If you read that Canada’s privacy regulators ruled against ChatGPT and wondered what it means for your business, the short answer is: not much. The rules that do apply to you are older, shorter and easier to act on. Most small businesses have never read them.
What the finding was actually about
It was about how OpenAI built its models. On May 6, 2026, the federal Privacy Commissioner, together with the Quebec, British Columbia and Alberta regulators, published the results of a joint investigation into OpenAI.
On training data taken from public websites and licensed datasets, they found the complaint “well-founded and conditionally resolved.” OpenAI hadn’t obtained valid consent for that collection, and it agreed to changes.
On training with users’ own conversations, they found the complaint “not-well founded.” Their reason was that OpenAI lets account holders “choose whether their interactions with ChatGPT would be used for model training,” along with other safeguards.
Nothing in the finding addresses businesses whose staff use ChatGPT, or what staff type into it. If you’ve seen it summarized as a warning to employers, the summary added that.
The rules that are about you
They were published in December 2023, by the same regulators. The Principles for responsible, trustworthy and privacy-protective generative AI technologies have a list of duties for “organizations using generative AI.” The regulators are careful to say that while the document uses “should,” “many of the considerations listed will be required for an organization to comply with applicable privacy law.”
Here are the ones a small business meets first, in their words:
- What goes into a prompt. “Where personal information (and, in particular, sensitive or confidential information) must be entered into a prompt, only do so where authorised.” And “where possible and reasonable, use anonymized or de-identified information within prompts.”
- What happens to prompts. “Unless otherwise required, prompts should not be retained, used for secondary purposes, or disclosed.”
- Who is responsible. “Accountability for decisions rests with the organization, and not with any kind of automated system used to support the decision-making process.”
- Telling people. “Clearly communicate to any affected party whether a generative AI tool will be used as part of a decision-making process.”
- Checking the output. “Take reasonable steps to ensure that any outputs from a generative AI tool are accurate as necessary for the purpose.”
- Somewhere to ask. “Establish a mechanism by which the organization can receive and respond to privacy-related questions or complaints.”
Why this matters now
Your staff are already making these decisions, one prompt at a time. Okta’s 2026 survey found that about half of Canadian office workers who use AI use tools their employer never approved. Across all seven countries in that survey, among workers using unapproved tools, 54% had put in internal emails and messages and 45% HR information.
Nobody authorized any of that, which is exactly the word the principles turn on. Nobody refused it either. Nobody was asked.
It fits on one page
Each duty above is already a line in a one-page AI policy. “Only where authorized” is the section that says what never goes in without a named person’s say-so. Accountability is the rule that a person checks anything AI helped produce, and their name goes on it. The complaints mechanism is the “where to ask” line with a real name and a real answer within a day.
If you don’t have that page yet, the template is here. Fill in the named tools and the named person, brief it in person, and you’ve done most of what the regulators ask of a business your size.
One caution. This is a plain-English reading of public guidance, not legal advice. Obligations vary by organization and province, and a lawyer should review anything that touches sensitive personal information at scale.