Issue sheets on Bill C-25 – Appearance before LCJC
General OPC Views on Bill C-25
Speaking points
- Bill C-25 sets new privacy policy requirements under the Canada Elections Act for the protection of personal information held by political parties.
- It adds basic requirements for safeguards and breach notification. It also introduces some limited accountability and enforcement measures.
- While these requirements represent another incremental improvement over the status quo, they still do not result in meaningful or comprehensive obligations on political parties for privacy protection.
- I believe that political parties should be subject to privacy rules that are substantially similar to requirements in the Privacy Act and PIPEDA.
Background
- Bill C-25 proposes new content requirements for a political party’s policy for the protection of personal information under s.446.6 of the Canada Elections Act (CEA) including:
- Protect personal information through physical, organizational and technological safeguards; (paragraph 446.6(1)(f))
- Ensure that any person or entity to which it transfers personal information provides a level of protection equivalent to that which the party is required to provide, by contract or otherwise, under their policy; (paragraph 446.6(1)(h))
- Prohibit the party, or any person or entity acting on its behalf, from providing false or misleading information about why the party collects personal information; selling personal information; or disclosing personal information to the public to cause harm. (paragraph 446.6(1)(j))
- Notify affected individuals in the event of privacy breaches where there is a real risk of significant harm to the individual. (paragraph 446.6(1)(g))
- Bill C-25 expands the list of required elements for a privacy policy (cl.36, s.446.6 (f) to (j) CEA). Since non-compliance by a political party with its privacy policy is already a violation of the CEA and subject to potential imposition of an AMP, this indirectly expands the potential range of privacy-related violations for which an AMP could be imposed (CEA, ss.446.5(2) and 508.1).
LEAD: PRPA
Gaps in Bill C-25
Speaking Points
- Although Bill C-25 would bring some improvements to the current privacy policy requirements under the Canada Elections Act, I believe that more could be done to better protect electors’ personal information.
- For example, the Bill fails to set precise requirements or minimum standards for privacy protection that reflect internationally recognized privacy principles. In other words, political parties can largely determine their own privacy requirements and can set the bar low.
- It also does not contain any requirement to report privacy breaches to a regulator, which is a key gap. Although the current regime does not establish robust or comprehensive privacy requirements for federal political parties, individuals may complain to the Commissioner of Canada Elections if they believe that a party has failed to comply with its own privacy policy in contravention of the Act.
- A privacy regime for political parties should go further than self-regulation; it should establish meaningful standards and independent oversight to protect and promote electors’ fundamental right to privacy.
Background
- Bill C-25’s privacy protections mostly build upon Bill C-4’s addition of s.446.6 to the Canada Elections Act (CEA), which sets out the basic requirements of a political party’s “policy for the protection of personal information.”
- s.446.6’s requirements are not stringent or detailed; political parties are still free to set the bar low in terms of what their privacy policies cover or require.
- In terms of oversight on privacy matters, the proposed new s.387(d) means that, to become eligible for registration, a political party must ensure that the Chief Electoral Officer is “satisfied” that the political party’s privacy policy complies with the requirements set out in s.446.6(1).
- Non-compliance with a party’s privacy policy is already a violation potentially subject to the imposition of an administrative monetary penalty (see ss. 446.5(2) and 508.1 CEA). AMPs may be issued if the Commissioner of Canada Elections believes on reasonable grounds that a person or entity has committed a violation and could be instigated by a public complaint.
LEAD: PRPA
Key Recommendations on Bill C-25
Speaking Points
- I have three key recommendations for improving Bill C-25 to better protect electors’ personal information:
- Establish requirements for political parties to seek consent, limit collection, use, and disclosure and provide a mechanism for access and correction of personal information.
- Expand privacy breach reporting to not only affected individuals, but also to a relevant, independent body without unreasonable delay and no later than seven calendar days after a political party becomes aware of the breach.
- Improve oversight by allowing for formal collaboration between my Office, the Commissioner of Canada Elections, and Elections Canada to ensure clear and coherent regulation on data-handling practices.
Background
- While the current s.385(2)(k) of the Canada Elections Act (CEA) requires political parties to develop specific privacy policies to protect personal information, the prescribed requirements are far from stringent or detailed; political parties are still free to set the bar low in terms of what their privacy policies cover or require.
