An AI notetaker sitting in on a meeting raises two separate legal questions that get run together constantly: is it lawful to record the conversation at all, and what happens to the transcript afterward. Canada answers them from two different bodies of law, and the second answer depends on whether the meeting was with a colleague or with a customer.
Key takeaways
Whether it is lawful to record a conversation at all is answered by the Criminal Code, not by privacy legislation. Intercepting a private communication is an offence unless an exception applies, and the operative exception for an ordinary business meeting is consent: the prohibition “does not apply to… a person who has the consent to intercept, express or implied, of the originator of the private communication or of the person intended by the originator thereof to receive it.” (Criminal Code, s.184(2)(a)) That is a one-party rule: if one participant — including the host who turned the notetaker on — consents to the recording, the interception itself is not a criminal offence. Some US states require every participant’s consent; Canada’s federal criminal law does not.
One-party consent settles whether turning the notetaker on was a crime. It says nothing about what privacy obligations attach to the resulting transcript once it exists, and that answer splits sharply depending on who was in the meeting. Treadstone Law’s employee-privacy explainer states the general trap directly: “Many Ontario employers assume the same privacy rules that protect customer data also protect employee data. That assumption is wrong more often than you would think.” (Treadstone Law, on Ontario employee privacy generally)
PIPEDA applies to personal information an organization collects, uses or discloses “in the course of commercial activities”, and separately to employee information only “in connection with the operation of a federal work, undertaking or business.” (PIPEDA, s.4(1)) For the great majority of Canadian businesses, which are provincially rather than federally regulated, that second branch simply does not apply. Treadstone Law’s explainer describes the consequence plainly: “PIPEDA’s specific employee-information provisions apply fully only to federally regulated employers, such as banks, airlines, and telecommunications companies. For most Ontario businesses, which are provincially regulated, employee records used strictly for employment purposes fall into a genuine legal gap: no dedicated statute governs them the way PIPEDA governs customer data.” (Treadstone Law, on Ontario employee privacy generally) An AI notetaker transcribing a purely internal team stand-up, at a provincially regulated business, therefore is not automatically caught by PIPEDA the way a transcript of a client call is — a client meeting is commercial activity, full stop, and everything already described in this hub about consent, safeguards and access applies to that transcript in full.
Where the internal-meeting gap is at its widest, Ontario’s Employment Standards Act has since stepped in, but narrowly. Employers with 25 or more employees in Ontario on January 1 of any year must have a written policy on electronic monitoring, and the guide’s own definition reaches this use case directly: “‘Electronic monitoring’ includes all forms of employee and assignment employee monitoring that is done electronically”, and the requirement is not limited to devices the employer issued. (Ontario, ESA guide — written policy on electronic monitoring) An AI notetaker that records, transcribes and retains what employees say in meetings is monitoring employees electronically by any ordinary reading of that definition. Where the 25-employee threshold is met, the policy has to describe “how the employer may electronically monitor employees”, “the circumstances in which the employer may electronically monitor employees”, and “the purposes for which information obtained through electronic monitoring may be used.” (Ontario, ESA guide — written policy on electronic monitoring)
It would be easy to read the electronic-monitoring policy requirement as Ontario finally giving employees a privacy right over meeting recordings. The government’s own guide corrects that reading directly: “The ESA does not require the employer to provide employees with a right to privacy. The ESA requirements give some employees the right to be provided with specified information about electronic monitoring by their employer.” (Ontario, ESA guide — written policy on electronic monitoring) An employer that discloses, in its written policy, that meetings are recorded and transcribed by an AI notetaker for a stated purpose has met the ESA obligation — the Act does not go on to limit whether the employer may do that in the first place.
A 40-employee Ontario marketing agency turns on an AI notetaker for two kinds of meetings: weekly internal planning calls, and client strategy calls. For the client calls, the transcript is personal information collected in the course of commercial activity, so consent (usually implied, by continuing the call after the host discloses the notetaker is on), the safeguards principle, and the client’s own access rights over that transcript all apply under PIPEDA in the ordinary way. For the internal planning calls, the agency is over the 25-employee threshold, so the ESA requires a written policy stating that meetings are recorded, describing the circumstances, and naming the purpose — for example, generating action-item summaries. One tool, one meeting format, two different legal baskets depending on who is in the room.
Related: what meaningful consent requires for AI uses, whether PIPEDA applies when a business uses AI, and what determines whether customer data is safe in an AI tool.
Not under Canadian criminal law — s.184(2)(a) of the Criminal Code excuses an interception where the originator or the intended recipient of the communication has consented, which is a one-party standard, not a unanimous one.
The ESA written-policy requirement does not apply below that threshold, but the absence of that specific statutory duty is not the same as no obligation whatsoever — general employment and contractual principles, and basic fairness in how monitoring is disclosed to staff, still apply outside the ESA’s own trigger.
Yes — the moment a client or customer is on the call, the transcript is personal information collected in the course of commercial activity under s.4(1)(a), and the consent, safeguards and access obligations covered elsewhere in this hub apply to it fully, regardless of the internal employee-data gap described above.
Integration & Automation covers connecting a notetaker to the calendar and CRM systems a business already runs.