AUTO-UPDATED

Op-Ed: Canada rewrites the rules on AI privacy with Bill C-36, and this is just the start

Canada’s proposed Bill C-36, the Protecting Privacy and Consumer Data Act, introduces a comprehensive regulatory framework to address modern AI security risks and evolving data privacy challenges for citizens.

Key Points

  • The legislation contains 147 specific sections aimed at governing personal information collection and commercial data usage.
  • It introduces new regulatory oversight, including the appointment of a Commissioner and the establishment of a dedicated Commission.
  • The bill specifically targets "data inference," addressing how AI uses indirect profiling and disparate data patterns to identify individuals.
  • It establishes formal processes for filing complaints, conducting audits, and enforcing compliance agreements regarding privacy breaches.
  • The framework requires amendments to 17 existing Canadian statutes to ensure legal consistency across the digital landscape.

Why it Matters

This bill represents a significant attempt to modernize privacy laws that were largely written before the widespread adoption of generative AI. Its success could serve as a global benchmark for how nations balance commercial data utility with the protection of individual privacy in an era of automated profiling.
Digital Journal Published by Paul Wallis
Read original