Privacy law for AI apps in Canada
Canadian privacy law does not care whether the code was written by a person or a model. It cares what personal information the app collects, where it goes, and what decisions it makes about people.
An AI-built app that handles personal information about people in Canada is subject to PIPEDA in most provinces, to Quebec's Law 25 for Quebec residents, and to PIPA in Alberta and British Columbia for organizations there. For AI features the questions that matter are: did the person understand their data goes to a model provider, is that provider bound to protect it, is anything decided about people by the model alone, and could you detect and report a breach. None of it depends on how the app was built.
| Where the organization or users are | Law | Regulator |
|---|---|---|
| Most provinces, commercial activity | PIPEDA | Office of the Privacy Commissioner of Canada |
| Quebec | Law 25 (the Quebec private sector privacy act as amended) | Commission d'accès à l'information |
| Alberta | PIPA (Alberta) | Office of the Information and Privacy Commissioner of Alberta |
| British Columbia | PIPA (BC) | Office of the Information and Privacy Commissioner for BC |
| Health information in Ontario | PHIPA | Information and Privacy Commissioner of Ontario |
Sending data to a model provider
Under PIPEDA, the organization that collected the data stays accountable for it when a service provider processes it, and must use contractual or other means to protect it. In practice: read the provider's data processing terms, turn off training on your data where the option exists, and say in your privacy policy that data is processed by third-party AI providers, including outside Canada. Under Law 25, communicating personal information outside Quebec requires a privacy impact assessment first. See sending data to OpenAI and PIPEDA.
Decisions made by the model
Law 25 requires an organization that uses personal information to make a decision based exclusively on automated processing to inform the person, and on request to tell them what information was used and the reasons and principal factors behind the decision, and to let them have it reviewed by a person. An AI feature that approves, rejects, prices or ranks people can trigger this. Keep a human in the loop for consequential decisions.
Breaches
Under PIPEDA, a breach of security safeguards involving personal information that creates a real risk of significant harm must be reported to the Privacy Commissioner and the affected individuals as soon as feasible, and every breach must be recorded and the record kept for 24 months. Law 25 has a parallel duty for confidentiality incidents presenting a risk of serious injury, plus a register of all incidents. An exposed database in an AI-built app is a breach under both.
A person responsible
Law 25 makes the person with the highest authority in the business the person in charge of protecting personal information by default, unless the role is delegated in writing, and requires their title and contact details to be published on the website. PIPEDA requires an individual accountable for compliance.
What may change
Bill C-36, the proposed Protecting Privacy and Consumer Data Act, was introduced on 15 June 2026 and is at second reading. If passed it would replace Part 1 of PIPEDA and add order-making powers and administrative monetary penalties. It is not law yet; build to PIPEDA and Law 25 now.
What to do before launch
- Map what personal information the app collects and where each item goes, including model providers.
- Update the privacy policy to name AI processing and cross-border transfer.
- Use provider settings that exclude your data from training.
- Keep a human review step for any automated decision about people.
- Keep a breach record template and know who decides whether to report.
- Have the app tested so the breach does not happen: security test and, for AI features, an AI security assessment.
For privacy compliance work beyond testing, GetAudited covers PIPEDA compliance in detail. This page is general information, not legal advice.
Make sure the app does what the policy says
A test confirms personal information only goes where you said it would.
Get matchedCommon questions
Does PIPEDA apply to a small startup?
Yes, if it collects personal information in the course of commercial activity. There is no size threshold.
Do I need consent to use customer data in an AI feature?
You need consent appropriate to the purpose, and people must be able to understand what you will do with their data. Using data for a new purpose, such as training, needs fresh consideration.
Is my US-hosted AI provider a problem?
Not in itself under PIPEDA, provided you are transparent and protect the data contractually. Under Law 25, assess the transfer first.