How it works Demo Pricing Guides The science About Français Request the audit

Law 25 and AI assistants: the questions to ask before uploading your documents

Manent — July 7, 2026
General information, not legal advice — consult your advisor for your particular situation.

Law 25 (protection of personal information, Quebec) also applies when you entrust your documentation to an AI vendor. The surprise for most SMEs: the risk isn't in the machine manuals — it's in what slips into them. Here are the concrete questions to ask, and the answers a serious vendor must be able to give.

"Where is the personal information in MY documents?"

A typical technical corpus contains more than you'd think: memos with technicians' phone numbers, customer emails in after-sales histories, names in incident reports. Demand that the vendor detect them automatically on upload and let you decide — document by document, BEFORE any processing — whether to include or exclude them. The decision is yours; it must be traced.

"Is my data used to train a model?"

The acceptable answer is no, never — your documents serve to answer YOUR teams, period. Ask for it in writing, and also ask what is the case for the vendor's AI subprocessors (serious major API providers contractually commit not to train on customer data).

"Who else can see my data?"

No one: each customer must live in a strictly isolated workspace. The level above the contractual promise is isolation verified by the software itself — the system mechanically refuses to cross two customers, rather than relying on employee discipline.

"Can you erase a person's data?"

Law 25 grants rights of access and rectification to individuals. If a former employee asks what your systems know about them, your vendor must be able to search for and erase their information everywhere — including in interaction logs and backups — and provide you with the trace of the operation.

"Who accessed what, and when?"

Every administrative access, every decision and every expense must be logged. In the event of an incident, it is this log that lets you meet notification obligations — without it, you can neither assess the scope nor prove your diligence.

"And at the end of the contract?"

Your documents and the data produced are returned to you, then deleted from the vendor's systems. If the contract is silent on this, have it specified before signing, not after.

The short list to copy into your email

  1. Do you detect personal information on upload, and who decides its fate?
  2. Does my data train a model, at your company or your subprocessors'?
  3. How is isolation between customers guaranteed — contract or mechanism?
  4. Can you erase a person's data, backups included?
  5. Do you provide an access log usable in the event of an incident?
  6. What becomes of all this at the end of the contract?

These six questions are exactly the ones Manent was designed with the right default answers for — PII detection on upload, traced customer decision, isolation verified by the engine, erasure per person, complete log.

Read our privacy policy