An AI receptionist collects personal information on every single call. PIPEDA has ten principles about that.
Most of them are unremarkable. Three of them decide whether a voice system is a compliance problem.
PIPEDA applies to an AI receptionist for a simple reason: a name, a phone number, an address and the reason someone is calling are all personal information, and the system collects them on every call. The Act sets out ten fair information principles. Seven of them are ordinary good practice. Three (consent, limiting use and retention, and accountability for third parties) are where a voice system either holds up or does not.
What personal information does an AI receptionist collect?
More than most people assume. Beyond the obvious name and callback number, a voice agent captures the audio itself, a transcript of it, the reason for the call, and whatever the caller volunteered along the way, which in a clinic or a law firm can be considerably more sensitive than the booking it was attached to.
The audio matters separately from the transcript. A recording is biometric-adjacent in a way a text log is not: it carries a voice, and increasingly a voice is identifying on its own. Treating the audio and the transcript as one artefact with one retention rule is how businesses end up keeping voice recordings for years without deciding to.
The volunteered content is the part nobody plans for. A caller booking a physio appointment explains the injury. A caller asking a law firm about a separation names the other party. None of that was requested and all of it is now in a transcript.
Which principles actually bite on an AI receptionist?
Consent, limiting use and retention, and accountability. The other seven (accuracy, safeguards, openness, individual access, challenging compliance, identifying purposes, limiting collection) matter, but they rarely turn into the problem that gets discovered late.
| Principle | What it demands | How an AI receptionist fails it |
|---|---|---|
| Consent | Meaningful consent for collection and use | No spoken notice, or a notice after the caller has already explained their problem |
| Limiting use, disclosure and retention | Keep only as long as needed for the stated purpose | Default retention nobody chose, applied to audio and transcripts alike |
| Accountability | Responsible for information transferred to a third party for processing | Assuming the vendor's compliance is the business's compliance |
| Individual access | Produce an individual's information on request | No way to find one caller's recordings among thousands |
The first three are where the exposure sits. The fourth is where it surfaces, usually on the day somebody asks.
If a vendor processes the calls, whose obligation is it?
Yours. Under the accountability principle an organization remains responsible for personal information it transfers to a third party for processing, and the Commissioner's recording guidance says the same thing about contracted call centres in as many words. A vendor's certification is evidence you did diligence, not a transfer of duty.
This is the question worth asking a voice-AI vendor first, and it is not "are you SOC 2 certified." It is: what do you retain, for how long, can I change it, can you delete a specific caller's data on request, and where does it sit. Those four answers determine whether the business can meet its own obligations, and a vendor that cannot answer them crisply is answering them.
It is also the question that separates configuration from a build. A line assembled from defaults inherits whatever the defaults retain. A line built for a business gets a retention decision made by someone who knew it was a decision.
- What is retained (audio, transcript, structured fields) and separately for each?
- For how long, and is the period configurable per line?
- Can personal information be excluded from what is stored at all?
- On a caller's access or deletion request, what is the actual process and how long does it take?
Handing your phone to a vendor does not hand over your privacy obligations - under PIPEDA's accountability principle the organization stays responsible for personal information it transfers to a third party for processing.
Retention, exclusion and deletion are decisions we make with a client during the build, because inheriting a default is not the same as choosing one.
Start free pilotWhat this page does not cover
This is a reading of the legislation as it applies to an AI receptionist answering a business phone, not legal advice. Statutes are amended and regulators publish new guidance; check the source links, which are dated, and take advice on anything that matters.
- Provincial equivalents. Alberta and BC's Personal Information Protection Acts, and Quebec's private-sector law, apply instead of PIPEDA to some organizations. Similar in shape, different in detail.
- Health information. Health custodians are governed by provincial health privacy statutes, which impose stricter and more specific duties.
- Cross-border transfer. Where call data is processed matters and is its own analysis. This page does not attempt it.
Questions this raises
- Does PIPEDA apply to a small business using an AI receptionist?
- PIPEDA applies to organizations that collect, use or disclose personal information in the course of commercial activity. Size is not the test. In Alberta, BC and Quebec, substantially similar provincial legislation may apply instead.
- Is a call transcript personal information?
- Yes, where it identifies an individual, which a transcript containing a caller's name, number and reason for calling plainly does. The audio is personal information too, and deserves its own retention decision.
- How long can we keep call recordings under PIPEDA?
- PIPEDA does not set a number. It requires that information be retained only as long as necessary for the purpose it was collected for, which means the business has to choose a period it can justify against its stated purpose.
- Does using a US-based voice provider breach PIPEDA?
- Not automatically. PIPEDA does not prohibit processing outside Canada, but it does require the organization to remain accountable and to use contractual means to provide comparable protection. Where data sits is a question to answer explicitly rather than assume.
- What is the first thing to fix on an existing line?
- The spoken notice, then retention. Those two are cheap to change, they are the ones a complaint would name first, and neither requires rebuilding anything.
Sources
- PIPEDA fair information principlesOffice of the Privacy Commissioner of Canadaconsulted 2026-08-09
- Recording of Customer Telephone Calls: guidance for organizationsOffice of the Privacy Commissioner of Canadaupdated 2018-04-18, consulted 2026-08-09
Want an AI receptionist built around these rules rather than despite them?
We build a working receptionist on your calls, your booking rules and your escalation rules, and you call it yourself before committing to anything. About 14 days, no call limit during the pilot.
Start free pilot
