What the Privacy Commissioner OpenAI Ruling Means for Anyone Using AI

Csae LogoCypher 30yrs logo

The Privacy Commissioner of Canada's investigation into OpenAI, with findings published in May 2026, is the first formal ruling by Canadian regulators that a major AI company violated Canadian privacy law in the development of its foundational models. The joint investigation, which involved four privacy bodies across federal and provincial jurisdictions, found that OpenAI collected and used personal information to train ChatGPT without adequate consent, without meaningful transparency, and without adequate safeguards for correction or deletion.

For Canadian nonprofit associations that have deployed AI tools, whether Microsoft 365 Copilot, AI-powered email platforms, or third-party tools built on large language models, the findings signal a direction in regulatory thinking that extends well beyond OpenAI's specific conduct.

What the Investigation Actually Found

The PIPEDA Findings #2026-002 identified three core problems with how OpenAI handled personal information in developing ChatGPT. First, personal information was collected from publicly accessible internet sources without any meaningful ability for individuals to consent to or opt out of that collection. Second, the original product design included a 'forced action' pattern that required users to allow their conversations to be used for model training in order to retain access to chat history. Third, OpenAI had no effective mechanism for individuals to correct or delete personal information that appeared in the model or its outputs.

All four participating privacy bodies, including the Office of the Privacy Commissioner of Canada, the Commission d'acces a l'information du Quebec, and the offices for British Columbia and Alberta, reached the same conclusion: OpenAI's practices violated applicable privacy laws. Quebec's regulator chose not to impose monetary penalties, opting instead for remedial recommendations.

OpenAI has since implemented filtering tools to detect and mask personal information in training data, decoupled the chat history and model training controls, and established a formal data retention and deletion policy. The finding nonetheless establishes that collecting and processing personal information for AI training purposes carries meaningful obligations under Canadian law.

The Forced Action Pattern Is a Warning About Your Consent Language

The 'forced action' finding deserves specific attention from associations. The problem the regulators identified was not simply that OpenAI collected data, but that the design of the consent mechanism was structured to prevent users from exercising a genuine choice. Consent obtained by making a service unusable without agreement does not satisfy the meaningful consent standard under PIPEDA.

Many associations collect consent in structurally similar ways. A membership form that requires agreement to a broadly worded data use policy in order to complete registration, or a conference registration process that bundles consent to marketing communications with the registration itself, may face the same 'forced action' objection if regulators review the design of the process.

The lesson is not that associations cannot require some data sharing to deliver services. It's that the specific purposes must be clearly stated, and consent for uses beyond service delivery, especially AI processing, must be genuinely separable.

The Ruling Applies to More Than Just OpenAI

The investigation was prompted by OpenAI's conduct, but the Privacy Commissioner used the findings to articulate principles about AI data collection that apply broadly. As reported by CBC News, regulators noted that organizations cannot assume public availability of information means implied consent to its use for AI training purposes.

For associations, this has immediate implications. If your association has enabled AI features in Microsoft 365 that process member communications, documents, or interaction data, that processing may constitute a new use of personal information that was not disclosed when members originally consented. If you're using an AI-powered membership management tool, you're likely a downstream user of a system built on the same kind of data collection that regulators just ruled unlawful.

Cypher Systems offers AI governance consulting for Ottawa organizations and associations specifically to help nonprofits understand how AI tools in their environment process member data, and what obligations that creates under PIPEDA and emerging federal privacy legislation.

The Joint Investigation Signals Coordinated Enforcement

The involvement of four privacy bodies in a single investigation is notable. Canada's privacy landscape has historically been fragmented, with federal and provincial bodies operating independently and sometimes reaching different conclusions. The fact that all four reached the same findings on OpenAI suggests an emerging coordination that associations with members across provincial boundaries will need to account for.

If your association is subject to Quebec's Law 25, which applies to any organization with Quebec members or operations, the coordination between federal and Quebec regulators is particularly relevant. Practices that satisfy PIPEDA may still require additional steps under Law 25, and regulators are demonstrably communicating with each other about their investigations.

What Nonprofit Associations Should Review Following This Ruling

The OpenAI findings provide a useful checklist for associations reviewing their own AI practices. 

  1. Identify every AI-enabled tool in your environment that processes member data. This includes platforms with AI features that may be enabled by default, not just tools you deliberately deployed as AI products.
  2. Review the consent language members agreed to when joining or renewing. Does it specifically mention AI processing? Does it describe automated decision-making, model training, or the use of member communications to personalize AI outputs?
  3. Evaluate whether any consent in your membership flow is 'forced,' meaning access to the core service is unavailable without agreeing to AI processing uses. If so, consider decoupling those consents.
  4. Ensure members have a clear mechanism to request information about what data is processed by AI tools, and to request deletion where applicable.

Our IT services for nonprofit associations include the technology assessment and vendor management support needed to give associations a clear picture of what AI tools are operating in their environment and what data flows are involved. Combined with our cybersecurity services, this gives your organization the foundation to respond to regulatory expectations rather than react to them.

To talk through what this ruling means for your specific technology environment, contact Cypher Systems at (613) 800-7654 or book a meeting with us. 

Gabriel Rapacz

Gabriel Rapacz

Vice President and Co-Owner, Cypher Systems
Gabriel Rapacz has been working in IT since 2013, starting during university before joining Cypher Systems full-time in 2017. He brings a well-rounded, hands-on approach with experience across support, infrastructure, and cybersecurity.

He believes IT is ultimately about supporting people, not just technology. Gabriel focuses on making systems approachable and effective for each client and their team, adapting to different levels of comfort and experience.

With a strong interest in cybersecurity, Gabriel stays current on emerging threats and attacker tactics, helping clients stay protected in an evolving landscape.
Connect with Gabriel on Linkedin
linkedin facebook pinterest youtube rss twitter instagram facebook-blank rss-blank linkedin-blank pinterest youtube twitter instagram