Draft. SignalOrange is still reviewing this text. Do not cite it as the company's final position, and do not treat it as professional advice.
This note describes public duties in Quebec’s Act respecting the protection of personal information in the private sector. It is not legal advice. Have the person in charge at your company, or a lawyer, read it before you rely on it.
A prompt is often personal information
A smaller firm connects an assistant to its CRM, its inbox, or its files. The text sent to the model contains a name, an email, a file number, sometimes a financial situation or a health problem. Once that text identifies a person, or could be used to identify one, it is personal information under Quebec law. Calling the field a “prompt” does not change that.
The model provider is not “just a productivity tool”. If the text leaves Quebec to be processed somewhere else, the statute covers that communication. An API call is a communication like any other.
Three dates worth keeping
Law 25 amended the Act respecting the protection of personal information in the private sector in stages. The public dates, which you should check against the statute if you are writing a file, are these.
- 22 September 2022. Name a person in charge of the protection of personal information. By default, that is the person with the highest authority in the enterprise. Keep a register of confidentiality incidents and, where there is a risk of serious injury, notify the Commission d’accès à l’information and the people concerned.
- 22 September 2023. Privacy policy, consent rules, confidentiality by default, privacy impact assessments for certain projects, and rules for communicating personal information outside Quebec.
- 22 September 2024. A right to portability for computerized personal information collected from the person.
This guide is about what happens when a Quebec SME sends prompts to an AI API. The two pieces that come up most often are the assessment and the communication outside Quebec.
Inventory the flow before you pick a model
Before you compare prices per million tokens, list what can end up in a call.
- What people paste. A meeting summary, a client email, a CV, an attachment.
- What the software adds on its own. Context that includes the account name, the file history, slices of a database.
- What the logs keep. The URL, the identifier, sometimes the full prompt and the reply, on your side, at the gateway, or at the model provider.
- What is used to train or evaluate. A setting labelled “improve the product” that reuses prompts. A dataset exported to another country to fine-tune a model.
- Secrets that do not belong there. API keys,
.envfiles, card numbers, tokens. These are not always personal information, but sending them is a leak.
For each flow, write who sends it, which provider receives it, which country does the processing, how long it is kept, and whether the text can be used for training. If you cannot answer, you are not ready to turn it on in production.
Before anything leaves Quebec
The statute calls for a privacy impact assessment before personal information is communicated outside Quebec. The assessment looks at, among other things, how sensitive the information is, the purpose, the protections (including the contract), and the legal regime of the place that will receive it. The communication goes ahead only if the assessment shows adequate protection, and the agreement is in writing.
A call to an API whose servers are in the United States, in Europe, or “somewhere in the provider’s cloud” is, in most cases, a communication outside Quebec as soon as the prompt contains personal information. “The provider says it is GDPR compatible” does not answer the Quebec question. The GDPR is a different regime. It can be a clue. It is not a conclusion.
An assessment is also expected when an enterprise acquires, develops, or overhauls an information system or an electronic service delivery that involves personal information. Connecting an assistant to the CRM often falls in that bucket. Do the assessment before the project, not after the first incident.
The Commission publishes guides. Start there. Have the person in charge at your company sign off. This note does not replace that assessment, and it does not quote section numbers from memory. The statute is the text that counts.
Questions to put to the provider, in writing
Ask for answers you can file with the assessment. A pricing page with no date is not enough.
- Where are the prompt and the response processed? Which province, which country, which subprocessors?
- Are the prompt and the response kept? For how long? For what reason (billing, abuse, debugging, training)?
- Can you refuse to have the text used to train a model, and is that the default?
- What happens if the model provider behind the gateway has a different policy?
- Is there a written processing agreement, and does it name the subprocessors?
- Where are the request logs?
- How quickly does the provider tell you about an incident?
- Can you delete or export the data if you leave?
- Do the invoice and the contract name an entity, a currency, and a person to reach?
If the answer is “it depends on the model” and there is no list, write it down as a risk, not as a yes.
Send less
The best protection is not to send the information. A few practices that do not need a six-month project.
- Strip names, emails, file numbers, and identity documents from the prompt when the task does not need them. “Client A, invoice 30 days late” is often enough.
- Do not send the whole file because it is easier to code. Separate the useful text from the context.
- In a short internal rule, forbid pasting secrets,
.envfiles, and card numbers into an AI tool. Say where they go instead. - Filter before you send. A filter that redacts personal information and secrets reduces what reaches the model. It does not replace the assessment: the rest of the prompt can still identify someone, and the filter can miss a case. Router, SignalOrange’s API, does this filtering before the call to the provider. The product page, read on 30 September 2026, also says request and response bodies are not retained. That is a technical control. It is not automatic compliance with Law 25.
- Keep your own logs small. Storing the full prompt “for debugging” is a new collection.
- Keep access off by default. A switch per team is better than an API key shared in a chat.
Consent, the policy, and incidents
Since September 2023, consent you request has to be manifest, free, and informed, given for specific purposes, and asked for in simple terms, separate from other information. Sensitive information calls for express consent. A box already ticked at the bottom of a long page does not do that job.
The privacy policy on your site has to describe what you actually do. If an employee sends a client’s file to an API, the policy has to be able to say so in plain language: which categories, for which purposes, and outside Quebec when that is the case.
Confidentiality by default means the most protective settings apply without the person having to act. For an internal tool, read that as: the API stays closed until someone opens it, verbose logs stay off, and sending text to a model that trains on it is not the factory setting.
A confidentiality incident includes, among other things, unauthorized access, use, or communication. An API key in a public repository, a client prompt showing up in a search tool, a list exported to a personal account: those go in the register. If there is a risk of serious injury, notice to the Commission and to the people concerned follows the Commission’s rules, not the rules of a chat thread.
A short checklist
Ask these before you widen access. A no means “not yet”, not “we will see in production”.
- Have we named a person in charge? If not, do that before you add an API. By default it is the highest authority.
- Do we know which prompts contain personal information? If not, do not send them in production. Do the inventory.
- Is the assessment for communication outside Quebec in writing? If not, do not communicate outside Quebec yet.
- Does the contract describe retention and subprocessors? A pricing page is not enough.
- Can we stop training on our prompts? Treat “maybe” as a no.
- Does the privacy policy describe this use? Update it before you widen access.
- Do we know what to do if a key or a prompt leaks? Write the first three steps and the name of the person who notifies.
What this guide does not do
It does not say a tool is “Law 25 compliant”. Compliance depends on what you collect, why, what the contract says, and what the assessment found. It does not quote fine amounts. The penalties are in the statute, and quoting them from memory is a bad idea. It does not cover the public sector, health information, or biometrics in any detail. If you handle health data, children’s data, or biometrics, stop and get help.
Choosing between a product off the shelf and software written for you is a different question, covered in Custom software or off the shelf.
Sources
- Act respecting the protection of personal information in the private sector, CQLR, c. P-39.1
- Commission d’accès à l’information du Québec
Prepared by SignalOrange on 30 September 2026 from these public sources. No adoption rates, no case studies, and no invented quotations.