On June 15, 2026, the federal government released its long-awaited, and latest version of reform of Canada’s private sector data protection law, the Personal Information Protection and Electronic Documents Act (PIPEDA). Following the failure of Bill C-27, Bill C-36 proposes to replace PIPEDA with the retitled Protecting Privacy and Consumer Data Act. To use an urban development metaphor, PIPEDA is the charming bungalow that no longer meets contemporary needs. Bill C-27 was a proposal to renovate that bungalow with a slightly awkward extension (the Personal Information and Data Protection Tribunal Act) that the neighbors complained about. Bill C-36 is a proposal to demolish the bungalow and replace it with an in-fill mega-house that will completely disrupt the character of the neighborhood. And there are just enough votes on the planning board that it might squeak through.
Two broad things are going on in Bill C-36. One is the updating of PIPEDA’s substantive provisions. There is considerable recycling here from Bill C-27, with some interesting tweaks – but really, very few updates considering the pace of technological change. These substantive changes (and non-changes) will be the topic of subsequent posts on the bill. The focus of this post is on the very significant and fundamental changes to oversight and enforcement – the AI Minister’s digital safety dream house.
Since the enactment of PIPEDA in 2000, consecutive federal privacy commissioners have provided oversight of the legislation, alongside carrying out their role under the public sector Privacy Act. PIPEDA was created with what was largely an ombuds-style of oversight, and the Commissioner lacked the power to issue orders or impose penalties. Because of this, there was little objection to the Office of the Privacy Commissioner of Canada (OPCC) taking on oversight of this new law. It already had experience with data protection principles, and it relatively easily grew into its oversight mandate for both public and private sectors. The model of a single commissioner with both public and private sector jurisdiction already existed in Quebec, and when Alberta and British Columbia passed substantially similar private sector data protection laws, their public sector privacy commissioners had oversight of those laws added to their roles.
However, one aspect of the OPCC’s dual role has become an irritant for the federal government. Because the Privacy Commissioner holds the government to account for its privacy practices under the Privacy Act, they are an independent agent of Parliament. This means that their accountability is to Parliament as a whole and not to the government. Normally, an agency that does not hold government to account will not be an independent agent of Parliament – there is simply no need for it. Further, governments have an interest in shaping how regulatory bodies carry out their administrative functions in the service of government policy. Some of the most significant changes in Bill C-36 reflect the government’s strongly held views on these issues. First, they see no need for a private sector data protection law to be overseen by an independent agent of Parliament, and second (most importantly) they want to play a much greater role in shaping how privacy law is interpreted and applied.
Bill C-36 lumps privacy in with other digital safety issues addressed in Bill C-34 (The Digital Safety Act) such as social media and chatbot regulation. In doing so, it reveals the concept of a new regulator with jurisdiction over digital safety issues construed more broadly, in which privacy is just one component. The argument will be that similar things should be similarly governed, and that there will be synergies and overlaps that are best addressed by one regulatory body. This ignores the fact that privacy is a complex, long-standing and well-developed body of law and regulation, that there are both domestic and international networks of privacy regulators that interact and collaborate, that privacy issues relate to the need to strike a balance between privacy rights and the thirst for data to fuel powerful technologies in a context in which humans are increasingly vulnerable and exploited, and that it is possible for different regulators to co-operate and collaborate without being smunched into one.
The interest of the government in redirecting the approach to privacy law within the digital ecosystem it is building is evident in s. 77 of Bill C-36, which mandates that the exercise of the powers and duties of the new Commission in relation to privacy law must be shaped by specific considerations:
77. In exercising any powers or performing any duties or functions under this Act, the Commission must take into account all relevant factors, including, if applicable,
(a) the purpose of this Act;
(b) the size and revenue of organizations;
(c) the volume of the personal information under the control of organizations and the sensitivity of that information;
(d) the best interests of children;
(e) the importance of respecting Canada’s international trade obligations;
(f) the importance of supporting economic growth, competition and innovation in the Canadian marketplace; and
(g) any other matter of general public interest. [My emphasis]
This list demonstrates clear political direction as to how and where privacy fits within the scheme of things, which helps to explain the major structural changes to privacy oversight found in Bill C-36. In s. 5 of the Bill, the government added the words\ “fundamental” to “right of privacy” as a gesture to those who have clamored for greater recognition of this fundamental right in a law that is meant to balance privacy rights against the thirst for data to fuel digital technologies – but this briefest mention of the fundamental human rights basis of privacy protection flickers only weakly in the background of this new scheme.
