CanucktAI
Back to Blog
PIPEDA August 4, 2026 9 min read

PIPEDA and Automated Decision-Making: What to Disclose When AI Influences Decisions About People

The moment an algorithm helps decide who gets a loan, a job interview, or a price, PIPEDA's transparency principles kick in. Here's what to explain to people and what to put in your privacy notice.

By Vivek Chakravarthy

PIPEDA and Automated Decision-Making: What to Disclose When AI Influences Decisions About People

PIPEDA doesn't yet use the phrase "automated decision-making," but its transparency, consent, and access principles apply in full the moment AI starts influencing decisions about people. In practice, that means telling individuals automation is involved, explaining in general terms what data feeds it and what factors it weighs, being honest about the consequences, and giving people a real path to human review and to correcting the data you used.

Why Automated Decisions Are a Privacy Problem

When an AI system helps decide who gets approved for credit, which resumes reach a human recruiter, what price a customer sees, or whose insurance claim gets flagged, it's making decisions about people using their personal information. That one fact pulls the whole exercise inside PIPEDA, Canada's federal private-sector privacy law — even though PIPEDA was written long before this kind of automation was common.

There's no section of PIPEDA that uses the phrase "automated decision-making." What it has instead is a set of principles that apply to any use of personal information, and those principles are more demanding for opaque, high-impact automation than most businesses realize. The Office of the Privacy Commissioner of Canada (OPC) has been clear in its guidance: transparency and meaningful consent extend to algorithmic uses of personal data. You don't get a pass because a model made the call instead of a person.

The PIPEDA Principles That Come Into Play

Four of PIPEDA's fair information principles do most of the work here.

Openness. Organizations have to be open about how they handle personal information. If an algorithm materially shapes a decision about someone, describing your data handling honestly means naming that automation — not tucking it behind vague talk about "our systems."

Identifying purposes. You have to identify why you're collecting personal information at or before the time you collect it. "To assess your application" is thinner than it should be when part of that assessment is a model quietly scoring the applicant. People are entitled to understand what their data actually feeds.

Consent and meaningful consent. Consent only counts if it's meaningful — the person understood what they were agreeing to. The OPC's guidance on meaningful consent asks organizations to spell out, among other things, what information is collected, who it's shared with, and the reasonably foreseeable consequences of the collection. An automated decision that can deny someone a service? That's exactly the kind of consequence people are entitled to understand.

Individual access and accuracy. People have the right to see the personal information you hold about them and to challenge its accuracy — the kind of privacy rights request you'll want a repeatable process to handle. When a decision rests on data — a credit history, a stated income, a scraped attribute — the person affected can ask what data was used and push to fix it if it's wrong.

What "Transparency" Realistically Means

Transparency about automated decisions doesn't mean publishing your source code or exposing a trade-secret model. Regulators aren't asking you to hand competitors your algorithm. They're asking for a meaningful explanation: enough for a reasonable person to grasp that automation is involved, what broad factors drive the outcome, and how to seek a human review or a correction.

Here's a useful test. Would an ordinary customer, reading your notice, come away surprised to learn a machine was involved? If yes, the notice isn't transparent enough. You're aiming for no unpleasant surprises.

It's also worth separating decisions that are fully automated from those where a human genuinely reviews the output. A model that recommends and a person who decides is a lighter-touch situation than a model that approves or denies with nobody in the loop. Both engage PIPEDA's principles, but fully automated, high-impact decisions deserve the most explanation and the clearest route to human recourse.

What to Put in Your Privacy Notice

Here's a practical set of disclosures for a Canadian business whose products use AI to influence decisions about people. You won't need every line for every use case — treat it as a menu to pick from.

  • That automation is used. State plainly that automated processing or AI helps make or support certain decisions, and name which kinds of decisions (for example, eligibility, pricing, fraud screening, or content ranking).
  • What personal information feeds it. Describe the categories of data used as inputs — not every field, but honest categories a person would recognize.
  • The purpose and the logic in general terms. Explain what the system is trying to do and the broad factors it weighs, without exposing proprietary detail.
  • The consequences for the individual. Be candid about what an automated outcome can mean — approval, denial, a higher or lower price, additional review.
  • Whether a human is involved. Say whether decisions are fully automated or reviewed by a person, because that shapes the individual's expectations and their rights.
  • How to seek review, correction, or an explanation. Give a real channel — a named contact or a request process — where someone can question the outcome, ask what data was used, and request correction of inaccurate information.

