Monday, September 14, 2026

Why Bill C-34’s Social Media Ban for Kids Is Unconstitutional

In my last episode about Bill C-34, the SafeSocial Media Act, I said that one provision jumped out at me as particularly constitutionally vulnerable: the rule that would keep people under sixteen from having accounts on social media services.

I said then that social media is fundamentally expressive. Teenagers have freedom of expression too. And telling a fifteen-year-old that the government will not allow them to have an Instagram account is very different from telling them they cannot buy a bottle of whisky.

Well, since then, something very interesting has happened in France.

France passed a remarkably similar law restricting social media use by young people. And on August 14, 2026, the French Constitutional Council struck down the core of that law as unconstitutional.

Canada is not France. The French Constitution is not the Canadian Charter of Rights and Freedoms. And the legal tests are not identical. But when you read the French decision, the reasoning sounds remarkably familiar to a Canadian constitutional lawyer.

Are there legitimate issues with social media, particularly for kids? Yes.

Is addressing this a “legitimate government objective”? Yes.

But a broad prohibition on young people using social media?

It is too blunt an instrument. It is too broad. And it is not sufficiently connected to the actual risks.

In Canada, I think we would reach much the same result under section 2(b) of the Charter and, particularly, the minimal impairment part of the Oakes test.

And today we’re going to do some constitutional law. Yippee!

Part One: What Bill C-34 Actually Does

First, let's be precise about what Bill C-34 says.

It does not literally say that every person under sixteen is forbidden from ever looking at social media.


Instead, section 27 says that operators of social media services selected by regulation have to use age verification or age estimation measures designed to prevent anyone under sixteen from having an account or otherwise being registered with the service. Section 28 allows the government to prescribe additional measures to accomplish exactly the same thing.

That distinction matters.

A fifteen-year-old might still be able to look at some publicly available material without an account.

But they cannot post. They cannot comment. They cannot participate through an account. They cannot use the platform in the way that social media is fundamentally designed to be used.

And there is an “escape hatch” that makes this less absolute.

Under section 29, the operator of a social media service can apply to the Digital Safety Commission for an exemption from the ban if the Commission concludes that the service provides “adequate safeguards” for children. The government can make regulations establishing the criteria, and the Commission can issue guidelines.


But notice what this exemption is not.

It is not an exemption for a particular fifteen-year-old.

It is not parental consent. (Parents have no say over any of this.)

It is not an assessment of whether this particular young person can safely use this particular service.

It is essentially a service-by-service exemption. The platform gets exempted, not the child.

Part Two: Section 2(b) of the Charter

The first Charter question is relatively straightforward.

Section 2(b) protects freedom of thought, belief, opinion and expression. It also includes freedom of “other media of communication.”

Fundamental freedoms

2 Everyone has the following fundamental freedoms:

(a) freedom of conscience and religion;

(b) freedom of thought, belief, opinion and expression, including freedom of the press and other media of communication;

(c) freedom of peaceful assembly; and

(d) freedom of association.

The Supreme Court of Canada has interpreted “expression” extremely broadly. The basic rule coming out of cases like IrwinToy is that an activity is expressive if it attempts to convey meaning.

Posting a video is expression. Writing a comment is expression. Participating in a political discussion is expression. Sharing your artwork is expression. Talking about your school, your community or your favourite hockey team is expression. And social media has become one of the principal places where people do all of those things.

If you just look at the definitions of “social media service” in the Bill, you can see that what makes a service “in scope” of the Bill is the fact that it enables accessing, sharing and communicating content. That is expression.

In fact, Bill C-34 itself recognizes the importance of freedom of expression but perhaps in more of a “window dressing” kind of way. One of the statutory purposes is to mitigate online harms while respecting freedom of expression, and another is to enable people in Canada to participate fully in public discourse and exercise their freedom of expression online.

The Bill even tells the Digital Safety Commission that when it makes regulations and guidelines, it has to take freedom of expression into account.

The social media ban for kids doesn’t take freedom of expression into account.

I don't think the government gets very far arguing that section 2(b) isn't engaged. It is clearly engaged.

The government is imposing a legal rule that prevents a class of people from obtaining the accounts they need to participate in major forums for expression. That is a restriction on expression, plain and simple.

Which takes us to section 1 of the Charter.

1 The Canadian Charter of Rights and Freedoms guarantees the rights and freedoms set out in it subject only to such reasonable limits prescribed by law as can be demonstrably justified in a free and democratic society.

Part Three: The Oakes Test

A violation of a Charter right is not necessarily unconstitutional.

Section 1 allows governments to impose reasonable limits on Charter rights if those limits can be demonstrably justified in a free and democratic society.

The test to determine if a government measure that limits a Charter can be demonstrably justified in a free and democratic society is called the Oakes test.

Very simplified, the government needs an important objective. The measure chosen by the government has to be rationally connected to that objective. It must impair the Charter right no more than is reasonably necessary. And, finally, the benefits have to justify the harm to the protected right.

I don't think the government is going to have much trouble at the first stage.

Bill C-34 expressly says one of its purposes is protecting children's physical and mental health.

There are legitimate concerns about young people and social media. There are legitimate concerns about harmful content, addictive or manipulative features, bullying and other risks. I am quite prepared to assume in this analysis that protecting children from those harms is a pressing and substantial objective.

I would probably give the government “rational connection” as well. If you keep children completely off a service, they obviously cannot be harmed by that service while they are off it. But that is far from the end of the analysis.

The really difficult question is: Do you have to keep them off the service altogether?

That's minimal impairment. And that is where I think this provision is in serious trouble.

Part Four: Minimal Impairment Does Not Mean “Anything That Works”

The Supreme Court does give governments some latitude here.

Minimal impairment does not mean that a judge gets to dream up some theoretically perfect alternative and strike down legislation because Parliament did not choose it. Governments are generally allowed a range of reasonable policy choices. But there is still a constitutional limit.

The question is whether the government can achieve its objective, in a real and substantial way, through a measure that interferes significantly less with the Charter right.

