Back to Blog
AI Adoption8 min read

The OPC Just Changed the Rules on AI Vendor Procurement: What Canadian SMBs Need to Do Now

By Anton Kuznetsov

On September 10, 2026, the Office of the Privacy Commissioner of Canada (OPC) published draft guidance titled "Guidance on Assessing Third-Party Service Providers" — the most specific direction the OPC has given Canadian organizations on how to evaluate vendors that handle personal information before signing a contract.

The guidance is not just for large enterprises with legal departments and procurement teams. It applies to every Canadian business subject to PIPEDA — which includes most private-sector organizations operating in Canada. And given that Statistics Canada's second-quarter 2026 survey found 19.2 per cent of Canadian businesses now using AI to produce goods or deliver services (tripled from 6.1 per cent in 2024), the guidance lands in an environment where AI vendor relationships are growing rapidly across Canadian SMBs.

The comment period on the draft closes December 4, 2026. But the underlying PIPEDA obligations the guidance codifies are not new — and do not wait for the guidance to be finalized.

What PIPEDA Already Required — and What the OPC Guidance Makes Explicit

Under PIPEDA's accountability principle (Principle 1 of Schedule 1), your organization remains responsible for the personal information under its control, even when a third party collects, uses, or discloses that information on your behalf. This has been in force since PIPEDA came into effect in 2001. What it requires in practice is that before transferring personal information to a third-party service provider, you take reasonable steps to ensure that provider will protect it with comparable security.

The September 2026 guidance translates "comparable security" into a structured assessment framework across five evaluation categories:

1. The provider's privacy and security policies — not just that they exist, but what they cover and whether they align with PIPEDA's requirements

2. How personal information is collected, used, stored, and disclosed by the provider and any sub-processors it engages

3. Security certifications and incident response capabilities — including whether the provider holds a current SOC 2 Type II report or equivalent, and what their breach notification timeline is

4. Cross-border data transfer arrangements — if the provider or its sub-processors operate outside Canada, what protections govern data after it leaves Canadian jurisdiction

5. AI-specific considerations — for providers whose technology relies on training data, organizations must request information about the source of that data and how it was collected, and confirm whether that collection complied with applicable privacy laws

That fifth category is the one that fundamentally changes the vendor conversation for any Canadian SMB deploying AI tools. It is not enough to confirm that an AI vendor has a privacy policy. You must now ask — and document asking — where the model was trained, what data was used, and whether that collection was lawful.

Why the OPC Is Focused on AI Vendors Right Now

The September 2026 guidance does not arrive in isolation. In 2026, the OPC has completed two significant investigations into AI companies operating in Canada, and both set precedents directly relevant to how Canadian SMBs evaluate their own AI vendor relationships.

In May 2026, the OPC published PIPEDA Findings #2026-002, the joint investigation of OpenAI's ChatGPT, finding violations of PIPEDA related to how OpenAI collected and used personal information to train its models. In June 2026, PIPEDA Findings #2026-004 found that X Corp. and xAI violated PIPEDA through the Grok AI chatbot's generation of non-consensual sexualized content, with significant implications for how AI-generated content companies are assessed under Canadian law.

These findings establish that the OPC will investigate AI vendors and hold them to PIPEDA's standards — and that Canadian organizations that chose those vendors had an accountability obligation that predated any investigation. The OPC's own 2025-2026 Annual Report reflects the consequences: PIPEDA complaints more than doubled year-over-year, rising 109 per cent to 3,044 complaints. The OPC also received nearly 700 breach reports from businesses, affecting more than 20 million Canadians. Third-party AI tool accountability is not a theoretical risk — it is an active enforcement priority.

The Financial Case for Getting Vendor Assessment Right

The IBM 2026 Cost of a Data Breach Report — Canada puts the stakes in concrete terms. The average Canadian breach now costs CA$7.11 million — a record high. Supply-chain and third-party vendor compromise is now the single largest cost amplifier in Canadian breaches, adding approximately CA$367,899 per incident above the baseline breach cost.

The global IBM data adds further context on the scale of the vendor risk problem: supply-chain breach incidents have quadrupled over the past five years, and supply-chain compromise now costs an average of USD 4.91 million globally. Organizations that experienced shadow AI — employees using unapproved AI tools without organizational oversight — incurred an additional USD 670,000 above the average breach cost globally.

For Canadian SMBs, that shadow AI figure is particularly relevant. Statistics Canada found that 19.2 per cent of Canadian businesses reported using AI in Q2 2026 — but the most common AI applications were data analytics (36.6 per cent of AI-using organizations), text analytics (34.5 per cent), and virtual agents or chatbots (28.2 per cent). Most of those tools involve a third-party AI provider. Most of those relationships were not assessed against the framework the OPC published on September 10.

More than 20 per cent of organizations in the IBM 2026 study reported experiencing a breach involving AI models or applications. That is an attack surface that did not exist at scale in 2022 and that has grown precisely as fast as enterprise and SMB AI adoption.

Seven Questions to Ask Every AI Vendor Before Signing

The OPC guidance gives Canadian SMBs a structured basis for vendor assessment. Translating the guidance into a practical checklist, here are the seven questions every Canadian organization should ask — and document answers to — before deploying an AI tool that handles personal information:

1. Where is our data stored, and does it leave Canada?

Canadian data residency matters for PIPEDA compliance and is a standard underwriting criterion for Canadian cyber insurance policies. AI vendors operating from U.S.-only infrastructure without a Canadian region create cross-border transfer risk that requires additional contractual protections under the OPC's Guidelines for Processing Personal Data Across Borders. Acceptable answers: Azure Canada Central or Canada East, AWS Canada (Central) regions, or equivalent documented data residency commitments.

