Monday, August 24, 2026

Privacy, Online Harms and Lawful Access: Keep an eye on Parliament this fall

If you care about privacy, the internet, artificial intelligence, social media, free expression, cybersecurity or government surveillance, you probably want to keep an eye on Ottawa this fall.

Because Parliament comes back from its summer break on September 21st, and waiting for MPs and Senators are three important pieces of legislation.

We have Bill C-34, the Safe Social Media Act, which would create an entirely new regulatory regime for social media, online harms and AI chatbots. Including a social media ban for anyone under 16.

We have Bill C-36, the Protecting Privacy and Consumer Data Act, which would repeal and replace the privacy portions of PIPEDA — Canada's private-sector privacy law for the last quarter-century.

And then we have Bill C-22, the Lawful Access Act, 2026, which has already made it through the House of Commons and is now sitting in the Senate.

Each one of these bills would be important on its own.

Taken together, this could be one of the most consequential sessions of Parliament for Canadian privacy and digital policy that we've seen in years.

Hi. My name is David Fraser. I'm a privacy, internet and technology lawyer with the Canadian law firm McInnes Cooper. I also teach Internet and Media Law at the Schulich School of Law at Dalhousie University.

I've already done detailed episodes on each of these bills, so I'm not going to go through every clause again. I’ll link to the previous episodes below.

Instead, I want to talk about where these bills stand, what they would actually do, and — most importantly — what we should be watching when Parliament gets back to work this fall.

Part 1: Three Different Bills — One Enormous Digital Policy Agenda

I think it's useful to start by looking at these three bills together.

Because they deal with different things, but they really are pieces of the same larger picture. And I think a fourth piece is coming.

Bill C-34 is about what online platforms are required to do.

Bill C-36 is about what organizations can do with our personal information and how they are regulated.

And Bill C-22 is about how law enforcement and national security agencies can obtain information and what technological capabilities companies may be required to build to facilitate that access.

So we are talking about regulation of platforms. Regulation of data. And government access to data.

That is a pretty significant chunk of Canada's digital policy landscape.

And there is another important connection between C-34 and C-36.

Bill C-34 creates a new Digital Safety Commission of Canada. Bill C-36 would expand and restructure that institution into a Digital Safety and Data Protection Commission of Canada, which would also become central to the enforcement of Canada's new private-sector privacy law.

In other words, we aren't just talking about three new statutes.

We may be watching the construction of an entirely new federal digital regulatory architecture.

And I fully expect we will have a bill to regulate artificial intelligence, and I bet the Digital Safety and Data Protection Commission will also have oversight of AI.

That deserves attention.

Part 2: Bill C-34 — The Safe Social Media Act

Let's start with Bill C-34.

The government introduced the Safe Social Media Act on June 10th, just before Parliament rose for the summer. It received first reading and is now sitting at second reading in the House of Commons.

This is essentially the government's replacement for Bill C-63, the Online Harms Act, which died when Parliament was prorogued before the last election.

But C-34 isn't simply C-63 with a new name.

There are some pretty significant changes.

The legislation would regulate three broad categories of services: social media services, AI chatbot services and potentially other highly interactive online services that the government considers sufficiently risky to children. Exactly which services are caught will depend enormously on regulations that have not yet been written.

Perhaps the most significant addition between C-63 and Bill C-34 is a social media ban for those under 16. Bill C-34 says that users have to be at least 16 years old to have an account on a regulated social media service unless the service obtains an exemption from the new Commission. And the ban will surely go into effect before the Commission has established criteria for exemptions.

It also requires age-assurance measures for services carrying pornographic content.

And that creates a glaring privacy problem.

To keep people under 16 off social media, social media companies have to figure out who is under 16.

Which means they have to determine the age of everybody.

So legislation promoted as a child-safety measure could result in an enormous new infrastructure for age verification or age estimation across the Canadian internet.

That is going to raise some very difficult questions.

What information are companies going to collect to establish age?

Do you have to upload government identification?

Can platforms use facial age-estimation technology?