The Supreme Court's decision in RJR-MacDonald is particularly interesting. That case dealt with a broad prohibition on tobacco advertising. The majority emphasized that a complete prohibition on expression is more difficult to justify than a partial prohibition, particularly where the government has not demonstrated why narrower measures would be inadequate.

And in a case called Carter, the Court made essentially the same point in a very different context: an absolute prohibition was not minimally impairing where a carefully designed system of safeguards could substantially accomplish the government's protective objective. 

Now, the government has a very good case it will undoubtedly rely upon: Irwin ToyThat was the famous case involving Quebec's prohibition on commercial advertising directed at children under thirteen. The Supreme Court found a section 2(b) violation but upheld the restriction under section 1. 

But there is an enormous difference.

Irwin Toy restricted what advertisers could say to young children. It regulated commercial expression directed at a particularly vulnerable audience. Bill C-34 restricts what young people themselves can do.

It removes their ability to participate through an account in an entire medium of communication, including political, educational, artistic, cultural and ordinary social expression.

Those are very different Charter interests.

Part Five: And Then There Is France

This is where the French decision becomes really interesting.

First, a quick note about the French Constitutional Council: its mandate includes reviewing certain laws after they are passed by the legislature but before they are signed into law. It’s kind of like an automatic reference to the Supreme Court. I think that’s a cool protection for constitutional rights.

Back to the social media ban: The French Constitutional Council began by recognizing essentially the same thing that I was just talking about: online communication services have become important to participation in democratic life and the expression of ideas and opinions. It concluded that freedom of expression therefore includes the freedom to access and express oneself through those services.

Then it acknowledged the government's legitimate concern.

The legislature was trying to protect young people from risks associated with social networks. The Constitutional Council accepted that protecting children could justify some restrictions.

But then it looked at what the law actually did.

The prohibition was not sufficiently tied to the particular functions of a service, the content it offered, the dangers it presented or the adequacy of its protections. It could therefore apply to services where a risk to children's health or safety had not actually been established. And the law treated all children under fifteen alike.

There was no mechanism for a parent, properly informed about the risks and safeguards, to authorize access. There was no individualized consideration of the child's age, maturity or circumstances, or of the particular service involved.

The Constitutional Council therefore concluded that the general prohibition was not appropriate, necessary and proportionate to the objective.

And it struck it down.

Does that decide the Canadian question? Nope. But it is almost a textbook description of the minimal-impairment problem with Bill C-34’s social media ban.

Part Six: The Canadian Law Is Different — But Not Different Enough

There are some important differences between the French law and Canada’s Bill C-34..

The Canadian scheme is somewhat more targeted. The government has to specify the regulated social media services or classes of services to which the under-sixteen rule will apply. This is solely based on the number of users, so has nothing to do with specific risks to specific kids.

And Canada has the section 29 exemption for services with adequate safeguards. (Which will likely only come into effect years after the bill becomes law and the Digital Safety Commission gets its stuff together.)

Bill C-34 also deals with the privacy implications of age verification more explicitly than the French law did. It limits the purposes for which age-verification information can be collected and requires its destruction after verification or estimation is completed.

Those differences matter, but they don’t solve the central section 2(b) problem.

Once a service has been selected, the rule right out of the gate is still: if you are fifteen, you don't get an account.

It doesn't matter why you want the account. It doesn't matter whether you're using it to talk about politics, follow community organizations, publish your photography, participate in a school activity or just talk to your friends.

It doesn't matter whether your parents think you're capable of using it responsibly.

And it doesn't matter whether the particular feature you want to use has anything to do with the harm that Parliament is trying to prevent.

That is a very broad response to a much more specific collection of problems.

Part Seven: The Strangest Part Is That Bill C-34 Already Contains the Alternatives

And this is what I think makes the minimal-impairment argument especially powerful.

Bill C-34 itself contains a whole range of less intrusive tools for protecting children.

Section 21 allows age-appropriate design requirements. Section 32 requires social media operators to implement measures to mitigate exposure to harmful content. Other provisions require blocking tools. And the Commission's regulation-making powers expressly contemplate things like children's account options, parental controls and other age-appropriate design features.

In other words, Parliament has already written a menu of more targeted interventions into the same statute.

  • Protective defaults.
  • Parental controls.
  • Age-appropriate account settings.
  • Restrictions aimed at particular risky features.
  • Measures aimed at harmful content.

Those approaches regulate the risk.

The under-sixteen ban regulates the person.

And that is exactly the question the government is going to have to answer in a Charter challenge: why aren't those less rights-infringing measures enough?

The government does not have to prove that no conceivable alternative exists. But it does have to justify the level of impairment it has chosen. And saying “social media can be harmful to kids” doesn't answer that question.

Conclusion

None of this means that social media is harmless.

And it doesn't mean that Parliament is powerless to regulate it.

The Charter does not require the government to sit on its hands while children are exposed to risks. It does, however, require the government to respond to those risks with some degree of precision.

Target the dangerous features.

Target the harmful content.

Require safer design.

Give parents useful controls.

Impose obligations on the platforms that are actually creating the risk.

But telling every fifteen-year-old that they cannot have an account on a designated social media service is something very different.

France's Constitutional Council has now confronted essentially the same constitutional tension. It accepted that the harms were real. It accepted that protecting children was legitimate. But it concluded that those legitimate concerns did not justify a general prohibition that swept far beyond the risks the government was trying to address.

Canadian courts will have to take a different constitutional route, but I am pretty confident they will arrive at the same destination.

If Bill C-34 is enacted in its current form and the under-sixteen account restriction is challenged, I think minimal impairment is where it breaks.

And I don't think putting an exemption process at the end of an overly broad prohibition fixes the problem at the beginning.

I realize that a social media ban for young people is very popular and politically wonderful, but we exist in a country with rights. A fifteen year old has the same right to freedom of expression as I do. I can have an account on YouTube to share my thoughts on privacy, technology and important public policy matters. Once Bill C-34 is passed – if it is passed in its current form – young people will not be able to do that. And that, in my view, is a serious issue that needs to be front and centre in the discussion of Bill C-34 when Parliament gets back from its summer break.