- Reporting breaches to a relevant regulator (such as the OPC, Elections Canada, and/or the Commissioner of Canada Elections) would add independent oversight, foster accountability, and help prevent repeat harm to individuals. It also would provide Canadians with reassurance that incidents involving their personal information are being handled appropriately.
- Clear, short timelines for breach reporting would allow for an effective response, provide certainty to political parties’ legal requirements, and be consistent with modern international norms.
- Effective oversight and redress are critical elements in improving data protection, and allowing inter-agency collaboration helps bring clarity to complex issues that cut across sectors and jurisdictions.
LEAD: PRPA
Breach reporting to a regulator
Speaking Points
- Reporting privacy breaches is an important aspect of privacy protection. Breaches of personal information must be addressed swiftly to reduce the risk of harm to affected individuals.
- While the provisions for notification to individuals in Bill C-25 are an important first step, a requirement to report privacy breaches to an independent regulator, such as my Office, Elections Canada, and/or the Commissioner of Canada Elections, would reassure Canadians that incidents involving their personal information are being handled appropriately.
- Requiring that breaches be reported to a regulator would add independent oversight and promote accountability. It would also allow for an independent assessment of what went wrong and whether safeguards were adequate and would help to ensure appropriate and timely remedial action.
Background
- Bill C-25 creates a breach-notification requirement with a “real risk of significant harm” test (s. 446.6(1)(g)). The definition of “significant harm” mirrors PIPEDA’s, and the factors outlined in the Bill for meeting this test are substantially similar to PIPEDA (ss. 446.6(2) and 446.6(3)).
- We recommend expanding privacy-breach reporting not only to affected individuals but also to a relevant, independent body, without unreasonable delay and no later than seven calendar days after becoming aware of the breach.
- Under PIPEDA, organizations are currently required to report breaches involving personal information as soon as feasible where there is real risk of significant harm to an affected individual.
- Federal government institutions are currently required by policy to report privacy breaches that present a real risk of significant harm to affected individuals and to our office within 7 days.
- For this fiscal year to date (April-May 2026), the average length of time between a breach incident and the time that organizations subject to PIPEDA have submitted their breach reports to the OPC has been five months.
LEAD: PRPA
Bill C-25 regulation of deepfakes
Speaking Points
- Bill C-25’s proposed amendments to the Canada Elections Act include provisions to combat election deepfakes.
- With the exception of parody and satirical content, the existing offence provisions against impersonating certain electoral actors (e.g., the CEO, a candidate) with the intent to mislead voters will be expanded to apply to the creation and/or publication of images and imitations of voice that are realistic deepfakes of those individuals.
- The Canadian Digital Regulators Forum recently highlighted in its paper on synthetic media (which includes deepfakes) how other global regulators are developing legislation to curb the possible misuse of synthetic media for purposes such as election manipulation.
- It notes that the production of outputs by synthetic media systems—images, videos, text or audio samples—may engage Canadian privacy laws.
Background
- The current impersonation offence in the Canada Election Act applies only to people who falsely represent themselves as a key player in the electoral system, or who cause someone else to do so; Bill C-25 would broaden that offence.
- Although Bill C-25 does not refer explicitly to “deepfakes”, cl. 48 would amend s. 480.1 of the CEA to expand the offence of “impersonation”—where there is an intention to mislead—to include images or voices of political candidates or election officials that are likely to be mistaken for those persons or that falsely represent something they said.
- Subsection 480.1(3) provides an exception: it is not an offence if the image, imitation or representation was manifestly for the purpose of parody or satire.
- The creation and distribution of deepfakes would involve the collection, use, and disclosure of personal information. PIPEDA could apply to a creator or distributor of deepfakes if such actions were taken in the course of commercial activity.
LEAD: PRPA
LCJC report on Bill C-4 and proposed amendments
Speaking Points
- I am aware of your committee’s February 18, 2026, report on Bill C-4 in which you highlighted concerns that the privacy obligations in that Bill fell short of the minimum standards required to protect the individual and national interests of Canadians.
- Some of the new requirements in Bill C-25 respond, at least in part, to recommendations in your report, such as requiring privacy breach notification to affected individuals and prohibiting selling or maliciously disclosing personal information.
- Despite these incremental improvements, the privacy policy requirements for federal parties still fall short of the privacy related obligations in both federal privacy laws.
- The recommendations I am proposing on Bill C-25 mirror those I proposed for Bill C-4: comprehensive baseline privacy standards, breach reporting to a regulator, and improved oversight.
