You're ready to plug an AI voice agent into your front desk line. Good news for your missed-call rate, but here's what the sales demos don't mention: the second your agent picks up a Quebec call, it starts collecting personal information. And in Quebec, that means Law 25.
Quebec's Law 25 (formerly Bill 64) has been fully in force since September 2023. It doesn't distinguish between a human employee taking notes and an AI agent transcribing — the collection is the same, the obligations are the same. The maximum penalty climbs to CA$25M or 4% of worldwide revenue, per the Commission d'accès à l'information.
We're not going to recite 47 sections of the law. Below are the 7 concrete steps to plug in your AI voice agent without spending nights wondering if the CAI is about to knock. It's the checklist we run for every Quebec SME we onboard at TECHMA.
Step 1 — Appoint a Privacy Officer (Required by Law)
First thing, and it surprises everyone: since September 2022, every Quebec business must designate a person responsible for personal information protection. Not optional. By default, the role falls to the highest-ranking executive — which, for most SMEs, means you.
What nobody mentions: this person's name and contact info must be published on your website (article 8). Not buried 5 clicks deep — accessible. If someone calls your AI agent and wants to exercise a right, they must be able to find out within a minute who to email.
You can delegate the function to an employee or external consultant. The function delegates, the legal responsibility doesn't.
Step 2 — Run a Privacy Impact Assessment (EFVP)
Article 3.3 requires a Privacy Impact Assessment before any project involving an automated decision system or a data transfer outside Quebec. An AI voice agent ticks both boxes — it analyzes voice, makes automated routing decisions, and most platforms (ElevenLabs, OpenAI, VAPI, Retell) process voice on US servers.
A PIA isn't a 200-page audit. It's a structured document answering 4 questions:
- What information is collected, and why
- Who has access, and for how long
- Where the data flows (countries, sub-processors, vendors)
- What residual risks remain, and how they're mitigated
For a voice agent booking dental appointments, realistically you're looking at 6 to 10 pages, deliverable within a week if you have the right info on hand.
Step 3 — Update Your Privacy Policy to Mention AI Explicitly
Your old privacy policy that says "we collect your name and email to provide our services" no longer cuts it. The law requires plain and clear language (article 8) and a specific mention when automated processing is used.
Three mandatory mentions to add, in French (and ideally bilingual):
- That an AI agent is used to handle the call
- The specific purposes of collection (booking, qualification, human transfer)
- The right to request a human transfer at any time
Article 12.1 goes further: if your agent makes a decision "based exclusively on automated processing" (e.g., declining a Saturday morning slot because the calendar is full), you must inform the person and offer a path for them to submit observations to an employee.
Step 4 — Program Explicit Consent Into the First Sentence
This is where 80% of AI agents currently deployed in Quebec are at risk. Implicit consent ("you called us, therefore you consent") doesn't hold for sensitive information (article 14). And voice itself is considered biometric data once it's analyzed.
The right reflex to program in your agent's system prompt:
It adds 8 seconds at the start of the call. Compared to a potential CA$25M fine, the trade is obvious. This is also why we recommend rigorously comparing your AI voice agent to your human receptionist before flipping 100% of your calls — compliance changes the math.
Step 5 — Govern Cross-Border Data Transfers
Article 17 is blunt: before transferring personal information outside Quebec, you must run an analysis confirming the destination jurisdiction offers "equivalent" protection. The United States is not considered equivalent by default (CLOUD Act, FISA, etc.).
Concretely, this means:
- Identify where your platform vendor (ElevenLabs, VAPI, etc.) processes voice
- Document transfers in a written agreement
- Inform users of the transfer in your privacy policy
The good news: ElevenLabs announced in April 2026 support for MCP servers, content guardrails, and agent versioning (official changelog). It improves control over what goes in, what comes out, and how. But it doesn't replace the legal analysis.
Step 6 — Cap Retention and Schedule Auto-Deletion
Article 23 says information must be destroyed or anonymized once the original purpose is fulfilled. For an AI voice agent, that means: there's no business reason to keep the audio recording of an appointment booking for 5 years.
The pragmatic rule we apply:
- Audio: 90 days max, ideally 30 days (enough to resolve a customer complaint)
- Transcript: 12 months if it feeds continuous improvement, otherwise deleted at 90 days
- Metadata (number, duration, detected intent): retained in the CRM per your internal policies
Schedule deletion within the platform — most allow it now. It also keeps your storage costs from ballooning, which is one of the hidden fees that inflate your monthly bill.
Step 7 — Document, Test, Measure
Law 25 compliance isn't a project, it's a cycle. Before launching to production, we ask every SME to:
- Maintain a privacy incident register (mandatory since 2022)
- Test the agent on 50 internal calls before go-live
- Measure the human-transfer request rate (a spike = friction signal)
- Review the policy every 12 months or whenever a vendor changes
It's also the right moment to verify your AI voice agent's real ROI in 14 days — compliance is a necessary condition, not a success metric.
The Real Cost of Non-Compliance (and Why You're Probably Not the Target)
Let's be honest: the CAI doesn't have an army of inspectors. The maximum fines (CA$25M or 4% of worldwide revenue) are calibrated for the Metas, Googles, and financial institutions that cause massive leaks.
For a typical Quebec SME with an AI voice agent, the realistic risk is:
- One client complaint → CAI inquiry → formal notice → fine of CA$5K–50K
- A B2B audit (your institutional client requests proof of compliance) → contract refused
- A minor leak → publication on the CAI website → local reputational damage
That's why the investment (CA$5K–15K for initial compliance setup of a 5–25 employee SME) pays back fast, especially if you sell B2B.
How TECHMA Handles It
At TECHMA, we don't let you plug an AI voice agent in without solving Law 25 first. Everything is included in the engagement: PIA, privacy policy, compliant system prompt, retention configuration, and training your privacy officer. You stay focused on your clients; we handle the mechanics.
If you're launching your agent this quarter, do yourself a favor — run these 7 steps before go-live. Two weeks well spent now beats six weeks fighting a legal fire later.
