Canada's privacy commissioner launches an investigation into OpenAI in response to a complaint alleging the non-consensual collection and use of personal data
Context & Ripple Effects
This investigation is Canada joining the first wave of national privacy regulators turning their attention to OpenAI. Weeks after this launch, MIT Technology Review mapped the legal stakes of training models on people's data without consent under strict regimes like the EU's legal stakes in the EU, and the Verge dug into the unresolved questions around future scraping and 'right to be forgotten' requests that make these probes hard for any lab to close quickly.
Since then the pattern has only intensified: Italy's data protection authority concluded a months-long probe saying OpenAI is suspected of violating EU privacy rules suspected of violating EU privacy rules, noyb filed a GDPR complaint in Austria over ChatGPT outputting incorrect personal details about an individual GDPR complaint in Austria, and by 2026 Canada itself reported Sam Altman agreeing to immediate safety-protocol steps around notifying police of suspicious ChatGPT use agreed to strengthen safety protocols — evidence that Canadian engagement with OpenAI outlasted this initial complaint.
First-order effects
- OpenAI now has a formal national-level inquiry into whether its training and use of personal data happened without consent, putting its data-collection practices under official Canadian review rather than just public criticism.
- The original complainant gains a state-backed channel: the commissioner's findings will determine whether OpenAI must change practices or face enforcement in Canada.
Second-order effects
- OpenAI faces a multi-jurisdiction squeeze — Italy's regulator already suspects GDPR violations and noyb has complained in Austria — so a Canadian finding adds pressure to adopt consent-based data handling globally rather than market by market.
- Rival model developers watch closely, because the outcome sets the template for how their own scraped-web training pipelines will be judged by privacy authorities.
Third-order effects
- If the pattern holds, consent for training data becomes a compliance requirement rather than a debate — reshaping how foundation models are built, including how labs handle deletion requests and future scraping, as the GDPR-risk reporting anticipated.
- Privacy regulators appear to be converging on generative AI as a shared enforcement target, pointing toward coordinated international scrutiny that no single lab can settle jurisdiction by jurisdiction.
The trend: National data protection authorities worldwide are making non-consensual training data the first major regulatory front for generative AI, forcing labs from OpenAI downward toward auditable, consent-based data pipelines.