Issue sheets on Main Estimates 2026-27 (Appearance before ETHI)
OPC Budget
Speaking Points
- The total proposed funding for my office in the 2026-27 Main Estimates is $37.5 million, a decrease of $0.9 million from the previous year due to the sunset of temporary funding received through Budget 2023.
- Included in our Main Estimates funding is the temporary funding received as part of Budget 2023, namely the funding for the preparation activities required to implement the Consumer Privacy Protection Act that was proposed as part of Bill C-27. This funding of $4M for fiscal year 2026-27 is subject to conditions that remain outstanding; consequently, the funds are held centrally in a frozen allotment and are currently unavailable for use by my Office.
- In the Spring Economic Update 2026, the federal government announced temporary funding of $3 million per year for five years to support our operations.
- We will use this funding to protect and promote privacy rights, including by investigating complaints, assessing compliance, providing advice and recommendations, and working with stakeholders in other jurisdictions.
Background
- The office’s 2026-27 Main Estimates of $37.5M break down as follows (2025-26 is provided for comparison):
|
|
2025-26 |
2026-27 |
||
|
Budgetary |
$M |
% |
$M |
% |
|
Personnel expenditures (including EBP) |
31.0 |
81 |
30.7 |
82 |
|
Operating expenditures |
6.9 |
18 |
6.3 |
17 |
|
Contributions program |
0.5 |
1 |
0.5 |
1 |
|
Total reference levels |
38.4 |
100 |
37.5 |
100 |
Note: The funding announced in the Spring Economic Update 2026 of $3M per year for five years is not included in these Main Estimates.
LEAD: Corporate
OPC resource allocation
Speaking Points
- My office continues to allocate its resources in a manner that is forward-looking to prevent privacy issues before they arise as opposed to addressing them only after the fact.
- One of our guiding strategic priorities is to maximize the reach and impact of our efforts to protect and promote privacy rights. To achieve this, we are increasing the use of business intelligence to identify trends and assist with decision-making, exploring the use of responsible AI and cultivating and leveraging strategic partnerships with partners.
- Given our current funding level, this is not always possible when a significant portion of our resources must be focused on the investigation of individual complaints.
- To ensure an appropriate balance between the need to promote and enforce compliance, we currently split our budget almost equally between our promotion and compliance programs.
Background
- The following table summarizes the funding and full-time equivalents (FTEs) by program and for internal services according to the office’s Departmental Results Framework (2025-26 is provided for comparison):
|
|
2025-26 |
2026-27 |
||
|
Program area |
$M |
FTEs |
$M |
FTEs |
|
Promotion Program |
12.9 |
86 |
15.1 |
91 |
|
Protection Program |
15.3 |
94 |
12.4 |
81 |
|
Internal services |
10.2 |
57 |
10.0 |
59 |
|
Total reference levels (Main Estimates) |
38.4 |
237 |
37.5 |
231 |
Note: The funding announced in the Spring Economic Update 2026 of $3M per year for five years is not included in these Main Estimates.
LEAD: Corporate
OPC spending on external contracts
Speaking Points
- The OPC utilizes contracted resources strictly to address ad hoc capacity gaps across its diverse operational areas, including privacy, law, information technology, finance, security and people management.
- This highly targeted approach accounts for an average annual expenditure of $3 million of dollars per year in professional and special services. My office carries out a continuous review and assessment of these contracts to maximize their impact on mandate delivery.
- As announced in the Spring Economic Update 2026, the government is committed to reducing expenditures on external management and other consulting services by 20% over the next three years.
- In alignment with this mandate, our Office has begun reducing reliance on external services by leveraging internal talent, supported by recently approved temporary funding.
- Furthermore, we have implemented strengthened contract management controls, fully aligning with the updated Treasury Board Directive on the Management of Procurement.
Background
- OPC business owners are required to document and justify the use of professional services according to the revised Directive on the Management of Procurement.
- For all professional services contracts that exceed $40,000 (including applicable taxes and fees), the following will apply:
- Managers will validate and document that no other alternatives approaches to procurement are available; and
- OPC will integrate an attestation from the business owners as per the new mandatory procedures, starting September 30, 2024.
- The OPC also reviewed and implemented the strengthened internal control measures for professional services procurement, that came into effect on July 1, 2025.
LEAD: Corporate
Litigation costs
Speaking Points
- My Office resolves many complaints in early resolution or through its investigative findings and recommendations. Nevertheless, in the absence of order-making power, litigation is sometimes the only means of achieving compliance with my recommendations.
- Initiating a court application or responding to an application for judicial review can be very costly, despite best efforts to be judicious in the use of resources.
- While my Office’s litigation expenditures have generally varied between $100,000 and $300,000 annually over the past six years, in 2023-2024, they more than doubled from the previous year to surpass $700,000.
- This was due to unique circumstances, with expenses related to two cases in Federal Court and three at the Federal Court of Appeal.
Background
- OPC litigation expenditures for retainers with external counsel by fiscal year:
|
2020-21 |
2021-22 |
2022-23 |
2023-24 |
2024-25 |
2025-26 |
|
$114,930.49 |
$212,329.02 |
$284,277.14 |
$771,381.86 |
$137,606.15 |
$294,477.25 |
LEAD: Legal
Finding efficiencies
Speaking Points
- Protecting and promoting the fundamental right to privacy with maximum impact is one of the key guiding priorities that I have set for my office under our current strategic plan.
- In the last year, my officials have undertaken several initiatives to this end, including a restructuring of our operations, the introduction of an internal AI tool, and an increasingly strategic use of our investigative powers.
- In keeping with our strategic plan, we continually look for ways to enable greater efficiency, adaptability, and preparedness in the constantly evolving privacy landscape.
Background
- The 2024-2027 Strategic Plan: Lays out three key priorities that guide the OPC’s work: (1) protecting and promoting privacy with maximum impact, (2) addressing and advocating for privacy in this time of technological change, and (3) championing children’s privacy rights.
- Transformation: Announced in January 2025, the OPC’s Transformation Plan recognizes that structural and cultural changes were needed to respond to an increase in workload. The new structure is based on reframing the compliance function to maximize impact and efficiency by combining proactive compliance through engagements with compliance through enforcement (investigations) within a single sector.
- New Structure: The Office’s new structure took effect in May 2025. It includes three sectors (Compliance Promotion and Enforcement Sector; Legal Services and Policy Sector; and Enabling Services Sector). A new Communications and Stakeholder Relations Directorate was also created.
- Digital transformation: We continue to refine cloud technologies supporting a hybrid work model and have initiated a digital strategy, which includes a considered AI approach based on sound privacy, cybersecurity and modern information management practices.
LEAD: Corporate
OPC Staff Expertise and Training
Speaking Points
- The scope of OPC’s operational environment is vast, requiring knowledge of fields such as privacy, IT, finance, national security, and law.
- As a result, we strive to recruit employees from diverse backgrounds and prioritize employee training and development given the pace with which our environment changes.
- We seek employees with the knowledge and skill set that can help us achieve the ambitious goals we have set for ourselves in our strategic plan, such as experts on children’s privacy.
- This also includes strengthening our technology-analysis function by hiring staff with expertise in AI and generative AI. This is a priority area which requires significant training and expertise.
Background
- As demand for privacy expertise continues to grow, we’re focusing on building strong internal skills that support our key business priorities.
- By investing in targeted learning, using partnerships to expand access to high-quality training, and strengthening our recruitment and retention practices, we increase the capabilities, commitment, and organizational knowledge needed to meet our goals.
- We are prioritizing access to technology-related training content to ensure we are keeping up with and staying ahead of technological advancements and their impact on privacy, particularly with respect to AI and generative AI and children’s privacy.
- We are taking a strategic approach to planning our learning investments to ensure our training, learning, and development programs directly support the organization’s mandate and priorities.
- We are in the early stages of developing a development program for employees in the Program Administration group (PM), which is the largest group of employees at the OPC.
Recruitment, retention, and people management
Speaking Points
- My office needs a stable, long-term source of funding to develop, attract, and retain the talent and expertise we need to deliver our mandate.
- The OPC remains an employer of choice, fostering employee development, well-being, and collaboration through technology. This commitment is reflected in the positive results of the latest Public Service Employee Survey on employee engagement, highlighting our engaging and meaningful work environment.
- We remain committed to promoting the values of the public service and to strengthening our culture of accountability, equity, diversity, inclusion and accessibility to leverage the full potential of our employees and produce better results for Canada and Canadians.
Background
- Integrated Human Resources Plan: We implemented the OPC Integrated Human Resources Plan (IHRP) as our five-year plan that encompass various aspects of HR, including EDI initiatives, well-being, and official languages.
- The IHRP will be reviewed, updated, and recalibrated annually to remain relevant and supportive of evolving organizational needs, priorities, and responsive to external factors.
- Recruitment Activities: We continue to leverage various staffing mechanisms to recruit talented candidates, while enhancing our use of data to inform recruitment and retention strategies.
- Hybrid work: We continue to adapt our hybrid work model to align with the Government of Canada’s direction, which announced an increase on-site presence.
- We will also continue to provide employees with the necessary information, adapted and modern tools to create an open, modern, flexible, and collaborative work environment designed to promote creativity, innovation, information sharing, and well-being.
LEAD: Corporate
Return to Office
Speaking Points
- We will be implementing the government’s plan to increase the on-site presence. Starting May 4, 2026, executives will be required to work on-site five days a week. Employees will be required to work on-site four days a week as of July 6, 2026.
- Both our headquarters in Gatineau and our regional Office in Toronto are well-equipped and have sufficient space to accommodate employees in accordance with the increased on-site presence.
- We have created activity-based workspaces and expanded access to reservable closed offices to support an accessible work environment.
- This approach promotes collaboration and productivity while helping employees make the most of their time on-site.
- Managers monitor compliance at the individual level, relying on their observations and employee self-reporting. The OPC assesses organizational compliance at an aggregate level using turnstile data.
Background
- TBS has informed deputy heads of their plans to increase on-site presence for eligible executives and employees. TBS has not yet shared further details on implementation, but the OPC has already updated its guidance documents to support employees with the change and facilitate the transition.
