OPC’s 15 key recommendations on Bill C-27

The OPC’s Submission on Bill C-27, the Digital Charter Implementation Act, 2022 provides further details about each recommendation.

Privacy as a fundamental right

1. Recognize privacy as a fundamental right.

2. Protect children’s privacy and the best interests of the child.

3. Limit organizations’ collection, use and disclosure of personal information to specific and explicit purposes that take into account the relevant context.

4. Expand the list of violations qualifying for financial penalties to include, at a minimum, appropriate purposes violations.

5. Provide a right to disposal of personal information even when a retention policy is in place.

Privacy in support of the public interest and Canada’s innovation and competitiveness

6. Create a culture of privacy by requiring organizations to build privacy into the design of products and services and to conduct privacy impact assessments for high-risk initiatives.

7. Strengthen the framework for de-identified and anonymized information.

8. Require organizations to explain, on request, all predictions, recommendations, decisions and profiling made using automated decision systems.

9. Limit the government’s ability to make exceptions to the law by way of regulations.

10. Provide that the exception for disclosure of personal information without consent for research purposes only applies to scholarly research.

Privacy as an accelerator of Canadians’ trust in their institutions and in their participation as digital citizens

11. Allow individuals to use authorized representatives to help advance their privacy rights.

12. Provide greater flexibility in the use of voluntary compliance agreements to help resolve matters without the need for more adversarial processes.

13. Make the complaints process more expeditious and economical by streamlining the review of the Commissioner’s decisions.

14. Amend timelines to ensure that the privacy protection regime is accessible and effective.

15. Expand the Commissioner’s ability to collaborate with domestic organizations in order to ensure greater coordination and efficiencies in dealing with matters raising privacy issues.

