Showing posts with label PIPEDA reform. Show all posts
Showing posts with label PIPEDA reform. Show all posts

Monday, June 29, 2026

Canada's proposed new privacy law: Bill C-36, the Protecting Privacy and Consumer Data Act

The Personal Information Protection and Electronic Documents Act, known as PIPEDA, has been Canada's private sector privacy law since 2001.

It's currently the law that governs how businesses collect, use and disclose your personal information. It's the law that made the Privacy Commissioner of Canada the federal privacy watchdog. And it's the law that most privacy professionals in Canada have built their careers around.

But now, the federal government has tabled Bill C-36, which would repeal and replace the privacy portions of PIPEDA with an entirely new framework.

And if you've been following federal privacy reform over the last few years, a lot of this will look familiar.

We've seen Bill C-11, the Digital Charter Implementation Act, 2020.

We've seen Bill C-27, Digital Charter Implementation Act, 2022.

Both died on the Order Paper.

Now we have Bill C-36 called the Protecting Privacy and ConsumerData Act.

But this bill does something that neither of those previous bills did.

It completely sidelines the existing Privacy Commissioner of Canada and hands enforcement to an entirely new regulatory structure that seems to be part of what I expect will be the super-mega digital regulator for Canada.

In this episode, I'm going to walk you through what Bill C-36 does, what's new, what's familiar, what businesses need to know, and what I think are some of the most significant changes.

On June 15, 2026, the Minister of Artificial Intelligence and Digital Innovation tabled Bill C-36, titled An Act to enact the Protecting Privacy and Consumer Data Act, to amend the Personal Information Protection and Electronic Documents Act and to make amendments to other Acts.

The centrepiece of the bill is a new law called the Protecting Privacy and Consumer Data Act, or PPCDA.

If passed, it would replace Part 1 of PIPEDA, which has governed private-sector privacy in Canada since 2001.

I don’t really like the name of the new law. On one hand, the law says that privacy is a fundamental right, but in the title it’s about people as “consumers”. If we have a fundamental right, it’s because we’re humans, not just consumers. I think it puts it all in a bad frame.

But in any event, let's dig in.

Déjà Vu All Over Again

If you've read Bill C-27, much of Bill C-36 will look very familiar. In substance, it takes PIPEDA and turns the obligations up to eleven. 

Many of the concepts are carried forward:

  • accountability obligations;
  • privacy management programs;
  • enhanced consent requirements;
  • legitimate interest exceptions;
  • rights to disposal of personal information;
  • data mobility provisions;
  • administrative monetary penalties; and
  • a much stronger enforcement framework.

What's missing, however, is the artificial intelligence legislation that was bundled into Bill C-27. It’s not really missing since it didn’t belong in Bill C-27 in the first place.

This new bill focuses exclusively on private-sector privacy law.

The Biggest Surprise — Goodbye Privacy Commissioner?

In my view, the most significant structural change is not about consent, de-identification or penalties. We expected that. 

It's about who oversees and enforces the law.

Historically, privacy complaints under PIPEDA have been investigated by the Privacy Commissioner of Canada.

The Commissioner acts primarily as an ombudsman. Complaints are investigated. Findings are issued. Organizations are encouraged to comply. And they can be named and shamed. And if things don't get resolved, the matter may end up in Federal Court, where orders can be issued and damages can be awarded.

Bill C-27 from 2002 would have given the Privacy Commissioner the power to investigate complaints and recommend orders and penalties. Those orders and penalties had to be levied by a proposed newly created, separate body called the Personal Information and Data Protection Tribunal.

Bill C-36 replaces the current PIPEDA model entirely by sidelining the current Commissioner.

Instead, oversight would be handled through the Digital Safety and Data Protection Commission of Canada, a new institution that originated in the government's online harms framework. (I covered that in my last episode.) The existing Privacy Commissioner would no longer be the regulator under the statute. Instead, there would be a new Privacy and Consumer Data Commissioner operating within this new commission structure.

This is a big shift.

For nearly twenty-five years, Canadian privacy regulation has been centred on an independent officer of Parliament.

Now, enforcement would be embedded within a broader administrative commission.

Whether that's a good thing or a bad thing will likely become one of the major debates surrounding the bill. The new Commissioner will be less independent and more beholden to the government. At this point, I’m not convinced that it’s a good idea – but I look forward to a lot of discussion about it over the summer.

A New Structure for the Law

Bill C-36 looks very different from PIPEDA. 

PIPEDA has always been a bit unusual. Rather than spelling out all of the rules directly in legislation, it incorporated the Canadian Standards Association Model Code for the Protection of Personal Information.

The law largely worked by saying: follow the Code, subject to these exceptions. Bill C-36 takes a different approach.

Much like the privacy statutes in Alberta and British Columbia, the principles are expressed directly in legislative language. For privacy professionals who work with Canadian federal and provincial laws, this means the substance will often feel familiar.

And because the essence of the principles are embedded directly in statute using traditional statutory language, I expect its interpretation will become more rigid and more legalistic than the current PIPEDA framework.

Expanded Scope?

The government seems to be expanding the scope of the private sector privacy law. One new provision, compared to PIPEDA, is particularly notable. PIPEDA applies to personal information collected, used or disclosed in the course of commercial activities, as well as federally regulated workplaces.

That basic framework remains. Bill C-36 will apply to personal information collected, used or disclosed in the course of commercial activities, as well as federally regulated workplaces.

But Bill C-36 includes a provision that specifically says that the legislation applies to personal information collected, used or disclosed interprovincially or internationally.

