AI Briefing
KO

OpenAI Violated Canadian Privacy Law

·2026.05.08 03:23

Key point

Canadian privacy regulators found that OpenAI's data collection and training practices violated privacy law.

Details

Canada's federal privacy regulator and the privacy regulators of British Columbia, Alberta, and Quebec concluded that OpenAI's early ChatGPT training process violated privacy law.

The investigation targeted the training data collection methods for GPT-3.5 and GPT-4, which included public web scraping, licensed third-party sources, and ChatGPT user interactions. The regulators found that OpenAI collected extensive personal information, which could include health status, political affiliation, and information related to children.

The key findings were as follows.

  • Personal information was collected without valid consent.
  • OpenAI did not sufficiently and transparently disclose that the data would be used for training.
  • There was a lack of effective means for access, correction, and deletion.
  • ChatGPT was launched without adequately addressing known privacy risks and deletion rules.

Handling differed by agency. The federal investigation and some issues in Quebec were conditionally closed, but the cases remain unresolved under British Columbia and Alberta's provincial privacy laws. OpenAI committed to introducing filtering to mask names and phone numbers, improving correction and deletion procedures, establishing a retention policy, adding notices for the logged-out web version, protecting datasets kept for historical reference, testing protections for the minor family members of public figures, and providing quarterly reporting.

The regulators emphasized that this outcome signals the need to modernize Canadian privacy law for the AI era.

This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.

Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.