No dedicated Canadian voice-cloning law exists — what recourse there is depends on how the clone gets used, not on the cloning itself.
Short answer
There is no standalone Canadian statute making voice cloning itself illegal or requiring consent to do it. What recourse exists depends entirely on how the cloned voice is used afterward: as personal information an organization handles, as something used to imply a false business connection, or as a tool in deceptive marketing, each of which is governed by a different existing Canadian law — none of them written with voice cloning in mind.
This is a genuine gap, not an oversight in this answer: no federal or provincial statute dedicated to deepfakes or voice cloning was located for this build. The nearest Canadian government material is guidance rather than a prohibition. The Canadian Centre for Cyber Security names misinformation and disinformation as one of eight risks organizations should understand, but guidance is not a law creating a personal right of action against someone who cloned a voice.
A recording of someone's voice, or a model trained on it, is information about an identifiable individual, which puts it inside PIPEDA's ordinary framework once an organization is doing anything commercial with it. PIPEDA applies here directly: an organization may collect, use or disclose it only for purposes “a reasonable person would consider are appropriate in the circumstances”, and if the recording moves to a vendor or a processor, responsibility for it does not disappear under Schedule 1's accountability clause. That doesn't stop an individual acting alone from cloning a voice for personal reasons — PIPEDA governs organizations, not private individuals — but it does constrain any business that collects or uses a cloned voice in its own operations.
Where a cloned voice is used to suggest a connection to a real business or person that doesn't exist — a fake endorsement, an impersonated spokesperson — passing off is the closest general Canadian legal route, even without a trademark. It is a common-law tort protecting goodwill built in a name or identity, and a claim generally needs genuine goodwill in the identity being copied, a use likely to confuse the public into assuming a connection, and actual or likely damage — that article addresses the general legal test, not voice cloning specifically, but the elements transfer directly to a cloned-voice impersonation used commercially. On the marketing side, the Competition Bureau's own discussion paper names “deepfake” (digitally altered) voices specifically as a way AI could make “deceptive marketing conduct more convincing” — a real Canadian regulator has already flagged the exact scenario, even without a dedicated statute behind it.
For the related question of whether producing a deepfake itself is illegal in Canada, see this companion answer.
A diligence review maps the real legal routes before a dispute happens.