The government’s recently tabled privacy reform bill would modernize many aspects of Canadian privacy law, including establishing privacy as a fundamental right in the purpose clause of the new law, creating a data mobility right for individuals that would enable them to move their data from one company to another, and giving businesses the potential to use approved codes of practice. These and many other changes will be subject to intense debate at committee, but the biggest challenge facing the bill is the long sequence of steps required for it to take effect. The government may claim that privacy is an urgent priority, and its recent national AI strategy, overseen by AI Minister Evan Solomon, declares trust to be its “north star”, yet a careful review of Bill C-36 confirms that the law will take years to take effect. This post and the accompanying infographic unpack the many steps built into the bill that, cumulatively, are likely to result in no substantive privacy reforms for Canadians until 2030 or later.
Archive for June 24th, 2026

Law Bytes
Episode 277: Kate Robertson on the Risks That Lie Behind Canada's Unexpected Signing of the UN Cybercrime Convention
byMichael Geist

June 22, 2026
Michael Geist
Search Results placeholder
Michael Geist on Substack
Recent Posts
From CCH to ChatGPT: How Canadian Copyright Law Played the Key Role in Deciding a Leading AI Training Data Case in India
Starting Over: Court Filing Confirms the CRTC’s Streamer Contribution Decisions Are Dead With a Full Online Streaming Act Reset to Come
The Name on the Window Was Enough: The Attacks on Kiva’s and the Normalization of Antisemitic Violence in Canada
The Law Bytes Podcast, Episode 277: Kate Robertson on the Risks That Lie Behind Canada’s Unexpected Signing of the UN Cybercrime Convention
A Surveillance Treaty in Disguise: The Trouble With Canada’s Quiet Decision to Sign the UN Cybercrime Convention

