← Blog

Canada AIDA LLM Requirements: The Current Baseline for AI Traffic

Parminder Singh
Parminder Singh··7 min read
Summarize with AI

Canada has no AIDA requirements for LLMs because Bill C-27 died before passage. The current baseline comes from privacy and public-sector rules already in force: PIPEDA accountability, appropriate purposes, consent, limiting use and disclosure, safeguards and breach records; Quebec Law 25 duties where applicable; and federal guidance and automated-decision rules for government institutions. This guide attaches those duties to the outbound prompt and inbound response.

Compliance & Regulationai-complianceai-governancecomplianceregulationllmpolicy-enforcement
Canada AIDA LLM Requirements: The Current Baseline for AI Traffic

Canada has no AIDA requirements for LLMs. The proposed Artificial Intelligence and Data Act formed Part 3 of Bill C-27, and Parliament's historical record shows the bill stalled in committee when Parliament was prorogued on 6 January 2025.

The current baseline begins with existing law. A Canadian business sending personal information in an LLM prompt may face PIPEDA or a substantially similar provincial statute. Quebec enterprises have project and transfer duties. They also have requirements for automated decisions. Federal institutions have government policy requirements for generative AI and covered administrative decisions.

TL;DR

  • AIDA never passed, so a vendor claiming present "AIDA-compliant LLMs" is describing a dead bill.
  • PIPEDA requires accountability and appropriate purposes where it applies. It also requires meaningful consent and limited handling, along with safeguards, access, and breach records.
  • An LLM request needs a recorded purpose and authorizing identity. The record also needs the content category, processor, destination, retention position, and policy result.
  • Quebec adds privacy impact assessments where its private-sector law applies. It also establishes rights around exclusively automated decisions.
  • Federal institutions should follow the government generative-AI guide within its scope. The automated-decision directive applies within a separate scope.

PIPEDA applies to the processing operation

The Personal Information Protection and Electronic Documents Act governs personal information in commercial activities within its scope. Provincial private-sector laws can replace it for intraprovincial activity when declared substantially similar, while PIPEDA continues to matter for federally regulated organizations and interprovincial or international flows. Scoping belongs in the legal file.

For an LLM call, the processing operation is concrete: an authenticated person or agent assembles context and sends an HTTPS request to a model endpoint. The person or agent then receives output and passes that output to another system or person. Each step may collect or use personal information. It may also disclose that information.

The required inventory should therefore reach request level. Record the purpose and data categories. Record the identity and role, along with the model provider. Also record the endpoint region, provider use and retention terms, output destination, access controls, and deletion rule. A contract inventory gives the processor relationship. It cannot show which customer record appeared in a Tuesday afternoon prompt.

Purpose and consent travel with a minimized prompt

PIPEDA requires purposes to be identified at or before collection and requires knowledge and consent, subject to statutory exceptions. Its limiting principles constrain collection and use. They also constrain disclosure and retention. The Act also restricts handling to purposes a reasonable person would consider appropriate in the circumstances.

Applied to LLM traffic, these rules require more than an approved vendor. The organization needs to know which purpose authorizes the prompt and which fields are necessary. It also needs to know who may send them and which destination may receive them. The OPC's meaningful-consent guidance emphasizes the personal information collected and the receiving parties. It also emphasizes purposes and meaningful risks.

Picture a claims adjuster dragging a 27-page PDF into a chat window to summarize one paragraph. The physical act takes a second; the disclosure can include names, addresses, medical details, signatures, and account numbers that the task never required. Prompt-level classification and redaction are the controls that turn minimization into an enforceable decision. The AI consent-enforcement article covers that policy link.

Safeguards belong on the AI egress path

PIPEDA's safeguards principle requires protection appropriate to sensitivity against loss, theft, unauthorized access, disclosure, copying, use, or modification. Encryption in transit answers one part of that requirement. An encrypted request sent to an unauthorized model is still a completed disclosure.

The egress control should evaluate the application-supplied identity and role before transmission. It should also evaluate prompt classification and approved purpose. The model and region require evaluation as well. Outcomes can include permit, redact, route to an approved endpoint, or refuse. This is where an AI usage policy becomes an operating safeguard.

AI data classification explains the content layer, while AI policy enforcement at the HTTP layer covers the decision point. The enforcement boundary is specific to HTTP prompts and responses routed through the control. Local inference and files copied before prompt construction require separate safeguards. Stolen credentials used on an unmonitored route and model training performed by the provider do too.

Access and correction duties shape breach records

PIPEDA's individual-access principle covers personal information about the requester and an account of its use and disclosure, subject to statutory limits. LLM operations complicate that response when the organization retains only token counts and model names. A useful record identifies the content category and processor. It identifies the destination, purpose, and time as well. It also identifies the authorizing identity without turning the audit store into an uncontrolled second copy of every prompt.

