Three requirements decide whether a Quebec biometric rollout is lawful. The collection has to be necessary, and the Commission d'accès à l'information has found that most biometric time clocks it has examined fail that test, which employee consent does not cure. The system has to be declared to the Commission before it is used, and at least 60 days before a database of biometric characteristics goes into service. And consent has to be express, so biometrics cannot be imposed and anyone who refuses needs another way to prove who they are.
On the dates: the express-consent rule and the protections around it have been law since 2001. What changed on 22 September 2022 is the prior declaration to the Commission and the 60-day database deadline. The regulator is Quebec's CAI, not the federal Office of the Privacy Commissioner of Canada.
This article is for general information and is not legal advice. Confirm obligations with qualified counsel.
A fingerprint reader at the plant door or a face-recognition clock on the warehouse floor is a regulatory filing in Quebec, not just a hardware purchase. The obligation runs both ways: the Commission d'accès à l'information has to hear about the system before anyone uses it, and it can suspend the launch, dictate how the database is built, or order the data destroyed[1].
Where the biometric rules actually live
Law 25 is the Act to modernize legislative provisions as regards the protection of personal information, 2021 chapter 25, introduced to the National Assembly as Bill 64[2]. Searching for the biometric rules inside its text is a dead end, because they are not there. Law 25 works by amending other statutes, and the two sections that govern workplace biometrics are sections 44 and 45 of the Act to establish a legal framework for information technology, a 2001 law about electronic documents[1]. Sections 80 and 81 of Law 25 are the amendments that put them in their current form[2].
The general privacy duties sit in a third statute, the Act respecting the protection of personal information in the private sector[3]. A Quebec biometric deployment answers to all three at once.
The dates, which are not the ones usually quoted
Law 25 was assented to on 22 September 2021, and that date is widely repeated as the day the law took effect. It is not. Section 175 sets 22 September 2023 as the default date for the Act's provisions and then carves out four groups of exceptions, and only five narrow provisions started on assent[2].
| Date | What started |
|---|---|
| 22 September 2021 | Assent. Five provisions in force: section 41 paragraph 2, and sections 73, 157, 172 and 173. |
| 22 September 2022 | The two biometric amendments, sections 80 and 81. Also the duty to appoint and publish a person in charge of the protection of personal information, and confidentiality incident reporting. |
| 22 September 2023 | The default date for everything else, including the mandatory privacy impact assessment, the governance policies duty, the penalty regime, and punitive damages. |
| 22 September 2024 | Data portability, the right to receive your computerized information in a structured, commonly used technological format. |
The 22 September 2022 date is narrower than it looks, and reading it as the start of the whole regime is the most common way to get this wrong. Express consent, the minimum-characteristics rule, the bar on covert capture, the purpose limit and the destruction duty have all been in force since 1 November 2001, in the original section 44. Disclosure of a biometric database to the Commission has been required since 2001 as well. What 22 September 2022 changed is two things: it inserted the prior-declaration requirement into section 44, and it attached the 60-day deadline to the database disclosure in section 45[1][2].
So an older system is not sitting outside the rules. Most of what applies to it has applied since 2001, and the Commission addresses the case directly: where a biometric time clock is already in place, the organization has to satisfy itself that the installation complies with the legislation[7].
Before any filing: the collection has to be necessary
This is the requirement that decides most Quebec biometric projects, and it is the one an implementation plan is least likely to have documented. Section 5 of the private sector Act allows collection of only the information necessary for the purposes determined before collecting it[3]. For biometrics the Commission has published what that means in the specific case of time and attendance, in a findings document on biometric time clocks and punch clocks[7].
Its headline conclusion is not a warning about edge cases. Having analysed biometric time clocks through investigations and through the database declarations it receives, the Commission concluded that most of the time, the use of biometric time clocks does not comply with the applicable legislation[7].
The test it applies has two parts. The purpose has to be important, legitimate and real, meaning it addresses a documented problem rather than an anticipated one, and the importance of that problem has to justify collecting information this sensitive. And the collection has to be proportionate: an effective means of achieving the purpose, chosen only after less intrusive means have been considered, with benefits that outweigh the intrusion on employees[7].
