Skip to content
Is there an AI for this?

Jurisdiction

Canada

Source
Editorial review of primary sources — not yet re-anchored
Verified
Evidence not verified
Confidence
Low

Structured issue-spotting to support your own review — not legal advice. Verify against the cited primary sources and your counsel.

01Framework

Canada has no AI statute. The Artificial Intelligence and Data Act died with Bill C-27 when Parliament was prorogued in January 2025, and no successor bill has appeared. Regulation is layered instead: PIPEDA federally, three substantially-similar provincial regimes, and Quebec’s Law 25, which carries the country’s only binding private-sector automated-decision and cross-border rules. A mandatory Treasury Board directive governs federal government AI, OSFI pulls machine-learning models into model risk management from May 2027, Ontario requires AI screening to be disclosed in job postings, and the federal generative-AI code is voluntary.

Region
North America
ISO code
CA
Privacy framework
PIPEDA (S.C. 2000, c. 5) governs commercial handling of personal information federally, through ten fair-information principles and an accountability model for transfers — the organisation stays responsible for information handed to a processor, wherever that processor sits. The Privacy Commissioner lists Alberta, British Columbia and Quebec as having general private-sector laws declared substantially similar, and Ontario, New Brunswick, Newfoundland and Labrador and Nova Scotia as substantially similar for health information. Quebec’s regime, as amended by Law 25, is the strictest and has been fully in force since September 2024: it carries a duty to inform a person subject to a decision based exclusively on automated processing, a privacy impact assessment before communicating personal information outside Quebec, and data portability, all enforced by the Commission d’accès à l’information with monetary penalties.
AI-specific rules
No binding general-purpose AI statute. Bill C-27, containing the Consumer Privacy Protection Act and the Artificial Intelligence and Data Act, never cleared committee and died at prorogation in January 2025. The binding AI obligations that do exist are narrow and specific: the Treasury Board Directive on Automated Decision-Making for federal administrative decisions, Quebec’s automated-decision duty for the private sector, Ontario’s job-posting disclosure requirement, and — from May 2027 — OSFI Guideline E-23 pulling machine-learning models into model risk management for federally regulated financial institutions. Everything else is guidance: the Privacy Commissioner’s generative AI principles and business guidance, the federal Voluntary Code of Conduct for advanced generative AI, and the national AI strategy.
Last reviewed
20 Aug 2026
Status
published

Cross-border transfer

PIPEDA has no localisation rule and no adequacy list. It uses an accountability model: the transferring organisation remains responsible for personal information handed to a processor anywhere, which makes the contract and the due diligence the work rather than a permission. Quebec is where the binding constraint lives. Before communicating personal information outside Quebec, an organisation must carry out a privacy impact assessment weighing the sensitivity of the information, the purposes, the contractual measures and the legal framework of the destination, and the communication must be covered by a written agreement. The same applies where a person outside Quebec is entrusted with collecting, using, communicating or keeping the information — which is exactly what using a foreign-hosted model API does. Hard localisation appears only in some provincial public-sector rules, which were not verified in this pass.

Primary sources

  1. LegislationPersonal Information Protection and Electronic Documents Act
  2. Regulator pageOPC — provincial laws deemed substantially similar to PIPEDA
  3. Regulator pageCommission d’accès à l’information — principal changes made by Law 25
  4. Regulator guidanceTreasury Board — Directive on Automated Decision-Making
  5. LegislationLEGISinfo — Bill C-27 (44th Parliament, 1st session)
  6. Regulator guidanceOSFI — Guideline E-23 Model Risk Management (2027)
  7. Regulator guidanceOSFI — Guideline B-13 Technology and Cyber Risk Management
  8. Regulator guidanceOPC — Principles for responsible, trustworthy and privacy-protective generative AI technologies
  9. Regulator guidanceOPC — AI, privacy, and your business
  10. StandardISED — Voluntary Code of Conduct for advanced generative AI systems
  11. Regulator pageISED — Overview of Canada’s National Artificial Intelligence Strategy

