Monday morning, 8:47 a.m. A restaurant owner in Quebec City opens her email and finds a notice from the Commission d'accès à l'information. A customer has filed a complaint. Her AI voice agent — installed six months ago by an American vendor — had been recording and routing every conversation to servers in Texas. No clear disclosure. No explicit consent. And critically, no Privacy Impact Assessment on file.
This case is not hypothetical. Since January 2026, the CAI has been processing complaints like these without indulgence, and administrative penalties can reach up to $25 million or 4% of worldwide revenue — whichever is greater.
And yet, 8 out of 10 Quebec SMBs running an AI voice agent today are missing at least three of the seven baseline Law 25 requirements. It's not bad faith. It's that most available guides cover either the law or voice agents — almost never both together.
This article closes that gap. Concretely, for an SMB.
The trap most owners don't see coming
Law 25 does not ban AI voice agents. It imposes a specific framework: transparency, consent, data localization, documentation. The catch is that most platforms sold in Quebec today — Vapi, Retell, Bland, and others — run on U.S. infrastructure. The moment a call is recorded and sent to a server in Texas, Virginia, or Oregon, you've triggered Article 17 of Law 25.
Practical translation: you must evaluate before the transfer whether the destination jurisdiction offers equivalent protection (it doesn't — thanks to the CLOUD Act), document that evaluation, and obtain explicit consent from the customer who knew where their data would land. This is not a formality — it's an operating condition.
Running an agent without this setup means creating a non-compliance event with every incoming call. Multiply that by 200 calls a month, across 12 months, and you're sitting on a mountain of accumulated risk long before the first complaint lands.
The 7 concrete requirements for an AI voice agent in Quebec in 2026
Here's what Law 25 specifically requires when an AI voice agent handles personal information. None of these are theoretical — each maps to a specific article of the law.
1. Opening-call disclosure (art. 12.1). The customer must be informed, at the very start, that they are speaking with an automated system and that the conversation is handled by AI. A simple sentence works: "Hello, you're speaking with our intelligent virtual assistant. The conversation is recorded to process your request." Saying this alone puts you ahead of 70% of current Quebec installations.
2. Manifestly informed and explicit consent (art. 14). Silence is not consent. The customer must actively say "yes" (or the equivalent) before collection begins. A quick "by continuing this call, you agree to…" slipped into the greeting will not survive an audit.
3. Privacy Impact Assessment — PIA (art. 3.3). Mandatory for any AI system that automatically processes sensitive personal information. The PIA documents risks, mitigation measures, and justifies why the agent is proportionate to the business need. Keep it current and ready to present to the CAI.
4. Hosting and cross-border transfers (art. 17). If data leaves Quebec, there must be a contractual agreement guaranteeing equivalent protection. In practice for 2026, the only sound and defensible path is to host in Canada, with a provider whose subprocessors are also Canadian or European.
5. Retention limits (art. 23). Call recordings cannot linger indefinitely. Set a retention period — typically 90 to 180 days for commercial calls — and make sure the system purges automatically. If your vendor says "we keep everything," change vendors.
6. 72-hour breach notification (art. 3.5). If an incident occurs — leak, unauthorized access, misrouting — you have 72 hours to notify the CAI and affected individuals. This countdown doesn't start when you learn about the incident: it starts when it should have been detected. A documented procedure is essential.
7. Right to human review of an automated decision (art. 12.1 para. 2). If your agent makes a decision that affects the customer (declining a booking, deprioritizing a callback, qualifying a lead), the customer must be able to reach a human for review. This is not optional. A clear "speak to a human" option solves this requirement.
None of these seven requirements is technically hard. The problem is that 95% of Quebec deployments cover three or four of them on average — and skip the rest because they're not included "by default" in the vendor's package.
The real problem: where your data actually travels
When a Quebec customer calls your SMB and your voice agent transcribes their speech, three things happen within seconds.
The voice is converted to text by a speech recognition model (often Deepgram or OpenAI's Whisper). The text is sent to a large language model (GPT, Claude, Gemini) to generate the response. The response is sent to a text-to-speech engine (typically ElevenLabs) to be played back. At every step, data can cross borders.
In April 2026, ElevenLabs and OpenAI both expanded their multi-agent and realtime capabilities. Great for conversation quality. A compliance headache, because those capabilities rely on pipelines distributed across multiple data centers — most of them American.
The answer for a Quebec SMB is not to avoid these models. It's to use them through an integrator that contractualizes the transfer properly and, above all, documents the PIA and the data journey. That's exactly what our TECHMA team handles during deployment: the client does not configure anything — the compliant infrastructure is delivered turnkey, with CAI-ready documentation from day one.
72 hours: the countdown no one explains properly
The 72-hour breach notification requirement (art. 3.5) is widely misunderstood by SMB owners. Here's what it means in practice.
The clock starts as soon as the incident is (or should have been) known. It includes weekends and statutory holidays. It applies to any incident that "presents a risk of serious harm" — which, for a voice agent capturing phone numbers, addresses, or payment details, is almost always the case.
To meet that window, you need three things before an incident occurs:
An audit log that records who accessed what and when. An internal trigger procedure (who calls whom, who writes the report, who communicates with customers). A CAI notification template already drafted, reviewed by legal counsel, ready to be adapted. If you wait for an incident to write those documents, you will blow through the 72 hours — and the fine doubles automatically.
Our standard approach at TECHMA: these three elements come packaged as the "compliance kit" shipped with every deployment. Not an add-on. Default.
A 30-day compliance plan for a Quebec SMB
If you already have a voice agent in production, here's the minimum viable plan to get back into compliance before you receive a complaint. If you're planning a deployment, the same plan applies — just before go-live rather than after.
Week 1 — Map. List every point at which personal data is captured by the agent. Document where each data element goes: which server, which country, which subprocessor. This is usually where owners realize their "Canadian platform" actually routes through Dallas.
Week 2 — Rework disclosure and consent. Update the opening line to cover points 1 and 2 above. Test with ten customers — if more than two don't understand they're speaking to AI, rewrite.
Week 3 — Document. Write (or have written) the PIA, the retention policy, and the incident response procedure. If you're working with an integrator, they should deliver these three documents tailored to your case — not generic templates.
Week 4 — Test and train. End-to-end test with a simulated incident scenario. Your team must know what to do if a customer asks for human review, for data deletion, or files a formal complaint.
One month — not six. Law 25 does not demand instant perfection, but it demands a documented, reasonable process. A 30-day plan, executed and archived, is a solid defense during an inspection.
What actually changed in April 2026
Three shifts make compliance more feasible today than twelve months ago.
OpenAI's new models (gpt-realtime, now in GA) and the documentation frameworks recommended by specialized Quebec legal counsel allow for far more granular consent configurations. An agent can now adapt its flow to the call type (appointment vs. billing) and scale its data collection accordingly — which satisfies the minimization requirement in Article 10.
Canadian and European infrastructures dedicated to voice AI have multiplied. It's now possible to deliver conversational quality on par with U.S. solutions without ever pushing sensitive data across the border.
Finally, in Q1 2026, the CAI published sector-specific guidance clarifying how Law 25 applies to conversational systems. Grey zones from two years ago are becoming documented zones — good news for SMBs who want to do things right.
Where to start, concretely
Three paths depending on where you stand.
If you don't yet have a voice agent. Before choosing a vendor, read our guide to the 10 questions to ask any AI voice agent vendor. Three of those ten questions map directly to Law 25 compliance — and the answers will tell you immediately whether you're dealing with a serious integrator or a reseller.
If you already have an agent in production. Run a quick audit: take the seven requirements above and check the ones your current installation satisfies with supporting documentation. If you tick fewer than five of seven, you're in a risk zone. Also read our piece on reliability mistakes to avoid — reliability and compliance are two sides of the same coin.
If you're planning to plug an agent onto your existing line. The technical integration is not the only concern. Our 2026 integration guide covers the technical side, but compliance must be designed in parallel — not afterward.
In all three cases, the mistake to avoid is treating Law 25 as an administrative afterthought. It's not. It's a design pillar that determines which platform, which architecture, and which vendor you can actually choose.
Our TECHMA team deploys every Agent IA Vocal with that compliance pillar built in from the first scoping meeting. No client configures compliance themselves — we deliver the full package, documented and inspection-ready. If you want a second opinion on your current installation's compliance posture or a 2026 rollout plan, we offer a free 30-minute review through our booking page. You either leave with a validation or a concrete action plan. Either way, you know exactly where you stand.
For a broader look at the legal framework, the Commission d'accès à l'information du Québec regularly publishes guidance specific to automated systems. SMB owners benefit from subscribing their technical team to those updates — 2026 compliance is won by anticipation, not reaction.