- We have updated our hybrid work guidelines and delegation instruments and have defined our organization’s values in a charter to help support consistent implementation across the OPC and ensures the model is well understood and reflected in how we work together, strengthening collaboration.
LEAD: Corporate
Departmental Results Report highlights
Speaking Points
- In 2024-2025, we continued to advance our three strategic priorities and work towards our departmental results.
- Our efforts and the infusion of temporary resources have allowed us to make modest progress in our compliance work, as we continue our work to meet all targets.
- We completed an internal strategic review, resulting in a major reorganization and transformation to refine our approach, streamline our activities and focus on achieving more efficient outcomes for Canadians in the years to come.
Background
- The latest available Departmental Results Report is for fiscal year 2024-2025 (Full Departmental Results Report in Annex).
- Targets met (2): Percentage of OPC recommendations on privacy-relevant bills and studies that have been adopted 89.5% (target at least 60%). Percentage of federal and private sector organizations that find OPC’s advice and guidance to be useful in reaching compliance 78% (target at least 70%).
- Targets missed (6): Percentage of Canadians who feel that: businesses respect their privacy rights 40% / the federal government respects their privacy rights 62% (target for both is at least 90%). Percentage of complaints responded to within service standards 62% (target at least 75%). Percentage of formal OPC recommendations implemented by departments and organizations 87% (target at least 90%). Percentage of Canadians who feel that they know about their privacy rights 47% (target at least 70%). Percentage of Canadians who read OPC information and find it useful 66% (target at least 70%).
- Indicators with no target (2): The 2 indicators that measures our guidance to businesses and information to Canadians on key privacy issues had no target, considering the possibility of a transformed legal framework and the fact that our guidance is grounded in legislation and could quickly become outdated following such reform.
- At the program level, the OPC met 2 of its targets. Outcome-level and Program-level results are published on GC Infobase.
LEAD: Corporate
Updated OPC Departmental Results Framework
Speaking Points
- My office reviewed and updated our departmental results indicators starting in 2026-2027, following the organizational transformation.
- The changes reflect the vision behind the organizational transformation with a strong focus on serving Canadians.
- The changes also strengthen the OPC’s accountability for results by closely aligning the results that we want to achieve with our program activities and resources.
Background
- Implemented in 2018-2019 to meet the requirements of the Policy on Results, it was essential that the Departmental Results Framework, including its results indicators and program-level indicators, be reviewed and adapted to reflect the current reality and priorities of the Office.
- Changes were made to the OPC’s result indicators and program-level indicators after a comprehensive internal review of its resources and structures and considered the implementation of its transformation plan.
- Through its review process, the OPC updated its 11 Departmental results indicators and its 7 program-level indicators. At the departmental level 2 indicators remained unchanged, 8 are new and 9 have been discontinued. At the program level, 2 indicators remained unchanged, 4 are new and 5 have been discontinued.
- The updated Departmental Results Framework better supports results-based decisions as it enables greater linkages between the OPC’s activities, resources and results.
LEAD: Corporate
Strategic Priorities (2024-2027)
Speaking Points
- My strategic plan and the three privacy priorities on which it is based offer a roadmap for maintaining trust and promoting innovation while protecting the fundamental right to privacy in the digital age.
- My three strategic priorities are 1) protecting and promoting privacy with maximum impact, 2) addressing and advocating for privacy in this time of technological change, and 3) championing children’s privacy rights.
- The priorities address areas where I believe that my Office can have the greatest impact, and where the greatest risks lie if they are not addressed. These will guide the OPC’s work through to 2027.
Background
- Priority one is focused on ensuring that the OPC’s activities are effective, efficient and impactful.
- e.g., the Transformation Plan (Launched in January, implemented in April 2025) restructured the OPC’s functions to ensure we respond rapidly and effectively to emerging issues and conduct compliance activities more strategically.
- Priority two focuses on bolstering our ability to address the privacy impacts of the fast-moving pace of technological advancements, especially in the world of artificial intelligence (AI) and generative AI.
- e.g., Collaboration amongst the G7 Data Protection and Privacy Authorities Roundtable to release statements on the role of data protection and privacy authorities in fostering trustworthy AI, and on child-appropriate AI.
- Priority three is about promoting and protecting the privacy rights of children, understanding and recognizing their unique sensitivities so that young people can benefit from technology without compromising their privacy and well-being.
- e.g., Conducting focused research and outreach with young people, launching a youth advisory council, and applying this lens to enforcement activities, i.e. TikTok and PowerSchool.
LEAD: Corporate
OPC Services to Canadians
Speaking Points
- My Office is implementing the Government of Canada Policy on Service and Digital to better protect and promote privacy by making its programs and services more modern, easier to use, and more responsive to the needs of Canadians.
- For example, we have launched a digital service optimization project to improve the usability and effectiveness of our online information request and complaints intake services.
- In addition to improving the client experience, this project is expected to deliver internal process efficiencies and enhance our ability to improve our other services to Canadians.
Background
- There are 11 services to Canadians the OPC reports on, including: Responses to requests for information from Parliamentarians; Contributions Program of the OPC; Breach reports under the PIPEDA; and Privacy Impact Assessment (PIA) Reviews.
- We recently added a new service that will be reported upon in future years: accept privacy codes of practice from Canadian organizations.
- Our initial research is showing that the current online complaint form is resulting in a rate of 43% of complaints being submitted to the OPC that fall outside of our jurisdiction or cannot be investigated and that it is difficult for persons with disabilities to use.
- We have launched a project that will optimize this critical service towards making it easier to use and improve the likelihood that we receive complaints that fall within our jurisdiction.
- We will use the lesson learned in this project to build our capacity to apply modern digital techniques to improve all of our services.
LEAD: Corporate
OPC adoption of Artificial Intelligence
Speaking Points
- In October 2024, my Office launched an internal AI strategy to demonstrate a privacy-first AI implementation within the Government of Canada, build practical AI expertise across the Office, and help staff improve efficiency through responsible AI use.
- My Office has invested in secure, high-performance internal AI servers. We aim to share our experience with other government departments to promote privacy by design principles and meeting policy and legal obligations.
- The first version of our internal AI service — focused on low-risk use cases such as summarization of public documents that do not include personal information — was rolled out in Q4 of 2025, with plans to expand to additional use cases later this year.
- This initiative supports OPC’s second strategic priority, which addresses the privacy impacts of rapid technological advancements, especially in AI.
Background
- Employees of the OPC are instructed not to use third-party AI services for work-related tasks or on OPC devices, except when evaluating them as part of an investigation or when their use follows guidance from our Chief Information Officer and Chief Security Officer and aligns with our acceptable use and AI-assisted technologies policies and guidelines.
- OPC’s first version of internal AI is not trained on internal data, does not collect any personal information, nor deliver research capabilities and automated decision making, and does not provide any external services to Canadians.
- A “privacy by design” approach was used in delivering the solution, including conducting a Privacy Impact Assessment (PIA). Updates to the PIA will be performed to ensure that risks are identified and adequately managed as we add functionality.
LEAD: Corporate
Advisory Services: Statistics and Trends
Speaking Points
- My Office provides advice and recommendations on privacy-impactful initiatives through advisory consultations to businesses and federal institutions. We also review federal institutions’ Privacy Impact Assessments (PIAs) as well as government policies, directives and standards developed by TBS.
- Following the OPC’s recent transformation, we are placing a greater emphasis on the provision of expedited privacy advice on priority issues, such as AI and children’s privacy.
- This past year, we received 181 PIA submissions, a 27% increase over the previous year, and engaged in 60 consultations involving 29 institutions, which focused on areas such as the use of AI, return to office monitoring and the use of open-source intelligence.
- We engaged in advisory consultations with 27 businesses, 60% of which related to the use of AI.
Background
- In the last year we received 595 notifications of disclosure of personal information under section 8(2)(m) of the Privacy Act, a decrease of about 10 percent.
- The OPC provided advice on several TBS guidance documents, including Privacy in Contracting, the Directive on Security Screening and the Guide of Responsible De- Identification.
- The OPC also meets regularly with larger federal institutions to assist them in building in privacy up front, before the launch of new or amended initiatives.
- In keeping with the aims of the OPC’s transformation, we have moved towards the provision of advice to businesses in an expedited manner, similar to that by which we provide advice to federal institutions.
- This frees up resources for the OPC to address, and resolve identified serious privacy concerns through proactive engagements with businesses (and federal institutions) without the need for a full formal investigation.
LEAD: Compliance
Privacy Breach: Statistics and Trends
Speaking Points
- In the 2025-2026 fiscal, the OPC received breach reports affecting approximately 20 million Canadian accounts for both acts in total.
- In the private sector, the main breach cause was unauthorized access, whether internally as a result of snooping or externally by threat actors.
- While the number of breach reports submitted to the OPC under PIPEDA has remained stable over the past years, breaches reported under the Privacy Act for the public sector have decreased by 27% compared to the 2024/25 fiscal year.
- The vast majority of public sector breaches and over half of private sector breaches reported to the OPC last year created a real risk of significant harm to those whose personal information was captured.
Background
|
Breaches reported to the OPC |
||||
|
Fiscal YR |
PIPEDA |
PA |
Total |
% RROSH |
|
2025-26 |
696 |
451 |
1,147 |
75% |
|
2024-25 |
686 |
613 |
1,299 |
72% |
|
2023-24 |
693 |
561 |
1,254 |
65% |
|
Total |
1,545 |
1,318 |
2,863 |
69% |
|
Breach Cause |
Number of Canadian Accounts Affected by Breach Cause |
||
|
PA |
PIPEDA |
Total |
|
|
Loss |
563 |
6,127 |
6,690 |
|
Theft |
1,204 |
16,327 |
17,531 |
|
Other |
- |
492 |
492 |
|
Unauthorized access |
28,309 |
20,235,305 |
20,263,614 |
|
Unauthorized Disclosure |
18,083 |
70,244 |
88,327 |
|
Total |
48,159 |
20,328,495 |
20,376,654 |
LEAD: Compliance
Complaints: Statistics and Trends
Speaking Points
- A core function of my office is to receive and investigate complaints about the personal information-handling practices of federal government institutions and private sector businesses.
