Download PDF (210 KB)
PDF version, ready to print or share with your team.
Written by Mike Pearlstein, CISSP, CEO of Fusion Computing Limited. Helping Canadian businesses build and manage secure IT infrastructure since 2012 across Toronto, Hamilton, and Metro Vancouver.
Somebody on your team has already done this. They joined a client call, a small bot joined alongside them, and a tidy summary landed in their inbox 4 minutes after the call ended. Nobody asked the client. Nobody asked you.
When that gets raised, the answer usually offered is that Canada is a one-party consent country, so recording is fine. That is a correct statement about the Criminal Code and it settles only half the question. The other half is the Personal Information Protection and Electronic Documents Act (PIPEDA), Canada’s federal private-sector privacy law. That is the half most businesses have to answer for.
Short answer: in a business setting you need consent, for 2 separate reasons. The Criminal Code decides whether the recording itself is lawful, and one participant consenting is enough there. Privacy law separately requires meaningful consent to collect, use and disclose the personal information inside that recording, and the sensitivity of the conversation raises the bar. Which privacy law applies depends on where you operate:
PIPEDA covers most private-sector activity. Quebec, British Columbia and Alberta have their own statutes that apply instead of PIPEDA to activity inside those provinces.
Microsoft Teams already defaults to sending detected external notetaker bots to the lobby for approval, through the ExternalBotAccessMode policy. That setting decides whether a bot can join. It decides nothing about whether the people on the call agreed.
Key takeaways
- Two gates, both must pass. The Criminal Code governs the recording; the applicable privacy law governs the personal information in it. Which law that is depends on where and how you operate (OPC).
- The OPC has published 7 guiding principles for meaningful consent, in force since January 1, 2019, and consent is valid only if the person can reasonably be expected to understand it (OPC).
- The form of consent has to reflect the sensitivity of the information, so a client matter is not a staff standup (OPC).
- Microsoft documents exactly 2 values for
ExternalBotAccessMode, and the default already forces detected bots into the lobby (Microsoft, 2026). - Bot-based notetakers join as a visible guest and stream audio to a third-party cloud, which puts the recording outside your tenant.
Do you need consent to use an AI notetaker in Canada?
Yes, and the reason is 2 rules rather than 1. Section 184 of the Criminal Code makes intercepting a private communication an offence, with an exception where a party to it consents. That exception is what people mean by one-party consent, and it is a test of criminal liability.
PIPEDA asks a different question. Under Principle 3, an organisation needs knowledge and consent to collect, use or disclose personal information. A transcript of a client conversation is personal information about everyone audible in it.
That sensitivity rule is what separates a 10 minute internal standup from a call about somebody’s divorce, their diagnosis, or their insurance claim. Fusion Computing treats the second category as needing consent captured in writing, because the OPC test scales with the stakes.
Where does the recording actually go?
A bot-based notetaker joins your meeting as a visible guest through the calendar invite and streams the audio to its own cloud. A tenant-native tool works from what Microsoft 365 already has: intelligent recap uses the meeting transcript, and Copilot uses either a saved transcript or temporary speech-to-text during the meeting.
Where that transcript lands depends on who organised the meeting: Teams stores an ordinary meeting recording in the organiser’s OneDrive, so a call your client hosts puts the record in their tenant rather than in yours. Your tenant here means the Microsoft 365 environment your organisation administers.
| Tool | How it joins | Audio leaves your tenant | Who controls retention |
|---|---|---|---|
| Teams intelligent recap | Reads the meeting’s own transcript | No, when your organisation hosts the meeting | Your Microsoft 365 administrators. Needs Teams Premium or Microsoft 365 Copilot |
| Microsoft 365 Copilot in Teams | Reads the transcript, or works from temporary speech-to-text with no saved transcript | No, when your organisation hosts the meeting | Your administrators, though Copilot prompts and responses are retained separately from the transcript |
| Otter | Bot joins as a guest participant | Yes | Customer-configurable where custom retention is available on the plan; provider terms and deletion timing still apply |
| Fireflies | Bot joins as a guest participant | Yes | Check the plan. Verify retention controls per product before you rely on them |
| Fathom | Bot joins as a guest participant | Yes | Check the plan. Verify retention controls per product before you rely on them |
| Read.ai | Bot joins as a guest participant | Yes | Check the plan. Verify retention controls per product before you rely on them |
None of that makes a third-party tool unlawful. It changes who you have to explain, and what you have to disclose when a client asks where the recording of their matter is kept. Using a processor does not move the accountability: under PIPEDA the organisation that collected the information remains answerable for it. Our note on AI tools data privacy covers the same boundary question for free consumer tools.
