The Field GuideAI Explained

AI data privacy for Canadian businesses

A practical privacy review for Canadian companies using AI vendors, with special attention to British Columbia businesses and personal information.

By Adi Huric, founder of Most AI LabsAugust 202611 min read

On this page
    Know which law appliesInventory the data and purposeApply necessity and proportionalityReview the vendor, not just the featureMatch the legal promise to the technical settingConduct a privacy impact assessmentDesign retention and incident responseA minimum launch gateSource checkSources

Putting personal information into an AI tool is still a collection, use or disclosure of personal information. Calling the feature a copilot does not create a privacy exemption.

For a Vancouver business, the first questions are ordinary privacy questions: what information is involved, why is it needed, who controls it, where does it go and what happens when a person exercises a privacy right?

This article is operational guidance, not legal advice.

Know which law applies

British Columbia's Personal Information Protection Act generally governs provincially regulated private organizations in BC. The federal Personal Information Protection and Electronic Documents Act can apply to federally regulated organizations and to personal information moving across provincial or national borders in commercial activity. Sector rules and contractual duties may add requirements.

The Office of the Privacy Commissioner of Canada explains the interaction between PIPEDA and provincial private-sector laws. OPC Canada The OIPC BC provides guidance specifically for private organizations in the province. OIPC BC

Do not assume an overseas AI vendor takes the organization out of scope. Under BC PIPA, the organization remains responsible for personal information under its control, including information handled by a service provider.

Inventory the data and purpose

For each AI use, document:

  • specific business purpose;
  • categories of personal and confidential information;
  • source and authority or consent for the use;
  • people affected;
  • model and other vendors involved;
  • data locations and subprocessors;
  • inputs, outputs, logs and derived profiles;
  • retention and deletion path;
  • person accountable for the use.

If the team cannot describe the data flow, it cannot make a credible privacy statement.

Apply necessity and proportionality

Ask whether personal information is actually needed. Remove names, contact details and free-text notes where aggregate or synthetic data will answer the question. Pseudonymization reduces some exposure but does not necessarily make data anonymous if it can be reconnected.

Canadian privacy regulators' joint generative-AI principles call for legal authority, appropriate purposes, necessity and proportionality, openness, safeguards, individual access and accountability. They also urge privacy by design and special attention to vulnerable groups. Joint regulator principles

Review the vendor, not just the feature

Obtain written answers to:

  • Is customer data used to train shared models?
  • Can that use be disabled contractually and technically?
  • How long are prompts, files, outputs and logs kept?
  • Where are they processed and stored?
  • Which subprocessors receive them?
  • What security controls, audit reports and incident duties apply?
  • Can administrators restrict connectors, models and sharing?
  • Can records be exported, corrected and deleted?
  • What happens to data after termination?
  • Will material terms or model providers change without approval?

A vendor's statement that data is encrypted answers one control. It does not answer purpose, retention, training, access or deletion.

If a contract says prompts are not used for training, verify that the purchased account and configuration receive that protection. Consumer and business plans can have different terms. Disable public sharing and unmanaged connectors where they are not required.

Limit user access, retain audit records, and prevent employees from pasting unapproved data into personal accounts. Training should include realistic examples, such as support tickets, resumes, health details, customer lists and private source code.

Conduct a privacy impact assessment

A privacy impact assessment should happen before deployment and when the use changes. Map data, purposes, permissions, vendors, risks, mitigations and residual risk. The OIPC BC publishes a PIA template and guidance that organizations can adapt. OIPC BC PIA guidance

For automated recommendations, assess accuracy, bias, explainability, human review and the process for a person to challenge or correct information. BC PIPA requires reasonable efforts to ensure accuracy when personal information is used to make a decision that directly affects an individual.

Design retention and incident response

Keeping every prompt "for improvement" is not a retention policy. Set periods based on purpose and legal need. Ensure deletion reaches vendor copies where the contract promises it. Preserve information connected to decisions as required, then destroy it securely when no longer needed.

BC PIPA addresses reasonable security safeguards in section 34 and retention and destruction in section 35. BC Laws

Update incident response for AI-specific paths: exposed knowledge indexes, public share links, prompt logs, unintended model output and compromised connectors.

A minimum launch gate

Do not put personal information into production until the organization has:

  1. a named owner and defined purpose;
  2. a documented data flow and legal review;
  3. data minimization and access controls;
  4. approved vendor terms and configuration;
  5. a privacy impact assessment;
  6. retention, deletion and incident procedures;
  7. testing for disclosure and unauthorized retrieval;
  8. clear notice, human contact and correction route where required.

Privacy work does not begin after an AI pilot becomes useful. The pilot itself can create the disclosure.

Source check

Privacy applicability depends on jurisdiction, sector, data flow and facts. Sources were checked against the current consolidated BC statute and federal and provincial regulator guidance on August 22, 2026. Obtain qualified legal advice for high-risk use.

Sources