Submission of the Office of the Privacy Commissioner of Canada on the Treasury Board Secretariat consultation on the Privacy Act modernization
August 5, 2026
The Honourable Shafqat Ali, P.C., M.P.
President of the Treasury Board
90 Elgin Street
Ottawa, Ontario K1A 0R5
Canada
Dear President Ali,
Thank you for the opportunity to provide views on the Treasury Board Secretariat (TBS) consultation paper on modernizing the Privacy Act. I am pleased to share the enclosed submission of the Office of the Privacy Commissioner of Canada.
Privacy is a fundamental right that reinforces the freedoms and trust that underpin our democracy and unites us as Canadians. It is intricately tied to dignity, autonomy, and the enjoyment of other fundamental rights and freedoms.
I strongly support prioritizing the modernization of our federal public sector privacy law to allow federal institutions to successfully meet the challenges and opportunities of these digital times. As stewards of so much sensitive financial, health, employment, immigration, and public safety-related data, federal institutions have a tremendous – and increasingly challenging – responsibility to protect it. Government data banks are attractive targets for bad actors and in the last decade, we have seen data breaches and cyberattacks surge in scale, complexity, and severity.
We also know that Canadians care about how their information is managed. A survey by my Office found that nine in 10 Canadians are concerned about privacy, and that 62 percent believe that the Government of Canada respects their privacy rights.
In an increasingly digital world, the collective expertise and shared values of our public service will be key to preserving and expanding the trust that Canadians hold in their federal institutions, programs, and services. The management of personal information is also an enabling factor in transformative initiatives that can drive results and fuel innovation in many areas.
I look forward to continuing to work with you and your office to advance the modernization of the Privacy Act, and to help federal institutions meet their obligations under the Act in the handling of Canadians’ personal information.
Sincerely,
(Original signed by)
Philippe Dufresne
Commissioner
c.c.: Mike MacDonald, Chief Information Officer of Canada
Submission of the Office of the Privacy Commissioner of Canada: Consultation on Privacy Act Modernization
PART 1: Areas of General Support
The OPC generally supports the policy direction reflected in the discussion paper and considers many of the proposals to be consistent with its recommendations for modernizing the Privacy Act. In particular, the proposals would strengthen the Act’s accountability framework and better equip it to address evolving technologies and data practices. The comments below identify areas of support and recommend additional measures that would further strengthen the legislation and enhance the protection of personal information.Footnote1
In line with TBS proposals, the OPC has recommended that the Privacy Act recognize privacy as a fundamental right and incorporate modern privacy principles. These reforms would establish a principled framework for interpreting and applying the Act and better align the federal public sector privacy regime with contemporary domestic and international standards. The OPC also supports the proposed recognition of the importance of data to Indigenous self-determination and encourages continued collaboration with Indigenous partners to ensure that amendments reflect Indigenous perspectives and meaningfully uphold Indigenous data sovereignty.
We support the proposal to make safeguards a legal requirement that expressly requires institutions to use physical, technical, and administrative security measures to protect personal information. Where personal information is processed or stored outside Canada, we recommend that the legislation also require institutions to assess and mitigate the privacy risks associated with transborder data flows.
The OPC also agrees with establishing explicit statutory requirements for the management, notification, and reporting of privacy breaches. To strengthen these obligations, the Act should prescribe timelines for reporting material breaches to affected individuals and to the Privacy Commissioner and expressly authorize the Commissioner to inspect institutional breach records.
Similarly, introducing a legislative requirement to conduct Privacy Impact Assessments (PIAs) would help to strengthen accountability, and support privacy-protective program design. The legislation should require PIAs in prescribed high-risk circumstances, including activities involving sensitive personal information, high-impact artificial intelligence systems, the development or training of AI models using personal information, and transborder processing or storage of personal information.
The OPC has recommended that a reformed Privacy Act should include an explicit necessity and proportionality requirement governing the collection of personal information. Replacing the current “relates directly to” standard with a more rigorous legal threshold would help address the risk of unnecessary or excessive collection by federal institutions. The proposed criteria of legal authority, necessity, effectiveness, and minimal intrusiveness typically inform a necessity and proportionality assessment. However, for greater clarity, we recommend that there also be an explicit proportionality requirement.
