Does Law 25 apply to a small service business?
Yes. Law 25 modernized Québec's private-sector privacy rules, and it applies to businesses of every size that collect, use, or hold personal information — names, phone numbers, addresses, appointment details, anything that identifies a person. There is no small-business exemption. If your phone rings and a customer gives you their name and number, you're in scope.
Adding an AI agent doesn't create new categories of obligation — the same rules that already applied to your paper intake form and your voicemail apply to the AI. What changes is scale and visibility: an AI receptionist collects information systematically, records it consistently, and often stores it with a third-party vendor. That makes the existing obligations impossible to ignore — which, frankly, is a feature. Most businesses were already non-compliant by accident; the AI conversation forces the cleanup.
Do you need consent before an AI collects customer information?
The principle is older than AI: you collect personal information for a stated purpose, with the person's consent, and you use it for that purpose. When a caller gives your AI receptionist their name and number to book an appointment, that's a clear purpose. Problems start when information collected for booking quietly gets reused for something else — marketing lists, profiling, training — without the person ever agreeing to it.
For an operator, the practical checklist is short: know what your AI collects, know why, and make sure the 'why' matches what the customer was told. If you want to use collected information for a second purpose later, that's a separate consent conversation, not a default. Any AI system you deploy should make it easy to see exactly what data it captured on each interaction — if the vendor can't show you, that's your answer about the vendor.
Do you have to tell customers they're talking to an AI?
Transparency is a core pillar of Law 25 — including specific attention to decisions and interactions driven by automated means. Beyond the letter of the law, hiding the AI is bad business: the moment a caller realizes they were tricked into thinking they had a human, you've spent trust you can't buy back. Every AI agent we deploy discloses that it's an AI assistant, plainly and early, and offers a path to a human on request.
Disclosure also covers recording. If calls or conversations are recorded or transcribed, callers should know. This is standard practice in Québec customer service for a reason — and it's why 'can recording be disabled or configured?' belongs on your vendor questionnaire (more on that below). The operating rule is simple: nothing about how the interaction works should be a surprise to the person on the other end.
What do data minimization and retention mean for an AI receptionist?
Minimization means the AI collects only what the job requires. Booking a plumbing visit needs a name, a callback number, an address, and a description of the problem. It does not need a date of birth, and it should not be coaxing callers into volunteering extra personal details 'to personalize the experience.' A well-scoped agent is configured with an explicit list of fields it may capture — everything else gets politely declined or discarded.
Retention is the other half: personal information shouldn't live forever by default. Law 25 expects information to be destroyed (or anonymized, where appropriate) once the purpose it was collected for has been fulfilled. In practice that means your AI system needs configurable retention — transcripts and recordings that expire on a schedule you set, not 'stored indefinitely because storage is cheap.' Decide your retention windows deliberately, write them down, and pick tooling that enforces them automatically.
Who is your privacy officer, and what happens if something leaks?
Law 25 requires every business to have a person in charge of the protection of personal information. By default that's the highest-ranking person in the company — the owner, in most service businesses — though the role can be delegated in writing, and the contact information for that person should be published (your website's privacy page is the natural place). For a ten-person plumbing company this isn't bureaucracy; it just means someone is explicitly on the hook for knowing where customer data lives and who can touch it.
The law also imposes duties when a confidentiality incident occurs — an unauthorized access, use, disclosure, or loss of personal information. At a high level: assess the incident, act to reduce the harm, notify the Commission d'accès à l'information and the affected individuals where the incident presents a risk of serious injury, and keep a register of incidents. The operational takeaway for AI adoption: before an incident ever happens, you should already know exactly what personal data your AI systems hold and where — because you cannot assess or report a leak of data you never inventoried.
What should you ask any AI vendor before signing?
Five questions separate serious vendors from demos in a suit. One: where is the data stored, and which third parties process it? Two: can retention be configured — and what happens to transcripts and recordings when the contract ends? Three: can recording be disabled entirely, or limited to what you actually need? Four: is customer data used to train models, and can that be turned off? Five: how do you support individual rights — if a customer asks what you hold about them, or asks for correction or deletion, can the vendor produce and purge their data on request? A vendor who answers all five in writing is a partner; a vendor who stalls is a liability you'd be signing for.
This is how we build: disclosure on by default, field-level scoping of what the agent may collect, configurable retention, recording that can be disabled, and no customer data used for model training. Compliant-by-design isn't a premium tier — it's the floor. One necessary caveat, operator to operator: this guide describes well-established obligations at a high level so you can ask better questions. It is not legal advice, and reading it is not a compliance program. For your specific situation — contracts, sector rules, cross-border data — consult a lawyer who practices Québec privacy law. Then make your vendors answer to the standard your lawyer sets.