Most "AI compliance checklist" content is generic enough to apply to nothing in particular. The Office of the Privacy Commissioner of Canada has actually published guidance on assessing third-party service providers — the real document a Canadian business is expected to work from. Here's what it asks, in plain language.
Why this matters more than it used to
Privacy reform legislation reintroducing the Consumer Privacy Protection Act framework has been moving back through Parliament, carrying fines of up to the greater of $25 million or 5% of global revenue for serious violations. Under PIPEDA today, and under that framework if it passes, a business is accountable for personal information it hands to a vendor — including an AI vendor — even after that vendor has it. Due diligence on the vendor isn't optional paperwork; it's the accountability mechanism.
What the OPC's guidance actually asks
The OPC's published guidance on assessing third-party service providers frames third-party assessment as a key due-diligence measure for meeting accountability obligations under PIPEDA. In practice, that translates into questions worth asking any AI vendor before signing:
- Where is the data actually processed and stored — not just "in the cloud," but which country, and under which jurisdiction's law?
- What happens to the data after the contract ends — is it deleted, and on what timeline, with what proof?
- Does the vendor use your data to train models — yours, or shared models used by other customers?
- Who has access on the vendor's side, and what's their own incident-response process if something goes wrong?
- Can the vendor actually demonstrate its safeguards, or is the answer just a general assurance with no specifics?
The pattern worth noticing
None of these are AI-specific questions dressed up in new language — they're the same accountability questions PIPEDA has always required for any third-party data handler. AI vendors don't get a separate, lighter standard just because the product is new.
FAQ
What guidance exists in Canada for assessing AI vendors?
The Office of the Privacy Commissioner of Canada has published specific guidance on assessing third-party service providers, framing it as a core due-diligence measure under PIPEDA's accountability principle.
What are the potential penalties for privacy violations under Canada's reform legislation?
Reintroduced privacy reform legislation carrying forward the Consumer Privacy Protection Act framework proposes fines up to the greater of $25 million or 5% of global revenue for serious violations.
Is a business still responsible for data once it's handed to a vendor?
Yes. Under PIPEDA's accountability principle, an organization remains responsible for personal information it transfers to a third party for processing.
Does an AI vendor need to meet a different privacy standard than other vendors?
No. The same due-diligence questions that apply to any third-party data handler apply to AI vendors — there's no separate, lighter standard for AI specifically.
Vetting a vendor right now?
If you want a second set of eyes on an AI vendor contract before you sign — from a Canadian team that stores data in-region by default — book a free 15-minute discovery call. (778) 401-6551.
