ComplianceBy Xavier Peich

Biometric time clocks, GPS, monitoring software: what Quebec's Law 25 actually lets an employer do

Fingerprint clocks, fleet GPS, productivity trackers: the test Quebec's privacy regulator applies to each, and why employee consent doesn't save a bad one.

Biometric time clocks, GPS, monitoring software: what Quebec's Law 25 actually lets an employer do

The fingerprint time clock usually walks into a small business through payroll. The vendor sells it as a time-tracking tool, the restaurant or plant mounts it by the locker room, and nobody asks what happens to fifteen people's fingerprints. The truck GPS arrives the same way, bundled with the fleet-management plan. Of all the digital tools we set up for small businesses, these are the ones whose rules surprise owners most.

Quebec's privacy regulator, the Commission d'accès à l'information (CAI), sees something else: a collection of personal information about your employees, which you have to prove is necessary. The same test covers the time clock, the GPS and the tracking software. Biometrics adds obligations of its own, and the CAI has already ruled on real cases.

The short answer, for the busy

In Quebec, an employer may install a biometric time clock, GPS tracking or monitoring software only if it can show that the information collected is necessary: the objective must be legitimate, important and real, documented rather than merely anticipated, and the collection must be proportionate, with no less intrusive option that would do the job. Employee consent does not rescue a collection that fails this test. For biometrics (fingerprint, face, hand shape), the Act to establish a legal framework for information technology adds the employee's express consent and disclosure to the Commission d'accès à l'information no later than 60 days before the database goes into service; the Commission also requires another way to clock in for anyone who refuses. In 2023, the CAI found that most biometric time clocks did not comply, because payroll convenience does not justify collecting such data. For location tracking and computer monitoring, Law 25 requires telling employees before collection starts.

One test, and consent doesn't change it

Quebec's private-sector privacy act requires a serious and legitimate reason (section 4) and allows you to collect "only the information necessary for the purposes determined before collecting it" (section 5). The CAI reads necessity in two steps. First, the objective must be legitimate, important and real: a documented problem you actually have, not a theoretical risk. Second, the collection must be proportionate: rationally connected to the objective, minimized, and clearly more useful to the business than harmful to employees. The burden of proof is on the employer.

These rules are mandatory. In its decision against Imprimeries Transcontinental (September 4, 2024), the CAI wrote that a business cannot depart from them even with the consent of the person concerned. A form signed by every employee does not make an unnecessary collection legal.

The test can be passed. In April 2026, the CAI found that Metro's planned facial recognition to spot repeat shoplifters met the necessity test, because every store in the pilot had documented theft, fraud and violence. Its February 2025 ban, based on the missing express consent, still stood and was still being challenged before the Court of Québec. What made the difference on necessity was the paper trail.

The biometric time clock: a question already settled

On March 27, 2023, the CAI published its findings on biometric time clocks, drawn from its investigations and the declarations it receives. The conclusion is blunt: most of the time, using a biometric time clock does not comply with the law.

The justifications that usually fail: more efficient payroll (an outdated system, automation, fewer errors, more accurate hours), using the same system as other branches, and avoiding lost or broken swipe cards. Preventing time theft fails too when no real, documented problem exists. Those happen to be the exact selling points in the vendor's brochure.

Converting the fingerprint to a code changes nothing: the mathematical template is still personal information, unique to the person, and Law 25 lists biometric information as sensitive (section 12).

The decisions follow the same line. In 2022, the Auberge du Lac Sacacomie, a hotel that used face shape to track hours and payroll, was ordered to stop and destroy the templates. The hotel had already dropped fingerprints: the reader kept getting dirty from the work of cooks and grounds staff. In 2024, Transcontinental was given 90 days to stop using facial recognition at the entrances of its Beauceville plant. The CAI noted that you cannot replace your face the way you replace a card or a password, and that encrypting the database lowers the risk of a leak without reducing the intrusion on privacy.

If biometrics really is necessary: the extra obligations

If your situation passes the test, Quebec's Act to establish a legal framework for information technology adds its own rules. Section 44 bars biometric identity checks unless they were disclosed to the CAI beforehand and the person gave express consent. It requires the minimum number of characteristics (if one finger is enough, collecting ten breaks the rule, the CAI says), and the data must be destroyed once its purpose is gone, for instance when the employee leaves. Section 45 requires the creation of a biometric database to be disclosed "promptly and not later than 60 days before it is brought into service."

