CanucktAI
Back to Blog
Compliance August 28, 2026 8 min read

Writing a Privacy Policy for an AI Feature in Canada

The day you ship an AI feature, your privacy policy goes stale. Here's what Canadian law expects you to tell people — purposes, data, models, decisions, retention.

By Vivek Chakravarthy

Writing a Privacy Policy for an AI Feature in Canada

When you add an AI feature, Canadian law expects your privacy policy to disclose the specific purposes, the personal information the AI uses, any third-party models the data flows to, whether decisions are automated, and how long inputs are kept. PIPEDA's openness and identifying-purposes principles and Quebec's Law 25 all want the policy to be an accurate, current picture of what you actually do — and an AI feature almost always changes that picture.

You shipped an AI feature last quarter — a chat assistant, a smart summarizer, an automated recommendation. Here's the quiet risk riding along with it: your privacy policy almost certainly still describes the product you had before the AI. Under Canadian law that gap matters, because the whole job of a privacy policy is to be an accurate, current account of what you actually do with people's personal information.

PIPEDA's openness principle asks organizations to make their information-handling practices easy to find and easy to understand. Its identifying-purposes principle asks you to spell out why you collect personal information at or before the moment you collect it. Quebec's Law 25 goes further on transparency, and it adds specific expectations around automated decisions. Introduce AI and you change what data you use and why — so the policy has to keep pace.

What must an AI privacy policy disclose?

At a minimum, an AI feature should push you to update five things:

DisclosureWhat to say
PurposesSpecifically what the AI feature is for
Data usedThe inputs — text, files, account history, inferences
Third-party modelsThe vendor or model provider the data flows to, often cross-border
Automated decisionsWhether the AI decides about people, and the human-review path
RetentionHow long inputs are kept and what happens on account deletion

Here's each in turn.

Purposes: say what the AI is actually for

Vague purposes were survivable in a simpler product. With AI they're a genuine weakness. If your assistant uses customer messages to draft replies, if your model reads uploaded documents, if your feature profiles user behaviour to recommend things — say so, specifically. "We use your information to provide and improve our services" doesn't tell a person that their support chat is being read by an AI model. Name the purpose in words a customer would actually recognize.

The data used: be concrete about inputs

Tell people what personal information the AI feature actually takes in. Is it the text they type into the assistant? The files they upload? Their account history, their behaviour on the site, their past purchases? People increasingly get that AI features run on data, and the trust cost of being coy about it runs higher than the cost of being plain. Where it's relevant, separate what the user hands over deliberately from what the system infers about them.

Third-party models: disclose the vendor in the loop

This is the disclosure most policies miss. If your AI feature runs on a third-party model — a foundation-model provider, a hosted API, an analytics engine — then personal information is flowing to that third party, and often across a border. PIPEDA's approach to transfers for processing expects a measure of transparency about the fact that you use service providers and that information may be processed outside Canada. Tell people, plainly, that the feature relies on third-party providers, and ideally that you've got contractual safeguards in place. And if your vendor could use inputs to train its own models — that's exactly the sort of thing a person would want to know before they type something sensitive.

Automated decisions: Quebec's specific expectation

If your AI makes or substantially shapes a decision about a person based solely on automated processing — approving or declining something, ranking, scoring, screening — Law 25 sets a specific bar. At or before the decision, you have to tell the person it rests exclusively on automated processing. On request, they're entitled to learn the personal information used, the reasons and principal factors behind the decision, and their right to have it corrected — and to put observations to a member of your staff who can review it. Building a clear path for these privacy rights requests is part of shipping the feature responsibly.

Even outside Quebec, this is a strong signal of where Canadian expectations are heading. If your feature makes consequential automated decisions about people, build the disclosure and the human-review path now, and describe them in your policy. Trivial personalization — suggesting a product, ordering a feed — doesn't carry the same weight; real decisions about people do.

