Canada (Federal)
Privacy Commissioner of Canada
The Privacy Commissioner of Canada heads the Office of the Privacy Commissioner (OPC), an independent agent of Parliament responsible for overseeing compliance with Canada's two main federal privacy statutes. The Commissioner investigates complaints, conducts audits and research, reviews federal institutions' privacy impact assessments, and reports to Parliament on federal privacy matters. The office can bring matters before the Federal Court but, outside Quebec, Alberta and British Columbia's private-sector regimes, generally cannot issue binding orders itself — most findings take the form of recommendations, with court referral as a backstop.
Laws and regulations administered:
- Personal Information Protection and Electronic Documents Act (PIPEDA) — governs the collection, use, and disclosure of personal information by private-sector organizations in the course of commercial activity, in provinces without their own substantially similar law (see the provincial pages for Quebec, British Columbia, and Alberta, which have their own private-sector regimes).
- Privacy Act — governs how federal government institutions collect, use, and disclose personal information, and gives individuals a right to access and correct their own information held by those institutions.
Information Commissioner of Canada
The Information Commissioner of Canada leads the Office of the Information Commissioner (OIC), an independent agent of Parliament that oversees federal access-to-information rights. The Commissioner investigates complaints from individuals and organizations who believe a federal institution has improperly withheld records, mediates disputes between requesters and institutions, and — since 2019 reforms — has the power to issue binding orders for the release of records, subject to review by the Federal Court. The office also reports publicly on institutions' access-to-information performance.
Laws and regulations administered:
- Access to Information Act — gives Canadian citizens, permanent residents, and others present in Canada a right to request records held by federal government institutions, subject to specific exemptions and exclusions.
Other federal legislation of note
-
Canada's Anti-Spam Legislation (CASL) — regulates the sending of commercial electronic messages and the installation of computer programs without consent. CASL is unusual in having three joint enforcement bodies: the CRTC (the lead enforcer, which monitors the Spam Reporting Centre and issues warnings and penalties), the Competition Bureau (which pursues false or misleading electronic marketing under the Competition Act), and the OPC (which addresses the privacy-violation dimension of unsolicited electronic communications), all drawing on the same shared complaints database.
-
Bill C-8 — Critical Cyber Systems Protection Act, the successor to the earlier, similarly contested Bill C-26, received Royal Assent in June 2026. It creates a mandatory cybersecurity framework for critical infrastructure operators in telecommunications, finance, energy, and transportation, and amends the Telecommunications Act to let the government order the removal of high-risk equipment or suppliers from federally regulated networks.
This law passed with privacy concerns still unresolved, by the Commissioner's own account. The government frames it as necessary protection for critical infrastructure against emerging cyber threats. Even after House amendments — the Minister of Public Safety said two or three of five recommendations from the Privacy Commissioner's office were incorporated — the Commissioner has said publicly that "the legal thresholds for exercising these new government powers remain too broad," and flagged the absence of a mandatory breach-notification requirement to his office and weak privacy safeguards on international information-sharing. The Citizen Lab separately warned the bill authorizes the Minister of Industry to compel telecom companies to hand over data with no warrant requirement — a gap Canada's Intelligence Commissioner himself called unusual in committee testimony ("In all cases I've known, you need a warrant... In the present bill, there is no such warrant requirement") — and that its broad ministerial order powers could be used to weaken encryption or allow information collected for cybersecurity purposes to be repurposed by CSIS or CSE beyond the bill's stated scope.
- Bill C-12 — Strengthening Canada's Immigration System and Borders Act received Royal Assent in March 2026. It is primarily an immigration and border-security bill (refugee-claim processing, CBSA authorities), introduced after the government split the original lawful-access provisions out of Bill C-2 into what eventually became Bill C-22, below. The Privacy Commissioner appeared before parliamentary committees on this bill twice (November 2025 and February 2026), which signals it has a real privacy dimension — likely touching information-sharing between CBSA, IRCC, and other agencies — but the specific provisions at issue haven't been independently verified for this page yet. Flagged here as a gap to close, not a finished entry.
Pending and proposed federal legislation
- Bill C-36 — Protecting Privacy and Consumer Data Act (PPCDA) (backgrounder), tabled June 15, 2026, would repeal Part 1 of PIPEDA and replace Canada's private-sector privacy framework. This is the third attempt in six years to reform PIPEDA, following failed bills in 2020 and 2022–23 (including the privacy-reform half of Bill C-27, discussed below). Notable elements include: recognizing privacy as a fundamental right; expanding "personal information" to expressly cover information inferred about an individual (capturing AI-generated profiling); a risk-based anonymization standard; mandatory privacy impact assessments for cross-border transfers and for relying on the "legitimate interest" exception; new rights to deletion, data portability, and human review of automated decisions; and administrative penalties of up to the greater of $10 million or 3% of global revenue. Most significantly for this page's structure, the bill would move enforcement out of the OPC and into a newly created Digital Safety and Data Protection Commission of Canada, housing a dedicated Privacy and Consumer Data Commissioner — with the existing Privacy Commissioner's role narrowed to the federal public sector (the Privacy Act side of the office's current mandate). That transfer is contingent on the companion Bill C-34 also passing. As of the bill's first reading, Parliament had adjourned for the summer and was due to resume September 21, 2026; the bill was at second reading and had not yet reached committee study. If this passes, this page's regulator structure for Canada will need to be revised accordingly.
This bill is contested. The government frames it as balancing two goals: enabling the innovation and AI opportunity it sees in "digital and data-driven technologies," while strengthening individual control through meaningful-consent requirements, stronger children's-data protections, security assessments before cross-border transfers, and a well-resourced dedicated enforcement body with real penalties. The Canadian Civil Liberties Association has taken the opposite view, calling the bill's "fundamental right" language rhetorical and arguing it actually promotes "personal data commodification" — pointing specifically to the "legitimate interest" exception and to a de-identification (as opposed to full anonymization) standard that, in the CCLA's reading, lets businesses retain personal data indefinitely with only light-touch consent obligations. The CCLA also argues the bill does little to address AI-specific harms despite being framed around the government's AI strategy, does not extend meaningful privacy obligations to federal political parties, and provides no new oversight of police access to data held by private companies.
- Bill C-22 — Lawful Access Act, 2026 (Fasken backgrounder), tabled March 12, 2026, is the successor to the lawful-access provisions (Parts 14–15) the government originally buried inside Bill C-2, the Strong Borders Act, in June 2025, then withdrew after sustained criticism and re-tabled as this standalone bill. Part 1 creates new "confirmation of service demands" and lowers the threshold for court-authorized subscriber-information production orders from "reasonable grounds to believe" to "reasonable grounds to suspect," while narrowing C-2's original scope to telecommunications providers and adding Intelligence Commissioner approval of ministerial orders. Part 2 enacts the Supporting Authorized Access to Information Act (SAAIA), which lets the Minister of Public Safety issue secret orders compelling a broadly defined set of "electronic service providers" — potentially extending beyond telecoms to messaging apps, cloud services, and connected devices — to build interception and monitoring capability into their systems, with data-retention obligations of up to a year and no sunset clause on the associated secrecy requirements. The bill passed third reading in the House of Commons after the government moved closure to limit debate, and was before the Senate as of this writing.
This bill is heavily contested. The government's position, per the Public Safety Minister's office, is that "the existing regime is poorly adapted to the migration of criminal activity to the online and increasingly global context," citing slow cross-border evidence requests and intercept obligations that currently apply only to wireless carriers. A coalition of 29 organizations — including the Canadian Civil Liberties Association, the BC Civil Liberties Association, OpenMedia, and privacy scholars Ron Deibert and Teresa Scassa — has called Part 2 "a mass surveillance capability regime," warning it would compel near-universal metadata retention and mandate security backdoors, pointing to the 2024 Salt Typhoon incident (in which a US-mandated intercept backdoor was exploited by state-linked hackers) as the realized version of that risk. Critics including Michael Geist also object to the legislative process itself — the government's use of a programming motion to limit debate was called "the most aggressive... in five years" by Conservative critic Frank Caputo — separately from the bill's substance. Signal and NordVPN have both indicated they would consider leaving the Canadian market if the bill passes unchanged.
- Federal AI regulation: Canada has no dedicated federal AI statute currently in force. The Artificial Intelligence and Data Act (AIDA), which had been proposed as part of Bill C-27, died on the order paper in January 2025 when Parliament was prorogued, and unlike its predecessor, Bill C-36 does not revive standalone AI legislation. In the interim, AI use is governed indirectly through existing law (PIPEDA's consent requirements apply to personal data used to train or run AI systems) and through voluntary frameworks: ISED's Voluntary Code of Conduct on the Responsible Development and Management of Advanced Generative AI Systems, and the OPC's published AI principles for generative AI. The federal government appointed its first Minister of Artificial Intelligence and Digital Innovation in 2025 and has been running consultations toward a renewed national AI strategy expected later in 2026; no new AI bill had been introduced as of this writing.