Skip to main content

Acceptable Use Policy (Quebec)

ACCEPTABLE USE POLICY

Technology Systems and Digital Resources — Quebec

ACCEPTABLE USE POLICY

[Organization Name]

Effective: [Effective Date] | Administrator: [Policy Administrator]

This Acceptable Use Policy ('Policy') governs the use of all information technology resources, systems, and digital assets owned, leased, or controlled by [Organization Name], located at [Business Address]. It is established in compliance with Quebec's Act respecting the protection of personal information in the private sector (LPRPSP/Law 25), the Act respecting labour standards (LNT), the Quebec Charter of Human Rights and Freedoms (ss. 4–5), the Civil Code of Quebec (arts. 35–41, 2088), and the Criminal Code of Canada (ss. 342.1, 430 — computer offences).

1. SCOPE

This Policy applies to: [Covered Persons]

It covers the following IT resources and systems: [Covered Systems]

All covered persons must read, understand, and comply with this Policy as a condition of continued access to organizational IT resources. By using any covered system, you acknowledge and agree to the terms of this Policy.

2. PERMITTED USES

[Organization Name]'s IT resources are provided primarily for legitimate business purposes. Permitted uses include: [Permitted Uses]

Any personal use must be incidental, brief, and must not compromise system security, productivity, or the organization's legal obligations under Law 25.

3. PROHIBITED USES

The following uses of [Organization Name]'s IT resources are strictly prohibited:

  • Unauthorized access to, copying, or distribution of confidential or proprietary information
  • Accessing, downloading, or distributing illegal, offensive, or harassing content
  • Installing unauthorized software, applications, or browser extensions
  • Disabling or circumventing security controls, firewalls, or monitoring software
  • Using organizational systems for personal financial gain, cryptocurrency activities, or operating a business
  • Sharing passwords or access credentials with unauthorized persons
  • Violating intellectual property rights (copyright, software licensing)
  • Transmitting personal information of clients or employees outside Quebec without prior Privacy Impact Assessment (Law 25)
  • Engaging in online harassment, cyberbullying, or discrimination contrary to the Quebec Charter

Additional prohibited uses specific to this organization: [Additional Prohibited Uses]

4. MONITORING AND PRIVACY

In accordance with the Quebec Charter of Human Rights and Freedoms (s. 5) and articles 35–41 C.c.Q., employees have a limited reasonable expectation of privacy when using organizational IT resources. By accepting this Policy, you acknowledge that [Organization Name] may monitor the following: [Monitoring Scope]

Purpose of monitoring: [Monitoring Purpose]

Monitoring is proportional to legitimate business needs and conducted in accordance with applicable Quebec privacy law. Monitoring data may be used as evidence in disciplinary proceedings or legal action. Personal communications incidentally captured during monitoring will be treated with appropriate discretion.

5. SOCIAL MEDIA AND EXTERNAL COMMUNICATIONS

[Social Media Rules]

Confidentiality obligations: [Confidentiality Obligations]

Any personal information of clients, colleagues, or third parties collected or processed through organizational systems is protected under Law 25. Unauthorized disclosure may result in personal liability and disciplinary action.

6. VIOLATIONS AND ENFORCEMENT

Violations of this Policy will be addressed as follows: [Violation Consequences]

How to report suspected violations: [Reporting Procedure]

[Organization Name] will investigate all reported violations promptly and in good faith. The organization prohibits retaliation against individuals who report violations in good faith.

7. ACKNOWLEDGEMENT

All covered persons are required to sign an acknowledgement confirming that they have read, understood, and agree to comply with this Acceptable Use Policy. This Policy was last updated on [Policy Date] and is effective as of [Effective Date]. Contact [Policy Administrator] at [Business Address] with any questions.

Policy Administrator

________________

Signature

Employee / Authorized User

________________

Signature

Maintained by Vladislav Sergienko, Founder·Template last modified: ·Report an error

What Is a Acceptable Use Policy (Quebec)?

