Alice BazdikianAI Automations + Safe Adoption Book a call
BlogAI for Small Business
What Canadian small businesses need to know about AI and privacy. Alice Bazdikian, AI educator and strategist

Canada's OpenAI Findings: What Small Businesses Need to Know About AI and Privacy Compliance

Canada's privacy regulators spent three years investigating ChatGPT. In May 2026 they released what they found: OpenAI did not meet Canadian privacy law on consent, transparency, accuracy or accountability.

It doesn't mean you can't use ChatGPT or Claude in your business. The regulators said that building and running a tool like ChatGPT can serve an appropriate purpose. It just means that the privacy rules you already follow apply to AI too, and being a new technology doesn't relax them.

The findings were written about OpenAI, but the regulators' report gives guidance to every private business operating in Canada. So if you use AI with client names, emails or notes, the report is about you as well.

Why this matters for you

The same five privacy principles the regulators applied to OpenAI apply to a ten-person business that uses AI with client information. A client can ask you how their information was used, and you need to be able to answer.

How tomorrow gets better

Your privacy notice says how you use AI, you know what your AI tools do with what you type into them, and your team knows which client information is allowed to go into an AI tool.

This is for you if: you run a business in Canada, you or your team use AI with client or customer information, and nobody has written down the rules yet.

This is NOT for you if: you need a legal opinion on your specific situation. For that, talk to a privacy lawyer.

What Canada's Privacy Regulators Found About OpenAI

The Office of the Privacy Commissioner of Canada ran the investigation jointly with the privacy regulators in Quebec, British Columbia and Alberta. It started in 2023, after a complaint alleged that OpenAI had collected, used and disclosed personal information without consent. You can read the announcement on the Office of the Privacy Commissioner of Canada's website.

The regulators looked at ChatGPT and the GPT-3.5 and GPT-4 models that powered ChatGPT at the time. They examined four places OpenAI got its information from:

  • Publicly available internet sources
  • Licensed datasets
  • What users typed into ChatGPT
  • Conversations written by human trainers

They paid particular attention to web-scraped data and user conversations being used to train and improve the models. Their conclusion was that OpenAI failed to satisfy several fundamental privacy requirements relating to consent, transparency, accuracy, accountability and the management of personal information.

Four laws were in play: the federal one, known as PIPEDA, and the private-sector privacy laws of Quebec, British Columbia and Alberta. If you do business in Canada, at least one of those four laws covers you.

Yes. The regulators did not find that generative AI is incompatible with Canadian privacy law.

They recognized that tools like ChatGPT can promote education, creativity and innovation, and they weighed privacy rights against freedom of expression and technological progress. They accepted that developing and deploying ChatGPT can serve an appropriate purpose.

They also said that a new technology doesn't get a pass. Consent, openness, accuracy and accountability still have to be met. So you can keep using AI. You just need to use AI the same careful way you already handle a client file.

The Five Privacy Principles That Apply to AI

These are the five principles the regulators measured OpenAI against, and what each principle means for a small business.

Principle What the Regulators Found What It Means for You
Consent OpenAI had not obtained valid consent for certain collection, use and disclosure, and people were not adequately informed about how their information would be used. People need to know how you plan to use their information, and that use has to match what they would reasonably expect.
Transparency OpenAI had a Privacy Policy and Help Centre articles, but key information was incomplete or unclear. The regulators also raised concerns about privacy information being available in French. Having a privacy policy is not enough. Your privacy policy has to say clearly what you actually do, including with AI.
Accuracy ChatGPT generated inaccurate and potentially harmful information about people, including false allegations that could damage a reputation. Check anything AI writes about a real person before you use it or send it.
Access, correction and deletion The regulators first found gaps. OpenAI then added correction and deletion tools, and the regulators found this part conditionally resolved. A person can ask what you hold about them and ask you to correct or delete it. You need a way to do that.
Accountability OpenAI had not met its accountability obligations and had no proper retention and disposal procedures for the personal information it used. Someone in your business is responsible for personal information, and you need a rule for how long you keep it.

On accuracy, the regulators were concerned that ChatGPT was trained on sources like social media and discussion forums, which can be subjective, biased or simply wrong. As a result, what AI tells you about a person can be wrong too, and you are the one who sends the email.

On access, OpenAI now filters personal information out of training data and can block specific personal details from showing up in answers. The regulators accepted that fix. So a business that finds a gap and corrects it is in a much better position than one that waits.

A lot of people assume that if information is on a public website, anyone can use it for anything. The regulators disagreed. Information being publicly available online does not mean it can be collected and reused for AI training.

Canadian privacy law asks two things. The person gave informed consent to the use, and the use lines up with what that person would reasonably expect. Someone who posted on a discussion forum did not expect that post to train an AI model.

The regulators took the same position in their earlier Clearview AI investigation, where personal information was collected from publicly accessible websites. So this is now a consistent line from Canada's regulators, and I would plan around it.

How to Check Your Own AI Privacy Compliance

The report tells organizations using generative AI to review three documents: privacy notices, internal governance documentation and vendor disclosures. In a small business, I would work through those three in this order.

  1. Read your privacy notice and add a plain description of how you use AI with client information.
  2. Open ChatGPT, Claude or whichever AI tool your team uses, and read what the vendor says happens to what you type in. The regulators looked closely at user conversations being used to train models.
  3. Write down which client information is allowed to go into an AI tool and which is not, then share that page with your team.
  4. Check anything AI writes about a real person before it goes out.
  5. Decide how a client can ask to see, correct or delete their information, and who in your business answers that request.
  6. Name one person who is accountable for privacy. In a small business, that person is probably you.
  7. Set how long you keep client information, and delete it when that time is up.

You don't need a compliance department for these steps. Most of them are one page in Notion, Google Drive or a Word doc, and once the page exists you can teach your AI tools and your team to follow it.

What Happens Next for AI and Privacy in Canada

The regulators took a practical approach. They recognized the benefits of generative AI, and they reaffirmed that consent, transparency, accuracy, access rights and accountability all still apply in the AI era.

So for a business in Canada, using generative AI is allowed. The regulators expect you to use AI in a way that complies with privacy law, and their expectations are changing quickly as the tools get more powerful.

Because the rules are still moving, the businesses that set up their AI rules now will have a much easier time later. It's a lot less work to write the page today than to rebuild how your team works after a client complains.

Recap

  • In May 2026, Canada's federal privacy regulator and the regulators in Quebec, British Columbia and Alberta found that OpenAI did not meet privacy law on consent, transparency, accuracy and accountability.
  • Generative AI is still legal to use in Canada. The existing privacy principles apply to it.
  • Information being public online is not the same as consent to use it.
  • Review your privacy notice, your internal AI rules and what your AI vendors disclose.
  • Give people a way to access, correct or delete their information, and name who is accountable.

Join my Free AI Community now and get the link to the office hours and all the guided content to get started with AI today. And if you want to go through how your team uses AI with client information, Book an AI Operations Diagnostic and let's map out a safe setup for you.

Keep reading

Claude's AI Watermark Explained: What Small Business Owners Need to Know

What AI watermarking is and what it means for your client work.

Read post

AI Agents for Small Business: Which One Do You Actually Need?

Why a tool that can read your emails is different from one that can send them.

Read post

AI Fluency for Small Business: The 4-Word Framework That Fixes Generic AI Output

The four habits that make a team good with AI.

Read post

Signal > Noise. Cut through the AI noise.

Join non-technical small biz owners getting one practical, no-hype AI email every week.