Canada's privacy regulators spent three years investigating ChatGPT. In May 2026 they released what they found: OpenAI did not meet Canadian privacy law on consent, transparency, accuracy or accountability.
It doesn't mean you can't use ChatGPT or Claude in your business. The regulators said that building and running a tool like ChatGPT can serve an appropriate purpose. It just means that the privacy rules you already follow apply to AI too, and being a new technology doesn't relax them.
The findings were written about OpenAI, but the regulators' report gives guidance to every private business operating in Canada. So if you use AI with client names, emails or notes, the report is about you as well.
Why this matters for you
The same five privacy principles the regulators applied to OpenAI apply to a ten-person business that uses AI with client information. A client can ask you how their information was used, and you need to be able to answer.
How tomorrow gets better
Your privacy notice says how you use AI, you know what your AI tools do with what you type into them, and your team knows which client information is allowed to go into an AI tool.
This is for you if: you run a business in Canada, you or your team use AI with client or customer information, and nobody has written down the rules yet.
This is NOT for you if: you need a legal opinion on your specific situation. For that, talk to a privacy lawyer.
What Canada's Privacy Regulators Found About OpenAI
The Office of the Privacy Commissioner of Canada ran the investigation jointly with the privacy regulators in Quebec, British Columbia and Alberta. It started in 2023, after a complaint alleged that OpenAI had collected, used and disclosed personal information without consent. You can read the announcement on the Office of the Privacy Commissioner of Canada's website.
The regulators looked at ChatGPT and the GPT-3.5 and GPT-4 models that powered ChatGPT at the time. They examined four places OpenAI got its information from:
- Publicly available internet sources
- Licensed datasets
- What users typed into ChatGPT
- Conversations written by human trainers
They paid particular attention to web-scraped data and user conversations being used to train and improve the models. Their conclusion was that OpenAI failed to satisfy several fundamental privacy requirements relating to consent, transparency, accuracy, accountability and the management of personal information.
Four laws were in play: the federal one, known as PIPEDA, and the private-sector privacy laws of Quebec, British Columbia and Alberta. If you do business in Canada, at least one of those four laws covers you.
Is It Still Legal to Use AI in Your Business in Canada?
Yes. The regulators did not find that generative AI is incompatible with Canadian privacy law.
They recognized that tools like ChatGPT can promote education, creativity and innovation, and they weighed privacy rights against freedom of expression and technological progress. They accepted that developing and deploying ChatGPT can serve an appropriate purpose.
They also said that a new technology doesn't get a pass. Consent, openness, accuracy and accountability still have to be met. So you can keep using AI. You just need to use AI the same careful way you already handle a client file.
The Five Privacy Principles That Apply to AI
These are the five principles the regulators measured OpenAI against, and what each principle means for a small business.
| Principle | What the Regulators Found | What It Means for You |
|---|---|---|
| Consent | OpenAI had not obtained valid consent for certain collection, use and disclosure, and people were not adequately informed about how their information would be used. | People need to know how you plan to use their information, and that use has to match what they would reasonably expect. |
| Transparency | OpenAI had a Privacy Policy and Help Centre articles, but key information was incomplete or unclear. The regulators also raised concerns about privacy information being available in French. | Having a privacy policy is not enough. Your privacy policy has to say clearly what you actually do, including with AI. |
| Accuracy | ChatGPT generated inaccurate and potentially harmful information about people, including false allegations that could damage a reputation. | Check anything AI writes about a real person before you use it or send it. |
| Access, correction and deletion | The regulators first found gaps. OpenAI then added correction and deletion tools, and the regulators found this part conditionally resolved. | A person can ask what you hold about them and ask you to correct or delete it. You need a way to do that. |
| Accountability | OpenAI had not met its accountability obligations and had no proper retention and disposal procedures for the personal information it used. | Someone in your business is responsible for personal information, and you need a rule for how long you keep it. |
On accuracy, the regulators were concerned that ChatGPT was trained on sources like social media and discussion forums, which can be subjective, biased or simply wrong. As a result, what AI tells you about a person can be wrong too, and you are the one who sends the email.
On access, OpenAI now filters personal information out of training data and can block specific personal details from showing up in answers. The regulators accepted that fix. So a business that finds a gap and corrects it is in a much better position than one that waits.
Why "It Was Public Online" Does Not Count as Consent
A lot of people assume that if information is on a public website, anyone can use it for anything. The regulators disagreed. Information being publicly available online does not mean it can be collected and reused for AI training.
Canadian privacy law asks two things. The person gave informed consent to the use, and the use lines up with what that person would reasonably expect. Someone who posted on a discussion forum did not expect that post to train an AI model.
The regulators took the same position in their earlier Clearview AI investigation, where personal information was collected from publicly accessible websites. So this is now a consistent line from Canada's regulators, and I would plan around it.
How to Check Your Own AI Privacy Compliance
The report tells organizations using generative AI to review three documents: privacy notices, internal governance documentation and vendor disclosures. In a small business, I would work through those three in this order.
- Read your privacy notice and add a plain description of how you use AI with client information.
- Open ChatGPT, Claude or whichever AI tool your team uses, and read what the vendor says happens to what you type in. The regulators looked closely at user conversations being used to train models.
- Write down which client information is allowed to go into an AI tool and which is not, then share that page with your team.
- Check anything AI writes about a real person before it goes out.
- Decide how a client can ask to see, correct or delete their information, and who in your business answers that request.
- Name one person who is accountable for privacy. In a small business, that person is probably you.
- Set how long you keep client information, and delete it when that time is up.
You don't need a compliance department for these steps. Most of them are one page in Notion, Google Drive or a Word doc, and once the page exists you can teach your AI tools and your team to follow it.
What Happens Next for AI and Privacy in Canada
The regulators took a practical approach. They recognized the benefits of generative AI, and they reaffirmed that consent, transparency, accuracy, access rights and accountability all still apply in the AI era.
So for a business in Canada, using generative AI is allowed. The regulators expect you to use AI in a way that complies with privacy law, and their expectations are changing quickly as the tools get more powerful.
Because the rules are still moving, the businesses that set up their AI rules now will have a much easier time later. It's a lot less work to write the page today than to rebuild how your team works after a client complains.
Recap
- In May 2026, Canada's federal privacy regulator and the regulators in Quebec, British Columbia and Alberta found that OpenAI did not meet privacy law on consent, transparency, accuracy and accountability.
- Generative AI is still legal to use in Canada. The existing privacy principles apply to it.
- Information being public online is not the same as consent to use it.
- Review your privacy notice, your internal AI rules and what your AI vendors disclose.
- Give people a way to access, correct or delete their information, and name who is accountable.
Join my Free AI Community now and get the link to the office hours and all the guided content to get started with AI today. And if you want to go through how your team uses AI with client information, Book an AI Operations Diagnostic and let's map out a safe setup for you.



