Skip to content
هذه ترجمة للتسهيل فقط. النسخة الإنجليزية هي النسخة الرسمية والملزمة قانونيا. عرض النسخة الإنجليزية
CADEEP coverage3 enforcement actions

Canada PIPEDA — AI & Automated Decision-Making (Post-C-27 Framework): AI Compliance Requirements

Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) governs AI and automated decision-making involving personal data of Canadians. Following the death of Bill C-27 (AIDA + CPPA) in January 2025 when Parliament prorogued, PIPEDA remains Canada's primary federal data protection law. Organizations must obtain meaningful consent to use personal data in AI models, explain significant automated decisions, and allow individuals to challenge those decisions. The OPC (Office of the Privacy Commissioner) has issued AI-specific guidance enforcing these principles.

Summary of publicly-available regulatory text as of 2026-08-22. Verify against current official sources before relying on this for compliance decisions. Not legal advice.

Key Facts

Effective Date

January 1, 2001

Maximum Penalty

PIPEDA itself has NO general administrative monetary penalty for ordinary non-compliance — the OPC cannot impose fines directly; its enforcement tools are investigation findings, compliance agreements, and application to the Federal Court for an enforcement order (Federal Court proceedings are a fresh hearing, not a review of OPC findings). A CAD $100,000-per-offence CRIMINAL penalty exists under PIPEDA s.28, but only for specific offences: destroying personal information subject to an access request, retaliating against a whistleblower, or failing to report a breach as required — not for general AI-consent or profiling violations. A proposed replacement bill, C-36 (Protecting Privacy and Consumer Data Act / PPCDA, introduced 2026-06-15, NOT YET LAW), would give the successor Commission real administrative-monetary-penalty power: up to CAD $10M or 3% of global revenue (standard non-compliance) and up to CAD $25M or 5% of global revenue (most serious offences).

What Your Business Must Do

4 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.

Meaningful Consent for AI Data Use

Critical

Under PIPEDA Principle 3, obtain meaningful consent from Canadians before using their personal data in AI training, profiling, or automated decision-making. Consent must be specific to AI use — general privacy policy consent is insufficient. Explain how the AI uses their data in plain language.

Deadline: January 1, 2001

PIPEDA Sch. 1, Principle 3 (Consent); OPC Generative AI Principles guidance

Automated Decision Explanation

High Priority

When AI systems make significant decisions about Canadians (affecting finances, employment, services), explain the decision in meaningful terms. OPC guidance calls for explanation of algorithmic logic and the right to request human review of adverse automated decisions.

PIPEDA Sch. 1, Principles 4.8-4.9 (Openness, Individual Access), as interpreted by OPC AI guidance

Privacy Policy — AI Data Practices

High Priority

Update your privacy policy to clearly describe all AI and automated decision-making uses of personal data, retention periods for AI-processed data, and how individuals can access, correct, or withdraw data used in AI systems.

PIPEDA Sch. 1, Principle 8 (Openness)

Breach Notification — AI System Incidents

High Priority

Under PIPEDA's Breach of Security Safeguards Regulations (in force November 2018): notify the OPC and affected individuals of any breach of security safeguards involving personal data that creates a real risk of significant harm (RRSH). AI system compromises — including unauthorized access to training data, model inversion attacks exposing personal data, or AI-generated output disclosing personal information — must be assessed for RRSH and reported within a reasonable time. Maintain a breach register for 24 months.

Deadline: November 1, 2018

PIPEDA s. 10.1; Breach of Security Safeguards Regulations (SOR/2018-64)

Who Does This Apply To?

PIPEDA applies to private-sector organizations that collect, use, or disclose personal information in the course of commercial activities across provincial or international borders, or within federally-regulated industries. Extraterritorial application: PIPEDA applies to personal data of Canadians processed by foreign organizations when those organizations collect or use that data in connection with commercial activities in Canada (OPC Federal Court interpretation). Québec, Alberta, and British Columbia have substantially similar provincial laws — organizations operating only within those provinces follow provincial law instead of PIPEDA; all others follow PIPEDA plus any applicable provincial law. Key AI trigger: any AI system that uses Canadian personal data for training, profiling, automated decisions, or behavioral analytics is in scope. With Bill C-27 (AIDA + CPPA) dead as of Parliament prorogation (January 2025), PIPEDA's existing principles are interpreted expansively by the OPC to cover AI — but there is no dedicated AI Act; this creates significant legal uncertainty that organizations must manage through robust documentation.

Recent Enforcement Actions

2021-02Source verified· as of 2026-08-22

Against:

2022-06Source verified· as of 2026-08-22

Against:

2026-05Source verified· as of 2026-08-22

Against:

Recent Regulatory Guidance

guidance2023-10

OPC Position Paper: Responsible Use of Personal Information in AI (2023)

The OPC published its position paper following the death of Bill C-27 (AIDA), confirming that existing PIPEDA principles apply to AI and clarifying expectations: (1) Consent must name AI as a purpose; (2) Organizations must conduct privacy impact assessments before deploying AI using personal data; (3) Profiling of Canadians without consent violates PIPEDA even if individual data elements were legitimately collected; (4) Automated decisions significantly affecting individuals require a meaningful explanation mechanism and right to challenge. Paper explicitly addresses that C-27's death does not create a compliance gap — PIPEDA fills it.

guidance2025

OPC — Principles for Responsible, Trustworthy and Privacy-Protective Generative AI Technologies

