Doing Business In..._2026

CANADA Trends and Developments Contributed by: Brent Arnold, Carole Piovesan, Tamara Adler, Michael Pascu and Dilan Brar, INQ Law

identified, assessed, managed and revisited as the business, technology, and data uses evolve. Vendor and cloud governance A related trend is that vendor and cloud governance are now central to data compliance risks. For most businesses, data flows through cloud providers, like software-as-a-service (SaaS) tools and other out - sourced services. Recent breach incidents, including the PowerSchool breach, which affected at least 80 Canadian school boards across seven provinces and one territory, illustrate how a single technology vendor incident can create broad, multi-jurisdictional privacy and governance consequences. These incidents explain why regulators and custom - ers scrutinise third-party vendors, credential con - trols, breach response, contractual protections, and understanding of where sensitive info sits in vendor ecosystems. Bill C-36 adds to this trend by signal - ling heightened expectations regarding the personal information of minors, reinforcing the need for busi - nesses to maintain clear records of data flows, service providers, cross-border transfers, and other related data-handling obligations. Age verification method - ologies are expected. Vendor management remains a core part of pri - vacy, security and accountability. Businesses need to flow through appropriate security and data han - dling requirements to third and fourth party vendors. In addition, they need to show they understand and document how vendors handle sensitive information, because vendor choices increasingly affect legal com - pliance, breach exposure, customer trust, and a busi - ness’s ability to show control over its data. AI trends in data governance AI is also driving a slowly emerging trend towards stronger data governance. This reflects the opera - tional reality that AI systems depend on accurate, reli - able, and well-governed data to produce the insights businesses are seeking. As a result, AI governance is being built not only through AI-specific rules, but through existing privacy laws, regulator guidance, procurement requirements, sector expectations, cybersecurity controls, and contracts that address

key privacy considerations, including legal authority for use, retention periods, and oversight. For businesses adopting AI at scale, the key questions are not just about the tool’s legality but also about data use, purpose, authority, safeguards, transpar - ency, and human review. Overall, it is apparent that AI is making data governance harder to avoid. Busi - nesses that cannot explain what data they have, where it came from, how it can be used, and who is accountable for the output will struggle to move AI from experimentation to reliable adoption. Regulators are also becoming increasingly critical of how AI is developed and used. For example, the federal, British Columbia and Alberta Privacy Com - missioners’ Offices jointly found that the development of some of OpenAI’s ChatGPT models contravened PIPEDA and the Personal Information Protection Acts of British Columbia and Alberta, and Quebec’s pri - vate-sector Privacy Act. Businesses will need to be increasingly aware of not only their own data practices but stay abreast of the practices of AI developers, to be able to responsibly procure AI tools in a privacy- complaint manner. Some businesses are pushing ahead with AI pilots despite poor data governance, unclear data owner - ship, weak retention practices, incomplete inven - tories, and limited oversight; this helps explain why many pilots are expensive, difficult to scale up, and ultimately unsuccessful. Other businesses remain stationary: they want to adopt AI, but hesitate to do the unglamorous data- governance work required to make it viable, includ - ing mapping and cleaning data, confirming authority for secondary use, reviewing vendor contracts, and assigning accountability for AI-generated outputs. In practice, businesses that move the fastest will not be the ones that implement the most AI tools, but the ones that recognise that data-governance readiness is the foundation of AI readiness, and invest accordingly. Cross-Border Data Considerations Canada’s federal privacy framework was built to be permissive. It does not prohibit transferring person -

156 CHAMBERS.COM

Powered by