- In 2025-2026, we received a significant increase of complaints under both the Privacy Act and PIPEDA: there were more than double in the private sector and almost double in the private sector, representing an 82% increase in complaints received overall compared to the previous year.
- Under the Privacy Act, the OPC accepted 1444 time-limit complaints in 2025-2026, an increase of 121% compared to the previous fiscal year, when the OPC accepted 653 time-limit complaints.
Background
- Complaints received and accepted over the past two years:
|
|
Privacy Act |
PIPEDA |
Total |
|||
|
FY |
Received |
Accepted |
Received |
Accepted |
Received |
Accepted |
|
2025-26 |
3,146 |
2,172 |
3,044 |
920 |
6,190 |
3,092 |
|
2024-25 |
1,950 |
1,279 |
1,467 |
446 |
3,417 |
1,725 |
|
2023-24 |
1,749 |
1,113 |
1,108 |
446 |
2,857 |
1,559 |
- We have seen a significant increase in complaints this year, especially under PIPEDA with a 109% increase compared to the previous year. Under the Privacy Act it represented approximately a 61% increase.
- The OPC received 454 complaints in 2025-26 through the 2022 extension order that enabled foreign nationals located outside Canada to access personal information held by federal institutions, a 165% increase compared to 2024-25 (171).
- We accept significantly fewer PIPEDA than PA complaints. A complaint may not be accepted for various reasons, including when it is outside OPC jurisdiction. We also often have to redirect complainants to contact the organization’s privacy officer first.
- Under PIPEDA, the OPC has greater discretion whether to investigate or not; many complaints received fall within provincial jurisdiction (e.g., health data).
LEAD: Compliance
Investigations under Privacy Act (general)
Speaking Points
- Pursuant to subsection 29(1) of the Privacy Act, I receive and investigate complaints from individuals who may have been denied the right to access and correct their personal information, or who allege that personal information has been collected, used, retained, or disclosed in contravention of the Act.
- I may also choose to initiate a complaint, under subsection 29(3), when I am satisfied that there are reasonable grounds to investigate.
- I can also decide, at my discretion, to carry out investigations under subsection 37(1) against a federal institution or organization covered by the Act.
- In 2025-2026, my Office concluded 1,661 investigations under the Privacy Act, 58% of which were related to delays in responding to access to personal information requests.
- Section 63 prevents me from discussing or disclosing the details of ongoing investigations.
Background
- Under section 63 of the Privacy Act, the Privacy Commissioner and every person acting on behalf or under the direction of the Commissioner shall not disclose any information that comes to their knowledge in the performance of their duties and functions under this Act.
- At the end of 2025-2026, we had 905 active investigations under the Privacy Act.
- 50% of all investigations closed in 2025-2026 were resolved without issuing a finding.
LEAD: Compliance
Investigations under PIPEDA (general)
Speaking Points
- Pursuant to s. 12(1) of PIPEDA, I investigate complaints filed by individuals against organizations engaged in commercial activity. If there are reasonable grounds to investigate a matter under the Act, I can also initiate a complaint under s. 11(2) of PIPEDA.
- In 2025-2026, my Office concluded 672 investigations under PIPEDA, 50% of which were related to the use and disclosure of personal information.
Background
- Where investigations are ongoing, due to confidentiality obligations, the OPC cannot provide further details.
- At the end of 2025-2026, we had 540 active investigations under PIPEDA.
- 45% of all investigations closed in 2025-2026 were resolved without issuing a finding.
LEAD: Compliance
Enforcement collaboration
Speaking Points
- In the digital economy, protecting privacy against global risks is a common goal amongst Data Protection Authorities. Collaboration allows regulators to expand their capacity and amplify their impact.
- My Office is a leader in enforcement collaboration, chairing or co-chairing for the International Enforcement Cooperation Working Group (IEWG) of the Global Privacy Assembly (GPA), the Domestic Enforcement Collaboration Forum (DECF) and the Global Privacy Enforcement Network (GPEN). My Office also conducts joint investigations with provincial counterparts where appropriate.
- On March 25, 2026, we released the findings of the most recent GPEN sweep of children’s privacy on websites and apps which my Office coordinated with international partners.
- On February 23, 2026, my Office issued a Joint Statement, with 60 other global privacy authorities, on AI content generation systems. The statement outlines fundamental privacy principles to guide organizations that are developing and using these systems protect individuals, including children, from potential harm caused by the creation of non-consensual content, including intimate imagery.
Background
- DECF: Facilitates info sharing and collaborative enforcement with substantially similar provincial data protection authorities.
- GPA: The IEWG has undertaken several joint activities towards enhancing global privacy compliance such as Credential Stuffing guidance and the joint statements on data scraping and AI-generated non-consensual imagery.
- GPEN Sweep: We led this year’s Sweep with the UK and Guernsey. Overall, the 27 participating authorities observed good practices. However, there were some concerns regarding collection and sharing of more personal information and age assurance mechanisms that could be easily circumvented and therefore expose children to inappropriate content.
Compliance backlog
Speaking Points
- We received 82% more complaints in 2025-26 over the previous year.
- My Office received temporary funding in Budget 2023 to improve its response rates to privacy complaints and breach reports.
- As of the end of March 2026:
- of the approximate 1500 complaints to be processed, more than half (865) exceeded our service standard of 28 days. This is largely due to the increase in complaints received in the last year.
- the backlog of investigations active for over 12 months represented only 4% (53) of ongoing files – a decrease from 2024-25, when it was at 9% (66) and 2023-24 when it was 20%.
- My Office was able to assess and close 78% of breach reports within our new service standard of 6 months, which is an improvement compared to fiscal year 2024-25 (66%).
- Given that we continue to receive high volume of complex complaints and breaches, we continue to innovate to improve efficiencies, such as improving our online complaint form, and reviewing internal processes.
Background
- Overall, we have received 12% fewer breach reports under both acts; however, a similar number of Canadian accounts were affected (just over 20 million).
- Without additional permanent funding and legislative changes to provide more discretion to decline to investigate complaints and improve breach reporting, the backlog is at risk of increasing.
- My Office concluded 2,333 investigations under both acts this year, almost three quarters of which (71%) were in the public sector. Although this represents a significant increase over last year (1755), we accepted 3092 complaints in 2025-26. The gap of 759 between complaints accepted and complaints closed highlights that the volume of complaints continues to outpace OPC’s capacity.
- Of the 865 backlogged Intake files, 23% (200) are PA and 73% (665) are PIPEDA.
Expedited Breach Report Resolutions
Speaking Points
- As part of our transformation, the OPC is increasing its focus on alternative approaches to address emerging privacy issues more rapidly and effectively, to the benefit of Canadians, organizations and the OPC.
- My Office has been addressing breach-related issues through early engagements with organizations to be satisfied that they have implemented or will implement measures to adequately mitigate the risk of a future breach and the risk to affected individuals, expeditiously.
- This new approach can result in a mediated voluntary agreement, such as a Compliance Letter. The OPC has concluded two such agreements to date, with PowerSchool and Nova Scotia Power, organizations that experienced serious privacy breaches impacting a large number of Canadians.
- These letters serve to obtain commitments to implement significant safeguard improvements and other privacy-protective measures, without the need for a full resource-intensive investigation. This approach allows the OPC to focus our resource on in-depth investigations that are more complex and systemic matters that cannot be resolved voluntarily.
Background
- The Privacy Commissioner is empowered to resolve complaints by dispute resolution pursuant to subsection 12.1(2) of PIPEDA.
- On July 15, 2025, PowerSchool signed a “Letter of Commitment”.
- On March 18, 2026, Nova Scotia Power signed a “Compliance Letter”, which is essentially the same document as the “Letter of Commitment” signed by PowerSchool but with a different title to be used moving forward.
- The OPC intends to increasingly leverage Compliance Letters where appropriate to address breach-related issues and expect to conclude more similar agreements in the coming months.
Proactive Engagement and Advice
Speaking Points
- As part of our transformation, launched in January 2025, my Office is increasing its focus on compliance engagements with organizations to address emerging privacy issues proactively, without the need for a formal investigation where appropriate.
- Through this proactive compliance approach, my Office engages with organizations to better understand their practices as they relate to emerging privacy issues.
- We provide advice with a view to assisting organizations in complying with the privacy laws I oversee, and follow up as appropriate to ensure compliance.
- Over the last year we have engaged informally with 14 organizations regarding new initiatives and novel practices with significant privacy considerations, some of which will be highlighted in my upcoming annual report, due to be tabled in early June.
- In these cases, where we identify potential privacy concerns, we provide advice to assist companies in complying with PIPEDA with the aim of supporting responsible privacy-protective innovation.
Background
- We have had several ongoing proactive compliance engagements in recent months on various initiatives, including innovative private sector projects related to autonomous vehicles and smart glasses, that had significant potential privacy implications.
- Proactive compliance engagements focus mainly on the private sector, given that for the public sector the OPC already engages extensively with federal institutions through review of Privacy Impact Assessments and associated consultations.
LEAD: Compliance
Outreach to Businesses and Federal Institutions
Speaking Points
- In the 2025-26 fiscal year, my Office held 43 outreach engagements with federal institutions and businesses with a view to promoting compliance with privacy responsibilities and best practices under the Privacy Act and PIPEDA.
- The OPC leveraged partnerships to maximize impact of these sessions and reach a broader audience more efficiently. This included extensive collaborative work with institutions including TBS, with private sector networks as well as provincial regulators.
- The OPC is increasingly leveraging virtual tools to reach business and federal employees across the country.
- Last year, the OPC’s outreach activities focused on key issues like responsible AI implementation, privacy in Human Resources, and breach prevention and response.
Background
- OPC outreach conducted by the advisory teams included 20 public sector events reaching 3,677 public servants, and 23 private sector events reaching 1,274 business owners and employees.
