If
you care about privacy, the internet, artificial intelligence, social media,
free expression, cybersecurity or government surveillance, you probably want to
keep an eye on Ottawa this fall.
Because
Parliament comes back from its summer break on September 21st, and waiting for
MPs and Senators are three important pieces of legislation.
We
have Bill C-34, the Safe Social Media Act, which would create an
entirely new regulatory regime for social media, online harms and AI chatbots.
Including a social media ban for anyone under 16.
We
have Bill C-36, the Protecting Privacy and Consumer Data Act, which
would repeal and replace the privacy portions of PIPEDA — Canada's
private-sector privacy law for the last quarter-century.
And
then we have Bill C-22, the Lawful Access Act, 2026, which has already
made it through the House of Commons and is now sitting in the Senate.
Each
one of these bills would be important on its own.
Taken
together, this could be one of the most consequential sessions of Parliament
for Canadian privacy and digital policy that we've seen in years.
Hi.
My name is David Fraser. I'm a privacy, internet and technology lawyer with the
Canadian law firm McInnes Cooper. I also teach Internet and Media Law at the
Schulich School of Law at Dalhousie University.
I've
already done detailed episodes on each of these bills, so I'm not going to go
through every clause again. I’ll link to the previous episodes below.
Instead,
I want to talk about where these bills stand, what they would actually do, and
— most importantly — what we should be watching when Parliament gets back to
work this fall.
Part 1: Three Different Bills — One Enormous Digital Policy Agenda
I
think it's useful to start by looking at these three bills together.
Because
they deal with different things, but they really are pieces of the same larger
picture. And I think a fourth piece is coming.
Bill
C-34 is about what online platforms are required to do.
Bill
C-36 is about what organizations can do with our personal information and
how they are regulated.
And
Bill C-22 is about how law enforcement and national security agencies can
obtain information and what technological capabilities companies may be
required to build to facilitate that access.
So
we are talking about regulation of platforms. Regulation of data. And
government access to data.
That
is a pretty significant chunk of Canada's digital policy landscape.
And
there is another important connection between C-34 and C-36.
Bill
C-34 creates a new Digital Safety Commission of Canada. Bill C-36 would expand
and restructure that institution into a Digital Safety and Data Protection
Commission of Canada, which would also become central to the enforcement of
Canada's new private-sector privacy law.
In
other words, we aren't just talking about three new statutes.
We
may be watching the construction of an entirely new federal digital regulatory
architecture.
And
I fully expect we will have a bill to regulate artificial intelligence, and I
bet the Digital Safety and Data Protection Commission will also have oversight
of AI.
That
deserves attention.
Part 2: Bill C-34 — The Safe Social Media Act
Let's
start with Bill C-34.
The
government introduced the Safe Social Media Act on June 10th, just before
Parliament rose for the summer. It received first reading and is now sitting at
second reading in the House of Commons.
This
is essentially the government's replacement for Bill C-63, the Online Harms
Act, which died when Parliament was prorogued before the last election.
But
C-34 isn't simply C-63 with a new name.
There
are some pretty significant changes.
The
legislation would regulate three broad categories of services: social media
services, AI chatbot services and potentially other highly interactive online
services that the government considers sufficiently risky to children. Exactly
which services are caught will depend enormously on regulations that have not
yet been written.
Perhaps
the most significant addition between C-63 and Bill C-34 is a social media ban
for those under 16. Bill C-34 says that users have to be at least 16 years
old to have an account on a regulated social media service unless the
service obtains an exemption from the new Commission. And the ban will surely
go into effect before the Commission has established criteria for exemptions.
It
also requires age-assurance measures for services carrying pornographic
content.
And
that creates a glaring privacy problem.
To
keep people under 16 off social media, social media companies have to figure
out who is under 16.
Which
means they have to determine the age of everybody.
So
legislation promoted as a child-safety measure could result in an enormous new
infrastructure for age verification or age estimation across the Canadian
internet.
That
is going to raise some very difficult questions.
What
information are companies going to collect to establish age?
Do
you have to upload government identification?
Can
platforms use facial age-estimation technology?
