Treadstone Associates
Guide

Writing an AI use policy for your own practice

A brokerage-wide AI policy, if one exists at all, is written for the brokerage. It rarely answers the actual question in front of you: what can go into a tool, what the tool can decide on its own, and what you tell a client about it. Here is how to write your own.

Treadstone Associates · Updated 2026

Key takeaways

  • • PIPEDA’s Schedule 1, clause 4.1.3 is the single rule that answers most 'can client data go into this tool' questions: accountability stays with you even after data is transferred to a vendor for processing.
  • • Quebec’s Law 25 requires disclosure whenever a decision about a person is based exclusively on automated processing — a real, sourced rule with no equivalent written into PIPEDA itself.
  • • A cross-border cloud tool almost certainly triggers PIPEDA even for an agent practising in BC, Alberta or Quebec, because the data crossing the border is what matters, not where you personally sit.
  • • A one-page policy that names what goes in, what the tool may decide alone, and who checks the output is more useful than a long document nobody reads before the first incident.

STEP 01 OF 10

Start from the one clause that answers most of this

PIPEDA’s Schedule 1, clause 4.1.3 is worth quoting in full, because it resolves more questions than any other single rule: “An organization is responsible for personal information in its possession or custody, including information that has been transferred to a third party for processing. The organization shall use contractual or other means to provide a comparable level of protection while the information is being processed by a third party.”

In plain terms: putting a client’s file into an AI tool does not transfer your responsibility for that information to the vendor. Your policy’s first line should say exactly this, because it is the assumption everything else in this guide builds on.

STEP 02 OF 10

List what may go into a tool, and what may not

Be specific, not general. “Client personal information” is too vague to actually guide a decision at 9pm when you are drafting a follow-up email. List actual categories: name and contact details, a stated budget or timeline, a property address, financial or credit information, anything given to you in confidence. Mark each one as generally fine to use in a grounded drafting tool, or as requiring a client’s specific awareness first.

Financial and credit information is the category worth flagging hardest. It is exactly the kind of data a generic AI tool’s terms of service were not written with in mind, and it is the category most likely to matter if something does go wrong.

STEP 03 OF 10

Write down that a transfer for processing is not a disclosure

This is worth including in your own policy because it answers a question clients sometimes ask directly. OPC guidance states: “A transfer for processing is a ‘use’ of the information; it is not a disclosure. Assuming the information is being used for the purpose it was originally collected, additional consent for the transfer is not required.”

That does not remove your accountability from step one — it answers a narrower, specific question: whether sending data to a vendor for processing needs its own separate consent on top of what you already obtained. Generally, it does not, provided the use stays within the purpose the client already understood.

STEP 04 OF 10

Add Quebec’s rule, even if you don’t practise there yet

Quebec’s Law 25 contains a real, specific rule that has no direct equivalent in PIPEDA: where a decision about a person is based exclusively on automated processing of their personal information, the organisation must inform them, no later than when it informs them of the decision, and must give them a chance to have that decision reviewed by a staff member. The CAI states it directly: “Les organisations doivent… informer la personne concernée lorsqu’elle fait l’objet d’une décision fondée exclusivement sur un traitement automatisé.”

This matters beyond Quebec because it names a genuinely useful boundary worth adopting anywhere: never let an AI tool be the sole, unreviewed decision-maker on anything that affects a person — a pre-qualification screen, a lead-scoring cutoff, an automated response that declines to follow up. Write that boundary into your policy as a standing rule, not a Quebec-only exception.

STEP 05 OF 10

Know the province you practise in probably doesn’t change which law applies

Alberta, British Columbia and Quebec have their own private-sector privacy laws, deemed substantially similar to PIPEDA, which apply instead of the federal Act for an organization operating wholly within the province. But most AI tools route data through servers outside Canada, and PIPEDA governs any organization whose personal-information handling crosses a provincial or national border — regardless of home province.

The practical result: your cross-border cloud CRM or drafting tool almost certainly triggers PIPEDA even if you practise entirely within BC, Alberta or Quebec, because the trigger is the data crossing the border, not where you personally sit. Write your policy against PIPEDA as the default assumption unless you have specifically confirmed a tool keeps all processing inside your own province.

STEP 06 OF 10

Name who is accountable, in writing, even if it’s just you

PIPEDA’s accountability principle requires a designated individual whose identity “shall be made known upon request.” For a solo practice, that is simply you — but writing it down, with your name attached, is different from it being true only by default. It is the line a client-facing privacy notice, if you have one, should point back to.

If you work within a team or under a brokerage, confirm explicitly whether the brokerage’s existing privacy officer covers your own AI tool use, or whether that responsibility sits with you specifically for tools you chose and pay for yourself.

STEP 07 OF 10

Write your breach-notification trigger before you need it

PIPEDA s.10.1(1) requires reporting a breach to the Commissioner where it is “reasonable in the circumstances to believe that the breach creates a real risk of significant harm to an individual,” and notifying the individual under the same test, “as soon as feasible after the organization determines that the breach has occurred.” Section 10.1(7) defines significant harm broadly — including “financial loss” and “damage to reputation or relationships,” both squarely relevant to a leaked client file.

Your policy does not need to solve this in detail — it needs one clear line: if a tool holding client data is compromised, you assess the risk of significant harm and report on that basis, without waiting to be told the process by someone else after it has already happened.

STEP 08 OF 10

Cover cross-border data explicitly, not by omission

OPC guidance is explicit that Canada takes an organization-to-organization approach rather than a jurisdiction-adequacy approach: “no contract can override the criminal, national security or any other laws of the country to which the information has been transferred.” Your policy should say plainly that client data processed by a US-hosted AI vendor is subject to US law while it sits there, not just to your own contract with the vendor.

