Quick Hits - The CAI found that Metro Inc.’s facial recognition pilot meets the necessity standard of the Act respecting the protection of personal information in the private sector (the Privacy Act). - Although it called facial recognition more intrusive than traditional video surveillance and the biometric data “sensitive,” the CAI held that the biometric bank does not “otherwise” infringe privacy under Article 45 of the Act to establish a legal framework for information technology (LCCJTI). - Necessity turns on a structured test: the objectives must be important, legitimate, and real, and the collection must be proportionate, rationally connected, minimized, and more beneficial than harmful. Notably, the CAI reached that result after a demanding and often critical review of the technology’s privacy risks, concluding that the project’s benefits outweigh the intrusion, subject to a two-year reporting obligation and to its separate, still-contested February 18, 2025, decision on consent. This 2026 decision is the second chapter of the same investigation. In its February 18, 2025, decision, the CAI held that Metro’s facial recognition amounts to identity verification requiring express consent under Article 44 LCCJTI, and prohibited the bank on that basis. That ruling, which we examined in our earlier article on Québec’s restrictive approach to biometric data, remains under appeal before the Court of Québec. The 2026 decision expressly leaves it untouched. The necessity “green light” is therefore conditional: the consent prohibition still stands unless and until it is overturned. Metro proposed a pilot in up to ten grocery and pharmacy stores that would convert surveillance images of suspected repeat offenders into biometric templates, store them in a database, and flag matches in real time. The CAI was openly skeptical: it found the accuracy evidence thin, flagged real risks of false positives and demographic bias, and warned that relying on a