Acceptable Use Policy (Quebec)
Key facts
Technology Systems and Digital Resources — Quebec
POLITIQUE D'UTILISATION ACCEPTABLE
En vigueur : [Effective Date] | Administrateur : [Policy Administrator]
La présente Politique d'utilisation acceptable (la « Politique ») régit l'utilisation de toutes les ressources, tous les systèmes et tous les actifs numériques informatiques appartenant à [Organization Name], loués par elle ou sous son contrôle, situés à [Business Address]. Elle est établie conformément à la Loi sur la protection des renseignements personnels dans le secteur privé du Québec (LPRPSP/Loi 25), à la Loi sur les normes du travail (LNT), à la Charte des droits et libertés de la personne du Québec (art. 4-5), au Code civil du Québec (art. 35-41, 2088) et au Code criminel du Canada (art. 342.1, 430 — infractions informatiques).
1. CHAMP D'APPLICATION
La présente Politique s'applique aux personnes suivantes : [Covered Persons]
Elle vise les ressources et systèmes informatiques suivants : [Covered Systems]
Toute personne visée doit lire, comprendre et respecter la présente Politique comme condition du maintien de son accès aux ressources informatiques de l'organisation. En utilisant tout système visé, vous reconnaissez et acceptez les conditions de la présente Politique.
2. UTILISATIONS PERMISES
Les ressources informatiques de [Organization Name] sont fournies principalement à des fins commerciales légitimes. Les utilisations permises comprennent : [Permitted Uses]
Toute utilisation personnelle doit être accessoire, brève et ne doit pas compromettre la sécurité des systèmes, la productivité ou les obligations légales de l'organisation en vertu de la Loi 25.
3. UTILISATIONS INTERDITES
Les utilisations suivantes des ressources informatiques de [Organization Name] sont strictement interdites :
- L'accès non autorisé, la copie ou la diffusion de renseignements confidentiels ou exclusifs
- L'accès, le téléchargement ou la diffusion de contenu illégal, offensant ou harcelant
- L'installation de logiciels, d'applications ou d'extensions de navigateur non autorisés
- La désactivation ou le contournement des contrôles de sécurité, des pare-feu ou des logiciels de surveillance
- L'utilisation des systèmes de l'organisation à des fins de gain financier personnel, d'activités liées aux cryptomonnaies ou d'exploitation d'une entreprise
- Le partage de mots de passe ou d'identifiants d'accès avec des personnes non autorisées
- La violation des droits de propriété intellectuelle (droit d'auteur, licences de logiciels)
- La transmission de renseignements personnels de clients ou d'employés à l'extérieur du Québec sans évaluation préalable des facteurs relatifs à la vie privée (Loi 25)
- Le harcèlement en ligne, la cyberintimidation ou la discrimination contraires à la Charte québécoise
Utilisations interdites additionnelles propres à cette organisation : [Additional Prohibited Uses]
4. SURVEILLANCE ET VIE PRIVÉE
Conformément à la Charte des droits et libertés de la personne du Québec (art. 5) et aux articles 35-41 C.c.Q., les employés ont une attente raisonnable de vie privée limitée lorsqu'ils utilisent les ressources informatiques de l'organisation. En acceptant la présente Politique, vous reconnaissez que [Organization Name] peut surveiller les éléments suivants : [Monitoring Scope]
Objet de la surveillance : [Monitoring Purpose]
La surveillance est proportionnelle aux besoins commerciaux légitimes et est exercée conformément à la législation québécoise applicable en matière de protection des renseignements personnels. Les données de surveillance peuvent être utilisées comme preuve dans le cadre de mesures disciplinaires ou de recours judiciaires. Les communications personnelles captées accessoirement pendant la surveillance seront traitées avec la discrétion appropriée.
5. MÉDIAS SOCIAUX ET COMMUNICATIONS EXTERNES
Obligations de confidentialité : [Confidentiality Obligations]
Tout renseignement personnel de clients, de collègues ou de tiers recueilli ou traité au moyen des systèmes de l'organisation est protégé par la Loi 25. Toute divulgation non autorisée peut entraîner une responsabilité personnelle et des mesures disciplinaires.
6. VIOLATIONS ET APPLICATION
Les violations de la présente Politique seront traitées de la façon suivante : [Violation Consequences]
Comment signaler une violation présumée : [Reporting Procedure]
[Organization Name] enquêtera sur toute violation signalée avec diligence et de bonne foi. L'organisation interdit toute mesure de représailles contre les personnes qui signalent des violations de bonne foi.
7. RECONNAISSANCE
Toute personne visée doit signer une reconnaissance confirmant qu'elle a lu, compris et accepté de se conformer à la présente Politique d'utilisation acceptable. La présente Politique a été mise à jour pour la dernière fois le [Policy Date] et entre en vigueur le [Effective Date]. Pour toute question, communiquez avec [Policy Administrator] à [Business Address].
Administrateur des politiques
________________
Signature
Employé / Utilisateur autorisé
________________
Signature
What Is a Acceptable Use Policy (Quebec)?
A Quebec Acceptable Use Policy (Politique d'utilisation acceptable, or PUA) is an organizational governance document regulated by the intersection of Quebec's Act respecting the protection of personal information in the private sector (CQLR c P-39.1, commonly called Law 25 or Loi 25), the Civil Code of Quebec (CCQ) obligations of good faith under arts. 1375 and 2088, and the Act respecting occupational health and safety (LSST, CQLR c S-2.1). Law 25, substantially amended in 2021 and fully in force by September 2023, is the most demanding Canadian provincial privacy statute and imposes obligations that no Quebec employer can satisfy without a formal written AUP governing how employees handle personal information on organizational systems.
Law 25 requires every organization in Quebec that handles personal information to designate a person in charge of the protection of personal information (responsable de la protection des renseignements personnels), to establish and publish a privacy governance policy, to conduct Privacy Impact Assessments (PIAs, évaluations des facteurs relatifs à la vie privée or EFVP) before certain data transfers outside Quebec, and to report confidentiality incidents to the Commission d'accès à l'information (CAI) within 72 hours under s. 3.5. The CAI is the independent oversight body that enforces Law 25 and can impose administrative monetary penalties of up to $25 million or 4% of worldwide turnover on organizations in serious breach.
The Quebec Charter of Human Rights and Freedoms (CQLR c C-12), specifically s. 5 which protects the right to respect for private life, creates a higher standard of employee privacy protection than applies in most other Canadian provinces. The Commission des droits de la personne et des droits de la jeunesse (CDPDJ) has established through adjudication that employers monitoring employees' electronic communications — including email, internet usage, and keylogging — must satisfy a three-part justification test: the surveillance must pursue a legitimate business objective, use the least intrusive means available, and employees must receive prior notice. An AUP that discloses monitoring practices and obtains employee acknowledgment satisfies the prior notice requirement that the CDPDJ mandates.
The Civil Code of Quebec imposes a general obligation on employers under art. 2088 to conduct themselves in a manner consistent with good faith toward employees, and on employees to be loyal and protect the employer's confidential information under art. 2088 para. 2. An AUP operationalises these CCQ obligations by specifying what constitutes acceptable and unacceptable use of employer-owned information technology assets, providing the contractual and regulatory basis for disciplinary action including the dismissal procedures under the Act Respecting Labour Standards (ARLS) for just cause termination.
Language compliance is a Quebec-specific dimension. All organizational policies that govern employees in Quebec must be available in French under s. 41 of the Charter of the French Language (CQLR c C-11, as amended by Bill 96). An AUP that exists only in English does not satisfy the employer's obligations under the Charter of the French Language, and the Office québécois de la langue française (OQLF) can require the employer to provide French-language documentation. Employers should also consider a Non-Disclosure Agreement for Quebec to address confidentiality obligations beyond what an AUP can achieve in a standalone IT-governance context.
When Do You Need a Acceptable Use Policy (Quebec)?
