PIPEDA was drafted in 2000 and does not mention artificial intelligence. It is nonetheless the federal law that governs it, and the Office of the Privacy Commissioner has been applying it to AI systems for years — with two outcomes that tell you more than the guidance does.
What is left after AIDA
The Personal Information Protection and Electronic Documents Act applies to organisations that collect, use or disclose personal information in the course of commercial activities. Its substantive rules are in Schedule 1, which incorporates ten fair information principles: accountability, identifying purposes, consent, limiting collection, limiting use disclosure and retention, accuracy, safeguards, openness, individual access, and challenging compliance. Sections 5(3), 6.1 and the access and complaint provisions in Part 1 sit on top. The Act is on the Justice Laws Website.
Because AIDA died on prorogation in January 2025, this is the operative federal framework, not a stopgap. Alberta, British Columbia and Quebec have substantially similar private-sector laws that displace PIPEDA within their provinces, and health information statutes apply in most provinces.
The OPC’s findings are the Commissioner’s view. Under PIPEDA the Commissioner is an ombudsman: findings are not binding orders, and enforcement runs through an application to the Federal Court under section 14. That distinction matters when someone tells you an OPC finding “requires” something. This page is not legal advice.
The generative AI principles document
In December 2023 the OPC, together with provincial and territorial privacy regulators, published principles for responsible, trustworthy and privacy-protective generative AI technologies. It is guidance, not a regulation, and it maps generative AI practices onto existing obligations. The substantive positions worth extracting:
- Legal authority and consent. Organisations must establish valid authority for each collection and use, including for training data. Scraping publicly accessible data does not remove the need for authority, because publicly available does not mean “publicly available information” within the narrow regulatory exception.
- Appropriate purposes. Some uses cannot be consented into legitimacy at all — see the next section.
- Openness and explainability. Individuals should be told when they are interacting with an AI system and how their information is used, in terms they can understand rather than in a model card.
- Accountability. Privacy impact assessments, documented at design time, with human oversight proportionate to the impact.
- Individual rights. Access and correction rights apply to personal information held in and produced by these systems, which is difficult but is not thereby excused.
The OPC’s AI material is collected on its own site. It also opened an investigation into OpenAI in May 2023, jointly with the Quebec, British Columbia and Alberta regulators; treat any statement about its conclusions as requiring verification against the OPC’s published findings rather than against news coverage.
Section 5(3): appropriate purposes
Section 5(3) of PIPEDA is the provision that does the heaviest lifting in AI cases and has no direct GDPR equivalent. It provides that an organisation may collect, use or disclose personal information only for purposes that a reasonable person would consider appropriate in the circumstances. It is a standalone limit: it operates even where valid consent was obtained, so consent cannot cure an inappropriate purpose.
The clearest application is the joint finding on Clearview AI, issued in February 2021 by the OPC with the Quebec, British Columbia and Alberta commissioners. The regulators concluded that Clearview’s scraping of billions of images from public websites to build a facial recognition database, and its provision of that database to law enforcement, contravened PIPEDA: the collection was without consent, publicly accessible was not the same as the regulatory exception, and — most importantly — the purposes were inappropriate under section 5(3) regardless of consent, because they created the risk of mass surveillance of people who had done nothing to warrant it.
That is the finding to reason from when assessing a training-data pipeline in Canada. The question is not only whether you can identify a basis for collection but whether a reasonable person would consider the purpose appropriate, and scale and surveillance potential are part of that assessment.
Meaningful consent, after the Facebook appeal
Section 6.1 requires that consent is valid only if it is reasonable to expect that the individual would understand the nature, purpose and consequences of the collection, use or disclosure. How demanding that is was tested in Canada (Privacy Commissioner) v. Facebook, Inc., 2024 FCA 140, decided by the Federal Court of Appeal on 9 September 2024. The Federal Court had dismissed the Commissioner’s application on the basis that no expert or subjective evidence had been led about user expectations. The Court of Appeal set that aside, holding that the standard is objective and can be assessed by the court on the record, and that Facebook had failed to obtain meaningful consent for disclosure of user data to third-party applications and had failed to adequately safeguard it.
For AI the implication is direct and unhelpful to the industry’s usual practice. A buried clause permitting use of user content to improve services is unlikely to constitute meaningful consent for training a model on that content, and the absence of user complaints or survey evidence will not save it, because the standard does not depend on proving what users actually thought. Organisations relying on terms-of-service consent for training should assume the objective standard applies and design the notice accordingly.
What PIPEDA does not give you
Three gaps that anyone comparing Canada to Europe should know. PIPEDA contains no right to an explanation of an automated decision and no restriction on solely automated decision-making; the access right in Principle 4.9 reaches personal information about the individual, which is not the same as reasons. It has no general prohibition on any category of AI use, no risk classification and no registration. And the Commissioner has no order-making or fining power over the substantive principles, so the deterrent is reputational plus the cost of Federal Court proceedings.
Quebec is the exception on the first point, and it is a significant one: section 12.1 of its private-sector Act gives a genuine notification and explanation right for exclusively automated decisions. That is set out in the Law 25 page, and for a national deployment it is the provision that sets the floor, because building two decision pipelines is usually worse than building the Quebec-compliant one everywhere.
Top comments (0)