Practical AI for Australian Small Business

AI Governance in Canada: What PIPEDA, the OPC and Quebec Law 25 Actually Say

Canadian AI governance is not contained in one statute. For private-sector businesses, the starting point is usually an existing privacy law whose application depends on the organisation, province and movement of personal information. This reference separates those layers so that a business can identify the relevant authority and open the source itself.

Last verified: 3 September 2026. References checked against current legislation.

Editorial Perspective

This page records what Canada’s federal Privacy Commissioner, PIPEDA, Quebec’s private-sector privacy law, and the private-sector statutes of British Columbia and Alberta say about AI and personal information. Each consequential point links to a primary source. It reports law and regulator guidance rather than giving legal advice or deciding how either applies to a particular business. Practical rollout steps belong in Need to Know AI’s implementation guidance, not in this jurisdiction reference.

This article summarises publicly available guidance from regulators and official sources. It is general educational information only and does not constitute legal or professional advice. Requirements vary by jurisdiction. Consult your regional authority or a qualified professional for advice specific to your situation.

Canadian AI governance is not contained in one statute. For private-sector businesses, the starting point is usually an existing privacy law whose application depends on the organisation, province and movement of personal information. This reference separates those layers so that a business can identify the relevant authority and open the source itself.

In short: PIPEDA remains the federal private-sector privacy law as at 3 September 2026, but Quebec, British Columbia and Alberta have substantially similar provincial laws that generally govern provincially regulated organisations within those provinces. Quebec’s legislation contains an express rule for decisions based exclusively on automated processing. Bill C-27 and its proposed Artificial Intelligence and Data Act did not become law, while Bill C-36 remains a proposal rather than legislation in force.

Canada’s AI privacy map has four private-sector layers

The applicable privacy framework cannot be identified from the word “AI” alone. The Office of the Privacy Commissioner of Canada’s jurisdiction guidance distinguishes federal businesses, commercial activity in provinces without substantially similar legislation, provincial activity in Quebec, British Columbia and Alberta, and personal information crossing provincial or national borders.

Business or data context Primary private-sector framework Authority or source
A federally regulated business, such as a bank, airline or telecommunications company PIPEDA Federal statutory text and the federal Privacy Commissioner
Commercial activity in a province without a substantially similar general private-sector law PIPEDA OPC summary of PIPEDA’s application
A provincially regulated enterprise handling information within Quebec Quebec’s Act respecting the protection of personal information in the private sector Official enacted text (2021, c. 25) and the Commission d’accès à l’information du Québec
A provincially regulated organisation handling information within British Columbia British Columbia’s Personal Information Protection Act Official British Columbia statutory text and the provincial Information and Privacy Commissioner
A provincially regulated organisation handling information within Alberta Alberta’s Personal Information Protection Act Government of Alberta PIPA reference and the provincial Information and Privacy Commissioner
Personal information crossing provincial or national borders during commercial activity PIPEDA may apply to that transaction, including where a substantially similar provincial law also matters OPC federal and provincial jurisdiction guidance

This split can change the source that answers an otherwise similar question. For example, an Ontario professional-services firm considering whether customer records will enter an AI service would ordinarily begin with the federal framework, while a Quebec enterprise would need to examine Quebec’s statute and its more specific provisions. That illustration does not determine the law for a particular organisation, especially where regulated sectors, employment information or cross-border processing complicate the facts.

PIPEDA applies existing privacy principles to AI rather than naming the technology

PIPEDA does not depend on a system being marketed as artificial intelligence. Its central private-sector rules concern an organisation’s collection, use and disclosure of personal information in commercial activity, so an AI workflow enters the framework when it processes information about an identifiable individual within the Act’s scope.

Section 5 of PIPEDA incorporates the obligations in Schedule 1 and says an organisation may collect, use or disclose personal information only for purposes a reasonable person would consider appropriate in the circumstances. Section 6.1 says consent is valid only where it is reasonable to expect that the person would understand the nature, purpose and consequences of the relevant handling of information.

Schedule 1 covers accountability, identifying purposes, consent, limiting collection, limiting use and retention, accuracy, safeguards, openness, individual access and challenges to compliance. These are technology-neutral principles. They can therefore reach activities such as sending customer information to a generative system, using personal information to train or refine a model, producing information about an identifiable person, or relying on an AI output in a decision.

