Reviewed by Jonathan West · Updated Aug 19, 2026

PIPEDA and PHIPA: Using AI With Health Data in Canada

How Canadian organizations meet PIPEDA and PHIPA when they adopt AI tools that touch personal or health data.

Reviewed by Jonathan West · Updated Aug 19, 2026

You can use AI with personal or health data in Canada, but you stay accountable for it. PIPEDA governs private-sector personal data federally. Health privacy is mostly provincial, so Ontario organizations also follow PHIPA.

PIPEDA lets you transfer data to a processor, including a US cloud AI vendor, but your organization remains responsible for protecting it. You need a written contract, comparable safeguards, and meaningful consent.

This guide explains the rules in plain terms. It covers PIPEDA's principles, PHIPA in Ontario, cross-border processing, the privacy regulators' generative AI principles, and a checklist you can act on.


What PIPEDA Requires

PIPEDA is Canada's federal private-sector privacy law, and it is built on 10 fair information principles. It applies to businesses that collect, use, or disclose personal data in commercial activity.

The 10 principles are accountability, identifying purposes, consent, limiting collection, limiting use, disclosure and retention, accuracy, safeguards, openness, individual access, and challenging compliance.

Accountability sits first for a reason. Your organization is responsible for personal data under its control, even when a third party processes it for you.

You must name someone accountable for compliance and put a privacy management program behind it. AI tools do not remove that duty. They add to it.

  • Consent: collection, use, and disclosure need the individual's knowledge and consent, with limited exceptions.
  • Safeguards: protect data with security matched to how sensitive it is; health data is highly sensitive.
  • Limiting use: only use data for the purposes you identified, not to secretly train a model.
  • Openness: be clear about what you collect and how AI uses it.

Rolling out AI in your Ontario clinic or Canadian nonprofit without breaching PIPEDA or PHIPA? We map the data, vet the vendor contract, and set your consent and cross-border safeguards.

Book a Consultation


PHIPA and Why Health Privacy Is Provincial

In Canada, health privacy is largely provincial, so the rules depend on where you operate. In Ontario, the Personal Health Information Protection Act (PHIPA) governs personal health information.

PHIPA applies to Health Information Custodians, called HICs. A HIC is a person or organization with custody or control of personal health information, such as a doctor, clinic, hospital, pharmacy, or lab.

Other provinces have their own health or private-sector privacy laws. Alberta and British Columbia each have a PIPA, and Quebec has its Law 25.

So a nonprofit or clinic must check which law applies to it. An Ontario HIC follows PHIPA; a business in another province may fall under PIPEDA or a substantially similar provincial law.

  • HIC examples: physicians, nurse practitioners, clinics, hospitals, pharmacies, labs.
  • PHIPA is overseen by the Information and Privacy Commissioner of Ontario (the IPC).
  • Alberta PIPA and BC PIPA cover private-sector data in those provinces.
  • Quebec's Law 25 is Canada's strictest private-sector regime.

How AI Vendors Fit In

Under PHIPA, an AI vendor usually acts as an agent or an electronic service provider, and the custodian stays responsible. An agent acts for the custodian's purposes, not its own.

An electronic service provider supplies services that let a custodian collect, use, disclose, retain, or dispose of health data. A cloud AI note-taker often falls in this category.

You need a written contract that limits the vendor to your purposes. The vendor should not use client health data to train its own models or for its own ends.

De-identification lowers your risk. If data no longer identifies a person, privacy law duties shrink, though you must guard against re-identification.

In our AI-compliance work with healthcare-adjacent and nonprofit clients, the failure mode we see most is staff pasting client data into consumer AI tools with no contract behind them. That single habit breaks both PIPEDA safeguards and PHIPA agent rules.

  • Sign a written data processing contract before any real data flows.
  • Bind the vendor to your purposes only; forbid model training on your data.
  • De-identify where you can, and control re-identification risk.
  • Keep an inventory of which AI tools touch which data.

Cross-Border and Offshore Processing

PIPEDA allows you to transfer data across borders for processing, but your organization stays accountable for it. Sending health data to a US cloud AI vendor is a transfer for processing, not a disclosure to a new controller.

The accountability principle means you must use contractual or other means to give the data a comparable level of protection while the vendor handles it.

US processing raises real questions. US law can compel a provider to hand over data, so weigh that risk for health information.

Be transparent with people that their data may be processed outside Canada. Some provinces and public bodies restrict or add steps for offshore storage, so check your provincial rules.

Transfer for processing is allowed, but the transferring organization remains accountable and must ensure comparable protection.

The Privacy Regulators' Generative AI Principles

Canada's federal, provincial, and territorial privacy regulators issued joint principles for responsible generative AI in December 2023. They explain how existing privacy law applies to generative AI.

The principles ask you to establish legal authority for collecting and using personal data, and to rely on valid, meaningful consent when consent is the basis.

They stress openness and transparency about how data is used and the privacy risks involved. They also ask you to limit the sharing of personal, sensitive, or confidential data with these tools.

For practical purposes, treat generative AI like any other processor. Map the data, get consent, be transparent, limit sensitive inputs, and keep a human accountable for outcomes.