For greater certainty

(2) For greater certainty, this Act applies in respect of personal information

(a) that is collected, used or disclosed interprovincially or internationally by an organization; or

(b) that is collected, used or disclosed by an organization within a province, to the extent that the organization is not exempt from the application of this Act under an order made under paragraph 139(2)‍(b).


It’s not limited to data that crosses borders in connection with any commercial activity. Does that mean it applies to data that a Nova Scotia-based non-profit stores in Ontario? Or what about an Alberta company that is subject to Alberta privacy law, which collects information from a British Columbian resident, which is protected by that province’s privacy law. Does the federal law apply once the data crosses the Rocky Mountains?

I think this was probably put here to expand our European GDPR adequacy, so that the new law will explicitly apply to all data transferred from Europe to Canada for processing. But I suspect lawyers and regulators will spend a fair amount of time debating exactly how far this provision reaches.

Bill C-36 explicitly addresses Anonymous vs. De-Identified Data

Another major feature of the bill is its treatment of anonymous and de-identified information.

To date, Canadian privacy law has not directly addressed this concept.

Bill C-36 formally distinguishes among personal information, de-identified personal information and anonymized information.

anonymize means to irreversibly and permanently modify personal information to ensure that there is no reasonably foreseeable risk in the circumstances that an individual can be identified from the information, whether directly or indirectly, by any means.‍ (anonymiser)

For greater certainty

6(5) For greater certainty, this Act does not apply in respect of anonymized information.

de-identify means to modify personal information so that an individual cannot be directly identified from it, although a risk of the individual being identified remains.‍ (dépersonnaliser)

Anonymous information is information that has been irreversibly and permanently modified so there is no reasonably foreseeable risk that an individual can be identified. Anonymous information falls outside the legislation altogether.

De-identified information is different.

The information has been modified so an individual cannot be directly identified, but some risk of re-identification remains. That information continues to be regulated under the Act.

This distinction is important because organizations increasingly rely on de-identification techniques for analytics, research and product development.

The bill provides a much more detailed framework than PIPEDA currently does.

Under Bill C-36, Privacy Management Programs Become Mandatory

Essentially, Principle 1 of PIPEDA required all regulated organizations to have a privacy management program. Bill C-36 makes that expectation explicit.

Organizations must establish and maintain a documented privacy management program. They must also provide supporting documentation to the regulator upon request.

In practical terms, this means:

  • policies;
  • procedures;
  • training materials;
  • risk management documentation; and
  • governance records

All of these become much more important.

For organizations that have treated privacy compliance as an informal exercise, that approach will no longer be sufficient. And very importantly, every organization has to provide a copy of their privacy management program to the regulator upon request. 

Consent Gets More Detailed

The bill retains consent as the principal basis under which personal information can be collected, used or disclosed.

But the Bill significantly expands what organizations must communicate to the individual in order for consent to be valid.

Organizations will need to explain:

(a) the purposes for the collection, use or disclosure of the personal information;

(b) the manner in which the personal information is to be collected, used or disclosed;

(c) any reasonably foreseeable consequences of the collection, use or disclosure of the personal information;

(d) the specific type of personal information that is to be collected, used or disclosed; and

(e) the names of any third parties or types of third parties to which the organization may disclose the personal information.

And these explanations must be provided in plain language.

That’s a lot of information. Imagine trying to convey that at a retail point of sale. Under PIPEDA, conveying the purposes of the collection was done outside of a privacy policy or privacy statement, but this is the sort of information that should be put in a privacy statement. And this is all while folks are saying that privacy policies are too long and unreadable. I think it should be sufficient to communicate the purposes, clearly and understandably, and leave the rest for the privacy policy if the individual has any questions. 

Legitimate Interests and Business Activities

When it comes to consent, one hand giveth and the other taketh away. 

One of the most controversial features of Bill C-27 from 2022 was the introduction of new exceptions to consent. Those provisions largely survive under the proposed Protecting Privacy and Consumer Data Act.

Under Bill C-36, organizations can collect and use personal information without consent for certain business activities where a reasonable person would expect it, for security purposes, for safety purposes and for other prescribed activities.

Business activities

18 (1) An organization may collect or use an individual’s personal information without their knowledge or consent if the collection or use is made for the purpose of a business activity described in subsection (2) and

(a) a reasonable person would expect the collection or use for such an activity; and

(b) the personal information is not collected or used for the purpose of influencing the individual’s behaviour or decisions.

List of activities

(2) Subject to the regulations, the following activities are business activities for the purposes of subsection (1):

(a) an activity that is necessary to provide a product or service that the individual has requested from the organization;

(b) an activity that is necessary for the security of the organization’s information, systems or networks;

(c) an activity that is necessary for the safety of a product or service that the organization provides; and

(d) any other prescribed activity.

However, there is an important limitation.

These exceptions cannot be used where the information is being collected or used to influence an individual's behaviour or decisions.

The bill also includes a legitimate interest exception, which is similar to what is found in Europe’s General Data Protection Regulation.

To rely on it, an organization must carry out a privacy impact assessment to:

  1. identify possible adverse effects on individuals;
  2. take measures to mitigate those effects; and
  3. determine that its legitimate interest outweighs those adverse effects.

This sounds straightforward.

In practice, it may generate substantial debate.

What is influencing an individual’s behaviour or decisions? Does that include search rankings? What video to suggest next? An advertisement?

How do you measure adverse effects?

What counts as sufficient mitigation?

And how should competing interests be balanced?

Those questions are likely to become important very quickly. 