What makes this document unusually useful is that the Commission lists the justifications it has seen and found insufficient. Better payroll management, replacing an obsolete system, automation, reducing human error, more accurate hours, standardising on the same system as other branches, and avoiding lost or broken magnetic cards are described as ordinary management objectives that generally do not reach the level of importance required. Preventing time theft does not either, where the problem is merely anticipated rather than real and documented. On proportionality it observes that another automated system that collects no biometric information can be just as effective and considerably less intrusive[7].
That is the Commission's own emphasis, and it reverses the order most projects work in. A signed consent form is not the foundation of a lawful biometric deployment. It is one requirement among several, and it does nothing at all if the necessity analysis was never done or does not hold. The Commission's finding is that in the vast majority of the cases it examined, the analysis had not been carried out rigorously and the problem the system was meant to solve had rarely been documented[7].
The two filings the Commission has to receive
This is the obligation most often missing from biometrics checklists, and it is the one with a hard deadline attached.
Using biometrics to verify identity at all. Section 44 states that a person's identity "may not be verified or confirmed by means of a process that allows biometric characteristics or measurements to then be used except where such verification or confirmation has been previously disclosed to the Commission d'accès à l'information and except with the express consent of the person concerned"[1]. That prior-disclosure requirement is what section 80 of Law 25 inserted, in force 22 September 2022[2]. The Commission's guide for organizations puts the timing plainly: the declaration goes in before the system or process is brought into service[5].
Creating a database of biometric characteristics. Section 45 requires that creation "be disclosed to the Commission d'accès à l'information promptly and not later than 60 days before it is brought into service"[1]. Section 81 of Law 25 replaced that first paragraph, and it is worth being exact about what changed, because the direction is the opposite of what a reader might assume. The 2001 version already required the disclosure to be made beforehand, and it carried a second duty the current text does not: the existence of such a database had to be disclosed whether or not it was in service. What the 2001 version lacked was a lead time. The replacement dropped the existing-database duty and put a number on the timing instead, which is the 60 days quoted above[1][2]. The Commission calls the 60 days a new deadline in its summary of what Law 25 changed[6]. A deployment that enrols and stores a template for each employee builds such a database, so in practice both filings apply and the 60 days is the one that sets the project timeline. That last step is our reading of a common setup, not a Commission ruling on your system. Whether a given architecture creates a database of biometric characteristics is a question the declaration form asks you to describe, and the answer decides which deadline governs.
The Commission publishes a declaration form for this. Every field on it is mandatory, and it asks whether the organization's person in charge of the protection of personal information was consulted about the project[7]. Two things about what comes back are worth knowing before anyone treats the filing as a formality. The Commission sends an acknowledgement of receipt, and it states in its own guide that this acknowledgement "in no way means that the Commission approves or authorizes your biometric project in whole or in part"[5]. And under section 45 the Commission may make orders determining how a database is set up, used, consulted, released and retained, may suspend or prohibit bringing it into service, and may order its destruction[1].
The authority here is provincial. Quebec's Commission d'accès à l'information is the body that receives the declaration and can stop the deployment[1][8]. The federal Office of the Privacy Commissioner of Canada administers a different statute and is not where these filings go.
The filing is also checkable from the other side. The Commission's page for employees tells them they may contact it to find out whether their employer declared its biometric system, and points them to a complaint form if the law is not being followed[8]. An undeclared system is therefore not a quiet gap. It is a question any enrolled employee can have answered.
Express consent, and a working way to say no
Section 44 permits biometric identity verification only with the express consent of the person concerned[1]. The Commission reads that as a prohibition on requiring biometrics at all, and draws a consequence employers have to build for: there must be an alternative way to verify or confirm identity for anyone who refuses to consent, or who consents and later withdraws. Its guide names access cards, single-use tokens, and a password or identification code as examples, and says the people concerned should suffer no pressure and no inconvenience over that choice[5]. On the page it writes for employees, the Commission puts it as a right: an employer cannot require identification by a biometric characteristic, the choice has to be free, consent can be withdrawn at any time, and in those cases the employer must allow another means of identification[8].