Can you just block them in Microsoft Teams?
You can control them, and the control is narrower than the coverage suggests. Microsoft’s Set-CsTeamsMeetingPolicy reference, revised on September 4, 2026, documents exactly 2 values for ExternalBotAccessMode. Several trade reports in August announced a blanket auto-block mode. The cmdlet reference does not carry one.
| Value | What Microsoft says it does |
|---|---|
| RequireApprovalWhenDetected (default) | “When detected, bots will be enforced to the meeting lobby, regardless of the lobby setting of the meeting. They will require approval before getting access to the meetings.” |
| AllowAllBots | “Don’t detect bots; Bots will appear the same as other participants. Standard lobby policies will apply to them. They may get mistakenly admitted to meetings.” |
Detected bots need lobby approval even when other participants can bypass the lobby. That is the default, so most organisations already have a gate.
Two limits are worth knowing: the policy is assigned to users and groups rather than being inherently tenant-wide, so check the policy actually assigned to the people who organise your meetings, and it governs meetings your organisation hosts, not meetings you attend in somebody else’s tenant. Detection is also not complete.
Fusion Computing recommends treating the setting and the consent practice as 2 separate jobs. This is 1 control among several that decide who reaches a meeting, alongside the lobby and anonymous-join settings. Blocking answers whether a bot can join. It does not answer whether the people on the call agreed to be recorded, and a tenant that blocks every bot can still have a consent problem with the tool Microsoft ships.
What does a defensible consent practice look like?
It looks like 5 steps done every time, mapped to the OPC’s meaningful consent principles. Name what is captured, meaning the audio, the transcript and any summary. Say who receives it, including any third-party service that processes it, and what each does with it.
State the purpose, where it is kept, for how long, and any consequence a participant would want to weigh. Give a route to decline or withdraw that is not socially impossible. Then record the consent you obtained, which for a sensitive matter means express agreement rather than a note that you gave notice.
Why Canadian firms bring this work to Fusion Computing
CISSP-led, a Microsoft Solutions Partner and a CompTIA Managed Services Trustmark holder, securing IT for Canadian SMBs across Toronto, Hamilton, and Metro Vancouver since 2012.
Write the standing rule into your AI acceptable use policy Canada so it survives the person who wrote it. This is a description of what the guidance requires, and it is not legal advice about your situation.
What changes if you are a regulated Canadian firm?
Two things change. First, which privacy statute governs you at all: Quebec, British Columbia and Alberta have laws deemed substantially similar to PIPEDA, and for activity inside those provinces they apply instead of it, while federal works and cross-border collection stay under PIPEDA.
Second, your professional regulator adds obligations on top of whichever statute applies.
For most Fusion clients that regulator is the layer that decides. In Ontario, a law firm answers to the Law Society, and our law society of ontario ai policy template covers the confidentiality wording. Ontario health information custodians are governed by PHIPA, which is a statute rather than a regulator. Ontario property and casualty insurance brokers answer to RIBO. Equivalent bodies differ province by province.
Accounting firms have their own overlay in the cpa ai policy template, and physicians in the cpso ai policy template. Brokerages carrying an insurance licence should read the ribo responsible ai use policy alongside this.
The provincial statutes are the ones to identify first. Quebec organisations answer to the Commission d’accès à l’information under Law 25. British Columbia has its own Personal Information Protection Act, overseen by the provincial commissioner, and Alberta has a comparable statute and its own regulator. Work out which statute governs each part of what you do before you write the consent wording.
Which tool should a Canadian SMB actually use?
For most of the Canadian firms Fusion Computing works with, the tenant-native path is the reasoned default. For meetings the firm hosts, the record stays in your own Microsoft 365 environment, so retention, deletion and eDiscovery stay on 1 policy surface your administrators control.
The two are not the same tool. Intelligent recap uses the meeting transcript. Copilot can use a saved transcript, or temporary speech-to-text data during the meeting with no transcript kept.
Fusion Computing recommends checking recording and transcript retention separately from Copilot interaction retention. eDiscovery here means finding and preserving records for a legal matter. There is no second vendor to explain to a client, though Copilot prompts and responses are retained separately from the transcript and belong in the same retention conversation.
That default may not fit in 2 situations. If your meetings happen somewhere other than Teams, a tenant-native tool cannot see them. If you need a feature Microsoft does not offer, the trade may be worth making deliberately.
