Treadstone Associates
Article · 9 min read

AI and cross-border data transfers

Most AI products a Canadian business signs up for run on infrastructure outside Canada. That fact alone does not put a business offside its federal privacy obligations — but it does not clear the business of them either. The Office of the Privacy Commissioner of Canada has a specific answer for exactly this situation, and it predates generative AI by more than a decade.

Treadstone Associates · Updated 2026

Key takeaways

  • • PIPEDA “does not prohibit organizations in Canada from transferring personal information to an organization in another jurisdiction for processing” — but it does establish rules for how.
  • • A transfer to a foreign AI vendor for processing is legally a “use” of the information, not a “disclosure”, so it generally does not require fresh consent on its own.
  • • The transferring Canadian business stays accountable for what happens to the data abroad — that accountability does not move with the data.
  • • No contract can override the receiving country’s own laws, including its law-enforcement and national-security access powers — that is a real limit worth knowing before signing.

PIPEDA regulates the transfer; it does not ban it

The OPC’s own guidelines on cross-border processing state the baseline directly: “PIPEDA does not prohibit organizations in Canada from transferring personal information to an organization in another jurisdiction for processing. PIPEDA does establish rules governing transfers for processing.” (OPC, cross-border processing guidelines) An AI vendor whose servers sit in the United States, the European Union, or anywhere else is not, by that fact alone, an unlawful destination for a Canadian customer’s data. What matters is whether the rules that apply to that transfer were actually followed.

A transfer for processing is a use, not a disclosure — and that matters for consent

The same guidance draws a distinction that decides most of the practical questions: “A transfer for processing is a ‘use’ of the information; it is not a disclosure. Assuming the information is being used for the purpose it was originally collected, additional consent for the transfer is not required.” (OPC, cross-border processing guidelines) Treadstone Law’s own explainer on sharing customer data with a service provider describes the same line from the general PIPEDA-compliance side: sharing information with a provider “processing it on your business’s behalf, for the same purpose it was originally collected for” generally does not need separate fresh consent, provided the business “remains accountable for how that provider handles the information and has appropriate contractual safeguards in place.” (Treadstone Law, on sharing data with a service provider under Ontario/federal privacy rules generally) An AI tool that receives customer data solely to do the job it was engaged for — drafting, summarising, scoring — sits inside that same processing relationship, whatever country its servers are in.

Accountability does not travel with the data

The OPC is direct about where responsibility lands: “The transferring organization is accountable for the information in the hands of the organization to which it has been transferred. Organizations must protect the personal information in the hands of processors. The primary means by which this is accomplished is through contract.” (OPC, cross-border processing guidelines) That mirrors Schedule 1’s general vendor clause, clause 4.1.3, which requires “contractual or other means to provide a comparable level of protection while the information is being processed by a third party.” (PIPEDA, Schedule 1, clause 4.1.3) A Canadian business cannot point at an AI vendor’s own privacy practices as the reason a customer’s data was mishandled — the OPC’s enforcement lands on the business that collected the data, not the processor it sent it to.

A contract cannot reach past the other country’s own laws

The genuine limit on all of this is one sentence: “What the organization cannot do through contract – or indeed by any other means – is to override the laws of a foreign jurisdiction.” (OPC, cross-border processing guidelines) If a foreign government has a lawful power to access data held by an AI vendor operating on its soil, no clause in the vendor contract removes that power. This is precisely why the guidance requires organizations to “assess the risks that could jeopardize the integrity, security and confidentiality of customer personal information when it is transferred to third-party service providers operating outside of Canada”, and to be “transparent about their personal information handling practices”, including telling customers their information may be sent abroad for processing. (OPC, cross-border processing guidelines)

A real complaint shows where the line actually falls

The guidance is not abstract about how this gets enforced: in an investigation into a complaint about outsourcing personal information processing to a U.S. firm, the OPC found CIBC Visa in compliance with PIPEDA, relying in part on the Office of the Superintendent of Financial Institutions’ own guidelines for federally regulated institutions, which advise organizations to weigh “potential foreign political, economic and social conditions, and events that may conspire to reduce the foreign service provider’s ability to provide the service”. (OPC, cross-border processing guidelines, citing its CIBC Visa finding) The finding did not turn on where CIBC’s vendor was located; it turned on what CIBC had actually done to assess and document that arrangement before signing it.

Canada did not copy the EU’s approach, and that is worth knowing

The guidance is explicit that Canada chose a different model than the one many businesses have heard of from European privacy law: “European Union member states have passed laws prohibiting the transfer of personal information to another jurisdiction unless the European Commission has determined that the other jurisdiction offers ‘adequate’ protection… In contrast to this state-to-state approach, Canada has, through PIPEDA, chosen an organization-to-organization approach that is not based on the concept of adequacy.” (OPC, cross-border processing guidelines) There is no Canadian government list of “approved” countries an AI vendor has to be hosted in. The obligation runs through each individual contract and each individual assessment, not through a jurisdiction’s general status.

A worked example

A Canadian law firm’s intake team starts using a US-hosted AI transcription service to summarise client calls. The information moves for one purpose — producing a summary of the call the client already agreed to have transcribed — so it is a use, not a disclosure, and does not need a fresh consent step on that basis alone. What the firm still has to do: check the vendor’s contract for a commitment to protect the data to a comparable standard, understand and be ready to explain that data may be subject to US law while it sits on US servers, and update its own privacy notice so clients are told, in advance, that call information may be processed outside Canada. Skipping that last step is the part that turns a lawful processing arrangement into a transparency failure.

Related: what determines whether customer data is safe in an AI tool, whether PIPEDA applies when a business uses AI, and Alberta and BC’s own privacy rules for AI.

Common questions

Does using a US-based AI vendor automatically breach PIPEDA?

No. The OPC guidance states plainly that PIPEDA “does not prohibit organizations in Canada from transferring personal information to an organization in another jurisdiction for processing” — the obligation is to manage that transfer properly, not to avoid it.

Do customers have to separately consent every time data goes to a foreign AI vendor for processing?

Generally not, where the vendor is processing the information for the same purpose it was originally collected for — the OPC treats that as a use rather than a disclosure. What is required is transparency about the practice and appropriate contractual protection, not a fresh consent form for every processing step.

What if the AI vendor itself suffers a data breach overseas?

The Canadian organization that collected the information is still the accountable party under PIPEDA’s own framing — it still has to make its own assessment against the s.10.1 real-risk-of-significant-harm test and report and notify accordingly, regardless of where the breach physically occurred.

Vendor contracts are where cross-border risk actually gets managed

Operations covers what to check in an AI vendor agreement once the tool is running day to day.