And I should note, as I wrap up, that I also think this violates adults’ Charter rights, because adults will have to jump through privacy-risking age verification measures before being allowed to use social media. I’m not sure that can be fully justified under the Oakes test, either.

Monday, August 24, 2026

Privacy, Online Harms and Lawful Access: Keep an eye on Parliament this fall

If you care about privacy, the internet, artificial intelligence, social media, free expression, cybersecurity or government surveillance, you probably want to keep an eye on Ottawa this fall.

Because Parliament comes back from its summer break on September 21st, and waiting for MPs and Senators are three important pieces of legislation.

We have Bill C-34, the Safe Social Media Act, which would create an entirely new regulatory regime for social media, online harms and AI chatbots. Including a social media ban for anyone under 16.

We have Bill C-36, the Protecting Privacy and Consumer Data Act, which would repeal and replace the privacy portions of PIPEDA — Canada's private-sector privacy law for the last quarter-century.

And then we have Bill C-22, the Lawful Access Act, 2026, which has already made it through the House of Commons and is now sitting in the Senate.

Each one of these bills would be important on its own.

Taken together, this could be one of the most consequential sessions of Parliament for Canadian privacy and digital policy that we've seen in years.

Hi. My name is David Fraser. I'm a privacy, internet and technology lawyer with the Canadian law firm McInnes Cooper. I also teach Internet and Media Law at the Schulich School of Law at Dalhousie University.

I've already done detailed episodes on each of these bills, so I'm not going to go through every clause again. I’ll link to the previous episodes below.

Instead, I want to talk about where these bills stand, what they would actually do, and — most importantly — what we should be watching when Parliament gets back to work this fall.

Part 1: Three Different Bills — One Enormous Digital Policy Agenda

I think it's useful to start by looking at these three bills together.

Because they deal with different things, but they really are pieces of the same larger picture. And I think a fourth piece is coming.

Bill C-34 is about what online platforms are required to do.

Bill C-36 is about what organizations can do with our personal information and how they are regulated.

And Bill C-22 is about how law enforcement and national security agencies can obtain information and what technological capabilities companies may be required to build to facilitate that access.

So we are talking about regulation of platforms. Regulation of data. And government access to data.

That is a pretty significant chunk of Canada's digital policy landscape.

And there is another important connection between C-34 and C-36.

Bill C-34 creates a new Digital Safety Commission of Canada. Bill C-36 would expand and restructure that institution into a Digital Safety and Data Protection Commission of Canada, which would also become central to the enforcement of Canada's new private-sector privacy law.

In other words, we aren't just talking about three new statutes.

We may be watching the construction of an entirely new federal digital regulatory architecture.

And I fully expect we will have a bill to regulate artificial intelligence, and I bet the Digital Safety and Data Protection Commission will also have oversight of AI.

That deserves attention.

Part 2: Bill C-34 — The Safe Social Media Act

Let's start with Bill C-34.

The government introduced the Safe Social Media Act on June 10th, just before Parliament rose for the summer. It received first reading and is now sitting at second reading in the House of Commons.

This is essentially the government's replacement for Bill C-63, the Online Harms Act, which died when Parliament was prorogued before the last election.

But C-34 isn't simply C-63 with a new name.

There are some pretty significant changes.

The legislation would regulate three broad categories of services: social media services, AI chatbot services and potentially other highly interactive online services that the government considers sufficiently risky to children. Exactly which services are caught will depend enormously on regulations that have not yet been written.

Perhaps the most significant addition between C-63 and Bill C-34 is a social media ban for those under 16. Bill C-34 says that users have to be at least 16 years old to have an account on a regulated social media service unless the service obtains an exemption from the new Commission. And the ban will surely go into effect before the Commission has established criteria for exemptions.

It also requires age-assurance measures for services carrying pornographic content.

And that creates a glaring privacy problem.

To keep people under 16 off social media, social media companies have to figure out who is under 16.

Which means they have to determine the age of everybody.

So legislation promoted as a child-safety measure could result in an enormous new infrastructure for age verification or age estimation across the Canadian internet.

That is going to raise some very difficult questions.

What information are companies going to collect to establish age?

Do you have to upload government identification?

Can platforms use facial age-estimation technology?

Can third-party identity providers do this?

What data gets retained?

And perhaps most fundamentally: how much additional information should adults have to provide about themselves just to use an online service?

There are also very significant freedom-of-expression questions.

Despite some people comparing “Big Tech” with “Big Tobacco”, social media is not cigarettes or booze or gambling.

Social media is fundamentally a medium of expression.

Young people use it to communicate with friends, participate in political discussions, organize, create art, learn about the world and express themselves.

So an outright age restriction raises Charter questions that I expect will receive considerable attention if this bill gets to committee.

Bill C-34 also creates four broad categories of duties for regulated operators: duties to protect children, to be transparent, to act responsibly, and to make certain content inaccessible.

The legislation continues to regulate seven categories of harmful content, ranging from intimate content communicated without consent and content that victimizes children through to bullying, hatred, violence and violent extremism.

And AI is explicitly part of this.

Regulated chatbot services would have obligations designed to prevent them from impersonating human beings or professionals and from encouraging unhealthy emotional relationships with users.

Synthetic audio and visual content would also have to be identified in certain circumstances.

So this isn't just a social-media law. It will affect a LOT of the internet.

It's also one of Canada's first significant attempts to directly regulate consumer-facing generative AI.

And then there is the regulator itself.

The new Digital Safety Commission would have significant investigation, rule-making and enforcement powers, backed by potentially enormous administrative monetary penalties — up to the greater of $20 million or five percent of global gross revenue in some circumstances.

A HUGE amount of the actual operation of this legislation is also left to future regulations and rules made by the Commission. And, as a result, so much will be determined by who is appointed to the Commission.