A Quebec Acceptable Use Policy is required by Law 25 (CQLR c P-39.1) as a component of the mandatory personal information governance framework that every organization handling personal information in Quebec must establish and maintain, and is independently needed to satisfy obligations under the Civil Code of Quebec, the Charter of the French Language, and the Act Respecting Labour Standards.
When an organization processes personal information of customers or employees on its IT systems — which encompasses virtually every Quebec business that maintains a client database, processes payroll through software, or uses cloud-based services — Law 25 requires written governance rules covering how that information is collected, used, stored, and protected. The AUP is the employee-facing component of this governance framework, specifying what employees may and may not do with personal information on organizational systems. Without an AUP, the organization cannot demonstrate to the Commission d'accès à l'information (CAI) that it has implemented the governance structures required under Law 25 s. 3.2.
When implementing electronic monitoring of employees — such as tracking internet usage, recording phone calls, monitoring productivity through screen capture software, or using GPS tracking on company vehicles — the CCQ art. 35 right to privacy and the CDPDJ's three-part justification test require the employer to disclose the monitoring practices in advance. The AUP is the standard vehicle for this disclosure. Without advance disclosure in the AUP, evidence obtained through electronic monitoring may be inadmissible in labour tribunal proceedings before the Tribunal administratif du travail (TAT).
When onboarding new employees who will use company information systems, the AUP provides the contractual basis for the employer's authority to discipline or dismiss for IT misuse, including unauthorized access to personal information (which may constitute a cybercrime under the Criminal Code, RSC 1985 c C-46, s. 342.1), use of company systems for personal commercial activities, or downloading unauthorized software creating malware risk. The ARLS requires just cause for dismissal of employees with two or more years of service under s. 124, and a documented AUP that the employee acknowledged establishes the policy baseline for that justification.
When the organization transfers personal information outside Quebec — including to cloud service providers, parent companies, or outsourced IT services in other provinces or countries — Law 25 s. 17 requires a prior Privacy Impact Assessment (EFVP) and a written agreement with the recipient confirming equivalent protection. The AUP must instruct employees on the prohibition against transferring personal information externally without completing the required EFVP process and obtaining the approval of the designated responsable de la protection des renseignements personnels.
When an organization holds personal information under a PIPEDA (federal Personal Information Protection and Electronic Documents Act, SC 2000 c 5) exemption for provincially regulated activities, the federal exemption in s. 26(2)(b) requires the provincial law to be substantially similar. Law 25 has been declared substantially similar to PIPEDA, meaning Quebec-regulated organizations satisfy federal obligations by complying with Law 25. The AUP must be drafted to satisfy Law 25 requirements, which are in several respects more stringent than PIPEDA, including the 72-hour breach notification rule.
What to Include in Your Acceptable Use Policy (Quebec)
A Quebec Acceptable Use Policy compliant with Law 25 (CQLR c P-39.1), the Civil Code of Quebec, the Charter of the French Language, and the Act Respecting Labour Standards must include the following components.
Scope and application must define which systems, devices, networks, and data assets are covered — including company-owned computers, mobile devices, email accounts, cloud storage, social media accounts, and any personally owned devices used for work purposes under a BYOD (Bring Your Own Device) arrangement. The scope must also specify which personnel are covered: employees, contractors, temporary workers, students, and any third parties with access to the organization's systems.
Personal information governance clause must identify the responsable de la protection des renseignements personnels designated under Law 25 s. 3.1 and their contact information, specify the categories of personal information processed on organizational systems, prohibit unauthorized access to or disclosure of personal information, require employees to complete the organization's privacy incident reporting protocol within the 72-hour timeline required by Law 25 s. 3.5 for reporting to the CAI, and confirm the organization's Law 25 privacy governance policy.
Monitoring disclosure must describe precisely what electronic monitoring the employer conducts — email filtering, internet usage logs, productivity tracking, GPS vehicle monitoring, CCTV surveillance — specifying the purpose, scope, and frequency of monitoring. Under the CDPDJ's guidelines, monitoring must be proportionate to the legitimate business objective and use the least intrusive means. This clause must be drafted in French and any other language under the Charter of the French Language (CQLR c C-11, s. 41).
