Stripping out a name feels like it should end the analysis. Under Canadian privacy law, it usually doesn't — the question the statute actually asks is different, and narrower.
Short answer
Usually, no — not just by deleting the obvious identifiers. Federal law defines “personal information” as information about an identifiable individual, and a person can stay identifiable through combination with other information even after a name is removed. Quebec goes further: since 2023 its law treats “anonymised” as a specific legal status a business has to meet, not a description it can apply on its own.
The federal Personal Information Protection and Electronic Documents Act defines the term at section 2(1) in eleven words: “personal information means information about an identifiable individual” (PIPEDA, s.2(1)). Nothing in that definition turns on whether a name is attached. A Treadstone Law explainer on the same definition puts the practical test plainly: personal information is “information about an identifiable individual — meaning it can reasonably be linked back to a specific person, whether alone or combined with other information a business has or can access” (Treadstone Law, on the general PIPEDA definition).
That last clause is the one an AI project tends to trip over. A spreadsheet with names removed can still be re-identifying if a business (or an AI tool trained on other records) can match the remaining fields — postal code, birth date, purchase pattern, device identifier — back to a specific person. Deleting the name deletes one field. It does not delete identifiability, which is a property of the whole dataset and what else can plausibly be linked to it.
Quebec’s Law 25 takes a stricter, more procedural approach than the federal test. Since September 2023, the law allows an organisation to anonymise personal information as an alternative to destroying it — but only if the anonymisation is done “selon les meilleures pratiques généralement reconnues et en fonction des critères et des modalités déterminés par règlement du gouvernement” (according to generally recognised best practices and criteria set by government regulation) (CAI, Principaux changements apportés par la Loi 25). The same page states the constraint directly: without that government regulation in place, an organisation cannot lawfully anonymise personal information at all — it can only destroy it. In other words, Quebec treats “anonymised” as a status a business qualifies for under a defined process, not a label it can attach to a spreadsheet because the direct identifiers are gone.
Assume data is personal information unless you can show, specifically, why an individual can no longer reasonably be identified from it — alone or in combination with anything else reasonably available. “We removed the name field” is not that showing on its own. This matters most for the two things AI projects do with data: training on a company’s own historical records, and sending records to a third-party model for processing — see the duties that follow once PIPEDA applies, and what changes if the same data later leaks, at what if AI leaks personal information.
Whether a dataset genuinely qualifies as de-identified is exactly the kind of question a diligence review has to answer before valuing what a target AI business actually owns.