The Field GuideAI Explained
AI data privacy for Canadian businesses
A practical privacy review for Canadian companies using AI vendors, with special attention to British Columbia businesses and personal information.
By Adi Huric, founder of Most AI LabsAugust 202611 min read
On this page
Putting personal information into an AI tool is still a collection, use or disclosure of personal information. Calling the feature a copilot does not create a privacy exemption.
For a Vancouver business, the first questions are ordinary privacy questions: what information is involved, why is it needed, who controls it, where does it go and what happens when a person exercises a privacy right?
This article is operational guidance, not legal advice.
Know which law applies
British Columbia's Personal Information Protection Act generally governs provincially regulated private organizations in BC. The federal Personal Information Protection and Electronic Documents Act can apply to federally regulated organizations and to personal information moving across provincial or national borders in commercial activity. Sector rules and contractual duties may add requirements.
The Office of the Privacy Commissioner of Canada explains the interaction between PIPEDA and provincial private-sector laws. OPC Canada The OIPC BC provides guidance specifically for private organizations in the province. OIPC BC
Do not assume an overseas AI vendor takes the organization out of scope. Under BC PIPA, the organization remains responsible for personal information under its control, including information handled by a service provider.
Inventory the data and purpose
For each AI use, document:
- specific business purpose;
- categories of personal and confidential information;
- source and authority or consent for the use;
- people affected;
- model and other vendors involved;
- data locations and subprocessors;
- inputs, outputs, logs and derived profiles;
- retention and deletion path;
- person accountable for the use.
If the team cannot describe the data flow, it cannot make a credible privacy statement.
Apply necessity and proportionality
Ask whether personal information is actually needed. Remove names, contact details and free-text notes where aggregate or synthetic data will answer the question. Pseudonymization reduces some exposure but does not necessarily make data anonymous if it can be reconnected.
Canadian privacy regulators' joint generative-AI principles call for legal authority, appropriate purposes, necessity and proportionality, openness, safeguards, individual access and accountability. They also urge privacy by design and special attention to vulnerable groups. Joint regulator principles
Review the vendor, not just the feature
Obtain written answers to:
- Is customer data used to train shared models?
- Can that use be disabled contractually and technically?
- How long are prompts, files, outputs and logs kept?
- Where are they processed and stored?
- Which subprocessors receive them?
- What security controls, audit reports and incident duties apply?
- Can administrators restrict connectors, models and sharing?
- Can records be exported, corrected and deleted?
- What happens to data after termination?
- Will material terms or model providers change without approval?
A vendor's statement that data is encrypted answers one control. It does not answer purpose, retention, training, access or deletion.
Match the legal promise to the technical setting
If a contract says prompts are not used for training, verify that the purchased account and configuration receive that protection. Consumer and business plans can have different terms. Disable public sharing and unmanaged connectors where they are not required.
Limit user access, retain audit records, and prevent employees from pasting unapproved data into personal accounts. Training should include realistic examples, such as support tickets, resumes, health details, customer lists and private source code.
Conduct a privacy impact assessment
A privacy impact assessment should happen before deployment and when the use changes. Map data, purposes, permissions, vendors, risks, mitigations and residual risk. The OIPC BC publishes a PIA template and guidance that organizations can adapt. OIPC BC PIA guidance
For automated recommendations, assess accuracy, bias, explainability, human review and the process for a person to challenge or correct information. BC PIPA requires reasonable efforts to ensure accuracy when personal information is used to make a decision that directly affects an individual.
Design retention and incident response
Keeping every prompt "for improvement" is not a retention policy. Set periods based on purpose and legal need. Ensure deletion reaches vendor copies where the contract promises it. Preserve information connected to decisions as required, then destroy it securely when no longer needed.
BC PIPA addresses reasonable security safeguards in section 34 and retention and destruction in section 35. BC Laws
Update incident response for AI-specific paths: exposed knowledge indexes, public share links, prompt logs, unintended model output and compromised connectors.
A minimum launch gate
Do not put personal information into production until the organization has:
- a named owner and defined purpose;
- a documented data flow and legal review;
- data minimization and access controls;
- approved vendor terms and configuration;
- a privacy impact assessment;
- retention, deletion and incident procedures;
- testing for disclosure and unauthorized retrieval;
- clear notice, human contact and correction route where required.
Privacy work does not begin after an AI pilot becomes useful. The pilot itself can create the disclosure.
Source check
Privacy applicability depends on jurisdiction, sector, data flow and facts. Sources were checked against the current consolidated BC statute and federal and provincial regulator guidance on August 22, 2026. Obtain qualified legal advice for high-risk use.
Sources
- BC Laws: Personal Information Protection Act
- OIPC BC: Guidance for private organizations
- OIPC BC: Privacy impact assessment guidance
- Office of the Privacy Commissioner of Canada: PIPEDA
- Canadian privacy regulators: Principles for responsible generative AI
- Government of Canada: Guide on the use of generative artificial intelligence
Where this leads
Next step
See where your own visibility stands.
The 7-day audit turns this research into a picture of your business. Yours to keep, whether you hire us or not.
Read next
The Agentic Web
The agentic web is here. Your next customer might send a bot first.
In mid-2026 Google, ChatGPT, and Claude all shipped AI agents that browse websites, compare options, and even book appointments for a person. Your site now has two audiences: humans, and the agents people send ahead of them. Here is what changed, and the honest, no-hype way to get ready.
8 min
AI Implementation
What an AI agent actually costs, and what it does
Real cost ranges, real examples, no buzzwords. What AI agents do in a working business, and how to know if one will earn its keep in yours.
8 min
Build decisions
Build vs buy for AI implementation
How to choose between a packaged AI product, a custom workflow and a mixed architecture based on differentiation, data, risk and exit cost.
10 min