OPC guidance confirming PIPEDA's existing consent-based framework applies to generative AI: consent for AI use must be as specific as possible (general terms-of-service acceptance is not sufficient), deceptive design patterns to obtain consent should be avoided, and transparency about what is done with personal information — and why — is what makes consent "meaningful." Verified this cycle via direct search of priv.gc.ca; exact publication date not independently confirmed this cycle, so none is asserted beyond "2025" era guidance referenced in year-end legal roundups (e.g., Lexology "2025 Wrapped: Top Five Privacy Developments in Canada").

guidance2026-06

Bill C-36 (Protecting Privacy and Consumer Data Act / PPCDA) introduced — PIPEDA reform attempt #3

Introduced 2026-06-15 — the federal government's third attempt to replace PIPEDA (following the 2020 and 2022 bills, including the AIDA-carrying Bill C-27 that died at prorogation in January 2025). PPCDA would give the successor Commission real enforcement teeth PIPEDA currently lacks: binding compliance orders plus administrative monetary penalties of up to CAD $10M or 3% of global revenue (whichever is greater) for standard non-compliance, and up to CAD $25M or 5% of global revenue for the most serious offences. NOT YET LAW as of this cycle — still must pass three readings in both the House of Commons and Senate; PIPEDA's current (much weaker) enforcement regime — described in maxPenalty above — remains in force until/unless C-36 is enacted. Sourced this cycle via Miller Thomson legal analysis; the bill's own Parliament.ca text was not independently fetched this cycle.

Quarterly Enforcement Digest

CYCLE 4 UPDATE (2026-08-22): PIPEDA is operating as Canada's de facto AI law following the death of Bill C-27 (AIDA + CPPA) in January 2025 when Parliament prorogued. The most significant verified OPC AI matter is the joint federal/provincial investigation into OpenAI/ChatGPT (launched 2023; findings jointly released 2026-05-06, confirmed this cycle as PIPEDA Findings #2026-002 — now also captured as a structured enforcementActions entry above), which found ChatGPT's GPT-3.5/GPT-4 training-data scraping breached PIPEDA on consent, transparency, accuracy, retention, access, and accountability grounds — OPC resolved the complaint conditionally; BC and Alberta's regulators left it unresolved. The predicted "PIPEDA successor bill" materialized: Bill C-36 (Protecting Privacy and Consumer Data Act) was introduced 2026-06-15, proposing real administrative-monetary-penalty power (up to CAD $10M/3% global revenue standard, $25M/5% severe) that current PIPEDA lacks — NOT YET LAW. (R134: removed unverified "LinkedIn/Vankoughnett" and "RBC v. OPC" references. CYCLE 4: corrected the Clearview AI and Tim Hortons enforcementActions entries — the former overstated OPC's order-making power, the latter fabricated "AI" and "ethnicity" framing not present in the actual OPC findings report; corrected the jurisdiction-level maxPenalty, which conflated a narrow criminal-offence penalty with general OPC fining power OPC does not have; removed a phantom "February 2025" guidance entry with a 404 sourceUrl.) Priority actions: (1) audit AI features against OPC's generative-AI consent principles; (2) ensure breach notification procedures cover AI system incidents; (3) monitor Bill C-36's progress through Parliament — its AMP regime would materially raise PIPEDA's current stakes. Québec Law 25 imposes stricter obligations for Québec-resident data — apply the more stringent standard for any Québec users.

Digest covers enforcement actions, guidance, and regulatory developments. Last verified: 2026-08-22.

Industry Playbooks covering Canada PIPEDA — AI & Automated Decision-Making (Post-C-27 Framework)

These industry playbooks include jurisdiction-specific checklist items and guidance for Canada PIPEDA — AI & Automated Decision-Making (Post-C-27 Framework).

Frequently Asked Questions

Does Canada PIPEDA — AI & Automated Decision-Making (Post-C-27 Framework) apply to my business?

Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) governs AI and automated decision-making involving personal data of Canadians. Following the death of Bill C-27 (AIDA + CPPA) in January 2025 when Parliament prorogued,… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.

What is the penalty for non-compliance?

The maximum penalty under Canada PIPEDA — AI & Automated Decision-Making (Post-C-27 Framework) is: PIPEDA itself has NO general administrative monetary penalty for ordinary non-compliance — the OPC cannot impose fines directly; its enforcement tools are investigation findings, compliance agreements, and application to the Federal Court for an enforcement order (Federal Court proceedings are a fresh hearing, not a review of OPC findings). A CAD $100,000-per-offence CRIMINAL penalty exists under PIPEDA s.28, but only for specific offences: destroying personal information subject to an access request, retaliating against a whistleblower, or failing to report a breach as required — not for general AI-consent or profiling violations. A proposed replacement bill, C-36 (Protecting Privacy and Consumer Data Act / PPCDA, introduced 2026-06-15, NOT YET LAW), would give the successor Commission real administrative-monetary-penalty power: up to CAD $10M or 3% of global revenue (standard non-compliance) and up to CAD $25M or 5% of global revenue (most serious offences).. Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.

How do I comply with Canada PIPEDA — AI & Automated Decision-Making (Post-C-27 Framework)?

The 4 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.

Official Source

https://www.priv.gc.ca/en/privacy-topics/privacy-laws-in-canada/the-personal-information-protection-and-electronic-documents-act-pipeda/

Last updated: 2026-08-22 — verify at source before relying on this information.

Don't leave compliance to chance

Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.

Start your free compliance scan