- These included events developed in close collaboration with TBS on the responsible use of Artificial Intelligence in the government context, and on HR and Privacy.
- For the private sector, we conducted in-person outreach in collaboration with privacy regulators in Nova Scotia and PEI and conducted several virtual engagements with business networks in Atlantic Canada and Western Canada.
- Outreach is structured in a manner where we can engage with a large number of businesses efficiently, with a smaller investment of our resources.
LEAD: Compliance
Technology Analysis Division: Activities, Statistics and Trends
Speaking Points
- Addressing the privacy impacts of technological advancements is one of my office’s strategic priorities. In support of this, my office studies different technologies to assess their potential privacy implications.
- OPC has a team of IT analysts who use their extensive technological expertise to examine malware, hardware components, mobile applications, enterprise systems and Internet-of-things devices with a view to promoting privacy through the safe and secure use of digital technologies by Canadians.
- This work takes place in our technology analysis lab, which also supports compliance investigations and research related to emerging technologies, including artificial intelligence, biometrics, and privacy-enhancing technologies.
- The Technology Analysis Division (TA) plays a key role in strengthening the OPC’s impact by building strategic partnerships, supporting international and FPT data protection authorities in developing technological expertise, and embedding technology foresight into organisational decision making.
Background
- TA currently employs nine employees, most with an educational and professional background related to computer science.
- This group has expertise related to digital forensics, incident response, penetration testing, software and hardware reverse engineering, and artificial intelligence to name a few.
- This past fiscal year, TA provided support for 60 compliance investigations and 37 promotion engagements.
- In addition to supporting activities related to the core mandate of the OPC, TA continues to support various internal IM/IT functions related to cyber security, such as conducting ad-hoc security assessments of various OPC systems.
LEAD: Corporate
Communications: Key activities, statistics, and trends
Speaking Points
- Pursuant to my mandate to protect and promote privacy as a fundamental right, my Office continues to deliver communications on a range of privacy issues, including youth privacy, major investigations, and domestic and international efforts to address the privacy impacts of new technologies.
- In the last fiscal year, major announcements including the release of investigative findings into TikTok, 23andMe, and Google drew significant attention from the public, the media, Parliament, and other stakeholders. So, too, has the release this week of investigative findings into the Canada Revenue Agency and OpenAI.
- This division is also responsible for developing and updating guidance for individuals to help them better understand their privacy rights and take actions to protect their privacy. Last year, for example, the OPC published “Your privacy and AI chatbots” to help individuals use the technology in a privacy-protective way.
- Under the theme “Prioritize privacy by design,” my Office marked Data Privacy Week in January with a social media campaign and video message.
Background
- Key communications statistics from 2025-2026 include:
- 60 news releases, statements, and media advisories
- 213 media requests
- 112 speaking engagements, events, conferences, meetings and exhibits
- 206 posts on X and 362 posts on LinkedIn
- 2.7 million unique visits to the website
- Work undertaken in 2025-2026 to better understand and address shifts in the information and communications landscape included public opinion research (Canadian businesses), the completion of a communication and stakeholder engagement strategy and a misinformation and disinformation strategy.
- The OPC also conducted a pilot project aimed at learning how to optimize the OPC website to improve visibility and accuracy of AI searches and answers.
LEAD: Communications
International relations: Statistics and trends
Speaking Points
- It is difficult to compare the powers and authorities of the OPC to other data protection authorities globally given the scope of mandates and enforcement powers vary widely, and that privacy legislation is at different levels of maturity worldwide.
- That said, unlike other regulators, I do not have the power to issue binding orders or impose administrative monetary penalties for privacy violations. These powers would increase the OPC’s effectiveness in ensuring compliance with federal privacy law.
- Mandatory privacy breach reporting is the international standard. The Privacy Act contains no such requirement for the public sector.
- Modernizing Canada’s privacy laws would help to ensure that the privacy rights of Canadians are protected in today’s digital, data-driven world, and support businesses and government institutions in ensuring that they have appropriate protections to operate successfully.
- Canada is amongst the 16 countries that have been determined as achieving ‘adequacy’ under the GDPR, allowing for transfers of personal information to easily flow between the EU and Canada. This advances economic goals and fuels innovation, while fostering trust that personal information is being protected at an adequate level outside our borders.
Background
- The last Global Privacy Assembly (GPA) census was conducted in 2023:
- 74% of DPAs can impose fines or penalties for privacy violations.
- 90% of DPAs have the power to investigate and sanction civil/administrative breaches.
- 63% of DPAs have a mechanism for cooperation with regulatory authorities.
- 87% of DPAs have mandatory breach-notification requirements.
- IAPP Global Privacy Law and DPA Directory (February 2026):
- 179 of 240 jurisdictions have data protection frameworks, covering 80% of the world’s population. Most populous countries without comprehensive data protection laws: Democratic Republic of Congo, U.S., Bangladesh, Pakistan.
International relations: Key activities
Speaking Points
- Domestic and international collaboration and cooperation amongst regulators, public institutions, industry, and civil society is essential to addressing global privacy challenges.
- On June 17, 2025, I concluded a joint investigation with the UK Information Commissioner on 23andMe, a direct-to-consumer genetic testing company. Results found that the company had failed to implement adequate security measures to protect the personal information of 7 million customers, including nearly 320,000 Canadians.
- From June 18-19, 2025, I hosted the G7 Data Protection and Privacy Authorities Roundtable in the context of Canada’s G7 presidency. The table issued a joint statement on promoting responsible innovation and protecting children by prioritizing privacy.
- In September 2025, at the 47th Annual Meeting of the Global Privacy Assembly, I was honoured to be elected Chair for a two-year term. As Chair, my vision centres around collaboration under three themes: Addressing the privacy impacts of technology; Youth privacy, and Continuing progress towards strong economies and a high level of data protection in global frameworks.
- In February 2026 as Co-Chair of the GPA International Enforcement Working Group, I signed with 60 signatories the joint statement on AI-generated imagery and the protection of privacy.
Background
- Participation in international for a with government participation: (1) Global Cross Border Privacy Rules Forum; (2) OECD Working Party on Data Governance and Privacy in the Digital Economy; and (3) European Commission Group of Countries with a Favorable Adequacy Decision.
- Memoranda of Understanding: OPC has signed 21 MOUs so far, including with international and domestic partners. The most recent are with the UK ICO (October 2025), Japan PPC (December 2025) and France CNIL (December 2025).
Parliamentary Affairs: Activities, statistics, and trends
Speaking Points
- As an Agent of Parliament, I am frequently called upon to provide advice and recommendations to committees in both Chambers, through appearances or submissions.
- Between April 1, 2025, and March 31, 2026, my office:
- appeared nine times before various Parliamentary committees,
- monitored and reviewed 17 bills and studies; and,
- responded to 14 inquiries from Parliamentarians.
- Since taking Office, I have appeared 27 times on Bills and Studies in both Chambers. Over a third of my appearances are before this Committee.
Background
- In 2025-26, you had the following key appearances on bills:
- October 2, 2025 on S-209 (Protecting Young Persons from Exposure to Pornography Act) at LCJC;
- October 30, 2025 on C-8 (An Act respecting Cybersecurity) at SECU;
- November 20, 2025 and February 12, 2026 on C-12 (Strengthening Canada’s Immigration System and Borders Act) at SECU and SECD respectively;
- December 4, 2024 and January 26, 2026 on C-15 (Budget 2025 Implementation Act, No. 1) at BANC and INDU respectively;
- February 12, 2026 on C-4 (Making Life More Affordable for Canadians Act) at LCJC.
- We anticipate being occupied with a range of initiatives and priorities in this session, including continued monitoring of progress on the following bills:
- C-8 (An Act respecting Cybersecurity)
- C-22 (Lawful Access Act, 2026)
- C-25 (Strong and Free Elections Act)
LEAD: PRPA
Contributions program
Speaking Points
- My office’s Contributions Program provides up to $500,000 a year for research and public education initiatives on a range of privacy issues related to PIPEDA.
- These independent projects generate new ideas, approaches and knowledge to help organizations better safeguard personal information and help Canadians make more informed decisions about how to protect their privacy.
- Each year’s call for applications focuses on a theme aligned with my Office’s priorities. This year’s theme aims to increase knowledge and awareness of privacy protection while online gaming.
- Gaming is an integral part of the entertainment landscape with nearly half of Canadian adults and 70% of Canadian teens regularly playing games online.
Background
- Established in 2004, the contributions program has funded a total of 216 projects.
- The program has funded a diverse range of projects, most recently including from the Automobile Protection Association (on privacy permissions of connected vehicles); the Toronto Metropolitan University (on privacy risks Canadian youth face when using generative AI tools); and the University of Western Ontario (on deceptive design practices).
- Last year’s theme was focused on increasing knowledge and awareness with respect to smart devices, and how they collect, share, and use personal data. We are currently evaluating final deliverables and summaries will soon be published on the OPC’s website.
- All projects must relate to PIPEDA since the program was established under that Act. Only not-for-profit organizations are eligible for funding.
- In 2025, the program’s Terms and Conditions were renewed for five years by the Minister of Justice (until March 31, 2030).
- The full list of funded projects is published on the OPC website, along with summaries of completed projects from previous years.
LEAD: PRPA
Guidance development
Speaking Points
- The guidance my Office provides is fundamental to its role in effectively promoting compliance with the law and in helping individuals understand and exercise their privacy rights.
- In today’s data-driven economy, my Office is seeing an increased need from organizations for guidance on how to comply with their privacy obligations. I expect this trend to further accelerate as the Government introduces measures to modernize Canada’s privacy laws.
- To better meet the needs of organizations, my Office recently held a consultation on its guidance development process. Submissions were received from a variety of stakeholders. I look forward to sharing the results of the consultation once we have finished analyzing submissions.
- My Office would welcome parallel guidance responsibilities with respect to public sector organizations under a reformed Privacy Act.
Background
- Section 24 of PIPEDA requires the Commissioner to develop and conduct information programs to foster public understanding of the purposes of the Act, undertake and publish research related to the protection of personal information, encourage organizations to develop policies and practices to comply with the Act, and promote the purposes of the Act by any means they consider appropriate.