Can
third-party identity providers do this?
What
data gets retained?
And
perhaps most fundamentally: how much additional information should adults have
to provide about themselves just to use an online service?
There
are also very significant freedom-of-expression questions.
Despite
some people comparing “Big Tech” with “Big Tobacco”, social media is not
cigarettes or booze or gambling.
Social
media is fundamentally a medium of expression.
Young
people use it to communicate with friends, participate in political
discussions, organize, create art, learn about the world and express
themselves.
So
an outright age restriction raises Charter questions that I expect will receive
considerable attention if this bill gets to committee.
Bill
C-34 also creates four broad categories of duties for regulated operators:
duties to protect children, to be transparent, to act responsibly, and to make
certain content inaccessible.
The
legislation continues to regulate seven categories of harmful content, ranging
from intimate content communicated without consent and content that victimizes
children through to bullying, hatred, violence and violent extremism.
And
AI is explicitly part of this.
Regulated
chatbot services would have obligations designed to prevent them from
impersonating human beings or professionals and from encouraging unhealthy
emotional relationships with users.
Synthetic
audio and visual content would also have to be identified in certain
circumstances.
So
this isn't just a social-media law. It will affect a LOT of the internet.
It's
also one of Canada's first significant attempts to directly regulate
consumer-facing generative AI.
And
then there is the regulator itself.
The
new Digital Safety Commission would have significant investigation, rule-making
and enforcement powers, backed by potentially enormous administrative monetary
penalties — up to the greater of $20 million or five percent of global gross
revenue in some circumstances.
A
HUGE amount of the actual operation of this legislation is also left to future
regulations and rules made by the Commission. And, as a result, so much will be
determined by who is appointed to the Commission.
So
when C-34 gets to committee, I would expect a lot of attention to be focused
not just on what the bill says, but on how much Parliament is being asked to
leave for somebody else to decide later.
Part 3: What to Watch on C-34 This Fall
There
are four things I'll particularly be watching.
First, the 16-year-old social media restriction. Does it survive in its current form? And if it does, what safeguards are added around age verification?
Second, freedom of expression. Does Parliament seriously grapple with the Charter implications of excluding younger Canadians from major platforms for communication and expression? It will be interesting to see how the government tries to stickhandle this in their Charter Statement for Bill C-34.
Third, the scope of the legislation. How far beyond Facebook, Instagram and TikTok does this go? Gaming? YouTube? Online communities? AI services?
The more services that can potentially be brought in by regulation, the more important that question becomes.
And fourth, the power of the regulator. Parliament should be very careful whenever it creates a powerful new administrative agency and says, essentially, "We'll work out a lot of the important details later."
My
expectation is that C-34 will be a significant government priority this fall.
Online safety — particularly child safety — has enormous political appeal. But that does not mean the details don't matter. In fact, it means the details matter even more. If they're going to be so ambitious, they need to really try to get it right.
Part 4: Bill C-36 — Replacing PIPEDA
Then
we have Bill C-36.
This
one was introduced on June 15th — only a few days before the House packed up
for the summer — and it is also waiting at second reading.
If
C-34 is politically flashy, C-36 may actually have the broader long-term
effect.
Because
Bill C-36 would repeal Part 1 of PIPEDA.
PIPEDA
has been Canada's federal private-sector privacy law since 2001.
For
twenty-five years, it has governed how businesses collect, use and disclose
personal information.
Bill
C-36 would replace that regime with a completely new statute called the Protecting
Privacy and Consumer Data Act, or PPCDA.
We've
been here before.
Bill C-11 tried to replace PIPEDA in 2020. It didn’t proceed. Bill C-27 tried again in 2022. It didn’t proceed. So Bill C-36 is kick number three at this particular can.
Much of the substance will be familiar to anyone who followed Bill C-27.
- There are more detailed accountability requirements.
- Documented privacy management programs.
- More detailed consent rules.
- New consent exceptions based on business activities and legitimate interests.
- Formal rules dealing with anonymized and de-identified information.
- A right to disposal of personal information.
- Data mobility.
- Privacy impact assessments for international transfers.
- Much stronger enforcement.