Can third-party identity providers do this?

What data gets retained?

And perhaps most fundamentally: how much additional information should adults have to provide about themselves just to use an online service?

There are also very significant freedom-of-expression questions.

Despite some people comparing “Big Tech” with “Big Tobacco”, social media is not cigarettes or booze or gambling.

Social media is fundamentally a medium of expression.

Young people use it to communicate with friends, participate in political discussions, organize, create art, learn about the world and express themselves.

So an outright age restriction raises Charter questions that I expect will receive considerable attention if this bill gets to committee.

Bill C-34 also creates four broad categories of duties for regulated operators: duties to protect children, to be transparent, to act responsibly, and to make certain content inaccessible.

The legislation continues to regulate seven categories of harmful content, ranging from intimate content communicated without consent and content that victimizes children through to bullying, hatred, violence and violent extremism.

And AI is explicitly part of this.

Regulated chatbot services would have obligations designed to prevent them from impersonating human beings or professionals and from encouraging unhealthy emotional relationships with users.

Synthetic audio and visual content would also have to be identified in certain circumstances.

So this isn't just a social-media law. It will affect a LOT of the internet.

It's also one of Canada's first significant attempts to directly regulate consumer-facing generative AI.

And then there is the regulator itself.

The new Digital Safety Commission would have significant investigation, rule-making and enforcement powers, backed by potentially enormous administrative monetary penalties — up to the greater of $20 million or five percent of global gross revenue in some circumstances.

A HUGE amount of the actual operation of this legislation is also left to future regulations and rules made by the Commission. And, as a result, so much will be determined by who is appointed to the Commission.

So when C-34 gets to committee, I would expect a lot of attention to be focused not just on what the bill says, but on how much Parliament is being asked to leave for somebody else to decide later.

Part 3: What to Watch on C-34 This Fall

There are four things I'll particularly be watching.

First, the 16-year-old social media restrictionDoes it survive in its current form? And if it does, what safeguards are added around age verification?

Second, freedom of expressionDoes Parliament seriously grapple with the Charter implications of excluding younger Canadians from major platforms for communication and expression? It will be interesting to see how the government tries to stickhandle this in their Charter Statement for Bill C-34.

Third, the scope of the legislationHow far beyond Facebook, Instagram and TikTok does this go? Gaming? YouTube? Online communities? AI services?

The more services that can potentially be brought in by regulation, the more important that question becomes. 

And fourth, the power of the regulatorParliament should be very careful whenever it creates a powerful new administrative agency and says, essentially, "We'll work out a lot of the important details later."

My expectation is that C-34 will be a significant government priority this fall.

Online safety — particularly child safety — has enormous political appeal. But that does not mean the details don't matter. In fact, it means the details matter even more. If they're going to be so ambitious, they need to really try to get it right.

Part 4: Bill C-36 — Replacing PIPEDA

Then we have Bill C-36.

This one was introduced on June 15th — only a few days before the House packed up for the summer — and it is also waiting at second reading.

If C-34 is politically flashy, C-36 may actually have the broader long-term effect.

Because Bill C-36 would repeal Part 1 of PIPEDA.

PIPEDA has been Canada's federal private-sector privacy law since 2001.

For twenty-five years, it has governed how businesses collect, use and disclose personal information.

Bill C-36 would replace that regime with a completely new statute called the Protecting Privacy and Consumer Data Act, or PPCDA.

We've been here before.

Bill C-11 tried to replace PIPEDA in 2020. It didn’t proceed. Bill C-27 tried again in 2022. It didn’t proceed. So Bill C-36 is kick number three at this particular can. 

Much of the substance will be familiar to anyone who followed Bill C-27.

  • There are more detailed accountability requirements.
  • Documented privacy management programs.
  • More detailed consent rules.
  • New consent exceptions based on business activities and legitimate interests.
  • Formal rules dealing with anonymized and de-identified information.
  • A right to disposal of personal information.
  • Data mobility.
  • Privacy impact assessments for international transfers.
  • Much stronger enforcement.
  • And enormous potential penalties.