- On April 2, 2026, TBS released a public consultation paper, 2026 Review of the Privacy Act: Policy Approaches. The paper does not propose an explicit research or education mandate for the OPC as we have previously recommended.
- From December 2025 to March 2026, the OPC ran a consultation on its guidance processes, seeking input from stakeholders about the presentation, content, and utility of our guidance, as well as how the OPC carries out guidance consultations. 17 submissions were received from organizations and individuals, representing perspectives across a wide range of industries and sectors, including banking, telecommunications, advertising, law, insurance, privacy professionals and health care.
LEAD: PRPA
OPC work on AI
Speaking Points
- One of my strategic priorities focuses on bolstering the OPC’s ability to address the privacy impacts of the fast-moving pace of technological advancements, especially in the world of AI and generative AI.
- We have taken significant steps towards enhancing our understanding of, and establishing expectations for, AI systems, often in collaboration with key partners.
- For example, we have drafted principles for responsible, trustworthy and privacy-protective generative AI technologies with our provincial and territorial counterparts; led on a resolution that establishes a common understanding of “meaningful human oversight” of AI-based decisions through the Global Privacy Assembly; and worked with our G7 partners on statements related to Children and AI and the role of data protection authorities in promoting responsible AI.
- We are also finding ways to stay on top of the latest research in this field, including by funding multiple AI-related projects through our contributions program during the 2024-2025 funding cycle.
- Finally, we are seeking to better understand AI by exploring how it can be integrated into our own work, including with our own internal LLM.
Background
- Funded Contributions Program projects include:
- Generative AI, Privacy Policy and Young Canadians (Toronto Metropolitan University)
- Benchmarking Large Language Models and Privacy Protection (University of Ottawa)
- The Machine-Readable Child: Governance of Emotional AI Used with Canadian Children (Internet of Things Privacy Forum)
- Relevant G7 Statements: 2024: Statement on the Role of Data Protection Authorities in Fostering Trustworthy AI; Statement on AI and Children. 2023: Statement on Generative AI.
LEAD: PRPA
OPC Review of Codes of Practice
Speaking Points
- As of March 4, 2025, reporting entities under the Proceeds of Crime (Money Laundering) & Terrorist Financing Act (PCMLTFA) can submit codes of practice for sharing personal information amongst themselves, without individuals’ consent, for my review and approval. I fully support this initiative, which seeks to combat serious financial crimes.
- To date, my Office has received 7 codes for review, significantly more than what was estimated in the associated Regulatory Impact Analysis Statement, which was 3 in the first 10 years.
- I am pleased to report that my Office approved the first code on December 19, 2025. We are currently reviewing 3 further submissions.
- We have appreciated FINTRAC’s close collaboration on this important file, including exchanges on FINTRAC’s Model Code and guidance, which serve as useful resources for entities wishing to develop a code.
- My Office is finalizing its own guidance on submitting codes under the PCMLTFA regulations and will be publishing it soon.
- The OPC did not receive any additional funding and has had to reallocate internal resources for this new activity.
Background
- Section 11.01 of the PCMLTFA allows for the disclosure, collection, and use of personal information without consent, provided the disclosure is made in accordance with the regulations.
- Under the regulations, reporting entities can develop a code of practice and submit it to the Commissioner for approval. The code must, among other things, provide for the substantially same or greater protection than PIPEDA.
- Participants in a code are protected from criminal and civil proceedings if they disclose, collect, or use personal information pursuant to a code in good faith.
- The OPC has 120 days (with a potential 15-day extension) to approve a code of practice. If there is no decision in that period, a code is deemed approved. Codes are to be reviewed every 5 years or when there is a significant change.
Special Report: ArriveCAN
Speaking Points
- On March 12, 2026, my Office tabled a Special Report in Parliament regarding an investigation into the Canada Border Services Agency (CBSA)’s contracting practices related to the development of the ArriveCAN app.
- The investigation assessed the CBSA’s compliance with the Privacy Act by examining the measures it took to mitigate privacy risks associated with the use of contracted resources.
- My investigation found no evidence to suggest that personal information collected through the app was used or disclosed in contravention of the Act.
- While no contraventions were found, the investigation identified certain shortcomings in procurement practices that could have an impact on privacy. My Office made four recommendations to address these shortcomings, which the CBSA accepted.
Background
- The investigation was launched in March 2024 following receipt of a complaint.
- The investigation also took into consideration the issues raised in the motion tabled by the House of Commons Standing Committee on Government Operations and Estimates (OGGO) on May 6, 2024.
- Specifically, OGGO requested that the OPC investigate the work of all contractors and subcontractors who worked on ArriveCAN to determine whether the privacy and personal information of Canadians was adequately protected.
- The OPC recommended that the CBSA: i) ensure that security requirements are rigorously and accurately assessed and completed within a reasonable time prior to contract award; ii) ensure that Task Authorization descriptions clearly and accurately define the projects or work to be performed to ensure that privacy and security requirements specific to those tasks or projects are accurately identified and assessed; iii) proactively manage security clearances and renewal processes with rigour and strong oversight; and iv) restrict permissions and access to personal information to what is strictly necessary.
Special Report: Canada Revenue Agency
Speaking Points
- On October 29, 2024, I received a complaint and subsequently launched an investigation related to a specific type of breaches at the CRA. The breaches involved the unauthorized use and modification of taxpayers’ information by a third party (UUTP).
- The investigation was recently completed with the report tabled just this morning. We found that the CRA contravened the accuracy and disclosure provisions of the Privacy Act.
- Overall, the investigation report notes that the CRA has made important enhancements to its security posture since 2020. However, we found shortcomings in relation to the CRA’s breach response to UUTPs.
- I made 9 recommendations to address these shortcomings, including in the areas of governance, tracking and the implementation of multi-factor authentication.
- The CRA accepted 8 recommendations in full, and one partially. My office will monitor the CRA’s implementation of these recommendations. We consider the matter conditionally resolved.
- The CRA was cooperative and collaborative during this complex investigation. I appreciate their commitment to address this issue.
Background
- The CRA reported over 42,000 individual UUTP breaches, confirmed since 2020.
- The investigation took a systemic approach. We considered prevention, monitoring and detection, containment, mitigation, remediation and governance.
- This most recent investigation considered all potential attack vectors that may compromise taxpayers’ accounts. The previous investigation for which a Special Report was tabled in Parliament in February 2024, focused more specifically on credential stuffing, a technique where a bad actor uses stolen credentials from previous attacks.
LEAD: Compliance
Key Investigation: GrokAI
Speaking Points
- In February 2025, after receiving a complaint, my Office initiated an investigation into X Corp., the operator of the social media platform X, regarding its collection, use, and disclosure of Canadians’ personal information to train AI models, including Grok.
- In January 2026, following multiple media reports that the AI chatbot Grok was being used to create and share explicit images of individuals without their consent, my Office expanded its current investigation into X Corp. and launched a related investigation into xAI, the AI company responsible for Grok.
- The investigations are considering whether X Corp. and xAI collected, used, and disclosed personal information via Grok to create sexualized deepfakes in contravention of PIPEDA.
- This includes examining whether the organizations’ practices were appropriate and whether the organizations obtained valid consent from the depicted individuals.
- I am unable to elaborate further given that the investigations are ongoing.
Background
- In January 2026, Ofcom, the UK’s media regulator, initiated a formal investigation into X under the Online Safety Act over the use of Grok AI to manipulate images. The UK ICO has also sought clarification from X and xAI regarding compliance.
- Australian online safety regulator, the eSafety Commissioner, is investigating this matter. Malaysia and Indonesia have blocked access to Grok.
- To address this issue, both X Corp. and xAI announced, in January 2026, that they have implemented measures to limit the creation of explicit content.
- However, recent media reports indicate that the issue is still ongoing.
LEAD: Compliance
Key Investigation: TikTok
Speaking Points
- My Office, along with my counterparts in Quebec, British Columbia and Alberta, published our joint report of findings for our investigation into TikTok on September 23, 2025.
- Our investigation found serious deficiencies in TikTok’s age assurance mechanisms, which allowed hundreds of thousands of Canadian children under the age of 13 to access TikTok each year, contrary to its own terms.
- We also found that TikTok failed to obtain meaningful consent from adults and teens for its collection and use of user data, including sensitive data of younger users such as biometric data.
- I am pleased that TikTok committed to improve its age assurance measures to keep children off its platform and to enhance its privacy communications to ensure meaningful consent was obtained.
- My Office is currently monitoring TikTok’s implementation of our recommendations. This is proceeding well given their collaboration in the process.
Background
- The investigation was launched in February 2023 in the wake of now-settled class-action lawsuits in the United States and Canada, and numerous media reports related to TikTok’s collection, use and disclosure of user data.
- The investigation examined whether TikTok was collecting children’s personal information for an appropriate purpose.
- The entity under investigation was TikTok Pte Ltd. (Singapore-based company), which is the business entity responsible for Canadians’ personal information and TikTok’s privacy practices in relation to that information.
- One of our recommendations to TikTok was that the organization enhance its privacy communication to support meaningful consent to include, without limitation, notice that Canadian users’ personal information may be transferred to China and accessed by the Chinese government.
LEAD: Compliance
Key Investigation: ChatGPT
Speaking Points
- Yesterday, along with my counterparts from Quebec, British Columbia, and Alberta, I announced the conclusions of a joint investigation into the practices of OpenAI in relation to its ChatGPT service.
- Our investigation revealed that a number of privacy issues were present in the initial development and deployment of ChatGPT.
- Some of these issues included the overcollection of personal information for model training; lack of valid consent and transparency; factual inaccuracies involving personal information; issues related to individuals’ ability to access, correct and delete their personal information; and a lack of accountability with respect to personal information.
- Throughout the course of the investigation and in response to our findings and recommendations, OpenAI was collaborative. They have already implemented measures to improve protections for personal information in the ongoing development and delivery of ChatGPT, in particular by significantly limiting the personal information used to train its AI models.