The proposal to authorize greater collaboration between the Privacy Commissioner and other regulatory and oversight bodies would facilitate coordinated oversight and more effective responses to increasingly cross-jurisdictional privacy issues, while promoting greater regulatory consistency and the sharing of expertise and best practices. Likewise, requiring a statutory review of the Privacy Act every five years would help to ensure that the Act remains responsive to technological developments, evolving privacy risks, and changing public expectations regarding the protection of personal information.
The OPC agrees with providing the Privacy Commissioner with the discretion to refuse to investigate, or to discontinue the investigation of, complaints that are trivial, frivolous, vexatious, made in bad faith, or where further investigation is unnecessary having regard to all the circumstances. An amendment modelled on subsection 30(4) of the Access to Information Act could support the efficient administration of the complaints process while enabling the OPC to focus its resources on matters of greater public interest and impact.
Similarly, providing institutions with limited discretion to decline requests for access to personal information that are vexatious, made in bad faith, or otherwise constitute an abuse of the statutory right would be appropriate to incorporate into a modernized Act. As under section 6.1 of the Access to Information Act, the exercise of this discretion should be subject to the prior written approval of the Privacy Commissioner to ensure appropriate oversight and preserve individuals’ access rights.
Finally, we believe that expanding the Federal Court’s jurisdiction and available remedies under the Act would strengthen the Act’s accountability framework. Providing individuals with recourse to the Federal Court in respect of all complaints and empowering the Court to grant a full range of remedies — including damages where appropriate — would ensure that individuals have access to meaningful redress where their privacy rights have been infringed and would create stronger incentives for federal institutions to comply with the Act. As discussed in our comments on Proposal 19, expanded judicial recourse would be most effective if complemented by order-making powers for the Privacy Commissioner. We look forward to assessing further details of this proposal, including under which circumstances complainants and the OPC would be entitled to apply to the court, and what remedies the court would be empowered to grant.
Recommendations
To ensure that the Privacy Act reflects modern privacy standards, the OPC recommends that:
- in cases where personal information is processed or stored outside Canada, institutions be required to assess and mitigate the privacy risks associated with transborder data flows;
- the Act prescribe timelines for institutions to notify affected individuals and the Privacy Commissioner of material breaches and include an express authority for the Commissioner to inspect institutional breach records;
- the Act require institutions to conduct PIAs in high-risk circumstances, including activities involving sensitive personal information, high-impact artificial intelligence systems, the development or training of AI models using personal information, and transborder processing or storage of personal information;
- the proposed necessity test to limit the collection of personal information explicitly incorporate an assessment of the proportionality of the privacy intrusion;
- institutions be provided with discretion to decline access requests that are vexatious, made in bad faith, or otherwise an abuse of the right of access, subject to the prior written approval of the Privacy Commissioner; and
- expanded judicial recourse be complemented by order-making powers for the Privacy Commissioner.
PART 2: Priority Recommendations to Strengthen the Proposed Legislative Framework
Proposal 15: Harmonize the request regime by incorporating requests for personal data into the Access to Information Act
Proposal 15 seeks to make it easier for Canadians and for federal institutions to deal with requests for access to personal information. The proposal suggests that moving requests to access personal information from the Privacy Act to the Access to Information Act would streamline processes for both requesters and institutions.
While this may appear to be the case at first glance, a closer review of the legislative scheme indicates that moving requests for access to personal information in this way would not result in additional efficiencies for requesters or institutions because it would require them to deal with two laws and two regulators instead of one when invoking their privacy rights. This would risk weakening Canadians’ fundamental right to privacy.
A faster, more efficient and economical solution to harmonize the access request regime would be for the OPC, the Office of the Information Commissioner of Canada (OIC) and TBS to enter into a Memorandum of Understanding (MOU) to streamline the process and make it more user-friendly for requesters and institutions alike. For example, the MOU could provide for efficient solutions to seamlessly direct complaints to the proper regulator and to ensure that compliance processes are coordinated and harmonized.
