Cross-border privacy arguments used to sound sophisticated. The company is foreign. The servers are foreign. The contract chooses foreign law. Therefore Canadian commissioners and courts should stay in their lane.
That story is failing in public.
In Clearview AI Inc. v. British Columbia (Information and Privacy Commissioner), 2026 BCCA 67, the British Columbia Court of Appeal upheld a compliance direction against a U.S. facial-recognition company. The core idea is not exotic: when an organization scrapes images of people in the province at scale, a real and substantial connection can exist. Geographic theatre does not erase local privacy authority.
This appellate result sits on top of an earlier enforcement story many of us already use in training. Canadian privacy authorities jointly investigated Clearview and rejected the casual industry claim that publicly available photos are free raw material for biometric systems. See the 2021 joint investigation findings. The BCCA chapter matters because it strengthens the judicial backbone behind extraterritorial reach and order compliance.
Real and substantial connection, in plain terms
Courts ask whether the facts link the activity to the jurisdiction in a meaningful way. Scraping local faces, building identification tools that can be used against local residents, and ignoring local cease-and-desist dynamics are not abstract internet events. They are local privacy events executed through remote infrastructure.
I explain it to executives this way: if your product’s value proposition needs people who live here, your compliance perimeter includes here.
Why “publicly available” keeps failing as a defence
Open web does not mean open season. Canadian privacy statutes generally regulate collection, use, and disclosure of personal information for commercial purposes. Publishing a photo for social reasons is not the same as industrial biometric indexing for sale to clients. Treating every public JPEG as training inventory without a valid legal basis is exactly the mindset regulators have been dismantling.
This point now travels beyond facial recognition. Generative AI scraping debates borrow the same logic. Public accessibility is a fact about the internet. It is not an automatic consent substitute. Federal guidance and findings remain easy to track through the Office of the Privacy Commissioner of Canada, and provincial authorities continue coordinated work where business models cross borders.
Operational consequences for Canadian organizations
Even if you are not Clearview, you buy tools that behave like distant cousins: people-search utilities, enrichment APIs, OSINT platforms, advertising graphs, and model providers trained on broad web corpora.
Ask harder intake questions:
- What Canadian personal information is collected or inferred?
- Is scraping part of the data supply chain?
- Can the vendor delete or stop processing on demand?
- Which regulator orders will the vendor honour?
- Where is the escalation path when a Canadian authority issues findings?
If procurement cannot get clear answers, you are importing extraterritorial conflict into your own accountability package. Under PIPEDA-style accountability, you do not outsource blame as easily as you outsource compute. The PIPEDA accountability principle still expects organizations to stand behind what service providers do with personal information they handle on your behalf.
What I changed in vendor risk reviews
I stopped accepting “no Canadian establishment” as a risk rating by itself. I now score “Canadian personal information effects,” “biometric or sensitive inference,” “scraped source dependency,” and “history of regulator conflict” as independent factors.
I also ask counsel for a position memo when a high-risk foreign vendor refuses to acknowledge Canadian law. Sometimes the business still proceeds. When it does, leadership should accept residual risk with eyes open, not with a slogan about cloud geography.
Quebec-facing programs should add another filter: does the vendor’s posture survive Law 25 expectations on governance, consent, and rights? A U.S. click-through terms page is not a Quebec compliance plan.
The sovereignty signal
Canadian courts and commissioners are drawing a perimeter around people, not around rack locations. Similar logic appears in other provincial contexts where control over data, not only the physical host address, informs jurisdiction analysis. For global product teams, that means geo-fencing marketing is not the same as geo-fencing compliance.
If your roadmap includes computer vision, identity resolution, or large-scale public-data ingestion, Clearview is not a niche biometrics tale. It is a warning about business models that treat Canadian residents as unregulated data deposits.
I also press internal builders, not only vendors. A Canadian company that scrapes abroad and sells insights at home can create the same connection problem in reverse. Design reviews should flag public-web harvesting early, before model weights make retreat expensive. Document your conflict plan too: if a foreign vendor refuses a Canadian deletion order, what is the walk-away threshold, who escalates, and what customer commitments break?
Contracting language that actually helps
When I redline high-risk foreign vendors, I look for more than a generic “comply with applicable law” sentence. Useful clauses include:
- Explicit acknowledgment that Canadian personal information may be in scope
- Deletion and stop-processing mechanics with timelines
- Cooperation with Canadian regulator inquiries
- Notice if the vendor is subject to foreign government access demands that could touch Canadian data
- Audit or attestation rights proportional to biometric or scraping risk
- A clear exit plan if continuing the relationship would breach a Canadian order
Paper alone will not save a bad business model. But paper without these points guarantees confusion when enforcement heat rises.
Actionable takeaway
Pick your highest-risk foreign data vendor this month and run a one-page extraterritorial exposure brief: Canadian data touched, scraping or public-web dependency, contractual deletion rights, and response plan if a Canadian commissioner orders changes. Anchor the brief in primary materials—the BCCA Clearview decision and the 2021 joint investigation report. Present it to the executive owner of that vendor relationship. If nobody owns the risk, you do not have a control—you have a hope.