This is a disclosure worth making to clients directly, not just documenting internally — a short line in your intake paperwork is enough, and it is the kind of transparency that heads off a much harder conversation later.

STEP 09 OF 10

Set the one rule that ties everything together: no sole automated decisions

This is the operating principle Quebec’s Law 25 states explicitly and that every hub in this project treats as a standing rule regardless of province: AI drafts, extracts, schedules and summarises. It does not decide. A person reviews and signs off on anything that affects a client — a price opinion, a pre-qualification, a response that could reasonably be relied on.

Put this sentence in your policy in exactly those terms. It is the single line that resolves most edge cases you have not thought to write down individually.

STEP 10 OF 10

Keep it to one page, and actually re-read it

A policy nobody re-reads is not a policy; it is a document that existed once. Keep it to a single page — the categories from step two, the accountability line from step six, the breach trigger from step seven, and the no-sole-decisions rule from step nine — and revisit it every time you adopt a genuinely new tool, not on a fixed annual schedule that may not line up with when you actually need it.

If you cannot summarise your own policy in under a minute without looking at it, it is too long to actually govern a decision made in the moment.

Common mistakes

Assuming a vendor’s terms of service replace your own accountability. PIPEDA’s clause 4.1.3 is explicit: responsibility stays with you even after data is transferred for processing. A vendor’s terms are a tool for meeting that responsibility, not a transfer of it.

Treating Quebec’s automated-decision rule as irrelevant outside Quebec. The specific disclosure requirement is Quebec law, but the underlying principle -- no sole automated decision on anything affecting a person -- is worth adopting everywhere as a standing practice.

Assuming your own province’s substantially-similar law means PIPEDA doesn’t apply. Most cloud AI tools cross a border, and PIPEDA governs on that basis regardless of your home province. Confirm a tool keeps data in-province before assuming otherwise.

Writing a policy with no named accountable person. Even in a one-person practice, PIPEDA’s accountability principle expects a designated individual made known on request. Write your own name down.

Building a policy too long to actually remember in the moment. A one-page policy you can summarise from memory beats a comprehensive document nobody re-reads before the decision that actually needed it.

The rule that catches the edge case you didn’t think to write down

This is not a numeric example -- it is the test worth running against your own draft policy, because the two rules above resolve more edge cases together than either does alone.

A lead-scoring tool. An AI tool ranks inbound leads and auto-sends a decline message to anyone scoring below a threshold, with no human review of the declined group. Under the no-sole-decisions principle in step nine, this fails: a person is affected by an entirely automated decision with no review step, exactly the pattern Quebec’s Law 25 requires disclosure and a review right for.

The same tool, fixed. The tool still ranks and prioritizes leads automatically, but every response — including a decline — is reviewed and sent by a person before it reaches anyone. The automation now drafts and sorts; a person still decides. The same underlying tool, the same ranking logic, but the sole-decision problem is gone.

Run every AI-assisted process in your practice through this same test: is a person reviewing and deciding, or is the tool’s output reaching a client with nobody in between? The second pattern is the one both PIPEDA’s spirit and Quebec’s explicit rule are built to catch.

PIPEDA and Law 25, side by side

These are not two versions of the same rule. Quebec’s automated-decision provision has no direct PIPEDA equivalent, and building a policy that only covers PIPEDA leaves a real gap for Quebec practice.

  • PIPEDA (most of Canada). Ten fair information principles, an accountability duty that survives a transfer to a vendor, and a breach-reporting trigger keyed to “real risk of significant harm” — but no explicit rule about automated decision-making standing alone.
  • Quebec’s Law 25. Adds a specific, named right: disclosure of a decision based exclusively on automated processing, and the opportunity to have it reviewed by a person. The CAI’s hiring guidance extends the same principle to recruitment screening specifically, naming emotional- or psychological-state recognition in video interviews as a use “très peu susceptibles d’être proportionnels aux besoins de l’employeur” — very unlikely to be proportional to the employer’s needs.
  • Alberta and British Columbia. Each runs its own substantially-similar private-sector law without Quebec’s specific automated-decision provision — closer to PIPEDA’s structure than to Quebec’s, though each has its own regulator and its own guidance worth checking directly rather than assumed identical to PIPEDA.

Write your policy to the stricter standard — Law 25's no-sole-decisions rule — regardless of where you practise. It is a better practice everywhere, and it means your policy does not need rewriting if you ever take on business in Quebec.

Frequently asked

Do you need a lawyer to write an AI use policy?

Not necessarily for a single-page practice-level policy covering your own tool use. The steps above are built from primary sources you can cite directly. A lawyer is worth involving if your practice handles unusually sensitive data, or if you are writing a policy for a team rather than yourself.

Does PIPEDA require you to disclose which AI tools you use to a client?

PIPEDA’s openness principle expects you to be transparent about your information-handling practices generally. A specific line in your intake documentation naming that AI tools may be used to draft, summarise or process their information is a reasonable, low-effort way to meet that expectation.

Is Quebec’s automated-decision rule only relevant if you practise in Quebec?

The specific legal disclosure requirement is Quebec-specific, but the underlying principle -- never let a tool be the sole, unreviewed decision-maker on anything affecting a person -- is worth adopting as a standing rule regardless of province, as the worked example above shows.

What happens if you don’t have a written AI policy at all?

PIPEDA’s accountability principle still applies whether or not you have written it down -- the absence of a policy is not a defence. Having one in writing mainly helps you apply the rule consistently, and gives you something concrete to show if a client or regulator ever asks how you handle their information.

See how a policy like this actually gets applied day to day.

A 30-minute call is enough to walk through what belongs in your own one-page version.