Canada's federal privacy regulator has published non-binding guidance telling organisations to ask a prospective vendor where its AI training data came from, and whether that collection was lawful, before they sign

OPC Puts Training Data Into Vendor Diligence. The Leveraged Years regulation briefing card.

One bullet and one example in an eleven-part checklist. They matter because of where they sit: not in an AI policy document, but in the ordinary procurement diligence that a buyer runs before signing.

The short version

Bottom line: Non-binding. This is guidance, not a rule, and it creates no obligation on any organisation. The OPC states it is accepting comments on the document until 4 December 2026, at which point it will evaluate whether amendments are required.

Who this affects: Privacy officers and privacy counsel at PIPEDA-regulated organisations, procurement and vendor-risk teams running pre-contract assessments, and AI and SaaS vendors selling into Canada who will be asked these questions in diligence.

Issue date: 10 September 2026, which is both the issued and the modified date carried by the published guidance. Comments are open to 4 December 2026.

What changed: The OPC's stated best practice for assessing a third-party provider now includes confirming whether the provider's technology relies on training data, and if it does, requesting the source of that data and how it was collected.

Analysis: The framing is the interesting part. The OPC presents the assessment as a way to meet accountability obligations under PIPEDA Principle 4.1.3, which is an existing statutory principle, while the checklist itself remains a recommendation.

Primary sources: Guidance on assessing third-party service providers

Instrument (EN)
Guidance on assessing third-party service providers
Authority
Office of the Privacy Commissioner of Canada
Jurisdiction
Canada, federal private sector under PIPEDA
Status
Published guidance, open for comment
Bindingness
Binds nobody. It sets out best practices and states that they do not necessarily address all considerations, and that organisations working with third parties have further obligations under PIPEDA
Issue date / next deadline
Issued 10 September 2026. Comments accepted until 4 December 2026 by email to the OPC consultation address given in the notice
Legal basis
Framed against the accountability obligation in Principle 4.1.3 of PIPEDA
Primary source
https://www.priv.gc.ca/en/privacy-topics/privacy-for-businesses/appropriate-handling-of-personal-information/gd_third-party_202609/

What the guidance actually says about AI

The AI content sits in two places, and it is worth being exact about how much of it there is. One of the eleven best-practice headings is titled Identify the source of training data, and it carries a single bullet: "Confirm whether the provider's technology relies on the use of training data, for example, to train an AI algorithm or test its functioning. If it does, request information about the source of the data and how the provider collected it. Consider whether this sourcing is consistent with legal requirements under PIPEDA and/or the jurisdictions in which it was collected."

The second place is the heading Confirm how data will be used, which asks the buyer to confirm each purpose for which the provider will handle personal information on its behalf, and then adds the case that matters here. If the provider intends to use any of the personal information for its own purposes, the guidance gives training an algorithm as its first example, and directs the buyer to assess whether consent is required and whether the purpose is consistent with PIPEDA and other applicable privacy laws.

A third heading does adjacent work without naming AI. Under Understand functionality and performance, the buyer is told to be aware of known risks in the technology's functionality, "such as systemic bias, security vulnerabilities, or factors that may lead to inaccuracy or discriminatory treatment", and to verify what the provider has done to reduce them.

That is the whole of the AI-specific material in a document of eleven practice areas. Calling this Canadian AI guidance would overstate its subject. What it is, is general vendor diligence guidance in which training-data provenance has been given its own heading.

Where the accountability hook sits

The guidance opens on Principle 4.1.3 of PIPEDA, under which organisations are responsible for personal information in their possession or custody, including information transferred to a third party for processing, and are required to use contractual or other means to ensure comparable protection while a third party processes it. That obligation is statutory and already binding.

What the OPC then says about the assessment is carefully hedged. Assessing a provider before deciding to work with them "can help organizations to ensure that they meet their obligations under Principle 4.1.3". The document repeats the point in its key points as a should, not a shall, and closes the section by noting that organisations are ultimately responsible for ensuring their use of a provider's product complies with all applicable privacy requirements under PIPEDA.

Read the two together and the practical position is this: the accountability duty is binding, the checklist is the regulator's view of how a buyer might discharge it, and the document itself declines to present the checklist as exhaustive. That is three removes from a rule, and the OPC does not claim otherwise.

The scraped data and anonymisation problems

Two bullets elsewhere in the document bear directly on how AI vendors are assessed today, even though neither mentions AI.

The first tells buyers to use extra scrutiny where a product involves collecting or using publicly available information, and states the OPC's position on it: PIPEDA still applies to personal information accessible in public spaces, including information posted online, and exceptions for publicly available personal information are limited. That is the OPC restating its own reading of the statute, and it lands on any vendor whose answer to the provenance question is that the data was public.