Section 44 also bars using biometric characteristics that could be captured without the person's knowledge, which the Commission reads as requiring collection directly from the person concerned rather than from a camera feed or a third party[1][5].
What makes consent valid comes from the private sector Act. Section 14 requires consent that is clear, free and informed, given for specific purposes, requested separately for each purpose, in clear and simple language, and presented separately from any other information when it is requested in writing. It is valid only for the time necessary to achieve those purposes, and consent that does not meet the section is without effect[3]. The Commission's guide adds that a signature is the surest way to express consent and to be able to account for having obtained it, and its employer checklist asks for consent that is manifest and express in writing, free, informed, specific and limited in time. It publishes a model consent form and suggests employees compare the one they are handed against it[5][8].
Biometric information is sensitive as a matter of statute, not just as a matter of judgment. Section 12 defines personal information as sensitive "if, due to its nature, in particular its medical, biometric or otherwise intimate nature, or the context of its use or communication, it entails a high level of reasonable expectation of privacy." Consent to use sensitive information for a purpose other than the one it was collected for must be express, and section 13 requires express consent to communicate it to a third person[3].
Collect the minimum, and use it for nothing else
Section 44 limits an employer to "only the minimum number of characteristics or measurements needed to link the person to an act." The Commission's illustration is direct: if one fingerprint identifies the person, do not collect ten[1][5]. Section 5 of the private sector Act runs parallel, allowing collection of only the information necessary for purposes determined before collecting it[3].
The purpose limit in section 44 is stricter than a general data-minimization principle. No other information revealed by the characteristics recorded "may be used as a basis for a decision concerning the person or for any other purpose whatsoever," and such information may be disclosed only to the person concerned, at that person's request[1]. A face template enrolled to confirm who clocked in cannot be turned into an input for anything else, however useful the by-product looks.
The privacy impact assessment is mandatory, and there are two of them
Section 3.3 requires an enterprise to conduct a privacy impact assessment for "any project to acquire, develop or overhaul an information system or electronic service delivery system involving the collection, use, communication, keeping or destruction of personal information," and to consult the person in charge of the protection of personal information from the outset of the project. The assessment must be proportionate to the sensitivity of the information, the purposes, the quantity and distribution of the information, and the medium it is stored on[3]. That section fell under Law 25's default date and took effect on 22 September 2023, which is also how the Commission's guide describes it[2][5].
The Commission connects the two itself. On its biometrics page it recommends carrying out the assessment from the beginning of a biometric project, and states in the same sentence that the assessment is mandatory for any project to acquire, develop or overhaul an information system or electronic service delivery system involving personal information[8]. A biometric time clock bought as a turnkey product is still an acquisition of such a system.
The second assessment is the one that catches cloud deployments. Section 17 requires a privacy impact assessment before personal information is communicated outside Quebec, weighing the sensitivity of the information, the purposes, the protection measures including contractual ones, and the legal framework of the destination state. The information may be communicated only if the assessment establishes that it would receive adequate protection, and the communication must be the subject of a written agreement reflecting the results. The same applies where a person or body outside Quebec is entrusted with collecting, using, communicating or keeping the information on the enterprise's behalf[3].
Consent is not the mechanism for a cross-border transfer under section 17. An assessment and a written agreement are. A biometric vendor hosting templates in a data centre outside the province puts the employer inside this section, whether or not employees have signed anything.
Destruction, not a retention period
The instinct on any new data type is to set a retention period. For biometrics in Quebec that is the wrong frame. Section 44 requires that the record of the characteristics or measurements and any notation relating to it "be destroyed as soon as the purpose of verification or confirmation of identity has been met or the reason for the verification or confirmation no longer exists"[1]. Section 23 of the private sector Act requires destruction or anonymization once the purposes are achieved, subject to any preservation period provided for by an Act[3].
