No Canadian statute mentions generative AI by name. What Canada's Privacy Commissioner has published instead is a set of nine principles that translate PIPEDA's existing rules into specific expectations for the technology — and they are worth reading closely, because they are guidance rather than law.
Key takeaways
On December 7, 2023, Canada's federal, provincial and territorial privacy authorities jointly published Principles for responsible, trustworthy and privacy-protective generative AI, updated on the page as of May 6, 2025. It is a considered application of PIPEDA and the provincial equivalents to generative AI — not a new statute, and not binding in the way a regulation is. Treat it the way a Canadian court or regulator would: as the clearest current statement of what “reasonable” and “appropriate” mean under existing privacy law when the technology in question is generative AI, rather than as an enforceable rulebook in its own right.
The principles use specific terminology throughout: “Developers and Providers” are “individuals or organizations that develop (including training) foundation models or generative AI systems, or that put such services onto the market,” while a separate category covers “organizations using generative AI.” The page is explicit that a single business “might shift between or play multiple roles at once” (OPC generative-AI principles). A company that fine-tunes a purchased model on its own customer data, for example, is not purely a downstream user any more — it has taken on some of the developer's obligations for that fine-tuned system.
Of the nine principles, one sentence does more practical work than the rest combined. Under Necessity and proportionality, the OPC states that organizations should not “develop or put into service generative AI systems that violate ‘no-go zones’…such as profiling that may lead to unfair, unethical, or discriminatory treatment, or creating outputs that threaten fundamental rights and freedoms” (OPC generative-AI principles). That single line is the reason a “the tool works, so we're using it” justification is not enough on its own — a use can be technically effective and still fall inside a no-go zone.
The same principle sets an evidentiary bar for justifying use in the first place: “the tool should be more than simply potentially useful. This consideration should be evidence-based and establish that the tool is both necessary and likely to be effective in achieving the specified purpose.” Deciding whether a specific use clears that bar — and when that decision needs to be documented before deployment — is covered in when AI use needs a privacy assessment.
The principles ask developers to “use an adversarial or red team…testing process to identify potential unintended inappropriate uses of the generative AI system” before release (OPC generative-AI principles), and to keep monitoring afterward. Two further specifics appear under Openness and Individual Access that businesses using a third-party tool often overlook: significant outputs about a person should be “meaningfully identified as being created by a generative AI tool,” and people affected by a significant automated decision should be given “an effective challenge mechanism” — “allowing them the opportunity to request human review and/or re-consideration of the decision.” A tool that produces a decision with no practical way for the affected person to contest it does not meet this expectation, even if the underlying data use was otherwise lawful.
The principles also address a specific practice common in how generative AI systems get built: scraping content from the open web to train a model. The guidance is blunt that “publicly accessible” is not the same as unregulated: privacy authorities “have recently called on organizations to exercise great caution before scraping…‘publicly accessible’ personal information, which is still subject to data protection and privacy laws in most jurisdictions” (OPC generative-AI principles). A photo, a post or a profile being visible to anyone online does not put the personal information in it outside PIPEDA's reach.
Principle 8, Accuracy, is easy to misread as being only about the model's final answer. The text is broader: developers and providers should ensure “that any personal information used to train their generative AI models is as accurate as necessary for the purposes,” maintain “a process by which a generative AI system can be updated…where it becomes known that the information on which it was trained is inaccurate or out-of-date,” and “inform organizations using generative AI about any known issues or limitations about the accuracy of generative AI outputs” (OPC generative-AI principles). That last clause puts a duty on the developer to disclose known accuracy problems, not just build them out silently — which matters for anyone deciding how to tell if an AI output is trustworthy in the first place.
A specific trap
What the OPC does not say. The principles page confirms that “the Office of the Privacy Commissioner of Canada (OPC) and its counterparts in British Columbia, Quebec and Alberta also have an open investigation relating to a particular generative AI service.” That is the complete extent of what the page states — it does not name the service, and it does not describe any finding against it. There is no published OPC decision naming any AI vendor as having breached PIPEDA. Treat the existence of an open investigation as exactly that: open, and unresolved.
Businesses building an internal privacy policy that needs to reflect these principles — rather than restate them from scratch — can start from the general PIPEDA customer-data framework the principles sit on top of (treadstonelaw.ca, PIPEDA customer data rules for Ontario small businesses).
No. They are guidance from Canada's federal, provincial and territorial privacy commissioners applying existing privacy law — principally PIPEDA — to generative AI. The underlying statutes are binding; the principles document is the regulators' considered interpretation of what those statutes require in this context.
Not publicly. The principles page states only that an open investigation exists “relating to a particular generative AI service,” without naming it or describing a finding. No published OPC decision names an AI vendor as having breached PIPEDA.
Yes, under the “organizations using generative AI” role the principles define separately from developers and providers. The specific obligations differ by role, but using a purchased tool doesn't exempt an organization from principles like necessity, no-go zones, and the challenge mechanism for significant decisions.
Turning nine principles into an actual internal policy — who signs off, what gets logged, how a challenge request gets handled — is the operational half of this.