By contrast, moving requests to access personal information from the Privacy Act to the Access to Information Act would not result in harmonization and would be inconsistent with the recognition of privacy as a fundamental right.
An individual’s right to access their personal information is one of the ten principles set out in the National Standard of Canada entitled Model Code for the Protection of Personal Information, CAN/CSA-Q830-96, which forms Schedule 1 of the Personal Information Protection and Electronic Documents Act (PIPEDA). The right of access is recognized in Article 15 of the General Data Protection Regulation (GDPR) and in the OECD Guidelines on the Protection of Privacy and Transborder Flows of Personal Data. It is undoubtedly one of the core privacy principles recognized both in Canada and internationally.
The right to access one’s personal information is critical to the fundamental right to privacy as it is a necessary precondition to the exercise of other key privacy principles such as accountability, identifying purpose, limiting retention, accuracy, safeguards, openness and challenging compliance. Without the right of access, individuals may be unable to invoke their other rights as they would not be aware of what is being collected and for what purpose.
As a result, moving the right of access to personal information from the Privacy Act to the Access to Information Act would require individuals and institutions to deal with two different laws and two different regulators when invoking their privacy rights. This would be inconsistent with the recognition of privacy as a fundamental right and would not achieve the objective of streamlining processes and creating a more effective and efficient regime for requesters and institutions.
For these reasons, we recommend that greater harmonization and user-friendliness be achieved by putting in place MOUs and other coordinating processes between the OPC, the OIC and TBS, and that access requests for personal information remain in the Privacy Act under the jurisdiction of the Privacy Commissioner of Canada.
Recommendations
To improve the efficiency of the access to personal information regime while preserving individuals’ privacy rights, the OPC recommends that:
- the statutory right of access to personal information remain within the Privacy Act and continue to be overseen by the Privacy Commissioner; and
- administrative efficiencies be pursued through enhanced collaboration and coordination between the OPC, the OIC and TBS, including improved guidance to institutions and more user-friendly processes for individuals.
Proposal 19: Grant the Commissioner binding order-making powers for corrective action plan enforcement and provide them with the discretion to discontinue or decline complaints
The OPC supports the proposal to grant the Commissioner binding order-making powers. The lack of order-making powers has been a long-standing gap in the law which has put Canada at odds with international counterparts.
However, the proposal considers that the Commissioner could require only that an institution develop and publish a corrective action plan and refer the matter to the Court if an institution fails to implement its action plan.
As drafted, this proposal would not enable the Commissioner to require the inclusion of any specified measure or timeline in the action plan, both of which would appear to be fully at the discretion of the institution.
Consequently, in situations where the Commissioner finds that an institution has breached the privacy rights of Canadians, the determination of the appropriate remedy would be up to that institution, not the Commissioner. In practice, this would risk replacing one non-binding mechanism with another.
For these reasons, the OPC continues to recommend that the Privacy Act provide the Commissioner with appropriately scoped order-making powers. Such powers should enable the Commissioner, as a measure of last resort following investigation and efforts to resolve a complaint informally, to issue binding orders requiring compliance with the legislative obligations established by the Act. This approach would provide a more effective means of enforcing privacy rights, ensuring that the Act’s requirements are supported by meaningful and enforceable remedies.
The OPC supports the proposal to provide the Commissioner with the discretion to decline to investigate, or to discontinue the investigation of, complaints that are trivial, frivolous, vexatious, made in bad faith, or where further investigation is unnecessary having regard to all the circumstances. This authority would promote the efficient administration of the complaints process and enable the OPC to focus its resources on matters of greater public interest and impact.
Recommendations
To strengthen the enforcement framework under a modernized Privacy Act, the OPC recommends that:
- the Privacy Act provide the Privacy Commissioner with appropriately scoped order-making powers that enable the Commissioner to require institutions to comply with their statutory obligations under the Act; and
- if the proposal for corrective action plans is pursued, it should complement – not replace – effective enforcement powers. At a minimum, the legislation should clearly define the Commissioner’s role in approving, amending, and enforcing corrective action plans, and establish binding implementation requirements and timelines.