The Commission spells out what that means operationally. The duty covers the data whether it is held raw or converted to a code, it covers every existing copy, and it extends to any third party providing services that involve access to the biometric information. Because the information is sensitive, the method has to be definitive and irreversible, and the storage media that held it should be wiped so nothing can be recovered. The Commission treats an employee leaving or withdrawing consent as a point at which the purpose has ended[5][8].
The practical test is whether a departing employee's template is gone from the vendor's environment as well as yours, and whether you can show it.
What employees have to be told, and what they can ask for
Section 8 requires that a person be told, at the time of collection and afterward on request, the purposes of the collection, the means used, their rights of access and rectification, and their right to withdraw consent to the communication or use of the information. Where applicable they must also be told the categories of third persons the information will be communicated to and the possibility that it could be communicated outside Quebec. On request they must be told what was collected, who inside the enterprise can access it, how long it will be kept, and how to reach the person in charge of the protection of personal information[3].
On rights, the common formulation of access, rectification and deletion overstates the third one. Section 27 gives a right of access and section 28 a right of rectification, both exercised by written request to the person in charge under section 30[3]. There is no general right to demand deletion of personal information. Section 28.1 provides for ceasing dissemination or de-indexing a hyperlink, but only where dissemination contravenes the law or a court order, or where three cumulative conditions about serious injury and the public interest are met[3]. What actually removes an employee's biometric template is the employer's own destruction duty under section 44, triggered by the purpose ending, not a deletion request.
Security, governance and the people named on your website
Section 10 requires security measures that are "reasonable given the sensitivity of the information, the purposes for which it is to be used, the quantity and distribution of the information and the medium on which it is stored"[3]. Because biometric information is sensitive by statutory definition, that proportionality clause sets the bar high rather than leaving it open. The Commission's guide points at data format, storage medium, server location, privacy-enhancing technologies, access logging with review for anomalies, and strict contractual terms with any third party that touches the data[5].
Three governance duties sit alongside it. Section 3.1 places responsibility with the person exercising the highest authority in the enterprise, who holds the function of person in charge of the protection of personal information and may delegate it in writing, and requires that person's title and contact information to be published on the enterprise's website. Section 3.2 requires governance policies and practices covering the keeping and destruction of information, the roles of personnel across its life cycle, and a complaints process, with detailed information about them published in simple and clear language. Section 3.5 requires reasonable measures after a confidentiality incident, and prompt notification of the Commission and of the people concerned where there is a risk of serious injury[3]. Section 3.1 and section 3.5 have been in force since 22 September 2022; section 3.2 since 22 September 2023[2].
What it costs to get wrong
Two tracks, both in force since 22 September 2023[2]. Monetary administrative penalties are imposed by a person designated by the Commission, and section 90.12 caps them at $50,000 for a natural person and, in all other cases, at "$10,000,000 or, if greater, the amount corresponding to 2% of worldwide turnover for the preceding fiscal year." Penal proceedings run separately: section 91 makes collecting, using, communicating, keeping or destroying personal information in contravention of the law an offence, punishable by a fine of $5,000 to $100,000 for a natural person and, in all other cases, $15,000 to $25,000,000, "or, if greater, the amount corresponding to 4% of worldwide turnover for the preceding fiscal year." Fines are doubled for a subsequent offence under section 92.1[3].
There is a private track as well. Section 93.1 requires a court to award punitive damages of not less than $1,000 where an unlawful infringement of a right conferred by the Act causes injury and the infringement is intentional or results from a gross fault[3].
Those figures are ceilings, and quoting them alone overstates what a real penalty looks like. Section 90.2 requires the Commission to publish a general framework for applying monetary administrative penalties, and it did so on 11 May 2023. The framework sorts a breach into one of four severity categories, from a minor administrative lapse with no or minor consequence up to a very serious breach whose consequence is major, real or irreparable, then applies a base amount by category and adjusts it up or down using aggravating and mitigating factors, one of which is the sensitivity of the information involved[8].
| Severity category | Base amount, natural person | Base amount, all other cases |
|---|---|---|
| A, minor | $500 | $1,000 |
| B, moderate | $1,500 | $4,000 |
| C, serious | $3,000 | $8,000 |
| D, very serious | $5,000 | $15,000 |
The base amount is where the calculation starts, not where it ends, and the framework states that the amount set can never exceed the statutory maximum[8]. Still, for an enterprise the published starting range is $1,000 to $15,000, which is a more useful number to plan against than $10,000,000.