- It is important that AI and other related emerging technologies be developed and deployed in a responsible, privacy-protective manner. This is why my Office has made it a strategic priority to address and advocate for privacy in this time of technological change.
Background
- ChatGPT is an AI-powered chatbot that generates text based on users prompts. While it can also generate images, this function was outside the scope of this investigation.
- In April 2023, the OPC launched its own an investigation into ChatGPT after receiving a complaint. We closed this investigation in May 2023 to pursue a joint investigation with provincial counterparts. The investigation focused on earlier models (3.5-4) of the chatbot.
LEAD: Compliance
Key Investigation: WADA
Speaking Points
- In November 2024, I launched an investigation into the World Anti-Doping Agency (WADA) after receiving a complaint about its handling of biological samples collected from athletes.
- The complaint alleged that WADA disclosed personal information to international sporting federations to assess athletes’ sex-based eligibility without their knowledge or consent, and for a purpose that would not be considered appropriate under PIPEDA.
- WADA entered into a Compliance Agreement with the OPC, in which it committed to implementing reasonable steps to ensure that international sport federations and other anti-doping organizations do not use personal information collected from athletes and that is in WADA’s database for purposes other than those related to anti-doping.
- We expect WADA will fulfill the terms of the Compliance Agreement by January 1, 2027.
- As the investigation has been put into abeyance, I am limited as to what I can share at this time.
Background
- Based in Montreal, WADA is responsible for monitoring and fighting the use of drugs in sports.
- It became subject to PIPEDA in 2015 following international pressure for Canada to ensure that WADA’s vast holdings of sensitive personal information are subject to proper oversight.
- The OPC had previously launched an investigation into WADA in 2016 following a breach of its Anti-Doping Administration and Management System which resulted in the public disclosure of athlete’s personal information, including their health information.
- Following that investigation, the OPC entered into a compliance agreement with WADA to implement remedies to address the identified deficiencies in its safeguards.
LEAD: Compliance
Key Investigation: Nova Scotia Power
Speaking Points
- On May 1, 2025, Nova Scotia Power advised my Office that it had detected a cyber incident on their network.
- Shortly thereafter, my Office began engaging with Nova Scotia Power to ensure that the organization was implementing measures expeditiously to mitigate the risk of harm to affected individuals and the impact on Canadians.
- On March 18, 2026, Nova Scotia Power signed a Compliance Letter confirming that, in addition to measures already implemented to address the breach, it was committing to implementing further measures to ensure adequate privacy protections for Nova Scotia Power customers in the future. This letter was posted on the OPC website on March 25, 2026.
- My investigation will remain open until I am satisfied that the company has fulfilled all its commitments. As our review is ongoing, I cannot share further details at this time.
- I can confirm that the company notified all affected individuals and offered five-years of credit monitoring to all affected customers.
Background
- Nova Scotia Power determined that on or around March 19, 2025, a threat actor gained access to its networks and exfiltrated client personal information stored on its systems. The threat actor shared the exfiltrated data on the dark web.
- The company determined that approximately 900,000 current and former customers were affected by the breach.
- Breached personal information of current and former customers included names, phone numbers, email addresses, mailing addresses, dates of birth, customer account histories (including customer payment/billing/credit history/bank account numbers), driver’s license numbers, and social insurance numbers.
- The Nova Scotia Energy Board is investigating the breach.
LEAD: Compliance
Recent Litigation: Facebook (Meta)
Speaking Points
- In 2024, the Federal Court of Appeal issued an important decision about Facebook’s data practices, acknowledging that international data giants, whose business models rely on users’ personal information, must respect Canadian privacy law and protect individuals’ fundamental right to privacy.
- As my Office had done in its 2019 investigation, the Federal Court of Appeal concluded that the social media platform had breached the requirement to obtain meaningful consent from users and had failed to appropriately safeguard users’ personal information.
- The Supreme Court of Canada heard Facebook’s appeal of the Federal Court of Appeal’s decision on March 19, 2026, and has reserved its judgement on the matter.
Background
- In March 2018, the OPC received a complaint about Facebook arising from media reports that Cambridge Analytica had accessed the personal information of Facebook users without their consent via a third-party application.
- The OPC and the Office of the Information and Privacy Commissioner for British Columbia jointly investigated and found that Facebook had not obtained meaningful consent from its users before disclosing their personal information and that it had not implemented adequate safeguards.
- The OPC filed an application with the Federal Court under s. 15 of PIPEDA seeking, in particular, an order requiring Facebook to correct its practices to comply with PIPEDA, as Facebook did not agree to implement the OPC’s recommendations.
- On April 13, 2023, the Federal Court dismissed the Commissioner’s s. 15 application and the OPC appealed this decision to the Federal Court of Appeal.
- On September 9, 2024, the Federal Court of Appeal allowed the OPC’s appeal with costs and declared that Facebook’s practices between 2013-2015 breached PIPEDA.
- On June 12, 2025, the Supreme Court of Canada granted Facebook’s application seeking leave to appeal the judgement of the Federal Court of Appeal.
LEAD: Legal
Recent Litigation: Aylo (MindGeek)
Speaking Points
- In February 2025, my Office filed an application with the Federal Court pursuant to section 15 of PIPEDA seeking an order requiring Aylo (formerly MindGeek), the operator of Pornhub and other popular pornographic websites, to comply with Canadian privacy law. The litigation is ongoing.
- The application follows an investigation by my Office that found significant problems with Aylo’s privacy practices. The Report of Findings was issued in 2024.
- My Office is seeking an order that would require Aylo to implement clear and specific measures to ensure that meaningful consent is obtained directly from all individuals who appear in intimate images and videos that are uploaded to its websites.
- While Aylo changed some of its privacy practices and consent verification mechanisms during and after the investigation, my Office has stated in the application that the company’s practices continue to fail to ensure that meaningful consent is obtained from everyone involved.
Background
- In April 2020, the OPC received a complaint against Aylo stemming from its alleged failure to obtain consent from everyone depicted in intimate content posted on its various websites.
- The OPC investigation found that Aylo contravened PIPEDA by allowing intimate content to be shared on its websites without the direct knowledge or consent of everyone depicted. The OPC recommended that Aylo immediately stop the collection, use and disclosure of user-generated intimate images and videos until it had implemented measures to ensure compliance with PIPEDA.
- The OPC was previously in litigation with Aylo from 2023-2024. Aylo had sought an injunction from the Federal Court to prevent the OPC from releasing the report of findings of the investigation while its application for judicial review was ongoing. The Federal Court dismissed Aylo’s injunction request, and the Federal Court of Appeal unanimously dismissed Aylo’s appeal.
LEAD: Legal
Regulation of AI in Canada
Speaking Points
- Given the importance of personal information for the development and use of AI systems, privacy legislation is a central element of the regulation of AI in Canada.
- The Government’s vision for AI, as described in the recent Spring Economic Update, strongly suggests that this positioning of privacy legislation will continue in the National AI Strategy.
- Under Pillar 1 (Protecting Canadians and Safeguarding our Democracy), the Government states that “AI will only deliver on its promise if Canadians trust it”, and that such trust requires modern privacy laws.
- Regardless of whether AI regulation is ultimately accomplished through standalone legislation or a more sectoral approach, privacy law will serve as an important foundational element.
Background
- In the OPC’s submission to ISED’s consultation on a National AI Strategy, we emphasized:
- “Privacy is not a barrier to innovation—it is a driver of innovation. When privacy considerations are built into the design and use of AI technologies from the outset, not only can AI systems and their outputs become more robust, accurate and interpretable, but individuals’ confidence and trust in the AI ecosystem grows, thereby creating a virtuous cycle of economic and ethical success.”
- The 2025 G7 Data Protection and Privacy Authorities Roundtable Statement argued that “When individuals have confidence that their data is protected and used lawfully and responsibly, trust exists; where trust exists, innovation is embraced.”
Algorithmic Pricing
Speaking Points
- Algorithmic pricing refers to the use of automated tools to assign prices for products or services, often in real time, based on a set of inputs.
- While it has the potential to improve market efficiencies, algorithmic pricing can also lead to harms such as discrimination, anti-competitive behaviour, lack of algorithmic transparency and privacy concerns.
- While context-based algorithmic pricing is common in certain sectors, it is unclear to what extent algorithmic pricing based on individuals’ personal information is occurring in Canada.
- Algorithmic pricing is a cross-regulatory issue; in fact, the Competition Bureau ran a public consultation on the topic in summer 2025.
Background
- At the December 10, 2025, ETHI meeting, Leslie Church (Liberal) moved the following Motion, which was agreed to, though the study has not yet commenced:
That, pursuant to Standing Order 108(3)(h), the committee undertake a study of the use of AI in algorithmic pricing in Canada; that the committee hold a minimum of six meetings for this study; that the study explore the costs to Canadian consumers from these practices; that the committee hear from representatives of major digital retailers in Canada, including Ticketmaster, Air Canada and Amazon, as well as from experts on algorithmic discrimination and any other witnesses the committee deems necessary; that the committee report its findings and recommendations to the House; and that, pursuant to Standing Order 109, the committee request that the government table a comprehensive response to the report. - Examples of context-based algorithmic pricing include Uber’s “surge pricing” based on driver availability and airline ticket prices based on remaining seats/closeness to flight date.
- Examples of algorithmic pricing based on individuals’ personal information include modifying prices based on individual demographics, socioeconomic status and purchasing behaviour.
- The “What We Heard” report from the Competition Bureau’s public consultation noted that there were significant concerns raised about how algorithms might collect and use consumer data, with respondents mentioning the risk of consumer information being shared with data brokers, and questioning how consent is obtained online.
Age Assurance
Speaking Points
- Age assurance – in which one of many potential methods is used to determine an Internet user’s age – has been proposed as a way to prevent children from accessing harmful content, or to ensure they are directed to age-appropriate versions of websites or online services.
- The OPC takes the position that age assurance can be a legitimate approach to mitigating potential harms to children online, but that it must be developed and used in a privacy-protective way.