Retention: how long, and what happens to inputs

Say how long you keep the personal information the AI feature uses, and be straight about what happens to the inputs. Are prompts and uploaded content stored, and for how long? Do they go when the user deletes their account? PIPEDA's retention principle expects you to hold personal information only as long as the identified purposes need it. AI features have a habit of quietly hanging onto inputs "for quality" — if yours does, disclose it; if it doesn't need to, turn it off.

A few practical drafting tips

Write it for a person, not a lawyer. Both PIPEDA and Law 25 favour plain, understandable language. A policy nobody can read satisfies nobody's rights.

Keep the AI disclosure easy to find. You can add an AI section to your existing policy or drop a focused notice at the point of use. What matters is that a reasonable person can find it before they decide to use the feature.

Update the effective date, and flag material changes. A policy that changes in silence is a policy people can't rely on. When you add an AI feature that meaningfully shifts your data practices, refresh the date and, where the change is significant, call it out.

Match the policy to reality. The most common failure — and the most damaging — is a policy that describes practices the business doesn't actually follow, or leaves out ones it does. Regulators and customers alike treat the gap between what you say and what you do as the real problem.

An AI feature is a real upgrade to your product. Handled carelessly, it's also a quiet expansion of your privacy footprint that your public commitments no longer describe. Closing that gap isn't just compliance housekeeping — it's how you hold onto the trust the feature was supposed to earn you in the first place.

*This article is general information, not legal advice; consult a qualified professional about your specific situation.*

At Canuckt we build privacy-first AI for Canadian businesses, and Valdra helps you keep your privacy policy and governing documents lined up with a working privacy rights process — in English and French, with your data in Canada — so what you publish matches what your product actually does.

Frequently asked questions

Do you need to update your privacy policy when you add an AI feature?+

Almost always. PIPEDA's openness principle wants your policy to be an accurate, current account of what you do. An AI feature usually changes what data you use, why, and who processes it — so the policy that described your pre-AI product is now out of date and needs a refresh.

What does Canadian law expect you to disclose about an AI feature?+

The specific purposes of the feature, the personal information it takes as input, any third-party models or providers the data flows to (often across a border), whether it makes automated decisions about people, and how long inputs are kept. Say it in plain language a customer can follow.

Does Law 25 require disclosure of automated decisions?+

Yes. If a decision about a person rests exclusively on automated processing, Law 25 requires you to tell them at or before the decision. On request, they can learn what personal information was used, the reasons and main factors, and can ask a staff member to review it.

Do you have to disclose that a third-party AI model processes your data?+

You should. If your feature leans on a third-party model or API, personal information flows to that provider, often outside Canada. PIPEDA's transparency approach expects you to tell people you use service providers and that data may be processed abroad — ideally noting the contractual safeguards you've put in place.

How long can you keep AI feature inputs like prompts and uploads?+

Only as long as the identified purposes need, under PIPEDA's retention principle. Disclose whether prompts and uploaded content are stored and for how long, and delete them when a user deletes their account. If the feature doesn't need to keep inputs, switch retention off.

AI privacy policyprivacy policy CanadaPIPEDA transparencyautomated decision-makingLaw 25 disclosureAI featurepersonal information

AI governance and privacy compliance, simplified.

Valdra helps Canadian companies govern AI and meet PIPEDA and Law 25 — hosted in Canada.

Explore Valdra

Our own compliance

We run our own compliance programme inside Valdra — the product we sell. Our SOC 2, ISO 27001 and ISO 42001 programmes are actively in progress; we do not claim certifications we do not yet hold.

Valdra compliance badge — click to verify
  • PIPEDA
  • Law 25 (Quebec)
  • CASL
  • Data hosted in Canada 🇨🇦
  • AI governance
View our Trust Centre

Self-declared, not audited by a third party. Click the badge to verify it is genuine and see what it covers.

Privacy Policy for AI Features in Canada | Canuckt AI