Back to Blog
Cybersecurity9 min read

109% More Privacy Complaints in One Year: What the OPC's 2025-2026 Annual Report Means for Canadian SMBs

By Anton Kuznetsov

On June 4, 2026, Privacy Commissioner Philippe Dufresne tabled the Office of the Privacy Commissioner of Canada's 2025–2026 Annual Report before Parliament under the title *Championing Privacy in the Age of AI*. The report describes a regulator under pressure.

The OPC received 3,044 PIPEDA complaints in fiscal 2025–26 — a 109 per cent increase over the prior year, the largest single-year jump in the report's history. It also received approximately 700 breach reports from businesses, with those breaches affecting more than 20 million Canadians. And it published the findings of a landmark joint investigation concluding that the way four separate Canadian privacy laws were violated by one of the world's most widely used AI tools.

For Canadian SMBs, this report is not a policy document. It is a signal about what the regulator has been seeing, what it has been doing, and where it is directing resources next — before a new enforcement law arrives that will change the consequences of non-compliance significantly.

What Is Driving the Complaints Surge

A 109 per cent increase in PIPEDA complaints in a single year is not explained by a proportional increase in privacy violations. The OPC's own analysis suggests the primary driver is accessibility: the regulator's new AI-enhanced online search tools made it substantially easier for Canadians to find, understand, and file complaints about the privacy practices of the businesses they interact with. As awareness of complaint mechanisms grows, volume will stay elevated — even in years with no major privacy incidents.

The practical implication for Canadian SMBs is a structural shift in exposure. Under PIPEDA, any individual who believes an organization has violated their privacy rights can file a complaint at no cost. The OPC investigates, and findings are published. An organization found to have violated PIPEDA faces reputational damage, possible court-ordered compliance, and civil damages of up to $100,000 per violation under the current statute. The 3,044 complaints filed in 2025–26 are not an anomaly — they are the new baseline.

700 Breach Reports from Businesses: The Notification Obligation Most SMBs Get Wrong

PIPEDA requires organizations to report to the OPC and notify affected individuals any time a breach of security safeguards creates a "real risk of significant harm." The approximately 700 breach reports the OPC received from businesses in 2025–26 — covering breaches affecting more than 20 million Canadians — represent only the reported incidents.

The real number of qualifying breaches is higher. A persistent finding in OPC enforcement work is that organizations either fail to identify breaches as PIPEDA-reportable, fail to assess them correctly against the "real risk of significant harm" threshold, or delay notification well beyond what the statute requires. PIPEDA requires notification and reporting "as soon as feasible" — which the OPC has interpreted to mean immediately on conclusion of the initial assessment, not weeks later after internal review is complete.

In March 2025, the OPC released a Privacy Breach Risk Assessment Tool to help organizations determine whether a specific breach crosses the reporting threshold. The tool walks through: the sensitivity of the information involved; the circumstances of the breach (who accessed what, for how long, whether there is evidence of malicious intent); the number of affected individuals; and whether affected individuals may be distinctly vulnerable. Based on the answers, it indicates whether reporting is "Likely" or "Unlikely" required.

The tool is deliberately anonymous — it does not identify the organization that uses it and does not send data to the OPC. Its purpose is to make the threshold assessment accessible rather than a source of uncertainty that creates delay. An SMB that uses it promptly after a breach and acts on its output is in a substantially better compliance position than one that waits for outside counsel to complete the same analysis.

What the OpenAI Investigation Established About AI and PIPEDA

The joint investigation published May 6, 2026 — PIPEDA Findings #2026-002 — found that OpenAI violated PIPEDA and three provincial privacy statutes when training ChatGPT on scraped public web content. The specific violations: overbroad collection, lack of valid consent, insufficient transparency, and inadequate deletion mechanisms.

For Canadian SMBs, the most practically significant finding is on consent. The OPC rejected the argument that information appearing on a public website constitutes implied consent to its collection for commercial AI training. Consent under PIPEDA must be meaningful, informed, and appropriate to the sensitivity of the information. The fact that data was publicly accessible does not satisfy that standard.

This matters directly to any Canadian organization collecting, processing, or generating personal information with AI tools. If your business uses AI tools that handle customer or employee personal information, your data handling agreements with those vendors — not the vendors' public privacy policies — are what establishes your PIPEDA compliance. The OPC's joint finding made clear that the compliance obligation sits with the organization that collects and is accountable for the data, not only with the AI provider that processes it.

Bill C-36: What Enforcement Will Look Like After the Transition

The current PIPEDA enforcement framework has structural limitations. The OPC can investigate, make findings, and seek court orders — but cannot directly impose fines. Maximum court-ordered damages under PIPEDA are $100,000 per violation.

