Skip to content
10 items · Free checklist

Canada PIPEDA — AI & Automated Decision-Making (Post-C-27 Framework) Compliance Checklist 2026

Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) governs AI and automated decision-making involving personal data of Canadians. Following the death of Bill C-27 (AIDA + C

Maximum penalty: PIPEDA itself has NO general administrative monetary penalty for ordinary non-compliance — the OPC cannot impose fines directly; its enforcement tools are investigation findings, compliance agreements, and application to the Federal Court for an enforcement order (Federal Court proceedings are a fresh hearing, not a review of OPC findings). A CAD $100,000-per-offence CRIMINAL penalty exists under PIPEDA s.28, but only for specific offences: destroying personal information subject to an access request, retaliating against a whistleblower, or failing to report a breach as required — not for general AI-consent or profiling violations. A proposed replacement bill, C-36 (Protecting Privacy and Consumer Data Act / PPCDA, introduced 2026-06-15, NOT YET LAW), would give the successor Commission real administrative-monetary-penalty power: up to CAD $10M or 3% of global revenue (standard non-compliance) and up to CAD $25M or 5% of global revenue (most serious offences).

Complete each item below to achieve compliance. Use Aegis Firma to generate all required documentation automatically.

Regulatory Requirements

1. Meaningful Consent for AI Data Use

Under PIPEDA Principle 3, obtain meaningful consent from Canadians before using their personal data in AI training, profiling, or automated decision-making. Consent must be specific to AI use — general privacy policy consent is insufficient. Explain how the AI uses their data in plain language.

Due: January 1, 2001

2. Automated Decision Explanation

When AI systems make significant decisions about Canadians (affecting finances, employment, services), explain the decision in meaningful terms. OPC guidance calls for explanation of algorithmic logic and the right to request human review of adverse automated decisions.

3. Privacy Policy — AI Data Practices

Update your privacy policy to clearly describe all AI and automated decision-making uses of personal data, retention periods for AI-processed data, and how individuals can access, correct, or withdraw data used in AI systems.

4. Breach Notification — AI System Incidents

Under PIPEDA's Breach of Security Safeguards Regulations (in force November 2018): notify the OPC and affected individuals of any breach of security safeguards involving personal data that creates a real risk of significant harm (RRSH). AI system compromises — including unauthorized access to training data, model inversion attacks exposing personal data, or AI-generated output disclosing personal information — must be assessed for RRSH and reported within a reasonable time. Maintain a breach register for 24 months.

Due: November 1, 2018

Implementation Steps

5. Obtain meaningful, AI-specific consent (not general privacy-policy consent) before using Canadians' personal data for AI training, profiling, or automated decision-making (PIPEDA Principle 3)

6. Provide a plain-language explanation of algorithmic logic for any AI decision with a significant effect on a Canadian (finance, employment, services)

7. Offer a right to request human review of adverse automated decisions

8. Establish a governance structure for AI oversight and documentation, since PIPEDA has no dedicated AI-specific statutory checklist — robust documentation is your main defense given the legal uncertainty

9. If you operate only in Quebec, Alberta, or British Columbia: confirm which provincial law (Law 25 / Alberta PIPA / BC PIPA) applies instead of federal PIPEDA

10. Monitor Bill C-36 (Protecting Privacy and Consumer Data Act), introduced June 15, 2026 and not yet law — it would give a successor Commission real fining power (up to CAD $10M/3% standard, CAD $25M/5% most serious)