← All laws
PIPEDA (Canada)In forceCanada (federal)

Personal Information Protection and Electronic Documents Act (PIPEDA)

Last reviewed Sep 25, 2026.

In short

PIPEDA is Canada's federal private-sector privacy law. It has no AI-specific chapter, but its ten fair-information principles — accountability, identified purposes, consent, limited collection, limited use and retention, accuracy, safeguards, openness, access and challenge — apply to any AI that collects or uses personal data, from training on scraped data to automated decisions. The May 2026 joint findings on OpenAI confirmed that scraping personal data from the internet is not 'publicly available' information and needs a valid legal basis.

Who it applies to

  • Organisations that build or use AI systems in Canada (federal).
  • Any use case — it is not limited to specific applications.
  • Size: everyone, including solo operators.
  • Applies to private-sector organisations handling personal information in commercial activity across Canada (Alberta, BC and Quebec have substantially similar laws for in-province activity). AI is covered wherever it uses personal data.

Key dates

  1. Nov 1, 2018✓Mandatory breach reporting in force
  2. May 6, 2026✓OPC and provincial regulators publish joint findings on OpenAI/ChatGPT (PIPEDA Findings #2026-002)

What you have to do

  • Identify and document the purpose before collecting personal data for AI training or inference.
  • Obtain meaningful consent, or confirm an exception applies, for new uses such as model training.
  • Limit collection to what is necessary and set retention periods for training and prompt data.
  • Take reasonable steps to keep AI outputs about people accurate, and warn users where they may not be.
  • Give people access to their data and a way to challenge decisions made about them.
  • Report breaches of security safeguards that create a real risk of significant harm to the OPC and affected people.

Penalties

The Privacy Commissioner issues non-binding findings and may take matters to Federal Court for damages and orders. Knowingly failing to report or record a breach, or obstructing an investigation, is an offence with fines of up to C$100,000. Bill C-27, which would have added administrative penalties, died in January 2025.

Related lessons

Real cases

  • Ruling2024 · CA-BC
    Moffatt v. Air Canada — airline liable for its chatbot's wrong answer

    Decision 2024 BCCRT 149 (February 2024). Air Canada was ordered to pay C$812.02 in total: C$650.88 in damages (the fare difference) plus pre-judgment interest and tribunal fees. Small money, but the first widely reported ruling that a company answers for what its customer-facing AI says.

  • Fine2024 · EU
    Clearview AI — EUR 90 million-plus in GDPR fines across Europe

    Fines totalling more than EUR 95 million across four countries (plus a UK ICO fine on separate grounds). Clearview has no EU establishment and is reported as having neither paid nor changed its practices, which is why the Dutch DPA is pursuing directors and warning customers that using the service is itself unlawful.

  • Ruling2026 · CA-federal
    Canadian privacy regulators v. OpenAI — joint findings on ChatGPT training data

    Complaint well-founded. The federal OPC treated it as conditionally resolved on the strength of OpenAI's commitments (filtering tools, clearer notices about accuracy and sources, improved access tools, quarterly reporting); the Quebec, BC and Alberta offices found the consent and retention issues unresolved. No fine was imposed — PIPEDA gives the OPC no penalty powers.

Industries where it matters

Sources

Last reviewed Sep 25, 2026.

Educational information, not legal advice. Laws change and details depend on your situation — check the linked sources and talk to a qualified lawyer before acting. Last content review: 2026-09-25.

Spotted an error? Ask the tutor or email hello@myaiguide.pro.