Treadstone Associates
Article · 7 min read

How to explain AI use in a privacy policy

Most privacy policies were written before a business added an AI feature to its website or its customer-service inbox, and it shows. PIPEDA’s Openness principle does not require a policy to use the word “AI” — it requires the policy to actually describe what the business does with personal information, and a description that goes quiet exactly where AI enters the picture has a specific, sourced problem.

Treadstone Associates · Updated 2026

Key takeaways

  • • PIPEDA’s Openness principle requires a business to make its information practices “readily available” and “generally understandable” — not merely posted somewhere.
  • • Schedule 1 lists specific content a policy has to cover: who is accountable, how to get access, what kind of information is held, and what is shared with related organizations.
  • • The commissioners’ generative AI principles add an output-labelling duty of their own where AI outputs could significantly affect a person.
  • • A copied or generic template policy is a recognized, named failure mode — not a hypothetical one.

The legal bar is “readily available” and “generally understandable”

Schedule 1’s Openness principle states: “An organization shall make readily available to individuals specific information about its policies and practices relating to the management of personal information”, and clause 4.8.1 adds that individuals “shall be able to acquire information about an organization’s policies and practices without unreasonable effort”, in a form “that is generally understandable.” (PIPEDA, Schedule 1, clause 4.8) A policy that is technically posted, but written in a way that does not actually communicate that an AI tool now reads customer messages, has a real gap against that standard — “posted” and “understandable” are not the same test.

Schedule 1 names what a policy actually has to contain

Clause 4.8.2 is specific about content, requiring “(a) the name or title, and the address, of the person who is accountable for the organization’s policies and practices… (b) the means of gaining access to personal information held by the organization; (c) a description of the type of personal information held by the organization, including a general account of its use… and (e) what personal information is made available to related organizations.” (PIPEDA, Schedule 1, clause 4.8.2) Item (c)’s “general account of its use” is where an AI use belongs. If personal information is used by an AI system to draft replies, score leads, or summarise files, that is a use of the information the policy is describing — leaving it out is leaving out exactly what clause 4.8.2 asks for.

The OPC’s own recommended format: layered, not buried

The Commissioner’s separate 2018 guidelines on meaningful consent recommend a specific structure rather than one dense paragraph: “presenting information in a layered-format… helps make better sense of lengthy, complex information by offering a summary of the key highlights up front”, with fuller detail still available underneath for anyone who wants it. (OPC, guidelines for obtaining meaningful consent) A short, plain sentence near the top of the policy naming that an AI tool reads or scores customer messages, backed by a fuller paragraph further down describing exactly what it does with that information, satisfies this guidance and clause 4.8.2(c)’s “general account of its use” requirement without forcing every reader through the full document to find it.

The policy also has to make good on Schedule 1’s Access principle once an AI system is in the picture: on request, an individual “shall be informed of the existence, use, and disclosure of his or her personal information”, including “an account of the use that has been made or is being made of this information”, and the organization must respond “within a reasonable time and at minimal or no cost to the individual”. (PIPEDA, Schedule 1, clauses 4.9 and 4.9.4) That means a customer can ask specifically what an AI tool did with their enquiry, not just what the business collected generally, and the policy should not leave them guessing who to ask.

The commissioners add an output-labelling duty on top

Beyond what the policy has to say about collection and use, the joint generative AI principles add a separate obligation about the AI system’s own outputs: “Ensure that system outputs that could have a significant impact on an individual or group are meaningfully identified as being created by a generative AI tool.” (OPC, generative AI principles) The principles also require organizations to give affected individuals “an effective challenge mechanism for any administrative or otherwise significant decision made about them… and allowing them the opportunity to request human review and/or re-consideration of the decision.” (OPC, generative AI principles) Where an AI tool produces something a customer will act on — a credit-related decision, an eligibility screen, a significant recommendation — the policy is the natural place to describe both that labelling and that review path, not an afterthought bolted onto a support page.

The most common failure is not silence — it is a template that does not match reality

Treadstone Law’s privacy-policy checklist for Ontario businesses names the recurring problem directly: “A privacy policy borrowed from another company’s website may describe practices — data sharing arrangements, retention periods, security…” that the business copying it does not actually follow, and warns that “a surprising number” of website privacy policies are “copied from a template, another company’s site, or a generator, without much thought about whether they actually reflect what the business does with visitor and customer data.” (Treadstone Law, on privacy policy content generally) A template policy is very unlikely to mention the specific AI tool a business added six months ago, which makes it wrong by omission in exactly the place clause 4.8.2 asks it to be specific.

Who has to appoint someone to be accountable for getting this right

Clause 4.8.2(a)’s requirement to name “the person who is accountable for the organization’s policies and practices” connects directly to Schedule 1’s Accountability principle, which requires a designated individual whose identity “shall be made known upon request.” (PIPEDA, Schedule 1, clauses 4.1–4.1.4) That person is the one who should actually know what the business’s AI tools do with personal information before the policy describing them gets published — not the marketing team drafting copy from a template, and not the AI vendor’s own boilerplate language.

A worked example

A home-services company’s privacy policy says only, in one generic line, that information may be used to respond to the visitor’s enquiry. The company has since added an AI tool that reads every enquiry, drafts a reply, and separately scores the enquiry for likely job value to prioritise which leads a salesperson calls first. The existing sentence arguably covers the reply-drafting use. It does not cover the scoring use, which is a different, more consequential application of the same information and clause 4.8.2(c) requires “a general account of its use” that actually names it. The fix is one added sentence — naming the scoring use and its purpose — not a rewrite of the whole policy.

Related: what meaningful consent requires for AI uses, whether PIPEDA applies when a business uses AI, and whether customer records can be used to train a model.

Common questions

Does a privacy policy have to use the word “AI” specifically?

PIPEDA does not require particular wording — clause 4.8.2(c) requires “a general account” of how personal information is used. What matters is that a reader can actually understand that an automated system is doing the drafting, scoring or summarising, not that a specific term appears.

Is it enough to mention AI once in a general list of technologies used?

It depends on whether that mention lets an individual “reasonably understand” the use, which is the standard clause 4.3.2 sets for consent and which the Openness principle’s “generally understandable” language echoes for policy content — a buried, generic reference to unspecified technology is a weaker case than a plain sentence naming what the AI feature actually does.

Who inside a business should sign off on the AI-related wording before it is published?

The individual accountable for privacy policies and practices under Schedule 1’s Accountability principle is the right person — someone who actually knows what each AI tool does with personal information, rather than whoever drafted the original template.

Customer-facing AI raises this question first

Growth & Marketing covers disclosure and trust questions for AI used in customer-facing campaigns and outreach.