Canada July 27, 2026 9 min read

AI Policy for Canadian Employers: PIPEDA, Quebec Law 25, and Ontario’s AI Disclosure Rule

Canada has no artificial intelligence statute. That single fact is the one most AI policy advice gets wrong about this country, and getting it wrong sends Canadian employers looking for compliance obligations that do not exist while missing the three that do.

The rules that actually bind a Canadian company using AI at work are privacy rules and employment rules, not AI rules. They come from three places: the federal privacy statute and how it treats sending personal information to a vendor outside the country, Quebec’s Law 25, and — as of this January — a single line in Ontario’s Employment Standards Act. This guide covers what each one requires and what it means for the wording of your AI acceptable use policy.

Legal status verified 27 July 2026 against the primary sources linked throughout this page — Parliament’s LEGISinfo record, the consolidated federal and Quebec statutes, and Ontario’s e-Laws. Legislative status changes; check the linked sources before relying on any of it. This is not legal advice.

1. There is no federal AI Act — and no bill to become one

Canada came close. The Artificial Intelligence and Data Act (AIDA) was Part 3 of Bill C-27, the Digital Charter Implementation Act, 2022, introduced in the 44th Parliament in June 2022. It would have imposed risk assessment, mitigation, record-keeping and disclosure duties on “high-impact” AI systems.

It never became law. Parliament’s own record shows C-27 reached second reading and referral to committee on 24 April 2023 and stopped there. It never received Royal Assent, and it was not reinstated when the next session began. AIDA has no legal force in Canada and never has.

Nor has it come back. As of this writing there is no bill before the current Parliament with “artificial intelligence” in its title. What is moving is privacy reform: Bill C-36, an Act to enact the Protecting Privacy and Consumer Data Act and amend PIPEDA, received first reading on 15 June 2026 and sits at second reading. It is not law either, and no one should be building a compliance programme around a bill that has not passed. But it is the thing to watch, and it is worth noting what it signals: Ottawa is legislating AI-adjacent risk through privacy law, not through an AI act.

What this means for your policy: do not write “as required by the Artificial Intelligence and Data Act” into anything. Several template vendors still do. It is a factual error, and in a document you may one day hand to a regulator or a plaintiff’s counsel, it is the kind of error that undermines everything around it.

2. The real federal issue: your prompts leave the country

Almost every general-purpose AI assistant your staff will reach for is operated by a company outside Canada. Some vendors offer regional data residency on enterprise plans; on consumer tiers you generally do not get that choice, and you usually cannot tell from the product interface where a given prompt is processed. So the moment an employee pastes a customer list into a chatbot, personal information under your control has been handed to a foreign processor.

The federal Personal Information Protection and Electronic Documents Act (PIPEDA) handles this through accountability rather than through a border. It contains no prohibition on transferring personal information outside Canada. What it contains is Principle 4.1.3 in Schedule 1:

An organization is responsible for personal information in its possession or custody, including information that has been transferred to a third party for processing. The organization shall use contractual or other means to provide a comparable level of protection while the information is being processed by a third party.

Read that against how AI tools are actually adopted inside a company and the problem is obvious. The obligation is yours, it survives the handoff, and it requires contractual or equivalent protection. An employee signing up for a free tier with a work email has created exactly the situation Principle 4.1.3 describes, with none of the contractual protection it demands — and has done it without procurement, legal, or IT ever seeing the terms.

That is the concrete reason a Canadian AI policy needs a tool tier list rather than a general instruction to “be careful.” The distinction that matters legally is not which tool is best, it is which tools you have a contract with.

The Office of the Privacy Commissioner has also published principles for generative AI (last modified 6 May 2025). They are guidance, not law, but they set out what the regulator expects: demonstrable accountability, a defined internal governance structure, privacy impact assessments, and — a point worth lifting straight into a policy — that accountability for a decision rests with the organization, never with the automated system that helped make it.

3. Quebec: Law 25 is the strictest regime in the country

If you have a single employee or customer in Quebec, this section governs you, and it is materially stricter than the federal baseline. The relevant statute is the Act respecting the protection of personal information in the private sector, as overhauled by Law 25 (2021, c. 25). Four provisions bear directly on AI use.

Section 17 — a mandatory assessment before data leaves Quebec

This is the one that catches people. Before communicating personal information outside Quebec, a business must conduct a privacy impact assessment, taking into account the sensitivity of the information, the purposes it will be used for, the protection measures including contractual ones, and the legal framework of the destination jurisdiction. The information may be communicated only if that assessment establishes it would receive adequate protection, and the communication must be the subject of a written agreement.

Crucially, section 17 says the same applies where the business “entrusts a person or body outside Québec with the task of collecting, using, communicating or keeping such information on his behalf.” That is a precise description of an AI vendor. Under PIPEDA, sending personal information to a US-hosted AI tool triggers a contractual obligation. Under Law 25 it triggers a documented assessment that has to be done first, and that has to conclude the data will be adequately protected.

Section 3.3 — assess the project, not just the transfer

A business must conduct a privacy impact assessment for any project to acquire, develop or overhaul an information system involving the collection, use, communication, keeping or destruction of personal information, and must consult its privacy officer from the outset of the project. Rolling out an AI assistant across a department is such a project. The assessment must be proportionate to the sensitivity, purposes, quantity and distribution of the information involved.