- Just this week my office released two guidance documents – one for the developers of age assurance systems, and one for the websites and online services that will use those systems – setting out recommendations and expectations for the protection of privacy.
- Age assurance is a tool that can advance an important goal – but it must not have undue impacts on the privacy rights of all Internet users.
Background
- In the OPC’s guidance for developers, we make six key recommendations:
- Minimize collection and avoid retention of personal information.
- Limit the information included in an age assurance result.
- Avoid secondary use or disclosure of personal information collected.
- Minimize, and do not keep or disclose, information generated during the process.
- Do not retain any information about the individual’s online activities and, where possible, design systems to ensure that such information cannot be collected.
- The age assurance process should not disadvantage any group.
- In the OPC’s guidance for websites and online services assessing whether and how to use age assurance, we set out a three-step process:
- Determine whether there is a need for age assurance.
- Determine the nature of age assurance to be used.
- Use age-assurance in a privacy-protective way.
- The OPC’s age assurance guidance documents were released on May 4, 2026, and we will be accepting comment on them until August 4.
LEAD: PRPA
Chinese Electric Vehicles
Speaking Points
- On April 16, 2026, I appeared before the House of Commons Standing Committee on Science and Research on their study of the Implications of the Canada-China Preliminary Joint Arrangement on Canada’s Electric Vehicle Sector.
- During my appearance, I noted that connected vehicles can raise important privacy considerations, as the vehicles collect and transmit large volumes of personal data, which could be transferred or stored in foreign jurisdictions without appropriate protection.
- The Committee showed interest in my law reform recommendations related to strengthening privacy protections when personal information leaves Canada, as well as other work undertaken by my office in this area.
- For example, this past year my office funded two independent research projects that explored data-collection practices and protection measures related to connected cars under the OPC’s Contributions Program.
Background
- The OPC Contributions Program received two projects at the end of March 2026.
- One examined the personal information that automakers require from Canadian customers to gain access to onboard features and connected applications (Automobile Protection Association).
- The other looked at processes that can enable data analytics on connected cars in a way that will protect consumer privacy (University of Windsor).
- The OPC has also formed a connected cars working group with regulators from Alberta, BC and Quebec given our common interest in pursuing work in this area.
- The working group is currently in the process of gathering information related to the collection, use and disclosure of personal information in the context of the connected cars ecosystem leveraging the findings from research conducted under the OPC’s Contributions Program.
Children’s Code
Speaking Points
- In the digital realm, children deserve to be free from deceptive practices and able to navigate online spaces securely. That is why championing children’s privacy rights is one of my key strategic priorities.
- To advance this priority, my Office ran an exploratory consultation on the development of a children’s privacy code, and heard from a wide range of stakeholders, including youth, on how a code can be developed to best protect children’s privacy rights. The results of the consultation were published earlier this week.
- My Office is currently drafting a code that will apply to businesses subject to PIPEDA and will promote compliance with privacy obligations and encourage best practices in this area.
- Given the increased risks to children and developments that have occurred internationally, the OPC believes that it is the right moment for Canadians and Canadian businesses to be able to benefit from a children’s privacy code that would expand on the OPC’s positions in this area and encourage alignment with other jurisdictions.
Background
- Many jurisdictions, including the United Kingdom, California and Ireland, have benefited from the development of guidance or the adoption of legislation that requires organizations to adapt their data practices to address the unique needs and best interests of children.
- Established codes of practice and special protections contained in legislation can empower children online to exercise their privacy rights and protect against potential harm.
- The OPC exploratory consultation for the children’s privacy code closed in August of 2025, and received 37 submissions, with one joint response representing the views of over 40 individuals and organizations. Responses came from a range of groups, including youth, industry, civil society, academia, policy think tanks, legal professionals, and individuals.
- Last year, the OPC focused on hearing directly from young people. These efforts included: launching the OPC Youth Council, holding a youth roundtable discussion on the children’s privacy code, co-hosting a two-day youth summit on the best interests of the child in the digital environment and conducting focus groups with children and teens.
Privacy Act priority recommendations
Speaking Points
- Over the years, my Office has made many recommendations to modernize the critically outdated Privacy Act.
- Most recently I have identified seven priority recommendations that would be the most impactful in enhancing privacy protections for Canadians:
- Collection Threshold: Create an explicit necessity and proportionality requirement for the collection of personal information.
- PIA Requirement: Require departments to conduct privacy impact assessments (PIA) in high-risk situations.
- Orders: Provide the Privacy Commissioner with the power to issue binding orders.
- Discretion to decline: Provide the Privacy Commissioner with discretion to discontinue or decline complaints.
- Safeguards: Adopt an explicit legal requirement to safeguard personal information.
- Breach Reporting: Create a legal requirement for reporting privacy breaches.
- Discretion to Report: Provide more discretion to the Privacy Commissioner to publicly report.
Background
- Beyond the seven priority recommendations, we have distilled our other previous recommendations for reform into a list of 11 additional more technical amendments.
- There have been engagements between the OPC and government officials on Privacy Act reform dating back to 2016. Of note are submissions the OPC made to ETHI in 2009 and 2016, and involvement in Justice Canada consultations (2019-2021).
- Most recently, on April 2, 2026, TBS published their proposals for Privacy Act modernization in a White Paper which we are currently analyzing. We will be responding formally to TBS’s proposals when that analysis is complete.
TBS Privacy Act Modernization White Paper
Speaking Points
- I am aware that, on April 2, 2026, TBS launched a review of the Privacy Act including the publication of a consultation paper on which they are seeking views.
- TBS has been actively engaging with my Office on Privacy Act modernization and has communicated its commitment to hearing my perspectives on its proposals in greater detail.
- My Office has made several submissions on enhancing the Privacy Act over the years, including to government and Parliament.
- I am encouraged to see that many of my Office’s suggestions are reflected in TBS’ proposals. That said, our analysis is at a preliminary stage and we look forward to further engaging with TBS as this work advances.
Background
- TBS’ consultation paper makes 23 proposals under 6 themes: 1) enabling integrated services 2) enhancing accountability and transparency 3) advancing safeguards across the spectrum of data sensitivity 4) modernizing the foundation for privacy and trust 5) Indigenous people’s access to, and protection of their data 6) updating the compliance framework.
- Specific proposals that generally align with previous OPC recommendations include: making PIAs a legal requirement; establishing transparency requirements for the use of AI and automated decision systems; making breach reporting a legal requirement; reinforcing safeguarding requirements in law; adding a legal necessity test for data collection; recognizing privacy as a fundamental right; incorporating privacy principles into the Act; defining core concepts such as privacy breaches, material breaches, anonymized data, publicly available personal information, etc.
- Of note are two proposals: 1) incorporating personal information requests and associated complaints into the Access to Information Act 2) Providing the Commissioner with the authority to require an institution to develop and publish a corrective action plan on the issuance of a report of findings.
LEAD: PRPA
PIPEDA priority recommendations
Speaking Points
- I have identified seven priority recommendations for PIPEDA reform that I believe would be the most impactful in enhancing privacy protections and privacy rights in Canada:
- Enforcement Powers: Provide the Privacy Commissioner with the power to issue binding orders, impose administrative monetary penalties and to conduct proactive audits.
- Fundamental Right to Privacy: Recognize privacy as a fundamental right in the purpose clause and embedded preamble.
- Children’s Privacy: Enhance children’s privacy rights by explicitly recognizing the best interests of the child and mandating the OPC to develop a code of practice for children’s privacy.
- De-identification: Promote innovation by including a framework for de-identification and anonymization.
- Right to Deletion and De-listing: Ensure individuals maintain control over their personal information by including a clear and explicit right to de-list and delete personal information.
- Privacy by Design and Privacy Impact Assessments (PIAs): Enhance accountability by requiring organizations to implement privacy by design, and conduct PIAs for high-risk activities.
- Trans-Border Data Flows: Institute rules and requirements to protect personal information moving outside of the country.
Background
- These priority recommendations would strengthen key regulatory powers and address systemic issues that we have observed, including emerging risks in the digital economy, and would bring PIPEDA more in line with other jurisdictions.
- Beyond the seven priority recommendations, we have identified twelve additional amendments that are intended to improve administrative timelines, processes, and powers that will allow the OPC to more effectively conduct investigations, address automated decision-making, and collaborate domestically.
- We have shared these recommendations with Innovation, Science and Economic Development Canada, and welcome the opportunity to work with them to update PIPEDA.
S-5: Connected Care for Canadians Act
Speaking points
- Last month, Deputy Commissioner Marc Chénier appeared before the Senate Standing Committee on Social Affairs, Science and Technology.
- He offered general support for Bill S-5 as it would help advance interoperability of health information systems in Canada, improving patient access and control over their personal health information.
- Increased access, use and exchange of personal health information in an interoperable health system could introduce risks to privacy.
- I am pleased that the interoperability requirement specifies that access, use and exchange of personal health information is not required where prohibited by privacy law. My deputy commissioner recommended that the data-blocking prohibition include a similar exception.
- As the Bill does not expressly mention privacy or security safeguards, I hope to see these elements addressed in regulations. My Office should be consulted on the regulations as they pertain to privacy and security.
Background
- Bill S-5 prohibits data-blocking (s. 6), which is defined as a practice or act that prevents, discourages or interferes with access to or the use or exchange of electronic health information. The Bill also requires health information technology (HIT) vendors to ensure that the HIT they license, sell or supply is interoperable, meaning that users can easily, completely, and securely access, use, and share electronic health information, unless privacy law prohibits it (ss. 5(2)(a)).
- The Connected Care for Canadians Act would only apply by order, partially or fully, in a province or territory, if the GIC is satisfied that the province or territory does not have requirements that are substantially similar to or exceed those in the Act (ss. 7(1)).
- Key details are left to regulations made by the GIC, including what practices or acts constitute data-blocking, the standards and specifications for interoperability, and the criteria and process for determining substantial similarity (s. 8).
- On April 30, 2026, SOCI amended the preamble of the Bill to, among other things, add a paragraph affirming that the Act must be implemented in a manner that respects Indigenous data sovereignty. SOCI adopted the amended Bill and presented a report to the Senate.