02Regulations and guidance

10 instruments
InstrumentStatus
OPC AI business guidanceThe Privacy Commissioner’s business-facing AI guidance: be open about how information is used and what the privacy risks are, make AI tools explainable to users, limit sharing of personal or confidential information, build in privacy by design, and account for vulnerable groups including children.In force
AIDA (dead)Not law. The Artificial Intelligence and Data Act and the Consumer Privacy Protection Act sat in Bill C-27, which never cleared committee and died when the session ended in January 2025. No successor privacy or AI bill has appeared since. Canada has no AI statute.Proposed
OSFI B-13OSFI’s expectations for federally regulated financial institutions on technology governance, technology operations and resilience, and cyber security. It reaches AI infrastructure, third-party model hosting and incident response without ever naming AI.In force
OSFI E-23OSFI’s enterprise-wide model risk management expectations for federally regulated financial institutions, expressly covering machine learning models. Enterprise model inventory, lifecycle governance, risk rating and validation proportionate to model risk. It is published but does not take effect until 2027.Adopted, not yet applicable
AI for AllCanada’s national AI strategy, framed around making AI serve people, strengthening businesses and communities, and giving Canada more control over its future. It signals legislative intent — including modern privacy and online safety laws — and creates no obligations.In force
PIPEDACanada’s federal private-sector privacy statute. It governs collection, use and disclosure of personal information in commercial activity through ten fair-information principles, and uses an accountability model for transfers: the organisation stays responsible for information handed to a processor, wherever that processor is.In force
OPC GenAI PrinciplesJoint guidance from Canada’s privacy commissioners applying legal authority, appropriate purposes, necessity and proportionality, openness, accountability, access, limiting collection, accuracy and safeguards to generative AI. It is careful to say that many of its considerations are in fact legal requirements.In force
Quebec Law 25Quebec’s private-sector privacy statute, and the strictest regime in Canada. It carries binding duties on decisions based exclusively on automated processing, a privacy impact assessment before communicating personal information outside Quebec, and data portability, enforced by the Commission d’accès à l’information with monetary penalties.In force
Directive on ADMA mandatory Treasury Board instrument for federal automated decision systems. It requires a published Algorithmic Impact Assessment before production, plus notice, explanation, peer review, testing, training and human involvement scaled to the assessed impact level.In force
Voluntary CodeA non-binding federal code whose signatories commit to accountability, safety, fairness and equity, transparency, human oversight and monitoring, and validity and robustness for advanced generative AI systems. It distinguishes measures for all developers from additional ones for systems with general-purpose capabilities.In force

03Common enterprise issues

5
  • Automated decision-making

    Quebec requires notice at decision time, not on request

    An enterprise making decisions about Quebec residents based exclusively on automated processing must inform the person no later than when it tells them the decision, then on request disclose the personal information used, the reasons and the principal factors, and offer review by a person who can revisit it. This has been in force since September 2023.

  • Cross-border transfers

    No federal localisation rule masks the Quebec assessment duty

    Teams conclude Canada imposes no transfer restriction and miss the Quebec requirement for a documented privacy impact assessment and a written agreement before personal information leaves the province — including when it is sent to a foreign-hosted model API or a processor elsewhere in Canada.

  • High-risk AI

    AIDA is not law, and a lot of published advice assumes it is

    The Artificial Intelligence and Data Act died with Bill C-27 in January 2025. Any assessment, policy or vendor questionnaire written against AIDA’s risk classes is measuring against a bill that never passed. There is no Canadian AI statute to comply with.

  • Sector rules

    OSFI pulls machine-learning models into model risk management from 2027

    Federally regulated financial institutions will have to treat machine-learning systems as models: enterprise-wide inventory, lifecycle governance, risk rating and proportionate validation. It takes effect in May 2027, and an inventory that does not exist takes longer to build than the time remaining.

  • Bias and fairness

    Ontario requires AI screening to be disclosed in the job posting

    Since January 2026, an employer advertising a publicly advertised job posting that uses artificial intelligence to screen, assess or select applicants must say so in the posting. The definition of artificial intelligence is set by regulation, so the scope question is answered there rather than in the Act.


04Vendor restrictions

0

Restrictions we have written down and the page each one must be checked against. A restriction becomes a verified claim only once the sync job has fetched that page and found the phrase it declares; until then it is an editorial note with a link, and says so.

No vendor restriction has been recorded for this jurisdiction.


05Stacks with notes for this jurisdiction

0

No published stack carries a compliance note for this jurisdiction yet.


06Evidence

0 records · 0 of 10 instruments

Every instrument above that we have fetched and anchored carries a footnote. The rest link to their primary source but have not been fetched and hashed yet, and are marked ASSESSMENT rather than FACT.

No sources were recorded for this answer. Nothing on this page should be treated as verified.

Improve this page

Sign in to contribute

From the field

0 deployments · 0 questions

Nobody has reported deploying this here yet, and no question has been opened against this page. Both appear once a reviewer accepts them.