A Quebec Acceptable Use Policy (Politique d'utilisation acceptable, or PUA) is an organizational governance document regulated by the intersection of Quebec's Act respecting the protection of personal information in the private sector (CQLR c P-39.1, commonly called Law 25 or Loi 25), the Civil Code of Quebec (CCQ) obligations of good faith under arts. 1375 and 2088, and the Act respecting occupational health and safety (LSST, CQLR c S-2.1). Law 25, substantially amended in 2021 and fully in force by September 2023, is the most demanding Canadian provincial privacy statute and imposes obligations that no Quebec employer can satisfy without a formal written AUP governing how employees handle personal information on organizational systems.

Law 25 requires every organization in Quebec that handles personal information to designate a person in charge of the protection of personal information (responsable de la protection des renseignements personnels), to establish and publish a privacy governance policy, to conduct Privacy Impact Assessments (PIAs, évaluations des facteurs relatifs à la vie privée or EFVP) before certain data transfers outside Quebec, and to report confidentiality incidents to the Commission d'accès à l'information (CAI) within 72 hours under s. 3.5. The CAI is the independent oversight body that enforces Law 25 and can impose administrative monetary penalties of up to $25 million or 4% of worldwide turnover on organizations in serious breach.

The Quebec Charter of Human Rights and Freedoms (CQLR c C-12), specifically s. 5 which protects the right to respect for private life, creates a higher standard of employee privacy protection than applies in most other Canadian provinces. The Commission des droits de la personne et des droits de la jeunesse (CDPDJ) has established through adjudication that employers monitoring employees' electronic communications — including email, internet usage, and keylogging — must satisfy a three-part justification test: the surveillance must pursue a legitimate business objective, use the least intrusive means available, and employees must receive prior notice. An AUP that discloses monitoring practices and obtains employee acknowledgment satisfies the prior notice requirement that the CDPDJ mandates.

The Civil Code of Quebec imposes a general obligation on employers under art. 2088 to conduct themselves in a manner consistent with good faith toward employees, and on employees to be loyal and protect the employer's confidential information under art. 2088 para. 2. An AUP operationalises these CCQ obligations by specifying what constitutes acceptable and unacceptable use of employer-owned information technology assets, providing the contractual and regulatory basis for disciplinary action including the dismissal procedures under the Act Respecting Labour Standards (ARLS) for just cause termination.

Language compliance is a Quebec-specific dimension. All organizational policies that govern employees in Quebec must be available in French under s. 41 of the Charter of the French Language (CQLR c C-11, as amended by Bill 96). An AUP that exists only in English does not satisfy the employer's obligations under the Charter of the French Language, and the Office québécois de la langue française (OQLF) can require the employer to provide French-language documentation. Employers should also consider a Non-Disclosure Agreement for Quebec to address confidentiality obligations beyond what an AUP can achieve in a standalone IT-governance context.

When Do You Need a Acceptable Use Policy (Quebec)?

A Quebec Acceptable Use Policy is required by Law 25 (CQLR c P-39.1) as a component of the mandatory personal information governance framework that every organization handling personal information in Quebec must establish and maintain, and is independently needed to satisfy obligations under the Civil Code of Quebec, the Charter of the French Language, and the Act Respecting Labour Standards.

When an organization processes personal information of customers or employees on its IT systems — which encompasses virtually every Quebec business that maintains a client database, processes payroll through software, or uses cloud-based services — Law 25 requires written governance rules covering how that information is collected, used, stored, and protected. The AUP is the employee-facing component of this governance framework, specifying what employees may and may not do with personal information on organizational systems. Without an AUP, the organization cannot demonstrate to the Commission d'accès à l'information (CAI) that it has implemented the governance structures required under Law 25 s. 3.2.