Notably, consent can still be implied if it’s appropriate taking into account the reasonable expectations of the individual and the sensitivity. But then section 15(6) says you can’t use implied consent for any activity listed in 18(2) or 18(3). 

Form of consent

(5)  Consent must be expressly obtained unless, subject to subsection (6), it is appropriate to rely on an individual’s implied consent, taking into account the reasonable expectations of the individual and the sensitivity of the personal information that is to be collected, used or disclosed.

Business activities

(6)  It is not appropriate to rely on an individual’s implied consent if their personal information is collected or used for an activity described in subsection 18(2) or if it is collected, used or disclosed for an activity described in subsection 18(3).

That includes “an activity that is necessary to provide a product or service that the individual has requested from the organization.” Those are exactly the sorts of activities where you should be able to rely on implied consent. The wording of the statute suggests that this is excluded from possible “implied consent”. 

For example, I tap my credit card to pay for a burger. My consent to processing that transaction should be implied without the cashier reciting everything listed in section 15 (like the reasonably foreseeable consequences of the collection, use or disclosure of my credit card number), but because it’s necessary for me to pay for my burger it can’t be implied.

That’s just dumb. That can’t be right. At a technical briefing on the bill, I asked officials with the Industry Department whether this was intentional or bad drafting and they couldn’t explain it. 

Bill C-36 includes a “Right to Disposal”

PIPEDA has long allowed individuals to withdraw consent in many circumstances.

Bill C-36 goes further or is at least more explicit. Under PIPEDA, an individual can withdraw consent. Since the organization can only retain personal information for as long as is reasonably necessary for the purposes for which consent was obtained, it was pretty clear – but implied – that the data should be deleted.

Under Bill C-36, individuals can explicitly require organizations to dispose of their personal information.

Importantly, disposal includes both deletion and anonymization.

This resembles the growing international trend toward stronger deletion rights, although it stops short of adopting a full European-style "right to be forgotten."

The Industry Minister, when speaking about this Bill, suggested this will allow people to have deepfakes deleted. I’m not sure that’s the case across the board. 

Cross-Border Transfers and Privacy Impact Assessments

Another area of note is the treatment of international transfers.

Before personal information is disclosed or transferred outside Canada, organizations would be required to conduct a privacy impact assessment in a prescribed format.

This is noteworthy.

For years, Canadian law has generally allowed cross-border transfers provided appropriate safeguards are in place. The same rules applied to domestic transfers, as well as international ones.

Bill C-36 moves toward a more structured assessment model. Exactly what those assessments must contain will depend on future regulations, and notably these assessments must be provided to the Commission on request. 

Enforcement Gets Serious

And now we come to what many people will consider the headline story.

Enforcement. Lots of enforcement.

Under the bill, investigations may begin following a complaint or on the initiative of the Privacy and Consumer Data Commissioner.

During an investigation, the Commissioner can compel records and testimony, receive any evidence regardless of whether it complies with the traditional rules of evidence, and enter and search any premises other than a dwelling. 

Following an investigation, the Commissioner may issue a notice of contravention. That notice can include proposed orders and proposed penalties.

If the organization does not challenge the notice, the contravention is deemed admitted and the proposed order and proposed penalties take effect.

If the organization disputes the notice, the matter goes before the Commission, which functions as a tribunal and can confirm, vary or cancel the findings. It will have to establish its rules of procedure, but notably is not bound by any legal or technical rules of evidence but the usual principles of fairness and natural justice apply.

Appeals can be made to the Federal Court.

This is a dramatically different model from the current PIPEDA process.

The Penalties

But a lot of focus will be on penalties. And yes, the penalties can be enormous.

Administrative monetary penalties can reach the greater of:

  • $10 million; or
  • 3% of global gross revenue.

For more serious offences prosecuted under the Act, penalties become even larger.

An indictable offence can result in fines up to the greater of:

  • $25 million; or
  • 5% of global gross revenue.

There is also directors and officers liability, regardless of whether the organization itself is hit with a penalty. For large multinational organizations, these are numbers that will attract immediate attention from boards of directors and senior executives.

The Private Right of Action

Bill C-36 will create a private right of action for individuals affected by a contravention of the Act. This is extremely broad and potentially problematic. Currently, under PIPEDA, a person who complains to the Privacy Commissioner can then go to the Federal Court at the conclusion of the Commissioner’s investigation to seek damages. It is a de novo process, which means that the complainant has to satisfy the Federal Court that the organization violated the law, that this violation harmed them and they are entitled to damages. PIPEDA does not create any sort of broader scheme beyond the individual complainant. 

Under Bill C-36, it says that any individual who is affected by a contravention of the act has “a cause of action against the organization for damages for loss or injury that the individual has suffered as a result of the contravention.” That tells me that this goes waaaay beyond the complainant having a right to sue the organization, by anyone affected by it. 

Presumably you’d have to prove to the court that you’re “affected” by the contravention. The bill does not say whether liability is assumed or even deemed. Does a final notice of contravention just result in a blank cheque for anyone who can claim to be affected? 

And section 132(5) says that an action can be brought in the Federal Court or any provincial superior court. That’s a recipe for overwhelming our courts. 

Let’s use a recent privacy commissioner report of findings as an example of what could happen. In 2022, the federal commissioner along with his counterparts in BC, Alberta and Quebec, issued a report of findings that the Tim Horton’s coffee and donut chain violated the relevant privacy laws in the way that the company’s mobile app collected location information. The report found the App had over 8.6 million Canadian downloads, and as of July 2020, there were 1,602,343 active App Users. 

