Professional-services firms should not treat public-web training, chatbot interactions, or vendor privacy claims as abstract AI-policy debates. When client or employee personal information enters an AI workflow, Canadian privacy regulators can ask whether the purpose, consent, openness, accuracy, retention, and accountability controls are defensible.
The joint investigation examined OpenAI personal-information collection, use, disclosure, consent, openness, accuracy, access and correction, retention and disposal, and accountability under Canadian private-sector privacy laws. The overview says the findings remain relevant to later OpenAI AI services even though the investigation focused on GPT-3.5 and GPT-4.
Confidence and caveat. Strong Canadian privacy-regulator source from the OPC, OIPC BC, CAI, and OIPC Alberta. The finding concerns OpenAI and older GPT models, so apply it as privacy-risk guidance rather than as a blanket statement about every vendor or current model.
Cited in. Framework; Shadow AI; Sources