Loi 25 and AI at Work: A Practical Approach for SMBs

An advisor connects early online credit-card concerns with a modern controlled AI workplace

Employees are already using ChatGPT, Claude, Gemini and AI features built into everyday work tools.

They polish emails, summarize documents, prepare proposals and search internal files. AI has become part of knowledge work, often without a formal project, a special budget or management approval.

Loi 25 was not designed for this speed of adoption.

It requires a privacy impact assessment, or PIA, for certain information-system projects involving personal information. It also requires an assessment before personal information is communicated outside Quebec or processed there on behalf of the business.

Applied mechanically, that can become absurd for an SMB. A simple “polish” feature in an email may process a customer's name, message and signature through infrastructure outside Quebec. Should a business launch a major compliance project every time an employee improves three sentences?

That is not how people work.

The useful answer is to apply the law at the right scale.

Assess the workflow, not every click

Quebec's privacy regulator says a PIA must be proportionate to the information's sensitivity, purpose, quantity, distribution and format.

For an SMB, the useful unit of analysis is the recurring workflow.

Employees use an approved Google Workspace writing feature to polish ordinary customer emails.

The business can assess that workflow once, record its rules and reuse the decision. It does not need a new assessment for every email.

Grouping routine uses into one workflow assessment is a practical governance method. The statute does not present it as an exemption or a compliance safe harbour.

Review the assessment when something material changes:

  • a new provider;
  • a new category of information;
  • a connection to an inbox, CRM or shared drive;
  • permission to send or delete;
  • a change in retention or processing location;
  • or use in HR, health, finance or decisions affecting people.

A proportionate assessment does not have to be a 40-page report for a routine low-risk use. It needs to leave credible evidence of what was checked and why the decision was reasonable.

The gap between Loi 25 and modern technology

The law thinks in terms of projects, systems and transfers of information. Modern AI arrives as a button inside almost every product.

An employee does not think they are launching a new information system when they click “rewrite.” They think they are fixing an email.

From a privacy perspective, however, content may leave the screen, be processed by a provider, be retained for a period and sometimes pass through connected services.

That gap is why blanket bans fail. People will keep using useful tools.

The business objective should be to make safe choices easy and genuinely dangerous uses difficult. A practical policy also helps address the shadow AI already present in many organizations.

We have seen this transition before

When online shopping first appeared, many people refused to enter a credit-card number on a website. The concern was understandable. The infrastructure, habits and protections were new.

Today, the same person may have several high-limit cards stored with dozens or even hundreds of services. The risk did not disappear. We built controls around it: encryption, payment standards, fraud detection, tokenization, alerts and chargebacks.

AI will likely follow a similar path.

The answer will not be to withhold all information forever. It will be to choose where information may go, limit what a tool can see, monitor what it does and retain a way to intervene when something goes wrong.

Personal or business account?

Use this practical rule.

SituationReasonable choice
Public, synthetic or properly de-identified informationA personal account may be acceptable under company policy.
Ordinary internal information or personal information needed for workUse an approved business environment administered by the organization.
Sensitive information or consequential decisions about peopleConduct a specific assessment, impose stronger limits and obtain specialist advice where appropriate.

A paid personal plan remains a consumer product. Turning off model training is useful, but it does not answer every question about retention, processing location, human access, connected services, deletion or administration.

Business versions of ChatGPT, Claude and Gemini generally provide more appropriate terms and controls for company data. They do not make a deployment automatically compliant with Loi 25.

Five questions before using AI at work

An SMB can begin with a one-page record.

1. What are we trying to do?

Describe one task, such as polishing customer emails, summarizing meetings or drafting proposals.

2. What information will be exposed?

Identify personal, confidential and sensitive information. Remove anything the task does not require.

3. Which account and terms apply?

Check whether the account is personal or business, whether information is used for training, how long it is retained and where it may be processed.

4. What can the tool see and do?

Reading text pasted by an employee is different from accessing an entire inbox. Drafting is different from sending.

5. How do we regain control?

Define logging, access revocation, deletion, incident handling and accountability.

If the team cannot answer those five questions, it should not connect the tool to a complete system yet.

A simple access rule

Grant the minimum needed and increase access only after observing results.

  1. Public or synthetic: evaluation and training.
  2. Manually selected content: an employee chooses what to submit.
  3. Scoped read-only access: one folder or shared inbox.
  4. Draft with approval: the agent proposes and a person decides.
  5. Limited action: only reversible, logged and low-impact actions.

External messages, deletion, payments, permission changes, HR decisions and decisions materially affecting a person should remain subject to human approval.

Example: an email and calendar agent

An SMB wants to classify messages sent to info@company.ca, prepare replies and propose meeting times.

A realistic starting point would be:

  • an approved business account;
  • access only to the shared inbox;
  • limited message history;
  • no HR, legal or finance folders;
  • free-and-busy calendar access without meeting details;
  • permission to draft but not send;
  • human review of the recipient, content and attachments;
  • and rapid access revocation.

The business documents this workflow once. After a few weeks, it reviews quality, errors and time savings. It can then decide whether one reversible action deserves automation.

Three understandable data zones

Green: public, synthetic or properly de-identified information. Allowed in approved tools.

Yellow: ordinary customer emails, contact details and necessary internal information. Business account, scoped access and retention rules.

Red: HR records, health information, identity documents, passwords, detailed financial information, privileged communications or consequential decisions. Keep these out of a general-purpose tool by default.

This classification is imperfect. It is still more useful than a 30-page policy nobody reads.

A realistic five-step approach

  1. Acknowledge the tools employees already use.
  2. Approve a small number of business environments.
  3. Create a reusable workflow assessment.
  4. Define green, yellow and red information.
  5. Begin with read-only access or drafts before granting actions.

Perfect compliance before any experimentation is not realistic for most SMBs. Documented, proportionate and controlled progress is more credible than a ban employees will work around.

Frequently asked questions

Is a PIA required every time someone uses an AI feature?

No. Assess the project or recurring workflow, then reuse that assessment while the provider, information, access and actions remain materially the same. Review it after a significant change.

Can a simple Gmail writing feature be covered?

Yes, if it processes personal information as part of a new information system or communicates that information outside Quebec. That does not mean a new document for every message. It means the business should assess and govern the feature before making it a normal work practice.

Is a business account enough?

No. It is a better starting point. The business still needs to understand the information, retention, processing locations, access and permitted actions.

Can a personal account be used for work?

It can be reasonable for public, synthetic or properly de-identified information if company policy permits it. An approved business environment is more appropriate for personal or confidential information.

How far should automation go?

Begin with reading, summarizing and drafting. Grant action only when it is limited, reversible, logged and low impact. Keep human approval for everything else.

Use AI without looking away

SMBs will not stop using AI. They need a simple way to use it without giving tools unrestricted access to company information and systems.

A clear one-page record, a few approved tools, minimum access and measured progression can accomplish more than a theoretical policy.

Nord Paradigm helps Canadian SMBs turn these principles into workable operating practices. Explore our AI Implementation Partnership or book a conversation.

Official sources

This article provides general operational guidance. It is not legal advice.

← Back to all articles