While a Minister cannot easily boss around an independent agent of Parliament, they are not so constrained with other statutory regulators. A good example of the Minister’s strong interest in playing a role in the activities of the proposed new Commission is found in s. 76(c)(iii) of Bill C-36, which, among other things, empowers the 5-member Commission to
(ii) develop guidance materials and tools for organizations in relation to their compliance with this Act — including any guidance materials and tools that are requested by the Minister — in consultation with stakeholders, including any relevant federal government institutions, [Emphasis added]
The Commission is also charged with preparing material about how it – and the new Privacy and Consumer Data Division – will exercise their powers and duties:
78(2) The Commission must develop, in consultation with the Minister and stakeholders, guidance material respecting the exercise or performance of the powers, duties and functions of the Commission, the Commissioner and the Division in relation to enforcement and dispute resolution under this Act,
This is a level of political control and direction that is not possible with an independent agent of Parliament. An important question, of course, is whether it is consistent with a reasonably independent data protection commissioner.
As noted earlier, Bill C-27 would have created a new tribunal to consider Commissioner recommendations for the imposition of administrative monetary penalties and to hear appeals from Commissioner orders or findings. A rationale for the creation of this new structure was that the substantial new enforcement powers in the Bill meant that the ombuds-type approach of PIPEDA was no longer adequate and that it was not appropriate for the same body that developed policy and guidance and engaged with stakeholders to also be responsible for enforcement activities, including the imposition of potentially substantial penalties. It was felt that there needed to be some separation between the policy and guidance functions of the office and the investigation/enforcement side. (Note that provincial commissioners with private sector jurisdiction and order making powers (Quebec, Alberta, and BC) all structure their offices internally to maintain a high level of separation of function to avoid conflicts – and this is one way that the desired result can be achieved.) Bill C-27’s proposed Data Protection Tribunal was an attempt to add a layer between the OPCC and the imposition of orders and penalties. It was not popular and raised concerns. What Bill C-36 does instead, is to remove private sector data protection from the OPCC entirely and hand it over to a new agency that separates policy from enforcement and that is not independent. With this change, the government gets something that it wanted much more than the unloved Tribunal – greater control at the policy level. Unfortunately, privacy may well be collateral damage. Of course, at least now it will be a “fundamental right” to privacy that is collateral damage. Think of it as an upgrade.
It is clearly no accident that this long overdue privacy reform bill had to wait until after the (also overdue) federal AI Strategy came out, because the AI Strategy makes it evident that AI (adopt it, develop it, deploy it, trust it) is the strategy. Bill C-36 supports that strategy by making it harder for data protection law to get in the way of innovation.
Make no mistake, the radical changes to the privacy regime reflected in this bill are within the power of the government to enact. However, just because you can do something doesn’t mean it is a good idea. The radical (and it is radical in the sense of both extreme and going to the root of things) restructuring of oversight for private sector data protection law in Canada will have consequences.
Humans have never been more vulnerable than they are today with respect to the thirst to collect and use their data for a dizzying range of purposes that all too often include exploitation and manipulation. Privacy matters – and it has become more complex and consequential than ever before. The OPCC is a highly respected body both within and outside Canada. In fact, Canada’s federal commissioner currently leads the Global Privacy Assembly, which is a testament to the esteem in which the office is held internationally. Domestically, the OPCC has built a team that is second to none, with deep experience and commitment to privacy, and strong technical knowledge and capacity. Although relations with the private sector have sometimes been uncomfortable, the current Commissioner is an effective bridge builder. The fact that some large offshore companies have resisted findings of this or previous commissioners in several investigations is not a sign of failure or of being out of step with best approaches to digital privacy; rather, it is a sign that this is a complex and rapidly evolving area where the tensions between commercial interests and individual privacy are often intense and have significant implications for both sides. Yet a human-rights based approach to privacy does not have to defeat an innovation-driven political agenda. Indeed, the federal Commissioner’s position in the OpenAI investigation report shows an important level of pragmatism in a complicated context. Enlightened independence is a real virtue in this space – and it builds trust on all sides. What is proposed in Bill C-36 is fundamentally disruptive. It will remove a respected institution from an oversight role. There will be an inevitable loss of personnel and of expertise. The new oversight body will have a steep learning and building curve. It is unclear what resources this organization will be given, and how its multiple mandates at the Commission level will be prioritized.
There is no urgent need for this restructuring. Choosing demolition over renovation in this context is about political control which in turn is about furthering the AI Strategy goals of supporting the AI industry and the adoption of AI. It is not about protecting privacy or human rights. The government is doubling down on AI and it is using our personal data to do so.

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.