Section 12.1 — automated decisions carry a duty to explain

Where a business uses personal information to render a decision based exclusively on automated processing, it must tell the person, no later than when it tells them the decision. On request it must also disclose the personal information used, the reasons and the principal factors and parameters that led to the decision, and the person’s right to have that information corrected. The person must be given the opportunity to submit observations to a member of staff who is in a position to review the decision.

Note the word exclusively. A genuine human review step takes a decision outside section 12.1 — which is a strong practical argument for writing a mandatory human-review requirement into your policy rather than treating it as best practice.

Sections 8 and 14 — consent and notice

Consent must be clear, free and informed, given for specific purposes, and requested separately for each purpose in clear and simple language; if requested in writing it must be presented separately from other information. Section 8 requires that, at the point of collection, people are informed of the possibility that their information could be communicated outside Quebec — which means a new AI tool that changes where data goes can require a change to your collection notices, not just to your internal policy.

4. Ontario: disclose AI in job postings, since 1 January 2026

Ontario added a job-postings part to the Employment Standards Act, 2000 that came into force on 1 January 2026. Section 8.4(1) reads:

Every employer who advertises a publicly advertised job posting and who uses artificial intelligence to screen, assess or select applicants for the position shall include in the posting a statement disclosing the use of the artificial intelligence.

Three details decide whether it applies to you, and all three live in O. Reg. 476/24:

The compliance step itself is small: one sentence in the posting. The failure mode is organisational — the people who write job postings are usually not the people who chose the ATS, and nobody has told them the tool scores applicants.

5. What to change in your AI policy

Four edits cover the Canadian position without turning the document into a legal treatise.

  1. Add a jurisdiction line to the data-handling section. State that personal information about Canadian customers or staff may only be entered into tools on the approved list, because approval is what establishes the contractual protection Principle 4.1.3 requires. If you have any Quebec footprint, say that data about Quebec residents may not be entered into a new tool until the section 17 assessment is done.
  2. Name who does the assessment and when. “Before a new AI tool is approved” is the trigger, and it needs an owner. In Quebec that owner has to be, or has to consult, the person in charge of the protection of personal information.
  3. Make human review mandatory, not encouraged, for any decision about a person — hiring, promotion, discipline, credit, benefits. This is good governance everywhere in Canada and it is the difference between falling inside and outside Quebec’s section 12.1.
  4. Give HR the job-posting disclosure line. If you post jobs in Ontario and have 25 or more employees, someone owns a standing check on whether the hiring stack screens with AI, and a standard sentence to paste when it does.

None of this requires a Canada-specific policy document. It requires four paragraphs in the policy you already have, plus knowing which of your tools are on a contract.

If you want a policy built around this structure, you can generate a tailored policy kit that maps your data categories to specific tool restrictions and role-based rules. To see what your current tools actually commit to on data handling, our AI tool risk directory documents each vendor’s published terms.

About Shadow AI Policy: We build AI acceptable use policy tools for HR and operations teams at 50–500 person companies. We publish guides on shadow AI, acceptable use policies, and AI governance, updated as regulations and AI tools change.

Common questions

Does Canada have an AI law we need to comply with?

No. Canada has no federal artificial intelligence statute in force. The Artificial Intelligence and Data Act (AIDA) was proposed as part of Bill C-27 in 2022, reached committee stage in April 2023, and died without receiving Royal Assent; it was not reinstated in the following session. There is currently no bill before Parliament with “artificial intelligence” in its title. What binds Canadian employers using AI is existing law: federal and provincial privacy statutes, employment standards legislation, human rights law, and sector regulation. Any template or advisor telling you to comply with AIDA is working from a bill that never passed.

Can we let Canadian employees use ChatGPT if the data is processed on US servers?

PIPEDA does not prohibit processing personal information outside Canada, so there is no automatic bar. What it does require, under Principle 4.1.3 of Schedule 1, is that you remain responsible for that information and use contractual or other means to provide a comparable level of protection while a third party processes it. In practice that means the tool needs to be on a business agreement whose terms you have read, not a personal free-tier account. If any of the personal information relates to people in Quebec, the additional requirement in section 17 of Quebec’s private-sector privacy act applies: a privacy impact assessment before the data goes, concluding that protection is adequate, plus a written agreement.

Our applicant tracking system ranks resumes automatically. Do we have to disclose that in Ontario?

If you have 25 or more employees on the day you post, the posting is publicly advertised, and the ranking feature is being used to screen, assess or select applicants, then yes — section 8.4 of the Employment Standards Act requires a statement in the posting disclosing the use of artificial intelligence. The regulation defines artificial intelligence broadly enough to capture a machine-based system that infers from input to generate predictions or recommendations, which is what resume ranking is. The practical first step is to ask your ATS vendor, in writing, which of their scoring or matching features are active on your account.

Do we need a separate AI policy for our Quebec employees?

Usually not a separate document, but you do need Quebec-specific provisions inside the one you have. The three that matter most: no personal information about Quebec residents goes into a tool hosted outside Quebec until the section 17 privacy impact assessment is complete and a written agreement is in place; any project to adopt or overhaul a system handling personal information triggers an assessment under section 3.3, with the privacy officer involved from the outset; and any decision about a person made exclusively by automated processing carries notification, explanation and human-review-on-request duties under section 12.1. Requiring genuine human review of decisions is the cleanest way to stay outside that last one.

Generate your AI policy in 10 minutes

Tailored to your industry and the AI tools your team uses. Free preview, $79 one-time or $149/mo with monthly updates.

Generate my policy kit →