Treadstone Associates
Ask an Expert · 4 min read

Do I need consent to use AI on client data?

Only if running it through AI is a new purpose beyond what the client agreed to — the test is the purpose, not the tool.

Treadstone Associates · Updated 2026

Short answer

Only if the AI use is a new purpose. PIPEDA doesn't ask whether AI is involved; it asks whether what you're now doing with the information is consistent with the purpose the client agreed to when it was collected. Using AI to do the same work you were retained for — summarizing a file, drafting a response — is usually a permitted use of already-consented information. Using AI to do something the client's original consent never contemplated is a new purpose, and that generally needs its own consent.

The statutory test is purpose, not method

PIPEDA s.5(3) sets the standard: “An organization may collect, use or disclose personal information only for purposes that a reasonable person would consider are appropriate in the circumstances.” Schedule 1, clause 4.2 adds the timing piece: the purposes for collecting personal information “shall be identified by the organization at or before the time the information is collected.” Neither provision mentions software. What they establish is a compatible-use test: is the new activity consistent with the purpose already identified, or is it a different purpose that was never disclosed?

Applying it to an AI workflow

If a client retained you for a service and an AI tool now helps you deliver that same service faster — summarizing their file, drafting a routine communication for your review — that's very likely still the same purpose the client already consented to, just delivered with different tooling. If instead their information is being fed into an AI system for a purpose they were never told about — building a marketing dataset, letting a vendor's model use it to improve a general-purpose product — that's a new purpose, and Schedule 1's Identifying Purposes principle requires it to have been disclosed, which in practice means going back for consent.

The OPC's generative-AI principles tighten this further

Canada's joint generative-AI principles add a necessity layer on top of the statutory test: “the tool should be more than simply potentially useful. This consideration should be evidence-based and establish that the tool is both necessary and likely to be effective in achieving the specified purpose.” The same principles note that “consent should be as specific as possible” wherever consent is the legal authority being relied on — a generic, years-old consent clause is a weaker foundation for a new AI use than a purpose-specific one.

A short decision test

Ask three questions: is this the same purpose the client's information was collected for; is the audience for the output the same as before; and does the AI vendor's own terms reuse the data for its own purposes rather than just processing it on your instructions. Same, same, no — proceed under existing consent. Any answer flips — get fresh consent or don't do it. Treadstone Law’s guide to PIPEDA customer-data rules for small businesses covers the underlying consent framework in more depth, and the related question of pasting a client’s name into a public AI tool covers the ad hoc, single-record version of this.

Working through this with a live system?

See how data practices get examined before an AI acquisition or partnership closes.