Treadstone Associates
Article · 7 min read

What happens to data you paste into AI

An employee pastes a paragraph of client information into a chat AI tool to save ten minutes drafting a summary. Mechanically, that text has just left the business’s own systems. What happens to it next, and who is legally accountable for it, depends on facts most employees never think to check.

Treadstone Associates · Updated 2026

Key takeaways

  • • Canada’s Cyber Centre warns plainly that “users may unknowingly provide sensitive corporate data or personally identifiable information (PII) in their AI queries and prompts.”
  • • Under PIPEDA, sending personal information to an AI vendor for processing is legally a “use,” not a disclosure — but the business stays fully accountable for what happens to it afterward.
  • • Accountability does not transfer with the data. A business remains responsible for information it hands to a third-party processor, AI vendor included.
  • • Where the vendor processes data outside Canada, no contract the business signs can override the laws of the country the data lands in.

“Where does it go?” has a mechanical answer and a legal answer, and a business needs both before it lets pasted client data become routine.

Mechanically: it leaves your systems the moment it is typed

The Canadian Centre for Cyber Security’s guidance on generative AI is direct about this risk: “users may unknowingly provide sensitive corporate data or personally identifiable information (PII) in their AI queries and prompts,” and warns that “threat actors could harvest this sensitive information to impersonate individuals or spread false information.” Cyber Centre, ITSAP.00.041 The same guidance is blunt about the resulting outputs too: they “can be incorrect,” “might not take certain factors into account,” and “can be biased” — its advice is to “always be aware of and validate your sources to verify whether the content being presented is accurate.” Cyber Centre, ITSAP.00.041 Once text is submitted to a tool a business does not operate, the business has lost direct control over where it is stored, for how long, and whether it is used to improve the vendor’s own models — those answers live in the vendor’s terms, not in general law.

Legally: it is a “use,” and the business stays accountable

Under the federal Personal Information Protection and Electronic Documents Act, Schedule 1’s accountability principle states it without qualification: “an organization is responsible for personal information in its possession or custody, including information that has been transferred to a third party for processing. The organization shall use contractual or other means to provide a comparable level of protection while the information is being processed by a third party.” PIPEDA, Schedule 1, cl.4.1.3 An AI vendor processing text a business submits to it functions, for this purpose, exactly like any other outside service provider. Treadstone Law’s guidance on sharing customer information with a third-party service provider sets out the general version of this rule: sharing information with a provider “processing it on your business’s behalf, for the same purpose it was originally collected for… generally doesn’t require separate fresh consent… as long as your business remains accountable for how that provider handles the information and has appropriate contractual safeguards in place.” Treadstone Law, sharing data with a third-party provider That is a general principle about vendors, not a rule written for AI specifically — but an AI tool processing pasted business data is, legally, exactly this kind of vendor.

If the vendor processes data outside Canada

Most consumer AI tools run on infrastructure outside Canada. The OPC’s guidance on cross-border processing confirms that “PIPEDA does not prohibit organizations in Canada from transferring personal information to an organization in another jurisdiction for processing,” and that “a transfer for processing is a ‘use’ of the information; it is not a disclosure” — so, assuming the information is used for the purpose it was originally collected for, no additional consent is required purely because of where the processing happens. OPC, cross-border processing guidelines But the same guidance is equally clear about the limit: “the transferring organization is accountable for the information in the hands of the organization to which it has been transferred” and “no contract can override the criminal, national security or any other laws of the country to which the information has been transferred.” A business that pastes client data into a US-hosted AI tool has not disclosed anything requiring fresh consent in the ordinary case — but it has not shed its own accountability either, and it cannot contract its way around US law applying to data once it sits on US servers.

What Canada’s privacy regulators say to actually do about it

The OPC’s joint AI principles ask organizations to “consider whether the use of a generative AI system is necessary and proportionate… the tool should be more than simply potentially useful,” and, more specifically, to “use anonymized, synthetic, or de-identified data rather than personal information where the latter is not required.” OPC, generative AI principles Applied to pasting: the practical fix is rarely “never use the tool.” It is removing names, account numbers, and other identifiers before the paste where the task does not actually need them, and reserving tools with an enterprise no-retention agreement for anything that does.

If the vendor itself mishandles what was pasted — an unsecured leak, unauthorized access — PIPEDA treats that as the business’s own breach to answer for, not the vendor’s. An organization must report to the Privacy Commissioner “any breach of security safeguards involving personal information under its control if it is reasonable in the circumstances to believe that the breach creates a real risk of significant harm to an individual,” and must separately notify the affected individual “unless otherwise prohibited by law.” PIPEDA, s.10.1 That duty falls on the business that pasted the data in, regardless of whose system actually failed. See Treadstone Law’s case study on a firm's missing breach response plan for what that actually looks like in practice.

A worked example

An employee wants an AI tool to summarize a client’s file history. Pasting the raw case notes — including the client’s name, SIN, and financial details — into a free public chatbot sends personal information to a vendor with no negotiated contract and, typically, US-based processing and no confirmed no-retention guarantee. The same task, run through the business’s own enterprise AI subscription with a signed data-processing agreement and the identifiers stripped from the notes first, satisfies the same PIPEDA accountability and necessity principles far more comfortably — not because a different law applies, but because the business has actually done the contractual and minimization work those principles ask for.

Related: where AI training data comes from, why business data is rarely AI-ready, and AI and employee privacy at work.

Common questions

Is pasting company data into a public AI chatbot automatically a privacy breach?

Not automatically — but it is a use of personal information the business remains fully accountable for under PIPEDA, including for what the vendor does with it afterward. Whether it becomes a reportable breach depends on what was pasted and what the vendor’s own safeguards and terms actually provide.

Does sending customer data to an AI tool require a fresh consent from the customer?

Generally no, if the AI tool is acting as a service provider processing the data for the same purpose it was originally collected for, and the business has appropriate contractual safeguards in place. It becomes a different question if the data is used for a genuinely new, unrelated purpose.

Does it matter if the AI vendor is based in the United States?

It matters for what law can reach the data once it is there — the OPC is explicit that no contract can override the laws of the country the information is transferred to — but it does not, by itself, require fresh consent from the individuals whose information it is, provided the purpose has not changed.

Not sure what your team is pasting into AI tools right now?

A short call is enough to map where the real exposure sits and what a workable AI-use policy would need to cover.