Treadstone Associates
Article · Privacy & records

What if an AI tool leaks client data?

The route the data took out does not change the obligation. It is a breach of security safeguards, and PIPEDA’s three duties — report, notify, record — apply exactly as they always did.

Treadstone Associates · Updated 2026

Key takeaways

  • Section 10.1 requires a report to the Privacy Commissioner, and notification of the individual, where the breach creates a real risk of significant harm.
  • • The record-keeping duty is unconditional. Section 10.3(1) plus the Breach of Security Safeguards Regulations require a record of every breach, kept 24 months.
  • • Five AI-specific vectors: the paste, the vendor training term, the over-broad retrieval index, retained prompt logs, and the mailbox-wide permission grant.
  • • Contain, preserve the logs, scope, assess sensitivity and probability of misuse, and open the record on day one whatever the assessment concludes.

The short answer

You treat it as a breach of security safeguards, because that is what it is. The route the data took out does not change the obligation. Section 10.1 of PIPEDA requires an organisation to report to the Privacy Commissioner any breach of security safeguards involving personal information under its control where it is reasonable in the circumstances to believe the breach creates a real risk of significant harm to an individual, and to notify the affected individual.

Two things surprise firms. The reporting trigger is a risk assessment, not a headcount. And the record-keeping duty is unconditional: section 10.3(1) requires a record of every breach, whether or not it met the reporting threshold, and the Breach of Security Safeguards Regulations set that retention at 24 months from the day the organisation determines the breach occurred.

The first hour

  • Contain. Revoke the API key, disable the integration, suspend the account, and ask the vendor in writing to purge the affected inputs and logs. Do it in that order and timestamp each step.
  • Preserve. Take copies of the relevant logs before anything rotates. The evidence you will want in week three is deleted by default in week one.
  • Scope. What information, whose, over what window, and to whom was it exposed. “We do not yet know” is a legitimate entry in the record; a guess is not.
  • Assess. The OPC directs you to assess the sensitivity of the personal information and the probability that it will be misused.
  • Record. Open the breach record now, whatever the assessment concludes. This is the step firms skip, and it is the one with an express statutory basis.

What a report has to contain

Section 2(1) of the Regulations lists it: a description of the circumstances and, if known, the cause; the day or period the breach occurred, or the approximate period; a description of the personal information involved so far as known; the number of individuals affected or an approximate number; the steps taken to reduce or mitigate the risk of harm; the steps taken or intended to notify affected individuals; and the name and contact details of a person who can answer the Commissioner’s questions. The report must be in writing and may be sent by any secure means.

Notification to individuals must contain enough information to let them understand the significance of the breach and take steps to reduce or mitigate the risk, and must be given as soon as feasible after the organisation determines the breach occurred. Section 10.1(7) defines significant harm broadly — bodily harm, humiliation, damage to reputation or relationships, loss of employment, business or professional opportunities, financial loss, identity theft, negative effects on the credit record, and damage to or loss of property. For a professional firm, “damage to reputation or relationships” is the limb that usually bites, because client lists and file contents are exactly that kind of information.

The AI-specific ways data leaves

The paste. Someone drops a client schedule into a consumer chatbot to reformat it. Whether that is a breach depends on your safeguards and the terms it went under — but if your policy prohibits it and the information left your control, open the record and assess it properly rather than deciding informally that it does not count.

The training term. A vendor whose terms permit using inputs to improve their models is not a breach by itself; it is a disclosure you either authorised or did not. Read the term before deployment, because discovering it afterwards converts a procurement decision into an incident.

The over-broad index. A retrieval system pointed at a shared drive will happily surface one client’s document to a staff member working on another. Nothing left the building, and it is still unauthorised access to personal information.

The log. Prompts and outputs are usually retained somewhere by default. Ask where, for how long, and who at the vendor can read them.

The connected mailbox. An assistant granted mailbox scope has, in one consent click, been granted everything in the mailbox. Scope the permission to what the task needs.

Worked example (illustrative)

An Ontario accounting firm discovers that a summarisation add-in was connected to a partner’s mailbox with full-account permissions for eleven days, and that the vendor retains prompt content for a period the firm had not checked.

The firm revokes the grant, exports the audit log, and identifies which client threads were processed. It opens a breach record the same day. The assessment considers sensitivity — corporate tax files and two personal-tax threads containing social insurance numbers — and probability of misuse, which turns on the vendor’s security posture and retention. The two personal-tax threads drive the decision to report and to notify those individuals; the record covers the whole incident either way, and is kept for 24 months.

The most valuable output was not the report. It was the standing rule the firm adopted afterwards: no add-in gets mailbox-wide scope, and no tool is connected until a named person has read its data-handling terms.

Where this sits, and which regulator

PIPEDA applies to organisations that collect, use or disclose personal information in the course of commercial activities, and the OPC is explicit that small businesses are covered as well as large ones. Alberta, British Columbia and Quebec have their own private-sector privacy statutes with their own regulators — the Office of the Information and Privacy Commissioner of Alberta and the Commission d’accès à l’information du Québec among them. Confirm which regime governs your firm before you build the runbook. Treadstone’s sister firm covers whether PIPEDA applies to a small business, mandatory breach reporting and notification obligations.

If your firm also performs the activities captured by anti-money-laundering rules, the same incident may touch a second regime — see AI and FINTRAC reporting obligations.

Questions we get asked

Is pasting into a chatbot automatically a breach?
Not automatically. It is a loss of control that you must assess. Treat the assessment as mandatory and the conclusion as open.

Does the vendor report, or do we?
The obligation sits with the organisation that has control of the personal information. That is your firm. A vendor may owe you contractual notice; it does not discharge your statutory duty.

Do we have to tell the client if there was no real risk of significant harm?
Notification is tied to that threshold, but the record is not. Keep the record regardless, and remember your professional confidentiality obligations may lead you to tell the client anyway.

How long do we keep the record?
24 months from the day you determine the breach occurred, and it must contain enough for the Commissioner to verify that you assessed and handled it properly.

Build the runbook before you need it.

A 30-minute call is enough to tell you whether AI pays for itself here.