So when C-34 gets to committee, I would expect a lot of attention to be focused not just on what the bill says, but on how much Parliament is being asked to leave for somebody else to decide later.

Part 3: What to Watch on C-34 This Fall

There are four things I'll particularly be watching.

First, the 16-year-old social media restrictionDoes it survive in its current form? And if it does, what safeguards are added around age verification?

Second, freedom of expressionDoes Parliament seriously grapple with the Charter implications of excluding younger Canadians from major platforms for communication and expression? It will be interesting to see how the government tries to stickhandle this in their Charter Statement for Bill C-34.

Third, the scope of the legislationHow far beyond Facebook, Instagram and TikTok does this go? Gaming? YouTube? Online communities? AI services?

The more services that can potentially be brought in by regulation, the more important that question becomes. 

And fourth, the power of the regulatorParliament should be very careful whenever it creates a powerful new administrative agency and says, essentially, "We'll work out a lot of the important details later."

My expectation is that C-34 will be a significant government priority this fall.

Online safety — particularly child safety — has enormous political appeal. But that does not mean the details don't matter. In fact, it means the details matter even more. If they're going to be so ambitious, they need to really try to get it right.

Part 4: Bill C-36 — Replacing PIPEDA

Then we have Bill C-36.

This one was introduced on June 15th — only a few days before the House packed up for the summer — and it is also waiting at second reading.

If C-34 is politically flashy, C-36 may actually have the broader long-term effect.

Because Bill C-36 would repeal Part 1 of PIPEDA.

PIPEDA has been Canada's federal private-sector privacy law since 2001.

For twenty-five years, it has governed how businesses collect, use and disclose personal information.

Bill C-36 would replace that regime with a completely new statute called the Protecting Privacy and Consumer Data Act, or PPCDA.

We've been here before.

Bill C-11 tried to replace PIPEDA in 2020. It didn’t proceed. Bill C-27 tried again in 2022. It didn’t proceed. So Bill C-36 is kick number three at this particular can. 

Much of the substance will be familiar to anyone who followed Bill C-27.

  • There are more detailed accountability requirements.
  • Documented privacy management programs.
  • More detailed consent rules.
  • New consent exceptions based on business activities and legitimate interests.
  • Formal rules dealing with anonymized and de-identified information.
  • A right to disposal of personal information.
  • Data mobility.
  • Privacy impact assessments for international transfers.
  • Much stronger enforcement.
  • And enormous potential penalties.

Administrative monetary penalties can reach the greater of $10 million or three percent of global gross revenue.

And serious offences can attract fines of up to the greater of $25 million or five percent of global gross revenue.

That should get the attention of corporate boards.

But perhaps the most interesting change is institutional.

For almost twenty-five years, federal private-sector privacy law has been overseen by the Privacy Commissioner of Canada — an independent officer of Parliament.

Bill C-36 would fundamentally change that.

The existing Privacy Commissioner would no longer be the regulator administering this law.

Instead, we would get a new Privacy and Consumer Data Commissioner operating inside this broader Digital Safety and Data Protection Commission. That Commission would also function as a tribunal when organizations challenge findings and penalties. And I think that is going to be one of the most important issues Parliament has to examine.

Why are we moving privacy regulation away from an independent officer of Parliament? What problem is that intended to solve?

How independent will the new Privacy and Consumer Data Commissioner actually be?

And have sufficient institutional walls been built between the investigative side and the tribunal side?

I don't particularly like the idea of having the investigator, prosecutor and adjudicator all living under one institutional roof.

Maybe that structure can work. But if that's what Parliament wants to create, the firewalls need to be very clear and I don’t see them in the text of the Bill.

Part 5: The Other Big C-36 Issues

There are a bunch of substantive issues I expect will get attention at committee. Consent is one. Bill C-36 requires organizations to provide considerably more information for consent to be valid.

At the same time, it introduces broader alternatives to consent through legitimate interests and specified business activities. So Parliament is simultaneously making consent more demanding and creating more circumstances in which organizations don't need it.

That tension deserves some careful thought. It works in Europe, but we’re not doing exactly what they’ve done in Europe. 

International transfers are another. Organizations transferring personal information outside Canada would have to undertake privacy impact assessments. That's a significant departure from the relatively technology-neutral accountability model we've had under PIPEDA.

And then there is the private right of action. Bill C-36 would allow an individual affected by a contravention to sue for loss or injury arising from it, including in provincial superior courts. I think that provision needs considerable work. Depending on how it is interpreted, a privacy contravention involving millions of individuals could produce an enormous multiplicity of proceedings.

There is also a bigger policy question. What do we actually want Canadian privacy law to accomplish in 2026 and beyond? We're now writing the law that could govern data processing for another generation. This is not the place for Parliament to rush. Bill C-36 isn't a tune-up. It is a wholesale replacement of Canada's federal private-sector privacy regime.

Part 6: Bill C-22 — Lawful Access Goes to the Senate

And then we come to Bill C-22. This one is at a completely different stage. Unlike C-34 and C-36, Bill C-22 made it through the House before the summer break. On June 18th, the House passed Bill C-22 at third reading, and the Senate gave it first reading that same day. So when Parliament returns, the lawful-access debate moves principally to the Senate.

If you've watched my previous episode, you know I have some pretty significant concerns about this bill. 

Bill C-22 has two major substantive pieces. Part 1 creates new and modified investigative tools.

There is a new confirmation-of-service demand, allowing police and CSIS in specified circumstances to require telecommunications service providers to confirm whether they provide services associated with a person or identifier.

There is a new subscriber-information production order operating on the relatively low threshold of reasonable grounds to suspect.

There are changes dealing with voluntary disclosure, publicly available information, tracking orders, transmission data and other investigative powers.

This part is considerably better than what the government originally proposed in Bill C-2, the Strong Borders Act, but I still have issues with Part 1.

Part 2 is where I remain much more concerned. It creates the Supporting Authorized Access to Information ActThat law would create a framework under which electronic service providers can be required to build and maintain technical capabilities to facilitate authorized government access to information.