The second tells buyers to use extra scrutiny where a provider claims the information involved is anonymised, on the footing that datasets which do not directly identify individuals may still contain personal information that could be re-identified. The guidance asks the buyer to request specific information about the anonymisation techniques used and how they meet applicable legal thresholds. It does not say which thresholds, and we do not supply one.

What a buyer would actually have to do differently

The familiar vendor-risk question is what a supplier does with your data. The provenance heading asks a different question, about data the buyer never had and cannot inspect, and the honest observation is that some vendors may struggle to answer it in the detail the bullet contemplates.

The guidance builds in the exit. It tells buyers that where they are unsure how the technology works they can request additional materials, and can consult independent external resources on the technology's performance. It also asks that the people carrying out the assessment have appropriate training and expertise, and says securing external legal or technical expertise may be necessary to address gaps.

Two further headings turn the answers into contract terms. Confirm roles and responsibilities suggests including the best practices in the agreement as contractual provisions, and Identify monitoring mechanisms asks how the provider's ongoing compliance can be monitored through inspections or independent audits. Nothing in the document obliges a buyer to do any of this. As a description of what the regulator considers reasonable diligence, it is still a clear statement from the regulator.

What we did not verify

What we opened: the full published guidance on the OPC site, read end to end, including the comment notice and deadline, the purpose and audience sections, the key points, the Principle 4.1.3 framing and all eleven best-practice headings with their bullets. The page carried an issued date and a modified date of 10 September 2026.

What we did not open: the OPC's news release about the guidance, the French version of the document, and every OPC resource it cross-references, including the guidance on outsourcing, the Interpretation Bulletins on accountability, sensitive information and publicly available information, the guidelines for processing personal data across borders, the breach reporting guidance and the retention and disposal guidance. We describe none of those, and we quote only the English text we read.

Quotations are reproduced with ASCII punctuation in place of the typographic apostrophes and quotation marks used on the page, which is a house typesetting convention and not a change to any word.

What we refuse to claim: we do not say any organisation is required to assess a vendor's training data, because the document is guidance and says so. We do not say the OPC has changed its position on scraped or publicly available data, because we did not compare this text against the earlier bulletin it points to. We do not give a number for how many organisations this reaches, because the guidance gives none and we have no denominator. We do not say the comment window will produce amendments, because the OPC says only that it will evaluate whether any are required.

Informational analysis for working professionals, not legal advice. Confirm how any rule applies to your situation with qualified counsel.

Key compliance takeaway

The question worth taking out of this one is whether your standard vendor questionnaire has a training-data provenance item in it at all. The OPC has now put one in writing, in ordinary procurement guidance rather than an AI framework, and paired it with a second question about whether the vendor will reuse your data to train its own models. Neither binds anyone. Both are now the stated expectation of the regulator that would assess your accountability if something went wrong, and the comment window closes on 4 December 2026.

Source File

https://www.priv.gc.ca/en/privacy-topics/privacy-for-businesses/appropriate-handling-of-personal-information/gd_third-party_202609/

Open the guidance and confirm four things: the comment notice and the 4 December 2026 deadline at the top, the bullet under Identify the source of training data, the algorithm-training example under Confirm how data will be used, and the Principle 4.1.3 framing in the Guidance section.

Confirm whether the provider's technology relies on the use of training data, for example, to train an AI algorithm or test its functioning. If it does, request information about the source of the data and how the provider collected it. ยท Guidance on assessing third-party service providers, Identify the source of training data, issued 10 September 2026

FAQ

Does this guidance oblige anyone to do anything?

No. It sets out best practices and is open for comment until 4 December 2026. The binding element it is framed against is the existing accountability obligation in Principle 4.1.3 of PIPEDA, under which organisations remain responsible for personal information transferred to a third party for processing.

What does it say about AI training data?

It asks buyers to confirm whether the provider's technology relies on training data, for example to train an AI algorithm or test its functioning, and if so to request the source of that data and how the provider collected it, then to consider whether the sourcing is consistent with legal requirements under PIPEDA and the jurisdictions where it was collected.

Does it address a vendor training on our data?

Yes, separately. Under Confirm how data will be used, the guidance asks buyers to confirm each purpose, and where the provider intends to use personal information for its own purposes, giving training an algorithm as the example, to assess whether consent is required and whether the purpose is consistent with PIPEDA and other applicable privacy laws.

How much of the document is about AI?

Little of it. Across the eleven best-practice headings, one is devoted to training-data provenance, one names training an algorithm as an example of a provider's own purpose, and one asks about known functional risks including systemic bias and discriminatory treatment without naming AI. The rest is general vendor assessment.

Sponsored Training

Practical AI training for regulated professionals, built around verification, documentation and a defensible process. See the courses.

."}}]}