Law 25 (Bill 64): What Quebec Employers Need to Know if Planning to Implement Biometrics in their Businesses

Before a fingerprint reader or a face-recognition clock goes live in Quebec, it has to be declared to the Commission d'accès à l'information. Here is what the law requires, and when each requirement started.

WX
WorkAxle
Field Notes · WorkAxle
TL;DR

Three requirements decide whether a Quebec biometric rollout is lawful. The collection has to be necessary, and the Commission d'accès à l'information has found that most biometric time clocks it has examined fail that test, which employee consent does not cure. The system has to be declared to the Commission before it is used, and at least 60 days before a database of biometric characteristics goes into service. And consent has to be express, so biometrics cannot be imposed and anyone who refuses needs another way to prove who they are.

On the dates: the express-consent rule and the protections around it have been law since 2001. What changed on 22 September 2022 is the prior declaration to the Commission and the 60-day database deadline. The regulator is Quebec's CAI, not the federal Office of the Privacy Commissioner of Canada.

A fingerprint reader at the plant door or a face-recognition clock on the warehouse floor is a regulatory filing in Quebec, not just a hardware purchase. The obligation runs both ways: the Commission d'accès à l'information has to hear about the system before anyone uses it, and it can suspend the launch, dictate how the database is built, or order the data destroyed[1].

Not legal advice. This post summarizes obligations that apply to Quebec employers using biometrics, as a general reference. It does not constitute legal advice. Consult qualified legal counsel before implementing any biometric system.

Where the biometric rules actually live

Law 25 is the Act to modernize legislative provisions as regards the protection of personal information, 2021 chapter 25, introduced to the National Assembly as Bill 64[2]. Searching for the biometric rules inside its text is a dead end, because they are not there. Law 25 works by amending other statutes, and the two sections that govern workplace biometrics are sections 44 and 45 of the Act to establish a legal framework for information technology, a 2001 law about electronic documents[1]. Sections 80 and 81 of Law 25 are the amendments that put them in their current form[2].

The general privacy duties sit in a third statute, the Act respecting the protection of personal information in the private sector[3]. A Quebec biometric deployment answers to all three at once.

The dates, which are not the ones usually quoted

Law 25 was assented to on 22 September 2021, and that date is widely repeated as the day the law took effect. It is not. Section 175 sets 22 September 2023 as the default date for the Act's provisions and then carves out four groups of exceptions, and only five narrow provisions started on assent[2].

DateWhat started
22 September 2021 Assent. Five provisions in force: section 41 paragraph 2, and sections 73, 157, 172 and 173.
22 September 2022 The two biometric amendments, sections 80 and 81. Also the duty to appoint and publish a person in charge of the protection of personal information, and confidentiality incident reporting.
22 September 2023 The default date for everything else, including the mandatory privacy impact assessment, the governance policies duty, the penalty regime, and punitive damages.
22 September 2024 Data portability, the right to receive your computerized information in a structured, commonly used technological format.

The 22 September 2022 date is narrower than it looks, and reading it as the start of the whole regime is the most common way to get this wrong. Express consent, the minimum-characteristics rule, the bar on covert capture, the purpose limit and the destruction duty have all been in force since 1 November 2001, in the original section 44. Disclosure of a biometric database to the Commission has been required since 2001 as well. What 22 September 2022 changed is two things: it inserted the prior-declaration requirement into section 44, and it attached the 60-day deadline to the database disclosure in section 45[1][2].

So an older system is not sitting outside the rules. Most of what applies to it has applied since 2001, and the Commission addresses the case directly: where a biometric time clock is already in place, the organization has to satisfy itself that the installation complies with the legislation[7].

Before any filing: the collection has to be necessary

This is the requirement that decides most Quebec biometric projects, and it is the one an implementation plan is least likely to have documented. Section 5 of the private sector Act allows collection of only the information necessary for the purposes determined before collecting it[3]. For biometrics the Commission has published what that means in the specific case of time and attendance, in a findings document on biometric time clocks and punch clocks[7].

Its headline conclusion is not a warning about edge cases. Having analysed biometric time clocks through investigations and through the database declarations it receives, the Commission concluded that most of the time, the use of biometric time clocks does not comply with the applicable legislation[7].

The test it applies has two parts. The purpose has to be important, legitimate and real, meaning it addresses a documented problem rather than an anticipated one, and the importance of that problem has to justify collecting information this sensitive. And the collection has to be proportionate: an effective means of achieving the purpose, chosen only after less intrusive means have been considered, with benefits that outweigh the intrusion on employees[7].

What makes this document unusually useful is that the Commission lists the justifications it has seen and found insufficient. Better payroll management, replacing an obsolete system, automation, reducing human error, more accurate hours, standardising on the same system as other branches, and avoiding lost or broken magnetic cards are described as ordinary management objectives that generally do not reach the level of importance required. Preventing time theft does not either, where the problem is merely anticipated rather than real and documented. On proportionality it observes that another automated system that collects no biometric information can be just as effective and considerably less intrusive[7].

Where an organization has not demonstrated that the information is necessary, collecting it, and therefore using it, is prohibited by law even if it has obtained employee consent.[7]

That is the Commission's own emphasis, and it reverses the order most projects work in. A signed consent form is not the foundation of a lawful biometric deployment. It is one requirement among several, and it does nothing at all if the necessity analysis was never done or does not hold. The Commission's finding is that in the vast majority of the cases it examined, the analysis had not been carried out rigorously and the problem the system was meant to solve had rarely been documented[7].

The two filings the Commission has to receive

This is the obligation most often missing from biometrics checklists, and it is the one with a hard deadline attached.

Using biometrics to verify identity at all. Section 44 states that a person's identity "may not be verified or confirmed by means of a process that allows biometric characteristics or measurements to then be used except where such verification or confirmation has been previously disclosed to the Commission d'accès à l'information and except with the express consent of the person concerned"[1]. That prior-disclosure requirement is what section 80 of Law 25 inserted, in force 22 September 2022[2]. The Commission's guide for organizations puts the timing plainly: the declaration goes in before the system or process is brought into service[5].

Creating a database of biometric characteristics. Section 45 requires that creation "be disclosed to the Commission d'accès à l'information promptly and not later than 60 days before it is brought into service"[1]. Section 81 of Law 25 replaced that first paragraph, and it is worth being exact about what changed, because the direction is the opposite of what a reader might assume. The 2001 version already required the disclosure to be made beforehand, and it carried a second duty the current text does not: the existence of such a database had to be disclosed whether or not it was in service. What the 2001 version lacked was a lead time. The replacement dropped the existing-database duty and put a number on the timing instead, which is the 60 days quoted above[1][2]. The Commission calls the 60 days a new deadline in its summary of what Law 25 changed[6]. A deployment that enrols and stores a template for each employee builds such a database, so in practice both filings apply and the 60 days is the one that sets the project timeline. That last step is our reading of a common setup, not a Commission ruling on your system. Whether a given architecture creates a database of biometric characteristics is a question the declaration form asks you to describe, and the answer decides which deadline governs.

The Commission publishes a declaration form for this. Every field on it is mandatory, and it asks whether the organization's person in charge of the protection of personal information was consulted about the project[7]. Two things about what comes back are worth knowing before anyone treats the filing as a formality. The Commission sends an acknowledgement of receipt, and it states in its own guide that this acknowledgement "in no way means that the Commission approves or authorizes your biometric project in whole or in part"[5]. And under section 45 the Commission may make orders determining how a database is set up, used, consulted, released and retained, may suspend or prohibit bringing it into service, and may order its destruction[1].

60
Days of advance notice a biometric database owes the Commission d'accès à l'information before it can be brought into service, under section 45[1].

The authority here is provincial. Quebec's Commission d'accès à l'information is the body that receives the declaration and can stop the deployment[1][8]. The federal Office of the Privacy Commissioner of Canada administers a different statute and is not where these filings go.