- And enormous potential penalties.
Administrative
monetary penalties can reach the greater of $10 million or three percent of
global gross revenue.
And
serious offences can attract fines of up to the greater of $25 million or five
percent of global gross revenue.
That
should get the attention of corporate boards.
But
perhaps the most interesting change is institutional.
For
almost twenty-five years, federal private-sector privacy law has been overseen
by the Privacy Commissioner of Canada — an independent officer of Parliament.
Bill
C-36 would fundamentally change that.
The
existing Privacy Commissioner would no longer be the regulator administering
this law.
Instead,
we would get a new Privacy and Consumer Data Commissioner operating inside this
broader Digital Safety and Data Protection Commission. That Commission would
also function as a tribunal when organizations challenge findings and
penalties. And I think that is going to be one of the most important issues
Parliament has to examine.
Why
are we moving privacy regulation away from an independent officer of
Parliament? What problem is that intended to solve?
How
independent will the new Privacy and Consumer Data Commissioner actually be?
And
have sufficient institutional walls been built between the investigative side
and the tribunal side?
I
don't particularly like the idea of having the investigator, prosecutor and
adjudicator all living under one institutional roof.
Maybe
that structure can work. But if that's what Parliament wants to create, the
firewalls need to be very clear and I don’t see them in the text of the Bill.
Part 5: The Other Big C-36 Issues
There are a bunch of substantive issues I expect will get attention at committee. Consent is one. Bill C-36 requires organizations to provide considerably more information for consent to be valid.
At the same time, it introduces broader alternatives to consent through legitimate interests and specified business activities. So Parliament is simultaneously making consent more demanding and creating more circumstances in which organizations don't need it.
That
tension deserves some careful thought. It works in Europe, but we’re not doing
exactly what they’ve done in Europe.
International transfers are another. Organizations transferring personal information outside Canada would have to undertake privacy impact assessments. That's a significant departure from the relatively technology-neutral accountability model we've had under PIPEDA.
And then there is the private right of action. Bill C-36 would allow an individual affected by a contravention to sue for loss or injury arising from it, including in provincial superior courts. I think that provision needs considerable work. Depending on how it is interpreted, a privacy contravention involving millions of individuals could produce an enormous multiplicity of proceedings.
There is also a bigger policy question. What do we actually want Canadian privacy law to accomplish in 2026 and beyond? We're now writing the law that could govern data processing for another generation. This is not the place for Parliament to rush. Bill C-36 isn't a tune-up. It is a wholesale replacement of Canada's federal private-sector privacy regime.
Part 6: Bill C-22 — Lawful Access Goes to the Senate
And then we come to Bill C-22. This one is at a completely different stage. Unlike C-34 and C-36, Bill C-22 made it through the House before the summer break. On June 18th, the House passed Bill C-22 at third reading, and the Senate gave it first reading that same day. So when Parliament returns, the lawful-access debate moves principally to the Senate.
If
you've watched my previous episode, you know I have some pretty significant
concerns about this bill.
Bill C-22 has two major substantive pieces. Part 1 creates new and modified investigative tools.
There
is a new confirmation-of-service demand, allowing police and CSIS in
specified circumstances to require telecommunications service providers to
confirm whether they provide services associated with a person or identifier.
There
is a new subscriber-information production order operating on the relatively
low threshold of reasonable grounds to suspect.
There
are changes dealing with voluntary disclosure, publicly available information,
tracking orders, transmission data and other investigative powers.
This
part is considerably better than what the government originally proposed in
Bill C-2, the Strong Borders Act, but I still have issues with Part 1.
Part 2 is where I remain much more concerned. It creates the Supporting Authorized Access to Information Act. That law would create a framework under which electronic service providers can be required to build and maintain technical capabilities to facilitate authorized government access to information.
And
"electronic service provider" is defined VERY broadly.
We're
not just talking about Bell, Rogers and Telus. We're likely talking about cloud
providers, social media services, online gaming companies, messaging services,
VPNs and other digital businesses.
The
legislation allows obligations to be placed on designated core providers
through regulations.
It
also gives the Minister of Public Safety authority to issue secret orders to
individual service providers, subject to approval by the Intelligence
Commissioner.
And it provides for mandatory retention of specified categories of metadata. The House did make important amendments before passing the bill. The maximum metadata retention period was reduced from one year to six months. The provisions dealing with systemic vulnerabilities were improved, but definitely not fixed.
The
government is still creating a permanent statutory framework under which
private companies can be required to design their systems so that government
access can be facilitated.
And
that raises some enormous questions about privacy, cybersecurity,
proportionality and the future design of communications infrastructure.
As I said in my earlier episode, I think Part 1 is largely fixed. Part 2 is better than what we saw before, but I still think it is deeply problematic.
Part 7: The Senate Could Really Matter
And that makes the Senate particularly important this fall. The House consideration of C-22 ended very quickly. On June 17th, the government obtained a programming motion that dramatically compressed the remaining committee and House proceedings, and the bill was passed by the Commons on June 18th.
So
the Senate now has an opportunity to give the legislation the detailed scrutiny
that a bill of this significance deserves.
I hope Senators take that opportunity. I would expect witnesses from law enforcement and national security agencies. I would expect privacy and civil-liberties advocates. I would expect telecommunications companies and major technology companies. I hope there are cybersecurity and encryption experts. And I hope Senators spend a lot of time on a fundamental question:
What
technological capabilities should the government be permitted to require
private companies to build in advance, so they are available if government
wants to use them later?
That is a very different question from whether police should be able to get a warrant. Of course police should be able to get warrants where the legal requirements are met. The much harder question is whether we should redesign communications infrastructure to make surveillance easier. Those are not the same thing.
Part 8: The Bigger Picture
And
that's why I think these three bills need to be looked at together.
With
Bill C-34, the government wants online services to know more about their users'
ages and identities so they can control access and manage harmful content.
With
Bill C-36, the government is completely rewriting the rules governing how
businesses collect and use personal information.
And
with Bill C-22, the government wants to ensure that information and technical
capabilities exist so law enforcement and national security agencies can obtain
data when legally authorized to do so.
There are legitimate public-policy objectives behind all three. Protecting children online is important. Most folks in the field agree that modernizing our privacy law is overdue. Giving police appropriate tools to investigate serious crime in a digital world is necessary. (Emphasis on “appropriate”.)
But good objectives do not automatically produce good legislation. And one of the recurring themes running through all three bills is information architecture. What data are companies required to collect? What data are they permitted to use? What data must they retain? What technological systems must they build? Who gets access to that information? Who is the “customer”? The police? Who regulates all of this? And what checks exist on those regulators and government agencies?
Those
questions are going to shape the Canadian internet for years.
Part 9: What I Will Be Watching
So
here is my fall 2026 privacy and digital-policy watch list.
For Bill
C-34, watch the age-16 restriction, age-verification requirements,
freedom-of-expression issues, the treatment of AI and the enormous amount of
substantive law being left to regulations and Commission rule-making.
For Bill
C-36, watch the fate of the existing Privacy Commissioner, the structure
and independence of the new regulator, consent and legitimate interests,
cross-border transfers, the private right of action and the penalty regime.
And
for Bill C-22, watch the Senate. Particularly watch what Senators do
with Part 2, metadata retention, technical capability requirements, ministerial
orders, encryption and cybersecurity protections.
And there is one final thing to watch: Speed. We've seen governments try to enact major digital-policy reforms only to have them die because they were too controversial, too complicated or simply ran out of parliamentary runway. Privacy law reform Bills C-11 and C-27 never became law. Online Harms Bill C-63 never became law. The lawful-access proposals in Bill C-2 did not survive in that form.
So introducing legislation is one thing, getting it through both Houses of Parliament is entirely different.
Bill
C-22 is already well down that road. C-34 and C-36 are just getting started.
And
I suspect we're going to know a lot more by Christmas about how serious the
government is about getting each of them enacted.
Conclusion
So
buckle up. The fall of 2026 will be enormously consequential for Canadian
privacy and technology law.
And I expect I'll have plenty to talk about over the next few months.
No comments:
Post a Comment