The Morning Quebec's Privacy Watchdog Knocked on Mathieu's Door
Mathieu runs a massage therapy clinic in Sherbrooke. Three practitioners, roughly 220 calls a week, and an AI voice agent installed eight months ago to handle after-hours bookings. Everything was humming along. Until that Tuesday morning in February when Quebec's Commission d'accès à l'information sent him a formal investigation notice: a client had filed a complaint because her voice recording had ended up on a Californian server without her ever authorizing it.
Mathieu had never heard of Quebec Law 25. He had even less idea that a client's voice counts as sensitive biometric data. Three months later, his SME got off with a formal warning — no fine, this time — and had to rebuild its entire AI voice infrastructure. Total cost: $14,800. And he got lucky. Maximum fines under Law 25 climb to $25 million or 4% of worldwide revenue.
If you operate an AI voice agent in a Quebec SME — clinic, garage, restaurant, real estate agency, whatever — this guide is for you. We're going to walk through, step by step, how to make your setup Law 25 compliant without breaking everything. No mind-numbing legal jargon. Just what to do, in what order, and why.
Quebec Law 25 in 2026: What Actually Changed for SMEs
The Act to modernize legislative provisions respecting the protection of personal information — everyone just calls it Law 25 — rolled out progressively from 2022 to 2024. By 2026, we're firmly in the active enforcement phase. The CAI is no longer doing only awareness work. It audits, it sanctions, and it has started publishing the names of non-compliant businesses.
Three major changes hit SMEs running an AI voice agent directly. First, explicit consent: gone are the fuzzy banners along the lines of "By continuing this call, you accept our terms." The client must know precisely that the call is being recorded, by whom, for what purpose, where the data is going, and how long it will be kept. Second, the mandatory designation of a Privacy Officer (RPRP) — yes, even for a three-person SME.
Third change, and the one most business owners miss: a 60-day prior notification to the CAI before creating or using a biometric database. Voice falls into this category as soon as it gets analyzed to identify a customer (voice recognition, voiceprint, authentication). If your AI voice agent does smart caller ID by recognizing returning voices, you're in. For a solid legal overview, the MNP Law 25 guide remains one of the best free references out there.
Step 1 — Map Every Voice Data Point Your Agent Collects
Before you touch anything, you need to know exactly what your AI voice agent is collecting. And trust me, it's more than you think. With every call, your agent records at minimum four data categories: raw audio, text transcript, metadata (caller number, duration, time), and analytical inferences (detected intent, sentiment, spoken language).
Pull up an Excel sheet — or better, a Notion doc — and list each data type, where it's stored, who has access, and how long it's kept. You'll likely run into surprises. Most AI voice agent platforms keep recordings for 30 to 90 days by default. Some, like certain American hyperscalers, keep them indefinitely to train their models.
This mapping work is technically required by Law 25 under the label personal information inventory. The CAI can ask for it at any moment during an audit. If you don't have it, the audit gets off to a bad start. If you want to see how this inventory fits into a complete preparation approach, we published a detailed guide on the 5 key steps before launching your AI voice agent that covers this phase in depth.
Step 2 — Rewrite Your Opening Script for Bulletproof Consent
Your AI voice agent probably opens with something like: "Hello, you've reached [Business Name], how can I help you?" It's friendly, it's effective, and it's no longer enough in 2026.
The new Law 25-compliant standard sounds like this: "Hello, you've reached [Business]. This call is being recorded and processed by our automated voice assistant for appointment booking. Your data is hosted in Canada and kept for 90 days. To speak with a human or refuse the recording, say 'human' or press 9. Otherwise, how can I help you?" Yes, it's longer. Yes, it adds 8 to 12 seconds to the call. And yes, it's mandatory.
Three elements absolutely must appear: (1) the fact that the call is handled by an AI and not a human — algorithmic transparency is a Law 25 pillar; (2) the specific purpose of the collection; (3) an easy opt-out option with no penalty. If your current AI voice agent doesn't allow these three elements, that's a major red flag on your vendor choice. We actually broke down the vendor traps in our piece on the 5 criteria AI voice vendors don't tell you about.
Six-step Quebec Law 25 compliance roadmap for AI voice agents
Step 3 — Host Your Voice Data in Canada (And Be Able to Prove It)
Law 25 doesn't formally ban hosting abroad, but it imposes a Privacy Impact Assessment (EFVP) before any transfer outside Quebec. In plain terms: if your data passes through AWS Virginia or Azure East US, you need to document why, demonstrate that the foreign jurisdiction offers equivalent protection, and obtain the client's informed consent. Good luck with that when your client is a 72-year-old grandfather who just wants a dental appointment.
The practical solution for 95% of Quebec SMEs: host in Canada, period. Ideally Montreal or Toronto. AWS, Google Cloud, and Microsoft Azure all have Canadian regions. Twilio, which serves as the telephony layer for many AI voice agents, has offered Canadian regional routing since 2024. ElevenLabs and OpenAI are not Canada-hosted by default — you need to negotiate specific data processing addenda.