PIPEDA also keeps accountability with the organisation when information is transferred to another processor. The OPC’s cross-border processing guidelines state that Principle 4.1.3 makes an organisation responsible for personal information transferred to a third party for processing and calls for contractual or other means that provide a comparable level of protection. The same guidance says PIPEDA does not prohibit processing outside Canada, but foreign law can affect the information and no contract can override that law.

The OPC’s generative AI principles describe its regulatory expectations

Canada’s privacy regulators have said that generative AI does not sit outside existing privacy legislation. Their principles for responsible, trustworthy and privacy-protective generative AI were published on 7 December 2023 for developers, providers and organisations using these systems.

The document addresses legal authority and consent, appropriate purposes, necessity and proportionality, openness, accountability, individual access, limits on collection and retention, accuracy and safeguards. It also says organisations using generative AI should communicate the role of the system in significant decision-making, retain accountability for decisions, and provide an effective challenge mechanism for affected people.

Those statements need to be read with the document’s own limits. The regulators say the principles do not exhaustively describe every requirement, may evolve as the technology develops, and do not bind the outcome of a particular investigation. The document is authoritative guidance from Canadian privacy regulators, but it is not a separate AI statute or a substitute for the text of the applicable law.

The OpenAI and Grok findings show how the OPC has applied existing law

Two 2026 investigations provide concrete examples of Canadian privacy authorities applying existing legislation to generative AI. They are findings about particular evidence and respondents, not universal rulings on every AI service or every business use.

On 6 May 2026, the federal, Quebec, British Columbia and Alberta privacy authorities published their joint investigation of OpenAI. The investigation examined personal information obtained from publicly accessible sources, licensed sources and interactions with ChatGPT, including consent, appropriate purposes, accuracy, openness, access and accountability.

The regulators found contraventions under PIPEDA and the British Columbia and Alberta statutes relating to matters including valid consent and openness. The federal Privacy Commissioner described the PIPEDA issues as well-founded and conditionally resolved in light of commitments and mitigation measures, while the provincial findings did not always reach the same result because the statutory consent provisions differ. The report expressly warns against treating “substantially similar” laws as identically worded rules.

On 11 June 2026, the OPC published its Grok report of findings. It found that X Corp. and xAI had not obtained valid consent for collecting, using and disclosing personal information to generate sexualised deepfakes and that the purpose was inappropriate under section 5(3) of PIPEDA.

The OPC classified images of identifiable people generated by the service as their personal information even when depicted characteristics were artificial. It found the complaints well-founded and not resolved at the date of the report, and it made recommendations concerning suspension of the relevant functionality, risk assessment, audits, monitoring and safeguards. Those recommendations arose from that investigation and are not a general statutory checklist for every organisation using an image generator.

Quebec Law 25 adds a specific rule for exclusively automated decisions

“Law 25” is the common name for the 2021 reform statute that amended Quebec’s privacy framework. The operative private-sector provisions now appear in Quebec’s Act respecting the protection of personal information in the private sector, as amended by 2021, c. 25, so that consolidated Act is the primary text to consult.

Section 12.1, as enacted by 2021, c. 25 addresses a decision based exclusively on automated processing of personal information. It says the enterprise is to inform the person no later than when it communicates the decision. At the person’s request, the enterprise is also to provide the personal information used, the reasons and principal factors and parameters that led to the decision, and information about the right to have the personal information corrected.

The same provision gives the person an opportunity to submit observations to a staff member able to review the decision. The word “exclusively” is important: section 12.1 does not say that every process in which software assists a human decision-maker is an exclusively automated decision. Whether a particular workflow crosses that line depends on how the decision is actually made, which this reference cannot determine.

Quebec’s Act also contains provisions relevant to AI projects even when section 12.1 is not the central issue. Section 3.3, as enacted by 2021, c. 25 calls for a privacy impact assessment when an enterprise acquires, develops or overhauls an information system or electronic service-delivery system involving personal information. The assessment is to be proportionate to the sensitivity, purpose, quantity, distribution and storage medium of the information.

Section 17 addresses communication of personal information outside Quebec. It calls for a privacy impact assessment considering the information, purpose, safeguards and destination’s legal framework, followed by a written agreement that reflects the assessment where the information receives adequate protection. This provision is particularly relevant to cloud and AI vendors that process information outside the province, but the statute, rather than a generic vendor checklist, determines its terms.