The filing is also checkable from the other side. The Commission's page for employees tells them they may contact it to find out whether their employer declared its biometric system, and points them to a complaint form if the law is not being followed[8]. An undeclared system is therefore not a quiet gap. It is a question any enrolled employee can have answered.

Express consent, and a working way to say no

Section 44 permits biometric identity verification only with the express consent of the person concerned[1]. The Commission reads that as a prohibition on requiring biometrics at all, and draws a consequence employers have to build for: there must be an alternative way to verify or confirm identity for anyone who refuses to consent, or who consents and later withdraws. Its guide names access cards, single-use tokens, and a password or identification code as examples, and says the people concerned should suffer no pressure and no inconvenience over that choice[5]. On the page it writes for employees, the Commission puts it as a right: an employer cannot require identification by a biometric characteristic, the choice has to be free, consent can be withdrawn at any time, and in those cases the employer must allow another means of identification[8].

Section 44 also bars using biometric characteristics that could be captured without the person's knowledge, which the Commission reads as requiring collection directly from the person concerned rather than from a camera feed or a third party[1][5].

What makes consent valid comes from the private sector Act. Section 14 requires consent that is clear, free and informed, given for specific purposes, requested separately for each purpose, in clear and simple language, and presented separately from any other information when it is requested in writing. It is valid only for the time necessary to achieve those purposes, and consent that does not meet the section is without effect[3]. The Commission's guide adds that a signature is the surest way to express consent and to be able to account for having obtained it, and its employer checklist asks for consent that is manifest and express in writing, free, informed, specific and limited in time. It publishes a model consent form and suggests employees compare the one they are handed against it[5][8].

Biometric information is sensitive as a matter of statute, not just as a matter of judgment. Section 12 defines personal information as sensitive "if, due to its nature, in particular its medical, biometric or otherwise intimate nature, or the context of its use or communication, it entails a high level of reasonable expectation of privacy." Consent to use sensitive information for a purpose other than the one it was collected for must be express, and section 13 requires express consent to communicate it to a third person[3].

Collect the minimum, and use it for nothing else

Section 44 limits an employer to "only the minimum number of characteristics or measurements needed to link the person to an act." The Commission's illustration is direct: if one fingerprint identifies the person, do not collect ten[1][5]. Section 5 of the private sector Act runs parallel, allowing collection of only the information necessary for purposes determined before collecting it[3].

The purpose limit in section 44 is stricter than a general data-minimization principle. No other information revealed by the characteristics recorded "may be used as a basis for a decision concerning the person or for any other purpose whatsoever," and such information may be disclosed only to the person concerned, at that person's request[1]. A face template enrolled to confirm who clocked in cannot be turned into an input for anything else, however useful the by-product looks.

The privacy impact assessment is mandatory, and there are two of them

Section 3.3 requires an enterprise to conduct a privacy impact assessment for "any project to acquire, develop or overhaul an information system or electronic service delivery system involving the collection, use, communication, keeping or destruction of personal information," and to consult the person in charge of the protection of personal information from the outset of the project. The assessment must be proportionate to the sensitivity of the information, the purposes, the quantity and distribution of the information, and the medium it is stored on[3]. That section fell under Law 25's default date and took effect on 22 September 2023, which is also how the Commission's guide describes it[2][5].

The Commission connects the two itself. On its biometrics page it recommends carrying out the assessment from the beginning of a biometric project, and states in the same sentence that the assessment is mandatory for any project to acquire, develop or overhaul an information system or electronic service delivery system involving personal information[8]. A biometric time clock bought as a turnkey product is still an acquisition of such a system.

The second assessment is the one that catches cloud deployments. Section 17 requires a privacy impact assessment before personal information is communicated outside Quebec, weighing the sensitivity of the information, the purposes, the protection measures including contractual ones, and the legal framework of the destination state. The information may be communicated only if the assessment establishes that it would receive adequate protection, and the communication must be the subject of a written agreement reflecting the results. The same applies where a person or body outside Quebec is entrusted with collecting, using, communicating or keeping the information on the enterprise's behalf[3].

