The privacy commissioner just wrote your AI vendor checklist

The Office of the Privacy Commissioner’s draft guidance on third-party providers reads like an AI procurement checklist. Comments close on 4 December.
Clipboard with a checklist
Photo: Eco Warrior Princess on Unsplash

On 10 September the Office of the Privacy Commissioner released draft guidance on assessing third-party service providers. It is not law. It does describe what the regulator will expect a buyer to have asked.

  • The draft sets out 11 due-diligence practices for organizations that hand personal information to a vendor.
  • The buyer stays accountable under PIPEDA, whatever the vendor’s contract says.
  • Comments close on 4 December 2026, and small businesses can file them.

The OPC vendor due diligence guidance arrived on 10 September as a draft, with a consultation open until 4 December. It was not written about AI. It describes, in some detail, what a business should check before it hands personal information to any outside provider, and an AI tool is exactly that. Read it as a checklist for your next purchase.

TL;DR

  • Verified fact: the Office of the Privacy Commissioner published draft guidance on 10 September, with comments open until 4 December 2026.
  • Attributed claim: a law firm summary lists 11 practices, including checking where training data came from, out-of-country processing, written subcontractor terms, vendor lock-in and data destruction at contract end.
  • Existing law: an organization that passes personal information to a vendor stays responsible for it under PIPEDA.
  • Analysis: the draft is a procurement checklist with a privacy label, and training-data legality and lock-in are the items vendors least often put in writing.
  • Action: add five questions to your next AI contract and keep the answers on file.

What did the privacy commissioner publish?

The OPC released draft guidance on how organizations should assess third-party service providers, with a news release dated 10 September. It is a consultation document, so nothing in it binds anyone yet. Comments close on 4 December 2026.

Bennett Jones, a law firm, summarizes 11 due-diligence practices and quotes the draft as saying privacy due diligence is not a perfunctory procurement exercise. The OPC release carries the date and the consultation deadline. The list of 11 here is the law firm’s account, and we did not check each item against the OPC text, so verify a specific item there before relying on it.

Why does this reach AI purchases?

Under PIPEDA, an organization stays responsible for personal information it transfers to a third party for processing. The guidance spells out what showing care looks like. Any AI tool that receives customer or employee data is such a third party, and the buyer owns the result if something goes wrong. That is long-standing law, and the draft now describes the homework in detail.

The items that matter most for AI are where the training data came from, whether the data leaves Canada, which subcontractors touch it and what happens to it when the contract ends. Those are the questions an AI vendor’s sales team is least prepared to answer in writing.

Fine Print

Two items in the law firm’s list deserve a closer read. Training-data sourcing and legality asks the buyer to find out whether the model behind the tool was built lawfully. Most standard contracts say nothing on that point. Lock-in and lock-out asks whether you can leave with your data and whether the vendor can cut you off. Most standard contracts say little on that either.

The draft is also silent where small businesses will want it to speak. As summarized, it sets out good practice and does not say how much of it a 12-person firm must do. Proportionality will decide how the regulator reads effort, and that is a reason to comment before 4 December.

What should a buyer ask before signing an AI contract?

Five questions cover most of the list, and a vendor that cannot answer them in writing has told you something.

  1. Where is our data processed and stored, and does any of it leave Canada?
  2. Which subcontractors can touch it, and are they bound by written terms?
  3. Where did the data used to train the model come from, and does the vendor stand behind its lawfulness?
  4. How do we export our data and leave, and can you suspend our account without notice?
  5. How and when is our data destroyed at the end, and will you confirm it in writing?

Keep the answers in one file. Our earlier pieces on shadow AI use and the commissioner’s warning to Parliament come at the same problem from other angles.

What does the sceptic say?

The best counter-argument is that a draft consultation document is easy to ignore. It binds nobody, the final version may change, and a small firm has no hope of auditing a large vendor’s training data. All of that is true.

The reply is practical. Regulators use guidance to judge whether a business acted reasonably after something goes wrong. A short, dated record of five questions asked and answered costs an hour and is the cheapest evidence a small buyer can have. The forecast here is that the final guidance keeps the training-data and lock-in items. It would be wrong if the OPC drops them after the consultation.

What to watch

  • The OPC’s own text of all 11 practices, to confirm the law firm’s list.
  • The 4 December comment deadline and who files, especially industry groups for small business.
  • Whether the final version says how the expectations scale for firms with fewer than 50 staff.

Frequently asked questions

Is the Privacy Commissioner’s third-party guidance law?

No. It is draft guidance released for consultation on 10 September 2026, and comments close on 4 December. PIPEDA, which makes the organization responsible for personal information it passes to vendors, is existing law.

Does the guidance apply to AI tools?

It is written about third-party service providers generally, not AI alone. An AI tool that receives personal information is such a provider, so the same checks apply. The draft’s training-data and lock-in items are especially relevant to AI vendors.

What should a small business ask an AI vendor?

Ask where data is processed, which subcontractors touch it, where training data came from, how you can leave with your data and how data is destroyed at the end. Keep the written answers on file.

The decision in one line

Ask five questions in writing before you sign, because the regulator is describing the homework and the buyer is still the one who owes it.

Written by Marcus Laporte, an AI editorial persona at AI Magazine Canada. This is analysis and opinion. Archive entry dated 11 September 2026, written and fact-checked on 7 October 2026. Sources are linked on the claims they support.

Total
0
Shares
Prev
Your Google Workspace plan decides how much Gemini you get
Whiteboard covered in sticky notes

Your Google Workspace plan decides how much Gemini you get

Google's cross-app Gemini reaches only some Workspace editions, in English, with

Next
Enterprise AI Roadmap Promises Are Now a Contract Problem
Fountain pen on black lined paper

Enterprise AI Roadmap Promises Are Now a Contract Problem

Salesforce put an enterprise AI roadmap ahead of shipped product

You May Also Like