Your AI voice agent vendor must give you a written hosting certificate showing the exact region, the cloud sub-processor, and the data transit chain. If they reply "Uh, it's in the cloud," run. For a comparative analysis of jurisdictions and their Law 25 implications, the Digitad complete guide lays out the issues well.
Step 4 — Designate Your Privacy Officer (Even at 3 Employees)
Law 25 requires that a person be officially named Privacy Officer (Responsable de la protection des renseignements personnels). In a large company, that's a full-time DPO. In a three-person SME, it's usually the business owner himself. That's fine. What's not fine is designating no one.
The Privacy Officer must (a) be publicly identified on your website and in your privacy policy, (b) have a dedicated email address like privacy@yourbusiness.com, (c) respond to data access requests within 30 days, and (d) maintain a privacy incident registry with notification to the CAI within 72 hours of any significant incident.
Concretely, that means if your AI voice agent has a leak — say a bug exposes transcripts to another client — you have 72 hours on the clock to notify the CAI. Not three business days. 72 calendar hours. Put that in your emergency playbook today. The Commission d'accès à l'information du Québec publishes the incident declaration form on its website — download it and print it.
Canadian-hosted voice AI infrastructure server illustrating Law 25 data residency
Step 5 — Run the Privacy Impact Assessment Before Launch (Not After)
The Privacy Impact Assessment — EFVP for those in the know — is mandatory for any technological project involving personal information. An AI voice agent ticks every box. The thing is, most SMEs do the EFVP after deployment, when an audit demands it. At that point, it's defensive paperwork. Done before, it becomes a real design tool.
The EFVP must answer six questions: What data are you collecting? Why? Who has access? How long do you keep it? What are the risks? What mitigation measures are you applying? The CAI provides a downloadable template. Budget about 4 to 8 hours of work for a standard SME. If you work with a professional integrator, it's usually included in onboarding — at TECHMA, we deliver the signed EFVP on day 1 of deployment.
Good reflex: review the EFVP at every major change. New use case, new cloud vendor, new feature (for example, adding smart caller ID that turns your setup into a biometric system) — all of that triggers a new EFVP.
Step 6 — The Brutal Math of Non-Compliance
Let's do the math. Law 25 has two fine regimes: criminal and administrative. Criminal: up to $25,000,000 or 4% of worldwide revenue — that's the cap for major violations. Administrative: up to $10,000,000 or 2% of worldwide revenue. For a typical Quebec SME with $1.5M in revenue, we're talking potential fines of $30,000 to $60,000 per incident.
But the fine is just the tip of the iceberg. The real costs of an incident include: the formal demand letter ($1,500 to $5,000 in legal fees), client notification (postage + labor, easily $3,000), forced technical rework ($10,000 to $50,000), and the reputational cost — the CAI is increasingly publishing the names of non-compliant businesses on its public site. On Google, that follows you for years.
Conversely, getting an AI voice agent compliant from the start costs between $800 and $3,000 in initial consulting. That's a risk/cost ratio no clear-headed business owner can ignore. And we haven't even talked about the trust gain — a sales argument 90% of Quebec SMEs underuse.
How Agent IA Vocal Sets Up Your Law 25 Compliance End-to-End
The TECHMA team behind Agent IA Vocal has tooled this process to make it invisible to our clients. When we onboard you, here's what happens behind the scenes: we map your existing call flows, draft your EFVP, configure Canadian hosting (Montreal by default), generate your bilingual compliant opening script, install your incident registry, and hand you a ready-to-sign Privacy Officer kit. All of that in under 5 business days.
We also handle ongoing updates. Law 25 is going to evolve — that's announced. Bill 64bis currently being debated at the National Assembly already plans tighter rules on voice biometrics by 2027. Our clients automatically receive configuration and script updates, at no additional cost. That's what we call dynamic compliance.
If you want to see concretely how this plays out for a Quebec SME, talk to us. Agent IA Vocal offers a free 30-minute consultation where we assess your current Law 25 exposure and hand you a raw compliance report, no strings attached. No sales pressure. Just numbers and recommendations.
Quebec SME owner partnering with a privacy officer to deploy a compliant AI voice agent
Compliance Isn't a Necessary Evil
Too many SME owners see Law 25 as an administrative chore imposed by Quebec. It's the most expensive blind spot on the market. Compliance, done right, is a commercial asset. Your clients — especially seniors, healthcare professionals, lawyers, accountants — place growing importance on data protection. An SME that can proudly display "Law 25 Compliant — Data Hosted in Quebec" signs more mandates. It's documented.
Mathieu, the Sherbrooke massage therapist we opened with? Six months after his failed audit, he rebuilt his infrastructure properly, updated his website with a compliance badge, and published an article explaining his approach. Result: +34% new clients in 4 months, a good chunk of which came from medical clinics looking for a compliant vendor. Sometimes things work out.
Your AI voice agent can be your best compliance ally — or your worst liability. The difference plays out in the six steps we just covered. Start with the mapping this week. Everything else flows naturally from there.