PIPEDA's breach provisions govern failures of security safeguards. A real risk of significant harm triggers reporting to the Privacy Commissioner. It also triggers notice to affected individuals as soon as feasible. Every breach requires a record, and the federal regulations set a 24-month retention period for that breach record.

The Canada AIDA audit-evidence guide shows how those records support a Canadian review. Operational logs should support the incident file while following a deliberate retention and access policy of their own.

Quebec adds requirements beyond the federal baseline

An enterprise subject to Quebec's private-sector privacy statute should test the separate duties in the official consolidated law.

The project provision requires a privacy impact assessment at the outset of a covered acquisition or development of an information system or electronic service involving personal information. It also applies to a covered overhaul of such a system or service. The transfer provision requires an assessment before communicating personal information outside Quebec and permits the communication only where the assessment establishes adequate protection. A multi-region LLM router needs destination evidence per request to support that file.

The automated-decision provision covers a decision based exclusively on automated processing of personal information. It requires notice by the time the person is informed of the decision. On request, it also requires information about the personal information used. The organization must provide the reasons and principal factors and parameters behind the result, plus an opportunity to submit observations to someone able to review it.

The duties have different triggers, and the Canada AIDA controls mapping ties each one to a distinct control point.

Federal institutions have government-specific rules

The Treasury Board of Canada Secretariat's Guide on the use of generative AI tells federal institutions to assess and mitigate risks before use and protect personal and sensitive information. It also tells them to involve legal and privacy stakeholders for relevant deployments, along with security and other stakeholders. It supports existing federal law and policy rather than creating a general rule for Canadian companies.

Covered systems that make or support federal administrative decisions also fall within the Directive on Automated Decision-Making. The government's automated decision-making portal links the Algorithmic Impact Assessment, scope guide, completed assessments, and peer-review guidance.

For LLMs, the key scoping question is the function inside the workflow. A drafting assistant and a system supporting an eligibility determination carry different obligations. My candid view is that procurement teams spend too much time on the model brand and too little on the decision the output enters.

A current LLM baseline in seven records

A practical Canadian baseline produces seven connected records for each approved LLM use case:

  • A purpose record naming the task and its basis under law or consent.
  • A data map naming prompt sources and categories. It also names the processor, region, output recipient, and retention.
  • A vendor record covering instructions and provider use. It also covers subcontractors, security, deletion, and incident terms.
  • A project or transfer assessment where the applicable law requires one.
  • An identity-bound request decision showing classification and destination. It also shows the policy version and outcome.
  • A decision-lineage record where an output affects an individual.
  • A breach record and escalation path that can apply the real-risk-of-significant-harm test.

The list deliberately starts with current obligations and operating facts. AIDA's proposed high-impact regime may still be useful as historical policy material, but labeling that proposal as Canadian law creates a false requirement and hides the duties already enforceable.

DeepInspect

DeepInspect turns the outbound LLM request into an enforcement point. For routed HTTP traffic, it evaluates application-supplied identity and role and classifies the prompt. It checks model and destination policy, then can permit, redact, route, or refuse before transmission.

Every decision produces a signed, tamper-evident record outside the calling application's write path. That record contributes operating evidence for safeguards and processor tracking. It also provides destination tracking. The record supports access reconstruction and automated-decision lineage. It can support breach investigation as well. It stays within the prompt-and-response channel and leaves the wider privacy program with its proper owners.

Book a technical deep dive at deepinspect.ai.

Frequently asked questions

Is there a Canadian certification for an AIDA-compliant LLM?

No statutory AIDA certification exists because AIDA never became law. A provider can map controls to the former proposal as a voluntary exercise, but the label has no current legal status. Buyers should ask which live privacy and sector duties apply to the deployment. They should also ask about provincial and public-sector duties and request evidence tied to those duties.

Does a provider's zero-retention setting resolve PIPEDA requirements?

A zero-retention term can reduce provider-side persistence and secondary-use risk while leaving the original disclosure in scope. The organization still needs an appropriate purpose. It also needs valid consent or another lawful basis where available. The remaining requirements include minimization and safeguards, plus accountability and an account of the recipient. Record the setting as one safeguard among several, then verify that the actual endpoint and account configuration used it.

Where does DeepInspect fit in the Canadian LLM baseline?

DeepInspect covers HTTP AI traffic routed through it between authenticated users or agents and LLM endpoints. It can evaluate identity-bound content and destination against model policy before forwarding and produce a record of the outcome. Vendor contracting and legal basis remain with the organization. Consent collection and upstream data quality remain there too. Local inference and human review remain with the organization. Public-sector impact assessment does too.