Permitted and prohibited uses must clearly distinguish authorized activities (work-related communications, professional development, limited personal use within defined parameters) from prohibited activities (accessing personal information without authorization, installing unauthorized software, using systems for personal commercial purposes, accessing illegal or discriminatory content, sharing access credentials). Prohibited activities that constitute grounds for serious disciplinary action including dismissal must be explicitly identified.
Social media policy must balance the employer's reputation interest with employees' freedom of expression rights under the Quebec Charter of Human Rights and Freedoms (CQLR c C-12), specifying what employees may and may not post in their capacity as employees or in contexts that identify them with the employer, and distinguishing between work-hours use and personal time use.
Data retention and security requirements must specify password policies, encryption requirements for portable devices handling personal information, prohibition on storing personal information on personal cloud accounts, and the requirement to use the organization's approved tools for any processing of personal information under Law 25's accountability principle.
The forms-legal.com Quebec Acceptable Use Policy template covers all Law 25 governance framework requirements including the CAI incident reporting protocol, the EFVP requirement for cross-border data transfers, the OQLF-compliant bilingual format, and the CCQ art. 2088 employee loyalty obligation reference.
Employee acknowledgment in writing must be obtained from every employee covered by the AUP, confirming they have read, understood, and agreed to comply with the policy. Under ARLS s. 102, an employer seeking to dismiss for just cause must demonstrate that the employee knew the rule that was violated — a signed acknowledgment of the AUP provides this evidence.
Sources & Citations
Statutory citations link to official government sources.
- RSC 1985 c C-46CA official
Cite this page
CC BY 4.0 · free to citeReference this free template in an article, syllabus, or research note:
Forms Legal. (2026). Acceptable Use Policy (Quebec) (Quebec) [Legal document template]. Forms Legal. https://forms-legal.com/quebec/business/policies/acceptable-use-policy-quebec
"Acceptable Use Policy (Quebec) (Quebec)." Forms Legal, 2026, https://forms-legal.com/quebec/business/policies/acceptable-use-policy-quebec.
Forms Legal. "Acceptable Use Policy (Quebec) (Quebec)." Forms Legal, 2026. https://forms-legal.com/quebec/business/policies/acceptable-use-policy-quebec.
@misc{formslegal-acceptable-use-policy-quebec,
author = {{Forms Legal}},
title = {Acceptable Use Policy (Quebec) (Quebec)},
year = {2026},
howpublished = {\url{https://forms-legal.com/quebec/business/policies/acceptable-use-policy-quebec}},
note = {Free legal document template. Based on Civil Code of Québec (CCQ), Book Five: Obligations}
}{{cite web |title=Acceptable Use Policy (Quebec) (Quebec) |website=Forms Legal |publisher=Forms Legal |date=2026 |url=https://forms-legal.com/quebec/business/policies/acceptable-use-policy-quebec}}TY - ELEC T1 - Acceptable Use Policy (Quebec) (Quebec) T2 - Forms Legal PB - Forms Legal PY - 2026 UR - https://forms-legal.com/quebec/business/policies/acceptable-use-policy-quebec ER -
Frequently Asked Questions
While no Quebec law explicitly mandates an Acceptable Use Policy by that name, several legal obligations make having one essential. Quebec's Law 25 (Act respecting the protection of personal information in the private sector) requires organizations to implement governance policies for personal information. The Act respecting occupational health and safety (LSST) imposes a general duty to maintain a safe workplace, which extends to cyber threats and online harassment. The Civil Code of Quebec imposes a duty of good faith in employment relationships (arts. 1375, 2088 C.c.Q.). An AUP documents the organization's expectations, provides a legal basis for disciplinary action, and reduces liability in case of misuse of company systems.
Yes, but with significant limitations. Under Quebec's Charter of Human Rights and Freedoms (s. 5 — right to privacy) and the Civil Code of Quebec (arts. 35–41), employees have a reasonable expectation of privacy even in the workplace. The Commission des droits de la personne et des droits de la jeunesse has held that employer monitoring of communications must be justified by legitimate business reasons, limited to what is necessary, and employees must be informed in advance. An AUP that clearly discloses monitoring practices satisfies the advance notice requirement. Covert monitoring of personal communications (even on company devices) may violate Quebec privacy laws.