If that were to happen after Bill C-36 comes into effect and the Commissioner found a “contravention”, it sounds like 1.6 million people would each be able to sue Tim Hortons in their local court. Not that that many people would do so, but even a small portion of them doing so would overwhelm our legal system. And in the case of the Tim Hortons app, the regulators found that the company didn’t even use the location information. So you could have a huge number of legal claims, where it really was a “no harm, no foul” situation. I do note that there were a few class actions filed over the Tim Hortons app location tracking, which resulted in a settlement worth about 16 million dollars paid in Tim Hortons gift cards. 

In my view, if they’re going to create a private right of action, they should all be heard in the Federal Court of Canada and there should be a clear process to prevent a multiplicity of proceedings. 

The provincial superior courts are already overwhelmed. That’s where serious criminal trials take place, and already charges are being thrown out because of delays in getting to trial. I think it’s irresponsible to send an enormous number of claims into those courts, at the provinces’ expense and at the risk to the overall administration of justice. If the federal government is going to create a rush to the courthouses, it should be in the court that the federal government pays for.

What’s missing

I can’t help but notice something missing from the new Protecting Privacy and Consumer Data Act. 

While the government’s agenda is so clearly in favour of the adoption of artificial intelligence across Canada, there’s nothing in the bill that expressly permits or authorizes the collection of publicly available personal information from the internet for training AI models. Given the government’s artificial intelligence agenda, I am surprised that it is not there. 

But like so many recent bills, a huge amount is left to the regulations.

Conclusion

So, in conclusion, where does this leave us?

Bill C-36 is not a minor update to PIPEDA. It is a wholesale replacement of Canada's federal private-sector privacy framework. 

It introduces stronger enforcement. It creates significant penalties. It formalizes privacy management programs.

It expands rights relating to disposal of personal information.

And perhaps most significantly, it replaces the traditional Privacy Commissioner model with an entirely new regulatory structure.

I’m still thinking this through, and I’m sure I’ll have more to say about this new Digital Safety and Data Protection Commission of Canada, which is taking on the full “online harms” regulation from Bill C-34’s “Safe Social Media Act”, and now privacy under this new Bill C-36. A specialized tribunal makes some sense, but the Data Protection Commissioner should not be a member of the tribunal hearing review of his own investigations. In any event, it still puts the judge, jury, prosecutor and executioner in too cozy a relationship. The statute should clearly build in the guardrails and the firewalls to keep the investigation function detached from the Commission as a tribunal.

Anyways, I’m still thinking this through and will certainly have thoughts to come. In the meantime, both Professor Geist and Professor Scassa, who think deeply about these issues, have some preliminary thoughts online on their blogs and substacks. You should check them out. 

So the bill has only just been introduced and Parliament rose shortly afterward for the summer break. We don't yet know whether the government will fast-track it, whether it will undergo substantial amendments, or whether it will suffer the same fate as Bills C-11 and C-27. I expect that in terms of government priority, Online Harms will be higher up the list than privacy law reform. 

But one thing is certain.

If enacted, Bill C-36 would represent the most significant change to Canadian private-sector privacy law since PIPEDA itself came into force.

  

Saturday, November 18, 2023

What is the "legitimate interests" exception to consent under Canada's proposed privacy law?

So Bill c-27, also known as the digital charter implementation act of 2022 has been before Canada's Parliament for consideration for quite some time. Even before this parliamentary session, a bill substantially similar to the present one was tabled and then died on the order paper in the previous parliamentary session. After more than 20 years of the personal information protection electronic documents act, people have had a long time to think about improvements that perhaps could or should be made to our national privacy regime .

One thing that I've heard over and over again, particularly from privacy activists since 2018 is the suggestion that Canada should simply follow Europe's lead and implement a form of its general data protection directive. Privacy activists and others hail it as the “gold standard”. 

Sometimes when I hear more from these folks, I realize that for some of them, it appears that all they know about the GDPR is the possibility of massive, company-ruining penalties. What they don't seem to understand is that it is relatively rare in Europe for a business to use consent as the basis for the collection, use or disclosure of personal information. This is in stark contrast to the current law, PIPEDA, where consent really is the only lawful basis for collecting, using and disclosing personal information. 

Here is a case in point. It is an op-ed to the globe and mail written by the former co-CEO of research in motion, also known as blackberry, and more recently, the philanthropist behind Canada center for digital rights and the Centre for International Governance Innovation, Jim Balsillie. 

In this op-ed, Balsillie “the EU's landmark general data protection regulation, a law that sets the baseline for modern protections around the world…”

He then goes on to viciously attack a portion of Bill c27 in the CPPA that is modeled directly on a provision from the GDPR: The ability for an organization to collect, use or disclose personal information without consent on the basis of legitimate interests .

Here is what Jim has to say in his op-ed. “ For example, the proposed new law creates a broad car vote for surveillance without knowledge or consent based on legitimate interests… there's worse, it's the businesses themselves that determine what constitutes legitimate interest for surveillance and they are under no obligation to tell the individual they are tracking and profiling them”

Look, either it is the gold standard or it is not.

And I really shouldn't have to tell a business leader that every one of us gets to decide how we comply with the law and if that assessment is incorrect, that is where enforcement comes in. The bill contains detailed information about what can be a legitimate interest in what cannot be a legitimate interest. Frankly, I am getting a little tired of this breathless hyperbole and want to set the record straight on what legitimate interests is and what it is not.

First, we'll look at the GDPR, then we will look at Bill c27.

