information or freedom of expression.
Strong DPIA/breach/security/retention coverage (green-level), but ROPA and joint-controller concepts are not codified in equivalent GDPR form, warranting an amber overall rating.
Primary frameworkAct Respecting the Protection of Personal Information in the Private Sector, CQLR c P-39.1, as amended by Law 25
Traffic-light rationale — AmberStrong DPIA/breach/security/retention coverage (green-level), but ROPA and joint-controller concepts are not codified in equivalent GDPR form, warranting an amber overall rating.
Sub-modules (7)
Accountability And DpiaGreen
Mandatory PIAs before adopting processing technology or transferring data outside Quebec; published privacy program required.
Claims: CLM-CA-QC-d1000001, CLM-CA-QC-d1000002
Dpo RequirementsGreen
Default CEO accountability, delegable in writing, with published contact details for the person in charge.
Claims: CLM-CA-QC-d1000003
Ropa RequirementsRed
No dedicated Article-30-style records-of-processing obligation was identified in this research pass; the nearest analogue is the mandatory confidentiality-incident register (see breach_notification).
Joint Controller ArrangementsRed
No GDPR-style joint-controller regime was located in the Private Sector Act or Law 25 text reviewed.
Security MeasuresGreen
Security obligation is proportionate/contextual (sensitivity, purpose, quantity, medium).
Claims: CLM-CA-QC-d1000004
Breach NotificationGreen
Mandatory dual notification (CAI + individuals) on 'risk of serious injury', plus an incident register and remediation review.
Claims: CLM-CA-QC-d1000005, CLM-CA-QC-d1000006
Retention And DisposalGreen
Destruction obligation on purpose-expiry, satisfiable via anonymisation.
Claims: CLM-CA-QC-d1000007
Category narrative43 words
Law 25 imposes accountability via mandatory PIAs, a designated (default CEO) accountable person, breach-notification and incident-register duties, and destruction/anonymisation on retention expiry. No explicit GDPR-Art.-30-style ROPA or 'joint controller' concept was located; the closest analogues are the confidentiality-incident register and general accountability program.
Sources and claims (7)
ConfirmedIAPP — Organizations must conduct a privacy impact assessment before adopting technology that processes personal information and before transferring personal information outside Quebec.
ConfirmedIAPP — Organizations must adopt and publish privacy governance policies and practices according to prescribed requirements, approved by the person in charge of protecting personal information.
ConfirmedIAPP — By default, the highest authority (e.g., CEO) of an organization is responsible for compliance with the Private Sector Act, but this responsibility may be delegated in writing to any person, whose name, title and contact information must be published.
ConfirmedDataGuidance — Enterprises must take security measures necessary to protect personal information that are reasonable given the sensitivity of the information, its purposes, quantity, and the medium on which it is stored.
ConfirmedIAPP — Organizations must notify the CAI and affected individuals of any confidentiality incident presenting a 'risk of serious injury,' assessed under real-risk-of-significant-harm factors.
ConfirmedIAPP — Organizations must maintain a register of confidentiality incidents and conduct a lessons-learned/remediation review to help prevent recurrence.
ConfirmedIAPP — Organizations must destroy personal information once it is no longer required for the purposes for which it was collected, a duty that may be satisfied through anonymization.
Robust TIA obligation is in force, but the absence of published adequacy lists and localisation clarity leaves cross-border compliance more case-specific than in EU-style regimes.
Primary frameworkAct Respecting the Protection of Personal Information in the Private Sector, CQLR c P-39.1, as amended by Law 25 (Section 17)
Traffic-light rationale — AmberRobust TIA obligation is in force, but the absence of published adequacy lists and localisation clarity leaves cross-border compliance more case-specific than in EU-style regimes.
Sub-modules (6)
Transfer MechanismsAmber
Section 17 requires an outbound transfer assessment rather than reliance on a fixed adequacy list.
Claims: CLM-CA-QC-e1000001
Adequacy ReceivedRed
No published inbound adequacy determinations affecting Quebec were located in this research pass.
