One of the most significant changes to Canadian privacy law proposed in Bill C-36 – a bill to reform Canada’s aged Personal Information Protection and Electronic Documents Act (PIPEDA) – is the shift from oversight by the Privacy Commissioner of Canada (PCC) who is an independent agent of Parliament to a Commission model where policy/guidance, oversight, and enforcement functions are divided between the Digital Safety and Data Protection Commission of Canada (DSDPCC) and Commission members designated as the Privacy and Consumer Data Commissioner (PCDC) and the ‘Division’. (For details on how these powers are allocated, see my previous post here). This post will consider both the merits and problems with this proposed change, using the United Kingdom (UK)’s shift from an Information Commissioner model to a Commission as a point of comparison.
The Commission model is not new to Canada. The Canada Radio-television and Telecommunications Commission is one example: a multi-member Commission is charged with oversight of the Online News Act, the Broadcasting Act and the Telecommunications Act. However, it is a new model for privacy governance. Currently in Canada, there is a federal privacy commissioner (with jurisdiction over federal public and private sector privacy laws), as well as thirteen provincial and territorial privacy commissioners. Three of these have jurisdiction over public, private, and health sector laws in their respective provinces (Alberta, British Columbia and Quebec), while the remaining commissioners oversee public sector privacy laws and in many cases health sector privacy laws. These commissioners are typically (although not exclusively) independent agents of their respective legislatures because they have, as part of their mandates, oversight of government compliance with privacy laws. The model proposed in Bill C-36 is significantly different.
In 2025, the UK passed the Data (Use and Access) Act 2025 (DUAA) to reform its domestic privacy law set out in the UK GDPR and the Data Protection Act 2018. One of the reforms in the DUAA was to move from an oversight model led by an Information Commissioner to one led by an Information Commission. This is change may have motivated Canada’s government to consider a similar move. Below, I explore some of the advantages and disadvantages of this change, comparing the British approach to that in Canada’s Bill C-36.
1. Commissioner v. Commission
The model of an independent Commissioner charged with oversight of privacy is very familiar to Canadians. It is also one in which there has generally been high confidence. Overall, the quality of appointments has been strong, and many of Canada’s federal, provincial and territorial commissioners have shown exemplary leadership. However, arguably, one of the disadvantages of this model is that it is vulnerable to human foibles. Some will remember how the uproar over former Commissioner Radwanski’s spending habits undermined both the reputation and the functioning of the Office of the Privacy Commissioner of Canada. In the UK, an ongoing investigation into the conduct of the last Information Commissioner has also proven disruptive. A multi-member Commission model is less reliant on the conduct of a single individual – or their health and well-being – and is therefore more resilient.
In theory, a multi-member model also creates space for more diversity of perspectives in oversight and governance. If the predominant goal of the legislation is to protect privacy, then expertise and a commitment to privacy should also take precedence for commission appointments. On the other hand, data protection laws are also about how to draw the boundaries between legitimate uses of personal data and its protection. Organizations that collect and process data would no doubt appreciate having their perspectives reflected at the Commission level. Perspectives of large organizations will be different from those of small or medium sized organizations. Other perspectives could also be reflected in appointments to the Commission. The challenge is, of course, finding an appropriate balance (not to mention agreeing on what would count as appropriate). And, as will be discussed below, the Digital Safety and Data Protection Commission will have multiple roles under at least two different statutes. This will make defining the relevant expertise even more challenging.
2. Appointments
The independent commissioner model has likely been particularly appreciated because privacy is a fundamental human right. It seems important enough to require governance from an actor insulated from the political fray. This is not just a piece of legislation aimed at economic governance, even though personal data and its exploitation are increasingly important for the economy. Excessive, improper, or careless uses of personal data have very real consequences for groups and individuals; and the privacy dimension is not just “one factor” to consider. The Supreme Court of Canada has, after all, characterized data protection laws as “quasi-constitutional” in character.
The UK legislation shifts to a Commission model but works to maintain the quality of appointments. For example, s. 5 of Schedule 12A in the UK DUAA provides that the person appointed as Chair of the Information Commission must be “selected on merit on the basis of fair and open competition”. They must also have no conflicts of interest (s. 6(1)). The same principles apply to the appointment of members of the Commission (s. 5(2)). Conflicts checks should be performed not just at appointment but “from time to time” to ensure that conflicts of interest do not develop during a commission member’s tenure. (s. 6(2)).
Under Bill C-36, appointments to the Commission are by the Governor in Council (cabinet). There is nothing in Bill C-36 that sets the parameters just described in the UK legislation. There are no requirements of merit, and nothing in the bill speaks to an open and fair competition.
That is not to say there are no rules for appointments in Canada. Governor in Council appointments are governed by policies which set out the process in some detail. But this is soft law, and clear statutory guidelines might be preferable in some contexts. In fact, one of the exceptions to the general rules around Governor in Council appointments is where a particular statute provides for something different: “Legislation may establish specific processes for an appointment, including specifying the need for a particular selection committee.” The same document notes that statutes can set requirements for experience, skills or other qualifications for Governor in Council appointees. Bill C-36 could do these things but does not.