S-209: Protecting Children from Exposure to Pornography Act
Speaking points
- I support the objective of Bill S-209 to protect children from the harmful effects of being exposed to pornography online.
- Bill S-209 would require organizations that make pornography available on the Internet to use a prescribed age verification or estimation method to prevent children from accessing such information.
- I believe that a strength of this Bill is that it sets out a number of criteria aimed at ensuring prescribed methods are privacy-protective, while also referencing a general need to meet privacy best practices.
- In my appearance on this Bill before the Senate Standing Committee on Legal and Constitutional Affairs in October 2025, I noted that my recommendations on a previous iteration of this Bill had been incorporated – including that the above-listed criteria must be ensured rather than considered.
- I believe that age assurance, if designed and used in a privacy-protective manner, can be an appropriate tool to advance the goal of creating safer, more positive online experiences for children.
Background
- Privacy-specific criteria for age verification and estimation methods, as set out in section 12(2) include that any prescribed method must:
- maintain user privacy and protect user personal information;
- collect and use personal information solely for age-verification or age-estimation purposes;
- limit the collection of personal information to what is strictly necessary;
- destroy any personal information collected once the verification or estimation is completed; and
- generally comply with best practices for privacy protection.
- Bill S-209 was tabled in the Senate in May 2025, with third reading completed on April 15, 2026. First reading of Bill S-209 in the House was completed on April 30 and is now awaiting referral to a House Committee.
C-2: Strong Borders Act
Speaking points
- Most of the provisions originally introduced in Bill C-2 have since been reintroduced in Bill C-12, which received royal assent in March 2026, and in Bill C-22, which has currently been referred to the Standing Committee on Public Safety and National Security (SECU).
- It is not clear whether or when the Government intends to move forward with the remaining provisions in Bill C-2, some of which have implications for privacy.
- The OPC remains committed to advising departments and agencies on how to mitigate potential privacy risks or impacts in any legislative, program, or policy proposals that they may be developing.
Background
- Bill C-2 was introduced in the House by the Minister of Public Safety in June 2025. In October 2025 the Minister introduced Bill C-12 (the Strengthening Canada’s Immigration System and Borders Act), which consisted of 11 parts originally put forward in Bill C-2 but excluded some of its most controversial elements, notably:
- amendments to the Canada Post Corporation Act to permit the demand, seizure, detention, or retention of anything in the course of post in accordance with an Act of Parliament and to enable Canada Post to open letter mail (Part 4);
- amendments to the Criminal Code, the CSIS Act, and a number of other statutes to create or modify a range of investigative powers (including a warrantless “information demand”) (Part 14);
- the proposed Supporting Authorized Access to Information Act, which would require electronic service providers to have the technical and operational capabilities to facilitate access to information by authorized persons (Part 15); and,
- amendments to the PCMLTFA and PIPEDA to establish new authorities for reporting entities under the PCMLTFA to collect and use personal information without knowledge or consent when it is disclosed to them by the RCMP or other prescribed government entities for the purposes of detecting or deterring money laundering, terrorist-activity financing, or sanctions evasion (Part 16).
- In March 2026, the Minister introduced Bill C-22 (the Lawful Access Act, 2026), which reintroduces the provisions originally contained in Parts 14 and 15 of Bill C-2.
- The proposed amendments to the Canada Post Corporation Act and to the PCMLTFA remain in Bill C-2.
C-8: An Act Respecting Cybersecurity
Speaking points
- The OPC supports the objective of Bill C-8 to protect systems and services that are vital to national security or public safety from cybersecurity threats and vulnerabilities.
- Stronger cybersecurity protections can also promote privacy by reducing the likelihood and impact of breaches involving personal data.
- Several amendments adopted in the last Parliament and more recently by the House will help ensure that the bill achieves an appropriate balance between privacy interests and cybersecurity objectives.
- I will be submitting a brief in the coming days to the Senate Standing Committee on National Security, Defence and Veterans Affairs, which is examining this Bill.
Background
- Part 1 of Bill C-8 would amend the Telecommunications Act to add promoting the security of Canada’s telecommunications system as a policy objective and to provide the GIC and Minister of Industry with order-making powers to that end.
- Part 2 would enact the Critical Cyber Systems Protection Act, which would authorize the GIC to designate certain services or systems in federally regulated sectors as “vital” (e.g., energy, finance, transportation, and telecommunications); to identify classes of operators that would be subject to cybersecurity directions and regulations; to issue cybersecurity directions; and to require designated operators to establish and implement cybersecurity programs, mitigate supply-chain, and report cybersecurity incidents.
- The Commissioner appeared before the House Standing Committee on Public Safety and National Security on C-8 in October 2025 and sent a follow-up letter thereafter.
- The House has since adopted several privacy-enhancing amendments based on or inspired by the Commissioner’s advice, including:
- the insertion of more consistent necessity and reasonableness requirements throughout the bill;
- the addition of privacy impacts as a factor that the Minister and the GIC must consider when making orders;
- the addition in Part 1 of language stipulating that personal and de-identified information is deemed confidential by default; and
- a general requirement that personal information collected or obtained under both Parts 1 and 2 be disposed of if it is no longer necessary.
C-16: Protecting Victims Act
Speaking points
- Bill C-16 criminalizes the non-consensual distribution of certain deepfakes and also contains other privacy-impactful criminal law amendments. The OPC is supportive of many of the elements of this Bill.
- I note that C-16 includes a significant expansion of authorized information sharing, which could be made more privacy protective.
- An effective response to the issue of deepfakes must extend beyond the criminal law. My Office needs stronger enforcement tools such as order-making powers to more effectively hold organizations to account. We also support the need for comprehensive online harms legislation.
Background
- C-16 received first reading in December 2025 and is currently being studied by the House Standing Committee on Justice and Human Rights.
- Scope of s. 162.1: this offence applies to “intimate images”, which includes deepfakes that depict a person as either “nude”, “exposing their sexual organs”, or “engaged in explicit sexual activity” (s. 162.1(2) of the Criminal Code). Other categories of deepfakes would not be covered, including for example deepfakes of children that do not meet the above criteria.
- Other privacy protective features: Bill C-16 limits reliance on evidence of a complainant’s past sexual history, as well as on private records such as therapeutic records, in certain criminal prosecutions under the Criminal Code (ss. 276-276.13 and 278.1-278.38 of the Criminal Code). These amendments will potentially limit the disclosure of sensitive information during the prosecution of sexual offences.
- Areas of potential concern in Bill C-16: Bill C-16 contains broad information-sharing authorities for Correctional Services Canada with relatively low thresholds (see proposed ss. 25.1-25.4 of the Corrections and Conditional Release Act).
- Former Bill C-63 proposed the Online Harms Act which would have regulated “social media services” and set out an arms-length regulatory structure. A new online harms bill is expected soon.
- Private Members Bill C-216, (presently at first reading in the House) is presented as an alternative to Bill C-63. It would apply exclusively to minors and regulates Internet “operators”. Rather than creating a new regulatory structure, it would extend the role of the Canadian Radio-television and Telecommunications Commission (CRTC).
C-22: Lawful Access Act, 2026
Speaking points
- Bill C-22 incorporates important changes that reflect some of the feedback that the Government received on Bill C-2: to that extent, it is a distinct improvement over its predecessor.
- However, despite its improvements, the Bill continues to pose risks to privacy, and certain changes have also introduced new concerns.
- I look forward to having the opportunity to share my views with the Standing Committee on Public Safety and National Security as it proceeds with its study of the Bill.
Background
- Bill C-22 incorporates several notable improvements over Bill C-2, including:
- the previous “information-demand” power has been replaced with a narrowly tailored “confirmation-of-service demand” that can be served only on telcos;
- a new oversight role for the Intelligence Commissioner for orders under the proposed Supporting Authorized Access to Information Act (SAAIA); and
- a new requirement in the SAAIA for the Minister of Public Safety and the GIC to consider the impacts of orders or regulations on privacy and cybersecurity.
- Despite such improvements, Bill C-22 also inherits or creates a number of privacy risks, including:
- the definition of subscriber information remains too broad in that it would capture not only basic identifiers but also potentially sensitive information about the nature of the services provided;
- the scope of the persons that may be served with production orders for subscriber information remains too broad (any person who provides services to the public), and the threshold(reasonable suspicion) is too low in light of the information’s potential sensitivity; and,
- under proposed authorities in the SAAIA, the government could require a wide range of electronic service providers to retain metadata for up to one year, without any grounds, which significantly exceeds the 90-day limit for preservation orders under the Criminal Code and the CSIS Act (both of which also require judicial pre-authorization based on reasonable suspicion).
- Bill C-22 was referred to SECU on April 20, 2026; you will be appearing on May 26.
C-25: Strong and Free Elections Act
Speaking points
- On March 26, 2026, the Government tabled Bill C-25, the Strong and Free Elections Act, part of which sets new privacy policy requirements for the protection of personal information held by political parties.
- While these requirements represent an improvement over the status quo, I believe that political parties should be subject to privacy rules that are analogous to those set out for public and private sector organizations under federal law.
Background
- Among changes, Bill C-25 would add new content requirements for a party’s policy for the protection of personal information under s. 446.6 of the Canada Elections Act (CEA). For example, a party’s policy would also need to require the party to:
- Protect personal information through physical, organizational and technological safeguards;
- Ensure that any person or entity to which it transfers personal information provides a level of protection equivalent to that the party is required to provide under their policy;
- Prohibit the party, or any person or entity acting on its behalf, from providing false or misleading information about why the party collects personal information; selling personal information; or disclosing personal information to the public to cause harm.
- Notify affected individuals in the event of privacy breaches where there is a real risk of significant harm to the individual.
- The bill would also combat election deepfakes. The existing offence against impersonating certain electoral actors (e.g., the CEO, a candidate) with the intent to mislead voters would be expanded to ensure that it applies to realistic deepfakes (see clause 48, amending CEA section 480.1).
- PROC has held one meeting on this, with the Minister of Transport and PCO officials. Privacy did not come up.
- Date modified: