Skip to main content
Security & Compliance9 min read

Privacy Impact Assessment for an AI Project

September 13, 2026By Ajan Kanagalingam

Bill C-36, the Protecting Privacy and Consumer Data Act introduced on June 15, 2026, is reported to include mandatory privacy impact assessments for each new AI use case. It is not law, and the final text may look different. The reason to learn this now is more immediate than legislation: clients have started asking, and a PIA written under deadline pressure is a worse document than one written on an ordinary Tuesday.

Where the obligation actually stands

Federal institutions in Canada have long completed PIAs for programs handling personal information. For a private business, PIPEDA requires you to protect personal information and be accountable for it without prescribing a PIA as the mechanism, so today the practice is generally governance rather than statute.

That may change. Reporting on Bill C-36 describes mandatory PIAs for new AI use cases alongside substantially higher penalties than PIPEDA carries. Since the bill has not passed and the details can move, treat this post as preparation rather than compliance, check the position in your province, and take legal advice on anything consequential. We covered the bill itself in what Bill C-36 means for AI in your business.

The practical trigger arrives sooner than the legal one. Client security questionnaires now routinely ask how you assess privacy risk in AI systems, and insurers have started adding AI sections to renewal forms.

The seven questions

One AI use case per assessment. Not your business as a whole, not AI in general. The customer support assistant, or the resume screening tool, or the meeting notetaker.

1. What personal information goes in? Be specific and be honest about the incidental stuff. A meeting notetaker captures whatever anyone says, which includes health details, complaints about colleagues, and client information nobody planned to record.

2. Why does it need that? If a field is not needed for the purpose, the cheapest privacy control available is not collecting it.

3. Where does it go and who can see it? The vendor, their sub-processors, the region it is processed in, and which of your staff can retrieve it. Vendor documentation answers most of this and few people read it.

4. How long is it kept, on both sides? Your retention policy and the vendor's are different documents and frequently disagree.

5. What could go wrong? Three or four realistic scenarios. Wrong recipient, breach at the vendor, staff member accessing something they should not, output used in a decision it was not fit for.

6. What have you done about each one? The controls, stated plainly. Access limits, retention settings, review steps, training.

7. What residual risk are you accepting, and who decided? A named person. This is the section auditors read first and the one most templates leave blank.

Five AI-specific questions templates leave out

QuestionWhy it matters
Do our inputs train the model?Differs by tier of the same product, and often defaults to yes on free plans
How long does the vendor keep prompts?Frequently longer than your own retention policy allows
Does it decide anything about a person?Hiring, credit, pricing and access raise obligations beyond privacy
Could we explain one output?If someone asks why they were declined, you need an answer
What if the vendor is acquired?Residency and training commitments can change on a change of control

The first two are answerable in ten minutes from the vendor's terms for the specific tier you are on, which is the check most businesses skip and the one covered in free AI tools and what they cost your business.

The third changes the character of the assessment. A tool that drafts an email is a privacy question. A tool that ranks job applicants is a privacy question plus a fairness question plus an explainability question, and the monitoring version of the same problem is in employee monitoring with AI.

What makes a PIA useless

Writing it about AI in general. One use case per document. A blanket assessment covering everything says nothing specific enough to act on.

Describing the process you wish you had. If people paste client details into a general assistant, the assessment says so. A document describing the approved workflow rather than the real one fails the moment anyone checks.

Leaving section seven blank. Every project carries residual risk. Naming it and naming who accepted it is the point of the exercise, and an assessment that claims all risk is mitigated is not credible.

Filing it and forgetting. Vendors change terms, tiers change defaults, and use cases expand quietly. Put a review date on it, six or twelve months out.

Two hours, this week

Pick the AI use case in your business that touches the most personal information. Sit with the person who actually operates it, not the person who bought it, and answer the seven questions in plain sentences. Then read the vendor's terms for your specific tier and answer the five AI questions.

You will finish with a document a client can read and, more usefully, with two or three things you did not know that morning. That output is the reason to do this before anybody requires it. The wider structure it fits into is in an AI governance framework for a small business, and the PIPEDA groundwork in PIPEDA-compliant AI.

Frequently Asked Questions

What is a privacy impact assessment?

A written record of what personal information a project collects, why, where it goes, what could go wrong, and what you did about it. Federal institutions in Canada have long been required to complete them for programs involving personal information. For a private business it is usually a governance practice rather than a statutory obligation, though that is the part currently under discussion in Parliament.

Is a PIA legally required for Canadian businesses?

Generally not today for a private-sector business under PIPEDA, which requires you to protect personal information and be accountable for it without prescribing a PIA as the mechanism. Bill C-36, the Protecting Privacy and Consumer Data Act introduced on June 15, 2026, is reported to include mandatory privacy impact assessments for new AI use cases, along with substantially higher penalties. It is not law, its final text may change, and this is not legal advice. Requirements also differ in Quebec and for federally regulated sectors.

When should a small business do a PIA anyway?

When you start putting personal information into a system you do not control, when a tool makes or materially influences a decision about a person, or when a client, insurer or tender asks how you assess AI privacy risk. The third trigger is the most common in practice. Businesses that write the assessment when the questionnaire arrives write it badly and under time pressure, and the exercise takes about two hours when nobody is waiting.

What do generic PIA templates miss for AI?

Five things. Whether your inputs train the vendor’s model. How long the vendor retains prompts and outputs, which is often different from your own retention policy. Whether the system makes or influences a decision about a person, which raises questions beyond privacy. Whether you could explain a specific output to the person it affected. And what happens to the data if the vendor is acquired or shuts the product down.

Who should write the PIA?

The person who understands the workflow, with the answers checked by whoever owns the vendor relationship. It does not need a lawyer to draft, and it does benefit from a lawyer reading it before it goes to a client or a regulator. A PIA written entirely by an external consultant who has never watched the process tends to describe an idealised version of it, which is exactly the version that fails when someone tests a real case.

Write it before somebody asks for it

We run privacy impact assessments on AI use cases with the people who operate them, in plain language, and flag the vendor terms worth renegotiating.

Related Articles

Security & Compliance

Canada’s New Privacy Law (Bill C-36) and Your AI

July 13, 2026Read more →
Security & Compliance

Cyber Insurance: What It Covers and What It Wants

September 14, 2026Read more →
Security & Compliance

AI Agents Mass-Exploited a Patch Nobody Applied

September 14, 2026Read more →
AK
Ajan Kanagalingam
Founder & ChatGPT Consultant, ChatGPT.ca

Ajan leads the ChatGPT.ca team: 200+ custom GPT builds and automation projects for 50+ businesses across 20+ industries. Based in Markham, Ontario. PIPEDA-compliant solutions.

Stay ahead of AI in Canada

Weekly case studies, new tools, and ROI playbooks for Canadian SMEs. One email, zero spam.