Write all of this in plain language, and layer it: a short, readable summary up front, with a link to fuller detail for the people who want it.

Where the Law Is Heading

Knowing the direction of travel matters, because it explains why getting ahead of this pays off. Bill C-27's proposed Consumer Privacy Protection Act, if it becomes law, would add an explicit right for individuals to request an explanation of predictions, recommendations, or decisions made about them by an automated decision system. Quebec's Law 25 already requires organizations to inform individuals when a decision is based exclusively on automated processing, and to let them submit observations and request a review. And any company operating in Europe faces the EU AI Act (Regulation (EU) 2024/1689), which layers transparency and human-oversight duties onto higher-risk systems.

The common thread? The same expectation PIPEDA's principles already imply today: people affected by automated decisions are entitled to know it's happening and to have a way to challenge it. Build clear disclosure and a human-review channel now, and you're building toward every one of these regimes at once. (For the Quebec-specific consent angle, see our Law 25 consent checklist for AI products.)

A Sensible Starting Point

Inventory the places where your products let an algorithm shape an outcome for a person — a PIPEDA self-assessment is a fast way to find them. For each one, ask three questions: is the person told, is there a human they can reach, and can they find out and correct the data you used? Any "no" is your first fix — and it's usually a wording and process change, not a rebuild.

This article is general information, not legal advice; how PIPEDA and related laws apply to your specific automated decisions depends on your circumstances, and you should consult a qualified professional before acting.

Mapping every automated decision in your product against transparency and access obligations is tedious to do by hand. It's the kind of work Canuckt built Valdra to streamline — surfacing where AI touches people and turning it into clear, prioritized disclosure tasks, with your data kept in Canada.

Frequently asked questions

Does PIPEDA regulate automated decision-making?+

PIPEDA does not use the phrase "automated decision-making," but its principles of openness, meaningful consent, identifying purposes, and individual access apply to any use of personal information — algorithmic decisions included. The Privacy Commissioner's guidance is clear that transparency and consent extend to AI-driven uses, so letting a model make the call does not erase your obligations.

What should a privacy notice say about AI decisions?+

Say plainly that automated processing or AI helps make certain decisions, and name which kinds. Describe the categories of personal information used, the purpose and broad logic, the consequences for the individual, whether a human is involved, and how to seek a review, an explanation, or a correction of the data used. Keep it plain and layered.

Do I have to explain how my AI algorithm works?+

No. Transparency does not require publishing source code or exposing a trade-secret model. It requires a meaningful explanation: enough for a reasonable person to understand that automation is involved, the broad factors that drive the outcome, and how to get human review or a correction. The test is simple — would an ordinary customer be surprised to learn a machine was involved?

Is a human review required for automated decisions in Canada?+

PIPEDA's principles push hard toward offering a route to human recourse, especially for fully automated, high-impact decisions. Quebec's Law 25 explicitly lets individuals submit observations and request a review of decisions based solely on automated processing, and Bill C-27 would add an explicit right to an explanation. Build a human-review channel now and you're ready for all three.

What is the difference between a fully automated and a human-reviewed decision?+

A fully automated decision is made by a model with nobody in the loop; a human-reviewed decision has a person genuinely assess the model's output before it takes effect. Both engage PIPEDA's principles, but fully automated, high-impact decisions deserve the most explanation and the clearest path to human recourse.

PIPEDAautomated decision-makingAI transparencyprivacy noticeCanadian privacy lawalgorithmic accountabilityAI compliance

AI governance and privacy compliance, simplified.

Valdra helps Canadian companies govern AI and meet PIPEDA and Law 25 — hosted in Canada.

Explore Valdra

Our own compliance

We run our own compliance programme inside Valdra — the product we sell. Our SOC 2, ISO 27001 and ISO 42001 programmes are actively in progress; we do not claim certifications we do not yet hold.

Valdra compliance badge — click to verify
  • PIPEDA
  • Law 25 (Quebec)
  • CASL
  • Data hosted in Canada 🇨🇦
  • AI governance
View our Trust Centre

Self-declared, not audited by a third party. Click the badge to verify it is genuine and see what it covers.

PIPEDA & Automated Decision-Making | Canuckt AI