AI privacy compliance Canada
AI Privacy Compliance in Canada: PIPEDA, PIPA and Bots
Statistics Canada reported on June 11, 2026 that 19.2% of Canadian businesses had used AI to produce goods or deliver services in the previous 12 months, up from 6.1% two years earlier, and that 28.2% of those AI users were running virtual agents or chat bots (Statistics Canada). Plenty of those bots are being handed real customer records.
That's where AI privacy compliance in Canada stops being an abstraction. Here's what a BC business should sort out before the first customer record goes into a chatbot.
Two privacy laws, and the one that probably applies to you
If you run a shop in Burnaby or a clinic in New Westminster, your default privacy law is BC's Personal Information Protection Act (PIPA), not the federal PIPEDA. PIPEDA governs federally regulated businesses like banks, telecoms and airlines, plus personal information crossing provincial or national borders in commercial activity.
This matters because vendors wave the wrong certificate constantly. The BC Office of the Information and Privacy Commissioner puts it plainly: "it is PIPA that applies to the use of AI scribes in BC. If data flows outside of BC, PIPA still applies to the personal information involved." The same guidance adds a warning worth taping to your monitor: "there is no accreditation program in Canada that assesses or approves companies' claims of legal compliance" (BC OIPC).
The regulators have already ruled on a case like this
On May 6, 2026 the Privacy Commissioner of Canada, with the Quebec, BC and Alberta commissioners, published findings from a joint investigation into OpenAI. They concluded that "the nature and scale of OpenAI's collection and use of personal information from publicly accessible websites and licensed datasets... was overbroad and therefore not necessary and proportional," and that "OpenAI did not have implied consent for its collection and use of individuals' personal information from publicly accessible websites and licensed third-party sources" (OPC, PIPEDA Findings #2026-002).
Read that second finding with your own lead list in mind. "It was publicly available" is not a legal basis. If you're scraping public profiles into an AI enrichment pipeline, you're on the ground the commissioners just rejected.
Your vendor's compliance is not your compliance
This is the most common mistake. From the BC OIPC guidance: "An organization cannot avoid its obligations under PIPA by contracting with another organization to store or use personal information on its behalf. Under PIPA, an organization remains responsible for personal information under its control, even when the personal information is not in its custody."
Canada's federal, provincial and territorial privacy regulators said the same thing about AI specifically back on December 7, 2023: "Accountability for decisions rests with the organization, and not with any kind of automated system" (OPC and provincial regulators).
If your AI receptionist mishandles a caller's health details, the complaint lands on you, not your model provider.
Consent has to be express, specific, and revocable
The BC guidance is written for healthcare, but the consent reasoning generalizes. Organizations "must get express consent from patients, rather than implicit consent," because AI tools are novel, vary enormously between products, and it "will not be obvious to a reasonable person what an AI scribe is, how much personal information it is collecting, and how it will use their personal information."
It also rejects vague purpose statements: "healthcare" is not specific enough to satisfy the collection notice requirement. People must be able to say no, must be told they can withdraw later, and you need a fallback if they decline. And if your vendor ships an update that turns a transcription tool into something that makes recommendations, your old consent doesn't cover it. The regulators' AI principles also say to "clearly communicate to any affected party whether a generative AI tool will be used as part of a decision-making process, and if so, in what capacity," and to prefer anonymized or de-identified information in prompts over personal information.
What to actually check in the vendor's documentation
Before you connect anything to customer data, get written answers to these:
- Does the vendor use your inputs, outputs, or "de-identified" derivatives to train models or for any secondary purpose?
- How long is data retained, and can you shorten it?
- Where is it processed and stored, and under whose laws?
- Is the vendor contractually required to notify you of breaches on their end, and of updates that change how data is handled?
- Do you keep the contractual right to control, modify and delete records the tool generates?
- What happens to the data if the vendor is sold, merged, or goes under?
Two examples, checked in August 2026. OpenAI's API documentation states that "As of March 1, 2023, data sent to the OpenAI API is not used to train or improve OpenAI models (unless you explicitly opt in to share data with us)," and that "by default, abuse monitoring logs are generated for all API feature usage and retained for up to 30 days." Zero Data Retention is available only on some endpoints, with stateful ones like conversations and assistants listed as ineligible. Data residency options include Canada, and the page notes that models released on or after March 5, 2026 carry a 10% pricing uplift where data residency is supported (OpenAI).
