This first step is to get a grip on the realities of privacy in the Age of AI. Let’s hope it works. The post Op-Ed: Canada rewrites the rules on AI privacy with Bill C-36, and this is just the start appeared first on Digital Journal .
Bill C-36, the Protecting Privacy and Consumer Data Act, is a broad-based initiative to try to manage privacy issues, notably for children. This is the first major revision of Canadian privacy laws in decades, targeting AI security risks. The Bill is also a good example of how incredibly complex the statutory regulation of data privacy has become as AI emerges as the driving factor of digital life.
It’s a very demanding environment for managing basic laws at the most fundamental level. In practice, Bill C-36 could include simple privacy issues or broad-spectrum breaches of privacy as big as the recent major data breaches. In its current form, the Bill looks very much like a catch-all for privacy issues on any scale.
With constant and increasing global demands for effective AI governance, Bill C-36 may well become a test case for the future of AI regulation worldwide. This is also no easy target on any practical enforcement level. Bill C-36 covers such a huge range of potential future issues.
The actual legislation now before for the first reading to Parliament includes 147 specific sections. The summary section of Bill C-36 is an indicator of degrees of difficulty: This enactment enacts the Protecting Privacy and Consumer Data Act to govern the protection of personal information of individuals while taking into account the need of organizations to collect, use or disclose personal information in the course of commercial activities. That’s a very broad base for the regulation of just about anything and everything related to privacy, compliance, and enforcement.
The other big issue in this legislation is “data inference”, not just the hard data gathered online, but indirect profiling and patterns used to identify people and markets. This is a major privacy issue in that people can be identified by inferences derived from both hard data and “disparate data,” building a picture of their health, financial issues, and more. It’s the working machinery of targeted ads, phishing, and the de facto
Source and reference
source of profiling. People can be indirectly identified by behaviours and other patterns. With the advent of AI, inferences have come into a whole new frame of reference for regulation. In legal terms, it’s a sandbox. The new terminology refers to “deidentification” and “reidentification”, which describe the process of privacy being eroded or completely destroyed by AI inferences. This also exposes the near-total inadequacy of current privacy laws. These processes didn’t even exist when most privacy laws were enacted. The role of Bill C-36 The draft bill includes functional roles in Part 2, including multiple delegations: Establishment of a Commission and its powers, duties, and functions The appointment of a Commissioner Division Codes of Practice and Certification Remedies Filing of Complaints Investigation of Complaints Compliance Agreements Audits Appeals Enforcement of Orders...
Read original source- Published
- Jul 11, 2026
- Updated
- Jul 11, 2026
- Source
- Digital Journal
- Category
- Technology
- Read time
- 5 min
Key facts
Why this matters locally
This technology story matters locally because it may affect readers, businesses, commuters, families, or public services in British Columbia.
Local impact
BC Post links this item to British Columbia coverage so readers can follow related city updates, weather, traffic, events, and category news in one place.
Timeline
Source and credit
BC Post may summarize, organize, and add local context for reader clarity. Original reporting remains with the listed publisher.