Background
- On February 18, 2026, following study of Part 4 of Bill C-4, LCJC reported observations, including proposals to enhance the privacy regime for federal parties, such as:
- minimum privacy standards aligned with recognized privacy principles, including rights of access and correction and breach notification requirements;
- prohibitions on selling or maliciously disclosing personal information, and on misleading individuals regarding the purposes of data collection, and;
- stronger administrative investigation tools for the Commissioner of Canada Elections or other designated authority.
- The Committee report also proposed options for amending Part 4, including a) that Part 4 of Bill C-4 be removed entirely, or, b) that Part 4 be severed to allow for continued study, or, c) a sunset clause be added for repeal of Part 4 after two years.
- These proposals were not adopted by the Senate Finance Committee, which was responsible for reporting on the entirety of Bill C-4. As a compromise, Senator Dalphond proposed an amendment to enact a three-year sunset clause over the privacy policy elements in Bill C-4, which was adopted on divided vote. The Government disagreed with that proposal in a statement read into the record on March 12, 2026. Later that day, the Senate debated and adopted a motion rejecting the Committee’s amendment.
LEAD: PRPA
Alberta privacy breach involving the provincial list of electors
Speaking Points
- I share Commissioner McLeod’s deep concern about the recent data breach involving the unauthorized disclosure of the personal information of some 2.9 million Albertans from Alberta’s list of electors.
- Unfortunately, outside BC and Quebec, provincial political parties are not subject to provincial privacy laws, which creates a significant gap in accountability, transparency, and public trust.
Background
- On April 30, Elections Alberta notified the Office of the Alberta Information and Privacy Commissioner of a privacy breach involving the unauthorized disclosure of personal information from the list of electors generated by Elections Alberta.
- Although the matter is reportedly still under investigation, evidence suggests that the Centurion Project, a registered third-party advertiser that supports Alberta independence, may have improperly received and used information contained in the list of electors from the pro-independence Republican Party of Alberta, a registered political party and authorized list recipient.
- The Centurion Project reportedly published the names, addresses, and – in some cases – phone numbers of some 2.9 million Albertans in a database on its website that has reported been accessed by over five hundred people. This information appears to have been sourced from the official list of electors.
- The Alberta Election Act (EA) governs the content, distribution, protection, and use of the list of electors, which includes the full names, addresses, postal codes, telephone numbers, and unique identifier numbers of electors.
- Access to the list is ordinarily restricted to the entities named in ss. 18 to 20 of the EA, namely, registered political parties, members of Alberta’s legislative assembly who are not members of a registered political party, candidates during a campaign period, and registered constituency associations. Third parties like the Centurion Project are not eligible to receive the list.
- EA section 19.1 requires that authorized recipients “take all reasonable steps to protect the list and the information contained in it from loss and unauthorized use.”
- In an April 30 news release by the Alberta OIPC, they noted that while the Alberta Election Act has some controls concerning the List of Electors, the law does not protect the privacy rights of Albertans concerning their personal information and does not have the strong privacy protections that are in AB’s PIPA to protect these rights. They renewed their call for the government to make political parties subject to the AB PIPA in the next set of amendments to the Act.
LEAD: PRPA
BC Court of Appeal: application of PIPA to federal political parties
Speaking Points
- I have been monitoring this litigation concerning the application of provincial privacy law to federal political parties with interest.
- While the BC OIPC determined that BC’s Personal Information Protection Act (PIPA) does apply to federal political parties, the Liberal Party of Canada, Conservative Party of Canada and New Democratic Party of Canada challenged that decision before the BC Supreme Court, which dismissed their applications.
- The political parties have appealed that decision to the BC Court of Appeal.
Background
- In 2019, the BC OIPC received complaints alleging that four federal political parties provided insufficient access to the complainants’ personal information, contrary to section 23 of BC’s Personal Information Protection Act (PIPA).
- In 2022, the BC OIPC concluded that BC’s PIPA applies to federal parties.
- Three of the four parties subject to the complaint brought a judicial review application of this decision: the Liberal Party of Canada, the Conservative Party of Canada and the New Democratic Party of Canada.
- They argued that it was unconstitutional to apply PIPA to them because of paramountcy and interjurisdictional immunity and argued that federal electoral law, rather than provincial privacy laws, applies to them.
- In May 2024, in Liberal Party of Canada v. The Complainants, 2024 BCSC 814, the BC Supreme Court dismissed the applications and found it reasonable for the BC OIPC to extend the definition of “organization” to federal parties given its plain meaning.