Consent is not the mechanism for a cross-border transfer under section 17. An assessment and a written agreement are. A biometric vendor hosting templates in a data centre outside the province puts the employer inside this section, whether or not employees have signed anything.

Destruction, not a retention period

The instinct on any new data type is to set a retention period. For biometrics in Quebec that is the wrong frame. Section 44 requires that the record of the characteristics or measurements and any notation relating to it "be destroyed as soon as the purpose of verification or confirmation of identity has been met or the reason for the verification or confirmation no longer exists"[1]. Section 23 of the private sector Act requires destruction or anonymization once the purposes are achieved, subject to any preservation period provided for by an Act[3].

The Commission spells out what that means operationally. The duty covers the data whether it is held raw or converted to a code, it covers every existing copy, and it extends to any third party providing services that involve access to the biometric information. Because the information is sensitive, the method has to be definitive and irreversible, and the storage media that held it should be wiped so nothing can be recovered. The Commission treats an employee leaving or withdrawing consent as a point at which the purpose has ended[5][8].

The practical test is whether a departing employee's template is gone from the vendor's environment as well as yours, and whether you can show it.

What employees have to be told, and what they can ask for

Section 8 requires that a person be told, at the time of collection and afterward on request, the purposes of the collection, the means used, their rights of access and rectification, and their right to withdraw consent to the communication or use of the information. Where applicable they must also be told the categories of third persons the information will be communicated to and the possibility that it could be communicated outside Quebec. On request they must be told what was collected, who inside the enterprise can access it, how long it will be kept, and how to reach the person in charge of the protection of personal information[3].

On rights, the common formulation of access, rectification and deletion overstates the third one. Section 27 gives a right of access and section 28 a right of rectification, both exercised by written request to the person in charge under section 30[3]. There is no general right to demand deletion of personal information. Section 28.1 provides for ceasing dissemination or de-indexing a hyperlink, but only where dissemination contravenes the law or a court order, or where three cumulative conditions about serious injury and the public interest are met[3]. What actually removes an employee's biometric template is the employer's own destruction duty under section 44, triggered by the purpose ending, not a deletion request.

Security, governance and the people named on your website

Section 10 requires security measures that are "reasonable given the sensitivity of the information, the purposes for which it is to be used, the quantity and distribution of the information and the medium on which it is stored"[3]. Because biometric information is sensitive by statutory definition, that proportionality clause sets the bar high rather than leaving it open. The Commission's guide points at data format, storage medium, server location, privacy-enhancing technologies, access logging with review for anomalies, and strict contractual terms with any third party that touches the data[5].

Three governance duties sit alongside it. Section 3.1 places responsibility with the person exercising the highest authority in the enterprise, who holds the function of person in charge of the protection of personal information and may delegate it in writing, and requires that person's title and contact information to be published on the enterprise's website. Section 3.2 requires governance policies and practices covering the keeping and destruction of information, the roles of personnel across its life cycle, and a complaints process, with detailed information about them published in simple and clear language. Section 3.5 requires reasonable measures after a confidentiality incident, and prompt notification of the Commission and of the people concerned where there is a risk of serious injury[3]. Section 3.1 and section 3.5 have been in force since 22 September 2022; section 3.2 since 22 September 2023[2].

What it costs to get wrong

Two tracks, both in force since 22 September 2023[2]. Monetary administrative penalties are imposed by a person designated by the Commission, and section 90.12 caps them at $50,000 for a natural person and, in all other cases, at "$10,000,000 or, if greater, the amount corresponding to 2% of worldwide turnover for the preceding fiscal year." Penal proceedings run separately: section 91 makes collecting, using, communicating, keeping or destroying personal information in contravention of the law an offence, punishable by a fine of $5,000 to $100,000 for a natural person and, in all other cases, $15,000 to $25,000,000, "or, if greater, the amount corresponding to 4% of worldwide turnover for the preceding fiscal year." Fines are doubled for a subsequent offence under section 92.1[3].