The CAI expects consent in writing, and the employer must offer another way to identify, such as a card or a code, to anyone who refuses or withdraws consent. Its guide recommends keeping the template rather than the raw image, on an individual medium the employee controls rather than in a central database. Finally, buying such a system triggers the privacy impact assessment required by section 3.3, which our privacy impact assessment guide for Quebec businesses walks through step by step.

Clock-in photos and location

An app that photographs employees when they clock in isn't necessarily biometric, and it isn't necessarily allowed either. In 2021, the CAI investigated Bruneau Électrique, an electrical contractor whose tablet and phone clock-in app photographed each worker at the start and end of every shift. With no enrolment database and no recognition step, the CAI found it wasn't biometrics, but still ordered the company to stop taking the photos and destroy them. The one time-theft case the company produced came from the app's imprecise geolocation, which could be off by several hundred metres, not from anyone faking an identity.

Location has its own rules. Section 43 of the same IT act says that, unless a law expressly provides otherwise for health protection or public security, "a person may not be required to be connected to a device that allows the person's whereabouts to be known." And section 8.1 of Law 25 requires you to tell people in advance when you use technology that can identify, locate or profile them, and how those functions are turned on.

Company vehicles: GPS and in-cab cameras

For a fleet, safety carries real weight: article 2087 of the Civil Code requires employers to protect the health, safety and dignity of employees, and Quebec's Charter of Human Rights and Freedoms guarantees both privacy (section 5) and fair and reasonable working conditions (section 46). Still, in its January 2025 brief on AI at work, the CAI points out that GPS on employer vehicles indirectly tracks the people driving them, possibly outside paid hours too.

The May 2025 decision against 13859380 Canada Inc. (Crane Supply), a wholesaler serving the construction industry, shows where the line sits. The company filmed the inside of its truck cabs continuously, with automatic detection of phone use while driving, unbuckled seatbelts and speeding. The CAI accepted that these safety objectives were important. It still ordered the company, within 90 days, to limit in-cab recording to a few seconds before and after an incident or stop filming the cab, and to stop recording when the engine is switched off rather than 20 minutes later, since drivers could be taking their breaks there. Configuration matters as much as the device. For cameras pointed at customers, see our piece on security cameras and Law 25.

Monitoring software and remote work

According to the same CAI brief, productivity-tracking software collects automatic screenshots, mouse movements, keystrokes, meeting counts and lengths, when emails are sent and how long they are, and browsing history. That information, the CAI notes, may have nothing to do with work, may be collected continuously, and is sometimes gathered without employees knowing.

The necessity test applies as is, and so does section 8.1, since the law defines profiling as assessing a person's characteristics "in particular for the purpose of analyzing that person's work performance." Software that scores productivity does exactly that. According to the CAI, a monitoring system is in most cases an information system that requires a privacy impact assessment. And if a tool recognizes employees by the way they type, the CAI classes that keystroke pattern as behavioural biometrics.

The decision tree

Start with the objective. If you can't write it in one sentence backed by dated facts (incidents, losses, an accident), stop there. If you can, ask whether something less intrusive would work, such as a card, a PIN, or GPS limited to working hours. If it would, use it. If not, write down why.

If the tool you pick reads the body (fingerprint, face, hand), add the privacy impact assessment, the disclosure to the CAI at least 60 days before go-live, written consent and an alternative. If it locates or profiles, tell employees in writing beforehand what is collected, when, and who looks at it. Either way, set the retention period and delete the data when someone leaves.

Where to start

List everything that already collects data on your employees (time clock, clock-in app, trackers, cameras, software) and, for each one, find the file that justifies the collection. Train the managers who look at that data (see training employees on Law 25), and if employee photos also appear on your website, read our piece on photo consent. It's a check we run before connecting any tool to a team's data.

→ Let's talk about your tools or see how we handle these questions in our services.

This article explains legal obligations so a small business can ask the right questions; it is not legal advice. The text of the Act respecting the protection of personal information in the private sector, the Act to establish a legal framework for information technology, the Charter of Human Rights and Freedoms and the Civil Code of Québec, along with the decisions and guides of the Commission d'accès à l'information, prevail. The cases cited turn on their facts: for your situation, especially in a unionized workplace where arbitration case law also applies, consult a lawyer.

Xavier PeichWritten byXavier Peich