Administrative monetary penalties can reach the greater of $10 million or three percent of global gross revenue.

And serious offences can attract fines of up to the greater of $25 million or five percent of global gross revenue.

That should get the attention of corporate boards.

But perhaps the most interesting change is institutional.

For almost twenty-five years, federal private-sector privacy law has been overseen by the Privacy Commissioner of Canada — an independent officer of Parliament.

Bill C-36 would fundamentally change that.

The existing Privacy Commissioner would no longer be the regulator administering this law.

Instead, we would get a new Privacy and Consumer Data Commissioner operating inside this broader Digital Safety and Data Protection Commission. That Commission would also function as a tribunal when organizations challenge findings and penalties. And I think that is going to be one of the most important issues Parliament has to examine.

Why are we moving privacy regulation away from an independent officer of Parliament? What problem is that intended to solve?

How independent will the new Privacy and Consumer Data Commissioner actually be?

And have sufficient institutional walls been built between the investigative side and the tribunal side?

I don't particularly like the idea of having the investigator, prosecutor and adjudicator all living under one institutional roof.

Maybe that structure can work. But if that's what Parliament wants to create, the firewalls need to be very clear and I don’t see them in the text of the Bill.

Part 5: The Other Big C-36 Issues

There are a bunch of substantive issues I expect will get attention at committee. Consent is one. Bill C-36 requires organizations to provide considerably more information for consent to be valid.

At the same time, it introduces broader alternatives to consent through legitimate interests and specified business activities. So Parliament is simultaneously making consent more demanding and creating more circumstances in which organizations don't need it.

That tension deserves some careful thought. It works in Europe, but we’re not doing exactly what they’ve done in Europe. 

International transfers are another. Organizations transferring personal information outside Canada would have to undertake privacy impact assessments. That's a significant departure from the relatively technology-neutral accountability model we've had under PIPEDA.

And then there is the private right of action. Bill C-36 would allow an individual affected by a contravention to sue for loss or injury arising from it, including in provincial superior courts. I think that provision needs considerable work. Depending on how it is interpreted, a privacy contravention involving millions of individuals could produce an enormous multiplicity of proceedings.

There is also a bigger policy question. What do we actually want Canadian privacy law to accomplish in 2026 and beyond? We're now writing the law that could govern data processing for another generation. This is not the place for Parliament to rush. Bill C-36 isn't a tune-up. It is a wholesale replacement of Canada's federal private-sector privacy regime.

Part 6: Bill C-22 — Lawful Access Goes to the Senate

And then we come to Bill C-22. This one is at a completely different stage. Unlike C-34 and C-36, Bill C-22 made it through the House before the summer break. On June 18th, the House passed Bill C-22 at third reading, and the Senate gave it first reading that same day. So when Parliament returns, the lawful-access debate moves principally to the Senate.

If you've watched my previous episode, you know I have some pretty significant concerns about this bill. 

Bill C-22 has two major substantive pieces. Part 1 creates new and modified investigative tools.

There is a new confirmation-of-service demand, allowing police and CSIS in specified circumstances to require telecommunications service providers to confirm whether they provide services associated with a person or identifier.

There is a new subscriber-information production order operating on the relatively low threshold of reasonable grounds to suspect.

There are changes dealing with voluntary disclosure, publicly available information, tracking orders, transmission data and other investigative powers.

This part is considerably better than what the government originally proposed in Bill C-2, the Strong Borders Act, but I still have issues with Part 1.

Part 2 is where I remain much more concerned. It creates the Supporting Authorized Access to Information ActThat law would create a framework under which electronic service providers can be required to build and maintain technical capabilities to facilitate authorized government access to information.

And "electronic service provider" is defined VERY broadly.

We're not just talking about Bell, Rogers and Telus. We're likely talking about cloud providers, social media services, online gaming companies, messaging services, VPNs and other digital businesses.

The legislation allows obligations to be placed on designated core providers through regulations.

