Law 25 & data
Law 25 Compliant AI Tools: The Practical Guide
By The ATOM Solutions teamUpdated 6 min read
Want to use an AI tool for your SMB, but Law 25 makes you nervous? Here's the short version: an AI tool is Law 25 compliant when you know where your data lives, you tell your clients clearly how their personal information is used, you ask for their consent when needed, and you keep track of who touches what. Compliance doesn't depend only on the tool you choose — it also depends on how you use it.
Law 25 (officially An Act to modernize legislative provisions as regards the protection of personal information) governs how businesses in Québec handle personal information. AI is no exception. Here's what that means in practice, and how to choose a tool without getting it wrong.
The criteria for a Law 25 compliant AI tool
- Data hosting
- Ideally in Canada
- Does your data train the model?
- Preferably not
- Data processing agreement
- Yes, signed with the vendor
- Access log
- Who viewed what, and when
- Sensitive data
- Option to keep it in-house
What Law 25 asks when you use AI
Law 25 doesn't talk about "artificial intelligence" as such. It talks about personal information — a name, an email address, a client file, an account number. As soon as an AI tool touches that data, four principles apply.
- Clear information and consent. You have to tell your clients, in plain language, how their information is used. If an AI tool analyzes their data in a new way, that has to be clear — and, in many cases, consented to.
- Transparency about automated decisions. If a decision affecting a person is made exclusively by an automated system (for example, denying an application without a human reviewing the file), that person has the right to be informed and to ask for a human to review the decision.
- Data minimization. You only collect — and only give the tool — the information truly necessary for the task. Not the whole file "just in case."
- Preference for processing in Canada. The law requires a risk assessment before transferring personal information outside Québec. In practice, keeping data hosted and processed in Canada makes that assessment much simpler.
The checklist for choosing a tool
Before connecting an AI tool to your data, ask the vendor these questions. A clear, straight answer is already a good sign.
- Where is the data hosted? Look for hosting in Canada. If the data goes to the United States or elsewhere, you need to assess the risk and, often, cover it by contract.
- Is my data used to train the vendor's model? The ideal answer is no. Your client data shouldn't feed a model shared with other companies. Many tools offer a "no training" option — make sure it's turned on.
- Is there a data processing agreement? Require a . It's the contract that spells out, in black and white, what the vendor may do with your data — and what it may not.
- Is there an access log? You need to know who accessed which data, and when. Useful day to day — and essential if there's ever an incident.
- Can sensitive data stay in-house? For the most delicate information (health, finances, HR files), the ideal is to process it on your own servers, without it ever leaving your environment.
Off-the-shelf tool or custom solution?
Both approaches can be compliant. The choice depends on how sensitive your data is and how much control you need.
| Criterion | Off-the-shelf tool | Custom solution |
|---|---|---|
| Hosting | Often outside Canada | Your choice (Canada possible) |
| Training on your data | Check case by case | None, by default |
| Sensitive data in-house | Rarely possible | Possible |
| Setup | Fast | Longer |
| Control and traceability | Variable | High |
A well-configured off-the-shelf tool can do the job perfectly well for low-sensitivity tasks. For delicate data or a use that's central to your business, a custom solution gives you control.
The trap: it's not just the tool
This is the most important point, and the most often forgotten. A "compliant" tool doesn't automatically make you compliant. Law 25 looks at how you use it, not just the technology.
You can have the best Canada-hosted tool and still be at fault if you pour data into it without consent, keep more than you need, or nobody knows who has access. Conversely, a well-governed tool — with clear rules and a trained team — puts you in a much stronger position.
How ATOM approaches the question
Our reflex isn't "let's put AI everywhere." It's "what's the right tool for this problem?" Often, AI is part of the answer, not the whole answer.
When AI genuinely belongs, we build custom solutions hosted in Canada, where your data stays with you and is never used to train a shared model. We start small, deliver a useful first version quickly, and explain every choice in plain language — not jargon. You keep control of your data, and the peace of mind that comes with it.