There is a private track as well. Section 93.1 requires a court to award punitive damages of not less than $1,000 where an unlawful infringement of a right conferred by the Act causes injury and the infringement is intentional or results from a gross fault[3].

Those figures are ceilings, and quoting them alone overstates what a real penalty looks like. Section 90.2 requires the Commission to publish a general framework for applying monetary administrative penalties, and it did so on 11 May 2023. The framework sorts a breach into one of four severity categories, from a minor administrative lapse with no or minor consequence up to a very serious breach whose consequence is major, real or irreparable, then applies a base amount by category and adjusts it up or down using aggravating and mitigating factors, one of which is the sensitivity of the information involved[8].

Severity categoryBase amount, natural personBase amount, all other cases
A, minor$500$1,000
B, moderate$1,500$4,000
C, serious$3,000$8,000
D, very serious$5,000$15,000

The base amount is where the calculation starts, not where it ends, and the framework states that the amount set can never exceed the statutory maximum[8]. Still, for an enterprise the published starting range is $1,000 to $15,000, which is a more useful number to plan against than $10,000,000.

Not published: an amount attached to any specific breach. The framework says plainly that the private sector Act sets no fixed amount for a monetary administrative penalty, and its categories turn on severity rather than on which obligation was broken, so nothing maps a biometrics failure to a figure[8]. The Commission d'accès à l'information is the authority to ask.

One limit on all of the above is worth stating, because it changes who you ask about what. The monetary and penal provisions quoted here are in the private sector Act. The Act to establish a legal framework for information technology, where the biometric declaration and consent rules live, contains no fine of its own: its consequence is the Commission's power to order how a database is built, to suspend or prohibit bringing it into service, and to order its destruction[1]. The penalty sections reach conduct carried out "in contravention of the law" rather than in contravention of that Act specifically[3], and the Commission's penalty framework is written throughout around breaches of the private sector Act[8]. Whether a missed declaration is itself a monetary-penalty matter is not stated either way, in the statutes or in the Commission's published guidance. What is not in doubt is that a biometric deployment which fails the necessity test is collecting personal information in contravention of the law, and that is squarely inside both penalty tracks.

The sequence for a Quebec rollout

StepWhat it requiresAuthority
Test necessity, and document it Show the purpose is important, legitimate and answers a real documented problem, then show biometrics are proportionate and that less intrusive means were genuinely evaluated. Ordinary payroll-efficiency reasons do not clear the bar. Consent does not substitute for this step. P-39.1 s. 5; CAI findings on biometric time clocks[3][5][4]
Run the assessment A privacy impact assessment for the system, with the person in charge consulted from the outset. A second one before any transfer outside Quebec, plus a written agreement. P-39.1 ss. 3.3, 17[3]
Declare to the CAI Before use for identity verification. At least 60 days before a biometric database is brought into service. Every field on the Commission's form is mandatory. C-1.1 ss. 44, 45[1][7]
Obtain express consent Per person, per purpose, in clear language, documented. A signature is the Commission's recommended form. C-1.1 s. 44; P-39.1 s. 14[1][3][5]
Stand up the alternative A non-biometric way to verify identity, available without penalty to anyone who refuses or withdraws consent. C-1.1 s. 44, as read by the CAI[5]
Destroy on purpose end All copies, raw or encoded, including at any third party, by a definitive and irreversible method. C-1.1 s. 44; P-39.1 s. 23[1][3][5]
Publish the governance The person in charge and their contact information, and the governance policies, on the enterprise's website. P-39.1 ss. 3.1, 3.2[3]

Where this lands in a time and attendance build

Read the Commission's findings closely and the practical conclusion for Quebec is not about how to file the paperwork for a biometric clock. It is that the proportionality test is hard to pass when a non-biometric method achieves the same operational result, because the Commission says so in as many words: another automated system that collects no biometric information can be just as effective and much less intrusive[4]. Verified time capture and biometric time capture are not the same requirement, and only one of them carries this burden.