PART 3: Additional Recommendations
Enabling integrated services
The OPC supports efforts to improve service delivery and reduce administrative burden for Canadians. Greater detail will be needed regarding the scope of permissible data sharing and reuse, the legal thresholds that would apply, and how these requirements would be reflected in legislation.
The OPC recognizes that broader information sharing may provide tangible benefits in certain contexts. For example, reusing basic identifying information, such as an individual’s name, address, or date of birth, would reduce the burden on Canadians of repeatedly providing or updating the same information across multiple institutions.
The OPC supports incorporating clear statutory criteria to govern decisions to reuse or share personal information, such as limiting re-use or sharing to what is necessary, clearly beneficial and minimally intrusive. We would emphasize that a framework for allowing broader sharing or reuse of personal information across government should include clear limitations so that it is not broadly interpreted and should include language to specify that the impact on privacy must be proportionate to the public interests at play.
The proposal to establish designated official sources of government digital data may also provide efficiencies in certain circumstances. At the same time, we would recommend that requirements be put in place with respect to risks relating to security breaches, accountability for decisions based on shared data, and individuals’ rights of access and correction.
Robust transparency measures will also be essential. The proposal to publish high-level summaries in a central registry will improve transparency, and we would recommend that it be accompanied by meaningful and accessible notice and transparency obligations that enable individuals to understand how, when, and why their personal information is collected, reused, shared, or disclosed.
Recommendations
To ensure that any framework for integrated services appropriately balances service innovation with the protection of privacy rights, the OPC recommends that:
- the Privacy Act clearly define the scope of any authority to collect, reuse, or share personal information for integrated services, including the categories of personal information that may be shared, the institutions that may rely on the authority, and the purposes for which personal information may be reused or disclosed;
- key concepts, including “public interest” and “direct benefit to individuals,” be clearly defined in legislation, with decision-making criteria that promote consistent application across government;
- any expanded authority to reuse or share personal information be subject to clear legal thresholds and safeguards, including a requirement to assess whether the privacy impacts are proportionate to the public interest or other legitimate objective being pursued;
- accountability measures comparable to those in subsection 8(2)(m) and subsection 8(5) of the Privacy Act be incorporated into any new authority permitting information sharing or reuse, including appropriate oversight and notification requirements;
- any framework establishing designated official sources of government digital data include clear governance, accountability, and safeguarding requirements, while ensuring that individuals’ rights of access to and correction of their personal information are preserved; and
- expanded authorities for indirect collection, information sharing, and reuse be accompanied by meaningful and accessible notice and transparency obligations that enable individuals to understand how, when, and why their personal information is collected, reused, shared, or disclosed.
Recognizing a spectrum of data sensitivity and key concepts
TBS’s policy Proposals 7 and 14 are aimed at modernizing the Privacy Act so that it recognizes a spectrum of data sensitivity and identifiability and adapts legal requirements and safeguards based on the sensitivity and identifiability of the data.
The OPC generally supports an approach that recognizes certain information as inherently sensitive and applies safeguards based on risk and the sensitivity of the data.
However, we have observations and recommendations concerning the interplay between the proposed definitions of core concepts under Proposal 14 and Proposal 7’s modified requirements under the Act based on sensitivity and identifiability. We have organized these comments by theme: 1) publicly available personal information, 2) anonymization, and 3) de-identified personal information.
- Publicly available personal information
The OPC welcomes the recognition in Proposal 7 that “publicly available” personal information should not include information in which an individual has a reasonable expectation of privacy. This important limitation should also be reflected in the proposed definition of “publicly available personal information” under Proposal 14.
