Canadian Privacy & AI Law

PIPEDA

Personal Information Protection and Electronic Documents Act (PIPEDA)

Canada's federal private-sector privacy law, built on 10 fair information principles. Explained here as it applies to feeding personal information into AI tools, from consent and safeguards to prompts sent to US-hosted vendors.

Canada (federal, private-sector commercial activity)In force since 2001; reform bill C-36 tabled June 2026 would replace its privacy partVerified 2026-08-31

What it means for AI and data privacy

PIPEDA applies to AI the same way it applies to any other handling of personal information: if an employee pastes customer, patient, or employee data into an AI tool, that is a use and disclosure the organization remains accountable for. The law's 10 fair information principles do the work here, particularly accountability (you answer for data you transfer to an AI vendor), consent (the original consent rarely covered AI processing), limiting use (data collected for one purpose cannot be repurposed as prompt material), and safeguards (protection proportionate to sensitivity). The OPC's December 2023 principles for generative AI make the regulator's expectations explicit. PIPEDA's own penalties are weak, but reform tabled in June 2026 (Bill C-36) would bring fines up to the greater of C$25 million or 5% of gross global revenue, so practices built now will be judged under a much harder regime.

Who it applies to

  • Private-sector organizations across Canada handling personal information in commercial activity
  • Federally regulated businesses (banks, telecoms, airlines) including their employee data
  • Organizations in provinces without substantially similar laws (everywhere except Quebec, British Columbia, and Alberta for intra-provincial matters)
  • Personal information crossing provincial or national borders, including prompts sent to US-hosted AI vendors

Enforcement and penalties

PIPEDA's direct penalties are limited, which is exactly why reform keeps returning. The OPC investigates complaints and issues findings, but cannot fine for most violations; complainants and the Commissioner can take matters to the Federal Court, which can award damages and order remediation, and the OPC can name organizations publicly. Offences such as failing to keep breach records or obstructing an investigation carry fines up to C$100,000. Bill C-27, which would have replaced PIPEDA's privacy part with real administrative penalties, died on the Order Paper when Parliament was prorogued in January 2025. Its successor, Bill C-36 (tabled June 2026), proposes penalties up to the greater of C$25 million or 5% of gross global revenue and a new enforcement body, so the current soft-penalty era is best treated as temporary.

Key provisions for AI and data privacy

Schedule 1, Principle 4.1 (Accountability)

Accountability: you answer for personal information, including at your AI vendor

An organization is responsible for personal information under its control and must designate someone accountable for compliance. Accountability follows the data: information transferred to a third party for processing must be protected by contractual or other means to a comparable level.

When employees send personal information to an AI tool, the organization stays accountable for what happens to it, whether the tool was approved or not. The OPC's position on transfers for processing means you need contractual protections and actual oversight of AI vendors receiving personal data. Shadow AI use breaks this principle directly: LayerX found in 2025 that organizations have no insight into roughly 89% of AI usage, and nobody can be accountable for flows they cannot see.

Schedule 1, Principle 4.3 (Consent)

Consent: the consent you collected rarely covers AI processing

Knowledge and consent of the individual are required for the collection, use, or disclosure of personal information, except where inappropriate. The form of consent depends on the sensitivity of the information, and consent is only valid if individuals could reasonably understand what they were agreeing to.

Customers who consented to have their data used to deliver a service did not thereby consent to having it pasted into an external AI chatbot, especially one that may retain or train on inputs. Using personal information in AI tools is a new purpose that generally needs fresh consent or a careful exception analysis. The safest operational answer is to keep identifiable personal information out of prompts altogether, so the consent question never arises.

Schedule 1, Principle 4.5 (Limiting Use, Disclosure, and Retention)

Limiting use: data collected for one purpose cannot become prompt material for another

Personal information shall not be used or disclosed for purposes other than those for which it was collected, except with consent or as required by law, and shall be retained only as long as necessary.

Pasting a client file into an AI tool to draft an email, summarize a case, or debug a report is a use, and often a disclosure to the vendor, that was almost never among the identified purposes at collection. Retention is also implicated: AI vendors may keep prompt data on their own schedules, outside your retention policy. Redacting identifiers before submission lets employees get the drafting and summarizing value without triggering a new use of identifiable data.

Schedule 1, Principle 4.7 (Safeguards)

Safeguards: protection proportionate to sensitivity, at the point where data actually leaves

Personal information must be protected by security safeguards appropriate to its sensitivity, including physical, organizational, and technological measures, protecting against loss, theft, unauthorized access, disclosure, copying, use, or modification.

An acceptable-use policy alone is not a technological safeguard. IBM's 2025 breach study found only 17% of organizations have technical controls that redact or block sensitive data at the point of entry, that 97% of organizations suffering AI-related breaches lacked proper AI access controls, and that shadow AI involvement added an average of $670K to breach costs. Under Principle 4.7, the browser, where prompts are typed, is now a place safeguards must exist.