Adequacy GrantedRed
Quebec does not appear to operate a published outbound adequacy-list mechanism; equivalence is assessed case-by-case under Section 17.
Sccs And BcrsAmber
Contractual equivalence obligations function similarly to SCCs but are not a named, standardized instrument.
Claims: CLM-CA-QC-e1000002
Transfer Impact AssessmentGreen
TIA must weigh sensitivity, purpose, destination protection, and downstream third-party obligations.
Claims: CLM-CA-QC-e1000003
Data LocalisationRed
No absolute or general data-localisation mandate was identified for Quebec's private-sector regime in this pass.
Category narrative38 words
Quebec uses a case-by-case Transfer Impact Assessment model (Section 17) rather than a published adequacy-list mechanism. No formal adequacy decisions received-from or granted-to other regimes were located, and no absolute data-localisation mandate was identified in the private-sector regime.
Sources and claims (3)
ConfirmedIAPP — Section 17 requires organizations to conduct a transfer/privacy impact assessment before transferring personal information outside Quebec, assessing sensitivity, purpose, and the adequacy of protection at the destination, including equivalent obligations on subsequent third-party recipients.
ProbableIAPP — Organizations relying on contractual safeguards to meet Section 17's outside-Quebec transfer requirement must bind subsequent third-party recipients to equivalent data-protection obligations, functioning similarly to standard contractual clauses.
ConfirmedIAPP — A Quebec transfer impact assessment must consider the sensitivity of the information, the purpose of the transfer, and whether the information will receive adequate protection once transferred, including from third parties who may subsequently access it.
Traffic-light rationale — AmberHealth overlay is well-evidenced (green-level); most other sectors carry no confirmed Quebec-specific overlay, driving an overall amber/gap rating.
Sub-modules (7)
Financial Sector OverlayRed
No Quebec-specific financial-sector privacy overlay (beyond the general Private Sector Act) was located.
Absence provenance: not recorded. Searched: Quebec financial sector data protection AMF overlay, Quebec Law 25 financial institutions.
Health Sector OverlayGreen
LRSSS establishes a dedicated health/social-services information regime, in effect since July 1, 2024.
Claims: CLM-CA-QC-f1000001
Telecoms And EprivacyRed
No Quebec-specific telecoms/ePrivacy instrument distinct from the general Private Sector Act was located.
Absence provenance: not recorded. Searched: Quebec telecoms ePrivacy cookies law.
Employment DataAmber
CAI has issued guidance on personal-data handling in recruitment, including responsible AI use.
Claims: CLM-CA-QC-f1000002
Credit And ScoringRed
No Quebec-specific credit-scoring overlay was located beyond general Private Sector Act obligations.
Absence provenance: not recorded. Searched: Quebec credit scoring privacy law.
EducationRed
No Quebec-specific education-sector data protection overlay was located in this pass.
Absence provenance: not recorded. Searched: Quebec education sector student data privacy law.
InsuranceRed
No Quebec-specific insurance-sector data protection overlay was located in this pass.
Absence provenance: not recorded. Searched: Quebec insurance sector privacy overlay.
Category narrative47 words
A dedicated health-and-social-services overlay (LRSSS) is confirmed in force since July 2024. CAI has issued recruitment/AI-hiring guidance touching employment data. No Quebec-specific financial-sector, telecoms/ePrivacy, credit-scoring, education, or insurance overlay instruments were surfaced in this research pass; searches covered CAI guidance pages, LRSSS coverage, and DataGuidance/IAPP sectoral commentary.
Sources and claims (2)
ConfirmedDataGuidance — The Act Respecting Health and Social Services Information (LRSSS), effective July 1, 2024, establishes a health-and-social-services-specific personal information regime intended to protect such information while enabling its use to improve service quality.
ProbableDataGuidance — The CAI has issued guidance advising employers on best practices for handling personal information in recruitment, including responsible use of AI tools in hiring.
Traffic-light rationale — AmberStrong privacy-by-default and marketing-consent coverage, but no evidence of signal-based opt-out or cross-context-advertising-specific rules.
Sub-modules (6)
Cookies And TrackersGreen
Default configuration must deactivate identification/location/profiling functions absent opt-in.
