{"id":125094,"date":"2026-07-10T22:48:07","date_gmt":"2026-07-10T22:48:07","guid":{"rendered":"https:\/\/www.europesays.com\/canada\/125094\/"},"modified":"2026-07-10T22:48:07","modified_gmt":"2026-07-10T22:48:07","slug":"canadas-bill-c-36-tackles-ai-privacy-is-it-enough-privacy-news","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/canada\/125094\/","title":{"rendered":"Canada\u2019s Bill C-36 tackles AI privacy. Is it enough? | Privacy News"},"content":{"rendered":"<p>Vancouver, Canada: In an era of artificial intelligence, deepfakes and data-driven decision-making, Canada is moving to revise its privacy laws through Bill C-36, the Protecting Privacy and Consumer Data Act.<\/p>\n<p>Announced in June, Bill C-36 is Canada\u2019s first major overhaul of private-sector privacy legislation in more than 25 years. The bill explicitly recognises privacy as a fundamental right and also aims to give children\u2019s personal information stronger protections, enhance deletion rights and require greater transparency where automated systems make significant decisions about people.<\/p>\n<p>Recommended Stories list of 4 itemsend of list<\/p>\n<p>The reforms also arrive amid growing scrutiny of AI after incidents such as British Columbia\u2019s Tumbler Ridge shooting in February raised greater questions about AI chatbots, vulnerable users and the responsibilities of technology companies.<\/p>\n<p>The 18-year-old shooting suspect allegedly used ChatGPT before the attack. The <a href=\"https:\/\/www.aljazeera.com\/economy\/2026\/4\/29\/families-sue-openai-alleging-chatbot-aided-in-canadian-school-shooting\" target=\"_blank\" rel=\"noopener nofollow\">victims\u2019 families are now suing OpenAI<\/a>, stating the company\u2019s AI safety team identified violent prompts but did not alert law enforcement. This week, the province of British Columbia also announced it is \u201c<a href=\"https:\/\/www.aljazeera.com\/news\/2026\/7\/7\/canadian-province-sues-openai-over-alleged-chatgpt-linked-shooting-warnings\" target=\"_blank\" rel=\"noopener nofollow\">preparing legal action<\/a>\u201d against the AI company.<\/p>\n<p>Meanwhile, Canada\u2019s federal government plans to modernise private-sector consumer privacy rules via Bill C-36.<\/p>\n<p>Evan Solomon, Canada\u2019s minister of AI and digital innovation, told Al Jazeera that the government\u2019s responsibility is \u201cto protect Canadians online and to ensure Canadians can benefit from artificial intelligence and emerging technologies. These goals are not mutually exclusive\u201d.<\/p>\n<p>\u201cBill C-36 establishes a framework for the responsible use of de-identified data. It includes safeguards designed to reduce the risk of re-identifying individuals while supporting important public-interest activities, including research, accountability and innovation.\u201d<\/p>\n<p>But as AI systems become more capable of predicting, profiling and influencing people, experts say the challenge is no longer just what data companies collect \u2014 it is what AI can infer from users.<\/p>\n<p>The question is whether privacy legislation can keep pace with technology designed to predict, profile and influence human behaviour.<\/p>\n<p>Inferred information<\/p>\n<p>The biggest issue is that AI is changing where privacy harms occur, according to Ignacio Cofone, professor of law and regulation of AI at the University of Oxford.<\/p>\n<p>\u201cOlder privacy law assumes the danger is in what a company collects from you. The danger now is in what a company infers about you from data you never handed over, and in what it does with that AI inference.\u201d<\/p>\n<p>In other words, today\u2019s AI systems don\u2019t necessarily need someone to disclose sensitive information voluntarily. Patterns in shopping habits, browsing history, location data or online activity can be enough for algorithms to make surprisingly accurate predictions about a person\u2019s health, finances or behaviours.<\/p>\n<p>\u201cA model trained on [anonymous] data can produce decisions that disadvantage a category of people without pointing at a named individual who can complain,\u201d Cofone told Al Jazeera.<\/p>\n<p>Bill C-36 responds by expanding the definition of personal information to include inferred information and requiring organisations to explain certain automated decisions.<\/p>\n<p>But, as Cofone argues, the real challenge is in ensuring regulation targets harmful uses of AI rather than just data collection.