Article 6 of the GDPR outlines the lawful bases for processing personal data. These include consent, contract, legal obligation, vital interests, public task, and legitimate interests. We’re going to zoom in on the last one – legitimate interests.

Legitimate interests are one of the more flexible lawful bases and probably the most-used. It is also the most open to interpretation. It allows data processing on the basis of the legitimate interests pursued by a data controller or a third party, unless such interests are overridden by the interests or fundamental rights and freedoms of the data subject.

This requires the data controller to carry out an analysis to see if “legitimate interests” can be used instead of another basis, such as consent. 

To rely on legitimate interests, you must:

1. Identify a legitimate interest (be it commercial, individual, or societal benefits).

2. Show that the processing is necessary to achieve it.

3. Balance it against the individual’s interests, rights, and freedoms. This involves conducting a Legitimate Interests Assessment (LIA).

Legitimate interests can include network and information security, preventing fraud, direct marketing, and the like. 

Using “legitimate interests” is not just carte blanche to do whatever you want. When invoking legitimate interests, the controller has to ensure transparency, adhere to data minimization principles, and implement safeguards to protect the rights of individuals. 

The proposed Consumer Privacy Protection Act in Canada has a similar framework. Personally, I think it should be replaced with an almost word for word copy from the GDPR in order to remove – or at least reduce – unnecessary barriers for organizations that operate internationally.

But let's focus on what is in fact written in the bill as it currently exists.

In section 18(3), it says an organization may collect or use an individual's personal information without their knowledge or consent if the collection of use is made for the purpose of an activity in which the organization has a legitimate interest that outweighs any potential adverse effect on the individual resulting from that collection or use. And a reasonable person would expect the collection of use for such an activity. And the personal information is not collected or used for the purpose of influencing the individual’s behavior or decisions.

So like in Europe, it requires balancing that organization's interest against the interest of the individual. Unlike in Europe, it requires that the collection or use be for purposes that would essentially be obvious or expected by the individual. It is unclear what is the intended scope of that paragraph (b) there, since there are so many things that happen in the world that would reasonably be expected to alter somebody's behavior.

Subsection (4) sets a requirement that must be met prior to an organization relying on this legitimate interest for the collection or use of personal information. It says prior to collecting using personal information under subsection (3), the organization must identify any potential adverse effect on the individual that is likely to result from the collection or use, then identify and take reasonable measures to reduce the likelihood that the effects will occur or to mitigate or eliminate them, and comply with any prescribed requirements. That means that additional requirements could be set out in regulations to come.

Then it says in subsection (5) that the organization must record its assessment of how it meets the condition set out in subsection (4) and must, on request, provide a copy of the assessment to the Privacy Commissioner. 

This doesn't, to me, sound like a completely arbitrary mechanism where organizations get to draw the line wherever they want. They have to document that decision-making and have to make it available to the privacy commissioner on request.

But that is not the end of it. Section 62 talks about what an organization has to include in its privacy statement to the public, and this says that they have to provide a general account of how the organization uses the personal information and how it applies the exceptions to the requirement to obtain an individual consent under this act, including a description of any activities referred to in subsection 18(3) in which it has a legitimate interest. 

So this means that every organization that determines that it is appropriate to use legitimate interests for the collection or use of personal information has to document their decision making in a defensible manner, knowing that it could be presented to the Privacy Commissioner. And they don't get to do it sneakily as the breathless critics would have you think, because they have to publish it in black and white, plain language in their public facing privacy statement.

In addition to the legitimate interests basis for the collection or use of personal information, the proposed CPPA also includes certain categories of business activities for which personal information can be collected or used without an individual's knowledge or consent. This is in section 18, sub 1.

This says an organization may collect or use an individual's personal information without their knowledge or consent if the collection or use is made for the purpose of a business activity described in subsection (2). And a reasonable person would expect the collection or use for such an activity. And the personal information is not collected to use for the purpose of influencing the individual’s behavior or decisions. Does that sound familiar? This is a similar framework to what is in 18 sub 3. 

This provision sets out what are the permissible business activities that fit within this exception. The first one is an activity that is necessary to provide a product or service that the individual has requested from the organization. It has to be necessary. Or it can be an activity that is necessary for the organization's information, system or network security. Or an activity that is necessary for the safety of a product or service that the organization provides. Or any other prescribed activity that could be set out in future regulations.

While I would like Canada’s version of “legitimate interests” to more closely parallel the one in the European General Data Protection Regulation, I think it is a completely reasonable addition to Canada’s privacy law. It requires a deliberate analysis and determination of whether it can be used and requires the organization to be transparent with its customers about the practice.


Monday, June 27, 2022

Video: Preparing for Canada's new Consumer Privacy Protection Act

The government of Canada tabled the Digital Charter Implementation Act, 2022 in the week before parliament rose for their summer break. While this is in limbo, what, if anything, should Canadian businesses be doing to prepare for the Consumer Privacy Protection Act?

In the week before the summer break, the Industry Minister tabled in parliament the Digital Charter Implementation Act, which will overhaul Canada’s federal private sector privacy law. It has been long anticipated and for many, long overdue. With parliamentarians off the for the summer, what can we expect and what should businesses be doing to get ready for it?

I expect that when the house resumes, the bill will be referred to either the Standing Committee on Industry, which is where PIPEDA went more than 20 years ago, or to the Standing Committee on Access to Information, Privacy and Ethics.

I have to say that the current government is very unpredictable. When Bill C-11 was tabled in 2019 for the Digital Charter Implementation Act of 2019, the bill just sat there with no referral to committee and it seemed to not be a priority at all. If they are serious about privacy reform, they should get this thing moving when they are back in session.