  • Set your legal authority and lawful basis before collecting or using data.
  • Be open about generative AI use and its privacy risks.
  • Limit personal, sensitive, or confidential data sent to AI tools.
  • Keep meaningful human oversight over AI decisions that affect people.

Quebec Law 25: The Stricter Bar

Quebec's Law 25 sets Canada's strictest private-sector privacy rules, so organizations touching Quebec residents' data face extra steps. It reformed Quebec's private-sector privacy law in stages.

Consent standards are higher, and sensitive data generally needs express consent. The law also builds in stronger transparency duties.

Law 25 requires a privacy impact assessment before you transfer personal data outside Quebec, and for certain projects that acquire or develop information systems. That directly affects offshore AI processing.

It also gives people rights around automated decision-making. If AI makes a decision based only on automated processing, you must inform the person and let them ask for a review.

  • Express consent is the norm for sensitive data.
  • A privacy impact assessment is needed before cross-border transfers.
  • People have rights when a decision is fully automated.
  • Penalties can be significant, so verify current thresholds on official sources.

PIPEDA vs HIPAA: A Quick Contrast

PIPEDA and HIPAA solve similar problems in different ways. PIPEDA is a broad Canadian private-sector law across all industries, while HIPAA is a US law focused only on health data held by covered entities and their business associates.

PIPEDA is principles-based and applies to almost any personal data in commercial activity. HIPAA is prescriptive and sector-specific, with detailed rules for Protected Health Information (PHI).

The vendor contract also differs. HIPAA uses a Business Associate Agreement (BAA); PIPEDA uses a general accountability contract, while PHIPA relies on the agent and electronic service provider rules.

A tool being HIPAA-ready does not automatically make it PIPEDA or PHIPA compliant. You still owe Canadian duties like meaningful consent and comparable cross-border protection.

  • Scope: PIPEDA covers all personal data; HIPAA covers only health data at covered entities.
  • Style: PIPEDA is principles-based; HIPAA is prescriptive.
  • Contract: HIPAA needs a BAA; Canada needs an accountability or agent contract.
  • Health rules in Canada are mostly provincial, like PHIPA in Ontario.

A Practical AI Compliance Checklist

Start with a simple rule: know your data, your law, and your vendor before you turn AI on. Most compliance failures come from skipping one of these three.

Work through the checklist below with your privacy lead. Then have a professional review it against your exact situation.

  • Confirm which law applies: PIPEDA, PHIPA, Alberta or BC PIPA, or Quebec Law 25.
  • Map what personal or health data the AI tool will collect and use.
  • Get meaningful, and for sensitive data express, consent for each purpose.
  • Sign a written contract limiting the vendor to your purposes, with no training on your data.
  • Check where processing happens and ensure comparable protection for any transfer.
  • Run a privacy impact assessment for cross-border transfers, and always for Quebec.
  • De-identify data where you can and control re-identification risk.
  • Keep a human accountable for AI decisions and set a retention limit.
  • Update your privacy notice to disclose AI use in plain language.
  • Document everything so you can show accountability if asked.
This is practical guidance, not legal advice. Confirm the details with the OPC, your provincial regulator, and a qualified advisor.

Frequently Asked Questions

  • Not with consumer versions and no contract in place. PIPEDA and PHIPA require safeguards, meaningful consent, and a written agreement limiting the vendor to your purposes. Use an enterprise plan with a data protection contract, de-identify where possible, and never paste client health data into a free consumer tool.
  • Yes, PIPEDA allows transfers to a processor across borders, but your organization stays accountable. You must use a contract to give the data comparable protection, be transparent that processing may happen outside Canada, and weigh the risk that US law can compel disclosure.
  • A Health Information Custodian, or HIC, is a person or organization with custody or control of personal health information in Ontario. Examples include physicians, clinics, hospitals, pharmacies, and labs. The HIC stays responsible even when an AI vendor processes the data as its agent or electronic service provider.
  • Health privacy is largely provincial in Canada. Ontario uses PHIPA, while other provinces have their own laws, such as Alberta PIPA, BC PIPA, and Quebec Law 25. PIPEDA is the federal private-sector law and can apply where a province lacks substantially similar legislation.
  • You need a written contract that limits the vendor to your purposes and forbids using your data to train its own models. Under PIPEDA this supports the accountability principle; under PHIPA the vendor is usually your agent or electronic service provider, and the contract sets the guardrails.
  • PIPEDA is a broad Canadian private-sector privacy law covering all industries, while HIPAA is a US law limited to health data at covered entities and their business associates. HIPAA uses a Business Associate Agreement, while Canada relies on accountability contracts and, for Ontario health data, the PHIPA agent rules. HIPAA-ready does not equal PIPEDA compliant.
  • Often, yes, especially for cross-border processing. Quebec's Law 25 requires a privacy impact assessment before transferring personal data outside Quebec and for certain new information systems. Even where it is not strictly required, a PIA is a strong way to show accountability under PIPEDA and PHIPA.

Adopt AI Under Canadian Privacy Law With Confidence

Layer3 Labs helps Canadian healthcare and nonprofit teams roll out AI without breaching PIPEDA or PHIPA. We map your data, vet vendors and contracts, and set consent and cross-border safeguards that hold up. Book a free AI compliance review to see where you stand.

Book a Compliance Review