A brokerage-wide AI policy, if one exists at all, is written for the brokerage. It rarely answers the actual question in front of you: what can go into a tool, what the tool can decide on its own, and what you tell a client about it. Here is how to write your own.
Key takeaways
STEP 01 OF 10
PIPEDA’s Schedule 1, clause 4.1.3 is worth quoting in full, because it resolves more questions than any other single rule: “An organization is responsible for personal information in its possession or custody, including information that has been transferred to a third party for processing. The organization shall use contractual or other means to provide a comparable level of protection while the information is being processed by a third party.”
In plain terms: putting a client’s file into an AI tool does not transfer your responsibility for that information to the vendor. Your policy’s first line should say exactly this, because it is the assumption everything else in this guide builds on.
STEP 02 OF 10
Be specific, not general. “Client personal information” is too vague to actually guide a decision at 9pm when you are drafting a follow-up email. List actual categories: name and contact details, a stated budget or timeline, a property address, financial or credit information, anything given to you in confidence. Mark each one as generally fine to use in a grounded drafting tool, or as requiring a client’s specific awareness first.
Financial and credit information is the category worth flagging hardest. It is exactly the kind of data a generic AI tool’s terms of service were not written with in mind, and it is the category most likely to matter if something does go wrong.
STEP 03 OF 10
This is worth including in your own policy because it answers a question clients sometimes ask directly. OPC guidance states: “A transfer for processing is a ‘use’ of the information; it is not a disclosure. Assuming the information is being used for the purpose it was originally collected, additional consent for the transfer is not required.”
That does not remove your accountability from step one — it answers a narrower, specific question: whether sending data to a vendor for processing needs its own separate consent on top of what you already obtained. Generally, it does not, provided the use stays within the purpose the client already understood.
STEP 04 OF 10
Quebec’s Law 25 contains a real, specific rule that has no direct equivalent in PIPEDA: where a decision about a person is based exclusively on automated processing of their personal information, the organisation must inform them, no later than when it informs them of the decision, and must give them a chance to have that decision reviewed by a staff member. The CAI states it directly: “Les organisations doivent… informer la personne concernée lorsqu’elle fait l’objet d’une décision fondée exclusivement sur un traitement automatisé.”
This matters beyond Quebec because it names a genuinely useful boundary worth adopting anywhere: never let an AI tool be the sole, unreviewed decision-maker on anything that affects a person — a pre-qualification screen, a lead-scoring cutoff, an automated response that declines to follow up. Write that boundary into your policy as a standing rule, not a Quebec-only exception.
STEP 05 OF 10
Alberta, British Columbia and Quebec have their own private-sector privacy laws, deemed substantially similar to PIPEDA, which apply instead of the federal Act for an organization operating wholly within the province. But most AI tools route data through servers outside Canada, and PIPEDA governs any organization whose personal-information handling crosses a provincial or national border — regardless of home province.
The practical result: your cross-border cloud CRM or drafting tool almost certainly triggers PIPEDA even if you practise entirely within BC, Alberta or Quebec, because the trigger is the data crossing the border, not where you personally sit. Write your policy against PIPEDA as the default assumption unless you have specifically confirmed a tool keeps all processing inside your own province.
STEP 06 OF 10
PIPEDA’s accountability principle requires a designated individual whose identity “shall be made known upon request.” For a solo practice, that is simply you — but writing it down, with your name attached, is different from it being true only by default. It is the line a client-facing privacy notice, if you have one, should point back to.
If you work within a team or under a brokerage, confirm explicitly whether the brokerage’s existing privacy officer covers your own AI tool use, or whether that responsibility sits with you specifically for tools you chose and pay for yourself.
STEP 07 OF 10
PIPEDA s.10.1(1) requires reporting a breach to the Commissioner where it is “reasonable in the circumstances to believe that the breach creates a real risk of significant harm to an individual,” and notifying the individual under the same test, “as soon as feasible after the organization determines that the breach has occurred.” Section 10.1(7) defines significant harm broadly — including “financial loss” and “damage to reputation or relationships,” both squarely relevant to a leaked client file.
Your policy does not need to solve this in detail — it needs one clear line: if a tool holding client data is compromised, you assess the risk of significant harm and report on that basis, without waiting to be told the process by someone else after it has already happened.
