Canada’s privacy commissioner ruled on May 28, 2026 that OpenAI violated federal private-sector privacy law while building and operating ChatGPT. The decision, the product of a joint federal and provincial investigation, found that the company collected personal information without valid consent, gathered more data than it needed, and handled children’s data without proper authorization.
The Findings
The investigation centered on three failures that regulators described as systemic rather than incidental.
- Overcollection: personal information was gathered and retained well beyond what the service required
- No valid consent: the regulator rejected reliance on publicly available web data as a lawful basis for training
- Children’s data: information about minors was processed without parental consent or meaningful age assurance
- Transparency gaps: users were not clearly told how their conversations and data would be used
How the Investigation Unfolded
The inquiry opened after a complaint from a Canadian privacy advocacy group and was widened into a joint effort with a provincial commissioner. Investigators examined the data pipeline that fed ChatGPT’s training corpus, reviewed internal retention practices and interviewed OpenAI representatives before issuing the determination this spring.
OpenAI’s Response
OpenAI said it had already introduced controls that let users turn off training on their chats and delete conversation history, and argued that its practices were consistent with its publicly posted policies. The company is expected to contest parts of the reasoning and can seek a review in Federal Court.
What Canada Can Enforce
Canadian private-sector privacy law does not carry fines on the scale of Europe’s GDPR. The commissioner issues findings and recommendations, and non-compliance can be escalated to Federal Court, which can order remedies. That makes the ruling more of a binding signal than an immediate punishment.
Industry Fallout
The decision lands amid parallel scrutiny in Europe, Brazil and several US states, where regulators have questioned whether scraping the open web can ever supply valid consent for model training. For AI developers, the practical effect is a rising expectation of consent flows, data minimization and special handling for minors.
What This Means
Canada’s ruling does not settle the global consent debate, but it pushes it in one direction: regulators increasingly expect AI companies to justify what they collected, prove consent was meaningful and protect children by default. For OpenAI, the cost is likely to be operational rather than financial, in the form of new consent screens, deletion pipelines and age checks.