Claims: CLM-CA-QC-g1000001
Dark PatternsAmber
Canadian regulators, including CAI, flag manipulative design (oversized opt-in buttons, addictive engagement incentives) as inconsistent with privacy-by-default and best-interest-of-minors principles.
Claims: CLM-CA-QC-g1000002
Opt Out SignalsRed
No Quebec-specific recognition of Global Privacy Control or equivalent browser-based opt-out signals was located.
Absence provenance: not recorded. Searched: Quebec Law 25 Global Privacy Control opt-out signal.
Clean Rooms And DcrRed
No Quebec-specific clean-room/data-collaboration-room rules were located.
Absence provenance: not recorded. Searched: Quebec data clean room privacy rules.
Cross Context AdvertisingRed
Quebec's regime does not define CPRA-style 'sale'/'share' categories for cross-context advertising.
Absence provenance: not recorded. Searched: Quebec Law 25 sale share personal information cross-context advertising.
Direct MarketingGreen
Marketing uses require identity disclosure and a consent-withdrawal mechanism.
Claims: CLM-CA-QC-g1000003
Category narrative34 words
Privacy-by-default rules require deactivation of identification/location/profiling functions absent opt-in, and marketing/'prospection' uses require identity disclosure and consent-withdrawal rights. No Quebec-specific recognition of Global-Privacy-Control-style opt-out signals, clean rooms, or CPRA-style 'sale/share' cross-context-advertising categories was located.
Sources and claims (3)
ConfirmedIAPP — By default, organizations must configure products and services so that functions enabling identification, location, or profiling of an individual are deactivated unless the individual actively opts in.
ProbableOffice of the Privacy Commissioner of Canada — Manipulative design patterns such as oversized opt-in buttons and addictive engagement incentives are flagged by Canadian privacy regulators, including Quebec's CAI, as inconsistent with privacy-by-default and best-interest-of-young-persons principles.
ConfirmedIAPP — Where personal information is used for marketing ('prospection') purposes, the organization must communicate the identity of the party using the information and inform individuals of their right to withdraw consent.
Biometric and profiling/ADM transparency rules are mature (green-level) but AI-specific risk-assessment obligations for the private sector and surveillance carveouts remain unconfirmed.
Primary frameworkAct Respecting the Protection of Personal Information in the Private Sector, CQLR c P-39.1, as amended by Law 25; Act to Establish a Legal Framework for Information Technology (biometrics)
Traffic-light rationale — AmberBiometric and profiling/ADM transparency rules are mature (green-level) but AI-specific risk-assessment obligations for the private sector and surveillance carveouts remain unconfirmed.
Sub-modules (6)
Profiling RestrictionsGreen
Profiling is defined and requires advance notice plus a deactivation mechanism where available.
Claims: CLM-CA-QC-h1000001
Automated Decision Making TransparencyGreen
Notice, principal-reasons disclosure, and contestation/human-review rights apply to solely-automated decisions; no outright Art.-22-style prohibition.
Claims: CLM-CA-QC-h1000002, CLM-CA-QC-h1000003
Ai Risk AssessmentsAmber
Public-sector AI principles (MCN) exist; private-sector AI-specific risk-assessment mandate beyond general PIA duty is unconfirmed.
Claims: CLM-CA-QC-h1000004
Biometric RegimeGreen
Express consent, minimisation, and CAI pre-notification apply to biometric identity verification and database creation.
Claims: CLM-CA-QC-h1000005
Genetic DataAmber
CAI has proactively addressed genetic-data risk in the 23andMe bankruptcy context.
Claims: CLM-CA-QC-h1000006
State Surveillance CarveoutsRed
No specific state-surveillance carveout provisions were located in this research pass.
Absence provenance: not recorded. Searched: Quebec Law 25 national security exemption surveillance carveout.
