Skip to Content

Bringing the Privacy Act into the digital age

The CBA agrees with many proposed changes to the Privacy Act, but has recommendations to strengthen transparency and the treatment of Indigenous peoples’ data

Glowing golden padlock over a futuristic circuit board and streams of blue data, symbolizing digital security, privacy, and encryption.
iStock/MF3d
National Members

Log in to listen to this article

In a nutshell

The Canadian Bar Association’s Privacy and Access Section broadly supports the proposed modernization of the Privacy Act but recommends safeguards to ensure privacy rights are not compromised. This includes Indigenous Peoples’ access to, and protection of, their data.

Key recommendations

The CBA recommends that:

  1. Data sharing for integrated services should be governed by published, registry-accessible information-sharing agreements with defined safeguards, mandatory data minimization, and direct electronic notice to individuals;
  2. Privacy Impact Assessments be legally required with plain-language summaries that describe risk mitigation;
  3. Automated decision-making systems be subject to public disclosure, bias mitigation (including for French-language processing), and scrutiny of human review weaknesses.

The CBA also highlights that de-identified data about small Indigenous communities carries heightened re-identification risks and must be handled in a way that respects Indigenous data sovereignty. The CBA recommends consulting with Indigenous groups and expanding data-sharing and enforcement provisions beyond entities with self-government agreements to include those exercising law-making powers under other federal laws.

Why this matters

Modernizing the Privacy Act must include stronger safeguards to ensure integrated services, accountability, transparency, and trust are realized without compromising privacy rights, particularly Indigenous data sovereignty.

Read the full submission