- The Court held that PIPA requirements do not impact parties’ authority to collect, use, and disclose personal information under the Canada Elections Act; both Acts complement each other and showcase co-operative federalism in action.
- The federal parties appealed to the BC Court of Appeal and the appeal is scheduled to be heard on May 27th-29th, 2026.
- (redacted)
LEAD: LEGAL
Bill C-4 amendments to the Canada Elections Act (2026)
Speaking Points
- Despite incremental improvements to the privacy policy requirements in the Canada Elections Act over the years, the Act’s requirements fall short of those in the Privacy Act and PIPEDA.
- The recommendations I am putting forward on Bill C-25 are the same that I put forward on Bill C-4: comprehensive baseline privacy standards, breach reporting to a regulator, and improved oversight.
Background
- Bill C-4 received royal assent in March 2026. Part 4 amended the Canada Elections Act including, most notably, by explicitly exempting political parties from any provincial or territorial privacy law (s. 446.4).
- Bill C-4 also added a new s. 446.6 requiring that privacy policies contain specific elements and be made publicly available, be in plain language, and be in both official languages.
- Section 446.4(2) of the CEA was also amended by Bill C-4 to explicitly exclude political parties from any requirement to provide access to, or correction of, personal information under their control.
- Following its pre-study of Part 4, LCJC reported several observations, noting that the following would be required to bring the proposed privacy regime for federal parties up to standard:
- minimum privacy standards aligned with recognized privacy principles, including rights of access and correction and breach notification requirements;
- prohibitions on selling or maliciously disclosing personal information, and on misleading individuals regarding the purposes of data collection;
- independent oversight by the OPC;
- stronger administrative investigation tools for the Commissioner of Canada Elections or other designated authority;
- limits on the retroactive effect of Part 4; and
- measures to protect data sovereignty and to guard against foreign interference.
- The Senate proposed a series of amendments to Part 4 at third reading, all of which were rejected by the House of Commons.
LEAD: LEGAL
Bill C-47 amendments to the Canada Elections Act (2023)
Speaking Points
- Bill C-47, which received royal assent in June 2023, amended the Canada Elections Act to specifically authorize political parties to collect, use, disclose, retain, and dispose of personal information in accordance with the party’s own privacy policy.
- The amendments did not establish rules or standards for political parties to follow in their handling of personal information, nor did they provide for independent oversight of parties’ privacy practices.
- Political parties collect a wide range of personal information about voters, much of which is sensitive in nature, from a variety of sources. Political parties should therefore be subject to privacy rules, based on internationally recognized privacy principles. These should include having an independent third party with authority to verify and enforce compliance.
Background
- Division 39 of Part 4 of Bill C-47 contained three provisions that were added to the Canada Elections Act:
- A definition of personal information stating that personal information means information about an identifiable individual. (385.2 (1))
- A provision stating that political parties and their affiliates (candidates, district associations, officers, agents, employees, volunteers, and representatives) may collect, use, disclose, retain and dispose of personal information in accordance with the party’s privacy policy. (385.2 (2))
- A purpose statement noting that the purpose of the section is to provide for a national, uniform, exclusive and complete regime applicable to registered parties and eligible parties respecting their collection, use, disclosure, retention, and disposal of personal information. (385.2 (3))
- No specific standards were set in the amendments for privacy policies or the data handling practices of parties, nor were there mechanisms for third-party review of complaints or for effective recourse.
LEAD: PRPA/LEGAL
Bill C-76 amendments to the Canada Elections Act (2018)
Speaking Points
- Bill C-76, which received royal assent in December 2018, amended the Canada Elections Act to require for the first time that federal political parties develop written privacy policies and publish them online as part of the official registration process.
- While those requirements represented important first steps, the lack of minimum privacy standards, effective recourse and oversight represented serious shortcomings.
- In 2018, my Office appeared before the House of Commons Standing Committee on Procedure and House Affairs on the amendments and recommended that the regime be strengthened to provide for recourse and independent review.
Background
- Bill C-76 inserted a new paragraph 385(2)(k) in the Canada Elections Act requiring parties to develop policies for the protection of personal information, to submit those to the Chief Electoral Officer (CEO), and to publish the policies on their websites.
- While the privacy policies must include specific elements, such as a statement indicating the types of personal information that the party collects, and how it collects, uses, and safeguards that information, there are no substantive requirements concerning the actual handling of personal information.