Not published: an amount attached to any specific breach. The framework says plainly that the private sector Act sets no fixed amount for a monetary administrative penalty, and its categories turn on severity rather than on which obligation was broken, so nothing maps a biometrics failure to a figure[8]. The Commission d'accès à l'information is the authority to ask.
One limit on all of the above is worth stating, because it changes who you ask about what. The monetary and penal provisions quoted here are in the private sector Act. The Act to establish a legal framework for information technology, where the biometric declaration and consent rules live, contains no fine of its own: its consequence is the Commission's power to order how a database is built, to suspend or prohibit bringing it into service, and to order its destruction[1]. The penalty sections reach conduct carried out "in contravention of the law" rather than in contravention of that Act specifically[3], and the Commission's penalty framework is written throughout around breaches of the private sector Act[8]. Whether a missed declaration is itself a monetary-penalty matter is not stated either way, in the statutes or in the Commission's published guidance. What is not in doubt is that a biometric deployment which fails the necessity test is collecting personal information in contravention of the law, and that is squarely inside both penalty tracks.
The sequence for a Quebec rollout
| Step | What it requires | Authority |
|---|---|---|
| Test necessity, and document it | Show the purpose is important, legitimate and answers a real documented problem, then show biometrics are proportionate and that less intrusive means were genuinely evaluated. Ordinary payroll-efficiency reasons do not clear the bar. Consent does not substitute for this step. | P-39.1 s. 5; CAI findings on biometric time clocks[3][5][4] |
| Run the assessment | A privacy impact assessment for the system, with the person in charge consulted from the outset. A second one before any transfer outside Quebec, plus a written agreement. | P-39.1 ss. 3.3, 17[3] |
| Declare to the CAI | Before use for identity verification. At least 60 days before a biometric database is brought into service. Every field on the Commission's form is mandatory. | C-1.1 ss. 44, 45[1][7] |
| Obtain express consent | Per person, per purpose, in clear language, documented. A signature is the Commission's recommended form. | C-1.1 s. 44; P-39.1 s. 14[1][3][5] |
| Stand up the alternative | A non-biometric way to verify identity, available without penalty to anyone who refuses or withdraws consent. | C-1.1 s. 44, as read by the CAI[5] |
| Destroy on purpose end | All copies, raw or encoded, including at any third party, by a definitive and irreversible method. | C-1.1 s. 44; P-39.1 s. 23[1][3][5] |
| Publish the governance | The person in charge and their contact information, and the governance policies, on the enterprise's website. | P-39.1 ss. 3.1, 3.2[3] |
Where this lands in a time and attendance build
Read the Commission's findings closely and the practical conclusion for Quebec is not about how to file the paperwork for a biometric clock. It is that the proportionality test is hard to pass when a non-biometric method achieves the same operational result, because the Commission says so in as many words: another automated system that collects no biometric information can be just as effective and much less intrusive[4]. Verified time capture and biometric time capture are not the same requirement, and only one of them carries this burden.
WorkAxle's time and attendance module treats identity verification as a set of methods rather than a single one. Desktop clock-in, mobile clock-in with geofencing, and Bluetooth beacons that confirm an employee is physically on the assigned site all verify a punch without capturing a biometric characteristic. Facial recognition exists as an option on kiosk and tablet clock-in, and in Quebec it is exactly that, an option carrying its own necessity analysis, its own declaration and its own consent record. A site can run on the non-biometric methods alone and still get a verified, location-validated punch on the same roster and the same timecard export as everywhere else. Where an operation does conclude that biometrics are necessary, the necessity analysis, the filings with the Commission, the consent and the alternative for anyone who refuses remain the employer's obligations, not the vendor's.