Bill C-36, tabled June 15, 2026, replaces PIPEDA with the Protecting Privacy and Consumer Data Act (PPCDA) and creates a new regulator: the Digital Safety and Data Protection Commission of Canada. The new Commission has direct fine authority — administrative monetary penalties of up to the higher of $10 million or 3 per cent of global gross revenues for most violations, and penal fines of up to the higher of $25 million or 5 per cent of global revenues for serious offences. For a Canadian SMB with $5 million in annual revenues, the administrative penalty ceiling is $150,000 — for the same conduct that currently tops out at $100,000 in court-ordered damages, but now assessable directly by the regulator without litigation.

Bill C-36 has not yet received Royal Assent and its coming-into-force date will be set by Order in Council. Organizations have a window — measured in years, not months — to build privacy programs that will survive scrutiny under the new regime. That window closes when the Order in Council is issued.

Five Things Canadian SMBs Need to Have in Place Before Bill C-36 Comes Into Force

1. A documented privacy program

The PPCDA (like its predecessor PIPEDA) requires organizations to have documented privacy policies, designated accountability, and records of consent. "We have a privacy policy on our website" is not a privacy program. A privacy program is a set of documented practices covering: what personal information is collected, why, from whom, how it is stored and protected, who has access, how long it is retained, and how individuals can exercise their rights. If yours does not exist in documented form, it is not yet a compliance asset.

2. A breach log

PIPEDA requires organizations to maintain a record of every breach of security safeguards — including those that do not meet the reporting threshold. That record must be retained for 24 months and produced to the OPC on request. Most SMBs without formal IT documentation do not have a systematic breach log. Start one now. A shared document that records incident date, nature, personal information involved, threshold assessment outcome, and actions taken is sufficient.

3. Vendor data processing agreements

Every third-party vendor that processes personal information on your behalf — your cloud email provider, your accounting software, your AI tools — needs a data processing agreement that specifies their obligations under PIPEDA. The OPC's 2025–26 report reflects increased scrutiny of supply chain and vendor accountability. The OPC's existing guidance makes clear that transferring data to a vendor does not transfer your accountability.

4. Consent records for personal data use

If you collect personal information — from customers, website visitors, employees, or any other individuals — you need records of how consent was obtained, when, and for what purposes. As the OpenAI finding confirmed, implied consent from public availability is not valid consent under PIPEDA. For any AI-assisted processing of personal information (generating customer communications, analyzing customer behaviour, processing job applications), confirm that the consent basis is explicit and documented.

5. A breach response procedure

The OPC's 2025–26 findings reflect recurring failures in breach response timing. "As soon as feasible" means within days of the threshold assessment, not weeks. A written breach response procedure — who is notified internally, who runs the OPC risk assessment tool, who sends the notification to the OPC, who notifies affected individuals, and what the notification must contain — is the difference between a compliant response and one that adds a failure-to-notify violation on top of the underlying breach.

The IBM Cost of a Data Breach Report 2026 put the average Canadian breach at CA$7.11 million — with phishing as the leading initial attack vector for the fourth consecutive year and breaches taking 205 days on average to detect and contain. Privacy compliance is not the only reason to improve your security posture, but it is increasingly the reason that attaches a specific dollar figure to the cost of not doing so.

What the OPC's 2025–26 Report Is Actually Telling You

The report's title — *Championing Privacy in the Age of AI* — is not rhetorical. Privacy Commissioner Dufresne used the report explicitly to signal regulatory priorities: AI tools that process personal information without adequate consent frameworks, data governance in AI-enabled organizations, and children's privacy in digital environments. These are not future concerns. The ChatGPT investigation that found four PIPEDA violations was published in May 2026. The 109 per cent jump in complaints reflects actual Canadian individuals asserting rights against actual Canadian businesses, right now.

The combination of rising complaint volumes, escalating breach report numbers, and a new enforcement framework with direct fine authority means the risk calculation for privacy non-compliance is changing materially. The time to build a defensible privacy program is before you receive the first complaint, not after.


Sources


Privacy compliance is not optional, and in 2026 the cost of getting it wrong is no longer theoretical. Our Cybersecurity team works with Canadian SMBs to build the privacy program foundations that PIPEDA requires today — breach logs, vendor agreements, consent records, and breach response procedures — and that will remain defensible when the PPCDA comes into force.

Anton Kuznetsov
Founder & Principal Engineer

Anton Kuznetsov is the founder and principal engineer of Cloud Forces, the Toronto firm he started in 2018 to make custom software and AI practical and affordable for Canadian SMEs. He works hands-on across application development, cloud architecture, and the production systems Cloud Forces runs for its clients.

Ready to bring AI to your business?

Book a free AI Readiness Consultation — no commitment required.

Book Free Consultation