Category narrative65 words
Law 25 defines profiling and imposes notice/deactivation duties, and requires notice-plus-contestation (not an outright prohibition, unlike GDPR Art. 22) for solely-automated decisions. Biometric processing carries express-consent and pre-notification duties. CAI has actively addressed genetic-data risk (23andMe) and AI use in recruitment; public-sector AI principles (the 'MCN') exist but are adjacent to (not squarely within) the private-sector DP regime. No specific state-surveillance carveout evidence was located.
Sources and claims (6)
ConfirmedIAPP — Profiling is a defined concept under Law 25, requiring organizations to give advance notice of technology that creates a profile of an individual and the means to deactivate that function where available.
ConfirmedIAPP — Individuals subject to a decision based exclusively on automated processing of their personal information must be informed of the information used, the principal reasons and factors, and their right to have the decision reviewed, with a right to contest and request human review.
ConfirmedOffice of the Privacy Commissioner of Canada — Unlike Article 22 GDPR, Law 25 does not prohibit solely automated decision-making outright; it instead imposes a notification and contestation requirement.
ProbableDataGuidance — Quebec's public-sector AI framework (the 'MCN') sets out ten principles for responsible AI use by public bodies covering compliance, equity, security and transparency.
ConfirmedOffice of the Privacy Commissioner of Canada — Quebec's Act to Establish a Legal Framework for Information Technology requires express consent to verify identity using biometric measurements, limits collection to minimum necessary characteristics, and restricts decisions based on other information revealed via biometric processing.
ProbableDataGuidance — Following 23andMe's bankruptcy, the CAI publicly reminded Quebec residents of their rights over genetic data and urged individuals to manage consent or request deletion of their genetic information.
Parental consent threshold is well-evidenced (green-level) but age-verification, education-settings, and dependent-adults sub-modules are unconfirmed gaps.
Primary frameworkAct Respecting the Protection of Personal Information in the Private Sector, CQLR c P-39.1, as amended by Law 25
Traffic-light rationale — AmberParental consent threshold is well-evidenced (green-level) but age-verification, education-settings, and dependent-adults sub-modules are unconfirmed gaps.
Sub-modules (5)
Age VerificationRed
No Quebec-specific age-verification mandate was located in this research pass.
Absence provenance: not recorded. Searched: Quebec Law 25 age verification requirement.
Parental ConsentGreen
Consent for minors under 14 must come from a parent/guardian absent a minor's-benefit exception.
Claims: CLM-CA-QC-i1000001
Minor Profiling BansAmber
CAI has urged (not yet codified) stricter minors' data rules including a commercial-use prohibition.
Claims: CLM-CA-QC-i1000002
Education SettingsRed
No Quebec-specific education-settings data protection rule was located.
Absence provenance: not recorded. Searched: Quebec student data privacy education settings.
Dependent AdultsRed
No Quebec-specific dependent-adults data protection provision was located.
Quebec sets a parental-consent threshold at under-14 (differing from the federal PIPEDA/OPC-suggested under-13 benchmark), with a minor's-benefit exception, and CAI has advocated for stricter minors' data rules including a commercial-use prohibition. No Quebec-specific age-verification mandate, education-settings rule, or dependent-adults provision was located.
Sources and claims (2)
ConfirmedIAPP — Personal information concerning a minor under 14 may not be collected without the consent of a parent or legal guardian, unless collection is clearly for the minor's benefit.
ProbableDataGuidance — The CAI has urged stricter rules to protect minors' personal information, including prohibiting its commercial use and prioritizing children's best interests in data-processing decisions.
Active, uniquely well-empowered regulator with recent (within-180-day) enforcement activity and a codified private right of action; funding/capacity and collective-redress specifics remain unconfirmed gaps.
Primary frameworkAct Respecting the Protection of Personal Information in the Private Sector, CQLR c P-39.1, as amended by Law 25
Traffic-light rationale — GreenActive, uniquely well-empowered regulator with recent (within-180-day) enforcement activity and a codified private right of action; funding/capacity and collective-redress specifics remain unconfirmed gaps.
Sub-modules (6)
Regulator Powers And PenaltiesGreen
CAI can impose AMPs up to $25M/4% turnover (orgs) or $50,000 (individuals), plus lesser $10M/2% administrative sanctions, and is the only Canadian regulator with such power.
