Responsible AI guide

Assessing generative AI privacy risk in Canada

Before a Canadian business uses generative AI with customer, employee, operational, or confidential information, it should map the data flow, purpose, legal authority, provider terms, storage, retention, model training, access, logging, deletion, output risk, human review, and incident process. Public tools should not receive sensitive data by default.

Data flow

Know what enters and leaves the system

Minimum access

Limit people, tools, and connected sources

Human review

Validate decisions and external outputs

Map the use case before selecting a tool

Define the business outcome, users, input data, connected systems, outputs, affected people, decisions, retention, and accountable owner. Reject uses where the risk cannot be controlled or the benefit is unclear.

Classify personal, confidential, privileged, regulated, copyrighted, and security-sensitive information before employees experiment.

Assess the provider and configuration

Review contract terms, data location, subprocessors, encryption, administrator access, model-training settings, deletion, logging, identity integration, incident notification, export, and termination.

Use enterprise controls where the risk warrants them. A paid logo does not prove that the configured service meets the organization's requirements.

Control the operating process

Define permitted uses, prohibited data, human review, accuracy testing, disclosure, records, prompt-injection resistance, connected-tool permissions, output handling, incident reporting, and periodic review.

Test with representative but non-sensitive data before expanding access. Monitor behaviour after model, policy, connector, or provider changes.

Primary sources

This page separates sourced facts from North Star's operational guidance. Check the current source before relying on a changing price, rule, list, or technical standard.

Questions businesses ask

Can employees paste customer information into public AI tools?

Not by default. The organization should assess purpose, authority, provider handling, retention, access, security, and disclosure before permitting personal or confidential data.

Does human review solve every AI risk?

No. Human review is one control and must be supported by appropriate data, access, vendor, testing, logging, and incident controls.

Should every AI use require a full impact assessment?

Use a documented risk-screening process to determine the depth of review appropriate to the data, decision, people affected, integration, and potential harm.

Turn the research into an operating plan

North Star can help assess the environment, define scope, document ownership, implement controls, and verify the result.

Plan secure AI automation