<\/p>\n<p>\u201cA model can predict your health, your sexuality, or your creditworthiness from unrelated traces and then act on the prediction, with no data leak or breach in a conventional sense,\u201d he said.<\/p>\n<p>\u201cThat matters enormously because it moves the law toward where AI harm actually occurs, the inference and the decision, rather than leaving it fixed on the act of collection.\u201d<\/p>\n<p>Protecting children online<\/p>\n<p>Protecting children\u2019s privacy is one of Bill C-36\u2019s headline reforms. The legislation would classify information belonging to anyone under 18 as inherently sensitive and gives young people stronger rights to have their personal information deleted.<\/p>\n<p>For Stephany Oliveros, ethical AI lecturer and CEO of Just Lyra, an AI talent-matching platform, data privacy and consent are about user agency.<\/p>\n<p>\u201cIt\u2019s one thing to donate my data towards cancer research, but another thing if tech firms find out the blood type and behaviours of my kid. Like, why does Facebook need to know that?\u201d<\/p>\n<p>Cofone added that the changes that come with Bill C-36 are worthwhile but only address part of the problem.<\/p>\n<p>\u201cIt will help, modestly, and less than the framing suggests. The bill does two things for children: It treats a child\u2019s information as sensitive, which raises the bar for consent and for the security an organisation owes, and it gives children a stronger deletion right. Both are useful.\u201d<\/p>\n<p>But, he said, the bigger challenge lies elsewhere.<\/p>\n<p>\u201cThe heavier protections people need with children online are age-appropriate design and limits on what platforms can do.\u201d<\/p>\n<p>According to Jill Ma, a tech founder who works in children\u2019s AI products, beyond privacy, the next frontier is algorithmic fairness.<\/p>\n<p>\u201cPrivacy isn\u2019t just about controlling data; it\u2019s about not being misjudged by an algorithm,\u201d she said. \u201cA child\u2019s early digital footprint shouldn\u2019t become a lifelong label. Our job as [product] builders is to teach AI how to respect people, not just collect their data.\u201d<\/p>\n<p>For concerned parents such as Martin Haucke, a Vancouver-based father of one, the greater issue is the cultural norm around internet permissiveness for children.<\/p>\n<p>\u201cThe physical world is the safest it\u2019s ever been, and the online world is what poses the biggest threats to kids\u2019 safety,\u201d he said. \u201cAnd yet we are treating the real world as a dangerous place and are cavalier about our kids having phones before they hit high school.\u201d<\/p>\n<p>Earlier this year, Ottawa introduced separate legislation proposing restrictions on social media access to platforms such as TikTok for users under 16. Other governments around the world have also begun responding in kind. Last year, Australia passed legislation to restrict access to certain social media platforms for under-16s.<\/p>\n<p>\u201cIt\u2019s backwards,\u201d said Haucke, who is also a school teacher. \u201cWhat we need are zero phones in school. More time outdoors socialising.\u201d<\/p>\n<p>Privacy is only one part of the solution<\/p>\n<p>Privacy is only one part of governing AI. Experts say future AI laws will need to balance user safety, journalism and public interest.<\/p>\n<p>\u201cAs technologies continue to evolve,\u201d Solomon said. \u201cWe will continue engaging with researchers, journalists, privacy experts, civil society and other stakeholders to ensure Canada\u2019s privacy framework remains effective, balanced and responsive to Canadians\u2019 expectations.\u201d<\/p>\n<p>One example of such a challenge is the bill\u2019s treatment of de-identified information, an issue that has prompted debate among privacy experts, researchers and journalists.<\/p>\n<p>While the legislation seeks to prevent organisations from reconstructing people\u2019s identities from de-identified datasets, experts such as Oxford law\u2019s Cofone say that this comes down to how organisations and researchers should be allowed to use de-identified data responsibly.<\/p>\n<p>\u201cI would separate the two concerns. On journalism, the bill keeps the exemption for journalistic, artistic and literary work,\u201d he said. \u201cInvestigative journalism is protected, as it was under the old law. The harder problem is research, which turns on how the bill draws the line between de-identified and anonymised data.