WorkAxle's time and attendance module treats identity verification as a set of methods rather than a single one. Desktop clock-in, mobile clock-in with geofencing, and Bluetooth beacons that confirm an employee is physically on the assigned site all verify a punch without capturing a biometric characteristic. Facial recognition exists as an option on kiosk and tablet clock-in, and in Quebec it is exactly that, an option carrying its own necessity analysis, its own declaration and its own consent record. A site can run on the non-biometric methods alone and still get a verified, location-validated punch on the same roster and the same timecard export as everywhere else. Where an operation does conclude that biometrics are necessary, the necessity analysis, the filings with the Commission, the consent and the alternative for anyone who refuses remain the employer's obligations, not the vendor's.

Frequently asked.

Do Quebec employers have to notify the CAI before using biometrics?

Yes, and it is two separate filings. Section 44 of the Act to establish a legal framework for information technology prohibits verifying or confirming a person's identity by a process that captures biometric characteristics unless that verification has been previously disclosed to the Commission d'accès à l'information. Section 45 requires the creation of a database of biometric characteristics and measurements to be disclosed to the Commission promptly and not later than 60 days before it is brought into service.

The regulator is Quebec's Commission d'accès à l'information, not the federal Office of the Privacy Commissioner of Canada. The Commission publishes a declaration form and states that its acknowledgement of receipt does not approve or authorize the project.

What is Law 25 (Bill 64) in Quebec, and when did it take effect?

Law 25 is the Act to modernize legislative provisions as regards the protection of personal information, 2021 chapter 25, introduced as Bill 64. It was assented to on 22 September 2021, but only five narrow provisions came into force on that date. Section 175 sets 22 September 2023 as the default. The two biometric amendments, sections 80 and 81, took effect on 22 September 2022, and data portability on 22 September 2024.

The biometric rules are not in Law 25's own text. They are amendments Law 25 made to sections 44 and 45 of the Act to establish a legal framework for information technology.

Is biometric data considered sensitive personal information in Quebec?

Yes, by statutory definition. Section 12 of the Act respecting the protection of personal information in the private sector states that personal information is sensitive if, due to its nature, "in particular its medical, biometric or otherwise intimate nature," or the context of its use or communication, it entails a high level of reasonable expectation of privacy. Consent to use sensitive information beyond the purpose it was collected for must be express, and section 13 requires express consent to communicate it to a third person.

Can a Quebec employer require employees to use a biometric time clock?

No, and consent alone does not make it lawful either. Section 44 opens with the words that no one may require identity verification by a biometric process, permitting it only with the express consent of the person concerned. The Commission d'accès à l'information states that the employer must provide an alternative way to verify identity for anyone who refuses or later withdraws consent, and gives access cards, single-use tokens, and a password or identification code as examples.

Separately, in its published findings on biometric time clocks and punch clocks, the Commission concluded that most of the time their use does not comply with the applicable legislation, because the collection is not necessary within the meaning of the law. Where necessity has not been demonstrated, the collection is prohibited even if employee consent was obtained. Ordinary objectives such as better payroll management, automation, more accurate hours or avoiding lost access cards generally do not meet the required level of importance.

Is a privacy impact assessment mandatory before deploying biometrics in Quebec?

Section 3.3 of the private sector Act requires an enterprise to conduct a privacy impact assessment for any project to acquire, develop or overhaul an information system involving the collection, use, communication, keeping or destruction of personal information, and to consult the person in charge of the protection of personal information from the outset. That obligation took effect on 22 September 2023.

A second assessment is required by section 17 before any personal information is communicated outside Quebec, together with a written agreement. Consent is not the mechanism for a cross-border transfer.

What rights do employees have over their biometric data in Quebec?

Access under section 27 and rectification under section 28, both by written request to the person in charge of the protection of personal information. There is no general right to demand deletion.

What applies to biometrics instead is an employer duty. Section 44 requires the record of the characteristics or measurements to be destroyed as soon as the purpose of verification has been met or the reason for it no longer exists, and the Commission treats withdrawal of consent and the end of employment as points at which that duty is triggered. Section 28.1 allows de-indexation only where narrow statutory conditions are met.

