Two sentences come up again and again when we work with a small business on its website and web tools or on an AI agent. The first: "We want to keep our old customer history for statistics, we'll just anonymize it." The second: "We'll send the file to ChatGPT, but we took the names out." Both people think they have stepped outside Law 25. Both almost certainly haven't.
Quebec's law separates three states of the same piece of information, and only one of them escapes its rules. The definitions are well covered elsewhere. This article handles the practical case: what anonymizing requires since the 2024 regulation, why a spreadsheet without names is still a file of personal information, and what to strip before handing data to an AI model.
The short answer, for the busy
Under Law 25, information is anonymized only if it is, at all times, reasonably foreseeable in the circumstances that it irreversibly no longer allows the person to be identified directly or indirectly (section 23 of the Act respecting the protection of personal information in the private sector). Removing names, email addresses and social insurance numbers produces de-identified information instead (section 12), which is still personal information covered by the Act. Since May 30, 2024, the Regulation respecting the anonymization of personal information has imposed a specific process: set the purposes in advance, work under the supervision of a qualified person, analyze re-identification risks against three criteria (individualization, correlation, inference), show that the residual risk is very low, reassess periodically and keep a register. Anonymization is the only lawful alternative to destruction once the retention purpose is achieved. And pseudonymized data sent to an AI model hosted outside Quebec is still personal information communicated outside Quebec.
Three states of the same information
The Act starts from a broad definition. Under section 2, personal information is "any information which relates to a natural person and directly or indirectly allows that person to be identified." The word that matters is "indirectly."
Section 12 then creates an intermediate state: de-identified information, which "no longer allows the person concerned to be directly identified." That is what you get when you delete the names. The Commission d'accès à l'information (CAI), Quebec's privacy regulator, lists the usual items to remove: name, street or email address, social insurance or health insurance number. Then it is blunt: de-identified information remains personal information subject to the Act. And a business using it must take reasonable measures to limit the risk of re-identification.
The third state is anonymized information (section 23): no identification possible, direct or indirect, irreversibly and at all times. According to the CAI, such information stops being personal information and can be used, shared and kept with no further obligation. It is the only exit.
What engineers call pseudonymization (replacing "Marie Tremblay" with "CLIENT-0417" and keeping the lookup table) is not a term the Act uses. Under Quebec law, it is de-identification. You hold the key, so the person is still identifiable, so the Act applies.
Why a spreadsheet without names is almost never anonymous
Take a customer list with the name and email removed. What's left is the postal code, year of birth, occupation, date of first purchase and amount spent. How many people share the same full postal code, birth year and occupation? Very few, sometimes one. The row has lost its name, but it still describes somebody.
The regulation names this problem precisely. It requires an analysis against three criteria.
Individualization: can a person be isolated or distinguished within the dataset? The single row above fails.
Correlation: can datasets about the same person be connected? Your file matched against a LinkedIn profile, for instance.
Inference: can personal information be deduced from other available information?
You must also account for other reasonably available information, "in particular in the public space," which includes whatever your customers publish about themselves.
In 2019, researchers from UCLouvain and Imperial College London estimated in Nature Communications that 99.98% of Americans would be correctly re-identified in any dataset using 15 demographic attributes. Your customer file rarely holds 15. It rarely holds fewer than three or four, and a Quebec region is a far smaller population.
The CAI itself considers it "almost impossible" to certify that anonymized information will never be re-identified, and says some information is too distinctive to be adequately anonymized at all: genetic, biometric or geolocation data.
Anonymization as the end-of-retention exit
Why anonymize rather than simply protect? Because of section 23. Once the purposes for which information was collected are achieved, the business "must destroy the information, or anonymize it to use it for serious and legitimate purposes," subject to any retention period set by another statute. We covered that rule in our article on data retention under Law 25.
Two exits, and de-identification is not one of them: the CAI states that it is not an alternative to destruction. A file of former customers with the names removed, kept "for statistics," is still personal information held past its purpose.