\u201d<\/p>\n<p>Oliveros, the ethical AI lecturer who has also collaborated with the United Nations, says this debate goes beyond legal definitions of privacy and should address accountability. Restricting access to data could make it harder for journalists and human rights organisations to uncover wrongdoing, she said.<\/p>\n<p>\u201cWatchdogs cannot rely on corporate summaries,\u201d Oliveros told Al Jazeera. \u201cTo find environmental racism, algorithmic bias or predatory lending, journalists and human rights groups need access to granular, line-by-line data. If Bill C-36 locks this data down entirely under the banner of privacy, it inadvertently shields powerful corporations from public accountability. Privacy must not become a legal cloak for corporate secrecy.\u201d<\/p>\n<p>But there may not be any easy answers.<\/p>\n<p>\u201cIf the definition of a public-interest researcher is too loose, the law fails. But if it is too rigid, it shuts out independent journalists and grassroots NGOs who do the heavy lifting in human rights work,\u201d Oliveros said.<\/p>\n<p>While the bill focuses on protecting personal information, Eric Wishart, journalism ethics author and professor at the University of Hong Kong, says privacy laws should preserve journalism\u2019s ability to hold accountable those in power as well as the public\u2019s right to know.<\/p>\n<p>He pointed to the United States-Israel conflict with Iran as one example.<\/p>\n<p>\u201cThere was very little information released by the Pentagon about attacks on Iran, so journalists were depending on imagery from [satellite imagery platform] Planet Labs to track the damage. It was a key source that showed the sites hit by bombing, but then Planet Labs announced it was withholding imagery from the war at the request of the US government.\u201d<\/p>\n<p>\u201cWe have to balance the need to protect people\u2019s privacy against journalists\u2019 right to carry out investigative work in the public interest,\u201d he said. \u201cLegislation designed to address the legitimate privacy concerns of private individuals, including children, should not prevent journalists from investigating potential wrongdoing by public figures or holding power to account.\u201d<\/p>\n<p>Bill C-36 may represent Canada\u2019s most significant privacy reform in decades, but the challenge for governments will be ensuring regulation evolves as quickly as the technology itself as AI becomes increasingly capable of predicting behaviour, influencing decisions and reshaping daily life.<\/p>\n<p>For Oliveros, the debate ultimately comes down to who holds power in an AI-driven world.<\/p>\n<p>\u201cData privacy rights shift the power dynamic, so the power is back onto you,\u201d she said. \u201cYou own something \u2014 your identity.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"Vancouver, Canada: In an era of artificial intelligence, deepfakes and data-driven decision-making, Canada is moving to revise its&hellip;\n","protected":false},"author":2,"featured_media":125095,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[433,17,41931,235,229,116,8067,12268,1194,236,438],"class_list":["post-125094","post","type-post","status-publish","format-standard","has-post-thumbnail","category-canada","tag-business-and-economy","tag-canada","tag-child-rights","tag-economy","tag-government","tag-news","tag-privacy","tag-science-and-technology","tag-social-media","tag-technology","tag-us-canada"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/canada\/wp-json\/wp\/v2\/posts\/125094","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/canada\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/canada\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/canada\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/canada\/wp-json\/wp\/v2\/comments?post=125094"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/canada\/wp-json\/wp\/v2\/posts\/125094\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/canada\/wp-json\/wp\/v2\/media\/125095"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/canada\/wp-json\/wp\/v2\/media?parent=125094"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/canada\/wp-json\/wp\/v2\/categories?post=125094"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/canada\/wp-json\/wp\/v2\/tags?post=125094"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}