Who Protects Canadians Online — and Who Protects Them From the Digital Regulator?
- By Tahani Elghazaly
- Published
Canada is preparing to redefine its relationship with the digital world through a proposed regulator with broad powers over social media platforms, artificial intelligence chatbots and the way companies collect and use Canadians’ personal information.
On the surface, the idea appears reassuring: a powerful authority capable of holding global technology companies accountable, protecting children from harmful content and addressing violations that older laws were never designed to handle.
But the proposal raises a second and equally important question: who will oversee the regulator when a single institution becomes responsible for online safety, privacy and digital-content governance?
The federal government introduced two bills in June 2026 that would form the foundation of the proposed framework.
Bill C-34, known as the Safe Social Media Act, would apply to social media services, livestreaming platforms and certain artificial intelligence chatbots. Bill C-36 would modernize privacy rules and strengthen consumer rights in the digital economy.
Both bills remain at an early stage of the parliamentary process and have not yet become law.
Under the government’s proposal, a new Digital Safety and Data Protection Commission of Canada would oversee both areas rather than dividing responsibility among several agencies.
The commission would examine how platforms respond to harmful content, establish safety standards for children, review age-assurance systems and enforce private-sector privacy rules.
Why does the government believe Canada needs a powerful regulator?
The government argues that existing laws often respond only after harm has occurred and do not place enough responsibility on platforms to prevent risks in advance.
Bill C-34 would require regulated companies to assess potential dangers, provide tools that allow users to block accounts and report content, identify certain materials created using artificial intelligence and publish regular digital-safety plans.
The proposed legislation would also restrict children under the age of 16 from creating accounts on some social media platforms unless a company could demonstrate that it provides sufficient safeguards.
Artificial intelligence chatbots would also be covered. Operators could be required to reduce the risk of harmful responses, dangerous interactions and failures to intervene during crisis situations.
Bill C-36, meanwhile, would give Canadians broader privacy rights, including the ability to request the deletion of personal data and receive explanations when automated systems are used to make important decisions about them.
It would also establish stronger standards for children’s information, describe privacy as a fundamental right and require companies to explain clearly how they collect and use personal data.
Supporters of stronger regulation point to real cases in which current Canadian law has struggled to keep pace with new technology.
In June, Canada’s privacy commissioner concluded that the image-generation tool connected to the Grok chatbot had been introduced without adequate safeguards, allowing users to create sexually explicit fake images of real people, including women and children.
The commissioner also noted that the current law did not provide sufficient authority to issue binding orders against companies, reinforcing the government’s argument that stronger enforcement tools are needed.
Where do the concerns begin?
The central concern is not the goal of protecting children or strengthening privacy. It is the amount of authority that could be concentrated inside one institution.
The proposed commission would not simply receive complaints. It could establish standards, conduct inspections and investigations, issue binding orders, determine whether age-verification methods adequately protect privacy and decide whether certain platforms qualify for exemptions from restrictions involving users under 16.
Companies could also face penalties worth millions of dollars or a percentage of their global revenue for serious violations.
University of Ottawa law professor Michael Geist has described the proposed body as a kind of “super-regulator,” warning that a small number of commissioners could oversee online content and user expression while also making decisions about how businesses across the economy handle personal information.
Law professor Teresa Scassa has argued that combining the files could improve coordination, but she has also warned that it might weaken or disperse the expertise developed by the Office of the Privacy Commissioner over many years.
A complicated transition could also create a period in which privacy rights do not receive the level of protection Canadians expect.
The regulator’s independence will be closely examined
One of the most sensitive elements of the proposal is that responsibility for private-sector privacy enforcement would move from the existing privacy commissioner to the new commission.
The current commissioner is an independent officer of Parliament, a structure intended to limit direct government influence over privacy investigations and decisions.
Members of the proposed commission, however, would be appointed by the governor general on the recommendation of the federal cabinet. The chair would be selected through the same process.
The legislation would also allow the responsible minister to request reports and information from the commission within its area of authority.
That does not automatically mean the commission would become a political instrument. Members would serve during good behaviour, could be removed only for cause and some decisions could be challenged before the Federal Court.
Still, the proposed structure raises legitimate questions about how much distance should exist between the government and an institution responsible for regulating personal data, online content and digital expression.
Age verification could create a new privacy risk
The proposed restrictions on children’s accounts also create a practical question: how will platforms determine a user’s age?
Some systems may require identity documents, facial-age estimation or verification through outside companies. Each method could generate highly sensitive databases containing identity or biometric information.
Bill C-34 attempts to address this concern by limiting the use of information collected for age verification, requiring companies to protect it and directing them to destroy it once the verification or age-estimation process is complete.
But the effectiveness of those safeguards will depend on future regulations, the technology selected by platforms and the regulator’s ability to audit companies properly.
Canada is not simply choosing between regulation and no regulation.
The real challenge is building a system powerful enough to confront multinational technology companies without creating a new form of surveillance or an administrative authority that becomes difficult to challenge.
Canadians need a regulator capable of compelling platforms to protect children, personal information and users from serious harm.
They also need guarantees that the regulator itself will remain independent, transparent and accountable, and that citizens and companies will have meaningful rights to challenge its decisions.
The internet does not become safer simply because a government creates a more powerful regulator.
It becomes safer when both technology companies and the regulator are subject to clear laws, independent oversight and accountability that applies to everyone.
You May Also Like
Authors
-
Tahani Elghazaly5371 Posts
Popular Posts
Newsletter
Subscribe to our mailing list to get the new updates!