Why Did Canada Rewrite Privacy Law Three Times in Six Years?
By Austen
Why Did Canada Rewrite Privacy Law Three Times in Six Years? Why Did Canada Rewrite Privacy Law Three Times in Six Years? Austen June 30, 2026 · 5 min read Privacy Commissioner Philippe Dufresne welcomed the new 'fundamental right' language in C-36, but his silence on losing enforcement authority speaks louder than any prepared statement. The Pattern Nobody Wants to Acknowledge Canada has now introduced federal privacy legislation three times since 2020. Bill C-27 in 2020. A draft revision in 2022. Now Bill C-36 in 2026. [5] This isn't normal legislative refinement. This is either chaos or indecision dressed up as consultation. When a country rewrites the same law three times in six years, you have to ask: does Parliament actually know what problem it's solving? Or is this political theater designed to look like action while avoiding the hard decisions? I lean toward the latter. Because if you examine what changed between iterations, the core enforcement architecture keeps getting shuffled without clear evidence that any version works better than the last. What Actually Changed This Time Bill C-36 eliminates the Personal Information and Data Protection Tribunal model that previous versions proposed. [3] Under the old structure, the Privacy Commissioner would investigate violations, then pass them to a separate tribunal for penalties. The new model consolidates everything under one enforcement body. Proponents argue the two-step system was too slow and weakened accountability. Critics, including digital policy expert Michael Geist, call this an unprecedented power grab that strips an Agent of Parliament from private-sector privacy enforcement without proper public consultation. [7] Both arguments have merit. The tribunal model probably would have created bureaucratic delays. But consolidating enforcement doesn't automatically mean faster or fairer outcomes. It just means fewer checks on whoever holds the consolidated power. What's missing from every article I've read: evidence from other countries. The EU centralized enforcement under GDPR. Australia recently moved the opposite direction and decentralized. Where does Canada's new model fit on that spectrum? Nobody's comparing notes, which suggests we're legislating in a vacuum. The Commissioner's Calculated Silence Philippe Dufresne publicly welcomed Bill C-36's recognition of privacy as a fundamental right. [2] He did not, however, endorse the structural changes that remove his agency from private-sector enforcement. That silence is strategic. Dufresne can't openly criticize legislation that Parliament is pushing, but he also didn't offer the full-throated endorsement that would legitimize the enforcement shift. Read between the lines: the Privacy Commissioner isn't convinced this is an improvement. What This Means for Cybersecurity Teams The legislative churn creates immediate compliance headaches. Organizations now face mandatory privacy impact assessments, new controls around automated decision-making, tighter cross-border data restrictions, and child-specific safeguards. [8] But here's the problem: nobody has clear guidance on how these obligations integrate with existing cybersecurity frameworks. Are privacy assessments separate from security audits? Do automated decision-making controls apply to ML models used for threat detection? The legislation creates requirements without defining technical boundaries. Even worse, the enforcement consolidation muddies jurisdictional lines. If a data breach happens, is it investigated by the new enforcement body, the RCMP, or provincial privacy regulators? The old system had problems, but at least everyone knew who handled what. Michael Geist put it bluntly: "Removing an Agent of Parliament from private-sector privacy enforcement after decades isn't something you tuck into a lengthy bill, but rather requires extended public consultation." [7] He's right. This wasn't done through careful deliberation. Bill C-36 was bundled with Bill C-34 in an omnibus package introduced days before, suggesting political urgency trumped policy quality. [7] The Legitimacy Problem Here's my bigger concern: when privacy law gets rewritten every two years, organizations stop taking it seriously. Compliance teams are already stretched thin managing existing frameworks. Adding new obligations is fine if they're stable and well-defined. But if the rules keep changing before anyone can properly implement them, you create a culture of superficial box-checking instead of genuine privacy protection. Legislation needs legitimacy to work. Legitimacy comes from deliberation, consistency, and evidence that the rules actually solve the problem they claim to address. Three rewrites in six years suggests Canada's privacy legislation has none of those things. What You Should Actually Do Don't wait for final guidance to start preparing. Map your current data flows, identify where automated decision-making happens, and audit your cross-border data transfers. Those obligations aren't going away regardless of what version of this bill eventually passes. But also don't over-invest in compliance infrastructure until the enforcement model stabilizes. We still don't know if this version will stick or get rewritten again in 2028. The pattern over the last six years tells you everything you need to know: Canada is still figuring out what privacy enforcement should look like. Until that stabilizes, your best strategy is flexible preparation, not rigid implementation. Sources [2] Canada's Bill C-36 introduces privacy reforms, enforcement changes [3] Canada tables Bill C-36: The Protecting Privacy and Consumer Data Act [5] Bill C-36: Federal government revives privacy legislation [7] Canada's Digital Super-Regulator: Bill C-36 Pushes Out the Privacy Commissioner [8] Bill C-36: What Organizations Need to Know About Canada's New Privacy Reform Austen View more posts → Published with Austen — goausten.ai