- In order to be registered, a political party must include a privacy policy as part of its application (s. 385(2)(k)); the CEO can deregister an existing party if it fails to maintain its privacy policy (s.412(3)), fails to notify the CEO of any updates to the policy (s. 412(1)(f)), or fails to publish an updated version of its policy online (s. 412(2)).
- The CEO does not have any express authority to verify that a political party is complying with its policy, or the adequacy of the policy to protect privacy.
LEAD: PRPA/LEGAL
2019 complaint to the OPC concerning political parties
Speaking Points
- In 2019, a complaint was submitted to the OPC alleging that federal political parties were violating PIPEDA because they collect, use and disclose personal information for the purpose of creating voter profiles and conducting political advertising.
- In 2021, after a thorough analysis, the OPC concluded that PIPEDA did not apply to the activities of federal political parties as they are not commercial in character.
- Although I believe that federal political parties should be covered by privacy legislation and that Canadians should be offered basic privacy protections in that regard, the OPC applies the law as adopted by Parliament.
Background
- Part 1 of PIPEDA applies to every organization in respect of personal information that “the organization collects, uses or discloses in the course of commercial activities” (s. 4(1)(a)).
- Federal political parties collect, use and disclose “personal information” during their activities, including of supporters, members, volunteers, electors and voters. That said, regular activities of the federal political parties are not considered to be commercial in character within the meaning of PIPEDA.
- In the former Commissioner’s response to the complainant, he noted:
“Although I strongly believe that privacy laws should govern political parties to better protect both privacy and democratic rights, I must apply the law as it is today. As you know, as Privacy Commissioner I have often called on the need to expand privacy laws to ensure that political parties are subject to legislation and fully respect the privacy rights of Canadians. As I told Parliament, what matters are that internationally recognized privacy principles… be included in domestic law and that an independent third party … have the authority to verify compliance.”
LEAD: COMPLIANCE
OPC Guidance for federal political parties (2019)
Speaking Points
- In 2019, the OPC and Elections Canada published guidance for political parties following new requirements contained in Bill C-76 (Elections Modernization Act) relating to privacy policies.
- Our guidance outlines privacy best practices, aligned with the ten fair information principles, to encourage political parties to better protect the personal information that they collect.
- This includes recommended practices on accountability, outlining clear purposes and obtaining valid consent for collection, including for inferred and predictive data, and data minimization.
Background
- In December 2018, Parliament enacted Bill C-76, the Elections Modernization Act, which amended the Canada Elections Act to require political parties to include a policy for the protection of personal information as part of applications for registration (s. 385(2)(k)), and to publish them online (s. 385(4)).
- Subsection 385(2)(k) of the Canada Elections Act requires that policies for the protection of personal information include details about the types of personal information collected and how it is collected, how personal information is used and under what circumstances it may be sold, training given to any party employee who could have access to personal information, and the contact information of a person to whom concerns about a party’s policy can be addressed, among other details.
- Following the passage of Bill C-76, in 2019, the OPC and the Chief Electoral Officer prepared guidance to assist federal political parties in complying with their new legal obligations relating to privacy policies. In it, it was noted that while these policies must have prescribed content, they do not require the substance to comply with international privacy standards, a step political parties were encouraged to take.
- The guidance outlines best practices aligned with the fair information principles to assist parties in handling personal information, so that privacy rights of Canadians are respected.
- Since the passage of Bill C-4, the OPC has been in discussions with staff from Elections Canada about updating the guidance, which will also be impacted by the new requirements contained in Bill C-25.
LEAD: PRPA
The Personal Information Protection and Electronic Documents Act (PIPEDA) Application Alternative
Speaking Points
- While federal political parties are currently not explicitly made subject to PIPEDA, the Act could be extended to cover them.
- Under PIPEDA, subsection 4(1.1) and paragraph 26(2)(c) provide a mechanism by which the Governor-in-Council can list any organization as being subject to the Act by including them in Schedule 4.
- My Office recommended that Parliament consider this in our 2021 submission on the former Bill C-11, and I maintain that this is a feasible option for extending the application of privacy rules to political parties.
Background
- Organizations currently listed under Schedule 4 of PIPEDA: at present only one organization in Canada, the World Anti-Doping Agency (WADA) based in Montreal, has been made subject to the Act in this manner.