Claims: CLM-CA-QC-j1000001, CLM-CA-QC-j1000002
Enforcement Activity IndexGreen
May 2026 joint OpenAI investigation is CAI's most significant recent enforcement action, finding consent/transparency/default-settings deficiencies.
Claims: CLM-CA-QC-j1000003, CLM-CA-QC-j1000004
Regulator Funding And CapacityRed
No specific CAI budget/headcount figures were located in this research pass.
Absence provenance: not recorded. Searched: CAI Quebec budget headcount funding 2026.
Collective Redress And Class ActionsRed
No Quebec-specific class-action mechanism data tied to the Private Sector Act was located; general Quebec class-action procedure exists under the Code of Civil Procedure but was not specifically evidenced for privacy claims in this pass.
Absence provenance: not recorded. Searched: Quebec Law 25 class action privacy lawsuit.
Private Right Of ActionGreen
Law 25 creates a statutory private right of action with punitive damages for intentional/gross-fault infringements.
Claims: CLM-CA-QC-j1000005
Recent Developments 180DGreen
Within the last 180 days: the May 6, 2026 joint OpenAI/ChatGPT report of findings and the February 23, 2026 multinational joint statement on AI-generated imagery, both involving CAI.
Claims: CLM-CA-QC-j1000006, CLM-CA-QC-j1000007
Category narrative72 words
CAI holds the only administrative-monetary-penalty (AMP) power among Canadian privacy regulators (up to CAD $25M/4% global turnover for organizations), plus notice-of-noncompliance powers, alongside a statutory private right of action. Recent enforcement activity includes the May 2026 joint OpenAI/ChatGPT investigation finding non-compliance with Quebec's consent/transparency duties, and CAI's February 2026 participation in a multinational joint statement on AI-generated imagery. No Quebec-specific class-action mechanism data or regulator funding/headcount figures were located in this pass.
Sources and claims (7)
ConfirmedIAPP — The CAI may issue notices of noncompliance and impose administrative monetary penalties of up to $25 million or, if greater, 4% of worldwide turnover for the preceding year for organizations (or up to $50,000 for individuals), with lesser administrative sanctions of $10 million or 2% of turnover for other violations.
ConfirmedOffice of the Privacy Commissioner of Canada — Quebec's CAI is currently the only Canadian privacy regulator empowered to impose administrative monetary penalties, and it can proactively verify organizational compliance.
ConfirmedOffice of the Privacy Commissioner of Canada — In a joint investigation with the federal OPC and the BC and Alberta privacy commissioners, the CAI found that OpenAI had not adequately documented how it fulfilled the duty to inform or obtained consent from individuals in connection with ChatGPT training data, and that disclosures for the free web version were insufficient.
ConfirmedOffice of the Privacy Commissioner of Canada — The CAI found that, under Quebec's Private Sector Act, default privacy settings for OpenAI's models should have provided the most privacy-protective option, i.e., that user chats would not be used for model training by default.
ConfirmedOffice of the Privacy Commissioner of Canada — Law 25 creates a private right of action allowing individuals to seek compensation for unlawful infringement of a right conferred by the Private Sector Act or the privacy provisions of the Civil Code of Québec, with punitive damages of at least $1,000 available for intentional or grossly-faulty infringements.
ConfirmedOffice of the Privacy Commissioner of Canada — On May 6, 2026, the CAI joined the federal OPC and the BC and Alberta privacy commissioners in releasing a joint report of findings concluding that OpenAI's early ChatGPT models were not compliant with their respective privacy laws, leading OpenAI to implement new safeguards.
Filters combine as OR inside a group and AND across
groups.
Editorial metadata
Provenance only. Nothing below gates publication or affects the render.
Editorial metadata for Canada – Quebec
Field
Value
trust.lawyer_review.status
never_reviewed
trust.lawyer_review.reviewer
not recorded
trust.content_source
ai_generated
Provenance and declared absence
Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.
Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.
Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.
Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.
Suppressed by doctrine: derived risk score; derived_scores = {}.
Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.
Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 50 claim(s), 18 source(s) in the cumulative register.