From the journal

Canadian Privacy Regulators Find OpenAI ChatGPT Non-Compliant Under PIPEDA May 2026

On 6 May 2026, Canada's Office of the Privacy Commissioner and its counterparts in Quebec, British Columbia, and Alberta published PIPEDA Findings #2026-002: the joint investigation of OpenAI OPCO LLC. The regulators concluded that OpenAI's collection of personal data through web scraping and user interactions to train ChatGPT lacked valid consent under federal and provincial privacy statutes.

3 min read

On 6 May 2026, the Office of the Privacy Commissioner of Canada (OPC), the Commission d'accès à l'information du Québec (CAI), the Office of the Information and Privacy Commissioner for British Columbia (OIPC-BC), and the Office of the Information and Privacy Commissioner of Alberta (OIPC-AB) jointly published PIPEDA Findings #2026-002: Joint Investigation of OpenAI OPCO LLC. The investigation, initiated in 2023, examined how OpenAI collected, used, and disclosed personal information in developing and operating ChatGPT and training its GPT-3.5 and GPT-4 models. The findings are at the published enforcement stage.

The investigation identified two categories of non-compliant data collection. First, OpenAI scraped personal information from publicly accessible internet sources to build training datasets, without valid consent under the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial statutes. Second, OpenAI collected user interaction data from ChatGPT conversations and used it to fine-tune subsequent model versions, also without valid consent. The regulators accepted that developing large language models constitutes an appropriate purpose under Canadian privacy law but held that consent, not purpose, was OpenAI's primary compliance failure. Deficiencies in disclosure to affected individuals were also identified.

AI developers, generative AI platform operators, and companies fine-tuning third-party AI models on user interaction data face the most direct compliance implications from these findings. The regulators' acceptance of LLM development as a legitimate purpose does not insulate training pipelines from consent and transparency obligations under PIPEDA. Companies relying on web-scraped data or user-generated content for AI training must audit their consent mechanisms, data minimisation practices, and individual disclosure obligations. These findings are likely to carry persuasive weight with privacy regulators in other jurisdictions conducting reviews of AI training data practices.

The investigation preceded Canada's proposed Consumer Privacy Protection Act (Bill C-27), which would tighten consent requirements, create rights for individuals to request explanations of AI-generated decisions affecting them, and introduce mandatory algorithmic impact assessments. Once enacted, Bill C-27 would impose a more demanding baseline than PIPEDA on AI training activities. OpenAI's cooperation during the investigation and subsequent transparency measures were acknowledged but did not constitute a finding of compliance. Companies operating in Canada should assess their current data practices against both PIPEDA and the requirements proposed in Bill C-27.

Licentium advises AI developers and platform operators on privacy law compliance, including data governance for training pipelines and cross-jurisdictional regulatory risk. We assist clients in evaluating exposure to privacy investigations and in building consent and transparency mechanisms that meet current and anticipated legal standards. Work we undertake includes AI training data legal review, PIPEDA and provincial privacy compliance, data subject rights program design, and regulatory investigation response strategy.

Source: PIPEDA Findings #2026-002, Joint Investigation of OpenAI OPCO LLC, Office of the Privacy Commissioner of Canada, 6 May 2026

More from the journal

See all

Hong Kong SFC and FSTB Conclude Consultation on Virtual Asset Advisory and Management Regimes, 26 May 2026

On 26 May 2026, Hong Kong's Securities and Futures Commission and Financial Services and the Treasury Bureau published consultation conclusions on proposed licensing regimes for virtual asset advisory and management service providers. The regimes apply the same business, same risks, same rules principle and align SFC licensing requirements with those for securities advisory and management businesses. A bill implementing the regimes is planned for introduction into the Legislative Council in 2026.

OCC Grants Circle Final Charter for First National Digital Currency Bank N.A., 9 July 2026

The Office of the Comptroller of the Currency granted final approval on 9 July 2026 for Circle Internet Group to establish First National Digital Currency Bank, N.A., operating as Circle National Trust. The bank opened 24 July 2026 under direct OCC oversight and will manage USDC reserves on a directed basis, act as collateral trustee for USDC holders, and provide digital asset custody services to Circle affiliates.

Manitoba Enacts Public Sector AI and Cybersecurity Governance Act June 2026

On 1 June 2026, Bill 51, The Public Sector Artificial Intelligence and Cybersecurity Governance Act (S.M. 2026, c. 43), received Royal Assent in Manitoba, Canada. The Act mandates transparency, accountability structures, and cybersecurity incident reporting for public sector entities using AI systems. Substantive obligations take effect only through regulations yet to be made.