A Quebec AUP should address personal and professional social media use, balancing the employer's interest in protecting its reputation with employees' rights to freedom of expression under the Quebec Charter. The policy should distinguish between use of personal accounts during work hours (generally permissible in moderation but subject to productivity expectations) and use of company accounts or the employee's public identification with the employer. The policy should prohibit disclosure of confidential information, disparagement of the company or colleagues, and publication of content that could create legal liability (defamation, harassment, copyright infringement). Restrictions on personal social media use during non-work hours are generally unenforceable under Quebec labour law unless the conduct directly harms the employer's legitimate business interests.
Quebec's Law 25 requires organizations to establish and publish governance rules for personal information. An AUP that covers how employees handle personal information (of customers, colleagues, or third parties) collected or processed on company systems is a key component of this governance framework. Specifically, the AUP should address prohibitions on unauthorized access to personal information, requirements to report confidentiality incidents within 72 hours to the designated privacy officer (who must then notify the CAI), restrictions on transferring personal information outside Quebec without prior PIA, and obligations to follow data minimization and retention principles. Employees who violate these provisions may be personally liable under Quebec law.
A Acceptable Use Policy (Quebec) does not legally require a lawyer in Quebec, and individuals and businesses may draft and execute the document independently. However, seeking independent legal advice from a qualified Quebec lawyer is recommended for transactions involving substantial financial value, complex regulatory requirements, or cross-border elements where multiple legal jurisdictions may apply. A lawyer can verify that the document complies with all applicable statutory requirements, identify potential risks specific to the transaction, and confirm that the terms adequately protect the interests of all parties involved. The Superior Court of Québec has jurisdiction over disputes arising from this type of document, and Registraire des entreprises du Québec may impose additional compliance obligations depending on the nature of the underlying transaction. Professional legal review is particularly advisable where the document will be submitted to government agencies or used as evidence in legal proceedings.
This template is provided for informational purposes only and does not constitute legal advice. Laws vary by jurisdiction and change over time. Consult a qualified attorney for advice specific to your situation.Full disclaimer
Found an error? Let us knowRelated Documents
You may also find these documents useful:
Politique anti-discrimination et harcèlement (Québec)
Créez une politique québécoise anti-discrimination et anti-harcèlement conforme à la Charte des droits et libertés de la personne (CQLR c C-12), aux dispositions sur le harcèlement psychologique de la LNT (CQLR c N-1.1) et au C.c.Q. Couvre les 17 motifs prohibés, le harcèlement psychologique, les obligations d'enquête de l'employeur, les procédures de plainte et les recours via le CNESST.
Rapport d'incident de travail CNESST (Québec — LSST)
Créez un rapport d'incident et d'accident de travail CNESST conforme à la LSST (CQLR c S-2.1), à la LATMP (CQLR c A-3.001) et aux exigences de déclaration de la CNESST. Documente les accidents du travail, les incidents évités de justesse et les maladies professionnelles. Couvre les obligations de l'employeur, la notification dans les 6 heures pour les blessures graves et le droit au retour au travail.
Code de conduite et d'éthique (Québec)
Rédigez un Code de conduite et d'éthique des affaires québécois régi par le C.c.Q., la Charte des droits et libertés de la personne (CQLR c C-12), la LNT et la Loi 25. Couvre les attentes en matière de conduite professionnelle, les conflits d'intérêts, la confidentialité, l'anti-corruption, les médias sociaux, la discipline et la conformité aux normes d'éthique des affaires du Québec.
Formulaire de consentement aux renseignements personnels — Québec (Loi 25 / LPRPSP)
Créez un Formulaire de consentement aux renseignements personnels québécois conforme à la Loi 25 (LPRPSP). Obtient le consentement explicite et éclairé pour la collecte, l'utilisation et la divulgation des renseignements personnels. Requis pour les données sensibles, les communications marketing, les transferts transfrontaliers et les utilisations secondaires. PDF ou Word.