Proposal 7 also suggests that publicly available personal information would need fewer safeguards than other types of personal information on the assumption that there are generally lower expectations of privacy for information that is freely made available to others. However, publicly available information can still include sensitive information. For example, the OPC’s 2026 investigation into Open AIFootnote 2found that OpenAI’s training on datasets, generally compiled from publicly accessible websites, included significant amounts of personal information of varying levels of sensitivity, such as medical information, individuals’ opinions on sensitive or controversial topics including about other individuals, and information relating to children. Similarly, even information that is made public by law, such as court records, can include sensitive information that is published for a specific purpose, and individuals might not reasonably expect that this information could be collected, used or disclosed by government for unrelated purposes without special consideration for the circumstances.
Recommendations
To ensure that the treatment of publicly available personal information appropriately reflects its potential sensitivity, the OPC recommends that:
- safeguarding requirements continue to apply in a manner proportionate to the sensitivity of the information, recognizing that publicly available information may nevertheless be highly sensitive.
- Anonymization
The consultation paper proposes defining “anonymize” as “to irreversibly and permanently modify personal data, such that there is no reasonably foreseeable risk of re-identification.” It further proposes that anonymized information would fall outside the scope of the Privacy Act and therefore would no longer be subject to its requirements.
The OPC recognizes that the proposed definition establishes a context-dependent standard for determining whether information has been anonymized. In other words, the proposed approach does not require the complete elimination of any theoretical possibility of re-identification but instead assesses whether there is a reasonably foreseeable risk of re-identification in the circumstances. This differs from an absolute standard, which would require that re-identification be impossible in all circumstances. The proposed definition would also require that anonymization be irreversible and permanent.
A context-dependent approach to anonymization is consistent with approaches adopted in other jurisdictions. In Quebec, the Act respecting the protection of personal information in the private sector (s. 23) and the Act respecting Access to documents held by public bodies and the Protection of personal information (s. 73) provide that information is anonymized where “it is, at all times, reasonably foreseeable in the circumstances that it irreversibly no longer allows the person to be identified directly or indirectly.” Similarly, Ontario’s Personal Health Information Protection Act (s. 2) defines “de-identify” (which is used in a similar sense as “anonymize” by TBS) as removing information that identifies an individual or for which “it is reasonably foreseeable in the circumstances that it could be utilized, either alone or with other information, to identify the individual.”
To the extent anonymized information falls outside the scope of the Privacy Act, the standard for anonymization should be set at a high bar. This requires not only an appropriate threshold for assessing identifiability, but also additional safeguards within the definition and surrounding legislative framework. These elements are important because they recognize that anonymization is not simply a one-time technical transformation. Rather, managing re-identification risk is an ongoing responsibility that must account for evolving technologies, new data sources, and increasingly sophisticated methods of combining information.
We therefore recommend incorporating additional parameters, drawing on the approaches adopted in Quebec and Ontario, so that the Act defines anonymization as follows:
“Anonymize” means to irreversibly and permanently modify personal information such that, at all times, there is no reasonably foreseeable risk of re-identification by any means, whether direct or indirect.
This formulation would strengthen the proposed definition in two important respects. First, by requiring that the standard be met at all times, it would recognize that anonymization is not a one-time exercise but an ongoing obligation requiring institutions to monitor and manage evolving re-identification risks. Second, by referring to re-identification by any means, whether direct or indirect, it would require a comprehensive assessment of the ways in which information could become identifiable, including as technologies and data-linkage techniques continue to evolve.
Finally, because the proposed definition does not require the complete elimination of re-identification risk, the OPC recommends that the offences contemplated under Proposal 21 extend to attempts to re-identify anonymized information. This additional safeguard would help preserve the integrity of anonymization over time and deter efforts to circumvent the protections established by the Act.
Recommendations
To ensure that anonymized information falls outside the scope of the Privacy Act only where the risk of re-identification is appropriately minimized, the OPC recommends that:
- the Act defines “anonymize” as the irreversible and permanent modification of personal information such that, at all times, there is no reasonably foreseeable risk of re-identification by any means, whether direct or indirect; and
- the offences contemplated under Proposal 21 apply to attempts to re-identify anonymized information.
- De-identified personal information
TBS’s discussion document proposes the following definition of “de-identify”: “to modify personal data so that an individual cannot be directly identified from it, though a risk of the individual being identified remains.”