OPC Principles for Generative AI (December 2023)

OPC guidance: how the regulator reads PIPEDA against generative AI

In December 2023 the federal, provincial, and territorial privacy regulators published principles for responsible, trustworthy and privacy-protective generative AI. They stress legal authority and valid consent for personal information in training and prompts, appropriate purposes, limiting collection, transparency, and accountability across the AI supply chain.

The guidance removes any argument that PIPEDA is silent on generative AI: regulators expect organizations to establish legal authority before personal information goes into prompts, to limit what goes in to what is necessary, and to remain accountable for downstream handling by the AI provider. It also flags that information relating to children and other sensitive data warrants heightened protection. Organizations deploying or merely tolerating AI tools are expected to have asked and answered these questions in advance.

Practical compliance steps

  1. 1Designate an accountable privacy lead whose mandate explicitly covers employee AI tool use
  2. 2Inventory where personal information could enter AI tools, including unapproved browser-based chatbots, not just procured systems
  3. 3Review your consents and identified purposes, and treat AI processing of identifiable data as a new purpose unless it clearly is not
  4. 4Adopt a written rule that identifiable personal information does not enter external AI prompts, and name the narrow exceptions
  5. 5Deploy a technological safeguard that catches and redacts personal information in prompts before submission, satisfying Principle 4.7 where policy alone cannot
  6. 6Put contracts and transfer assessments in place for any AI vendor that will receive personal information, especially US-hosted ones
  7. 7Log and review interception and usage evidence so accountability is demonstrable, not asserted

How Sanitized AI maps to this

Principle 4.7 (Safeguards)

Personal information such as names, contact details, SINs, and financial identifiers is caught and redacted in prompts before submission, providing the technological safeguard the principle requires at the point where data actually leaves.

Principle 4.5 (Limiting Use and Disclosure)

Because identifiers are removed before a prompt goes out, employees can use AI for drafting and summarizing without turning collected personal information into an unauthorized new use or disclosure.

Principle 4.1 (Accountability)

Admin dashboards show which AI tools are in use and what categories of personal data were caught, giving the accountable officer evidence of oversight instead of assumptions.

Cross-border transfer exposure

Redaction before submission means prompts reaching US-hosted vendors carry less identifiable personal information in the first place, shrinking the transfer that accountability and contract clauses must cover.

Frequently asked questions

Does PIPEDA apply to employees using ChatGPT at work?

Yes, whenever personal information is involved. If an employee pastes customer, patient, or colleague data into any AI tool in the course of commercial activity, PIPEDA's principles apply: it is a use, usually a disclosure to the vendor, and the organization remains accountable. Whether the tool was approved by IT makes no difference to the law.

Is putting personal information into an AI prompt a disclosure under PIPEDA?

Treat it as one. The information leaves your organization for the AI vendor's systems, which the OPC analyzes as a transfer for processing at minimum: you stay accountable and must ensure comparable protection through contracts and oversight. If the vendor can use the data for its own purposes, such as model training, it goes beyond processing and raises a consent problem.

Do we need consent before using customer data in AI tools?

Generally, yes, unless the AI use fits within the purposes identified when the data was collected, which is rare for data gathered before the generative AI era. New purposes need fresh consent, and sensitivity raises the bar. The practical alternative is to de-identify or redact the data before it enters the tool, so the prompt no longer contains personal information.

Can Canadian companies send personal information to US-hosted AI vendors?

PIPEDA does not prohibit cross-border transfers, but accountability travels with the data: you need contractual protections, transparency with individuals that their information may be processed abroad, and awareness that data in the US is subject to US legal access. Quebec's Law 25 goes further and requires a formal assessment before communicating personal information outside Quebec.

What are the penalties for violating PIPEDA?

Currently modest: OPC findings, Federal Court damages, public naming, and fines up to C$100,000 for specific offences like failing to keep breach records. That is changing. After Bill C-27 died in January 2025, the government tabled Bill C-36 in June 2026, proposing penalties up to the greater of C$25 million or 5% of gross global revenue under a new enforcement regime.

What is the OPC's guidance on generative AI?

In December 2023, Canada's federal, provincial, and territorial privacy regulators jointly published principles for responsible, trustworthy and privacy-protective generative AI. They expect organizations to have legal authority and valid consent for personal information used in prompts or training, to limit what goes in, to be transparent, and to remain accountable for what AI providers do with the data downstream.

Primary sources

This guide summarizes the cited primary sources as of the verification date. It is general information, not legal advice.

The gap in every framework is the prompt box.

Sanitized AI catches sensitive data in prompts before it leaves and shows administrators which AI tools employees actually use.

Get a demo

Related standards