- Political parties as analogous to WADA: Like political parties, WADA is not a commercial organization nor a for-profit entity. It is funded by the Olympic Movement and governments from around the world. However, given that WADA handles the drug-testing regime for Olympic and other athletes, it does collect, use, and process sensitive personal information.
- The full text of the OPC’s recommendation was provided to ETHI in its Submission of the Office of the Privacy Commissioner of Canada on Bill C-11, the Digital Charter Implementation Act, 2020 (May 2021). In it, the OPC recommended using the Schedule to bring political parties under the proposed Consumer Privacy Protection Act.
- Schedule 4 of PIPEDA could reference “registered party” or “eligible party” as defined under the Canada Elections Act (CEA) instead of individually listing each political party, to avoid continuous updating.
LEAD: LEGAL
Division 2, Part 18 of Canada Elections Act as an “exclusive regime”
Speaking Points
- An “exclusivity clause” was first introduced via Bill C-47 in June 2023 and then replaced with the passing of Bill C-4 in March 2026.
- The current provision, s.446.2, underlines the exclusive and complete nature of the Canada Elections Act as a regime governing the personal information handling practices of federal political parties.
- The Act also includes a provision expressly indicating that federal parties are not subject to provincial or territorial privacy law, unless their privacy policy expressly indicates otherwise (s.446.4(1)).
- The constitutional validity of these provisions is currently before the BC Court of Appeal in litigation involving the BC OIPC and three federal political parties. I understand that hearings in that matter are taking place this week.
Background
- In March 2022, the BC OIPC concluded that BC’s Personal Information Protection Act applies to federal political parties (2022 BCIPC 13).
- In June 2023, Bill-47 received royal assent and introduced s.385.2 of the CEA (now repealed) to “provide for a national, uniform, exclusive and complete regime applicable to registered parties and eligible parties respecting their collection, use, disclosure, retention and disposal of personal information”.
- In May 2024, the BC Supreme Court upheld the BC OIPC’s decision (see Liberal Party of Canada v The Complainants, 2024 BCSC 814); the matter has been appealed to the BCCA and hearings are scheduled for May 27—29th, 2026.
- On March 12th, 2026, Part 4 of Bill C-4, which received royal assent, made various amendments to the Canada Elections Act, including to repeal s.385.2 and replace it with a very similarly-worded provision (s.446.2), along with a carve-out provision (s.446.4) ousting the application of provincial/territorial privacy legislation unless otherwise provided for in a party’s privacy policy.
- On March 13th, 2026, the Respondents (Complainants) filed a notice of constitutional question submitting that these provisions, which are intended to apply retroactive to May 2000, are ultra vires.
LEAD: LEGAL
Privacy regulation for political parties – other jurisdictions
Speaking Points
- Privacy laws in Quebec, the EU and the UK apply to political parties.
- Since 2023, many provisions of Quebec’s private sector privacy law apply to provincial political parties; failure to comply can lead to the imposition of administrative monetary penalties.
- In the EU and the UK, political parties are covered by the GDPR and UK GDPR respectively. The UK also has other laws that impose additional privacy obligations on political parties.
- My counterpart in BC has concluded that that province’s privacy legislation applies to political parties, including federal ones. The BC Supreme Court upheld the reasonableness of that decision. I understand that the BC Court of Appeal is hearing the appeal of that decision this week.
Background
- Quebec: Many provisions of Quebec’s private sector privacy legislation (Loi sur la protection des renseignements personnels dans le secteur privé) (LPRPSP) apply to personal information handled by political parties via s.127.22 of Quebec’s Loi électorale. Certain provisions are excluded (e.g., access). Political parties may be subject to AMPs (s. 90.1 et seq. LPRPSP), fines (s. 91 et seq. LPRPSP), or punitive damages (s. 93.1 LPRPSP) for certain contraventions of the Act.
- EU: Political parties in EU member states are subject to the GDPR. Among other obligations, political parties must process personal data lawfully, fairly and transparently (art. 5(1)(a)); provide a right to access personal data they hold (art. 15); and enable individuals to object to use of their personal data for political profiling purposes (art. 21).
- UK: In the UK, political parties and candidates are subject to several privacy laws: the UK General Data Protection Regulation, the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003. Failure to abide by these laws can result in significant financial penalties.
- BC: Federal political parties appealed the May 2024 BC Supreme Court decision (2024 BCSC 814) regarding BC PIPA’s application to political parties. At the time of writing, that hearing was scheduled to be held May 27-29, 2026.
