Skip to main content
Agentica

Answer · financial operations automation

Is AI compliant with Québec’s Law 25 for a bookkeeping firm?

Law 25 applies to the firm, not to the tool: no software or AI is compliant by itself; the firm’s practices are. Agentica certifies nothing: it installs systems configured so a Québec bookkeeping firm can meet its obligations, with accountability staying with the firm’s own professionals.

Can a tool be “Law 25 compliant”?

No, and that is the honest starting point. Law 25, the Québec law that modernized the protection of personal information, places obligations on the organizations that collect and handle that information: it applies to the firm, not to the software the firm uses. A tool, AI included, is never compliant by itself; the firm’s practices are, or are not: how access is granted, how consent is obtained, how incidents are recorded. A vendor selling a product as “Law 25 compliant” is selling a shortcut that does not exist. Agentica certifies nothing and makes no one compliant; accountability stays with the firm and its own advisors. What a vendor can usefully do is install systems that make good practice possible, then document what is verifiable, so the firm’s own review has something solid to work with. The useful question is therefore not “is the tool compliant?” but “are our practices compliant, tool included?”.

What does Law 25 broadly require of a firm?

Broadly, and per the Commission d’accès à l’information du Québec (CAI), Law 25 asks an organization to designate a person responsible for the protection of personal information; to obtain valid consent for collecting and using that information; to put security measures in place proportionate to its sensitivity; and to keep a register of confidentiality incidents, with notification when an incident presents a serious risk of harm. That summary describes the terrain, not legal advice: the detailed obligations, and how they apply to one firm’s specific situation, are matters for the CAI and for the firm’s own advisors. The sound practice is simple: the firm’s designated responsible person evaluates every new tool, AI included, with those obligations in mind, and decides with the help of the firm’s own professionals rather than on a vendor’s word. None of this is exotic; it is the ordinary discipline of handling other people’s information, written into law.

What does Agentica install, relative to those obligations?

Agentica installs systems configured so the firm can meet its obligations, without ever claiming to meet them in the firm’s place. Concretely: access granted per employee, with individual accounts rather than a shared password, so “who can access what” has a clear answer; logging of system activity, so checking after the fact is possible; a data-protection sheet handed to the firm, stating who hosts each system, who can access what, what is logged, and that client data is never used to train AI; and interfaces that work fully in French, for the team and for its clients. After the setup, Agentica maintains, supports and extends those systems. Accountability does not move: it stays with the firm, its designated responsible person, and its professionals. That division of roles is not a disclaimer; it is how the law is built: the configuration is the vendor’s job, the practice is the firm’s.

What should a firm ask any AI vendor, with Law 25 in mind?

The useful questions are the ones whose answers can be verified in writing. Who hosts each system, and where is that documented? Who can access personal information, and is access individual? What is logged, and can the firm consult the logs? Is the data used to train AI, and where does the vendor publish that commitment? Does the interface work entirely in French, for the team and its clients? A serious vendor answers each of them with a document, not with a reassuring phrase. And the final decision never belongs to the vendor: the firm’s person responsible for the protection of personal information evaluates, with the firm’s advisors, whether the tool fits its practices. Agentica shows up to that examination with its data-protection sheet; it is exactly the examination a firm should put every one of its vendors through, and it keeps the burden of proof where it belongs: on the vendor.

Sources