Policy

Canada Rules ChatGPT Violated Privacy Law — A Landmark for AI Regulation

A joint investigation by Canada's federal and provincial privacy commissioners found OpenAI collected and used personal data without meaningful consent, setting a precedent that could reshape AI data practices globally.

By Michael C ·

Canada Rules ChatGPT Violated Privacy Law — A Landmark for AI Regulation

Canada's Office of the Privacy Commissioner (OPC), together with the privacy commissioners of Quebec, British Columbia, and Alberta, has concluded a joint investigation into OpenAI's ChatGPT and found that the company violated Canadian privacy law. The investigation, which began in 2023 following a complaint, found that OpenAI collected, used, and disclosed personal information without obtaining meaningful consent — a violation of Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and equivalent provincial legislation.

The ruling is the most significant privacy enforcement action against a major AI company in North America to date. It does not impose a financial penalty — Canadian privacy law's enforcement mechanisms are primarily declaratory and remedial rather than punitive — but it establishes a legal precedent that regulators in other jurisdictions are watching closely. OpenAI has disputed the findings and indicated it will not implement the commissioners' recommended changes voluntarily, setting up a potential court referral.

What the Investigation Found

The commissioners found three core violations. First, OpenAI failed to obtain valid consent for the collection of personal information used to train ChatGPT. The company's argument that publicly available data does not require consent was rejected — Canadian law requires consent for collection regardless of whether data is technically accessible. Second, OpenAI's privacy policy was found to be insufficiently clear about how personal information is used in model training. Third, the company failed to provide adequate mechanisms for individuals to access or correct their personal information held within training datasets.

The Office of the Privacy Commissioner of Canada in Ottawa — the lead regulator in the joint investigation into OpenAI's ChatGPT.
The Office of the Privacy Commissioner of Canada in Ottawa — the lead regulator in the joint investigation into OpenAI's ChatGPT.

The ruling arrives at a moment when Canadian privacy law is itself under reform. Bill C-22, the proposed Consumer Privacy Protection Act, would significantly strengthen enforcement powers — including the ability to impose fines of up to 5% of global revenue for serious violations. If C-22 passes in its current form and is applied retroactively to the ChatGPT violations, OpenAI could face a fine in the hundreds of millions of dollars. The bill is currently before the Senate.

Global Implications

Canada's ruling is significant beyond its borders because it directly addresses the question that regulators everywhere are grappling with: does training a large language model on publicly scraped data require consent? The European Data Protection Board has been wrestling with the same question under GDPR. Italy's Garante temporarily blocked ChatGPT in 2023 over similar concerns. The Canadian commissioners' clear answer — yes, consent is required — gives other regulators a legal framework to cite.

The Canadian Parliament buildings in Ottawa — where Bill C-22, which would dramatically strengthen AI privacy enforcement, is currently before the Senate.
The Canadian Parliament buildings in Ottawa — where Bill C-22, which would dramatically strengthen AI privacy enforcement, is currently before the Senate.

For AI companies, the ruling signals that the 'publicly available data' defence is losing ground in common law jurisdictions. The practical implication is that any AI company training on web-scraped data faces potential liability in Canada, and potentially in other jurisdictions that follow Canada's lead. The ruling does not require OpenAI to delete its models or stop operating in Canada — but it does require the company to implement a consent mechanism for data collection, which, if applied globally, would fundamentally change how frontier AI models are trained.

Topics: OpenAI, Privacy, Canada, AI Regulation, PIPEDA