When it gets to committee, the usual cast of characters will appear to provide comments. First up will be the minister of Industry and his staff. Then will be the privacy commissioner of Canada, who will only have had a few months in his office at that point. I would not be surprised to see provincial privacy commissioners have their say, and maybe even data protection authorities from other countries. Then industry and advocacy groups will have their say.

The Commissioner in 2019 was very critical of the C-11 version of the bill, and it appears that most of his suggestions have gone unheeded. I expect that between 2019 and now, there has been a lot of consultation and lobbying going on behind the scenes that resulted in the few changes between C-11 and C-27. It will be interesting to see how responsive the committee and the government are to making changes to the bill.

I would not be surprised to see this bill passed, largely in its current form, before the end of the year. But even if it speeds though the House of Commons and the Senate, I do not expect that we will see this law in effect for some time. In order for the Consumer Privacy Protection Act and the Personal Information and Data Protection Tribunal Act to be fully in force, the government will have a lot of work to do.

The biggest effort will be standing up the new tribunal under the Personal Information and Data Protection Tribunal Act. Doing so will not be a trivial matter. At least three members have to be recruited, and at least three of those have to have expertise in privacy and information law. They’ll need offices, staff, a registry, IT infrastructure, then they’ll need to make their rules of procedure. I can’t see that taking any less than a year, even if the government is currently informally recruiting for those roles.

An example I’d look at is the College of Patent Agents and Trademark Agents, which was established pursuant to a bill passed in December 2018 and came into force on June 28, 2021. Essentially, it took two and a half years between the passing of the bill and when the College was open for business. The college was probably more complicated to set up than the tribunal, but it provides some insight I think.

Personally, I don’t think the CPPA can be phased in without the tribunal operating as a going concern. There are transitional provisions related to complaints that are being dealt with by the Commissioner prior to the coming into force of the CPPA, but otherwise the existence of the tribunal is essential to the operation of the CPPA and the Commissioner’s mandate.

So if I had to look into my crystal ball, I don’t think we’ll see this fully in effect for at least a year and a half.

So should companies be doing anything now? I think so. When the CPPA and the Tribunal Act come into effect they will be fully in effect. In addition to making your politicians aware of any concerns you have, companies should be looking very closely at their current privacy management program – if any – to determine if it will be up to snuff.

Section 9 of the Act says that “every organization must implement and maintain a privacy management program that includes the policies, practices and procedures the organization has put in place to fulfill its obligations under this Act, including policies, practices and procedures respecting

(a) the protection of personal information; (b) how requests for information and complaints are received and dealt with; (c) the training and information provided to the organization’s staff respecting its policies, practices and procedures; and (d) the development of materials to explain the organization’s policies and procedures.”

It then says “In developing its privacy management program, the organization must take into account the volume and sensitivity of the personal information under its control.”

This is, of course, very similar to the first principle of the CSA Model Code that’s in PIPEDA. But section 10 of the CPPA says the Commissioner can ask for it and all of its supporting documentation at any time.

I can imagine the OPC sending out requests for all of this documentation to a huge range of businesses shortly after the Act comes into force.

So what does a privacy management program include? If of course includes your publicly-facing privacy statement described in section 62. What has to be in this document will change a lot compared to PIPEDA. It has to explain in plain language what information is under the organization’s control, a general account of how it uses that personal information.

If the organization uses the “legitimate interest” consent exception, the privacy statement has to include a description of that. If the organization uses any automated decision system to make predictions, recommendations or decisions about individuals that could have a “significant impact on them”, that has to be described. It also has to say whether or not the organization carries out any international or interprovincial transfer or disclosure of personal information that may have reasonably foreseeable privacy implications. You also have to state the retention periods applicable to sensitive personal information, then explain the process for questions, complaints, access requests and requests for deletion. Most privacy statements don’t currently include all this information.

You need to assess what personal information you have, where it is, who has it, who has access to it, what jurisdiction is it in or exposed to, how it is secured, when did you collect it, what were the purposes for that collection, are there any new purposes, and have those purposes expired.

A good starting point for your privacy management program is to document all the personal information under the organizations’ control and the purposes for which it is to be used. Section 12(3) of the CPPA requires that this be documented. You will also need to ensure that all of these purposes are appropriate using the criteria at section 12(2).

You’ll also want to review whether any of the consent exceptions related to business activities under 18(1) or legitimate interests in section 18(3) could be applicable, and document them.

Under s. 18(4), this documentation will have to be provided to the Commissioner on request.

You will also need to document the retention schedule for all of your personal information holdings, and make sure they are being followed. And remember, all information related to minors is deemed to be sensitive and the retention schedule for sensitive information has to be included in your privacy statement.

Next, you’ll want to inventory and document all of your service providers who are collecting, using or disclosing personal information on your behalf. You’ll need to review all of the contracts with those service providers to make sure the service provider provides the same level of protection equivalent to original controlling organizations’ obligations. It should be noted that service providers, in the definition in the Act, expressly includes affiliated companies. So you’ll need to make sure that intercompany agreements are in place to address any personal information that may be transferred to affiliates.

You’ll want to check your processes for receiving questions, complaints and access requests from individuals. You may need to tweak your systems or processes to make sure that you can securely delete or anonymise data where required.

