Schedule 1, Principle 4.1 (Accountability)
Accountability: you answer for personal information, including at your AI vendor
An organization is responsible for personal information under its control and must designate someone accountable for compliance. Accountability follows the data: information transferred to a third party for processing must be protected by contractual or other means to a comparable level.
When employees send personal information to an AI tool, the organization stays accountable for what happens to it, whether the tool was approved or not. The OPC's position on transfers for processing means you need contractual protections and actual oversight of AI vendors receiving personal data. Shadow AI use breaks this principle directly: LayerX found in 2025 that organizations have no insight into roughly 89% of AI usage, and nobody can be accountable for flows they cannot see.
Schedule 1, Principle 4.3 (Consent)
Consent: the consent you collected rarely covers AI processing
Knowledge and consent of the individual are required for the collection, use, or disclosure of personal information, except where inappropriate. The form of consent depends on the sensitivity of the information, and consent is only valid if individuals could reasonably understand what they were agreeing to.
Customers who consented to have their data used to deliver a service did not thereby consent to having it pasted into an external AI chatbot, especially one that may retain or train on inputs. Using personal information in AI tools is a new purpose that generally needs fresh consent or a careful exception analysis. The safest operational answer is to keep identifiable personal information out of prompts altogether, so the consent question never arises.
Schedule 1, Principle 4.5 (Limiting Use, Disclosure, and Retention)
Limiting use: data collected for one purpose cannot become prompt material for another
Personal information shall not be used or disclosed for purposes other than those for which it was collected, except with consent or as required by law, and shall be retained only as long as necessary.
Pasting a client file into an AI tool to draft an email, summarize a case, or debug a report is a use, and often a disclosure to the vendor, that was almost never among the identified purposes at collection. Retention is also implicated: AI vendors may keep prompt data on their own schedules, outside your retention policy. Redacting identifiers before submission lets employees get the drafting and summarizing value without triggering a new use of identifiable data.
Schedule 1, Principle 4.7 (Safeguards)
Safeguards: protection proportionate to sensitivity, at the point where data actually leaves
Personal information must be protected by security safeguards appropriate to its sensitivity, including physical, organizational, and technological measures, protecting against loss, theft, unauthorized access, disclosure, copying, use, or modification.
An acceptable-use policy alone is not a technological safeguard. IBM's 2025 breach study found only 17% of organizations have technical controls that redact or block sensitive data at the point of entry, that 97% of organizations suffering AI-related breaches lacked proper AI access controls, and that shadow AI involvement added an average of $670K to breach costs. Under Principle 4.7, the browser, where prompts are typed, is now a place safeguards must exist.
OPC Principles for Generative AI (December 2023)
OPC guidance: how the regulator reads PIPEDA against generative AI
In December 2023 the federal, provincial, and territorial privacy regulators published principles for responsible, trustworthy and privacy-protective generative AI. They stress legal authority and valid consent for personal information in training and prompts, appropriate purposes, limiting collection, transparency, and accountability across the AI supply chain.
The guidance removes any argument that PIPEDA is silent on generative AI: regulators expect organizations to establish legal authority before personal information goes into prompts, to limit what goes in to what is necessary, and to remain accountable for downstream handling by the AI provider. It also flags that information relating to children and other sensitive data warrants heightened protection. Organizations deploying or merely tolerating AI tools are expected to have asked and answered these questions in advance.