Section 11 says personal information used to make a decision about a person is to be accurate and up to date and retained for at least one year after the decision. Sections 3.1 and 3.2 address responsibility for personal information and governance policies and practices. Together, these provisions make Quebec’s framework more explicit than PIPEDA on automated decisions, system assessments and internal privacy governance.

British Columbia and Alberta use their own PIPA consent rules

British Columbia and Alberta each have a Personal Information Protection Act, usually shortened to PIPA. These statutes are considered substantially similar to PIPEDA for the federal exemption framework, but their wording and application remain distinct.

British Columbia’s Personal Information Protection Act covers provincially regulated organisations and includes rules on consent, collection, use, disclosure, employee personal information, access and correction. Sections 6 to 8 contain its core consent provisions, while section 11 limits collection to purposes a reasonable person would consider appropriate in the circumstances.

Alberta’s government describes its Personal Information Protection Act as the province’s private-sector privacy law for provincially regulated businesses and, in some circumstances, non-profit organisations. The federal Alberta exemption order exempts covered non-federal organisations from Part 1 of PIPEDA for handling that occurs within Alberta.

The 2026 OpenAI investigation illustrates why the distinction matters. The British Columbia and Alberta commissioners found that the specific provincial conditions for implicit, deemed or notice consent were not established for certain collection and use of publicly accessible information, even where the federal Commissioner accepted a different path under PIPEDA for future models subject to stated mitigations. “Substantially similar” therefore describes the jurisdictional arrangement, not interchangeable answers to every AI privacy question.

Bill C-27 ended, while Bill C-36 is pending privacy reform

Bill C-27 did not become law. Parliament’s LEGISinfo record for C-27 shows that the bill belonged to the parliamentary session that ended on 6 January 2025 and that committee consideration was not completed. Its proposed Consumer Privacy Protection Act and Artificial Intelligence and Data Act, usually called AIDA, therefore did not enter into force.

A new federal proposal appeared on 15 June 2026. The LEGISinfo record for Bill C-36 listed it at second reading in the House of Commons, with no second-reading activity recorded, when checked on 3 September 2026.

The first-reading text of C-36 proposes a Protecting Privacy and Consumer Data Act and would repeal Part 1 of PIPEDA if enacted and brought into force. It does not revive C-27’s proposed AIDA as part of the bill. Until the parliamentary process and commencement provisions are completed, PIPEDA remains the operative federal private-sector law addressed in this reference.

Canadian regulator guidance leaves material questions unresolved

The sources establish privacy principles, jurisdictional boundaries and findings on specific facts. They do not provide a single approval test for an AI product, certify that a particular deployment complies with every applicable law, or decide whether a partly automated workflow is “exclusively” automated under Quebec section 12.1.

The OPC’s generative AI principles acknowledge that the field is evolving and that the guidance neither exhausts all requirements nor binds future investigations. PIPEDA also does not turn every risk assessment recommended by regulators into a universal statutory PIA requirement for private-sector organisations. Quebec section 3.3 is more explicit, while the Alberta privacy regulator says there is no PIA requirement in Alberta PIPA for private-sector organisations, although it recommends PIAs as a risk-management practice.

AI in hiring also crosses beyond this page’s privacy-law boundary. PIPEDA or a provincial privacy statute can govern personal information used in recruitment, and Quebec section 12.1 may matter where a decision is based exclusively on automated processing. Employment standards, human rights, collective agreements and sector rules raise separate questions that require their own authorities and factual analysis.

Questions that identify the relevant Canadian source

A business or adviser reviewing an AI use can frame the source check around questions rather than assuming one national rule supplies every answer:

  • Is the organisation federally regulated, provincially regulated, or operating in more than one jurisdiction?
  • Which province contains the relevant collection, use or disclosure, and does information cross a provincial or national border?
  • Does the system process information about identifiable customers, employees, applicants or other individuals?
  • What purpose was stated when the information was collected, and does the AI service use it for another purpose such as model training?
  • Which party controls the information, and what does the vendor’s contract say about processing, retention, safeguards, subprocessors and foreign access?
  • In Quebec, is a decision truly based exclusively on automated processing, or does a person exercise meaningful decision-making authority?
  • Which regulator has published guidance or findings on the specific issue, and where does that source say its guidance stops?
  • Does the activity involve health, employment, credit, insurance, children or another context governed by additional legislation?