And last, but certainly not least, you’ll want to look very closely at your data breach response plans. It needs to identify all suspected data breaches, make sure they are properly escalated and reviewed. Any breach itself of course has to be stopped, mitigated and investigated. The details will need to be recorded and you’ll also want to think about the processes for getting legal advice at that stage so information you may want to keep privileged will be protected and you can understand your reporting and notification obligations.

At the end of the day, the CCPA is not a radical departure from the existing framework of PIPEDA. It requires greater diligence and what we in the privacy industrial complex call “privacy maturity”. Even if it didn’t, the significant penalties and the cost of dealing with investigations and inquiries by the commissioner and possible hearings before the tribunal should be enough to convince organizations to up their privacy games.

Monday, June 20, 2022

Video: An overview of the Digital Charter Implementation Act, 2022

Finally, the government of Canada has tabled its long-awaited privacy law, intended to completely overhaul Canada’s private sector privacy law, and rocket the country to the front of the pack for protecting privacy. Not quite, but I’ll give you an overview of what it says.

Highlights

On June 26, 2022, the Industry Minister François Philippe Champagne finally tabled in the House of Commons Bill C-27, called the “Digital Charter Implementation Act, 2022”. This is the long-awaited privacy bill that is slated to replace the Personal Information Protection and Electronic Documents Act, which has regulated the collection, use and disclosure of personal information in the course of commercial activity in Canada since 2001.

PIPEDA, contrary to what Minister Champagne said at the press conference later that day, has been updated a number of times but there really has been a broad consensus that it was in need of a more general overhaul.

The bill is very similar to Bill C-11, which was tabled in 2019 as the Digital Charter Implementation Act, 2019, and which languished in parliament until dying when the federal government called the last election.

The bill creates three new laws. The first is the Consumer Privacy Protection Act, which is the main privacy law. The second is the Personal Information and Data Protection Tribunal Act and the third is the Artificial Intelligence and Data Act, which I’ll have to leave to another episode.

I don’t plan to do a deep dive into the bill in this video, as I want to spend more time poring over its detailed provisions. We can’t just do a line-by-line comparison with PIPEDA, as the Bill is in a completely different structure than PIPEDA. You may recall that PIPEDA included a schedule taken from the Canadian Standards Association Model Code for the Protection of Personal Information. The statute largely said “follow that”, and there are a bunch of provisions in the body of the Act that modify those standards or set out how the law is overseen.

The most significant difference is what many privacy advocates have been calling for: the Privacy Commissioner is no longer an ombudsman. The law includes order-making powers and punitive penalties. The Bill also creates a new tribunal called the Personal Information and Data Protection Tribunal, which replaces the current role of the Federal Court under PIPEDA with greater powers.

Other than order making powers, I don’t see much of a difference between what’s required under the new CCPA and what diligent, privacy-minded organizations have been doing for years.

This is a high-level overview of what’s in Bill C-27, and I’ll certainly do deeper dives into its provisions in later videos.

Does the law apply any differently?

PIPEDA applied to the collection, use and disclosure of personal information in the course of commercial activity and to federally-regulated workplaces. That hasn’t changed, but a new section 6(2) says that the Act specifically applies to personal information that it collected, used or disclosed interprovincially or internationally. The privacy commissioner had in the past asserted that this was implied, but it was never written in the Act. Now it will be. Two things about that are problematic: the first is that it’s not expressly limited to commercial activity, so there’s an argument that could be made that it would apply to non-commercial or employee personal information that crosses borders. The second dumb thing is that this means that a company with operations in British Columbia and Alberta, when it moves data from one province to another not only has to comply with the substantially similar privacy laws of each province, now they have to comply with the Consumer Privacy Protection Act. That seems very redundant.

It includes the same carve-outs for government institutions under the Privacy Act, personal or domestic use of personal information, journalistic, artistic and literary uses of personal information and business contact information.

We really could have benefitted from a clear extension of the Act to personal information that is imported from Europe so we can have confidence that the adequacy finding from the EU, present and future, really applies across the board.

It does have an interesting approach to anonymous and de-identified data. It officially creates these two categories. It defines anonymize as: “to irreversibly and permanently modify personal information, in accordance with generally accepted best practices, to ensure that no individual can be identified from the information, whether directly or indirectly, by any means.” So there effectively is no reasonable prospect of re-identification. To de-identify data means “means to modify personal information so that an individual cannot be directly identified from it, though a risk of the individual being identified remains.” You’re essentially using data with the identifiers removed.

The legislation does not regulate anonymous data, because there is no reasonable prospect of re-identification. It does regulate de-identified data and generally prohibits attempts to re-identify it. The law also says that in some cases, de-identified data can be used or even has to be used in place of fully identifiable personal information.

What happened to the CSA model code?

When you look at the CCPA, you’ll immediately see that it is very different. It’s similar in structure to the Personal Information Protection Acts of Alberta and British Columbia, in that the principles of the CSA Model Code are not in a schedule but are in the body of the Act. And the language of these principles has necessarily been modified to be more statutory rather than the sort of language you see in an industry standards document.

Any changes to the 10 CSA Principles?

The ten principles themselves largely haven’t been changed, and this should not be a surprise. Though written in the 90’s, they were based on the OECD guidelines and we see versions of all the ten principles in all modern privacy laws.

What has changed is the additional rigor that organizations have to implement, or more detail that’s been provided about how they have to comply with the law.