Security of tenure is also an issue, since it is not desirable to have appointees who make decisions with one eye on their continued service or reappointment. The Chair of the UK Information Commission can only be removed from office for cause (set out in s. 7(7), and only by “His Majesty on an Address from both Houses of Parliament”. (s. 7(6)). This additional, non-partisan, protection is likely there because, unlike the new Commission created by Bill C-36, the UK’s Information Commission will continue to have public sector oversight functions. The Chair of the UK Commission holds office for a maximum of 7 years.
Under Bill C-36, the members of the Commission hold office during good behaviour (s. 10, Digital Safety Commission of Canada Act (DSCCA), Bill C-34), and for renewable terms of up to five years, with the idea that these terms will be staggered between the members (DSCCA, s. 11). One of these commissioners will be designated as Chair by the Governor in Council (DSCCA, s. 17(1)). While it is possible that a commissioner may be named Chair at the start of their first five-year mandate, it is also possible that it will happen later in their mandate, giving them a relatively short term as Chair. The duration of the Chair’s tenure is therefore less certain. As for removal from office, under Bill C-36, the Governor in Council can suspend a member without pay if “exceptional circumstances” warrant it, pending a determination of whether they should be removed from office. The decision to remove them from office rests with the Governor in Council. There are other indicia in the Bill that, by design, the new commission may be designed to be more responsive to political direction.
3. Privacy…and other stuff
The UK shift from an Information Commissioner to an Information Commission takes place entirely within the context of the oversight of access to information, privacy and data protection law. This has several advantages. One of these relates to the points made above – it is much easier to identify the relevant perspectives and desired expertise of commissioners if their mandate relates to access to information and data protection. Another is that there is relatively minimal disruption in governance and oversight if the pre-existing duties of the Commissioner are effectively transferred to the Commission (see s. 119 of the UK DUAA).
Bill C-36 does not benefit from either of these advantages. The government has decided to create an entirely new Digital Safety and Data Protection Commission of Canada which will have jurisdiction over the new Digital Safety Act in Bill C-34 as well as private sector data protection law. As Colin Bennett notes in a recent article, this is quite unprecedented internationally, and other countries have chosen not to join these different roles under one commission or agency. In Brazil, which also has a new (and autonomous) data protection agency, age verification and the protection of children in digital environments. It is still not a mandate cast as broadly as the proposed Canadian Commission. Data protection, on its own, is a very substantial mandate, requiring expertise and focus. No doubt the government believes that there are synergies to be found in a Commission governing things like online safety, deepfakes, chat bots, social media platforms and data protection – and there may be some – but it will be a diverse and complicated portfolio that will make any transition more fraught. It might also be a mandate that is simply too diverse and complex to be practicable.
To make matters more complicated, authority over both public and private sector data protection will be split under the new model. The current Privacy Commissioner of Canada (PCC) will continue to exercise functions under the federal public sector Privacy Act, while the new Commission will take on private sector data protection law. This will have significant consequences. Unlike the UK approach, where the top-level oversight model changed but not the underlying office and mandate, there will be no easy carry-over of staff. The Privacy Commissioner of Canada will need to retain expert staff to administer the Privacy Act. Other staff may (or may not) choose to migrate to the new Commission – but there will be disruption and loss of expertise, and it may be substantial.
In addition, synergies will be lost in how data protection is governed across public and private sectors that are increasingly intertwined in terms of data collection and processing. In Ontario, for example, the adjudication of a complaint into “smart” vending machines on an Ontario university campus addressed the university’s responsibility under Ontario’s public sector law regarding the procurement and instalment of the machines but could not address issues regarding the data collection and governance practices of the private sector supplier of the technology because Ontario does not have its own private sector data protection law. This is not to say that federal Privacy Act investigations are rolled in with PIPEDA investigations – they are not. But the federal Commissioner may see both sides of the same issue through different investigations under the two statutes that he oversees. This was the case with Clearview AI, for example, which was investigated under PIPEDA for its data scraping practices, while the RCMP was investigated under the Privacy Act for its use of Clearview AI’s facial recognition database.
Finally, this is not a simple change in how the top end of the organization is structured. A large part of Bill C-36 creates a complicated new governance framework that is meant to separate policy/guidance, investigation, and adjudication functions to prepare the Commission for its new oversight and enforcement roles. Since one of the objectives of Bill C-36 is to create a more robust enforcement regime, there will necessarily be new roles and responsibilities. It was therefore not open to the government to simply transfer existing oversight and enforcement functions from the PCC to the new Commission. However, transitioning from the Commissioner model to the Commission model while adding new substantive areas (digital safety and online harms) and designing an untested new oversight and enforcement framework is a lot to handle at once. My colleague Michael Geist has written about how challenging it will be to get the new Commission up and running.
Overall, there are pieces of Bill C-36 that are important (new oversight and enforcement powers lead the list), and there are also new rights. However, the total package is one that contains so much disruptive change that it risks substantially setting back privacy and data protection in Canada. Decisions to divorce public and private sector data protection governance (which the UK does not do), and to merge private sector data protection with a broad range of online harms concerns (which no one else does) have significant implications. So too does a drastic reconfiguration of governance frameworks. There may be too much going on in this bill for its own good (or ours).

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.