Treadstone Associates
Article · 9 min read

What the OPC expects of generative AI

No Canadian statute mentions generative AI by name. What Canada's Privacy Commissioner has published instead is a set of nine principles that translate PIPEDA's existing rules into specific expectations for the technology — and they are worth reading closely, because they are guidance rather than law.

Treadstone Associates · Updated 2026

Key takeaways

  • • The Office of the Privacy Commissioner's generative-AI principles are guidance, not statute — a joint statement from Canada's federal, provincial and territorial privacy commissioners applying existing privacy law to a new technology, not a new law of its own.
  • • The principles distinguish two roles — “Developers and Providers” who build or supply generative AI systems, and “organizations using generative AI” — and an organization can hold both roles at once.
  • • One line does real work across every hub on this site: organizations should not “violate ‘no-go zones’ such as profiling that may lead to unfair, unethical, or discriminatory treatment.”
  • • The OPC's own principles page confirms an open, unnamed investigation exists — “a particular generative AI service” — without naming the vendor or stating a finding. No public OPC decision names an AI vendor as having breached PIPEDA.

Guidance, not a statute

On December 7, 2023, Canada's federal, provincial and territorial privacy authorities jointly published Principles for responsible, trustworthy and privacy-protective generative AI, updated on the page as of May 6, 2025. It is a considered application of PIPEDA and the provincial equivalents to generative AI — not a new statute, and not binding in the way a regulation is. Treat it the way a Canadian court or regulator would: as the clearest current statement of what “reasonable” and “appropriate” mean under existing privacy law when the technology in question is generative AI, rather than as an enforceable rulebook in its own right.

Two roles, and an organization can hold both

The principles use specific terminology throughout: “Developers and Providers” are “individuals or organizations that develop (including training) foundation models or generative AI systems, or that put such services onto the market,” while a separate category covers “organizations using generative AI.” The page is explicit that a single business “might shift between or play multiple roles at once” (OPC generative-AI principles). A company that fine-tunes a purchased model on its own customer data, for example, is not purely a downstream user any more — it has taken on some of the developer's obligations for that fine-tuned system.

The line that carries the most weight: no-go zones

Of the nine principles, one sentence does more practical work than the rest combined. Under Necessity and proportionality, the OPC states that organizations should not “develop or put into service generative AI systems that violate ‘no-go zones’…such as profiling that may lead to unfair, unethical, or discriminatory treatment, or creating outputs that threaten fundamental rights and freedoms” (OPC generative-AI principles). That single line is the reason a “the tool works, so we're using it” justification is not enough on its own — a use can be technically effective and still fall inside a no-go zone.

The same principle sets an evidentiary bar for justifying use in the first place: “the tool should be more than simply potentially useful. This consideration should be evidence-based and establish that the tool is both necessary and likely to be effective in achieving the specified purpose.” Deciding whether a specific use clears that bar — and when that decision needs to be documented before deployment — is covered in when AI use needs a privacy assessment.

Testing before deployment, and watching after

The principles ask developers to “use an adversarial or red team…testing process to identify potential unintended inappropriate uses of the generative AI system” before release (OPC generative-AI principles), and to keep monitoring afterward. Two further specifics appear under Openness and Individual Access that businesses using a third-party tool often overlook: significant outputs about a person should be “meaningfully identified as being created by a generative AI tool,” and people affected by a significant automated decision should be given “an effective challenge mechanism” — “allowing them the opportunity to request human review and/or re-consideration of the decision.” A tool that produces a decision with no practical way for the affected person to contest it does not meet this expectation, even if the underlying data use was otherwise lawful.

On scraping public data

The principles also address a specific practice common in how generative AI systems get built: scraping content from the open web to train a model. The guidance is blunt that “publicly accessible” is not the same as unregulated: privacy authorities “have recently called on organizations to exercise great caution before scraping…‘publicly accessible’ personal information, which is still subject to data protection and privacy laws in most jurisdictions” (OPC generative-AI principles). A photo, a post or a profile being visible to anyone online does not put the personal information in it outside PIPEDA's reach.

Accuracy is a duty on the data, not just the answer

Principle 8, Accuracy, is easy to misread as being only about the model's final answer. The text is broader: developers and providers should ensure “that any personal information used to train their generative AI models is as accurate as necessary for the purposes,” maintain “a process by which a generative AI system can be updated…where it becomes known that the information on which it was trained is inaccurate or out-of-date,” and “inform organizations using generative AI about any known issues or limitations about the accuracy of generative AI outputs” (OPC generative-AI principles). That last clause puts a duty on the developer to disclose known accuracy problems, not just build them out silently — which matters for anyone deciding how to tell if an AI output is trustworthy in the first place.

A specific trap

What the OPC does not say. The principles page confirms that “the Office of the Privacy Commissioner of Canada (OPC) and its counterparts in British Columbia, Quebec and Alberta also have an open investigation relating to a particular generative AI service.” That is the complete extent of what the page states — it does not name the service, and it does not describe any finding against it. There is no published OPC decision naming any AI vendor as having breached PIPEDA. Treat the existence of an open investigation as exactly that: open, and unresolved.

Businesses building an internal privacy policy that needs to reflect these principles — rather than restate them from scratch — can start from the general PIPEDA customer-data framework the principles sit on top of (treadstonelaw.ca, PIPEDA customer data rules for Ontario small businesses).

Common questions

Are the OPC's generative-AI principles legally binding?

No. They are guidance from Canada's federal, provincial and territorial privacy commissioners applying existing privacy law — principally PIPEDA — to generative AI. The underlying statutes are binding; the principles document is the regulators' considered interpretation of what those statutes require in this context.

Has the OPC found that a specific AI product violates Canadian privacy law?

Not publicly. The principles page states only that an open investigation exists “relating to a particular generative AI service,” without naming it or describing a finding. No published OPC decision names an AI vendor as having breached PIPEDA.

If our business only uses a generative AI tool someone else built, do these principles still apply?

Yes, under the “organizations using generative AI” role the principles define separately from developers and providers. The specific obligations differ by role, but using a purchased tool doesn't exempt an organization from principles like necessity, no-go zones, and the challenge mechanism for significant decisions.

Where this goes next

Turning nine principles into an actual internal policy — who signs off, what gets logged, how a challenge request gets handled — is the operational half of this.