An AI system that personalises a marketing offer is making the same privacy trade a marketer has always made — taking information collected for one purpose and using it for another. PIPEDA’s answer to how far that can go does not change because a model, rather than a person, is doing the sorting.
Key takeaways
Feeding a customer’s purchase history into an AI system to decide who gets a discount, or what offer to show next, is not a new kind of activity under Canadian privacy law. It is a use of personal information for a purpose, and PIPEDA has always asked whether that purpose is appropriate — the AI system doing the sorting does not change the question being asked.
PIPEDA states the core limit plainly: “An organization may collect, use or disclose personal information only for purposes that a reasonable person would consider are appropriate in the circumstances.” (PIPEDA, s.5(3)) Whether an AI model, a rules engine, or a person decides who gets a personalised offer, the underlying test is the same: is this a reasonable, appropriate use of the information that was collected.
Canada’s federal, provincial and territorial privacy commissioners are specific about where personalisation crosses a line. Their guidance warns against “profiling that may lead to unfair, unethical, or discriminatory treatment, or creating outputs that threaten fundamental rights and freedoms,” and requires developers to evaluate training data to ensure it does not “replicate, entrench, or amplify historical or present biases.” (OPC, generative AI principles) A personalisation model built from historical purchase or engagement data can inherit exactly the kind of bias this guidance is warning about, without anyone intending it to.
The same guidance sets a specific standard for whether a personalisation system should be used at all: “Consider whether the use of a generative AI system is necessary and proportionate… the tool should be more than simply potentially useful. This consideration should be evidence-based and establish that the tool is both necessary and likely to be effective in achieving the specified purpose.” (OPC, generative AI principles) A marketing tool that personalises offers because the vendor markets it as effective, without the business itself having evidence that it is necessary for its specific purpose, has not cleared this bar on the vendor’s say-so alone.
Using an email address collected at checkout to feed a personalisation model is a new purpose under PIPEDA, separate from the question of whether CASL permits sending the resulting message. A sister firm’s guidance describes exactly this overlap: the two federal regimes “overlap but aren’t the same thing, and satisfying one doesn’t automatically satisfy the other.” (Treadstone Law, using customer emails for marketing) The consent question for feeding data into the model and the consent question for sending the message it produces have to be answered separately, a point covered further in the companion piece on CASL and AI-written email.
The two regimes are also enforced on different scales, which is part of why conflating them is a mistake worth avoiding. CASL sets its maximum administrative monetary penalty at $1,000,000 for an individual and $10,000,000 for any other person, per violation. CASL, s.20(4) See Treadstone Law’s guide to how a CASL complaint actually proceeds for who is likely to raise one and what typically happens next.
Most marketing personalisation runs through a vendor’s platform rather than a system a business built itself, and PIPEDA is explicit that outsourcing the processing does not outsource the responsibility: “An organization is responsible for personal information in its possession or custody, including information that has been transferred to a third party for processing. The organization shall use contractual or other means to provide a comparable level of protection while the information is being processed by a third party.” (PIPEDA, Schedule 1, clause 4.1.3) If the vendor’s AI model mishandles the data, the business that supplied it is still accountable — the contract with the vendor is the mechanism for managing that risk, not a way to hand the risk off.
PIPEDA does not let accountability for a personalisation programme dissolve into “the vendor’s AI decided.” Schedule 1’s Principle 1 requires organisations to designate an accountable individual whose identity “shall be made known upon request,” and to implement policies and practices to give effect to the Act’s principles, including staff training and a complaints procedure. (PIPEDA, Schedule 1, clause 4.1) A business running an AI personalisation tool needs a named person who can answer for what it does, not just a vendor contract on file.
A retailer feeds purchase history into an AI system that scores customers for a “win-back” discount campaign. Before relying on the scores, the business has real questions to answer under the OPC’s own framing: was the original collection purpose disclosed in a way that covers this use; is the scoring necessary and proportionate to the goal, rather than just a feature the vendor happened to ship; and could the scoring produce a discriminatory pattern — systematically excluding or including customers along lines connected to a protected characteristic — that nobody set out to build but the training data quietly encoded. If the scoring runs on a vendor’s platform, the retailer still owns the answer to all three questions.
Related: CASL and AI-written email, and disclosing that a customer is talking to an AI system.
How a business builds a personalisation programme around these limits is covered on the AI growth and marketing hub.
It solves part of it. The OPC’s own principles instruct organisations to “use anonymized, synthetic, or de-identified data rather than personal information where the latter is not required to fulfill the identified appropriate purpose,” which reduces privacy risk considerably — but it does not, on its own, satisfy CASL’s separate consent-to-send requirement once a message actually goes out to a real person.
That depends on how much of the decision is automated. Québec’s Law 25 requires notice specifically where a decision about a person is based exclusively on automated processing of their personal information, with a right to have a staff member review it, (CAI, principaux changements — Loi 25) — a system that ranks offers for a human marketer to approve is a different case from one where the discount is applied with no human step at all.
A short call is enough to walk through a specific scoring or targeting model against the guidance above.