-
Canada proposed two new laws that will regulate online services and overhaul federal privacy rules for the private sector.
-
The proposed bills aim to ensure that social media, artificial intelligence chatbots, and other online platforms don’t serve harmful content to consumers, particularly children.
-
Companies that violate the proposed bill could pay penalties of up to 5% of their global annual revenue.
Canada just introduced two new bills that work hand-in-hand to reshape online safety and data protection in Canada. These new laws will subject online platforms to heavy fines for noncompliance.
The main objective of the proposed legislation, Bill C-34 and Bill C-36, is to ensure the safe use of the internet by children. It also forces businesses to be more open about how they handle user data.
Under the proposed legislation, several online platforms would be required to introduce privacy and safety features into their services. There will also be a single regulator to oversee both data privacy and digital safety in Canada.
A connected approach to privacy and digital safety
Bill C-34, also called the Digital Safety Act, and Bill C-36 referred to as the Protecting Privacy and Consumer Data Act (PPCDA), were proposed in June 2026. Although each piece of legislation has its own unique objective, they are designed to operate in a collaborative effort in order to create a comprehensive digital governance system.
Bill C-34 aims to decrease harm online, particularly to children, while Bill C-36 will replace Canada’s current federal privacy law, called the Personal Information Protection and Electronic Documents Act (PIPEDA).
A key feature of the proposal is the creation of the Digital Safety and Data Protection Commission of Canada. Rather than having separate agencies oversee privacy and online safety, one regulator would administer both laws. One commissioner would also serve as the Privacy and Consumer Data Commissioner.
According to the government, this shared oversight would help regulators better understand how privacy and digital safety often overlap. It would also allow businesses to deal with a more coordinated regulatory system instead of navigating separate frameworks.
The new Commission would get real enforcement power. It could issue binding orders and impose huge fines. For most violations, penalties could reach CA$10 million or 3% of a company’s gross global revenue, whichever is higher.
The most serious offences could cost companies up to CA$25 million or 5% of global revenue. The PPCDA would also let individuals sue companies for damages after a privacy breach.
The New Bill Targeting Harmful Content
Bill C-34’s Digital Safety Act would apply to three types of online services. These include social media platforms, AI chatbot services, and certain other online services that allow user interaction.
A service qualifies if it meets a specific user number threshold or if regulators determine it poses significant risks related to harmful content, harm to individuals, or risks to children. The bill also provides detailed definitions for each category of digital services.
Social media services include websites or apps built mainly for sharing user-generated content. The definition also covers adult content platforms and live-streaming services.
AI chatbot services include internet-based systems that generate adaptive, human-like conversations and can simulate ongoing personal relationships with users
The law targets seven specific categories of harmful content:
- Intimate content shared without consent (including deepfakes)
- Content that sexually victimizes children
- Content that pushes children to self-harm
- Content used to bully children
- Content that foments hatred
- Content that incites violence
- Terrorism or violent extremist material
The Act imposes four main duties on regulated services:
- They must protect children. This means adding age-verification features and designing safer experiences for minors.
- They must act responsibly by ensuring they label synthetic content like deepfakes as well as removing content that could be harmful to users.
- Platforms would need to make certain content inaccessible to users. And they must take down child sexual abuse material within 24 hours of posting.
- They must be transparent by publishing a digital safety plan.
Overhauling Canada’s Privacy Law
Bill C-36 would be a replacement for Part 1 of PIPEDA, which is Canada’s private sector privacy law, with the Protecting Privacy and Consumer Data Act. The new bill will acknowledge that privacy is a basic right.
The law would bring several key changes:
It would treat personal information about children as sensitive automatically. This means there are stringent laws for them. Bill C-36 will also define the term “sensitive personal information,” just like GDPR.
The bill requires companies to maintain formal privacy management programs with documented policies. It also creates a right for individuals to request the deletion of their personal information in certain cases.
Companies will have to conduct a privacy impact assessment before transferring personal information to foreign parties. The law distinguishes between “anonymized” (not protected by any regulations) and “de-identified” data.
The PPCDA has also provided a more comprehensive definition of sensitive personal information. It includes children’s information, biometric information, political opinions, religious or philosophical beliefs, and sexual orientation.
These categories become especially important because many digital safety measures involve processing sensitive information.
Automated decision-making gets special attention. The new framework will require organizations to give an explanation when an AI system makes major decisions regarding individuals.
Where the Two Bills Connect
The Digital Safety Act and the PPCDA share common ground. This is intentional. The government designed them to work together. The proposed framework recognizes that many digital safety measures depend on collecting and processing personal information.
For example, age verification, complaint handling, account controls, chatbot monitoring, and recommender system risk assessments all involve personal data.
Because of that, organizations regulated under both laws would need to treat privacy and safety compliance as one continuous process rather than two separate tasks.
Child Protection is a Major Crossover Point
The Digital Safety Act seeks to address the issue of online harm to minors. The PPCDA, on the other hand, requires organizations to prioritize the privacy interests of children in their compliance considerations.
Both legislations consider a child as any person below 18 years. Therefore, organizations will have to give an explanation of how they use and gather data of children.
They’d need to deploy solutions such as age verification, parental controls, and other features to ensure the safety of children using their services. This process must follow the stricter rules under the PPCDA.
Promoting Accountability & Transparency
The legislation also requires transparency. Organizations would need to clearly explain how they process personal information while operating digital safety features. This will help users better understand how the companies collect and use their information.
Accountability also requires alignment. The importance of transparent breach disclosure was highlighted when Nextcloud confirmed a website breach after initially attributing it to an infrastructure issue.
The digital safety plan required under Bill C-34 and the privacy program needed under Bill C-36 must work together. This is especially important when processing sensitive information for safety measures.
The dual mandate of the new Commission ensures a holistic view. One agency will oversee both safety and privacy compliance for any business subject to both regimes.
Both bills are now before Parliament and could still change. Given the government’s stated commitment, the likelihood of passage in some form is high.