AI and client privacy for Canadian nonprofits: a practical checklist
By Tamjid Shah Bari · October 5, 2026 · 8 min read
Most nonprofits hold information about people at difficult moments in their lives. Before any AI tool touches that information, a few questions need clear answers. This checklist is a starting point for that conversation.
This is practical guidance, not legal advice. Which law applies depends on your province, your sector and what you do with the information. Check with your privacy lead or a lawyer before you rely on it.
1. Know which privacy rules apply to you
Privacy law in Canada is a patchwork. The federal law, PIPEDA, covers personal information handled in the course of commercial activity, which can include some nonprofit activities but not always core charitable work. Some provinces have their own laws that reach further, such as Quebec's private sector law, and Alberta's and British Columbia's PIPA. Health information has its own rules in several provinces, including PHIPA in Ontario. On top of the law, funder agreements and government contracts often set their own requirements.
Write down which of these apply to the data in question before choosing a tool. It shapes every answer below.
2. Check what people actually consented to
Consent is usually given for a purpose: to receive a service, to be referred, to be contacted. Ask whether using an AI tool to process that information fits within the purpose people agreed to. Sorting an intake email so it reaches the right worker probably does. Using case notes to write a fundraising story probably doesn't, unless people agreed to it.
3. Give the AI the least it needs
- List the fields the task needs. An agent drafting a funder report may need counts and outcomes, not names or dates of birth.
- Remove or mask identifying details before the AI sees the data where you can.
- Keep the most sensitive information, such as health details, immigration status or safety concerns, out of scope unless the task truly requires it.
4. Know where the data goes and how long it stays
- Which company processes the data, and where are its servers? Some organizations need data to stay in Canada.
- Does the provider use your data to train its models? Business and enterprise terms from the major providers usually let you opt out or exclude it by default. Read the terms that apply to your account.
- How long are prompts and outputs kept, and can you delete them?
- Is there a data processing agreement you can sign?
5. Keep personal information out of logs and test data
AI systems are usually logged for debugging and tested against past examples. Those logs and test sets are easy to forget and easy to leak. Strip personal details from logs, build test cases from de-identified or synthetic records, and check automatically that no names or contact details appear where they shouldn't.
6. Keep people in charge of decisions about people
An agent can read, sort, summarize and draft. Decisions that affect someone's service, such as eligibility, priority for housing or a safety response, should be made by a named staff member, with the agent's output as one input. Write down where those approval points are, so it's clear to staff and to anyone reviewing the system later.
7. Limit who can see what
The agent should only reach the systems and records it needs, using its own account rather than a staff member's. Its outputs should follow the same access rules as the data they came from: a summary of a confidential file is still confidential.
8. Keep a record and be ready to explain it
- Document what the system does, what data it uses, where it runs and who approves its outputs, in plain language.
- Keep an audit trail of what it did and who signed off.
- Be able to tell a client, in a sentence or two, how their information was used.
- Know what you'll do if something goes wrong, including who to notify.
If you can answer these eight questions clearly for a specific task, you're in a good position to try AI on it. If you can't yet, that's the work to do first.
See how an intake workflow keeps people in the loop
Want a second pair of eyes on this?
I'm Tamjid Shah Bari. I build AI agent systems for nonprofits and small teams in Toronto and across Canada, with tests and human sign-off built in. How I work with nonprofits.
More guides
- How to use AI for grant reporting without inventing numbersA practical approach for nonprofits using AI to draft grant and impact reports: every figure tied to a source, automatic checks, and a person signing off before anything goes to a funder.
- What a small nonprofit should automate first, and what to leave aloneA simple way for small nonprofits to choose their first AI automation: look for frequent, checkable, low-harm tasks, and leave relationship and judgement work with people.