There is no single Canadian checklist that tells a business exactly when an AI deployment needs a formal privacy review first. What exists instead is a handful of specific triggers, spread across federal guidance, a federal directive, and one province's own statute — and knowing them is what actually answers the question.
Key takeaways
PIPEDA's core purpose limitation is short: an organization “may collect, use or disclose personal information only for purposes that a reasonable person would consider are appropriate in the circumstances” (PIPEDA s.5(3)). Feeding existing customer or employee data into a new AI tool is very often a new purpose — the data was collected to run a transaction or process a claim, not to train or feed a model. Whenever an AI deployment reuses data for something the organization didn't originally tell people about, that reopens the appropriate-purposes question, and a documented assessment of whether the new use still clears it is the direct answer to that reopened question.
The Privacy Commissioner's generative-AI principles single out specific domains as carrying the highest stakes for exactly this reason. Under the Fairness discussion, the guidance warns that unaddressed bias “may be more likely to result in discriminatory outcomes based on race, gender, sexual orientation, disability, or other protected characteristics, particularly where they are used as part of an administrative decision-making process…or in highly impactful contexts such as health care, employment, education, policing, immigration, criminal justice, housing or access to finance” (OPC generative-AI principles). An AI use inside any of those eight named domains is precisely the kind of use where skipping a documented assessment is hardest to justify afterward.
Quebec goes further than guidance and states an actual requirement, in the context of recruitment specifically. The province's privacy regulator, the Commission d'accès à l'information, states that before using an AI system in a hiring process, the employer must complete a privacy impact assessment (in the original, an évaluation des facteurs relatifs à la vie privée, or EFVP) (CAI, AI in recruitment guidance). That is a before, not an after — the assessment has to happen before the tool is deployed, not as a response to a complaint. The same guidance separately names emotional- or psychological-state recognition software used in video interviews as a use unlikely to be proportionate to an employer's actual needs, which is itself a useful worked example of what an assessment is supposed to catch before deployment rather than after.
Where a decision about a specific person is based exclusively on automated processing of their personal information — no human review in the loop at all — Quebec's Law 25 requires the organization to tell the person and give them a route to have a staff member review it (CAI, Law 25 changes). That is a narrower trigger than “any AI use” — it specifically targets decisions with no meaningful human review — but it is a hard legal requirement in Quebec, not guidance, and it is the kind of use an assessment needs to flag before launch so a human-review step can be designed in from the start rather than retrofitted.
Ottawa's own Directive on Automated Decision-Making sets out the most detailed Canadian description of what a pre-deployment assessment actually looks like — but it binds federal government departments, not private businesses, and should never be cited as a private-sector obligation. Under the directive, a federal body must “complete, approve and publish” an Algorithmic Impact Assessment “on the Open Government Portal prior to the production of any automated decision system,” give notice “before decisions…that the decision will be made or assisted by an automated decision system,” and provide “a meaningful explanation after” the decision is made (TBS, Directive on Automated Decision-Making, ss.6.1 & 6.2). It also grades systems into four Impact Assessment Levels based on how reversible the impact is and how sensitive the data involved is. A private business has no legal duty to follow this model, but as a design template — assess before building, disclose before deciding, explain after — it is the most concrete one available in Canada.
A concrete case makes the four triggers easier to apply than a list on its own. Suppose an Ontario employer wants to screen incoming job applications with an AI tool that scores resumes against the posted role. Trigger one applies immediately: applicant data was collected for a hiring process, and using it to train or run a scoring model is a new purpose that has to clear the reasonable-person test on its own terms. Trigger two applies because employment is one of the OPC's named high-impact contexts. If the same employer also operates in Quebec, trigger three converts the case for an assessment into an actual legal requirement that has to happen before the tool goes live, not after a candidate complains. And if the tool's scoring is allowed to reject an application with no recruiter looking at it first, trigger four adds a separate notice-and-review obligation for Quebec applicants specifically. None of the four triggers is exotic on its own; a single ordinary hiring-AI project can trip all four at once.
Once an assessment identifies a real necessity or fairness gap, the next question is usually who inside the organization owns fixing it (treadstonelaw.ca, privacy officer requirements for Ontario small businesses) — a question this page treats as a separate one from whether an assessment was needed in the first place.
No single federal rule requires one for every private-sector AI project. Specific triggers exist instead — Quebec's requirement before using AI in hiring is a hard legal one; the OPC's high-impact-context guidance and PIPEDA's purpose-limitation test are strong reasons to do one even where no statute names the word “assessment.”
Only if your organization is a federal government department or agency. It does not bind private businesses. It is, however, the most detailed Canadian model of what a pre-deployment assessment looks like in practice, and businesses can borrow its structure voluntarily.
Generally no for Quebec's specific automated-decision notice-and-review rule, which targets decisions based exclusively on automated processing. A genuine, substantive human review changes that analysis — but a token or rubber-stamp review that doesn't actually reconsider the outcome is unlikely to count.
Whether a target business ran the right assessment before deploying AI — and can document it — is exactly the kind of question a buyer's diligence checklist should ask.