Anthropic's Commercial Terms, effective June 17, 2025, state that "Anthropic may not train models on Customer Content from Services" (Anthropic). Its privacy documentation, effective July 1, 2026, says that for the API "we automatically delete inputs and outputs on our backend within 30 days of receipt or generation," while content flagged for policy violations can be held up to 2 years and trust and safety scores up to 7 years (Anthropic privacy centre).
Both of those are commercial terms. Consumer chat subscriptions are governed by different documents with different training defaults. Pasting a client spreadsheet into a personal chat account is not the same act as sending it through a business API, and only one of those is defensible.
Retention, deletion, and breaches
PIPA section 35 requires you to destroy records containing personal information, or strip the identifiers, once the purpose is served and no legal or business need remains. One catch: if you used that information to make a decision that directly affects someone, you must keep it for at least a year so they have a fair chance to ask for it.
If PIPEDA applies to your business, you must report breaches of security safeguards that pose "a real risk of significant harm" to the OPC, notify affected individuals as soon as feasible, and keep records of every breach for 24 months whether it was reportable or not. Knowingly contravening those requirements is an offence (OPC breach guidance).
Where this doesn't apply
The BC guidance above is healthcare specific, and health data sits at the top of the sensitivity scale. A restaurant's reservation bot that captures a name and a phone number is a lighter analysis than a clinic recording a patient conversation. Don't import the strictest reading into a low risk workflow and conclude AI is off limits.
Volume matters too. If you get fifteen enquiries a week and a staff member clears them in twenty minutes a day, the assessment, the consent script, the vendor review and the retention policy will cost more than the automation saves. Wait until the volume justifies the governance.
There's a real tradeoff hiding in the controls, too. Zero Data Retention rules out the stateful endpoints that give a bot memory across a conversation, and Canadian data residency costs more and covers a subset of models. A tighter privacy posture buys you a less capable assistant, and pretending otherwise is how projects stall in month three.
One area is thin rather than settled: PIPA contains no provisions specific to disclosing personal information outside Canada. The obligation arrives indirectly, through the section 34 duty to make reasonable security arrangements. The OIPC recommends a privacy impact assessment with a cross border component, and that's a recommendation, not a requirement.
And the checklist's own bottom line: "If you cannot identify a PIPA authority for each of the collections, uses, or disclosures of personal information involved in your initiative, don't go ahead with it!"
Sources
- Statistics Canada, "Analysis on artificial intelligence use by businesses in Canada, second quarter of 2026," June 11, 2026. https://www150.statcan.gc.ca/n1/pub/11-621-m/11-621-m2026010-eng.htm
- Office of the Information and Privacy Commissioner for British Columbia, "PIPA and AI scribes: best practices for healthcare organizations in BC," January 28, 2026. https://www.oipc.bc.ca/documents/guidance-documents/3082
- Office of the Privacy Commissioner of Canada et al., "PIPEDA Findings #2026-002: Joint Investigation of OpenAI OpCo, LLC," May 6, 2026. https://www.priv.gc.ca/en/opc-actions-and-decisions/investigations/investigations-into-businesses/2026/pipeda-2026-002/
- Canadian federal, provincial and territorial privacy regulators, "Principles for responsible, trustworthy and privacy-protective generative AI technologies," December 7, 2023. https://www.priv.gc.ca/en/privacy-topics/technology/artificial-intelligence/gd_principles_ai/
- Office of the Privacy Commissioner of Canada, "What you need to know about mandatory reporting of breaches of security safeguards." https://www.priv.gc.ca/en/privacy-topics/business-privacy/breaches-and-safeguards/privacy-breaches-at-your-business/gd_pb_201810/
- OpenAI, "Your data" (API platform documentation), accessed August 2026. https://developers.openai.com/api/docs/guides/your-data
- Anthropic, "Commercial Terms of Service," effective June 17, 2025. https://www.anthropic.com/legal/commercial-terms
- Anthropic, "How long do you store personal data?" privacy centre, effective July 1, 2026. https://privacy.claude.com/en/articles/7996866-how-long-do-you-store-personal-data
None of this is legal advice, and a lawyer who knows PIPA is worth the money before you go live with anything sensitive. But most of the work is design: choosing what the bot never sees, writing a consent line people understand, setting retention to the shortest window that works, and keeping a human on anything that decides something about a person. If you'd like a hand mapping that out for your own workflows, book a free call with Autana and we'll walk through it together.
Want an AI employee for your business?
We install a 24/7 AI worker for businesses in Vancouver, Burnaby, and beyond. Book a free Discovery Call.
Book a call →