Access requests
The discussion paper proposes that de-identified personal information would not be accessible through an individual’s request to access their personal information because the individual cannot readily be identified from the data.
This proposal highlights an inherent tension. De-identification is an important privacy-enhancing safeguard that institutions should be encouraged to use to reduce privacy risks. At the same time, the more data is de-identified, the more difficult it becomes for individuals to exercise their statutory right of access to their personal information.
Other jurisdictions have addressed this tension without creating a blanket exemption. In Quebec, the Act respecting Access to documents held by public bodies and the Protection of personal information does not exclude de-identified personal information (as it does anonymized information, which no longer constitutes personal information) from access rights. Under Article 11 of the GDPR, requirements for data requests do not apply where a controller “is able to demonstrate that it is not in a position to identify the data subject”.Footnote 3 However, if a data subject provides additional information “enabling his or her identification,” then this exception no longer applies.
With respect to the Privacy Act, a blanket exemption from access rights for de-identified personal information would likely go further than necessary as it would limit the right of access and could also affect related rights, such as the ability to request correction of inaccurate personal information.
The OPC therefore recommends that the Privacy Act not include a blanket exemption for de-identified personal information. If an exemption is adopted, we would recommend that it follow the EU model whereby the exemption would apply only where an institution can demonstrate that it is not reasonably able to re-identify the individual’s information.
Safeguards
Proposal 7 suggests that de-identified personal information may require fewer safeguards than identifiable personal information. The OPC does not agree that de-identification alone justifies reducing security requirements.
De-identified information continues to present a risk of re-identification and, where sensitive information is involved, a breach may still expose individuals to significant harm if the information is subsequently re-identified or combined with other available data.
Accordingly, the Privacy Act should expressly recognize that de-identification does not diminish the sensitivity of personal information. Institutions should be required to protect de-identified personal information in a manner that reflects both the sensitivity of the information and the reasonably foreseeable risk of re-identification.
Data sharing
Proposal 7 also contemplates permitting the sharing of de-identified personal information with trusted partners for purposes such as research and service improvement. As the discussion paper acknowledges, this practice is not without risk.
As a result, the sharing of de-identified personal information should be governed by written information-sharing agreements that establish permitted purposes, prohibit unauthorized onward disclosure, require appropriate safeguards, and assign accountability for compliance.
Recommendations
To ensure that the treatment of de-identified personal information appropriately balances privacy protection with legitimate uses of information, the OPC recommends that:
- the Privacy Act not include a blanket exemption from access rights for de-identified personal information. If an exemption is adopted, it should apply only where an institution can demonstrate that it is not reasonably able to re-identify the individual’s information;
- institutions be required to apply safeguards to de-identified personal information that are proportionate to both the sensitivity of the information and the risk that it could be re-identified;
- any sharing of de-identified personal information be governed by written information-sharing agreements that establish permitted purposes, prohibit unauthorized onward disclosure, require appropriate safeguards, and assign accountability for compliance; and
- the sharing of de-identified personal information be limited to what is reasonably necessary to achieve the specified purpose and permitted only where the anticipated public benefits outweigh the impacts on privacy.
Personal Information vs. Personal Data
TBS proposes that a modernized Act replace the term “personal information” with “personal data.” While the consultation paper does not provide a proposed definition, it indicates that the current requirement limiting personal information to data that is “recorded in any form” would be removed. The OPC supports removing this requirement, which would ensure that the Act applies to the processing of personal information that may affect individuals, even where the information is not retained in a recorded form.Footnote 4
With respect to changing the terminology, the proposal should ensure that it maintains consistency across Canada’s access and privacy framework, including key statutes such as the Access to Information Act and PIPEDA as well as those at the provincial/territorial level. Introducing different terminology may create interpretive challenges or unintended consequences unless the relationship between these concepts is clearly established.
Regardless of the terminology adopted, the definition should remain grounded in the concept of identifiability. The Act should include a definition of “identifiability” based on the test established by the Federal Court in Gordon v. Canada: “information will be about an ‘identifiable individual’ where there is a serious possibility that an individual could be identified through the use of that information, alone or in combination with other information.”