It also gives the Minister of Public Safety authority to issue secret orders to individual service providers, subject to approval by the Intelligence Commissioner.

And it provides for mandatory retention of specified categories of metadata. The House did make important amendments before passing the bill. The maximum metadata retention period was reduced from one year to six monthsThe provisions dealing with systemic vulnerabilities were improved, but definitely not fixed.

The government is still creating a permanent statutory framework under which private companies can be required to design their systems so that government access can be facilitated.

And that raises some enormous questions about privacy, cybersecurity, proportionality and the future design of communications infrastructure.

As I said in my earlier episode, I think Part 1 is largely fixed. Part 2 is better than what we saw before, but I still think it is deeply problematic.

Part 7: The Senate Could Really Matter

And that makes the Senate particularly important this fall. The House consideration of C-22 ended very quickly. On June 17th, the government obtained a programming motion that dramatically compressed the remaining committee and House proceedings, and the bill was passed by the Commons on June 18th.

So the Senate now has an opportunity to give the legislation the detailed scrutiny that a bill of this significance deserves.

I hope Senators take that opportunity. I would expect witnesses from law enforcement and national security agencies. I would expect privacy and civil-liberties advocates. I would expect telecommunications companies and major technology companies. I hope there are cybersecurity and encryption experts. And I hope Senators spend a lot of time on a fundamental question:

What technological capabilities should the government be permitted to require private companies to build in advance, so they are available if government wants to use them later?

That is a very different question from whether police should be able to get a warrant. Of course police should be able to get warrants where the legal requirements are met. The much harder question is whether we should redesign communications infrastructure to make surveillance easier. Those are not the same thing.

Part 8: The Bigger Picture

And that's why I think these three bills need to be looked at together.

With Bill C-34, the government wants online services to know more about their users' ages and identities so they can control access and manage harmful content.

With Bill C-36, the government is completely rewriting the rules governing how businesses collect and use personal information.

And with Bill C-22, the government wants to ensure that information and technical capabilities exist so law enforcement and national security agencies can obtain data when legally authorized to do so.

There are legitimate public-policy objectives behind all three. Protecting children online is important. Most folks in the field agree that modernizing our privacy law is overdue. Giving police appropriate tools to investigate serious crime in a digital world is necessary. (Emphasis on “appropriate”.)

But good objectives do not automatically produce good legislation. And one of the recurring themes running through all three bills is information architectureWhat data are companies required to collect? What data are they permitted to use? What data must they retain? What technological systems must they build? Who gets access to that information? Who is the “customer”? The police? Who regulates all of this? And what checks exist on those regulators and government agencies?

Those questions are going to shape the Canadian internet for years.

Part 9: What I Will Be Watching

So here is my fall 2026 privacy and digital-policy watch list.

For Bill C-34, watch the age-16 restriction, age-verification requirements, freedom-of-expression issues, the treatment of AI and the enormous amount of substantive law being left to regulations and Commission rule-making.

For Bill C-36, watch the fate of the existing Privacy Commissioner, the structure and independence of the new regulator, consent and legitimate interests, cross-border transfers, the private right of action and the penalty regime.

And for Bill C-22, watch the Senate. Particularly watch what Senators do with Part 2, metadata retention, technical capability requirements, ministerial orders, encryption and cybersecurity protections.

And there is one final thing to watch: Speed. We've seen governments try to enact major digital-policy reforms only to have them die because they were too controversial, too complicated or simply ran out of parliamentary runway. Privacy law reform Bills C-11 and C-27 never became law. Online Harms Bill C-63 never became law. The lawful-access proposals in Bill C-2 did not survive in that form.

So introducing legislation is one thing, getting it through both Houses of Parliament is entirely different.

Bill C-22 is already well down that road. C-34 and C-36 are just getting started.

And I suspect we're going to know a lot more by Christmas about how serious the government is about getting each of them enacted.

Conclusion

So buckle up. The fall of 2026 will be enormously consequential for Canadian privacy and technology law.

And I expect I'll have plenty to talk about over the next few months. 

No comments: