Canada Canada AIDA artificial intelligence data act

Canada Abandons Standalone AI Law, Bets Enforcement on Redefining 'Personal Information'

Bill C-36 folds automated-decision oversight into privacy law after AIDA died in 2025 — a narrower, more enforceable model than its predecessor, but not a full answer to algorithmic harm.

Bill C-36 at a Glance People of Internet Research · Canada 3% Max admin penalty (global revenue) Or $10M, whichever is greater — is… 5% Max criminal fine on indictment Of global revenue, or $25M, whiche… 3rd Attempt at privacy reform Two prior bills (including AIDA's … Jan 2025 Date AIDA died Parliament's prorogation terminate… peopleofinternet.com
Bill C-36 at a Glance People of Internet Research · Canada 3% Max admin penalty (global revenue) 5% Max criminal fine on indictment 3rd Attempt at privacy reform Jan 2025 Date AIDA died peopleofinternet.com

Key Takeaways

Canada has quietly closed the book on AI-specific legislation and reopened it under privacy law. On June 15, 2026, Minister of Artificial Intelligence and Digital Innovation tabled Bill C-36, the Protecting Privacy and Consumer Data Act (PPCDA), which would replace Part 1 of the 25-year-old Personal Information Protection and Electronic Documents Act (PIPEDA). Absent from the bill: anything resembling the Artificial Intelligence and Data Act (AIDA), the standalone AI statute that died when Parliament was prorogued on January 5, 2025, taking the omnibus Bill C-27 down with it.

This is not a minor drafting choice. It is Canada's second attempt at AI governance, built on the theory that the first attempt failed for structural reasons that a privacy-law wrapper can fix.

What Killed AIDA, and What C-36 Does Differently

AIDA, introduced in June 2022, tried to regulate "high-impact AI systems" directly — screening tools for hiring and credit, biometric identification, content-recommendation engines, autonomous vehicles — through a risk-tiered compliance regime enforced by a future Artificial Intelligence and Data Commissioner. The archived AIDA companion document shows a framework long on categories and short on triggering thresholds; critics across academia and industry hammered it for vagueness on what counted as "high-impact" and for leaving core definitions to future regulation. It never got a committee vote before prorogation ended it.

Bill C-36 sidesteps that failure mode by not trying to define AI systems at all. Instead, it amends what counts as "personal information." Under the bill, personal information now explicitly includes "information that is inferred about the individual" — meaning a credit score, a purchase-propensity model, or a churn-risk prediction gets the same statutory protection as a name or address, regardless of whether the company collected it directly. Two provisions do the actual work: Section 62 requires organizations to give "a general account" of their use of any automated decision system that could have a "legal or similarly significant effect" on a person, and Section 63 gives individuals a right to request the specific factors, data sources, and reasoning behind an automated prediction, plus a route to challenge it in writing. Section 18(3) separately restricts using automated systems to influence behavior without consent, and Section 75 bars re-identifying de-identified data except for narrow purposes like fairness testing.

That is a materially narrower ambition than AIDA's. It does not regulate model training, does not create risk tiers for "high-impact" systems, and does not touch autonomous vehicles or safety-critical AI as such. What it regulates is the moment an inference about a specific person gets used against them — which is a privacy-law problem, and one Canada's regulators already know how to enforce.

The Steelman: Cofone Is Right About the Gap

The strongest objection to this approach, made by Oxford's Ignacio Cofone in Al Jazeera's coverage, deserves to be taken seriously rather than waved off: "Older privacy law assumes the danger is in what a company collects from you. The danger now is in what a company infers about you from data you never handed over." That is a real limitation. Transparency and access rights under Sections 62–63 tell an individual what happened to them after a decision is made; they do nothing to stop a company from building a discriminatory scoring model in the first place, or from deploying it at scale before anyone files a complaint. A privacy-law frame is inherently reactive and individual-complaint-driven, where AIDA's risk-tiering was — on paper — meant to be systemic and preventive. Journalism-ethics concerns raised in the same coverage, that broad "personal information" definitions could be invoked to block scrutiny of algorithmic bias, are a second legitimate risk worth watching as the bill moves through committee.

Why the Narrower Bet Is Still the Better One

Even granting Cofone's point, C-36's approach is more likely to actually govern something than AIDA's was — and an enforceable narrow rule beats an unenforceable broad one. The bill consolidates power in a single new Digital Safety and Data Protection Commission of Canada, replacing the split jurisdiction (Privacy Commissioner investigates, separate tribunal penalizes) that made PIPEDA's predecessor bill, C-27, slow and toothless. Per DLA Piper's analysis, the new Commission can issue binding orders and administrative penalties directly, up to the greater of $10 million or 3% of global revenue, with criminal fines reaching 5% on indictment. Those are PIPEDA-successor numbers, not invented for AI, and they attach to a body with one clear mandate rather than two bodies negotiating jurisdiction.

The Privacy Commissioner's own statement on June 15 welcomed the bill's recognition of privacy as a "fundamental right" and its mandatory privacy impact assessments, while flagging that the Office "will be carefully analysing the Bill" before detailed recommendations — an appropriately cautious endorsement, not a rubber stamp.

The honest read is that C-36 is not an AI law and was never trying to be one. It is a bet that Canada can get more real-world protection from a narrower, enforceable inferred-data regime than from a third attempt at a broad AI statute that risks the same fate as AIDA. Given that AIDA produced zero enforcement actions and no binding rules in three years of existence, that trade looks defensible. The gap Cofone identifies — governing model development and deployment before harm occurs, not just disclosure after — is real, and Parliament should leave room to revisit it. But it is a reason to add a second law later, not a reason to have blocked this one.

Sources & Citations

  1. Bill C-36, First Reading — Parliament of Canada
  2. Privacy Commissioner's Statement on Bill C-36
  3. AIDA Companion Document (archived) — ISED
  4. Parliament of Canada: Bill C-36 (45-1), First Reading
  5. Al Jazeera: Canada's Bill C-36 tackles AI privacy. Is it enough?