When implementing electronic monitoring of employees — such as tracking internet usage, recording phone calls, monitoring productivity through screen capture software, or using GPS tracking on company vehicles — the CCQ art. 35 right to privacy and the CDPDJ's three-part justification test require the employer to disclose the monitoring practices in advance. The AUP is the standard vehicle for this disclosure. Without advance disclosure in the AUP, evidence obtained through electronic monitoring may be inadmissible in labour tribunal proceedings before the Tribunal administratif du travail (TAT).

When onboarding new employees who will use company information systems, the AUP provides the contractual basis for the employer's authority to discipline or dismiss for IT misuse, including unauthorized access to personal information (which may constitute a cybercrime under the Criminal Code, RSC 1985 c C-46, s. 342.1), use of company systems for personal commercial activities, or downloading unauthorized software creating malware risk. The ARLS requires just cause for dismissal of employees with two or more years of service under s. 124, and a documented AUP that the employee acknowledged establishes the policy baseline for that justification.

When the organization transfers personal information outside Quebec — including to cloud service providers, parent companies, or outsourced IT services in other provinces or countries — Law 25 s. 17 requires a prior Privacy Impact Assessment (EFVP) and a written agreement with the recipient confirming equivalent protection. The AUP must instruct employees on the prohibition against transferring personal information externally without completing the required EFVP process and obtaining the approval of the designated responsable de la protection des renseignements personnels.

When an organization holds personal information under a PIPEDA (federal Personal Information Protection and Electronic Documents Act, SC 2000 c 5) exemption for provincially regulated activities, the federal exemption in s. 26(2)(b) requires the provincial law to be substantially similar. Law 25 has been declared substantially similar to PIPEDA, meaning Quebec-regulated organizations satisfy federal obligations by complying with Law 25. The AUP must be drafted to satisfy Law 25 requirements, which are in several respects more stringent than PIPEDA, including the 72-hour breach notification rule.

What to Include in Your Acceptable Use Policy (Quebec)

A Quebec Acceptable Use Policy compliant with Law 25 (CQLR c P-39.1), the Civil Code of Quebec, the Charter of the French Language, and the Act Respecting Labour Standards must include the following components.

Scope and application must define which systems, devices, networks, and data assets are covered — including company-owned computers, mobile devices, email accounts, cloud storage, social media accounts, and any personally owned devices used for work purposes under a BYOD (Bring Your Own Device) arrangement. The scope must also specify which personnel are covered: employees, contractors, temporary workers, students, and any third parties with access to the organization's systems.

Personal information governance clause must identify the responsable de la protection des renseignements personnels designated under Law 25 s. 3.1 and their contact information, specify the categories of personal information processed on organizational systems, prohibit unauthorized access to or disclosure of personal information, require employees to complete the organization's privacy incident reporting protocol within the 72-hour timeline required by Law 25 s. 3.5 for reporting to the CAI, and confirm the organization's Law 25 privacy governance policy.

Monitoring disclosure must describe precisely what electronic monitoring the employer conducts — email filtering, internet usage logs, productivity tracking, GPS vehicle monitoring, CCTV surveillance — specifying the purpose, scope, and frequency of monitoring. Under the CDPDJ's guidelines, monitoring must be proportionate to the legitimate business objective and use the least intrusive means. This clause must be drafted in French and any other language under the Charter of the French Language (CQLR c C-11, s. 41).

Permitted and prohibited uses must clearly distinguish authorized activities (work-related communications, professional development, limited personal use within defined parameters) from prohibited activities (accessing personal information without authorization, installing unauthorized software, using systems for personal commercial purposes, accessing illegal or discriminatory content, sharing access credentials). Prohibited activities that constitute grounds for serious disciplinary action including dismissal must be explicitly identified.

Social media policy must balance the employer's reputation interest with employees' freedom of expression rights under the Quebec Charter of Human Rights and Freedoms (CQLR c C-12), specifying what employees may and may not post in their capacity as employees or in contexts that identify them with the employer, and distinguishing between work-hours use and personal time use.

