This post closes the series started with our article on the Meta pixel and Law 25, which covered the consent layer before the pixel fires. Here, we assume consent is settled and the event is allowed to leave. The remaining question is different: where does that data go once it leaves the browser or the store's server, and what does the law require before it leaves. Legal passages are a practitioner's reading, not legal advice, and the official source is linked every time. Re-read on September 23, 2026, from the Commission d'accès à l'information's guide (version 3.1, April 2024).

What section 17 says

Section 17 of the Act respecting the protection of personal information in the private sector requires a privacy impact assessment, the EFVP, in two specific cases: before communicating personal information outside Quebec, and before entrusting a person or body located outside Quebec with the task of collecting, using, communicating, or keeping such information on the company's behalf. This obligation took effect on September 22, 2023, and the Commission's guide specifies that it applies to any project not finalized by that date, as well as to any communication outside Quebec taking place after that date, even under an older project.

A Meta Pixel event, a server-side conversion sent through a conversion API, or an identifier transmitted to Google Ads for conversion tracking, are all communications of personal information to entities whose processing infrastructure sits outside Quebec. The question is therefore not whether the EFVP applies to this type of use, it applies by construction, but what the assessment must contain for a case as routine as an advertising pixel.

What the EFVP must examine, according to the Commission's guide

The Commission details, for this exact case in section 7.1 of its guide, four elements the assessment must take into account: the sensitivity of the information communicated, the purpose of its use, the protection measures it would benefit from, including contractual measures, and the legal regime applicable in the state where it would be communicated, notably the personal information protection principles in force there.

The guide adds the criterion that allows a conclusion: the company may communicate the information if the assessment demonstrates it would benefit from adequate protection, understood as protection that respects the full set of generally recognized protection principles, appropriate to the sensitivity and purpose of the information at stake. If the assessment concludes there is no adequate protection, the company must refuse to communicate the information or refrain from entrusting the task to a third party outside Quebec.

Nothing in this text requires a report running dozens of pages for routine use. The guide itself specifies that the law determines neither the content nor the form of the report, and that the level of detail must be proportionate to the sensitivity, purpose, quantity, distribution, and format of the information involved. An advertising pixel transmitting an identifier, a page view, and an order amount is not a medical file: the exercise must be real, not necessarily long.

The five elements to document for a pixel or a conversion API

Applying the guide's framework to this specific use case, here is what we document for each advertising tool that receives client-side or server-side data.

1. The data flow inventory. What information leaves, to which service, at what frequency, in what format. For a Meta Pixel: browser identifier, IP address, browsing events (page view, add to cart, purchase), and the order amount. For the conversion API, the same list, plus hashed email address and phone number if the store transmits them to improve event matching.

2. The actual recipient and its applicable law. Name the entity receiving the data (Meta Platforms, Inc. or Meta Platforms Ireland Limited depending on the contractual relationship, Google LLC for Google Ads conversions) and the legal regime of its country of establishment, generally the United States.

3. The applicable legal regime. This is the point most documented by commentators tracking this file: for a US-based recipient, one must account for the government access mechanisms provided under US law, notably the CLOUD Act and section 702 of the Foreign Intelligence Surveillance Act (FISA), which can allow US authorities to access data held or processed by a US company, regardless of where the server is physically located.

4. Mitigation measures. The guide cites encryption, minimization, pseudonymization, or relocation of the data as possible strategies. For a pixel, this translates concretely into the decision to hash the identifiers transmitted, to limit the fields sent to what is strictly necessary for the advertising purpose, and to the contractual clauses imposed by the platform itself, to be documented and attached if the vendor publishes them.

5. The decision, with its justification. Record in writing the conclusion: the communication takes place because the assessment demonstrates protection deemed adequate given the relatively low sensitivity of the browsing and purchase data at stake, its declared advertising purpose, and the contractual measures in place. Or the communication does not take place, and the pixel or API concerned stays disabled, if the assessment concludes otherwise for data more sensitive than that of routine advertising use.

The written agreement that must follow the EFVP

The guide specifies a point advertisers rarely discover before an audit: communicating personal information outside Quebec must be the subject of a written agreement between the company and the recipient third party, which takes the EFVP results into account and includes, where needed, terms agreed upon to mitigate the risks identified. For a pixel or a conversion API, this written agreement already exists, in the form of the advertising platform's terms of use and, for Meta, its data processing terms. The advertiser's job is not to draft a new agreement, but to verify that the existing one covers the actual uses and to keep it as an attachment to the EFVP report.

What Meta does not offer, and why that does not exempt anyone

Our article on the Meta pixel established this already: Meta's documentation on restricted data processing options covers only certain US states, with no value for Canada or Quebec. The absence of such a setting does not exempt anyone from the EFVP, it instead confirms that no technical measure provided by the platform replaces the assessment required by section 17. The company remains solely responsible for documenting that the communication is justified, whatever tool is used to carry it out.

What does not require an EFVP

The Commission's guide is clear on this: if the project does not involve personal information and presents manifestly no privacy risk, the EFVP is not mandatory. A technical performance-measurement pixel that transmits no identifier, no IP address, and no data attributable to a person, if such a thing existed, would not be covered. In practice, this case does not arise for any common advertising tool: Meta Pixel, Google Ads, TikTok Pixel and their equivalents all transmit, at minimum, an IP address and a browser identifier, which is enough to qualify the communication as personal information under the law.

EFVP template for an advertising tool

Element What we document
Tool Meta Pixel and conversion API, ad account XXX
Data transmitted Browser identifier, IP, browsing events, order amount, hashed email and phone where applicable
Recipient Meta Platforms Ireland Limited (or the applicable contracting entity)
Recipient's legal regime Irish law and GDPR for European processing, potential exposure to US law depending on infrastructure
Protection measures Hashing of direct identifiers, platform contractual clauses, minimization of fields transmitted
Conclusion Protection deemed adequate given sensitivity and purpose, subject to annual review
Date and owner To complete

What remains to be done

  1. Inventory every advertising and measurement tool that transmits data outside Quebec: pixels, conversion APIs, email platforms, analytics tools.
  2. For each one, fill out a sheet using the template above, drawing on the vendor's published terms of use and data processing clauses.
  3. Date and keep these sheets, noting the company's privacy officer, also required elsewhere under Law 25.
  4. Review the sheet whenever the tool changes vendor or purpose, or annually if nothing changes.

The EFVP is not an obstacle to using a pixel or a conversion API: it is the written record that the decision to use them was made with knowledge of the recipient's legal regime, not by default because the tool was already installed. We produce this documentation for our clients as part of our Google Ads and Meta Ads engagements in Montréal, alongside the consent test described in our article on the Meta pixel and Law 25.