PIPEDA and AI: 5 Obligations for Canadian Advisors

4 min read

The Federal Layer: PIPEDA and AI

PIPEDA establishes the federal privacy baseline for all provinces. This chapter covers what it specifically requires when you use an AI tool that processes client data.

2.1 Five PIPEDA Obligation Areas for AI

PIPEDA is 25 years old. It has no AI provisions. It applies to AI anyway. Five areas create specific obligations for advisors using AI tools:

1. Consent. Express consent is almost certainly required when client financial data is processed by a third-party AI tool. The OPC classifies financial information as "extremely sensitive." The Federal Court of Appeal's Facebook decision (2024) established a "double reasonableness" standard: the advisor must make reasonable efforts to inform, AND the client must reasonably understand what they consented to. Burying AI processing in lengthy terms of service does not satisfy this standard.

2. Cross-border transfers. PIPEDA permits cross-border data transfers but requires accountability to travel with the data. Contractual protections must provide a comparable level of protection regardless of jurisdiction. Clients must be advised that their information may be processed in another jurisdiction. The OPC's 2009 Guidelines treat a transfer for processing as a "use" of information (not a disclosure), meaning additional consent for the transfer itself is not typically required if the original collection purpose is maintained. However, for highly sensitive financial information, the OPC warns that transfer to certain jurisdictions "may be unwise."

3. Accountability. The advisor and firm remain responsible for client information transferred to a third-party processor. This cannot be outsourced. The OPC's Equifax investigation confirmed that security safeguard requirements apply to a service provider independently of its contractual obligations, and the advisor retains responsibility for what happens to client data after it reaches the processor.

4. Automated decision-making. PIPEDA has no specific provisions for automated decisions. General principles still apply: the accuracy principle (4.6) requires AI outputs to be based on accurate information, the openness principle (4.8) implies disclosure of AI use, and Section 5(3) prohibits processing that a reasonable person would consider inappropriate.

5. Breach notification. The "real risk of significant harm" (RROSH) threshold applies. Financial data is inherently high-sensitivity, lowering the bar for notification. All breaches must be recorded and retained for 24 months, whether or not they meet the RROSH threshold. Knowingly contravening breach requirements is an offence carrying fines up to $100,000 per offence.

2.2 Why PIPEDA Still Applies Despite Its Age

AI does not occupy a space outside of current legislative frameworks.

OPC Generative AI Principles, December 2023

The OPC further stated that "the inference of information about an identifiable individual (such as outputs about a person from a generative AI system) will be considered a collection of personal information."

The law is old. The obligations are current. PIPEDA's principles-based framework means it adapts to new technologies without amendment, and the OPC has made clear that AI tools fall squarely within existing requirements.

2.3 Where PIPEDA is heading

Bill C-27, which would have enacted the Consumer Privacy Protection Act and the Artificial Intelligence and Data Act, died on the Order Paper when Parliament was prorogued on 6 January 2025.

On 15 June 2026 the Minister of Artificial Intelligence and Digital Innovation tabled Bill C-36, An Act to enact the Protecting Privacy and Consumer Data Act, to amend the Personal Information Protection and Electronic Documents Act and to make amendments to other Acts. As introduced, it would repeal Part 1 of PIPEDA and replace it with the Protecting Privacy and Consumer Data Act. The bill had first reading on 15 June 2026 and has not passed. Its provisions can change before it becomes law.

Until Bill C-36 passes and comes into force, PIPEDA is the federal baseline, and the five obligations above apply today. On the Record reports each stage of the bill as it happens.

Source: Parliament of Canada, Bill C-36 first reading text, parl.ca, retrieved 17 September 2026.

Key Takeaways

  • Five PIPEDA obligation areas apply to AI: consent, cross-border transfers, accountability, automated decision-making, and breach notification
  • Express consent is almost certainly required for processing client financial data through third-party AI
  • The OPC has confirmed AI falls within existing PIPEDA requirements
  • Bill C-27 and AIDA died in January 2025; Bill C-36 (the Protecting Privacy and Consumer Data Act) had first reading on 15 June 2026 and is not yet law