Rules · pipeda ai compliance canada
PIPEDA reaches your prompts. The OpenAI finding settled that.
The Privacy Commissioner's May 2026 OpenAI finding confirmed Canadian privacy law reaches AI training data, prompts and outputs. What that means for SMEs.
Lasse Pettersen
On May 6, 2026 the Office of the Privacy Commissioner of Canada released the results of a joint investigation into OpenAI and found that the initial training of ChatGPT did not comply with Canadian privacy law, with recommendations covering consent, transparency and data minimisation.
For an Ontario business that only wants to know what to do on Monday, the useful takeaway is narrower and blunter: personal information does not stop being personal information when it goes into a prompt. The consent, limitation and safeguard obligations under the Personal Information Protection and Electronic Documents Act follow it into training data, into retrieval corpora, into prompts and into outputs.
That is not a new law. It is the existing law, applied, in a decision you can point at.
The scale of the shift
Complaints to the federal Privacy Commissioner under PIPEDA rose 109% year over year to 3,044. That is not all about AI, and the Commissioner has attributed part of the increase to greater public awareness driven by AI-enhanced search. But the direction is unambiguous, and it arrives at the same time as a set of tools that make it very easy for an ordinary employee to disclose somebody else’s information without noticing.
Meanwhile Statistics Canada put Canadian business AI use at 19.2% in the second quarter of 2026, up from 6.1% two years earlier. Adoption tripled. Almost nobody wrote a rule first.
What this means in a normal business
Four situations cover most of it.
Somebody pastes a client list into a chatbot to tidy the formatting. That is a disclosure of personal information to a third party. Whether it is lawful depends on purpose, consent and the terms of the service, and in most cases nobody has considered any of the three.
A resume goes into a general chatbot to be summarised. Same category, with the extra problem that a job applicant handed you that information for one purpose. This intersects with Ontario’s hiring rules, covered in the Ontario AI job posting disclosure rule.
An intake agent on your website collects a name, a number and a description of a problem. That is collection by design, which is the easier case to handle properly because you get to design it. It needs a stated purpose, a retention rule, and a processor operating under an agreement.
A retrieval system is pointed at your shared drive so staff can ask it questions. This is the one that surprises people. Whatever is in that drive is now reachable through a new interface, including the folder of scanned identity documents somebody saved in 2019. The corpus is the exposure, not the model.
The five questions that decide the tooling
Before features, before price, before anybody demonstrates anything:
- Whose information is it? Yours, your staff’s, or your customers’. The third is the one that changes the answer.
- How sensitive is it? The Commissioner’s safeguards guidance expects controls proportionate to sensitivity, and names multi-factor authentication, encryption in transit and at rest, role-based access, vendor due diligence and monitored detection as a reasonable baseline for a typical small or mid-sized business.
- Where does it go? Which company, under which terms, in which country.
- Is it used for training? Consumer tiers and business tiers frequently differ on this, and the difference is usually the point of the business tier.
- How long is it kept, and who can delete it? Including conversation logs, which people forget are records.
Answer those five and the eligible tool list writes itself. Skip them and you will choose a tool on price and rewrite the project later, which is why this appears in the scope of every build I quote rather than as an afterthought.
What proportionate looks like for a 25 person firm
Not an enterprise privacy program. Six things, most of which take an afternoon each:
- A written list of approved tools, naming products rather than categories, and a matching list of what is not approved.
- A hard rule on what may never be entered into a general chatbot: customer and candidate personal information, anything under a confidentiality agreement, credentials, unreleased commercial terms.
- Business or enterprise tiers for anything used at work, chosen specifically because the terms differ on training and retention.
- A retention rule for conversation logs, decided by you rather than inherited from a default.
- A named human approval step for any output that affects a person or leaves the building.
- A dated record that you decided all of the above.
That last one matters more than it reads. Once you have looked at this properly, “nobody realised” stops being available as an explanation. Having the dated decision is what converts an incident from an unexplainable failure into a breach of a known rule, which is a materially better position to be in.
This is the scope of AI policy and staff training here, at $1,500 to $4,000 with a training half day included. It is the cheapest engagement on the site and, for most Ontario businesses, the correct first purchase.
What it means for a build
Three concrete effects on price and design, all of which belong in the quote rather than in a surprise later.
A smaller eligible tool list. The cheapest option is frequently ruled out at question three or four above, and a supplier who quotes a regulated process at the same price as an unregulated one has not understood which one you are.
An approval step. Where an output affects a person or commits money, a named human approves it and the approval is recorded. This is the rule I hold to on every build and it is not caution for its own sake: a model does not carry the consequence of a wrong decision, and the person harmed cannot appeal to it.
Data minimisation in the design. Send the fields the process needs, not the whole record. It is unglamorous, it costs a few hours, and it removes categories of risk permanently rather than mitigating them.
Where that sits in the overall arithmetic is covered in what AI consulting costs in Ontario, and the constraint is why the personal information row moves a build up its price band faster than technical complexity does.
What is coming, and what is not here yet
Federal privacy reform has been in and out of Parliament, with proposals carrying substantially higher penalties than the current regime and AI-specific provisions. Treat those as direction rather than as obligation: what binds you today is PIPEDA as it stands, plus sector rules, plus the provincial employment rules that already came into force.
The mistake is waiting for the definitive AI statute before writing a rule. The obligations that catch small businesses are the ones that have been in force for years and were simply never applied to a chatbot before.
The one thing to do this week
Ask your staff, without consequences attached, which AI tools they are already using and what they have put into them. The answer is always more than the owner expects. That conversation costs nothing, takes an hour, and is the single highest-value privacy activity available to a business that has not had it yet.
Then write the rule down. If you want the inventory and the rule produced together, that is what the $999 assessment covers alongside the automation work, and the fee comes off any build.
This is a summary of published findings and guidance rather than legal advice. Verify anything you intend to rely on with a lawyer or a privacy professional.