L’été s’envole. Renouvelez votre adhésion à l’ABC et obtenez la série Maîtres en pratique sans frais.
Veuillez consulter notre FAQ ou communiquer avec l'équipe des Services aux membres.

Skip to main content

Faire entrer les lois canadiennes sur la protection de la vie privée dans l'ère numérique

10 juillet 2026

(Disponible uniquement en anglais)

Re: Modernizing Canada’s Privacy Act – Online Public Consultation

I write on behalf of the Canadian Bar Association’s Privacy and Access Section (CBA Section) in response to the Privacy Act modernization consultation.

The Canadian Bar Association is a national association of 40,000 members, including lawyers, notaries, academics and students across Canada, with a mandate to seek improvements in the law and the administration of justice. The CBA Section comprises lawyers across Canada with an in-depth knowledge of privacy and access to information law and policy.

Theme 1: Enabling Integrated Services

We agree with enabling integrated services but believe transparency requirements should include information with respect to challenging compliance. Safeguards before sharing data with provincial, territorial, or municipal partners should be defined. Standard data-sharing provisions are recommended and can be addressed in regulations. Any data-sharing arrangement for integrated services should be the subject of a published information-sharing agreement accessible through a central public registry.

We suggest establishing a principle of data minimization (collecting the minimum necessary information) as a statutory obligation applicable to all integrated service activities.

Also, an obligation to provide direct electronic notice to individuals when their personal information is shared with another institution, including the personal information that was shared and the program in respect of which their personal information is being shared.

Theme 2: Enhancing accountability and transparency

The CBA Section agrees with enhancing accountability and transparency.

We suggest Privacy Impact Assessments (PIAs) should be legally required for programs/activities involving personal information. Regs/policy should dictate the level of detail required based on factors such as the sensitivity and quantity of the personal information involved.  We agree that plain language summaries would improve public understanding. Institutions should be required to mitigate the risks identified in the PIAs and the PIA summaries should include a description of those mitigation measures.

The CBA Section agrees that replacing Personal Information Banks (PIBs)/classes of PI with single, centralized registry would improve transparency.

Automatic Decision Making (ADM): In addition to the transparency mechanisms proposed, institutions should be required to make available a general account of their use of any automated decision system to make predictions, recommendations or decisions about individuals that could have a legal or similarly significant effect on them. They should be cognizant of the additional risk of bias when processing data in French (system trained on Anglo-dominant data) and mitigate it. Be cognizant of weakness in human reviews and mitigate it as there is a tendency for humans to default to decisions/information provided by Artificial Intelligence (AI) or ADM as correct. Summaries of the PIAs should be required to be published with respect to ADMs.

We also agree with strengthening privacy notice requirements by using plain language/central register.

We suggest requiring proactive publication of all active information-sharing agreements.

Theme 3: Advancing safeguards across the spectrum of data sensitivity

The CBA Section agrees with all proposals under this theme.

With respect to proposal 7, we note that de-identified data about Indigenous communities specifically carries unique risks and requires unique considerations. E.g. Indigenous communities have long dealt with researchers using their information and data in ways that do not respect Indigenous data sovereignty. Also, Indigenous communities are small. Data about Grassy Narrows for example may appear de-identified to someone outside of the community, but individuals within or familiar with it may be able to recognize individuals in the data with ease. The risk of re-identification for data about Indigenous communities is often higher than other data sets.

Theme 4: Modernizing foundation for privacy and trust

The CBA Section agrees with most proposals.

Definitions should remain technologically neutral to be flexible as technology evolves.

Incorporating personal information access requests into the Access to Information Act (ATIA) requires study. There may be strong arguments for keeping the PI access regime in the Privacy Act. Having one single law regarding the government’s obligations and individuals’ rights with respect to their personal information is consistent with what exists in the private sector in this country. The success of Alberta’s changes to its regime should be reviewed to understand if they have had any positive impact with regards to the exercise of individuals’ access rights.

It’s unclear that it’s a given that the separation between the Privacy Act and ATIA is “confusing and inefficient”, as there is a clear delineation between access to government records generally and access and other protections regarding one’s own personal information. Further, access to personal information is an important element of a privacy scheme, and thus access rights should work harmoniously with that scheme. Finally, privacy oversight already exists in the Privacy Act through the OPC but does not under ATIA.

For proposal 12, we agree with the updating purpose clause to acknowledge privacy as a fundamental right, underscore importance of enabling services, and advance reconciliation with Indigenous peoples. We recommend these be set out separately and not joined into one clause so that important concepts can be explicitly addressed, such as compliance with UNDRIP and the recognition of Indigenous data sovereignty as a necessary precondition to inherent rights to self-determination and self-governance.

Theme 5: Indigenous Peoples’ access to, and protection of, their data

Regarding proposal 7, it is important to acknowledge that de-identified data concerning Indigenous communities carries unique risks that require special considerations, particularly because these communities have long faced challenges with researchers utilizing their information in ways that do not respect Indigenous data sovereignty. Because many Indigenous communities are small, data that appears de-identified to an outsider—such as information about Grassy Narrows—may remain easily recognizable to those familiar with the community, leading to a higher risk of re-identification than in other datasets. Consequently, while we agree with efforts to modernize out-of-date terminology and enhance protection/access rights for Indigenous Peoples’ data. Consultation with Indigenous groups on this matter is encouraged to ensure changes are consistent with Indigenous views and beneficial to Indigenous communities.

For proposal 16 and expanding data sharing under 8(2)(f), we agree it should be expanded but acknowledge that there are circumstances where Indigenous governments will need data to help enforce laws or carry out investigations but have not signed a self government agreement (SGA). For example, Indigenous nations can enact their own child protection legislation under An Act respecting First Nations, Inuit and Métis children, youth and families, S.C. 2019, c.24 without having a self government agreement in place. First Nations can also enact a land code under the Framework Agreement on First Nation Land Management, which becomes the basic land law of the First Nation, after which numerous sections of the Indian Act no longer apply. Expansion to just nations that have a self government agreement is still too limited. It’s possible to act on law making powers without a self government agreement.

As well, to the extent that the above or any future laws that similarly give law making powers without SGA include data reporting obligations, section 19(1) should be expanded beyond just Indigenous entities with modern treaty or SGA.

Theme 6: Updating the compliance framework

The CBA Section agrees to all proposals but ask to clarify whether the Privacy Commissioner would continue to exist even if Bill C-36 is enacted, or whether the public-sector oversight function would also been moved to the Digital Safety and Data Protection Commission of Canada and Privacy and Consumer Data Commissioner (presumably the former). In the public sector it makes more sense to have a Privacy Commissioner accountable to Parliament as opposed to a Commission whose members are appointed by cabinet.

Yours truly,

(original letter signed by Julie Terrien for Christiane Saad)

Christiane Saad, Chair,
Privacy Law and Access Section