There is a version of the privacy conversation that a business can have in an afternoon, and it goes: where does the data sit. Canada or the United States, this region or that one, and once residency is settled everyone feels the matter is handled.

Residency is real and well covered. It is also the easiest question in the set, because it has a binary answer and a technical fix. The obligations that actually govern what a business can do with AI are quieter and harder to point at. What did you tell people you were collecting their information for. Does that cover what you are about to do with it. And how long are you keeping it.

Those three get mentioned in passing far more often than they get answered. This piece answers them for a business of five to fifty in British Columbia, where the governing statute is provincial and the principles are the ordinary ones that have applied since 2004.

As with anything on this subject: Entoura.Studio is an AI development studio instead of a law firm, and this is general information rather than legal advice. It is written so you know which questions to ask and which to take to a lawyer.

Purpose is the one that catches people

Of the three, purpose limitation is the provision most likely to be engaged by an AI project, and the one businesses are least likely to have thought about.

The principle is straightforward. Information collected for a reason may be used for that reason, and for purposes a person would reasonably consider compatible with it. A customer gives you their details so you can deliver the thing they bought. That covers delivering the thing. It covers, uncontroversially, using a system to help draft the confirmation email.

Where it stops covering is less obvious, and the honest test is whether the customer would be surprised. Would a guest who booked a room be surprised that their booking history is now training a demand model. Would a patient be surprised that their file was summarised by a third-party service. Would a client be surprised that the notes from their matter are searchable by everyone in the firm.

Surprise is not a legal standard, and it is a reliable indicator that you are operating outside the purpose you disclosed, available to anyone without a law degree. The regulators are already applying the underlying principles to generative AI: in May 2026 the federal, Quebec, BC and Alberta commissioners jointly found that OpenAI’s collection practices were overbroad and inappropriate, on transparency, accuracy, access and retention grounds.

Three AI-specific patterns are worth watching for.

Secondary use of operational records. The records were collected to run the business. Using them to build something new, a prediction, a profile, a model, is a different purpose. This is the most common one and it usually arrives with good intentions.

Anything that outlives the relationship. A model trained on customer data continues to exist after the customer leaves, and after they ask you to delete their information. If a person exercises a deletion right, what happens to what was derived from them is a question with no comfortable answer, which is a strong argument for retrieval over training in most business cases: retrieval reads a record you can delete, whereas training absorbs it into something you cannot unpick. Retrieval only keeps that advantage if the deletion also purges the derived index entries, which is a thing that has to be built instead of assumed.

Aggregation. Three systems each hold a piece that is individually unremarkable. Joined, they produce a picture of a person that nobody consented to and nobody intended. This is a normal consequence of connecting systems, which is exactly what an AI project does.

British Columbia’s PIPA asks for consent that is meaningful, which means the person understood what they were agreeing to.

Two practical consequences.

A clause saying the business “may use technology to improve services” does no work. It names no purpose, so it authorises nothing specific, and its vagueness is what makes it useless instead of clever.

And the level of consent required scales with sensitivity and surprise. Using a tool to spell-check a reply needs nothing beyond the original purpose. Feeding health information, financial detail or anything a person would consider private into a third-party service is at the other end, and the more sensitive the material the less you can rely on consent being implied.

The useful version for most businesses is a short, specific, current privacy notice that says what is collected, what it is used for including the AI uses in plain language, who it is shared with, where it goes, and how long it is kept. Written to be understood rather than to be unassailable. A notice a customer could actually read is doing more work than three pages of defensive drafting.

Retention, the one that is pure upside

Of the three, retention is the easiest to fix and the one that most reduces risk for the least effort.

The obligation is to keep personal information only as long as needed for the purpose, plus whatever a law or professional rule requires. The common practice is to keep everything forever, because storage costs nothing and deleting feels irreversible.

That default is a liability, and the arithmetic is simple. Every record you hold is a record that can be breached, has to be produced if someone exercises an access right, has to be found if someone asks for deletion, and has to be handled in any migration. Records you no longer need carry all of that cost and none of the benefit. As an earlier piece on collecting data put it, volume you cannot account for is a liability instead of an asset.

A workable schedule is a table with three columns: category, how long, and why. Financial records for the statutory period. Employment records per employment standards. Marketing contacts until consent is withdrawn. Operational records for as long as the operation needs them. CCTV for days instead of years. Call recordings for a period you can justify, which for most businesses is much shorter than the period they are actually kept.

Then the part that matters: something has to enforce it. A schedule nobody executes still leaves you non-compliant, and now also inaccurate about your own practice, so it has to be paired with the mechanism that runs it. Automated deletion is a small piece of engineering and belongs in the build rather than in a policy.

With one requirement that has to be built at the same time. Deletion must be suspendable, by record and by category, because a live dispute, an audit, an insurance claim or a regulatory request freezes the schedule for whatever it touches. Building the deletion without building the hold creates a worse problem than the one it solves, since destroying records that were subject to a hold is considerably harder to explain than keeping them too long.

AI adds two wrinkles worth naming. Prompts and outputs are records too, and a log of what staff typed into a tool alongside what came back is often a rich store of personal information nobody has scheduled. And derived data, embeddings, summaries, scores, is personal information when it relates to a person, so it needs a retention period like anything else.

Third parties, which is where AI actually lives

Almost every AI use involves sending information to somebody else’s system, and the accountability stays with you.

Four questions per tool, and they can be answered from the terms.

Is the data used for training? The single biggest difference between consumer and business tiers, and it changes the analysis completely. As a general pattern in 2026, consumer tiers permit training on inputs and business agreements prohibit it, though this is contractual instead of fixed and it moves, so the only reliable answer is the one in the terms you are actually on. Staff using a personal account to do work is therefore a different exposure from the same person using a sanctioned one, and it is invisible until someone looks.

How long do they keep it? Providers retain inputs for varying periods, and your retention schedule means little if your processor holds copies for longer.

Where is it processed? The residency question, in its correct place: one of four rather than the whole conversation.

What are the sub-processors? The people your provider uses. Rarely asked, occasionally important.

Two behaviours follow. Establish the answers before adopting a tool instead of after, because the terms are much easier to read than to renegotiate. And re-check them, because they change. A tool that was acceptable in January under terms that changed in June is a tool your business is now using under terms nobody read.

What to write down

The three things worth having on paper, none of which takes long.

An inventory. Which tools, used by whom, on what kind of information, under whose account. This is the foundation for everything else and most businesses have never made one.

A retention schedule. The table above, with something that actually enforces it.

An assessment for anything significant. What the project handles, why, where it goes, who can reach it, what could go wrong, what was done about it. Quebec’s Law 25 already requires this before moving personal information out of the province. The federal Bill C-36, tabled on 15 June 2026 and still early in the process, would require one before transferring personal information outside Canada. For a small business a few pages is genuinely enough, and the value is in being forced to answer the questions before the build instead of during an incident.

The part worth carrying out the door

Residency is the question everyone asks because it has a clean answer. The three that govern more of what you can actually do are quieter.

What did you tell people you were collecting this for, and does that cover what you are about to do. What would a customer be surprised by. And how long are you keeping it, on what schedule, enforced by what.

None of that requires a lawyer to start. It requires a list of what you hold, a table of how long you keep it, and a habit of asking about a new tool before adopting it rather than after. The businesses that find privacy easy are the ones that can produce those two documents. The ones that find it hard are the ones that have to reconstruct both under pressure, on a deadline set by somebody else.