Is the feds’ digital privacy bill enlightened or uncertain?
The legislation proposes some radical changes, and critics say parts of it favour business interests over privacy
Log in to listen to this article
At first pass, Chantal Bernier was taken aback by some of the changes in Ottawa’s updated privacy legislation. But after some reflection, she’s come to see them as “enlightened.”
“It is both audacious and relevant,” Bernier, co-chair of Dentons' global privacy and cybersecurity group, and the former interim federal privacy commissioner, says of Bill C-36.
The legislation has been a long time in the making. Several previous attempts by the federal government to modernize the Personal Information Protection and Electronic Documents Act (PIPEDA) died on the order paper in successive parliamentary sessions.
The current version proposes something radical—removing most of the federal privacy commissioner's functions and transferring them to a member of the Digital Safety Commission, which will be created as part of the Digital Safety Act proposed in Bill C-34. That will leave the privacy commissioner responsible only for the federal public sector.
If Bill C-36 passes, Bernier says Canada will be the only country with a legal framework that addresses privacy protection, digital safety, and the overlapping challenges that arise when trying to enforce the rule of law online. Fundamentally, that’s a question of how to ensure compliance without falling into a surveillance regime, and where accountability rests.
“There are risks that are common to digital safety and privacy protection, and there are enforcement challenges to address these risks that are common to the two,” she says, pointing to a situation where someone’s personal information is used to produce a deepfake as both a privacy and a digital safety issue.
The fact that the new Digital Safety Commission is not an agent of Parliament doesn’t concern her, as she says the CRTC and the Competition Bureau, which are also not agents, still operate effectively.
‘A complete shift’
The new structure does concern some, however.
Teresa Scassa, the Canada Research Chair in Information Law and Policy at the University of Ottawa, says the shift will mean a loss of independence, credibility, experience, and networks.
“You’re handing it over to this weird structure where you have a five-person [Digital Safety] Commission with no particular privacy experience necessary under the legislation,” she says.
The Commission will oversee guidance, policy and research on privacy. One commissioner will be selected to oversee the investigation component, while the division will handle adjudication.
Scassa says the creation of this structure stems from a concern that policy needs to be separated from adjudication, particularly when there are order-making powers.
However, it contains features that undermine independence in significant ways, including renewable five-year commissioner terms, which lead to a loss of security of tenure. She also worries that the lack of an experienced privacy commissioner will mean a loss of vision and a strategic approach to privacy.
David Fraser, a partner with McInness Cooper in Halifax, doesn’t see a principle of restraint in the legislation, given that the privacy-focused Commission member will have order-making powers, but will be less independent from government than the current privacy commissioner. That means they could wind up taking direction from the minister they report to.
“If you’re going to give a commissioner the ability to recommend orders and penalties, give that to the existing privacy commissioner and have the Commission as the appeal tribunal.”
Fraser says having the privacy-focused digital commissioner in the same office as the enforcement body, with the same staff, makes it hard to separate judge, jury, prosecutor, and executioner.
Scassa says the Commission will likely fall under the minister of industry because, like businesses, the government views access to and use of data as an economic policy. The proposed legislation has framed digital security as an economic issue with some privacy dimensions, rather than a privacy issue in which you have to carve out space for economic activity.
“It’s a complete shift.”
While the use of personal data requires consent, Scassa worries that the current climate demands more, such as privacy by design and by default.
Bernier says the jury is still out on whether we can rely on consent for the use of personal data, and whether that reliance reflects the reality of the internet. As drafted, the legislation does allow some use of personal data without consent, but still puts the consumer firmly in the driver’s seat.
“My preference is to respect consumers’ autonomy, which is expressed through consent,” she says.
“The alternative would be…to construct a regulatory framework that would be very prohibitive, which would put very strict rules upon organizations, requiring opt-in for everything, which may not be realistic either.”
Bernier says the public benefits from internet searches and social media for free in exchange for ads and some use of personal information within reasonable limits. She’ll be looking to see whether the legislation has struck the right balance between reliance on consent to preserve consumer autonomy and its effectiveness in the digital context.
Legitimate use
Although most personal information requires consent for use, the legislation includes exceptions for legitimate use, which Scassa says organizations have been asking for. This allows them to collect or use information for an activity in which they have a legitimate interest, if that interest outweighs any foreseeable adverse effects on the individual. Under PIPEDA, there were set conditions for assessing legitimate interests, but those have since been extended to include disclosure.
With the advent of AI technologies, organizations have the ability to use that data in novel ways. While the current iteration of PIPEDA requires fresh consent to do so, under the new bill, with disclosure, the same company can give, sell, or trade that information to another company with which an individual has no relationship, without their knowledge or consent.
“I’m not sure that it makes sense from a privacy point of view, or that it’s at all palatable from an individual point of view,” Scassa says.
“I’m not sure why disclosure was added, but it’s a game-changer with legitimate interest.”
Bernier says the responsible use of de-identified personal data will now be allowed for internal research, analysis, and development, but only under a governance structure to ensure it is handled responsibly and in compliance with the law.
“There is a framework around it that could foster innovation in a privacy-protected way for the benefit of all,” she says.
“We have to be realistic about the fact that we now have a treasure-trove of information that can allow us to benefit for medical purposes, for scientific purposes, for social governance purposes. We cannot simply blanket deny access to that treasure trove. For the good of humankind, we need to find pathways to the responsible use of personal information for the greater good.”
That said, Scassa is concerned the legitimate interest exception is drafted in a way that favours business interests. While organizations will still need to do privacy impact assessments to identify reasonably foreseeable adverse effects and mitigate them, and will be required to outline their use of the legitimate interest exception, that doesn’t extend to specific transfers or uses.
“That’s going to be a point of debate and discussion,” she says.
The legislation also requires privacy impact assessments for cross-border data transfers, which Bernier is a fan of. She says when personal information is sent abroad through service providers that can store it in any country deemed to be in their best commercial interest, it’s within the reach of the local government where it is stored.
“That corresponds to a very real privacy risk,” she says. “We need to take into account the actual risks of doing that.”
A 2009 report from the Office of the Privacy Commissioner set out guidelines for cross-border data transfers. It was clear that an organization’s obligations included a duty to consider the local data protection conditions in the country where the data was stored. Bernier says what’s proposed in Bill C-36 formalizes the OPC’s direction.
Scassa worries about smaller organizations being responsible for the data they transfer across borders, as they may lack the resources to do so and will likely consider a privacy impact assessment too onerous.
‘It seems like a bad idea to me’
Other changes in the bill include the right to an explanation by a human decision-maker about how an automated decision was made, codifying children’s information as sensitive, and defining personal information to include inferences. What concerns Fraser, however, is the creation of a private right of action.
Currently, under PIPEDA, when a person makes a complaint to the privacy commissioner and an investigation is conducted, and a report is issued, that person can seek damages in the Federal Court. He says under C-36, anyone affected by a finding can seek damages in court, not just the complainant. That’s in addition to remedies that already exist under provincial laws for invasions of privacy.
“That opens the floodgates, from a really bad public policy point of view.”
This means anyone can go to court to claim damages, including provincial courts, which are already overburdened with criminal law cases. Fraser says the Federal Court should have been the place for these actions, given that it’s resourced by the federal government and could manage these cases centrally.
“When murder and rape cases are being stayed because they can’t get court time, you’re going to dump a bunch of penny-ante privacy cases into those courts? It seems like a bad idea to me.”