Data retention and security requirements must specify password policies, encryption requirements for portable devices handling personal information, prohibition on storing personal information on personal cloud accounts, and the requirement to use the organization's approved tools for any processing of personal information under Law 25's accountability principle.

The forms-legal.com Quebec Acceptable Use Policy template covers all Law 25 governance framework requirements including the CAI incident reporting protocol, the EFVP requirement for cross-border data transfers, the OQLF-compliant bilingual format, and the CCQ art. 2088 employee loyalty obligation reference.

Employee acknowledgment in writing must be obtained from every employee covered by the AUP, confirming they have read, understood, and agreed to comply with the policy. Under ARLS s. 102, an employer seeking to dismiss for just cause must demonstrate that the employee knew the rule that was violated — a signed acknowledgment of the AUP provides this evidence.

Sources & Citations

Statutory citations link to official government sources.

  1. RSC 1985 c C-46CA official

Cite this page

Reference this free template in an article, syllabus, or research note:

APA

Forms Legal. (2026). Acceptable Use Policy (Quebec) (Quebec) [Legal document template]. Forms Legal. https://forms-legal.com/quebec/business/policies/acceptable-use-policy-quebec

MLA

"Acceptable Use Policy (Quebec) (Quebec)." Forms Legal, 2026, https://forms-legal.com/quebec/business/policies/acceptable-use-policy-quebec.

BibTeX
@misc{formslegal-acceptable-use-policy-quebec,
  author       = {{Forms Legal}},
  title        = {Acceptable Use Policy (Quebec) (Quebec)},
  year         = {2026},
  howpublished = {\url{https://forms-legal.com/quebec/business/policies/acceptable-use-policy-quebec}},
  note         = {Free legal document template. Based on Civil Code of Québec (CCQ), Book Five: Obligations}
}

Frequently Asked Questions

Based on Civil Code of Québec (CCQ), Book Five: Obligations — Template last modified June 2026

This template is provided for informational purposes only and does not constitute legal advice. Laws vary by jurisdiction and change over time. Consult a qualified attorney for advice specific to your situation.Full disclaimer

Found an error? Let us know

Related Documents

You may also find these documents useful:

Politique anti-discrimination et harcèlement (Québec)

Créez une politique québécoise anti-discrimination et anti-harcèlement conforme à la Charte des droits et libertés de la personne (CQLR c C-12), aux dispositions sur le harcèlement psychologique de la LNT (CQLR c N-1.1) et au C.c.Q. Couvre les 17 motifs prohibés, le harcèlement psychologique, les obligations d'enquête de l'employeur, les procédures de plainte et les recours via le CNESST.

Rapport d'incident de travail CNESST (Québec — LSST)

Créez un rapport d'incident et d'accident de travail CNESST conforme à la LSST (CQLR c S-2.1), à la LATMP (CQLR c A-3.001) et aux exigences de déclaration de la CNESST. Documente les accidents du travail, les incidents évités de justesse et les maladies professionnelles. Couvre les obligations de l'employeur, la notification dans les 6 heures pour les blessures graves et le droit au retour au travail.

Code de conduite et d'éthique (Québec)

Rédigez un Code de conduite et d'éthique des affaires québécois régi par le C.c.Q., la Charte des droits et libertés de la personne (CQLR c C-12), la LNT et la Loi 25. Couvre les attentes en matière de conduite professionnelle, les conflits d'intérêts, la confidentialité, l'anti-corruption, les médias sociaux, la discipline et la conformité aux normes d'éthique des affaires du Québec.

Formulaire de consentement aux renseignements personnels — Québec (Loi 25 / LPRPSP)

Créez un Formulaire de consentement aux renseignements personnels québécois conforme à la Loi 25 (LPRPSP). Obtient le consentement explicite et éclairé pour la collecte, l'utilisation et la divulgation des renseignements personnels. Requis pour les données sensibles, les communications marketing, les transferts transfrontaliers et les utilisations secondaires. PDF ou Word.