Canada has introduced Bill C-36, the Protecting Privacy and Consumer Data Act, marking the nation's first major overhaul of private-sector privacy laws in over 25 years. The bill explicitly recognizes privacy as a fundamental right and aims to address the challenges posed by artificial intelligence, deepfakes, and automated decision-making.
The legislative reform arrives amid heightened scrutiny of tech companies following a tragic shooting in Tumbler Ridge, British Columbia. The 18-year-old suspect allegedly used ChatGPT before the attack, leading the victim's family and the province of British Columbia to initiate legal action against OpenAI, accusing the company of failing to notify law enforcement despite identifying violent prompts.
Evan Solomon, Canada’s minister of AI and digital innovation, emphasized that the government's dual goals of protecting citizens and fostering tech innovation are not mutually exclusive. Bill C-36 establishes a framework for the responsible use of de-identified data, including safeguards to minimize the risk of re-identification while supporting research and public-interest activities.
However, experts point out that the nature of privacy harms is shifting. Ignacio Cofone, a professor of law and regulation of AI at the University of Oxford, explains that the primary threat is no longer just what data companies collect, but what AI can infer from it. Using patterns in location data, browsing history, and shopping habits, algorithms can accurately predict sensitive personal attributes like health status or creditworthiness without users ever disclosing them.
To address this, Bill C-36 expands the definition of personal information to encompass inferred data and mandates that organizations explain significant automated decisions. While Cofone views these updates as vital, he argues that the law must ultimately regulate the harmful applications of AI predictions rather than focusing solely on data collection.
Additionally, the bill introduces robust protections for minors. Information belonging to individuals under 18 will be classified as inherently sensitive, granting youth stronger rights to have their personal data deleted. While tech builders and parents support the reforms, many argue that further regulation is needed to establish age-appropriate designs and ensure algorithmic fairness, preventing a child's early digital footprint from defining their adult lives.