Guide · Privacy & trust
Is ChatGPT PIPEDA compliant? Using AI without breaking PIPEDA or PHIA
"Is ChatGPT PIPEDA compliant?" is the question every Canadian business owner should ask before pasting client information into an AI tool. The short answer: no AI tool is "PIPEDA compliant" on its own. Compliance depends on which plan you use, how it's configured, and what your business does with personal information.
Short answer
- PIPEDA applies to your business. You stay accountable for personal information you send to any AI vendor.
- Consumer ChatGPT (Free, Plus, Pro) may use chats for training by default. Business, Enterprise and API plans don't train on your data by default.
- In May 2026, federal and provincial privacy commissioners released findings on OpenAI. The federal complaint was "conditionally resolved."
- Manitoba clinics are trustees under PHIA. They need safeguards and a written agreement with any vendor that handles health information.
Why "compliant" is the wrong question
PIPEDA, Canada's federal private-sector privacy law, governs organisations, not software. There's no PIPEDA certification for a product. What matters is whether your use of a tool meets PIPEDA's principles: accountability, identifying purposes, consent, limiting collection and use, safeguards, openness and individual access.
The better question is: can we use this tool, on this plan, in a way that meets our obligations? For most businesses, the answer is yes, with the right setup.
What the privacy commissioners found about OpenAI (2026)
On May 6, 2026, the Office of the Privacy Commissioner of Canada published joint findings with British Columbia, Alberta and Quebec on OpenAI (PIPEDA Findings #2026-002). The OPC found the complaint well-founded but conditionally resolved, based on commitments from OpenAI and ongoing quarterly reporting. The provincial commissioners found it unresolved.
The concerns centred on how training data was collected, the lack of express consent to train on users' chats, and people's ability to access and delete their information. For businesses, the lesson is to avoid putting client personal information into consumer AI accounts.
Which AI plans use your data for training
| Tool / plan | Trains on your data by default? | Canadian data residency |
|---|---|---|
| ChatGPT Free, Plus, Pro | Yes, unless you turn off "Improve the model for everyone" | No |
| ChatGPT Business (formerly Team) | No | Not listed |
| ChatGPT Enterprise, Edu, Healthcare, API | No | Available for data at rest (new workspaces) |
| Microsoft 365 Copilot | No. Prompts, responses and your Microsoft 365 data aren't used to train foundation models | Data residency commitments apply; in-country processing for Canada expected in 2027 |
Two details matter. Even with training turned off on a consumer plan, a thumbs-up or thumbs-down rating can send that conversation to OpenAI. And "data residency" usually covers where data is stored, not necessarily where the AI processes it. Check both.
Sending data outside Canada
The OPC's guidance on cross-border processing says transferring personal information to a service provider is a use, not a disclosure. It doesn't automatically require new consent. But your business stays accountable, so you must:
- ensure comparable protection through your contract with the vendor, and
- tell people their information may be processed outside Canada and could be accessed by foreign authorities.
In practice, update your privacy policy to mention AI and cloud processors, and use vendors with proper business terms.
The regulators' principles for generative AI
In December 2023, Canada's federal, provincial and territorial privacy commissioners jointly published principles for generative AI. They cover legal authority and consent, appropriate purposes, necessity and proportionality, openness, accountability, individual access, limiting collection, accuracy and safeguards. They also named "no-go zones," such as using AI to manipulate people into disclosing personal information.
For a small business, a sensible reading is to use AI for clear purposes, send it only the personal information it needs, check its output, and be open about it.
PHIA and AI in Manitoba clinics
Manitoba's Personal Health Information Act (PHIA) makes clinics and health professionals "trustees" of personal health information. For AI tools, that means:
- Safeguards (s.18): reasonable administrative, technical and physical protections, such as access controls, MFA and retention limits.
- Information manager agreements (s.25): a written agreement with any vendor that processes health information for you. The trustee stays responsible.
Shared Health Manitoba's guidelines for AI scribes are a useful benchmark even outside the public system:
- Avoid public or consumer AI tools.
- Choose vendors from Canada Health Infoway's pre-qualified list.
- Record informed patient consent.
- Make sure the vendor doesn't train on patient data.
- Set short retention and use MFA.
The College of Physicians and Surgeons of Manitoba also advises informed consent before recording, a privacy impact assessment, and reviewing AI output before it enters the chart.
Manitoba began public consultations on updating privacy law for AI in March 2026, so expect these rules to evolve. We build AI receptionists and automation for clinics with these requirements in mind.
What's changing federally
Bill C-27, which included the proposed Artificial Intelligence and Data Act, died when Parliament was prorogued in January 2025. In June 2026, the federal government tabled Bill C-36, the Protecting Privacy and Consumer Data Act. It has no standalone AI law, but it proposes much higher penalties, disclosure of automated decisions with significant effects, and risk assessment before sending data outside Canada. It hadn't become law when we last checked.
A practical checklist for your business
- Ban client personal information in consumer AI accounts. Provide a business-tier tool instead.
- Write a one-page AI use policy. List what tools are approved, what data can go in, and who reviews output.
- Check each vendor's terms for training, retention, data residency and subprocessors.
- Update your privacy policy to mention AI and cross-border processing.
- Keep a person in the loop for anything that affects a customer, patient or employee.
- Clinics: sign information manager agreements and document patient consent.
We set this up as part of every AI consulting in Winnipeg engagement, and our AI training covers it for staff.
This guide is general information, not legal advice. For decisions about your specific obligations, consult a privacy lawyer or your privacy officer.
Sources
- OPC: Findings on OpenAI (May 6, 2026)
- OPC: Guidelines for processing personal data across borders
- OPC: Principles for responsible, trustworthy and privacy-protective generative AI
- OpenAI Help: Data controls in ChatGPT
- OpenAI Help: Data residency for ChatGPT
- Microsoft Learn: Copilot privacy and data
- Manitoba: The Personal Health Information Act
- Manitoba Health: Information manager agreements under PHIA
- Shared Health Manitoba: AI scribe usage guidelines
- CPSM: Responsible use of AI in the practice of medicine
- DLA Piper: Canada tables Bill C-36