LEAD: LEGAL
Bill C-8 (An Act Respecting Cybersecurity)
Speaking points
- The OPC supports the objective of Bill C-8 to protect systems and services that are vital to national security or public safety from cybersecurity threats and vulnerabilities. Stronger cybersecurity protections can also promote privacy by reducing the likelihood and impact of breaches involving personal data.
- Together with amendments to the former Bill C-26 that have been preserved in Bill C-8, the amendments to Bill C-8 as passed by the House will help ensure that it achieves an appropriate balance between privacy interests and security objectives.
- I recently submitted a brief to the Senate Committee on National Security, Defence and Veterans Affairs in which I reiterated a small number of recommendations from my previous testimony on the bill.
Background
- Part 1 of Bill C-8 would amend the Telecommunications Act to provide the GIC and the Minister of Industry with order-making powers to strengthen cybersecurity; Part 2 would enact the Critical Cyber Systems Protection Act (CCSPA).
- You last appeared on Bill C-8 at the House Standing Committee on Public Safety and National Security in October 2025; you also sent a follow-up letter shortly thereafter.
- The House adopted several privacy-enhancing amendments based on or inspired by your testimony and written advice, including:
- the insertion of more consistent necessity and reasonableness requirements;
- the addition of privacy impacts as a factor that the Minister and the GIC must consider when making orders;
- the addition in Part 1 of language stipulating that personal and de-identified information is deemed confidential by default; and
- a general requirement that personal information collected or obtained under both Parts 1 and 2 be disposed of if it is no longer necessary.
- On May 22, 2026, you sent SECD a written brief in which you noted these improvements and reiterated the following additional privacy-focused recommendations:
- That a reference to “personal information” be added to the definition of “confidential information” in the CCSPA; and,
- That the Communications Security Establishment be required to provide the OPC with copies of cybersecurity incident reports that identify serious or systemic privacy issues.
Bill C-22 (Lawful Access Act, 2026)
Speaking points
- Bill C-22 improves on its predecessor, Bill C-2, in several respects.
- However, aspects of Bill C-22 continue to pose privacy risks, and certain changes have also introduced new concerns.
- I recently recommended amendments to the House Standing Committee on Public Safety and National Security with a view to mitigating some of the Bill’s most serious privacy-related shortcomings.
Background
- Bill C-22 incorporates several notable improvements over Bill C-2, including:
- the previous “information-demand” power has been replaced with a narrowly tailored “confirmation-of-service demand” that can be served only on telcos;
- a new oversight role for the Intelligence Commissioner for orders under the proposed Supporting Authorized Access to Information Act (SAAIA); and
- a new requirement in the SAAIA for the Minister of Public Safety and the GIC to consider the impacts of orders or regulations on privacy and cybersecurity.
- In your May 21, 2026 brief to SECU, you recommended:
- Narrowing the scope of the definition of “subscriber information” as well as the range of persons that could be compelled to produce it (from any “person who provides services to the public” to “telecommunications service providers”);
- Amending the new production-order provisions to ensure that the justice or judge making the order can specify the subscriber information that must be produced (as opposed to only what the subscriber information must “relate to”);
- Defining “information that is available to the public” in such a way as to exclude information in respect of which a person has a reasonable expectation of privacy;
- Adding an overarching requirement to the Supporting Authorized Access to Information Act that any obligation imposed under it – including with respect to the retention of metadata – meet the standard of necessity and proportionality;
- Amending the SAAIA to expressly prohibit the making of, or compliance with, orders and regulations that would cause a “systemic vulnerability”; and
- Amending the definition of “systemic vulnerability” to expressly include actions that would render systemic methods of authentication or encryption less effective.
Bill C-16 (Protecting Victims Act)
Speaking points
- Bill C-16 criminalizes non-consensual distribution of certain deepfakes and also contains other privacy-impactful criminal law amendments. The OPC is supportive of many of the elements of this Bill.
- I note that Bill C-16 includes a significant expansion of authorized information sharing, which could be made more privacy protective.
- An effective response to the issue of deepfakes must extend beyond the criminal law. My Office needs stronger enforcement tools such as order-making powers to more effectively hold organizations to account. We also support the need for comprehensive online harms legislation.
Background
- Bill C-16 received first reading in December 2025 and returned to the House on May 25, 2026 after clause-by-clause review.
