Language selection

Search

Issue sheets on the Implications of the Canada-China Preliminary Joint Arrangement on Canada’s Electric Vehicle Sector – Appearance before the Standing Committee on SRSR

Privacy Implications of Chinese EVs entering the Canadian market

Speaking points

  • Most of today’s electric vehicles pose a different scale and type of privacy risk than traditional vehicles due to the data that they collect and generate and their internet connectivity. These risks are not specific to vehicles manufactured in one country and would extend across most connected vehicles.
  • A manufacturer is generally obliged to comply with the laws of the country in which it is based, even if the vehicle is destined for sale and use in another country. Depending on the laws of the manufacturer’s jurisdiction, this could lead to the data of Canadians being accessible to law enforcement and national security authorities of that foreign jurisdiction, potentially without the knowledge or consent of the vehicle’s eventual owner.
  • Unlike most modern privacy laws, PIPEDA does not contain explicit rules governing trans-border data flows, which I have recommended should be rectified.

Background

  • The OPC has not investigated or conducted an audit of an EV manufacturer.
  • To fully assess the privacy implications of Chinese EVs, the Office would have to analyze the specific model(s) of the vehicles, contractual arrangements, and legal requirements in the other implicated jurisdiction (China).
  • Key ways in which EV data could potentially be accessible to manufacturers include through data being transmitted to manufacturer-controlled cloud systems that are located outside of Canada and by manufacturers having access to vehicle data for troubleshooting, responding to service requests and improving vehicle systems.
  • Several countries such as the US (2025), Poland (2026) and Israel (2025) have prohibitions related to Chinese EVs, citing national security concerns.
  • During their March 12 and 26, 2026 INDU committee meetings, INDU witnesses briefing on the committee’s Federal Government’s Electric Vehicle (EV) Policies study discussed privacy, cybersecurity and national security concerns related to these vehicles.

Lead: PRPA


Digital and Data Sovereignty

Speaking points

  • I understand that that allowing Chinese EVs to enter the Canadian market may raise questions regarding where the personal information collected by these vehicles is being processed or stored, and more generally about the implications the arrangement has on Canada’s data sovereignty.
  • Personal information processed in a foreign country, such as China, or by foreign companies, may be accessible to the law enforcement and national security authorities of that jurisdiction.
  • While Canadian privacy laws do not prohibit the transfer of personal information to foreign countries or require data be stored in Canada, I have recommended modernizing Canada’s privacy laws to help effectively regulate some of the risks associated with cross border data transfers.

Background

  • The Government of Canada (GC) has published two white papers on this topic, specifically Data Sovereignty and Public Cloud (2018) and Digital Sovereignty: A Framework to improve digital readiness of the Government of Canada (2025). These documents define key terms, such as:
    • Digital sovereignty: the ability of the GC to exercise autonomy over its digital infrastructure, data and intellectual property, and the capacity to operate effectively and make independent decisions about digital assets regardless of where technologies are developed, hosted, or supported.
    • Data sovereignty: Canada’s right to control access to and disclosure of its digital information subject only to Canadian laws
  • In August 2025, the GC launched a Major Projects Office mandated to get nation-building projects built faster. The second tranche of projects will deploy several strategies, including, among other things, establishing data sovereignty in Canada.
  • In January 2026, during a speech at the World Economic Forum, the Prime Minister noted that Canada was building strategic autonomy while maintaining values like human rights and sovereignty.

Lead: PRPA


Government / Lawful Access

Speaking points

  • PIPEDA requires organizations to be transparent, and customers should be advised when their information is sent to another jurisdiction where it could be accessed by that country’s courts, law enforcement and national security authorities.
  • PIPEDA recognizes the need for law enforcement to access personal information in certain circumstances and contains exceptions to consent for the disclosure of personal information in certain law enforcement and national security contexts where a government institution has lawful authority to do so.
  • Government access should not be unfettered and should respect fundamental tenets such as independent judicial oversight, necessity, proportionality, and transparency.

Background

  • PIPEDA permits the disclosure of personal information without knowledge or consent to a requesting government institution if it has identified its lawful authority and indicated that: it suspects the information relates to national security, the defence of Canada, or the conduct of international affairs; the request is for the enforcement of, or investigating the enforcement of, any law of Canada, a province or a foreign jurisdiction; or is requesting the information for administering any law of Canada or a province (s. 7(3)(c.1)).
  • An organization can make a disclosure of their own initiative to a government institution under s. 7(3)(d) of PIPEDA, if they have reasonable grounds to believe that the information relates to a contravention of Canadian, provincial, or foreign laws; or if they suspect that the information relates to national security, the defence of Canada or conduct of international affairs.
  • In 2022, the OECD published a Declaration on Government Access to Personal Data Held by Private Sector Entities that advances several principles for legitimate government access, which include: Legal basis, legitimate aims, approvals, data handling, transparency, oversight and redress.
  • On March 12, 2026, the Government tabled Bill C-22, the Lawful Access Act, which sets out parameters regarding how personal information can be used in the context of investigations. See separate sheet.

Lead: PRPA


OPC work on connected vehicles

Speaking points

  • My office has been closely following the emergence and development of connected vehicles and has undertaken work to understand the potential privacy implications. We are also looking at ways to expand our ability to assess the vehicles themselves.
  • For example, my Office has formed a connected cars working group with my counterparts in provinces with substantially similar private-sector privacy legislation, namely Alberta, BC and, Quebec. The working group is gathering information related to the collection, use and disclosure of personal information related to connected vehicles.
  • Additionally, last year, my Office funded two research projects on connected vehicles through our Contributions Program, that will be published soon.

Background

  • The FPT Working Group agreed to start information-gathering in April of 2026, after leveraging the findings from recent contributions program funded research. Once the group has reviewed the findings, it will consider potential avenues to assess and ensure compliance with Canadian privacy laws in this area.
  • Draft reports from the 2025-2026 Contributions Program funding cycle were received on March 31, 2026 and will be published in the next few weeks. The two relevant projects are:
    1. Automobile Protection Association: Inventory of the privacy permissions and releases automakers require of Canadian customers to access onboard features and connected applications in vehicles.
    2. University of Windsor: Examination of how privacy by design can be used to improve privacy protection when companies access identifiable information from connected vehicles.

Lead: PRPA


OPC technical capacity to assess connected vehicles

Speaking points

  • My office has looked at how it could assess the technical capabilities of select Chinese EVs should there be a need to determine if personal information is being collected from various elements, such as the navigation or infotainment systems, and, if so, if this is being done in compliance with PIPEDA.
  • While my office has computer hardware and software reverse engineering expertise, it does not have any formal expertise related to automotive vehicles. We also currently lack the physical space or equipment needed to analyse EVs, such as a secure garage, mechanical tools, and a dedicated EV charging station.
  • Because of this, we are actively exploring possible partnerships with like-minded parties that have the complementary skills and physical space to conduct a technical assessment of Chinese EVs.

Background

  • Currently, no formal complaint has yet been made to the OPC related to the collection of personal information by Chinese EVs.
  • Should such a complaint be made, the OPC would likely need to conduct a technical assessment of the implicated Chinese EV model(s) to determine what information is being collected and sent to the parent company.

Lead: TA


OPC funded research on connected vehicles

Speaking points

  • My office administers a contributions program that provides up to $500,000 a year for research and public education initiatives on a range of privacy issues related to PIPEDA.
  • Last year we solicited projects that increase knowledge and awareness with respect to smart devices, including associated data flows and privacy protections, and funded two projects related to connected vehicles:
    • A project from the Automobile Protection Association that inventoried the privacy permissions and releases automakers require of Canadian customers to access onboard features and connected applications in vehicles.
    • A project from the University of Windsor that examined how privacy by design can be used to improve privacy protection when companies access identifiable information from connected vehicles.

Background

  • Draft reports from the 2025-2026 funding cycle have been received. Final reports will be published online in the next few weeks.
  • Findings from the University of Windsor show that access to connected vehicle data can be restricted through the use of privacy-preserving techniques while preserving data utility.
  • A study from the Automobile Protection Association (APA) suggests that automakers’ approaches to data collection vary significantly across brands and that consent for the use of personal information is not always obtained.
    • This is particularly concerning given information collected can include Social Insurance Numbers, permissions to record in-vehicle conversations, location tracking, websites visited, contacts, and driving habits.
    • Furthermore, some automakers require customers to opt-in to information sharing to access connected features.

Lead: PRPA


FPT connected vehicles working group

Speaking points

  • My office formed a connected cars working group with regulators from Alberta, BC and Quebec given our common interest in pursuing work in this area.
  • Last year, this working group met on several occasions and members are currently in the process of gathering information related to the collection, use and disclosure of personal information in the context of the connected cars ecosystem.
  • The working group intends to leverage the information gathered along with the findings from research conducted under the OPC’s Contributions Program to identify and better understand privacy issues that may exist with connected cars.
  • This information will enable us to determine what measures, if any, our respective Offices can take to better protect the personal information of Canadians in this context.

Background

  • Findings for research work on the question of connected cars under the Contributions Program were received at the end of March 2026 and are currently under review.
  • Once it has reviewed the results of this work and information gathered by the members, the working group will determine next steps, if any, to assess and ensure the compliance of connected cars with Canadian privacy laws.

Lead: BA


Transfer requirements under PIPEDA

Speaking points

  • PIPEDA requires organizations to be transparent about their data practices. If personal information collected through EVs is being sent to another jurisdiction, like China, customers should be made aware of that fact, and that the information may be accessible by that country’s courts, law enforcement and national security authorities.
  • Organizations also remain responsible for personal information transferred to a third party for processing, whether the transfer is domestic or international. They must also ensure that a “comparable level of protection” is provided.
  • I believe Canadians need and expect stronger requirements, that is why I have advocated for amending PIPEDA to institute specific rules and requirements to protect personal data moving outside of the country.

Background

  • PIPEDA does not prohibit organizations in Canada from transferring personal information to organizations in China, or any other jurisdiction.
  • Principle 4.1.3. of PIPEDA requires organizations to use contractual or other means to provide a “comparable level of protection” when transferring information to a third party for processing.
    • This means that the third party must provide a level of protection comparable to the level the personal information would receive if it had not been transferred. The protections do not have to be the same, but they should be generally equivalent.
  • Most modern privacy laws, such as in Australia, New Zealand and the EU, explicitly and separately address trans-border data flows, providing for specific transfer mechanisms, such as adequacy rulings, standard contractual clauses, codes of conduct or other schemes such as binding corporate rules.
  • The OPC’s Guidelines for processing personal data across borders provides guidance to organizations on their obligations under PIPEDA when transferring personal information across borders.

Lead: PRPA


PIPEDA law reform recommendations on cross-border transfers

Speaking points

  • Canadians need and expect modernized privacy laws, such as those we have seen enacted in other jurisdictions, that address the global data-driven economy and promote innovation and international trade.
  • I have recommended that PIPEDA be amended to specifically address trans-border data flows to ensure that Canadians’ personal information is appropriately protected prior to leaving the country, including by:
    • Requiring organizations to conduct a PIA to ensure that information would receive a comparable level of protection to PIPEDA, taking into account, among other things, the legal data protection framework in the other jurisdiction; and
    • Providing for specific tools to help ensure a comparable level of protection, like standard contractual clauses, codes of practice, certification programs, and binding corporate rules.

Background

  • The privacy laws of Australia, New Zealand, and the EU provide for specific transfer mechanisms, such as adequacy rulings, standard contractual clauses, codes of conduct or other schemes such as binding corporate rules.
  • Quebec’s private sector privacy law requires organizations to conduct a PIA before transferring personal information outside Quebec, ensuring it receives "adequate protection" (s. 17). The PIA has to consider data sensitivity, purpose, safeguards and the legal framework of the other jurisdiction. Similarly, the UK and France also require transfer risk/impact assessments.
  • The OPC’s submissions on the former Bill C-11 and Bill C-27 recommended that a framework for addressing TBDF be included in a reformed law, addressing, among other things: 1) to whom the obligations apply; 2) enhanced accountability measures; 3) criteria to be met prior to a transfer taking place; and 4) jurisdictional assessments of protections.
  • In response to a 2024 report by ETHI on Social Media Platforms, the Government noted the importance of addressing cross-border data transfers and highlighted government activities related to promotion of DFFT and implementation of the Global CBPR.

Lead: PRPA


OPC work ensuring trusted transfers (DFFT)

Speaking points

  • I work closely with other data protection authorities to help ensure high standards for cross-border flows of personal information, which would include those potentially coming from the use of connected vehicles.
  • With my counterparts, I try to identify and work towards elements of convergence, to foster interoperability, which provides businesses with regulatory certainty and reduces compliance costs, while maintaining high privacy standards and public trust.
  • Data Free Flow with Trust (DFFT) is a key pillar of the G7 Data Protection Authorities Roundtable, which I hosted last year, and is a main theme for my vision as Chair of the Global Privacy Assembly (GPA).
  • My Office has explored data transfer mechanisms that can establish trust, including those being implemented in Canada such as the Global Cross-Border Privacy Rules (CBPR) certification mechanism.

Background

  • In 2019 at the G20 Osaka Summit, the Japanese Government introduced the concept of DFFT as ensuring “trust”, including a high standard of protection of personal data, as a prerequisite to facilitating the free flow of data.
  • On November 1, 2024, the OPC co-sponsored the GPA Global Frameworks and Standards WG resolution on DFFT.
  • The G7 Roundtable DFFT working group completed a comparison of the Global CBPR and GDPR certification mechanisms in 2024 and released a position paper in 2025.
  • The OECD maintains a DFFT Experts Community group, the OPC is on the subgroups related to cross border payments and health data.
  • The Global CBPR Forum is a voluntary international privacy certification system based on a commonly agreed upon set of principles. The OPC has participated since April 2024 in Global Cooperation Arrangement for Privacy Enforcement which facilitates enforcement cooperation amongst participating privacy enforcement authorities. In June 2025, the OPC responded to ISED’s consultation on the implementation of this system in Canada.

Lead: PRPA


International Transfers in Trade Agreements

Speaking points

  • My Office supports the objectives that underpin international trade agreements and recognizes the need to expand trade to new countries as well as with our existing partners.
  • Privacy protections should not be seen as a barrier to trade. Modern trade agreements, such as the Canada-United States-Mexico Agreement (CUSMA), and the Canada-European Union Comprehensive Economic Trade Agreement (CETA) include provisions and chapters that address privacy and data protection to facilitate electronic commerce.
  • While these agreements support trade and cross-border data flows, they also preserve a degree of flexibility for countries to develop their own privacy laws. Under CUSMA, for example, countries can adopt measures to further their own public policy objectives, provided these are not arbitrary, discriminatory or a disguised barrier to trade.

Background

  • CUSMA requires that a “joint review” be conducted six years after its coming into force (Article 34.7(2)). Since the agreement came into force on July 1, 2020, this joint review is in principle scheduled to take place in July, 2026.
  • CUSMA recognizes the economic and social benefits of protecting personal information and how doing so enhances consumer confidence in digital trade (Article 19.8(1)) as well as the importance of ensuring that any restrictions on cross-border data flows of personal information are necessary and proportionate to the risks presented (Article 19.8(3)).
  • CUSMA generally prohibits restrictions on cross-border data transfers (Article 19.11(1)) except where necessary for a “legitimate public policy objective” which cannot be arbitrarily or unjustifiably discriminatory, a disguised restriction on trade, or impose greater restrictions than are necessary for the objective (Article 19.11(2)).
  • Article 16.4 of CETA notes that each party should adopt or maintain laws, regulations or administrative measures for the protection of personal information of users engaged in electronic commerce.

Lead: PRPA


Schrems II Decision

Speaking points

  • In its Schrems II decision in 2020, the European Court of Justice noted that standard contractual clauses, alone, may not always ensure adequate protection for personal data transferred across borders.
  • In particular, the Court noted that a country’s national-security and lawful-access legislation may impose obligations on the recipients of transferred data that conflict with such clauses, thereby undermining the protection they are intended to provide.
  • In such cases, data transfers to that country may be prohibited absent additional safeguards to supplement the protection offered by standard contractual clauses.

Background

  • Schrems II, para. 126: “[T]here are situations … in which the content of … standard clauses might not constitute a sufficient means of ensuring, in practice, the effective protection of personal data transferred to the third country concerned. That is the case, in particular, where the law of that third country allows its public authorities to interfere with the rights of the data subjects to which that data relates.”
  • Schrems II, para. 133: “In so far as … standard data protection clauses cannot, having regard to their very nature, provide guarantees beyond a contractual obligation to ensure compliance with the level of protection required under EU law, they may require, depending on the prevailing position in a particular third country, the adoption of supplementary measures by the controller in order to ensure compliance with that level of protection.”
  • Schrems II, para. 135: “Where [an EU] controller or a processor … is not able to take adequate additional measures to guarantee [adequate] protection, the controller or processor [must] suspend or end the transfer of personal data to the third country concerned. That is the case, in particular, where the law of that third country imposes on the recipient of personal data from the [EU] obligations which are contrary to [standard data protection] clauses and are, therefore, capable of impinging on the contractual guarantee of an adequate level of protection against access by the public authorities of that third country to that data.”

Lead: LEGAL


International Responses to Connected Vehicles

Speaking points

  • I am aware of various activity in other jurisdictions setting restrictions on connected vehicles, primarily due to national and cyber security concerns.
  • For instance, the US Department of Commerce has issued a binding rule prohibiting the import and sale of connected vehicles and associated hardware and software from China and Russia beginning in 2027, while countries such as Poland and Israel have banned Chinese-made electric vehicles from entering military installations.
  • Other jurisdictions, such as the EU and California have instituted requirements to manage cyber security risks in connected and autonomous vehicles.
  • While national and cyber security concerns are predominantly cited as the reasoning for these prohibitions and restrictions, there could also be privacy implications regarding the use of connected vehicles.

Background

  • The US Department of Commerce’s Bureau of Industry and Security (BIS) issued a rule in 2025 prohibiting the sale of connected vehicles by manufacturers owned by, controlled by, or subject to the jurisdiction or direction of China or Russia, and vehicles using their software. BIS determined these transactions pose national security risks as companies from these countries may be compelled to share data or allow remote access to connected vehicles.
  • The EU General Safety Regulation (via regulation UN R155) requires that manufacturers implement a cybersecurity management system in the design and manufacture of vehicles, including requirements for risk assessment, mitigation measures, monitoring, testing, and reporting.
  • During INDU’s March 12 and 26, 2026, committee meetings on their study regarding Federal Government’s Electric Vehicle (EV) Policies, committee members and witnesses discussed privacy, cybersecurity, as well as national security concerns related to these vehicles that have led to bans in Poland (2026) and Israel (2025).

Lead: PRPA


Transport Canada’s Safety Framework for Connected and Automated Vehicles 2.0

Speaking points

  • Transport Canada has advanced a number of guidance pieces and strategies to address vehicle cyber security and guidelines for testing automated driving systems, as well as a Safety Framework for Connected and Automated Vehicles (2.0).
  • I am encouraged that Transport Canada has identified that, as these technologies continue to evolve at a rapid pace, we need to consider safety, security and privacy; and that they have directed organizations trialing these technologies to adhere to applicable privacy laws.

Background

  • In February 2025, Transport Canada published version 2.0 of Canada’s Safety Framework for Connected and Automated Vehicles, which provides information on the legislative and regulatory regime, non-regulatory guidance and tools for this sector.
  • The document provides an overview of domestic and international collaborations, automated vehicle-related research and testing, and their approach to road safety as connected and automated vehicle technologies advance.
  • It also highlights the roles of other federal departments such as the Canadian Transportation Agency, ISED, CBSA, as well as the OPC; and encourages organizations to consult PIPEDA and substantially similar legislation when trialing technologies. The document notes that PIPEDA provides a framework with both strong privacy protections and the flexibility to support businesses’ legitimate needs to access personal information.
  • The Framework encourages those conducting research and innovating in this area to continue to monitor progress in related areas like safety, artificial intelligence, privacy and cyber security.
  • Finally, it references a number of guidance pieces and government strategies, including the Transport Canada Vehicle Cyber Security Strategy (2021) that, among other priorities, focus on addressing emerging issues related to vehicle cyber security such as protecting privacy, digital infrastructure, supply chain security, aftermarket, and special vehicle considerations.

Lead: PRPA


Privacy considerations under the Investment Canada Act

Speaking points

  • The Investment Canada Act (ICA) allows the Government to review certain investments in Canada by non-Canadians for their overall economic benefit to Canada and for national security concerns.
  • Although these reviews do not require the government to consult with my Office, I am aware that, under the guidelines issued under the ICA, the Government may take into account various factors, including the potential of an investment to enable access to sensitive personal data that could be leveraged to harm Canada’s national security.

Background

  • National security reviews may be undertaken when an investment by a non-Canadian (a) establishes a new business in Canada; (b) acquires control of a Canadian business; or (c) acquires, in whole or in part, or establishes an entity carrying on operations in Canada (s. 25.1).
  • S. 25.3(6) of the ICA - if the Minister of Industry, after consulting the Minister of Public Safety, “is satisfied that an investment would be injurious to national security,” they shall refer the investment under review to the Governor in Council.
  • The Guidelines on the National Security Review of Investments (Mar. 2025 rev.), issued under s. 38 of the ICA, provide, at s. 9(xii), that the Governor in Council may take into account during national security reviews “[t]he potential of the investment to enable access to sensitive personal data that could be leveraged to harm Canadian national security through its exploitation”.
  • “Sensitive personal data” under the Guidelines includes but is not limited to personally identifiable health or genetic information; biometric information; financial information; communications; geolocation; and personal data concerning government officials.
  • S. 25.4 of the ICA - the Governor in Council may, by order, take any measures in respect of the investment that he or she considers advisable to protect national security, including (a) direct the non-Canadian not to implement the investment; (b) authorize the investment subject to terms and conditions; or (c) require the non-Canadian to divest from the investment.

Lead: PRPA / LEGAL


TikTok

Speaking points

  • My Office, along with its counterparts in Quebec, British Columbia and Alberta, completed a joint investigation into TikTok and published the report of findings on September 23, 2025.
  • Our investigation found serious deficiencies in TikTok’s age assurance mechanisms, which allowed hundreds of thousands of Canadian children under the age of 13 to access TikTok each year, contrary to the company’s own terms.
  • We also found that TikTok failed to obtain meaningful consent from adults and teens for its collection and use of user data, including sensitive data of younger users and biometric data.
  • I am pleased that TikTok committed to improving its age assurance measures to keep children off its platform and to enhance its privacy communications to ensure meaningful consent.
  • My Office is currently monitoring TikTok’s implementation of our recommendations.

Background

  • The investigation was launched in February 2023 in the wake of now-settled class-action lawsuits in the United States and Canada, and numerous media reports related to TikTok’s collection, use and disclosure of user data.
  • The investigation namely examined whether TikTok was collecting children’s personal information for an appropriate purpose.
  • The entity under investigation was TikTok Pte Ltd. (Singapore-based company) as it is the business entity responsible for Canadians’ personal information and TikTok’s privacy practices.
  • It should be noted that we did not specifically inquire about whether, or the extent to which, the Chinese government has compelled TikTok or affiliate companies to provide access to data of users located in Canada.
  • One of our recommendations to TikTok was that the organization must enhance its privacy communication to support meaningful consent. This should include, without limitation, notice that Canadian users’ personal information may be transferred to China and accessed by the Chinese government.

Lead: COMPLIANCE


ArriveCan Special Report

Speaking points

  • On March 12, 2026, my Office tabled a Special Report in Parliament regarding an investigation into the Canada Border Services Agency (CBSA)’s contracting practices related to the development of the ArriveCAN app.
  • The investigation assessed the CBSA’s compliance with the Privacy Act by examining the measures it took to mitigate privacy risks associated with the use of contracted resources.
  • My investigation found no evidence to suggest that personal information collected through the app was used or disclosed in contravention of the Act.
  • While no contraventions were found, the investigation identified certain shortcomings in procurement practices that could have an impact on privacy.
  • My Office made four recommendations to address these shortcomings, which the CBSA accepted.

Background

  • The investigation was launched in March 2024 following the receipt of a complaint.
  • The investigation also took into consideration the issues raised in the motion tabled by the House of Commons Standing Committee on Government Operations and Estimates (OGGO) on May 6, 2024.
  • Specifically, OGGO requested that the OPC investigate the work of all contractors and subcontractors who worked on ArriveCAN to determine whether the privacy and personal information of Canadians was adequately protected.
  • The OPC recommended that the CBSA: i) ensure that security requirements are rigorously and accurately assessed and completed within a reasonable time prior to contract award; ii) ensure that Task Authorization task descriptions clearly and accurately define the projects or work to be performed to ensure that privacy and security requirements specific to those tasks or projects are accurately identified and assessed; iii) proactively manage security clearances and renewal processes with rigour and strong oversight; and iv) restrict permissions and access to personal information to what is strictly necessary.

Lead: COMPLIANCE


C-2: Strong Borders Act

Speaking points

  • Most of the provisions originally introduced in Bill C-2 have since been reintroduced in Bill C-12, which received royal assent in March 2026, and in Bill C-22, which is currently at second reading in the House.
  • It is not clear whether or when the Government intends to move forward with the remaining provisions in Bill C-2, some of which have implications for privacy.
  • My office remains committed to advising departments and agencies on how to mitigate potential privacy risks or impacts in any legislative, program, or policy proposals that they may be developing.

Background

  • Bill C-2 was introduced in the House by the Minister of Public Safety in June 2025. In October 2025 the Minister introduced Bill C-12 (the Strengthening Canada’s Immigration System and Borders Act), which consisted of 11 parts originally put forward in Bill C-2 but excluded some of its most controversial elements, notably:
    • amendments to the Canada Post Corporation Act to permit the demand, seizure, detention, or retention of anything in the course of post in accordance with an Act of Parliament and to enable Canada Post to open letter mail (Part 4);
    • amendments to the Criminal Code, the CSIS Act, and a number of other statutes to create or modify a range of investigative powers (including a warrantless “information demand”) (Part 14);
    • the proposed Supporting Authorized Access to Information Act, which would require electronic service providers to have the technical and operational capabilities to facilitate access to information by authorized persons (Part 15); and,
    • amendments to the PCMLTFA and PIPEDA to establish new authorities for reporting entities under the PCMLTFA to collect and use personal information without knowledge or consent when it is disclosed to them by the RCMP or other prescribed government entities for the purposes of detecting or deterring money laundering, terrorist-activity financing, or sanctions evasion (Part 16).
  • In March 2026, the Minister introduced Bill C-22 (the Lawful Access Act, 2026), which reintroduces the provisions originally contained in Parts 14 and 15 of Bill C-2.
  • The proposed amendments to the Canada Post Corporation Act and to the PCMLTFA remain in Bill C-2.

Lead: PRPA


C-8: An Act Respecting Cybersecurity

Speaking points

  • The OPC supports the objective of Bill C-8 to protect systems and services that are vital to national security or public safety from cybersecurity threats and vulnerabilities.
  • Stronger cybersecurity protections can also promote privacy by reducing the likelihood and impact of breaches involving personal data.
  • In my view, several amendments adopted in the last Parliament and more recently by the House help ensure that the bill achieves an appropriate balance between privacy interests and cybersecurity objectives.

Background

  • Part 1 of Bill C-8 would amend the Telecommunications Act to add promoting the security of Canada’s telecommunications system as a policy objective and to provide the GIC and Minister of Industry with order-making powers to that end.
  • Part 2 would enact the Critical Cyber Systems Protection Act, which would authorize the GIC to designate certain services or systems in federally regulated sectors as “vital” (e.g., energy, finance, transportation, and telecommunications); to identify classes of operators that would be subject to cybersecurity directions and regulations; to issue cybersecurity directions; and to require designated operators to establish and implement cybersecurity programs, mitigate supply-chain, and report cybersecurity incidents.
  • You appeared before the House Standing Committee on Public Safety and National Security on C-8 in October 2025 and sent a follow-up letter thereafter.
  • The House has since adopted several privacy-enhancing amendments based on or inspired by your advice, including:
    • the insertion of more consistent necessity and reasonableness requirements throughout the bill;
    • the addition of privacy impacts as a factor that the Minister and the GIC must consider when making orders;
    • the addition in Part 1 of language stipulating that personal and de-identified information is deemed confidential by default; and
    • a general requirement that personal information collected or obtained under both Parts 1 and 2 be disposed of if it is no longer necessary.

Lead: PRPA


C-16: Protecting Victims Act

Speaking points

  • Bill C-16 criminalizes the non-consensual distribution of certain deepfakes, and also contains other privacy-impactful criminal law amendments that my office is presently reviewing. I am supportive of many of the elements of this Bill.
  • I note that the Bill includes a significant expansion of authorized information sharing, which could be made more privacy-protective.
  • An effective response to the issue of deepfakes must extend beyond the criminal law. My office needs stronger enforcement tools such as order-making powers to more effectively hold organizations to account. I also support the need for comprehensive online harms legislation.

Background

  • C-16 received first reading in December 2025 and is currently being studied by the House Standing Committee on Justice and Human Rights.
  • Scope of s. 162.1: this offence applies to “intimate images”, which includes deepfakes that depict a person as either “nude”, “exposing their sexual organs”, or “engaged in explicit sexual activity” (s. 162.1(2) of the Criminal Code). Other categories of deepfakes would not be covered, including for example deepfakes of children that do not meet the above criteria.
  • Other privacy protective features: Bill C-16 limits reliance on evidence of a complainant’s past sexual history, as well as on private records such as therapeutic records, in certain criminal prosecutions under the Criminal Code (ss. 276-276.13 and 278.1-278.38 of the Criminal Code). These amendments will potentially limit the disclosure of sensitive information during the prosecution of sexual offences.
  • Areas of potential concern in Bill C-16: Bill C-16 contains broad information-sharing authorities for Correctional Services Canada with relatively low thresholds (see proposed ss. 25.1-25.4 of the Corrections and Conditional Release Act).
  • Former Bill C-63 proposed the Online Harms Act which would have regulated “social media services” and set out an arms-length regulatory structure. A new online harms bill is expected soon.
  • Private Members Bill C-216 (currently at first reading in the House) is presented as an alternative to Bill C-63. It would apply exclusively to minors and regulates Internet “operators”. Rather than creating a new regulatory structure, it would extend the role of the Canadian Radio-television and Telecommunications Commission (CRTC).