And "electronic service provider" is defined VERY broadly.

We're not just talking about Bell, Rogers and Telus. We're likely talking about cloud providers, social media services, online gaming companies, messaging services, VPNs and other digital businesses.

The legislation allows obligations to be placed on designated core providers through regulations.

It also gives the Minister of Public Safety authority to issue secret orders to individual service providers, subject to approval by the Intelligence Commissioner.

And it provides for mandatory retention of specified categories of metadata. The House did make important amendments before passing the bill. The maximum metadata retention period was reduced from one year to six monthsThe provisions dealing with systemic vulnerabilities were improved, but definitely not fixed.

The government is still creating a permanent statutory framework under which private companies can be required to design their systems so that government access can be facilitated.

And that raises some enormous questions about privacy, cybersecurity, proportionality and the future design of communications infrastructure.

As I said in my earlier episode, I think Part 1 is largely fixed. Part 2 is better than what we saw before, but I still think it is deeply problematic.

Part 7: The Senate Could Really Matter

And that makes the Senate particularly important this fall. The House consideration of C-22 ended very quickly. On June 17th, the government obtained a programming motion that dramatically compressed the remaining committee and House proceedings, and the bill was passed by the Commons on June 18th.

So the Senate now has an opportunity to give the legislation the detailed scrutiny that a bill of this significance deserves.

I hope Senators take that opportunity. I would expect witnesses from law enforcement and national security agencies. I would expect privacy and civil-liberties advocates. I would expect telecommunications companies and major technology companies. I hope there are cybersecurity and encryption experts. And I hope Senators spend a lot of time on a fundamental question:

What technological capabilities should the government be permitted to require private companies to build in advance, so they are available if government wants to use them later?

That is a very different question from whether police should be able to get a warrant. Of course police should be able to get warrants where the legal requirements are met. The much harder question is whether we should redesign communications infrastructure to make surveillance easier. Those are not the same thing.

Part 8: The Bigger Picture

And that's why I think these three bills need to be looked at together.

With Bill C-34, the government wants online services to know more about their users' ages and identities so they can control access and manage harmful content.

With Bill C-36, the government is completely rewriting the rules governing how businesses collect and use personal information.

And with Bill C-22, the government wants to ensure that information and technical capabilities exist so law enforcement and national security agencies can obtain data when legally authorized to do so.

There are legitimate public-policy objectives behind all three. Protecting children online is important. Most folks in the field agree that modernizing our privacy law is overdue. Giving police appropriate tools to investigate serious crime in a digital world is necessary. (Emphasis on “appropriate”.)

But good objectives do not automatically produce good legislation. And one of the recurring themes running through all three bills is information architectureWhat data are companies required to collect? What data are they permitted to use? What data must they retain? What technological systems must they build? Who gets access to that information? Who is the “customer”? The police? Who regulates all of this? And what checks exist on those regulators and government agencies?

Those questions are going to shape the Canadian internet for years.

Part 9: What I Will Be Watching

So here is my fall 2026 privacy and digital-policy watch list.

For Bill C-34, watch the age-16 restriction, age-verification requirements, freedom-of-expression issues, the treatment of AI and the enormous amount of substantive law being left to regulations and Commission rule-making.

For Bill C-36, watch the fate of the existing Privacy Commissioner, the structure and independence of the new regulator, consent and legitimate interests, cross-border transfers, the private right of action and the penalty regime.

And for Bill C-22, watch the Senate. Particularly watch what Senators do with Part 2, metadata retention, technical capability requirements, ministerial orders, encryption and cybersecurity protections.

And there is one final thing to watch: Speed. We've seen governments try to enact major digital-policy reforms only to have them die because they were too controversial, too complicated or simply ran out of parliamentary runway. Privacy law reform Bills C-11 and C-27 never became law. Online Harms Bill C-63 never became law. The lawful-access proposals in Bill C-2 did not survive in that form.

So introducing legislation is one thing, getting it through both Houses of Parliament is entirely different.

Bill C-22 is already well down that road. C-34 and C-36 are just getting started.

And I suspect we're going to know a lot more by Christmas about how serious the government is about getting each of them enacted.

Conclusion

So buckle up. The fall of 2026 will be enormously consequential for Canadian privacy and technology law.

And I expect I'll have plenty to talk about over the next few months. 

Monday, June 29, 2026

Canada's proposed new privacy law: Bill C-36, the Protecting Privacy and Consumer Data Act

The Personal Information Protection and Electronic Documents Act, known as PIPEDA, has been Canada's private sector privacy law since 2001.

It's currently the law that governs how businesses collect, use and disclose your personal information. It's the law that made the Privacy Commissioner of Canada the federal privacy watchdog. And it's the law that most privacy professionals in Canada have built their careers around.

But now, the federal government has tabled Bill C-36, which would repeal and replace the privacy portions of PIPEDA with an entirely new framework.

And if you've been following federal privacy reform over the last few years, a lot of this will look familiar.

We've seen Bill C-11, the Digital Charter Implementation Act, 2020.

We've seen Bill C-27, Digital Charter Implementation Act, 2022.

Both died on the Order Paper.

Now we have Bill C-36 called the Protecting Privacy and ConsumerData Act.

But this bill does something that neither of those previous bills did.

It completely sidelines the existing Privacy Commissioner of Canada and hands enforcement to an entirely new regulatory structure that seems to be part of what I expect will be the super-mega digital regulator for Canada.

In this episode, I'm going to walk you through what Bill C-36 does, what's new, what's familiar, what businesses need to know, and what I think are some of the most significant changes.

On June 15, 2026, the Minister of Artificial Intelligence and Digital Innovation tabled Bill C-36, titled An Act to enact the Protecting Privacy and Consumer Data Act, to amend the Personal Information Protection and Electronic Documents Act and to make amendments to other Acts.

The centrepiece of the bill is a new law called the Protecting Privacy and Consumer Data Act, or PPCDA.

If passed, it would replace Part 1 of PIPEDA, which has governed private-sector privacy in Canada since 2001.

I don’t really like the name of the new law. On one hand, the law says that privacy is a fundamental right, but in the title it’s about people as “consumers”. If we have a fundamental right, it’s because we’re humans, not just consumers. I think it puts it all in a bad frame.

But in any event, let's dig in.

Déjà Vu All Over Again

If you've read Bill C-27, much of Bill C-36 will look very familiar. In substance, it takes PIPEDA and turns the obligations up to eleven. 

Many of the concepts are carried forward:

  • accountability obligations;
  • privacy management programs;
  • enhanced consent requirements;
  • legitimate interest exceptions;
  • rights to disposal of personal information;
  • data mobility provisions;
  • administrative monetary penalties; and
  • a much stronger enforcement framework.

What's missing, however, is the artificial intelligence legislation that was bundled into Bill C-27. It’s not really missing since it didn’t belong in Bill C-27 in the first place.

This new bill focuses exclusively on private-sector privacy law.

The Biggest Surprise — Goodbye Privacy Commissioner?

In my view, the most significant structural change is not about consent, de-identification or penalties. We expected that. 

It's about who oversees and enforces the law.

Historically, privacy complaints under PIPEDA have been investigated by the Privacy Commissioner of Canada.

The Commissioner acts primarily as an ombudsman. Complaints are investigated. Findings are issued. Organizations are encouraged to comply. And they can be named and shamed. And if things don't get resolved, the matter may end up in Federal Court, where orders can be issued and damages can be awarded.

Bill C-27 from 2002 would have given the Privacy Commissioner the power to investigate complaints and recommend orders and penalties. Those orders and penalties had to be levied by a proposed newly created, separate body called the Personal Information and Data Protection Tribunal.

Bill C-36 replaces the current PIPEDA model entirely by sidelining the current Commissioner.

Instead, oversight would be handled through the Digital Safety and Data Protection Commission of Canada, a new institution that originated in the government's online harms framework. (I covered that in my last episode.) The existing Privacy Commissioner would no longer be the regulator under the statute. Instead, there would be a new Privacy and Consumer Data Commissioner operating within this new commission structure.

This is a big shift.

For nearly twenty-five years, Canadian privacy regulation has been centred on an independent officer of Parliament.

Now, enforcement would be embedded within a broader administrative commission.

Whether that's a good thing or a bad thing will likely become one of the major debates surrounding the bill. The new Commissioner will be less independent and more beholden to the government. At this point, I’m not convinced that it’s a good idea – but I look forward to a lot of discussion about it over the summer.

A New Structure for the Law

Bill C-36 looks very different from PIPEDA. 

PIPEDA has always been a bit unusual. Rather than spelling out all of the rules directly in legislation, it incorporated the Canadian Standards Association Model Code for the Protection of Personal Information.

The law largely worked by saying: follow the Code, subject to these exceptions. Bill C-36 takes a different approach.

Much like the privacy statutes in Alberta and British Columbia, the principles are expressed directly in legislative language. For privacy professionals who work with Canadian federal and provincial laws, this means the substance will often feel familiar.

And because the essence of the principles are embedded directly in statute using traditional statutory language, I expect its interpretation will become more rigid and more legalistic than the current PIPEDA framework.

Expanded Scope?

The government seems to be expanding the scope of the private sector privacy law. One new provision, compared to PIPEDA, is particularly notable. PIPEDA applies to personal information collected, used or disclosed in the course of commercial activities, as well as federally regulated workplaces.

That basic framework remains. Bill C-36 will apply to personal information collected, used or disclosed in the course of commercial activities, as well as federally regulated workplaces.

But Bill C-36 includes a provision that specifically says that the legislation applies to personal information collected, used or disclosed interprovincially or internationally.

For greater certainty

(2) For greater certainty, this Act applies in respect of personal information

(a) that is collected, used or disclosed interprovincially or internationally by an organization; or

(b) that is collected, used or disclosed by an organization within a province, to the extent that the organization is not exempt from the application of this Act under an order made under paragraph 139(2)‍(b).


It’s not limited to data that crosses borders in connection with any commercial activity. Does that mean it applies to data that a Nova Scotia-based non-profit stores in Ontario? Or what about an Alberta company that is subject to Alberta privacy law, which collects information from a British Columbian resident, which is protected by that province’s privacy law. Does the federal law apply once the data crosses the Rocky Mountains?

I think this was probably put here to expand our European GDPR adequacy, so that the new law will explicitly apply to all data transferred from Europe to Canada for processing. But I suspect lawyers and regulators will spend a fair amount of time debating exactly how far this provision reaches.

Bill C-36 explicitly addresses Anonymous vs. De-Identified Data

Another major feature of the bill is its treatment of anonymous and de-identified information.

To date, Canadian privacy law has not directly addressed this concept.

Bill C-36 formally distinguishes among personal information, de-identified personal information and anonymized information.

anonymize means to irreversibly and permanently modify personal information to ensure that there is no reasonably foreseeable risk in the circumstances that an individual can be identified from the information, whether directly or indirectly, by any means.‍ (anonymiser)

For greater certainty

6(5) For greater certainty, this Act does not apply in respect of anonymized information.

de-identify means to modify personal information so that an individual cannot be directly identified from it, although a risk of the individual being identified remains.‍ (dépersonnaliser)

Anonymous information is information that has been irreversibly and permanently modified so there is no reasonably foreseeable risk that an individual can be identified. Anonymous information falls outside the legislation altogether.

De-identified information is different.

The information has been modified so an individual cannot be directly identified, but some risk of re-identification remains. That information continues to be regulated under the Act.

This distinction is important because organizations increasingly rely on de-identification techniques for analytics, research and product development.

The bill provides a much more detailed framework than PIPEDA currently does.

Under Bill C-36, Privacy Management Programs Become Mandatory

Essentially, Principle 1 of PIPEDA required all regulated organizations to have a privacy management program. Bill C-36 makes that expectation explicit.

Organizations must establish and maintain a documented privacy management program. They must also provide supporting documentation to the regulator upon request.

In practical terms, this means:

  • policies;
  • procedures;
  • training materials;
  • risk management documentation; and
  • governance records

All of these become much more important.

For organizations that have treated privacy compliance as an informal exercise, that approach will no longer be sufficient. And very importantly, every organization has to provide a copy of their privacy management program to the regulator upon request. 

Consent Gets More Detailed

The bill retains consent as the principal basis under which personal information can be collected, used or disclosed.

But the Bill significantly expands what organizations must communicate to the individual in order for consent to be valid.

Organizations will need to explain:

(a) the purposes for the collection, use or disclosure of the personal information;

(b) the manner in which the personal information is to be collected, used or disclosed;

(c) any reasonably foreseeable consequences of the collection, use or disclosure of the personal information;

(d) the specific type of personal information that is to be collected, used or disclosed; and

(e) the names of any third parties or types of third parties to which the organization may disclose the personal information.

And these explanations must be provided in plain language.

That’s a lot of information. Imagine trying to convey that at a retail point of sale. Under PIPEDA, conveying the purposes of the collection was done outside of a privacy policy or privacy statement, but this is the sort of information that should be put in a privacy statement. And this is all while folks are saying that privacy policies are too long and unreadable. I think it should be sufficient to communicate the purposes, clearly and understandably, and leave the rest for the privacy policy if the individual has any questions. 

Legitimate Interests and Business Activities

When it comes to consent, one hand giveth and the other taketh away. 

One of the most controversial features of Bill C-27 from 2022 was the introduction of new exceptions to consent. Those provisions largely survive under the proposed Protecting Privacy and Consumer Data Act.

Under Bill C-36, organizations can collect and use personal information without consent for certain business activities where a reasonable person would expect it, for security purposes, for safety purposes and for other prescribed activities.

Business activities

18 (1) An organization may collect or use an individual’s personal information without their knowledge or consent if the collection or use is made for the purpose of a business activity described in subsection (2) and

(a) a reasonable person would expect the collection or use for such an activity; and

(b) the personal information is not collected or used for the purpose of influencing the individual’s behaviour or decisions.

List of activities

(2) Subject to the regulations, the following activities are business activities for the purposes of subsection (1):

(a) an activity that is necessary to provide a product or service that the individual has requested from the organization;

(b) an activity that is necessary for the security of the organization’s information, systems or networks;

(c) an activity that is necessary for the safety of a product or service that the organization provides; and

(d) any other prescribed activity.

However, there is an important limitation.

These exceptions cannot be used where the information is being collected or used to influence an individual's behaviour or decisions.

The bill also includes a legitimate interest exception, which is similar to what is found in Europe’s General Data Protection Regulation.

To rely on it, an organization must carry out a privacy impact assessment to:

  1. identify possible adverse effects on individuals;
  2. take measures to mitigate those effects; and
  3. determine that its legitimate interest outweighs those adverse effects.

This sounds straightforward.

In practice, it may generate substantial debate.

What is influencing an individual’s behaviour or decisions? Does that include search rankings? What video to suggest next? An advertisement?

How do you measure adverse effects?

What counts as sufficient mitigation?

And how should competing interests be balanced?

Those questions are likely to become important very quickly. 

Notably, consent can still be implied if it’s appropriate taking into account the reasonable expectations of the individual and the sensitivity. But then section 15(6) says you can’t use implied consent for any activity listed in 18(2) or 18(3). 

Form of consent

(5)  Consent must be expressly obtained unless, subject to subsection (6), it is appropriate to rely on an individual’s implied consent, taking into account the reasonable expectations of the individual and the sensitivity of the personal information that is to be collected, used or disclosed.

Business activities

(6)  It is not appropriate to rely on an individual’s implied consent if their personal information is collected or used for an activity described in subsection 18(2) or if it is collected, used or disclosed for an activity described in subsection 18(3).

That includes “an activity that is necessary to provide a product or service that the individual has requested from the organization.” Those are exactly the sorts of activities where you should be able to rely on implied consent. The wording of the statute suggests that this is excluded from possible “implied consent”. 

For example, I tap my credit card to pay for a burger. My consent to processing that transaction should be implied without the cashier reciting everything listed in section 15 (like the reasonably foreseeable consequences of the collection, use or disclosure of my credit card number), but because it’s necessary for me to pay for my burger it can’t be implied.

That’s just dumb. That can’t be right. At a technical briefing on the bill, I asked officials with the Industry Department whether this was intentional or bad drafting and they couldn’t explain it. 

Bill C-36 includes a “Right to Disposal”

PIPEDA has long allowed individuals to withdraw consent in many circumstances.

Bill C-36 goes further or is at least more explicit. Under PIPEDA, an individual can withdraw consent. Since the organization can only retain personal information for as long as is reasonably necessary for the purposes for which consent was obtained, it was pretty clear – but implied – that the data should be deleted.

Under Bill C-36, individuals can explicitly require organizations to dispose of their personal information.

Importantly, disposal includes both deletion and anonymization.

This resembles the growing international trend toward stronger deletion rights, although it stops short of adopting a full European-style "right to be forgotten."

The Industry Minister, when speaking about this Bill, suggested this will allow people to have deepfakes deleted. I’m not sure that’s the case across the board. 

Cross-Border Transfers and Privacy Impact Assessments

Another area of note is the treatment of international transfers.

Before personal information is disclosed or transferred outside Canada, organizations would be required to conduct a privacy impact assessment in a prescribed format.

This is noteworthy.

For years, Canadian law has generally allowed cross-border transfers provided appropriate safeguards are in place. The same rules applied to domestic transfers, as well as international ones.

Bill C-36 moves toward a more structured assessment model. Exactly what those assessments must contain will depend on future regulations, and notably these assessments must be provided to the Commission on request. 

Enforcement Gets Serious

And now we come to what many people will consider the headline story.