Before adding a licence, check what you already hold. Intelligent recap is available through Teams Premium or Microsoft 365 Copilot, so the recap path may already be paid for. Our note on copilot vs chatgpt vs claude sets out where each assistant fits.
Ask us to review your meeting-notetaker controls and the consent wording that goes with them. →
Whichever way you go, the consent obligation travels with the recording. Microsoft’s own recap still collects personal information about everyone on the call, and choosing it does not make you compliant by default. Fusion Computing sets the policy and the practice together, because 1 without the other fails at the first client question.
Review your meeting-notetaker controls
CISSP-led, securing IT for Canadian SMBs since 2012.
An unsanctioned notetaker joining client calls is shadow AI. Start with a 30-minute scoping call. We’ll establish what your environment can report and scope a review of the AI use already in it.
Book the 30-minute scoping call or read how the shadow AI review works
The short version
Check ExternalBotAccessMode in your tenant, because the default already helps and 1 change undoes it. Then write the consent sequence down, and apply the sensitivity test to client calls. Blocking a bot and obtaining consent are 2 different jobs.
Frequently Asked Questions
Is it legal to use an AI notetaker in a meeting in Canada?
There are 2 separate questions. Section 184 of the Criminal Code makes intercepting a private communication an offence but excepts a recording where a party to the conversation consents, which is what one-party consent means. The applicable privacy law separately requires meaningful consent to collect, use and disclose the personal information captured in the recording.
Which law applies depends on where and how you operate: PIPEDA covers commercial activity and certain federally regulated employment, while Quebec, British Columbia and Alberta have private-sector statutes that can apply instead for activity inside those provinces, and health information can fall under a separate health privacy law. A business has to satisfy the Criminal Code question and the privacy question both.
Does one-party consent mean I can record a client call without telling them?
Not in a business context. One-party consent addresses criminal liability for the recording itself. It says nothing about privacy law, which separately requires knowledge and consent to collect and use the personal information in the transcript.
PIPEDA covers most private-sector activity, and Quebec, British Columbia and Alberta have their own statutes that apply instead of it inside those provinces. The Office of the Privacy Commissioner’s published guidelines say the form of consent should take into account how sensitive the information is, so a client matter sets a higher bar than an internal standup.
Can a Microsoft Teams admin block Otter, Fireflies or Fathom?
Teams has a setting for this, ExternalBotAccessMode on Set-CsTeamsMeetingPolicy, and Microsoft documents 2 values for it. The default, RequireApprovalWhenDetected, means detected bots need lobby approval even when other participants can bypass the lobby.
The policy is assigned to users and groups rather than being inherently tenant-wide, it governs meetings your organisation hosts, and detection is not complete, so it is 1 control among several rather than a blanket block. AllowAllBots turns detection off, and Microsoft notes that bots may then be mistakenly admitted. No blanket auto-block value appears in the reference as of its September 4, 2026 revision.
Does Microsoft Teams Copilot recap need consent too?
Yes. Keeping the record inside your own Microsoft 365 environment changes who holds the data and who sets retention, and it does not remove the consent obligation. Note that Teams stores an ordinary meeting recording in the organiser’s OneDrive, so a meeting your client hosts puts the record in their environment rather than yours.
Intelligent recap and Copilot still collect personal information about everyone on the call. Choosing a tenant-native tool simplifies the disclosure, because there is 1 policy surface rather than 2, but the consent step remains.
What should we actually say before recording a meeting?
Cover 5 things: name what is captured, meaning the audio, transcript and any summary; say who receives it, including any third-party processor, and what each does with it; state the purpose, where it is kept, for how long, and any consequence a participant would want to weigh; give a route to decline or withdraw; and record the consent obtained, which for a sensitive matter means express agreement rather than a note that you gave notice.
That sequence maps to the Office of the Privacy Commissioner's 7 guiding principles for meaningful consent, which have been in force since January 1, 2019.
Do provincial privacy laws change the answer?
They can replace it. Quebec, British Columbia and Alberta have laws deemed substantially similar to PIPEDA, and for activity inside those provinces those statutes apply instead of PIPEDA, while federal works and cross-border collection stay under PIPEDA. Health privacy statutes can also be the governing law.
For Ontario health information custodians covered by PHIPA, collection, use and disclosure within Ontario are exempt from PIPEDA Part 1, and federal coverage should be checked separately for cross-border activity. Professional regulators can impose separate duties on top of whichever statute governs, which in Ontario means the Law Society for law firms and RIBO for property and casualty insurance brokers. Identify the governing statute for each part of what you do before writing consent wording.

