New report on privacy drift in cloud and AI services
Oct 7, 2026

The Information and Privacy Commissioner of Ontario (IPC) has published our report Beyond the Initial Agreement: How Privacy Drift Affects Modern Third-Party Contracting. It examines how the privacy terms of cloud and AI services change after institutions in Ontario's broader public sector adopt them, using examples from leading AI companies.
Privacy drift is the gradual change in privacy-relevant rights and obligations after an institution has assessed and approved a service. It happens because providers govern their enterprise services through layers of linked documents. These include master agreements, product terms, privacy policies, data processing addenda, and service-specific terms. Each document can change on its own schedule, often without renegotiation or meaningful notice. A provider might add an AI feature, change a subprocessor, or expand its rights over the data generated around a service. When that happens, the conditions an institution reviewed in its privacy impact assessment can shift soon after the assessment is complete.
We call that surrounding data user-adjacent data. It includes metadata, telemetry, diagnostics, and interaction histories. Such data can reveal a person's role, habits, and relationships even when the provider never sees the content of a file or message. A provider can commit not to train its AI models on customer content while keeping broader rights over this data. Drift also reaches institutions when staff use consumer AI tools or personal accounts, whose terms are often more permissive and less stable than enterprise terms. Our earlier research found 119 changes to the consumer terms of service and privacy policies of four leading AI providers over 12 months in a single jurisdiction.
Recent Ontario reforms strengthen the privacy duties of public institutions without imposing matching duties on vendors. None of the Canadian laws and guidance we reviewed provides a complete framework for addressing privacy drift. We propose six elements of an anti-drift legislative framework. These include a duty on vendors to keep a current, versioned register of the documents governing a service, and limits on unilateral amendments that expand privacy risk. Our central conclusion is that institutions need to keep reviewing the privacy terms of cloud and AI services for as long as they use them.
Thank you to Gareth Spanglett, Joanna Thomai, and Rejhan Takur N Doobay, who wrote the report. Thank you also to CIPPIC team members Fumi Shibutani, Orian Israelson, Vera Bi, Kate Winiarz, and Clara Mustata, who assisted with the research. We also thank the IPC for supporting this research.
Read the report on the IPC’s website.
Documents |
|---|