Enforcement. Lots of enforcement.

Under the bill, investigations may begin following a complaint or on the initiative of the Privacy and Consumer Data Commissioner.

During an investigation, the Commissioner can compel records and testimony, receive any evidence regardless of whether it complies with the traditional rules of evidence, and enter and search any premises other than a dwelling. 

Following an investigation, the Commissioner may issue a notice of contravention. That notice can include proposed orders and proposed penalties.

If the organization does not challenge the notice, the contravention is deemed admitted and the proposed order and proposed penalties take effect.

If the organization disputes the notice, the matter goes before the Commission, which functions as a tribunal and can confirm, vary or cancel the findings. It will have to establish its rules of procedure, but notably is not bound by any legal or technical rules of evidence but the usual principles of fairness and natural justice apply.

Appeals can be made to the Federal Court.

This is a dramatically different model from the current PIPEDA process.

The Penalties

But a lot of focus will be on penalties. And yes, the penalties can be enormous.

Administrative monetary penalties can reach the greater of:

  • $10 million; or
  • 3% of global gross revenue.

For more serious offences prosecuted under the Act, penalties become even larger.

An indictable offence can result in fines up to the greater of:

  • $25 million; or
  • 5% of global gross revenue.

There is also directors and officers liability, regardless of whether the organization itself is hit with a penalty. For large multinational organizations, these are numbers that will attract immediate attention from boards of directors and senior executives.

The Private Right of Action

Bill C-36 will create a private right of action for individuals affected by a contravention of the Act. This is extremely broad and potentially problematic. Currently, under PIPEDA, a person who complains to the Privacy Commissioner can then go to the Federal Court at the conclusion of the Commissioner’s investigation to seek damages. It is a de novo process, which means that the complainant has to satisfy the Federal Court that the organization violated the law, that this violation harmed them and they are entitled to damages. PIPEDA does not create any sort of broader scheme beyond the individual complainant. 

Under Bill C-36, it says that any individual who is affected by a contravention of the act has “a cause of action against the organization for damages for loss or injury that the individual has suffered as a result of the contravention.” That tells me that this goes waaaay beyond the complainant having a right to sue the organization, by anyone affected by it. 

Presumably you’d have to prove to the court that you’re “affected” by the contravention. The bill does not say whether liability is assumed or even deemed. Does a final notice of contravention just result in a blank cheque for anyone who can claim to be affected? 

And section 132(5) says that an action can be brought in the Federal Court or any provincial superior court. That’s a recipe for overwhelming our courts. 

Let’s use a recent privacy commissioner report of findings as an example of what could happen. In 2022, the federal commissioner along with his counterparts in BC, Alberta and Quebec, issued a report of findings that the Tim Horton’s coffee and donut chain violated the relevant privacy laws in the way that the company’s mobile app collected location information. The report found the App had over 8.6 million Canadian downloads, and as of July 2020, there were 1,602,343 active App Users. 

If that were to happen after Bill C-36 comes into effect and the Commissioner found a “contravention”, it sounds like 1.6 million people would each be able to sue Tim Hortons in their local court. Not that that many people would do so, but even a small portion of them doing so would overwhelm our legal system. And in the case of the Tim Hortons app, the regulators found that the company didn’t even use the location information. So you could have a huge number of legal claims, where it really was a “no harm, no foul” situation. I do note that there were a few class actions filed over the Tim Hortons app location tracking, which resulted in a settlement worth about 16 million dollars paid in Tim Hortons gift cards. 

In my view, if they’re going to create a private right of action, they should all be heard in the Federal Court of Canada and there should be a clear process to prevent a multiplicity of proceedings. 

The provincial superior courts are already overwhelmed. That’s where serious criminal trials take place, and already charges are being thrown out because of delays in getting to trial. I think it’s irresponsible to send an enormous number of claims into those courts, at the provinces’ expense and at the risk to the overall administration of justice. If the federal government is going to create a rush to the courthouses, it should be in the court that the federal government pays for.

What’s missing

I can’t help but notice something missing from the new Protecting Privacy and Consumer Data Act. 

While the government’s agenda is so clearly in favour of the adoption of artificial intelligence across Canada, there’s nothing in the bill that expressly permits or authorizes the collection of publicly available personal information from the internet for training AI models. Given the government’s artificial intelligence agenda, I am surprised that it is not there. 

But like so many recent bills, a huge amount is left to the regulations.

Conclusion

So, in conclusion, where does this leave us?

Bill C-36 is not a minor update to PIPEDA. It is a wholesale replacement of Canada's federal private-sector privacy framework. 

It introduces stronger enforcement. It creates significant penalties. It formalizes privacy management programs.

It expands rights relating to disposal of personal information.

And perhaps most significantly, it replaces the traditional Privacy Commissioner model with an entirely new regulatory structure.

I’m still thinking this through, and I’m sure I’ll have more to say about this new Digital Safety and Data Protection Commission of Canada, which is taking on the full “online harms” regulation from Bill C-34’s “Safe Social Media Act”, and now privacy under this new Bill C-36. A specialized tribunal makes some sense, but the Data Protection Commissioner should not be a member of the tribunal hearing review of his own investigations. In any event, it still puts the judge, jury, prosecutor and executioner in too cozy a relationship. The statute should clearly build in the guardrails and the firewalls to keep the investigation function detached from the Commission as a tribunal.

Anyways, I’m still thinking this through and will certainly have thoughts to come. In the meantime, both Professor Geist and Professor Scassa, who think deeply about these issues, have some preliminary thoughts online on their blogs and substacks. You should check them out. 

So the bill has only just been introduced and Parliament rose shortly afterward for the summer break. We don't yet know whether the government will fast-track it, whether it will undergo substantial amendments, or whether it will suffer the same fate as Bills C-11 and C-27. I expect that in terms of government priority, Online Harms will be higher up the list than privacy law reform. 

But one thing is certain.

If enacted, Bill C-36 would represent the most significant change to Canadian private-sector privacy law since PIPEDA itself came into force.