Treadstone Associates
Article · 8 min read

Consent and AI under Canadian privacy law

An AI system does not get its own consent rules under Canadian privacy law. It has to satisfy the same consent principle a paper form or a phone call has always had to satisfy — the difference is that an AI workflow makes it much easier to quietly fail the test without noticing.

Treadstone Associates · Updated 2026

Key takeaways

  • • PIPEDA’s consent principle requires “knowledge and consent”, not just consent — the individual has to actually understand what is being done with their information.
  • • An organization cannot make consent to an unrelated AI use a condition of getting the product or service it was actually asked for.
  • • The joint federal-provincial privacy commissioners’ generative AI guidance adds a necessity test on top of consent: a use has to be more than “potentially useful” before personal information goes into the system at all.
  • • Sensitivity still decides the form consent has to take — express consent for sensitive information, implied consent for routine information, exactly as it did before AI existed.

“Knowledge and consent” is the actual bar, not just a signature

Schedule 1’s consent principle states it as a single sentence: “The knowledge and consent of the individual are required for the collection, use, or disclosure of personal information, except where inappropriate.” The clauses under it do the real work. Clause 4.3.2 requires the organization to make “a reasonable effort to ensure that the individual is advised of the purposes for which the information will be used”, and adds that “to make the consent meaningful, the purposes must be stated in such a manner that the individual can reasonably understand how the information will be used or disclosed.” (PIPEDA, Schedule 1, clause 4.3) A privacy policy that says data may be used “to improve our services” without naming that an AI system reads the record does not clear that bar on its own — the individual cannot “reasonably understand” a use that was never described.

The OPC’s separate 2018 guidelines on obtaining meaningful consent turn clause 4.3.2’s “reasonably understand” standard into an operating rule about where that explanation has to live: “information buried in a privacy policy or terms of use serves no practical purpose to individuals with limited time and energy to devote to reviewing privacy information”, so the key elements of what an AI system does have to be surfaced where a person will actually see them, not merely included somewhere in a document they were unlikely to read in full. (OPC, guidelines for obtaining meaningful consent)

Consent cannot be the price of the product

Clause 4.3.3 is the provision that catches a common shortcut: “An organization shall not, as a condition of the supply of a product or service, require an individual to consent to the collection, use, or disclosure of information beyond that required to fulfil the explicitly specified, and legitimate purposes.” (PIPEDA, Schedule 1, clause 4.3.3) A customer who wants a quote should not have to also consent to their file being used to fine-tune a model, if the quote does not require that use. Bundling the two into one all-or-nothing checkbox is the exact pattern this clause exists to stop, whether the second use is AI-related or not.

Sensitivity still sets the form of consent

Clause 4.3.4 ties the form consent takes to how sensitive the information is, and clause 4.3.6 makes the practical rule explicit: “An organization should generally seek express consent when the information is likely to be considered sensitive. Implied consent would generally be appropriate when the information is less sensitive.” (PIPEDA, Schedule 1, clause 4.3.6) Routing a general customer-service inbox through an AI assistant is a different consent question than routing health or financial records through the same assistant — the statute was already built to treat those differently before generative AI made the question more common. Treadstone Law’s own explainer on PIPEDA consent for Ontario small businesses describes the same two-tier practice: “Express consent is explicit — a checked box, a signed form, a verbal agreement on a recorded call.” (Treadstone Law, on PIPEDA consent generally)

The commissioners add a necessity test before consent is even reached

The Office of the Privacy Commissioner of Canada, together with its counterparts in the provinces and territories, published generative AI principles that sit on top of PIPEDA rather than replacing it. Their first principle is headed “Legal Authority and Consent” and instructs organizations to “ensure legal authority for collecting and using personal information; when consent is the legal authority, it should be valid and meaningful”, adding that “consent should be as specific as possible, and deceptive design patterns should be avoided.” A separate principle on necessity and proportionality goes further: using a generative AI system with personal information “should be evidence-based and establish that the tool is both necessary and likely to be effective in achieving the specified purpose”, not merely helpful. (OPC, generative AI principles) In practice that means the consent question and the question of whether the business needs AI for this at all arrive together, not one after the other.

Consent can be withdrawn, and the organization has to explain what that means

Clause 4.3.8 preserves an ordinary consumer right that is easy to overlook once data has already moved into a model’s context or training pipeline: “An individual may withdraw consent at any time, subject to legal or contractual restrictions and reasonable notice. The organization shall inform the individual of the implications of such withdrawal.” (PIPEDA, Schedule 1, clause 4.3.8) Whether withdrawal is even mechanically possible once information has fed an AI process is a real operational question — and the honest answer, where it is not possible, is to say so at the point consent is sought, not after a customer asks.

A worked example

A retailer’s support inbox already discloses, in plain terms at sign-up, that messages may be “reviewed to improve service quality.” The retailer now wants to route the same messages through a generative AI tool that drafts replies and also flags customers who seem likely to churn, for the retention team to call. The first use — drafting replies — arguably sits inside what a customer already expected from “improve service quality.” The second — scoring a customer’s likelihood of leaving from the content of a support ticket — is a materially different, and more sensitive, use of the same message, and clause 4.3.2’s “reasonably understand” standard is unlikely to stretch to cover it on the strength of the original wording. The fix is not a longer privacy policy paragraph buried at sign-up; it is naming the churn-scoring use specifically, at a point the customer can actually notice it.

Related: whether PIPEDA applies when a business uses AI at all, training a model on customer records, and how to explain AI use in a privacy policy.

Common questions

Does implied consent ever cover an AI use of customer data?

It can, for information PIPEDA would treat as less sensitive and where the use fits what clause 4.3.5 calls the individual’s “reasonable expectations” — but the more an AI use diverges from what a customer would expect from the original interaction, the weaker that argument gets, and sensitive information generally needs express consent regardless.

Can a business just add one line to its privacy policy and call AI use consented to?

Only if that line actually lets the individual “reasonably understand how the information will be used or disclosed”, which is the test clause 4.3.2 sets. A vague reference to “improving our services” is unlikely to meet that standard for a use as specific as AI-driven scoring or profiling.

Do the OPC’s generative AI principles create new legal obligations on top of PIPEDA?

They are principles issued jointly by Canada’s privacy commissioners, not a statute, so they do not create new causes of action on their own — but they describe how the regulators read PIPEDA’s existing consent and necessity requirements when a generative AI system is the thing doing the collecting or using.

Consent decisions do not stop at the privacy policy

Operations covers what changes once a consented-to AI process is actually running day to day.