← Back to Insights
Compliance Education

Employee data and Canadian privacy law: What SMB owners get wrong

HR files aren't exempt from Law 25 or PIPEDA. Here's what Canadian small business owners get wrong about employee data — and how to fix it cheaply.

By Augure·
Canadian technology and compliance

Employee data and Canadian privacy law: What SMB owners get wrong

Most small business owners think privacy law is about customer data. That's only half the picture. If you have employees, you have a filing cabinet, real or digital, full of information Canadian privacy law cares about a great deal. SIN numbers. Medical notes. Performance reviews. Direct deposit details. Quebec's privacy law treats employee files as seriously as customer files. Businesses that get this wrong usually aren't being careless. They just never thought to ask.

An AI tool matters more here than people expect. If you're using a chatbot to summarize a termination letter or draft a performance review, that employee's data is going somewhere. Where it goes is the question nobody in HR ever gets asked to answer.

Is employee data actually covered?

Here's the part that trips people up: PIPEDA, the federal privacy law, mostly does not cover employee records for provincially regulated businesses. It covers customer data. If you're a nine-person marketing agency in Ontario, your client list falls under PIPEDA. Your staff files, in most cases, do not.

That gap doesn't mean employee data is unregulated. Quebec closed it directly. Quebec's privacy law applies to employee information the same way it applies to customer information, with no carve-out. British Columbia and Alberta have their own private-sector privacy laws with similar employee coverage. Ontario has no general private-sector law yet, which is exactly why so many Ontario owners assume nothing applies to them. Something usually does, once you count sector-specific rules and plain old negligence liability.

Treating "PIPEDA doesn't cover this" as "nothing covers this" is the mistake. Wrong conclusion, common one.

There's a second wrinkle. If you're federally regulated, a bank, an airline, a telecom, PIPEDA does cover your employees directly, no gap to close. Most nine-person businesses aren't in that category, but check before assuming the general rule applies to you. The test isn't your province, it's your sector.

What information actually counts as sensitive?

People picture social insurance numbers and medical leave forms. Fair, those count. But the list is longer and weirder than that:

  • Performance reviews and disciplinary records
  • Salary history and banking details for payroll
  • Health information tied to accommodation requests or sick leave
  • Immigration and work permit status
  • Emergency contact information for family members who never agreed to anything

That last one surprises people every time. If an employee lists a spouse's cell number as an emergency contact, that spouse is now a data subject in your HR system, whether anyone meant for that to happen or not.

What does a breach actually cost?

This is where owners start paying attention. Quebec's privacy law allows penalties up to $10 million or 2% of worldwide turnover, whichever is higher, for the most serious violations. Most SMB cases never hit that ceiling. But even a modest incident, a leaked spreadsheet, an unencrypted laptop stolen from a car, triggers mandatory notification to Quebec's regulator and to affected employees if there's a real risk of harm.

A single leaked HR spreadsheet can trigger the same notification duty as a full-blown ransomware attack.

That surprises people. The trigger is about whether the information was sensitive and whether the exposure created real risk, not about scale. A ten-person company can trip this wire as easily as a thousand-person one.

Here's what that process actually involves once it's triggered. You assess the risk within a reasonable window, notify Quebec's regulator with a description of what happened, then notify each affected employee directly, not by posting a notice somewhere and hoping. You also have to keep an internal log of every incident that met the threshold, even ones you decided not to report, in case the regulator asks later. None of that requires a lawyer on retainer, but it does require someone who knows the steps before the day they're needed, not after.

The other cost is quieter. An employee finds out their medical note got pasted into a general-purpose AI tool that may keep the input to train its next model, and now doesn't trust HR at all. No fine attached to that. Still expensive.

Where do AI tools fit into this?

Increasingly, this is where employee data actually leaks. Someone in HR pastes a termination letter into a chatbot to soften the tone. Someone else uploads a stack of résumés to summarize candidates faster. Reasonable instinct, real exposure.

The question to ask before doing either isn't "is this tool good." It's "where does this data go, and does anyone use it to train something else." Many US-based AI tools reserve the right to use free-tier input for training, and route processing through infrastructure under US jurisdiction, which matters if your own cross-border transfer obligations apply to that data flow.

A skeptical owner might ask: if the data touches EU servers at all, isn't that just a different foreign jurisdiction problem? Fair question. The answer depends on what you're assessing transfers against, not on the geography being automatically better or worse.

A genuinely Canadian AI tool changes that calculation. Augure is Canadian, starts free, and stores customer data in Canada, as Canadian privacy regulation requires. It never uses customer data to train models. AI inference for customer content runs on Canadian infrastructure, with vetted EU partners handling certain model tiers and failover under zero-data-retention agreements, and is never routed to providers in the United States. Some flows still touch US infrastructure regardless, payment processing and email delivery among them, and that's disclosed plainly in the privacy policy rather than glossed over.

Augure has no US corporate parent and no US investors. Customer conversations, documents, and AI inference aren't handled by US-jurisdiction providers, so the CLOUD Act's reach over those providers doesn't extend to that content.

None of that guarantees you're compliant. No vendor can promise that. It does mean the tool drafting your HR letter isn't the weak link in your own privacy obligations.

Do I need a written policy for this?

Yes, and it doesn't need to be long. A one-page employee privacy notice covering what you collect, why, how long you keep it, and who can access it does most of the legal work. Pair it with a retention schedule: delete résumés after twelve months if the candidate wasn't hired, delete termination files after the period your employment lawyer recommends. That covers the basics regulators actually check for.

The businesses that get flagged aren't usually the ones with imperfect policies. They're the ones with none.

What to do this week

  1. List what employee data you actually hold — payroll, health notes, reviews, emergency contacts — and where each piece lives.
  2. Check what tools touch that data, especially AI tools, and confirm none of them train on your input by default.
  3. Write a one-page retention rule: what gets deleted, when, and who's responsible for doing it.

Start with Augure's Chat product on the free tier if you want to test document handling on real policy files before committing to anything. See how it handles a real HR document, then decide.

More detail on all of this lives at augureai.ca.

Where this comes from: Quebec's Act respecting the protection of personal information in the private sector, s. 3.

A

About Augure

Augure is a sovereign AI platform for regulated Canadian organizations. Chat, knowledge base, and compliance tools — all running on Canadian infrastructure.

Ready to try sovereign AI?

Start free. No credit card required.

Get Started