Codifying this test in legislation would promote greater certainty and consistency in the interpretation of “identifiable individual,” while preserving the contextual analysis required to account for evolving technologies and increasingly sophisticated methods of linking and analyzing information.
Recommendations
The OPC recommends that a modernized Privacy Act:
- ensure that any revised terminology or definition (whether “personal information” or “personal data”) maintains consistency with Canada’s broader access and privacy framework and avoids interpretive uncertainty with related legislation; and
- include a statutory definition of “identifiability” based on the Gordon v. Canada test, recognizing that an individual is identifiable where there is a serious possibility that they could be identified through the use of the information, alone or in combination with other available information.
Notice and transparency requirements
The OPC supports the objective of strengthening the Privacy Act’s transparency framework. Transparency is a foundational element of meaningful privacy protection. It enables individuals to understand how federal institutions collect, use, disclose, and retain their personal information, exercise their rights under the Act, and hold institutions accountable for their information-handling practices.
The proposed centralized registry of personal information holdings, plain-language privacy notices, and enhanced transparency requirements for automated decision systems (ADS) are positive steps toward modernizing the Act. In particular, providing individuals with information about the use of ADS is essential to ensuring that they understand when ADS are used to support decisions that affect them and are able to exercise their rights to access, correction, and review.
In addition, we recommend the following transparency measures:
The Act should establish clear transparency obligations that specify when notices are required, the information they must contain, and the circumstances in which additional transparency measures apply.
The Act should require that privacy notices be provided in plain, accessible language and include sufficient information to enable individuals to understand what personal information has been collected, the source of the information, when it was collected, the purposes for which it will be used or disclosed, and whether it may be reused or shared with other institutions.
More direct forms of notice should be considered to complement the centralized registry of personal information holdings to ensure timely, accurate, and sufficiently detailed information about how, when and why an individuals’ personal information is collected, used, or disclosed.
Recommendations
To ensure that individuals receive meaningful and timely information about how their personal information is handled, the OPC recommends that a modernized Privacy Act:
- Specify when privacy notices are required;
- Require that notices be written in plain, accessible language;
- Set out what information notices must contain; and
- Provide for direct forms of notice to individuals.
Strengthening the OPC’s ability to inform Canadians
Expanded public reporting authority
The OPC recommends that the Privacy Commissioner be granted greater discretion to communicate publicly about matters arising from the exercise of the Commissioner’s responsibilities under the Privacy Act. While the Commissioner may report to Parliament through annual and special reports, the Act does not otherwise permit the public disclosure of information obtained in the course of carrying out the Commissioner’s functions. Providing greater discretion to report publicly, where appropriate and in the public interest, would enable the OPC to communicate important privacy issues in a more timely manner, promote greater transparency, and provide guidance to federal institutions on the interpretation and application of the Act.
Research and public education mandate
The OPC recommends that the Privacy Act expressly provide the OPC with an explicit research and public education role. During the Department of Justice’s 2021–2022 review of the Act, consideration was given to expanding the OPC’s mandate in this manner. The OPC remains of the view that an explicit statutory mandate to undertake public education and awareness activities, conduct research, and support external research on issues of public importance would strengthen its ability to identify emerging privacy risks, promote compliance, and support the effective administration of the Act.
Recommendations
The OPC recommends that a modernized Privacy Act:
- provide the Privacy Commissioner with greater discretion to publicly report on matters arising from the exercise of the Commissioner’s statutory responsibilities; and
- provide the OPC with an explicit mandate to conduct research and public education activities.
Conclusion
The OPC appreciates TBS’s leadership in advancing modernization of the Privacy Act and the opportunity to provide comments on the proposed policy approaches. Many of the proposals represent important steps toward a modernized public sector privacy framework. As the policy proposals are translated into legislative provisions, the OPC looks forward to continuing to work collaboratively with TBS to ensure that the resulting legislation provides clear, effective, and durable protections for the personal information of Canadians.
- Date modified: