Call us Free audit

Guide · Privacy & trust

Is ChatGPT PIPEDA compliant? Using AI without breaking PIPEDA or PHIA

"Is ChatGPT PIPEDA compliant?" is the question every Canadian business owner should ask before pasting client information into an AI tool. The short answer: no AI tool is "PIPEDA compliant" on its own. Compliance depends on which plan you use, how it's configured, and what your business does with personal information.

Short answer

  • PIPEDA applies to your business. You stay accountable for personal information you send to any AI vendor.
  • Consumer ChatGPT (Free, Plus, Pro) may use chats for training by default. Business, Enterprise and API plans don't train on your data by default.
  • In May 2026, federal and provincial privacy commissioners released findings on OpenAI. The federal complaint was "conditionally resolved."
  • Manitoba clinics are trustees under PHIA. They need safeguards and a written agreement with any vendor that handles health information.

Why "compliant" is the wrong question

PIPEDA, Canada's federal private-sector privacy law, governs organisations, not software. There's no PIPEDA certification for a product. What matters is whether your use of a tool meets PIPEDA's principles: accountability, identifying purposes, consent, limiting collection and use, safeguards, openness and individual access.

The better question is: can we use this tool, on this plan, in a way that meets our obligations? For most businesses, the answer is yes, with the right setup.

What the privacy commissioners found about OpenAI (2026)

On May 6, 2026, the Office of the Privacy Commissioner of Canada published joint findings with British Columbia, Alberta and Quebec on OpenAI (PIPEDA Findings #2026-002). The OPC found the complaint well-founded but conditionally resolved, based on commitments from OpenAI and ongoing quarterly reporting. The provincial commissioners found it unresolved.

The concerns centred on how training data was collected, the lack of express consent to train on users' chats, and people's ability to access and delete their information. For businesses, the lesson is to avoid putting client personal information into consumer AI accounts.

Which AI plans use your data for training

Tool / planTrains on your data by default?Canadian data residency
ChatGPT Free, Plus, ProYes, unless you turn off "Improve the model for everyone"No
ChatGPT Business (formerly Team)NoNot listed
ChatGPT Enterprise, Edu, Healthcare, APINoAvailable for data at rest (new workspaces)
Microsoft 365 CopilotNo. Prompts, responses and your Microsoft 365 data aren't used to train foundation modelsData residency commitments apply; in-country processing for Canada expected in 2027

Two details matter. Even with training turned off on a consumer plan, a thumbs-up or thumbs-down rating can send that conversation to OpenAI. And "data residency" usually covers where data is stored, not necessarily where the AI processes it. Check both.

Sending data outside Canada

The OPC's guidance on cross-border processing says transferring personal information to a service provider is a use, not a disclosure. It doesn't automatically require new consent. But your business stays accountable, so you must:

  • ensure comparable protection through your contract with the vendor, and
  • tell people their information may be processed outside Canada and could be accessed by foreign authorities.

In practice, update your privacy policy to mention AI and cloud processors, and use vendors with proper business terms.

The regulators' principles for generative AI

In December 2023, Canada's federal, provincial and territorial privacy commissioners jointly published principles for generative AI. They cover legal authority and consent, appropriate purposes, necessity and proportionality, openness, accountability, individual access, limiting collection, accuracy and safeguards. They also named "no-go zones," such as using AI to manipulate people into disclosing personal information.

For a small business, a sensible reading is to use AI for clear purposes, send it only the personal information it needs, check its output, and be open about it.

PHIA and AI in Manitoba clinics

Manitoba's Personal Health Information Act (PHIA) makes clinics and health professionals "trustees" of personal health information. For AI tools, that means:

  • Safeguards (s.18): reasonable administrative, technical and physical protections, such as access controls, MFA and retention limits.
  • Information manager agreements (s.25): a written agreement with any vendor that processes health information for you. The trustee stays responsible.

Shared Health Manitoba's guidelines for AI scribes are a useful benchmark even outside the public system:

  • Avoid public or consumer AI tools.
  • Choose vendors from Canada Health Infoway's pre-qualified list.
  • Record informed patient consent.
  • Make sure the vendor doesn't train on patient data.
  • Set short retention and use MFA.

The College of Physicians and Surgeons of Manitoba also advises informed consent before recording, a privacy impact assessment, and reviewing AI output before it enters the chart.

Manitoba began public consultations on updating privacy law for AI in March 2026, so expect these rules to evolve. We build AI receptionists and automation for clinics with these requirements in mind.

What's changing federally

Bill C-27, which included the proposed Artificial Intelligence and Data Act, died when Parliament was prorogued in January 2025. In June 2026, the federal government tabled Bill C-36, the Protecting Privacy and Consumer Data Act. It has no standalone AI law, but it proposes much higher penalties, disclosure of automated decisions with significant effects, and risk assessment before sending data outside Canada. It hadn't become law when we last checked.

A practical checklist for your business

  1. Ban client personal information in consumer AI accounts. Provide a business-tier tool instead.
  2. Write a one-page AI use policy. List what tools are approved, what data can go in, and who reviews output.
  3. Check each vendor's terms for training, retention, data residency and subprocessors.
  4. Update your privacy policy to mention AI and cross-border processing.
  5. Keep a person in the loop for anything that affects a customer, patient or employee.
  6. Clinics: sign information manager agreements and document patient consent.

We set this up as part of every AI consulting in Winnipeg engagement, and our AI training covers it for staff.

This guide is general information, not legal advice. For decisions about your specific obligations, consult a privacy lawyer or your privacy officer.

Sources

  1. OPC: Findings on OpenAI (May 6, 2026)
  2. OPC: Guidelines for processing personal data across borders
  3. OPC: Principles for responsible, trustworthy and privacy-protective generative AI
  4. OpenAI Help: Data controls in ChatGPT
  5. OpenAI Help: Data residency for ChatGPT
  6. Microsoft Learn: Copilot privacy and data
  7. Manitoba: The Personal Health Information Act
  8. Manitoba Health: Information manager agreements under PHIA
  9. Shared Health Manitoba: AI scribe usage guidelines
  10. CPSM: Responsible use of AI in the practice of medicine
  11. DLA Piper: Canada tables Bill C-36

FAQ

Frequently asked questions

Is ChatGPT PIPEDA compliant?

No tool is PIPEDA compliant on its own. PIPEDA applies to your business. Business-tier plans that don't train on your data, combined with a clear policy and updated privacy notice, let most businesses use ChatGPT in line with PIPEDA.

Does ChatGPT store data in Canada?

OpenAI offers Canadian data residency for data at rest on ChatGPT Enterprise, Edu, Healthcare and the API (new workspaces). Consumer plans and ChatGPT Business aren't listed for Canadian residency.

Can a Manitoba clinic use AI under PHIA?

Yes, with safeguards. Clinics need a written information manager agreement with the vendor, strong access controls, informed patient consent where recording is involved, and vendors that don't train on patient data.

Is Microsoft Copilot safer than ChatGPT for privacy?

Copilot doesn't train on your prompts or Microsoft 365 data, and it respects your existing file permissions. That makes it a good fit for Microsoft 365 businesses, but only if permissions are cleaned up first. ChatGPT's business plans offer similar no-training commitments.

Use AI without the privacy risk.

We'll review the AI tools your team already uses and set up a safe, documented alternative in a free audit call.

Book a free audit