Consent Under Quebec's Law 25: A Practical Checklist for AI-Powered Products
Quebec's Law 25 raised the bar on consent, and AI products test every part of it. Here's a practical checklist: express consent, purpose specification, privacy by default, and the privacy officer role.
Under Quebec's Law 25, consent for an AI product has to be clear, free, informed, and tied to specific purposes — asked for in plain language, separately from your terms. Sensitive data needs an express opt-in, privacy settings must default to their most protective state, withdrawal has to be as easy as granting, and you must name a privacy officer and publish their contact details. This checklist walks through each requirement.
Why AI Products Stress-Test Consent
Law 25 rebuilt Quebec's private-sector privacy regime and pushed the standard for consent well above what many businesses were used to. AI-powered products put that standard under unusual strain, because they tend to collect more data, use it for more purposes, and process it in ways an ordinary user struggles to picture. An AI feature that "learns from usage," personalizes results, or feeds a model raises consent questions a static sign-up form never did.
The good news? Law 25's consent rules are demanding but learnable. Build the following into how your product asks for and manages consent, and you'll be well ahead of most of the market. This is a checklist, not legal advice, but it maps to the obligations any AI product operating in Quebec should be able to meet.
The Consent Standard in One Paragraph
Under Law 25, consent must be clear, free, and informed, and given for specific purposes. You have to request it in plain language, separately from any other information you present. For sensitive information — health, financial, biometric, and similar categories — consent must be express: an active, unmistakable opt-in, not a pre-checked box or silence. And you have to seek it in a way the people you're asking can actually understand, including minors where relevant.
In short, valid consent under Law 25 must be:
- Clear, free, and informed — the person genuinely understood what they agreed to
- Purpose-specific — tied to named purposes, not a blanket acceptance
- Plain-language and separate — distinct from your terms of service
- Express for sensitive data — an active opt-in, never a pre-checked box
- Easy to withdraw — the off-switch as accessible as the on-switch
Everything below is a way of putting that into practice.
The Checklist
1. Specify each purpose, separately. Don't bundle "improve our services, personalize your experience, and train our models" into one blanket acceptance. Law 25 wants consent tied to specific purposes. If your AI uses personal information to personalize output and, separately, to improve the underlying model, those are two different purposes — and a person should be able to understand each and, ideally, choose between them.
2. Get express consent for sensitive data. Handling health, financial, biometric, or other sensitive personal information? A buried clause won't do. You need an active, affirmative action from the user that clearly relates to that sensitive use. Voice and face data used by AI features almost always land here.
3. Separate consent from your terms of service. Ask for consent on its own, not stapled to a wall of terms nobody reads. A single "I accept the Terms" checkbox can't carry the weight of privacy consent for AI processing. Give the privacy ask its own footing — a dedicated consent center keeps each purpose separable and auditable.
4. Use plain language, and layer it. The request has to be intelligible to the person giving it. A short, readable explanation of what data is used and why, with a link to fuller detail, beats dense legalese every time. If a typical user of your product couldn't paraphrase what they agreed to, the wording needs work.
5. Turn privacy on by default. This is one of Law 25's signature demands: where a product or service offers privacy settings, the highest level of privacy has to apply by default, with no action from the user. For an AI product, that means features that share, publish, or broaden the use of personal data start in their most protective state, and the user chooses to open them up — not the other way around.
6. Make withdrawal as easy as granting. People can withdraw consent, and doing so should be genuinely within reach, not buried three menus deep — the same channel that handles privacy rights requests should handle withdrawals. Design the off-switch with the same care as the on-switch, and make sure a withdrawal actually propagates to downstream AI processing.
7. Be honest about automated decisions. Law 25 requires that individuals be told when a decision is based exclusively on automated processing, and gives them the right to submit observations and request a review. If your AI product makes or heavily shapes decisions about people, your consent and notice flow should disclose that and point to the review path.
8. Handle cross-border processing openly. Most AI tooling routes data through infrastructure outside Quebec, so start by knowing where your data flows. Law 25 expects you to assess whether personal information sent outside the province gets adequate protection — which triggers a privacy impact assessment — and your notices should be upfront about where data goes. Consent given without knowing about an offshore transfer stands on shaky ground.
9. Mind minors and vulnerable users. If children could use your product, consent expectations tighten and the plain-language bar rises further. Ask yourself whether an AI feature aimed at or accessible to minors needs a different, more protective default.
10. Keep a record. You should be able to show what a user consented to, when, and in what wording. Change your purposes or your model's use of data, and you generally need fresh consent — not a quiet retrofit of the old one. Versioned consent records are what let you prove this later.
The Privacy Officer Is Not Optional
Law 25 requires every organization to have a person responsible for the protection of personal information. By default that responsibility sits with the person of highest authority — usually the CEO — until it's formally delegated, and the responsible person's title and contact details have to be published so people can reach them.
For an AI product company, this role is more than a nameplate. The privacy officer signs off on new data uses, fields access and withdrawal requests, oversees the assessment before you ship a feature that changes how personal data is used, and owns the response when something goes wrong. Naming the role and giving it real authority is one of the cheapest, most visible ways to show you take the law seriously.
Putting It to Work
Walk your product's actual sign-up and settings flows as if you were a cautious Quebec user. Where are you asking for consent? Is each purpose specified? Is anything sensitive getting swept up without an express opt-in? Do the privacy defaults start protective? Most teams find two or three fixable gaps in an afternoon — usually a bundled purpose, a pre-checked box, or a default that shares more than it should.
This article is general information, not legal advice; how Law 25 applies to your product depends on your specific data flows, and you should consult a qualified professional before acting.
Turning a checklist like this into shipped consent flows, versioned records, and a privacy officer's working queue is exactly what Canuckt built Valdra to support — Law 25 obligations translated into concrete tasks, in English and French, with your data kept in Canada.
Frequently asked questions
What kind of consent does Law 25 require?+
Law 25 wants consent that is clear, free, and informed, given for specific purposes, asked for in plain language and separately from your other terms. For sensitive information such as health, financial, or biometric data, consent has to be express — an active, unmistakable opt-in, not a pre-checked box or silence.
What is privacy by default under Law 25?+
Privacy by default means that where a product or service offers privacy settings, the highest level of privacy applies automatically, with no action from the user. For an AI product, features that share, publish, or broaden the use of personal data start in their most protective state, and the user chooses to open them up.
Does my AI product need a privacy officer under Law 25?+
Yes. Law 25 requires every organization to designate a person responsible for the protection of personal information. By default this falls to the person of highest authority until it's formally delegated, and you have to publish that person's title and contact details so individuals can reach them. At an AI company, the role owns new data uses, rights requests, and breach response.
Do I need express consent to use customer data to train AI?+
Purposes have to be specified separately, so using personal information to train a model is a distinct purpose from personalizing someone's experience — and people should be able to understand each and ideally choose between them. If the data is sensitive, an express opt-in is required. Bundling model training into a blanket acceptance is a Law 25 gap.
Can a Toronto or Calgary company be subject to Quebec's Law 25?+
Yes. Law 25 governs any organization that collects, uses, or discloses the personal information of people in Quebec, wherever the business itself sits. A SaaS company in Toronto with Quebec users, or a Calgary retailer shipping to Quebec, is covered. And there's no small-business exemption.
AI governance and privacy compliance, simplified.
Valdra helps Canadian companies govern AI and meet PIPEDA and Law 25 — hosted in Canada.
Explore Valdra