💰 $1.333 TRILLION Federal Debt  |  🏠 $817K Avg Canadian Home Price  |  📱 $54M ArriveCAN App  |  ⚖️ 2 Ethics Violations — First PM in History

The Daily Record

Accountability journalism the $600M government-subsidized media won't tell you.

Privacy Act Modernization Needs an Enforcement Ledger

Ottawa says it wants modern privacy law. The watchdog’s complaint and breach numbers show Canadians need enforcement receipts, not slogans.

Editorial cartoon showing Ottawa promising privacy modernization while complaint backlogs, breach reports, AI systems and taxpayers demand an enforcement ledger

Ottawa can call its Privacy Act rewrite “modernization.” Canadians should call it unfinished until the enforcement ledger is public.

The Treasury Board consultation puts serious issues on the table: broader government data sharing, privacy notices, safeguards, and rules for automated decision systems. It also admits a key weakness in plain language. The federal directive on automated decision-making is policy, not law, and it does not apply to every institution covered by the Privacy Act. If Ottawa is increasingly using AI and automated tools in service delivery, that gap is not technical. It is the difference between a promise and a right.

The Privacy Commissioner’s August submission is the useful reality check. Philippe Dufresne’s office supports modernizing the Act, but it also asked for hard edges: mandatory high-risk privacy impact assessments, clearer breach-notification timelines, authority to inspect breach records, stronger transparency obligations, and real order-making powers. The Commissioner warned that a corrective action plan controlled by the offending institution could simply replace one weak mechanism with another.

The watchdog’s own annual numbers show why this matters now. In 2025-26, the Office of the Privacy Commissioner received 6,190 complaints under federal privacy laws, up from 3,400 the year before. Privacy Act complaints alone hit 3,146, a 62 percent increase. Time-limit complaints rose 121 percent, and the biggest accepted-complaint institutions included CSIS, IRCC, the RCMP and CBSA. Those are not fringe files. They are national-security, immigration, policing and border agencies handling deeply sensitive personal information.

The breach numbers are just as sobering. OPC highlights say federal institutions reported 451 Privacy Act breaches affecting 48,159 Canadians, and 94 percent of reported breaches were assessed as likely to cause a real risk of significant harm. Mishandling information, not sophisticated foreign hacking, was the leading category. That should end the idea that modernization can be measured by press releases alone.

A conservative accountability standard is simple: before giving the Carney government credit for privacy reform, publish the receipts. How many high-risk programs launched without a completed privacy impact assessment? Which institutions missed response deadlines? How many breach reports were late? Which automated decision systems affect benefits, immigration, policing or border decisions? Which departments corrected problems voluntarily, and which would have faced binding orders if the Commissioner had that power?

Canadians do not need a government-wide data-sharing superhighway wrapped in privacy language. They need enforceable limits, public inventories, plain-language notices, audit trails, breach timelines and consequences when institutions fail.

Modern privacy law should protect citizens from the state, not merely help the state move data faster. If Ottawa wants trust, publish the enforcement ledger.

The receipt test: publish complaint backlogs, breach totals, late-response departments, high-risk PIA status, automated-decision inventories, corrective-action timelines and whether the Privacy Commissioner gets binding order powers.
Sources

This article argues for public enforcement metrics and stronger oversight. It does not claim that a final Privacy Act bill has been tabled or that every federal automated decision system is currently unlawful.