Binding law — in force
Exclusively-automated decisions require notice, explanation, and human review (Quebec)
Under Quebec Law 25 (s. 12.1 of the private-sector privacy Act), an enterprise that uses personal information to render a decision based exclusively on automated processing must inform the person no later than when it communicates the decision, and on request disclose the personal information used, the reasons and principal factors/parameters, and the right to correct the data — and must give the person an opportunity to submit observations to a staff member able to review the decision. Applies to Quebec residents' data wherever the controller sits; French-language notice required. Detect a solely-automated significant-decision path with no ADM notice, explanation-on-request, correction, or human-review affordance.
Who it applies to
- Duty falls on: controller
- Systems covered: automated decision, consequential decision
- Sectors: lending, insurance, employment, housing, essential services
- Enterprises using personal information of Quebec residents to render decisions based exclusively on automated processing (no meaningful human involvement). In force since 2023-09-22. Extraterritorial: follows Quebec residents' data. French notice required.
The guard to add
Route significant automated decisions through meaningful human review, or wire in an automated-decision notice, reasons, human intervention, a way to give a view, and contest.
At the point where model output becomes a significant decision about a person (approve, deny, underwrite, set_status), either queue the case for a reviewer who weighs the evidence and can change the outcome before it takes effect (review_queue.enqueue, requires_human_review), or, where the decision stays solely automated, record the permitted basis for that decision type and wire the safeguards in. Those safeguards are a notice in the decision message that it was made by automated processing, reasons the person can read, and request_human_review or contest routes where the person can give their view and have a human reconsider. A reviewer who approves every case without examining it does not make the decision non-automated, so the review records reviewer identity, the evidence viewed, and the outcome.
Where it goes: 1 application source code, 9 AI output handling, 15 agent action surface, 14 user-facing text.
What this provision adds:
- Inform the person that the decision was based exclusively on automated processing no later than when the decision is communicated.
- On request, disclose the personal information used, the reasons and principal factors and parameters, and the right to correct the data, and let the person submit observations to a staff member able to review the decision.
- Provide the notice in French.
Example (Python + OpenAI SDK), before:
verdict = client.chat.completions.create(model=MODEL, messages=msgs).choices[0].message.content
if verdict.strip() == 'deny':
deny(applicant)
send_decision_email(applicant, 'Your application was not approved.')After:
out = client.chat.completions.create(model=MODEL, messages=msgs,
response_format={'type': 'json_object'})
result = json.loads(out.choices[0].message.content)
if result['decision'] == 'deny':
if requires_human_review('credit'): # a person decides
review_queue.enqueue(applicant.id, proposal=result)
else: # solely automated, recorded basis
deny(applicant, basis=DECISION_BASIS['credit'], reasons=result['reasons'])
send_decision_email(applicant, render('adm_denial.txt', notice=ADM_NOTICE,
reasons=result['reasons'], contest_url=f'{BASE}/decisions/{applicant.id}/contest'))Control: Solely-automated significant decision without human-intervention safeguards. The same guard addresses 3 items with binding law in 2 jurisdictions. Engineering guidance, not legal advice.
Standards that recommend the same control
- Solely-automated AI decisions require contest, human review, explanation, and a DPIA (UK ICO) (UK ICO AI Guidance · ICO UK GDPR guidance — Rights related to automated decision-making including profiling (Article 22))
Related incidents
No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.
- UnitedHealth nH Predict claim-denial litigation (2023-11; alleged (not proven)). A class action filed in November 2023 alleges that UnitedHealth's nH Predict model had a 90% error rate, measured by denials reversed on appeal, while only about 0.2% of members appealed. UnitedHealth disputes the allegations; the litigation is ongoing. Source: STAT News · evidence grade: primary · cited by Monitor how often adverse AI decisions are reversed, and suspend models that are usually wrong
- Cigna PXDX batch claim denials (reported) (2022; alleged (not proven)). ProPublica, citing internal Cigna records, reported that Cigna's PXDX system was used to reject more than 300,000 claims over two months in 2022, with physicians spending an average of 1.2 seconds on each. Cigna disputes the reporting; related lawsuits are ongoing. Source: ProPublica / The Capitol Forum · evidence grade: press of record · cited by Make human review of adverse AI decisions substantive, not nominal
Rule id qc-law25.automated-decision-inform-and-review · review status: primary source derived