AI strategy · Canada

Canadian privacy law and AI: what applies now

There is no federal AI statute in Canada. That does not mean nothing applies — the existing privacy law already reaches most of what people are worried about.

Updated September 2026

The short version
  • PIPEDA is still the federal private-sector privacy law. It applies to personal information regardless of whether AI is involved.
  • AIDA died with Bill C-27 in January 2025 and the government has said it is not returning.
  • Bill C-36 would replace PIPEDA with the PPCDA, with much larger penalties. It is in the House, not in force.
  • Quebec, Alberta and British Columbia have their own private-sector laws, and Quebec already regulates automated decisions.

This is a summary of the landscape as at September 2026, written for technology leaders deciding what to put in place. It is not legal advice, and where a specific use touches personal information at scale you want your own counsel involved early.

What applies today

PIPEDA. The Personal Information Protection and Electronic Documents Act remains the federal private-sector privacy law. It is technology-neutral: putting personal information into an AI tool is a use and a disclosure like any other, and the existing requirements around consent, purpose limitation, accountability and safeguards apply without modification.

That is the practical answer to most questions. There is no AI exemption, and there is no AI-specific federal rule.

Provincial private-sector laws. Quebec, Alberta and British Columbia have their own legislation covering provincially regulated organizations. Of these, Quebec’s Law 25 is the most consequential for AI. Where a decision about someone is based exclusively on automated processing, they have to be told. They can ask for the reasons and the principal factors behind it, and they can ask for a person to review it.

Sector rules. Health information is governed provincially under its own statutes. Federally regulated financial institutions have supervisory expectations around model risk and third-party arrangements. These often bite before privacy law does.

What is not in force

AIDA is not coming back. The Artificial Intelligence and Data Act was part of Bill C-27, which died on the Order Paper when Parliament was prorogued in January 2025. The government has said it will not be revived. Planning against AIDA’s risk classifications as though they were law is planning against a document with no legal force.

Bill C-36 is proposed, not enacted. In June 2026 the government tabled Bill C-36, which would enact the Protecting Privacy and Consumer Data Act and replace the private-sector part of PIPEDA. As tabled, it recognizes privacy as a fundamental right, creates a new federal regulator in place of the Office of the Privacy Commissioner, includes provisions addressing automated decision-making, and carries administrative penalties far larger than anything in the current regime.

It is at first reading. It may change substantially or not pass at all, and a bill in the House is not a compliance obligation.

What to do with that

Treat AI use as personal information handling. If the tool processes personal information, the existing analysis applies: what is the purpose, what is the basis, who has access, where is it processed, how long is it kept.

Know where processing happens. Residency is a contractual and risk question rather than a general legal prohibition for most private-sector organizations, but it is one your customers and your own contracts will ask about.

Check whether anything is decided automatically. If a system makes a decision about a person with no human involvement, Quebec’s requirements are live now, and the direction of federal reform is the same. Designing for explanation and human review is the safe position regardless of what passes.

Read the vendor terms. What the provider does with your inputs, whether they are used for training, where they are processed, and what happens at termination. These are contractual questions, and they are the ones most likely to matter in practice.

Do not wait for the statute. The governance that would satisfy a future law — knowing what data goes where, who is accountable, what is logged, how a wrong answer is caught — is the same governance that makes the systems work. Building it now is not compliance theatre; it is what stops the projects failing.

The short version

Nothing about AI is currently unregulated in Canada, because privacy law never required a new statute to reach it. What is missing is an AI-specific federal regime, and the one that was proposed is gone. Plan against the law that exists, watch the bill that is in front of the House, and design for explanation and review because both directions of travel point there.

Working out what applies to you?

We will tell you what your use actually touches, and what to put in place. For the legal opinion, you want your counsel — we will make sure they get the right question.