Our view as practitioners: in most small businesses, the right move is to compute first, then destroy. If what you want is revenue by region and by quarter, compute it while the purpose is still active, keep the aggregate table and destroy the individual rows. A table of totals where no cell describes a single person is far easier to defend than a row-by-row "anonymized" file.
The regulation's process, step by step
If you really do want to anonymize, the Regulation respecting the anonymization of personal information, in force since May 30, 2024, sets out the method. Without it, the CAI says, no business could anonymize at all.
1. Set the purposes before you start. Section 3 requires them to be consistent with section 23. A new purpose later means checking again.
2. Work under supervision. Section 4 requires "the supervision of a person qualified in the field," without defining the qualification.
3. Remove all direct identifiers, then analyze the re-identification risks. Section 5 requires this preliminary analysis against the three criteria. Deleting names is only step one.
4. Choose the anonymization techniques. Under section 6, they must be consistent with generally accepted best practices and come with protection and security measures that reduce the risks.
5. Analyze the risks again once the techniques are applied. That is section 7. Zero risk is not required, but residual risk must be "very low," taking into account, among other things, the effort, resources and expertise re-identification would take.
6. Reassess periodically. Section 8 requires you to account for technological advances. If the update fails, the information is no longer considered anonymized.
7. Keep a register. Section 9, in force since January 1, 2025, sets its content: a description of the anonymized information, the intended purposes, the techniques and measures used, and the date of the risk analysis and of each update.
The Act adds a penal side. Section 91 makes it an offence to identify or attempt to identify a person using anonymized information, or using de-identified information without the authorization of whoever holds it. For a business, the fine runs from $15,000 to $25 million, or 4% of worldwide turnover if that is higher.
The AI case: what to strip before sending data to a model
This is where the distinction stops being theoretical. An employee pasting a CRM extract into an AI assistant, or an agent passing records to a language model, is communicating that data to the model's provider. If the provider processes it outside Quebec, section 17 applies: a privacy impact assessment (PIA) before the communication, and a written agreement. The section also covers entrusting a party outside Quebec with using information on your behalf, which, on our reading, describes an API call quite well.
Swapping names for codes before sending is good practice. But the lookup table stays with you: the data you send is de-identified, therefore still personal information, and section 17 still applies. The detail of those requirements is in our article on AI agents running on US servers, and how to document them is in our PIA guide for private businesses.
The method that holds up, in order:
First ask whether the task needs person-level data at all. A trend can be computed on an aggregate, without a single individual row.
Remove direct identifiers: names, email addresses, phone numbers, street addresses, file numbers, social insurance and health insurance numbers.
Coarsen the quasi-identifiers the task doesn't need: a date of birth becomes an age band, a full postal code becomes its first three characters, an exact date becomes a month.
Distrust free text. Sales reps' notes and email threads carry names, health situations and details no column flags.
Keep the lookup table out of the pipeline, with restricted access.
None of this exempts you from section 17 if the model runs outside Quebec, but it shrinks what is exposed, and the assessment takes that into account. It is the principle behind the architecture in our article on AI agents and confidential data: the agent gets the minimum it needs, not the whole CRM.
Where to start
List the files you believe are "anonymous." For each one, ask two of the regulation's three questions: does any row describe a single person, and can this file be matched with something else? If yes, treat it as personal information, with a retention period and a destruction date. For AI use, write a one-page rule on what never leaves the business and what gets stripped before the rest is sent.
Planning an AI agent or a web tool that handles customer records? We always start with what the tool actually needs to see.
→ Let's talk about your project
This article explains legal obligations to help a small business ask the right questions; it is not legal advice. The text of the Act respecting the protection of personal information in the private sector, the Regulation respecting the anonymization of personal information and the positions of the Commission d'accès à l'information govern: for your specific situation, consult a lawyer.