STEP 08 OF 10
OPC guidance is explicit that Canada takes an organization-to-organization approach rather than a jurisdiction-adequacy approach: “no contract can override the criminal, national security or any other laws of the country to which the information has been transferred.” Your policy should say plainly that client data processed by a US-hosted AI vendor is subject to US law while it sits there, not just to your own contract with the vendor.
This is a disclosure worth making to clients directly, not just documenting internally — a short line in your intake paperwork is enough, and it is the kind of transparency that heads off a much harder conversation later.
STEP 09 OF 10
This is the operating principle Quebec’s Law 25 states explicitly and that every hub in this project treats as a standing rule regardless of province: AI drafts, extracts, schedules and summarises. It does not decide. A person reviews and signs off on anything that affects a client — a price opinion, a pre-qualification, a response that could reasonably be relied on.
Put this sentence in your policy in exactly those terms. It is the single line that resolves most edge cases you have not thought to write down individually.
STEP 10 OF 10
A policy nobody re-reads is not a policy; it is a document that existed once. Keep it to a single page — the categories from step two, the accountability line from step six, the breach trigger from step seven, and the no-sole-decisions rule from step nine — and revisit it every time you adopt a genuinely new tool, not on a fixed annual schedule that may not line up with when you actually need it.
If you cannot summarise your own policy in under a minute without looking at it, it is too long to actually govern a decision made in the moment.
Assuming a vendor’s terms of service replace your own accountability. PIPEDA’s clause 4.1.3 is explicit: responsibility stays with you even after data is transferred for processing. A vendor’s terms are a tool for meeting that responsibility, not a transfer of it.
Treating Quebec’s automated-decision rule as irrelevant outside Quebec. The specific disclosure requirement is Quebec law, but the underlying principle -- no sole automated decision on anything affecting a person -- is worth adopting everywhere as a standing practice.
Assuming your own province’s substantially-similar law means PIPEDA doesn’t apply. Most cloud AI tools cross a border, and PIPEDA governs on that basis regardless of your home province. Confirm a tool keeps data in-province before assuming otherwise.
Writing a policy with no named accountable person. Even in a one-person practice, PIPEDA’s accountability principle expects a designated individual made known on request. Write your own name down.
Building a policy too long to actually remember in the moment. A one-page policy you can summarise from memory beats a comprehensive document nobody re-reads before the decision that actually needed it.
This is not a numeric example -- it is the test worth running against your own draft policy, because the two rules above resolve more edge cases together than either does alone.
A lead-scoring tool. An AI tool ranks inbound leads and auto-sends a decline message to anyone scoring below a threshold, with no human review of the declined group. Under the no-sole-decisions principle in step nine, this fails: a person is affected by an entirely automated decision with no review step, exactly the pattern Quebec’s Law 25 requires disclosure and a review right for.
The same tool, fixed. The tool still ranks and prioritizes leads automatically, but every response — including a decline — is reviewed and sent by a person before it reaches anyone. The automation now drafts and sorts; a person still decides. The same underlying tool, the same ranking logic, but the sole-decision problem is gone.
Run every AI-assisted process in your practice through this same test: is a person reviewing and deciding, or is the tool’s output reaching a client with nobody in between? The second pattern is the one both PIPEDA’s spirit and Quebec’s explicit rule are built to catch.
These are not two versions of the same rule. Quebec’s automated-decision provision has no direct PIPEDA equivalent, and building a policy that only covers PIPEDA leaves a real gap for Quebec practice.
Write your policy to the stricter standard — Law 25's no-sole-decisions rule — regardless of where you practise. It is a better practice everywhere, and it means your policy does not need rewriting if you ever take on business in Quebec.
Not necessarily for a single-page practice-level policy covering your own tool use. The steps above are built from primary sources you can cite directly. A lawyer is worth involving if your practice handles unusually sensitive data, or if you are writing a policy for a team rather than yourself.
PIPEDA’s openness principle expects you to be transparent about your information-handling practices generally. A specific line in your intake documentation naming that AI tools may be used to draft, summarise or process their information is a reasonable, low-effort way to meet that expectation.
The specific legal disclosure requirement is Quebec-specific, but the underlying principle -- never let a tool be the sole, unreviewed decision-maker on anything affecting a person -- is worth adopting as a standing rule regardless of province, as the worked example above shows.
PIPEDA’s accountability principle still applies whether or not you have written it down -- the absence of a policy is not a defence. Having one in writing mainly helps you apply the rule consistently, and gives you something concrete to show if a client or regulator ever asks how you handle their information.
A 30-minute call is enough to walk through what belongs in your own one-page version.