Sources

  1. Gouvernement du Québec. Act to establish a legal framework for information technology, CQLR c. C-1.1, ss. 43, 44 and 45. legisquebec.gouv.qc.ca. Accessed 6 August 2026. Official consolidated text, up to date as of 1 April 2026. Sections 44 and 45 as amended by 2021, c. 25, ss. 80 and 81.
  2. Assemblée nationale du Québec. Loi modernisant des dispositions législatives en matière de protection des renseignements personnels (Bill 64 / Law 25), LQ 2021, c. 25, ss. 80, 81 and 175 (PDF). publicationsduquebec.gouv.qc.ca. Accessed 6 August 2026. Official annual statute as assented to on 22 September 2021. French only. Section 175 is the coming-into-force provision and is the source for every date in this post.
  3. Gouvernement du Québec. Act respecting the protection of personal information in the private sector, CQLR c. P-39.1, ss. 3.1, 3.2, 3.3, 3.5, 5, 8, 10, 12, 13, 14, 17, 23, 27, 28, 28.1, 30, 90.2, 90.12, 91, 92.1 and 93.1. legisquebec.gouv.qc.ca. Accessed 6 August 2026. Official consolidated text. Every quoted figure and phrase was read from this version.
  4. Commission d'accès à l'information du Québec. Horodateurs et pointeuses biométriques: constats, 27 March 2023 (PDF). cai.gouv.qc.ca. Accessed 6 August 2026. The Commission's findings from its investigations and from the biometric database declarations it has received, addressed specifically to time clocks and punch clocks. French only, so wording from it that appears in quotation marks above is a translation and not an official English text.
  5. Commission d'accès à l'information du Québec. Biométrie: principes à respecter et obligations légales des organisations, guide d'accompagnement, version 2.0, 21 September 2022 (PDF). cai.gouv.qc.ca. Accessed 6 August 2026. The regulator's own guidance, French only, so any wording from it that appears in quotation marks above is a translation and not an official English text. The guide states that it has no legal value and that the statutes prevail where they differ from it. It was published to cover the provisions in force in September 2022, so its references to the 2023 obligations are forward-looking.
  6. Commission d'accès à l'information du Québec. Principaux changements apportés par la Loi 25, biométrie section. cai.gouv.qc.ca. Accessed 6 August 2026. The Commission's summary of what Law 25 changed for biometrics, used to corroborate the two declaration triggers and the 60-day deadline against the statutory text.
  7. Commission d'accès à l'information du Québec. Formulaire de déclaration d'un système biométrique ou procédé permettant de saisir des caractéristiques ou des mesures biométriques, September 2022 (PDF). cai.gouv.qc.ca. Accessed 6 August 2026.
  8. Commission d'accès à l'information du Québec. Biométrie (topic page, with the declaration form, model consent form and guides). cai.gouv.qc.ca. Accessed 6 August 2026.
  9. Commission d'accès à l'information du Québec. Cadre général d'application des sanctions administratives pécuniaires, 11 May 2023 (PDF). cai.gouv.qc.ca. Accessed 6 August 2026. The framework required by P-39.1 s. 90.2. Sections 5.1 (severity categories), 5.2.1 (base amounts) and 5.2.2 (aggravating and mitigating factors). French only. It is written throughout around breaches of the private sector Act.
WX
WorkAxle Field Notes · WorkAxle

Analysis and perspective from the WorkAxle team on workforce management, compliance automation, and operational technology for shift-based enterprises.

More from this author

Get workforce management insights delivered.

One post every two weeks. Long-form analysis from the team that runs the platform. Written for operators, not for the marketing pipeline.

The Compliance Rule Engine.

See how WorkAxle enforces jurisdiction-specific labor rules, union agreements, and regulatory requirements at the point of scheduling.

Run the WFM Readiness Diagnostic.

Six inputs, one number, no email gate. A read on whether your current stack is built for prevention or for reporting.

See WorkAxle in action.

Bring your compliance requirements and your current stack. We will walk through how WorkAxle handles your jurisdiction's rules live.