- Scope of s. 162.1: this offence applies to “intimate images”, which includes deepfakes that depict a person as either “nude”, “exposing their sexual organs”, or “engaged in explicit sexual activity” (s. 162.1(2) of the Criminal Code). Other categories of deepfakes would not be covered, including for example deepfakes of children that do not meet the above criteria.
- Other privacy protective features: Bill C-16 limits reliance on evidence of a complainant’s past sexual history, as well as on private records such as therapeutic records, in certain criminal prosecutions under the Criminal Code (ss. 276-276.13 and 278.1-278.38 of the Criminal Code). These amendments will potentially limit the disclosure of sensitive information during the prosecution of sexual offences.
- Areas of potential concern: Bill C-16 contains broad information-sharing authorities for Correctional Services Canada with relatively low thresholds (see proposed ss. 25.1-25.4 of the Corrections and Conditional Release Act).
- Former Bill C-63 proposed the Online Harms Act which would have regulated “social media services” and set out an arms-length regulatory structure. A new online harms bill is expected soon.
- Private Members Bill C-216, (presently at first reading in the House) is presented as an alternative to Bill C-63. It would apply exclusively to minors and regulates Internet “operators”. Rather than creating a new regulatory structure, it would extend the role of the Canadian Radio-television and Telecommunications Commission (CRTC).
Bill S-209 (Protecting Children from Exposure to Pornography Act)
Speaking points
- I support the objective of Bill S-209 to protect children from the harmful effects of being exposed to pornography online.
- Bill S-209 would require organizations that make pornography available on the Internet to use a prescribed age verification or estimation method to prevent children from accessing such material.
- I believe that a strength of this Bill is that it sets out a number of criteria aimed at ensuring that prescribed methods are privacy-protective, while also referencing a general need to meet privacy best practices.
- In my appearance on this Bill before the Senate Standing Committee on Legal and Constitutional Affairs in October 2025, I noted that my recommendations on a previous iteration of this Bill had been incorporated – including that those privacy-protective criteria must be ensured rather than considered.
- I believe that age assurance, if designed and used in a privacy-protective manner, can be an appropriate tool to advance the goal of creating safer, more positive online experiences for children.
Background
- Privacy-specific criteria for age verification and estimation methods, as set out in section 12(2), include that any prescribed method must:
- maintain user privacy and protect user personal information;
- collect and use personal information solely for age-verification or age-estimation purposes;
- limit the collection of personal information to what is strictly necessary;
- destroy any personal information collected once the verification or estimation is completed; and
- generally comply with best practices for privacy protection.
- Bill S-209 was tabled in the Senate in May 2025, with third reading completed on April 15, 2026. First reading of Bill S-209 in the House was completed on April 30, 2026, and it is now at Second Reading stage.
Bill S-5 (Connected Care for Canadians Act)
Speaking points
- Last month, Deputy Commissioner Chénier appeared before the Senate Standing Committee on Social Affairs, Science and Technology to offer the OPC’s general support for Bill S-5 as it would help advance interoperability of health information systems in Canada, improving patient access and control over their personal health information.
- Increased access, use and exchange of personal health information in an interoperable health system could introduce risks to privacy.
- I am pleased that the interoperability requirement specifies that access, use and exchange of personal health information is not required where prohibited by privacy law. My Office recommended that the data-blocking prohibition include a similar exception.
- As the Bill does not expressly mention privacy or security safeguards, I hope to see these elements addressed in regulations. My Office should be consulted on the regulations as they pertain to privacy and security.
Background
- Bill S-5 prohibits data-blocking (s. 6), which is defined as a practice or act that prevents, discourages or interferes with access to or the use or exchange of electronic health information. The Bill also requires health information technology (HIT) vendors to ensure that the HIT they license, sell or supply is interoperable, meaning that users can easily, completely, and securely access, use, and share electronic health information, unless privacy law prohibits it (ss. 5(2)(a)).
- The Connected Care for Canadians Act would only apply by order, partially or fully, in a province or territory, if the GIC is satisfied that the province or territory does not have requirements that are substantially similar to or exceed those in the Act (ss. 7(1)).
- Key details are left to regulations made by the GIC, including what practices or acts constitute data-blocking, the standards and specifications for interoperability, and the criteria and process for determining substantial similarity (s. 8).
- On April 30, 2026, SOCI amended the preamble of the Bill to, among other things, add a paragraph affirming that the Act must be implemented in a manner that respects Indigenous data sovereignty. SOCI adopted the amended Bill and presented a report to the Senate, where the Bill currently remains at 3rd reading.
- Date modified: