Partner Spotlight

Generative AI and client data: What Ontario businesses need to know under PIPEDA

Left unchecked, generative AI tools can create a privacy problem nobody budgeted for

WALK INTO ALMOST any office in London and someone is asking an AI assistant for help. The bookkeeper wants a summary of a client’s file, the property manager needs a firmer letter to a tenant, the sales lead is cleaning up a contact list before a campaign. The time savings are real. So is the fact that client names, addresses and account numbers are now travelling to servers the business does not control.

The numbers explain why this has become an everyday question. Statistics Canada reported on June 11, 2026, that 19.2 per cent of Canadian businesses used AI to produce goods or deliver services in the previous 12 months, up from 6.1 per cent two years earlier. That figure measures AI built into how a business operates. The informal kind, an employee with a free account and a deadline, may not show up in it at all.

For small and mid-sized firms in Ontario, the practical question is how to use these tools without creating a privacy problem nobody budgeted for. Federal privacy law already covers it, the Office of the Privacy Commissioner of Canada has published guidance aimed squarely at generative AI, and a few practical habits go a long way.

AI adoption is climbing, and privacy is the main brake

The same Statistics Canada release offers a useful clue about what is holding firms back. Cybersecurity or privacy concerns were the barrier most often cited as limiting the use of AI, reported by 13.4 per cent of businesses, ahead of cost. The worry is already on the radar of owners and managers, then, even if it has not always been turned into a written rule that staff can follow.

That worry is well placed. Generative AI tools are at their most useful when they work on real material: the actual email from a client, the actual spreadsheet of overdue accounts, the actual notes from a meeting. That is exactly the material that contains personal information, and it is the material most likely to be pasted in a hurry by someone trying to clear a task before lunch.

The good news is that the fix does not require a large compliance budget. It starts with understanding which rules apply. Most Ontario businesses will find that the answer is a federal law they have been subject to for years, and that its existing principles translate quite naturally to a chat window once someone takes the time to spell them out for staff.

PIPEDA applies to what you paste into a chatbot

Ontario has no general private sector privacy law of its own. Unlike Alberta, British Columbia and Quebec, it relies on the federal Personal Information Protection and Electronic Documents Act for the personal information businesses handle in the course of commercial activity. The province does have its own health privacy legislation, but for most firms outside health care, PIPEDA sets the ground rules.

One clause in PIPEDA is particularly relevant to AI. Under its fair information principles, an organization remains responsible for personal information it transfers to a third party for processing, and must use contractual or other means to provide a comparable level of protection. Sending a client’s file to an outside AI service can fit that description, and the responsibility stays with the business.

The law also requires businesses to report breaches of security safeguards that pose a real risk of significant harm to the Privacy Commissioner, and to keep records of all breaches, whatever their severity. Whether a client file pasted into a personal AI account amounts to a breach depends on the facts. Either way, it is the kind of incident a business should be able to explain if a client ever asks.

What the Privacy Commissioner says about generative AI

In December 2023, the Office of the Privacy Commissioner of Canada published principles for responsible, trustworthy and privacy protective generative AI technologies. The document is clear on a basic point: generative AI tools do not occupy a space outside existing privacy law. The obligations a business already has follow it into the chat window.

The principles speak to organizations that use these tools, not only to the companies building them. They ask users to consider whether a generative AI system is necessary and proportionate for the task and, where possible and reasonable, to put anonymized or de-identified information into prompts rather than personal information.

They also name a simple mitigation in plain language: not entering personal information into a prompt unless it is necessary. For a small business, that is the most useful takeaway. Most of the work people ask an AI to do, from drafting and summarizing to rewording and organizing, does not depend on knowing who the client actually is.

What AI data masking looks like in practice

Masking means replacing the identifying details in a piece of text with neutral labels before it goes to the AI. A client named in a collections letter becomes CLIENT_1, the account number becomes REFERENCE_1, and the AI writes a perfectly good letter around those placeholders. The business keeps the link between label and person on its own side, and puts the real details back in at the end.

Done by hand, this is tedious enough that people soon stop bothering. That is the gap tools for AI data masking are designed to fill. Nonimo, for example, is a desktop app for Mac and Windows that detects personal information such as names and phone numbers and replaces it with placeholders on the computer itself, before the text reaches ChatGPT, Claude or Copilot.

Whatever tool a firm chooses, the principle is the one the Privacy Commissioner describes. The AI receives what it needs to do the task and nothing more. The client’s identity stays with the business that collected it, which is where the client expected it to be.

Ontario’s new hiring rule, and a policy for everything else

Ontario has already written AI into one area of employment law. Since January 1, 2026, employers with 25 or more employees that use artificial intelligence to screen, assess or select applicants for a publicly advertised job posting must say so in the posting. A short statement is enough, and the rule is a sign that regulators increasingly expect AI use inside a business to be disclosed.

For everything else, a one page internal policy will cover most of the risk. Name the AI tools staff may use and on which accounts, list the information that never goes in, such as health details, social insurance numbers and banking information, and make masking or removing client details the default step before any prompt. Then revisit it every few months, because the tools change quickly.

None of this needs to slow anyone down. The firms that get the most from generative AI over the next few years will be the ones that can use it on real work without having to apologize to a client afterwards. Building that habit now, while adoption is still climbing, is far cheaper than explaining a lapse later.

Recent Posts

Best of London: Neighbourhood Auto Plus

Meet the 2026 Best Auto Repair Garage and Best Oil Change service: Neighbourhood Auto Plus

3 hours ago

RIP remote?

The remote work dream isn’t dead, but it sure is slipping away

22 hours ago

Best of London: Fayez Spa

Meet the 2026 Best Day Spa: Fayez Spa

1 day ago

London Inc. Weekly

London Inc. Weekly: A summary of regional business news from the past week

2 days ago

Best of London: North London Dance Centre

Meet the 2026 Best Dance School: North London Dance Centre

2 days ago

How to choose a data analytics course that actually fits your goals

The right data analytics training paves the way to what you want to do afterwards

3 days ago