Use your browser's Print function to save as PDF — File → Print → Save as PDF.
← Back to post
PIPEDA AI Compliance Checklist
Six areas to review before using AI tools with personal information in your Canadian business
Note
This checklist is a practical self-assessment tool, not legal advice. PIPEDA (the Personal Information Protection and Electronic Documents Act) is Canada's federal private-sector privacy law, administered by the Office of the Privacy Commissioner of Canada. For the authoritative text and guidance, visit priv.gc.ca. Quebec businesses should also review Law 25, which imposes additional obligations.
- You have a written inventory of what personal information your business collects — names, emails, payment details, employee data, client files
- You've identified which of that information is processed by or passed to an AI tool
- You know whether that AI tool uses your data to train its models — and you've read the vendor's terms to confirm
- Sensitive information (health, financial, government ID) is handled with extra care and is not passed to AI tools without explicit authorization
- You've documented the data flows: what goes in, what comes out, where it's stored, and for how long
- Your privacy policy discloses that you use AI tools to process personal information — and specifies what kind
- Clients and customers are told their information may be processed by AI, in plain language they can understand
- Employees know which of their information (performance reviews, HR files, communications) is processed by AI tools
- You offer an opt-out where the law requires it — individuals can ask that their information not be used in certain ways
- Consent is not buried in a click-through agreement — it's findable and specific
- If you're collecting data for AI training purposes (internally or via a vendor), this is disclosed separately from general privacy terms
- Each AI tool you use has a documented purpose — what it does and what data it accesses to do it
- You're not feeding client data into a general-purpose AI tool without a documented business reason
- If a tool's use has expanded since you first deployed it, you've revisited whether the original consent still applies
- Personal information collected for one purpose (e.g., billing) is not being used for another (e.g., AI model training) without separate consent
- You have a process for reviewing new AI tools before they're added to your stack — someone approves before deployment
- You know which country each AI vendor processes and stores your data in — US, Canada, EU, or unclear
- Where data crosses borders, you've assessed whether PIPEDA's cross-border transfer rules are satisfied
- If you have Quebec clients or employees, you've reviewed Law 25's cross-border transfer obligations — they're stricter than federal PIPEDA requirements
- Your vendor contracts include a data processing agreement (DPA) or equivalent that specifies their obligations
- You know what happens to your data if you cancel the vendor relationship — deletion timelines, export rights
- You retain only as long as necessary — you have a retention and deletion schedule
- Individuals can ask what personal information you hold about them — and receive a response within 30 days
- If AI tools have produced inaccurate information about an individual, you have a process to correct it
- Individuals can request deletion where it's legally required — you know when that applies and when it doesn't
- If AI is making consequential decisions about individuals (creditworthiness, job screening, eligibility), humans review those decisions
- You have a named privacy contact — a person, not just a generic inbox — for individuals to reach with questions
- You have a written breach response plan — not just "call IT"
- The plan covers AI-specific incidents: model output leaks, unauthorized access via a vendor's API, or training data exposure
- Under PIPEDA, you must notify the Office of the Privacy Commissioner of Canada and affected individuals if a breach poses a real risk of significant harm — the threshold and process are at priv.gc.ca
- You maintain a breach log — all breaches recorded, even those that don't meet the notification threshold
- Your vendors have told you how they will notify you of a breach on their end, and their SLA is documented
- You review your AI compliance posture at least annually, or whenever you add a significant new tool