Responsible AI guide
Assessing generative AI privacy risk in Canada
Before a Canadian business uses generative AI with customer, employee, operational, or confidential information, it should map the data flow, purpose, legal authority, provider terms, storage, retention, model training, access, logging, deletion, output risk, human review, and incident process. Public tools should not receive sensitive data by default.
Know what enters and leaves the system
Limit people, tools, and connected sources
Validate decisions and external outputs
Map the use case before selecting a tool
Define the business outcome, users, input data, connected systems, outputs, affected people, decisions, retention, and accountable owner. Reject uses where the risk cannot be controlled or the benefit is unclear.
Classify personal, confidential, privileged, regulated, copyrighted, and security-sensitive information before employees experiment.
Assess the provider and configuration
Review contract terms, data location, subprocessors, encryption, administrator access, model-training settings, deletion, logging, identity integration, incident notification, export, and termination.
Use enterprise controls where the risk warrants them. A paid logo does not prove that the configured service meets the organization's requirements.
Control the operating process
Define permitted uses, prohibited data, human review, accuracy testing, disclosure, records, prompt-injection resistance, connected-tool permissions, output handling, incident reporting, and periodic review.
Test with representative but non-sensitive data before expanding access. Monitor behaviour after model, policy, connector, or provider changes.
Primary sources
This page separates sourced facts from North Star's operational guidance. Check the current source before relying on a changing price, rule, list, or technical standard.
Questions businesses ask
Can employees paste customer information into public AI tools?
Not by default. The organization should assess purpose, authority, provider handling, retention, access, security, and disclosure before permitting personal or confidential data.
Does human review solve every AI risk?
No. Human review is one control and must be supported by appropriate data, access, vendor, testing, logging, and incident controls.
Should every AI use require a full impact assessment?
Use a documented risk-screening process to determine the depth of review appropriate to the data, decision, people affected, integration, and potential harm.
Turn the research into an operating plan
North Star can help assess the environment, define scope, document ownership, implement controls, and verify the result.
Plan secure AI automation