2. What training data was used to build the model, and was its collection lawful?

This is the direct requirement introduced by the September 2026 OPC guidance. If the vendor's AI relies on training data, you must confirm the source, how it was collected, and whether that collection complied with PIPEDA and applicable privacy laws. A vendor that cannot or will not answer this question has not satisfied its own accountability obligations — and you cannot satisfy yours by relying on a vendor that hasn't.

3. Will our organizational data be used to retrain or improve the model?

Consumer-grade AI products commonly use user inputs to improve their models as a default setting. Enterprise agreements should contractually prohibit this. Confirm that personal information submitted through the tool is not used for model training outside your organization's tenant environment. This is what distinguishes enterprise M365 Copilot from a consumer ChatGPT account, for example — and it is why Microsoft's contractual commitments under its enterprise agreements matter for PIPEDA compliance.

4. Does the vendor hold a current SOC 2 Type II report?

SOC 2 Type II is the baseline independent security attestation for SaaS vendors handling sensitive data. An AI vendor without a current SOC 2 report has not had its security controls verified by an independent auditor. Request the report under NDA; review the audit scope, the period covered, and whether any findings were qualified. ISO 27001 certification is the international equivalent and is acceptable in lieu of SOC 2 for vendors operating primarily in non-U.S. markets.

5. What is the vendor's contractual breach notification commitment?

PIPEDA requires organizations to report breaches that create a real risk of significant harm "as soon as feasible." That obligation is only actionable if your vendor agreement requires the vendor to notify you of any breach affecting your data within a defined window — the standard enterprise commitment is 24 to 72 hours. Vendor agreements that are silent on notification timelines leave you unable to meet your own PIPEDA reporting obligations.

6. Who are the sub-processors that can access our data?

AI products regularly rely on sub-processors — underlying model providers, cloud infrastructure, authentication services, support platforms. Each sub-processor represents an additional link in the accountability chain. Your vendor agreement should list current sub-processors, restrict their use of data to the purposes disclosed, and require advance notice before adding new sub-processors.

7. Are the contractual protections enforceable under Canadian or provincial law?

Data processing agreements governed exclusively by foreign law with no Canadian jurisdiction clause create enforcement uncertainty. For organizations handling personal information of Canadians, agreements should specify applicable Canadian law or include an express acknowledgment of PIPEDA applicability and the jurisdiction of the Office of the Privacy Commissioner for complaints.

What the CCCS Adds on the Security Side

The OPC guidance addresses privacy accountability. The Canadian Centre for Cyber Security's ITSAP.10.070 — Cyber Supply Chain: An Approach to Assessing Risk addresses the security side of the same assessment framework. The CCCS recommends that organizations assess the security posture of every vendor that accesses organizational systems or data, require vendors to notify of security incidents within a defined timeframe, and include key suppliers in business continuity planning and resilience exercises.

The CCCS National Cyber Threat Assessment 2025-2026 identifies supply chain attacks — where a threat actor compromises a software, IT, or cloud services vendor to reach the vendor's customers — as one of the most persistent and significant threats facing Canadian organizations. Taking the OPC guidance and CCCS supply chain framework together gives Canadian SMBs a coherent, authority-backed assessment process that satisfies both PIPEDA accountability requirements and the security due diligence that cyber insurers increasingly require as a condition of coverage.

The Practical Starting Point: Your Active AI Vendor Inventory

Before any formal vendor assessment is possible, you need to know which AI vendors you are already working with. A complete inventory for a typical Canadian SMB will surface:

  • Enterprise AI platforms — Microsoft 365 Copilot, Azure OpenAI Service, Google Workspace AI features
  • SaaS tools with embedded AI features — CRM, ERP, and HR platforms that have activated AI components that may have been included in base licences
  • Point solutions adopted by specific teams — AI writing tools, customer support chatbots, document management platforms with AI search
  • Consumer tools accessed by individual employees — the shadow AI category that IBM's data identifies as adding USD 670,000 in breach costs

That last category will not appear in a procurement log because no organizational procurement generated the relationship. It requires a different discovery process — a team survey, a SaaS spend audit, DNS log review — and its presence in your environment is the norm, not the exception. Statistics Canada's data on AI adoption reflects planned organizational use; the actual use in most Canadian organizations is considerably higher.

Once your vendor inventory is complete and assessed against the seven-question framework above, you have the foundation for a personal information data map: a document showing where personal information flows, through which third-party systems, under what contractual protections. That data map is simultaneously a PIPEDA accountability artifact, a breach response accelerator that compresses the detection-to-notification window, and a cyber insurance documentation requirement.

The OPC's comment period closes December 4, 2026. Using it as a planning deadline — completing your vendor inventory and assessment framework before then — gives you a documented accountability posture before the guidance is finalized and before the next OPC investigation makes an undocumented one consequential.


Sources


The OPC's September 2026 guidance formalizes what PIPEDA's accountability principle has always required: AI vendors handling your customers' and employees' data are your accountability responsibility, not theirs alone. Cloud Forces works with Canadian SMBs to conduct vendor assessments against the OPC framework, negotiate compliant data processing agreements, and deploy enterprise AI platforms with documented Canadian data residency. Our AI Advisory team can walk through your current AI vendor inventory and identify the gaps before your next renewal cycle — or before the next OPC investigation makes the gaps relevant for a different reason. Book a consultation to get started.

Anton Kuznetsov
Founder & Principal Engineer

Anton Kuznetsov is the founder and principal engineer of Cloud Forces, the Toronto firm he started in 2018 to make custom software and AI practical and affordable for Canadian SMEs. He works hands-on across application development, cloud architecture, and the production systems Cloud Forces runs for its clients.

Ready to bring AI to your business?

Book a free AI Readiness Consultation — no commitment required.

Book Free Consultation