Lead: PRPA


C-22: Lawful Access Act

Speaking points

  • Bill C-22 incorporates important changes that reflect some of the feedback that the Government received on Bill C-2: to that extent, it is a distinct improvement over its predecessor.
  • However, despite its improvements, the Bill continues to pose risks to privacy, and certain changes have also introduced new concerns.
  • I look forward to the opportunity to provide my views on the Bill once it reaches committee stage.

Background

  • Bill C-22 incorporates several notable improvements over Bill C-2, including:
    • the previous “information-demand” power has been replaced with a narrowly tailored “confirmation-of-service demand” that can be served only on telcos;
    • a new oversight role for the Intelligence Commissioner with respect to orders under the proposed Supporting Authorized Access to Information Act (SAAIA); and
    • a new requirement in the SAAIA for the Minister of Public Safety and the GIC to consider the impacts of orders or regulations on privacy and cybersecurity.
  • Despite such improvements, Bill C-22 also inherits or creates a number of privacy risks, including:
    • the definition of subscriber information remains too broad in that it would capture not only basic identifiers but also potentially sensitive information about the nature of the services provided;
    • the scope of the persons that may be served with production orders for subscriber information remains too broad (any person who provides services to the public), and the threshold (reasonable suspicion) is too low in light of the information’s potential sensitivity; and,
    • under proposed authorities in the SAAIA, the government could require a wide range of electronic service providers to retain metadata for up to one year, without any grounds, which significantly exceeds the 90-day limit for preservation orders under the Criminal Code and the CSIS Act (both of which also require judicial pre-authorization based on reasonable suspicion).

Lead: PRPA


C-25: Strong and Free Elections Act

Speaking points

  • I am aware that on March 26, 2026, the Government tabled Bill C-25, the Strong and Free Elections Act, which would in part establish new privacy policy requirements for the protection of personal information held by political parties.
  • While these requirements represent an improvement over the status quo, I have recommended that political parties should be subject to privacy rules that are analogous to those set out for public and private sector organizations under federal law.
  • I look forward to sharing my full views with Parliamentarians once Bill C-25 has been referred to Committee for further study.

Background

  • Among changes, Bill C-25 would add new content requirements for a party’s policy for the protection of personal information under s. 446.6 of the Canada Elections Act. For example, a party’s policy would also need to require the party to:
    • Protect personal information through physical, organizational and technological safeguards;
    • Ensure that any person or entity to which it transfers personal information provides a level of protection equivalent to that the party is required to provide under their policy;
    • Prohibit the party, or any person or entity acting on its behalf, from providing false or misleading information about why the party collects personal information; selling personal information; or disclosing personal information to the public to cause harm
  • It would also add a requirement for parties to notify affected individuals in the event of privacy breaches where there is a real risk of significant harm to the individual.
  • At the time of writing, Bill C-25 remains at Second Reading in the House and has yet to be debated – however, given the subject matter, it will very likely be referred to the Procedure and House Affairs Committee (PROC) for study before summer.
  • Your last appearance on this issue was before the Senate Legal and Constitutional Affairs Committee on Part 4 of Bill C-4. That Bill was adopted unamended after recommendations of the Senate were rejected.

Lead: PRPA


C-230: Debt Forgiveness Registry

Speaking points

  • Tabled in September 2025, C-230 would require the President of the Treasury Board to establish a public registry of large debts and obligations owed by certain entities to the Crown that have been waived, written off or forgiven.
  • During consideration at the Standing Committee on Public Accounts, the Chair asked that I submit my views for their consideration, which I did on March 19, 2026.
  • In my submission, I noted that potential impacts to privacy, if any, would be minor given the information at stake appears to be that of corporations, trust companies, and partnerships rather than the personal information of individuals.

Background

  • In your submission you noted that, without more information or context about what information could be requested, it is possible that there may be privacy implications associated with s.25.1(2)(e) of Bill C-230, which states:

    “The registry must include the following information in relation to each debt, obligation or claim: […] (e) any other information that the President of the Treasury Board may require”.

  • However, you noted that s. 151(2)(f) of the Financial Administration Act already serves as an example where the wording “any other information that the President of the Treasury Board may require” is used with respect to quarterly reports on the activities of Crown corporations, and that the Office is not aware of any privacy concerns having arisen in relation to this existing provision.
  • At the time of writing, Bill C-230 remains under study at the House Standing Committee on Public Accounts.

Lead: PRPA


Date modified: