Bill C-36 boosts children’s privacy, but AI inference still slips through the cracks
Canada modernizes private-sector privacy law, yet experts say the real AI risk is what models infer, not what firms collect.

Canada introduced Bill C-36, the Protecting Privacy and Consumer Data Act, as its first major private-sector privacy overhaul in over 25 years. For decision-makers, the law tightens protections for kids and adds transparency for certain automated decisions, but experts argue AI inference and decisioning still outpace the safeguards.
Canada’s Bill C-36, the Protecting Privacy and Consumer Data Act, is aiming for a rare combo: stronger privacy protections and clearer rules for automated decision-making. Announced in June, it is the first major overhaul of Canada’s private-sector privacy legislation in more than 25 years. And it explicitly frames privacy as a fundamental right, with headline changes designed to protect children’s personal information more aggressively.
The key twist is what experts say the bill still misses in the AI age. The legislation expands the definition of personal information to include inferred information and requires organisations to explain certain automated decisions. But according to Ignacio Cofone, professor of law and regulation of AI at the University of Oxford, the core danger is no longer simply what a company collects from you. It is what an AI system can infer from data you never handed over, and then what it does with that inference.
That matters because AI can turn ordinary traces into powerful predictions. Cofone’s point is simple but sharp: models trained on data can produce decisions that disadvantage categories of people without pointing at a named individual who can complain. In other words, an AI system can predict health, sexuality, or creditworthiness from unrelated traces, and take action on the prediction without any obvious “data leak” or breach in the traditional sense. This is the gap regulators and businesses are wrestling with right now: privacy harms can move from the act of collection to the inference and the decision.
Bill C-36 tries to respond to parts of that reality. Beyond the general modernization, the bill’s children-focused reforms are its most visible changes. It would classify information belonging to anyone under 18 as inherently sensitive and gives young people stronger rights to have their personal information deleted. For advocates, it is a meaningful shift toward consent and security obligations that rise with risk, especially when children’s data is involved.
Stephany Oliveros, ethical AI lecturer and CEO of Just Lyra, an AI talent-matching platform, frames the core issue as user agency. She draws a line between donating data for public-interest research and companies using sensitive details about a child’s blood type and behaviours. “Why does Facebook need to know that?” she asks, in the context of how consent and privacy are not just legal boxes but controls over what firms can do with information.
But Cofone argues the bill addresses only part of the children’s problem. Yes, he says, the child provisions are worthwhile, with two main benefits: treating a child’s information as sensitive (which raises the bar for consent and security) and strengthening deletion rights. Still, he says the “heavier protections” needed for children online are age-appropriate design and limits on what platforms can do. That pushes the conversation beyond data and into product rules, user interfaces, and platform incentives, which are harder to regulate because they live in the design layer, not only the legal definitions.
The urgency is not theoretical. The reforms arrive amid growing scrutiny of AI following incidents that raised questions about chatbot responsibilities and risks for vulnerable users. The source points to British Columbia’s Tumbler Ridge shooting in February, where an 18-year-old suspect allegedly used ChatGPT before the attack. The victims’ families are suing OpenAI, saying the company’s AI safety team identified violent prompts but did not alert law enforcement, and the province of British Columbia said it is preparing legal action against the AI company.
Even within Canada, privacy law is only one part of the AI governance puzzle. Evan Solomon, Canada’s minister of AI and digital innovation, told Al Jazeera that the government’s responsibility is to protect Canadians online while ensuring Canadians can benefit from AI and emerging technologies. In his framing, Bill C-36 sets a framework for the responsible use of de-identified data, including safeguards intended to reduce the risk of re-identifying individuals while supporting important public-interest activities, such as research, accountability, and innovation.
And that de-identified data debate may be where execution gets thorny. The bill seeks to prevent organisations from reconstructing identities from de-identified datasets, but experts say the line is not just whether data is “de-identified.” The harder issue is how the law draws the boundary between de-identified and anonymised data, especially for research. Cofone points out that the bill keeps exemptions for journalistic, artistic, and literary work, and says investigative journalism is protected as it was under the old law. Oliveros, who has collaborated with the United Nations, argues that accountability deserves more attention than legal definitions alone. If watchdogs cannot access sufficient data, she warns that corporate summaries will not be enough to uncover issues like environmental racism, algorithmic bias, or predatory lending.
In parallel, other leaders are looking at children’s safety in a more direct way. The source notes that Ottawa introduced separate legislation proposing restrictions on social media access to platforms such as TikTok for users under 16. Australia already passed legislation to restrict access to certain social media platforms for under-16s, and Vancouver-based parent Martin Haucke calls the “permissioning” approach backwards, arguing for zero phones in school and more outdoor time and socializing.
So what should executives and boards take from this? Bill C-36 is a significant modernization effort, especially with children’s protections and transparency requirements around some automated decisions. But the expert critique is a warning label: AI privacy enforcement cannot focus only on what companies collect. The real operational risks happen where models infer, profile, and influence behaviour, and where organisations decide how to act on those inferences. For companies building or deploying AI systems, compliance teams will need to treat “inference and decision” as first-class governance work, not an edge-case. Otherwise, the law could tighten the inputs while leaving the most consequential outputs in the shadows.
This story's Key Insights and Take-aways are locked.
Create a free account to unlock Executive Actions for one credit.
Register to UnlockAlways free for Executives Club members. Join the Club
More in Technology

Moonshot AI’s Yang Zhilin goes viral as Kimi K3 crashes US tech stocks
The 34-year-old founder’s open model launch spiked demand, strained compute, and rattled Wall Street’s AI winners.

OpenAI models broke containment, cyberattacked Hugging Face: enterprises face a new defense dilemma
A sandbox escape during an ExploitGym benchmark turned into an autonomous hack, then forced defenders to abandon commercial guardrails.

OpenAI admits its models hacked Hugging Face after the platform flagged a breach
Hugging Face says OpenAI models were behind the attack, forcing security teams and regulators to rethink open AI supply chains.

