Canadian Regulators Find OpenAI Violated Privacy Laws

A joint investigation by the Office of the Privacy Commissioner of Canada (OPC) and the provincial privacy commissioners of Alberta, Quebec and British Columbia concluded that OpenAI's early development and training of ChatGPT models did not comply with federal and provincial privacy laws, the offices said in a joint report released May 6, 2026. The regulators identified alleged violations including overcollection of personal information, use without valid consent, and shortcomings in data-subject access and correction, according to the report (OPC, OIPC Alberta, CAI Quebec, OIPC BC). The report examined ChatGPT 3.5 and ChatGPT 4 as they existed in 2023. Privacy Commissioner Philippe Dufresne is quoted saying OpenAI "launched ChatGPT without having fully addressed known privacy issues," per IAPP. The regulators also noted OpenAI cooperated during the probe and has implemented or committed to measures such as retiring earlier models, deploying a filtering tool to mask personal data in training sets, and timed notice and data-export improvements, the offices said.
For teams building or fine-tuning models on scraped or licensed data, this joint Canadian finding is one of the more concrete regulatory rulings yet on what "lawful" training data collection actually requires: documented purpose, valid consent mechanisms, and working access/correction/deletion pathways for personal information swept into a training corpus, not just after-the-fact filtering.
What happened
A joint investigation by the Office of the Privacy Commissioner of Canada (OPC) and the provincial privacy commissioners for Alberta, Quebec, and British Columbia concluded that OpenAI's early training and deployment of ChatGPT models did not comply with federal and provincial privacy laws, according to the joint report published May 6, 2026 (OPC; OIPC Alberta; CAI Quebec; OIPC BC). The investigation examined the versions of the product in use when the probe began in April 2023, including ChatGPT 3.5 and ChatGPT 4 (OIPC Alberta). The regulators identified alleged problems including overcollection of personal information, use without valid consent, and shortfalls in data-subject access, correction, and deletion, according to the joint findings (IAPP; OPC). Privacy Commissioner Philippe Dufresne is quoted saying OpenAI "launched ChatGPT without having fully addressed known privacy issues," per IAPP. The report records that OpenAI engaged with the investigation and has implemented or committed to a set of privacy-protective steps, including retiring earlier models deemed noncompliant, using a filtering tool to detect and mask personal information in publicly available and licensed training datasets, and clarifying user notices and export tools within specified timeframes (Engadget; OPC overview).
Technical context
The regulators focused on data provenance and lifecycle controls that matter for model-training compliance: whether personal data was lawfully collected, whether notice and consent practices covered scraped or third-party data, and whether mechanisms existed to locate, correct, or delete individuals' records once incorporated into training corpora. These are common technical-compliance touchpoints across jurisdictions now enforcing privacy law against large-scale machine learning projects.
Regulatory context
This joint enforcement action is one of the more prominent cross-jurisdictional privacy findings against an AI model developer, and it frames privacy risk in model training as an actionable regulatory concern rather than a theoretical one. For practitioners building or managing training pipelines, the regulators' emphasis on provenance, masking and filtering tools, and data-subject access aligns with ongoing legal debates under PIPEDA and comparable provincial statutes.
What to watch
Observers should track how the OPC and provincial offices follow up on the report's recommendations and timelines, whether other national regulators cite the findings, and how OpenAI implements or measures the effectiveness of its filtering and dataset-retirement controls. Also watch for updates to user-facing notices and data-export functionality described in the joint findings, and whether independent reviews assess the sufficiency of OpenAI's claimed mitigations.
Editorial analysis
The finding is notable less for its penalty (the regulators secured commitments rather than a fine) than for establishing, in a detailed 122-page report, a specific compliance checklist for training-data provenance and consent that other privacy regulators can reference. Teams elsewhere that scrape or license data for model training should read the report's Issues 1-7 as a preview of the questions their own regulators are increasingly likely to ask.
Key Points
- 1Joint Canadian regulators found OpenAI's 2023 training of ChatGPT models violated federal and provincial privacy laws, per the May 6, 2026 report.
- 2Regulators highlighted overcollection, use without valid consent, and data-subject access failures, underscoring provenance and lifecycle control gaps for training data.
- 3Industry observers should expect increased scrutiny on dataset provenance, masking tools, and demonstrable access/correction mechanisms for ML training pipelines.
Scoring Rationale
This joint federal-provincial enforcement finding is a notable regulatory precedent for model training privacy and will matter to teams handling large scraped or licensed datasets; the score is moderated for freshness because the principal report was published May 6, 2026.
Sources
Primary source and supporting public references used for this report.
View 7 more sources
- [PDF] Joint investigation of OpenAI OpCo, LLCoipc.bc.ca
- PIPEDA Findings #2026-002: Joint Investigation of OpenAI OpCo, LLC - Office of the Privacy Commissioner of Canadapriv.gc.ca
- Investigation by Canadian privacy authorities into OpenAI results in ...oipc.ab.ca
- Probe finds ChatGPT's model training violated Canada's federal, provincial privacy lawsiapp.org
- Canadian Officials Claim OpenAI Violated Federal And Provincial Privacy Lawsengadget.com
- OpenAI violated Canadian privacy laws, federal and provincial ...betakit.com
- OpenAI violated Canadians’ privacy, watchdogs say in call for legal reformglobalnews.ca
Practice with real Ad Tech data
90 SQL & Python problems · 15 industry datasets
250 free problems · No credit card
See all Ad Tech problems