For example, principle 1 of the CSA model code required that an organization “implement policies and practices to give effect to the CSA Model Code principles”. The CCPA explicitly requires that an organization have a privacy management program:

Privacy management program

9 (1) Every organization must implement and maintain a privacy management program that includes the policies, practices and procedures the organization has put in place to fulfill its obligations under this Act, including policies, practices and procedures respecting

(a) the protection of personal information;

(b) how requests for information and complaints are received and dealt with;

(c) the training and information provided to the organization’s staff respecting its policies, practices and procedures; and

(d) the development of materials to explain the organization’s policies and procedures.

Volume and sensitivity

(2) In developing its privacy management program, the organization must take into account the volume and sensitivity of the personal information under its control.

This privacy management program has to be provided to the Privacy Commissioner on Request.

With respect to consent, organizations expressly have to record and document the purposes for which any personal information is collected, used or disclosed. This was implied in the CSA Model Code, but is now expressly spelled out in the Act.

Section 15 lays out in detail what is required for consent to be valid. Essentially, it requires not only identifying the purposes but also communicating in plain language how information will be collected, the reasonably foreseeable consequences, what types of information and to whom the information may be disclosed.

I’ll have to save digging into the weeds for another episode.

Collection and use without consent

One change compared to PIPEDA that will delight some and enrage others is the circumstances under which an organization can collect and use personal information without consent. Section 18 allows collection and use without consent for certain business activities, where it would reasonably be expected to provide the service, for security purposes, for safety or other prescribed activities. Notably, this exception cannot be used where the personal information is to be collected or used to influence the individual’s behaviour or decisions.

There is also a “legitimate interest” exception, which requires an organization to document any possible adverse effects on the individual, mitigate them and finally weigh whether the legitimate interest outweighs any adverse effects. It’s unclear how “adverse effects” would be measured.

Like PIPEDA, an individual can withdraw consent subject to similar limitations that were in PIPEDA. But what’s changed is that an individual can require that their information be disposed of. Notably, disposal includes deletion and rendering it anonymous.

Law enforcement access

On a first review, it doesn’t look like there are many other circumstances where an organization can collect, use or disclose personal information compared to section 7 of PIPEDA.

In my view, it is very interesting that the exceptions that can apply when the government or the cops come looking for personal information have not changed from section 7(3) of PIPEDA. For example, the provision that the Supreme Court of Canada in R v Spencer said was meaningless is essentially reproduced in full.

44 An organization may disclose an individual’s personal information without their knowledge or consent to a government institution or part of a government institution that has made a request for the information, identified its lawful authority to obtain the information and indicated that the disclosure is requested for the purpose of enforcing federal or provincial law or law of a foreign jurisdiction, carrying out an investigation relating to the enforcement of any such law or gathering intelligence for the purpose of enforcing any such law.

The Supreme Court essentially said “what the hell does lawful authority mean”? And the government has made no effort to do so in Bill C-27. but that’s just as well, since Companies should always say “come back with a warrant”.

Investigations

The big changes are with respect to the role of the Privacy Commissioner. The Commissioner is no longer an ombudsman with a focus on nudging companies to compliance and solving problems for individuals. It has veered strongly towards enforcement.

As with PIPEDA, enforcement starts with a complaint by an individual or the commissioner can initiate it on his own accord. There are more circumstances under the CCPA where the Commissioner can decline to investigate. After the investigation, the matter can be referred to an inquiry.

Inquiries seem to have way more procedural protections for fairness and due process than under the existing ad hoc system. For example, each party is guaranteed a right to be heard and to be represented by counsel. They’ve always done this to my knowledge, but this will be baked into the law. Also, the commissioner has to develop rules of procedure and evidence that have to be followed. These rules have to be made public.

At the end of the inquiry, the Commissioner can issue orders to measures to comply with the Act or to stop doing something that is in contravention of the Act. The commissioner can continue to name and shame violators. Notably, the Commissioner cannot levy any penalties.

The Commissioner can recommend that penalties be imposed by the new Privacy and Data Protection Tribunal.

The Tribunal

The legislation creates a new specialized tribunal which hears cases under the CCPA. It is expected that its jurisdiction will likely grow to include more matters. The “online harms” consultation that took place in the last year anticipated that certain questions would be determined by this tribunal as well.

Compared to C-11, the new bill requires that at least three of the tribunal members have expertise in privacy.

Its role is to determine whether any penalties recommended by the Privacy Commissioner are appropriate. It also hears appeals of the Commissioner’s findings, appeals of interim or final orders of the Commissioner and a decision by the Commissioner not to recommend that any penalties be levied.

Currently, under PIPEDA, complainants and the Commissioner can seek a hearing in the federal court after the commissioner has issued his finding. That hearing is “de novo”, so that the court gets to make its own findings of fact and determinations of law, based on the submissions of the parties. The tribunal, in contrast, has a standard of review that is “correctness” for questions of law and “palpable and overriding error” for questions of fact or questions of mixed law and fact. These decisions are subject to limited judicial review before the Federal Court.

So what about these penalties? They are potentially huge and I have a feeling that the big numbers were pulled out of the air in order to support political talking points that they are the most punitive in the G7. The maximum administrative monetary penalty that the tribunal can impose in one case is the higher of $10,000,000 and 3% of the organization’s gross global revenue in its financial year before the one in which the penalty is imposed.

The Act also provides for quasi-criminal prosecutions, which can get even higher.

The Crown prosecutor can decide whether to proceed as an indictable offence with a fine not exceeding the higher of $25,000,000 and 5% of the organization’s gross global revenue or a summary offence with a fine not exceeding the higher of $20,000,000 and 4% of the organization’s gross global revenue. If it’s a prosecution, then the usual rules of criminal procedure and fairness apply, like the presumption of innocence and proof beyond a reasonable doubt.