These questions do not produce a compliance conclusion. They identify facts that can be matched to the statutory text, regulator guidance or advice from a qualified Canadian professional.

How this was researched

This guide is researched against primary regulatory sources and official regulator guidance, checked against those documents as of the date shown, and written for a business with no dedicated compliance function. We report what a named authority has published and link the document so you can read it yourself. We do not tell you what your legal obligations are.

Related reading: our AI governance by region.

Related reading: Claude AI Review: Pricing, Features, and Business Verdict and Is Claude Pro Worth It? An Honest Assessment for Business Users.

Free tools: AI Privacy Risk Scorer to score your current AI tool setup against data-privacy best practice | AI Policy Generator to generate a customised AI policy for your business.

Does Canada currently have a federal Artificial Intelligence and Data Act?

No AIDA entered into force through Bill C-27. The parliamentary record shows that C-27’s session ended on 6 January 2025 before committee consideration was completed. Other laws can still apply to AI activities, including existing privacy legislation.

Does PIPEDA apply to every Canadian business using AI?

No. The OPC’s jurisdiction guidance explains that Quebec, British Columbia and Alberta have substantially similar private-sector laws, while PIPEDA continues to cover federal businesses and relevant interprovincial or international transactions. Sector-specific statutes can add another layer.

Does Quebec Law 25 prohibit automated decisions?

Section 12.1 does not state a general prohibition. The provision, as enacted by 2021, c. 25 sets information and review-related rules where an enterprise renders a decision based exclusively on automated processing of personal information.

Does PIPEDA require every private business to conduct a privacy impact assessment for AI?

The reviewed PIPEDA text does not create a general private-sector PIA provision equivalent to Quebec section 3.3. The Canadian regulators’ generative AI principles recommend assessments as an accountability measure, but the document says its guidance does not itself exhaust or determine legal requirements.

Does an AI vendor take over the customer organisation’s privacy accountability?

Not under the OPC’s interpretation of PIPEDA processing arrangements. Its cross-border processing guidance says the transferring organisation remains accountable and identifies contractual or other means as the mechanism for comparable protection. Quebec, British Columbia and Alberta require their own statutory analysis.

Methodology and verification record

This desk-research assessment was checked on 3 September 2026. It reviewed the consolidated PIPEDA text, official Quebec and British Columbia statutes, Government of Alberta materials, federal and provincial regulator guidance, the 2026 OpenAI and Grok findings, and LEGISinfo records and bill text for C-27 and C-36.

The method separates enacted law, regulator guidance, findings about named respondents and pending legislation. The four Quebec provisions cited here (sections 3.3, 11, 12.1 and 17) were read in the Quebec Official Publisher's English text of the enacting statute, An Act to modernize legislative provisions as regards the protection of personal information (2021, c. 25), because LegisQuebec's consolidated version of the Act was returning a server error on the check date. That enacted text is the source verified here; a subsequent amendment to those particular sections could not be checked against the consolidation while that site was unavailable. It does not infer an obligation where a source is silent, determine which law applies to a specific organisation, or extend a finding about one AI provider to another product.

Find official guidance for your region

Requirements vary by jurisdiction. This article provides general information only. Consult your regional authority or a qualified professional for advice specific to your situation.

The information in this article is general in nature. It reflects a summary of publicly available guidance and does not constitute legal, privacy, or professional advice. Your obligations will depend on your specific situation, jurisdiction, and business circumstances. Do not rely on this article as a substitute for qualified legal or professional advice.

Browse Need to Know AI’s practical implementation guides for operational planning resources that sit alongside this Canadian jurisdiction reference.

Browse Need to Know AI’s practical...

How this page was verified

On 3 September 2026, every consequential claim on this page was checked against the primary document it cites. Each source was fetched and read directly. The research of the model that drafted the page was not accepted as evidence for its own claims.

  • 21 claims checked
  • 17 confirmed against the cited source
  • 4 recorded as unverified

4 claims could not be confirmed because the source host was unreachable at the time of checking. They are recorded as unverified rather than assumed correct.

This is desk research against published documents. It is not independent testing, legal review, or an audit, and a document can change after it is checked. What this standard covers, and what it does not.