RiverRidge Policy & Risk Intelligence · Legislative analysis
Children, social media and AI · September 2026
How the federal government is tackling the harms of social media and AI chatbots.
Three of Bill C-34's central obligations would not be defined on the day the Act comes into force since in each case the regulations have yet to be written.
Canada has two bills before Parliament that together decide how social media and AI chatbot services will be regulated. Both Bill C-34, the Safe Social Media Act, and Bill C-36, the Protecting Privacy and Consumer Data Act, are at second reading. They are not two separate files. C-36 cannot come into force unless C-34 passes, and C-36 rewrites parts of C-34 before either one takes effect.
Both bills recognize the harm to children. They can be improved by more clearly addressing that harm at the point of application and in reassuring both providers and individuals, through explicit guidelines, that the new Commission's powers have checks and balances. In addition, based on challenges federal governments have faced when inventing new agencies and commissions, strong consideration should be given to how the new organization will operate before handing it over to bureaucracy to develop more bureaucracy. Much of the meat of the legislation is left to a lengthy process of regulatory development alongside the establishment of a new commission. Other jurisdictions have indeed already created many of these requirements, and operator compliance there will sometimes spill over to Canadians, though that is not always the case. The uncertainty of a process that includes a new Commission and the development of a significant set of regulations creates a long period of uncertainty for the many Canadian businesses that use these platforms to advertise their products, and for the citizens who use them.
This is not an argument against the bills, but to suggest more thought go into their completion prior to Royal Assent. Six considerations would go a long way.
Each is set out in full, with its instrument and its stage, under what Parliament could settle now.
The two bills are at the same stage. Both have second reading ahead of them.
Second reading is the vote on the principle of a bill, which is why amendments afterwards cannot change its scope. Committee is where witnesses appear and amendments are actually made. Third reading is the final vote. Now that the House has returned, both will ultimately go to committee, where witnesses will be heard and amendments considered. Then it goes to the report stage, which includes issuing a report to the House, and then third reading.
The same sequence then occurs in the Senate. Amendments are likely, but with a majority government and no significant public opposition so far, both bills can be expected to pass in some form. Now is the time to engage with elected officials and key opinion leaders to provide input through the committee process.
While still not assigned, the Digital Safety Act will likely go to the Canadian Heritage Committee, with C-36 to the Standing Committee on Access to Information, Privacy and Ethics or Industry and Technology.
Neither bill is a first attempt. C-34 follows the 2021 online harms consultation and Bill C-63, the Online Harms Act, which died on the order paper at prorogation before the 2025 election. C-34 drops the Criminal Code and Human Rights Act provisions that dominated that debate and keeps the platform regulation. C-36 is the third try at private sector privacy reform, after Bill C-11 died in 2021 and Bill C-27 at prorogation in January 2025. The two are intertwined, and C-36 makes significant changes to the Personal Information Protection and Electronic Documents Act (PIPEDA).
Australia moved first on a minimum age and others have followed. Canada has now followed suit. As is common practice for bills of this kind, the legislation sets out broad terms and defers much of the detail to a regulator, here a new Digital Safety Commission of Canada. Taken together the two bills also move private sector privacy to that new body, leaving the Privacy Commissioner of Canada with the public sector Privacy Act.
The difficulty is one of pace. As the House begins its deliberation, artificial intelligence and other advances are arriving at speed and at scale, and much of the world is legislating around them at once. Technology is moving faster than regulators can. That is why how the new Commission is designed matters as much as what the bill requires today.
The documented harms have been captured in four broad areas.
Samantha Teague, Klaire Somoray, Adrian Shatte and colleagues published a systematic review and meta-analysis in JAMA Pediatrics in March 2026, pooling 153 longitudinal studies across 115 cohorts and 1,072 effect sizes, drawn from 18,933 screened articles. Participants ranged in age from two to nineteen, with a mean of just under thirteen. What that examination found is that social media use is consistently associated with higher depression, behavioural problems, self-injury, and substance use. In addition, there is lower self-perception and academic achievement. The authors describe the links as modest but consistent.
In the 2026 World Happiness Report, Jonathan Haidt and Zachary Rausch argue across seven lines of evidence that the harms of social media are now large enough to cause changes at the population level, contributing to the rise in adolescent mental illness that began in the mid-2010s. They frame their chapter like a trial, openly arguing one side as a prosecutor would, and ask readers to judge it on the civil standard of the preponderance of the evidence rather than beyond a reasonable doubt. They also urge readers to read their critics, naming Candice Odgers and Amy Orben. The argument is theirs rather than the Report’s, and it is contested.
One finding in that chapter bears directly on the number Parliament has chosen. Research on sensitive periods suggests the association between social media use and poor mental health is strongest at ages 11 to 13 for girls and 14 to 15 for boys, which the authors give as a reason to set minimum ages no lower than sixteen. Whatever else is unsettled, the age in Bill C-34 is not arbitrary. It is based on evidence.
Many of these platforms the children are interacting with are now using techniques such as casino-like interfaces that disproportionately affect children's developing brains compared to adults. And daily use is high. Gallup found that teenagers in the United States spend almost five hours a day on social media alone, and that goes up to almost six hours a day by age seventeen. Operators require more direction around a balance between appropriately maximizing attention to sell products and services with how certain techniques such as the architecture behind a user’s feed (termed a recommender) impact the health of young people.
The perspective of educators is critical to ensuring we get this right, given their front-line insight. Educators are among the most consistent witnesses in the research. A 2024 NBC survey of 559 American elementary and secondary principals found that 42 percent firmly believed smartphones and social media were major causes of deteriorating student mental health, while only 1.3 percent thought the concern was overblown. A National Education Association survey of 2,889 American educators the same year found that 84 percent said social media use contributes to student mental health problems. Pew found that 72 percent of American high school teachers consider cellphone distraction a major problem in their classrooms. Similar findings appear among teachers in England, Spain, France and across the European Union.
The same National Education Association survey put something else at the top of the list, ahead of social media. Ninety-two percent named lack of parental involvement and communication. That is worth carrying to the section on what legislation cannot reach.
Sextortion, cyberbullying and grooming are all rising. Surveys of parents, teachers and clinicians confirm growing concern about exploitation and scams. Notably, fraud is absent from these two bills.
Bill C-34, the Safe Social Media Act, enacts the Digital Safety Act and creates a new regulator, the Digital Safety Commission of Canada. Bill C-36, the Protecting Privacy and Consumer Data Act, replaces the private-sector half of Canada's privacy law and hands the new commission a privacy mandate on top of its safety mandate.
That list is exhaustive. It is the whole of what the Act means by harmful content.
C-34 requires every operator of a regulated social media service to submit a digital safety plan to the Commission for each service it runs, under section 42. Chatbot operators file the same thing under section 58. The digital safety plan is not a form. It has to set out the operator's own assessment of the risk that users will be exposed to harmful content, the measures taken to mitigate it, the operator's assessment of how well those measures work individually and together, and a description of the indicators used to judge that.
It also has to describe the design features integrated under section 21, assess their effectiveness, and name the indicators used there too. The operator must make the plan available to the public, with carve-outs for trade secrets and other confidential business information, and for anything that could prejudice a criminal investigation. Every operator chooses its own indicators, so fifty companies will publish fifty different measures of effectiveness and nothing makes them comparable.
The two bills aren't simply related. Section 52(2) of C-36 provides that its Part 3 comes into force only if C-34 receives royal assent and becomes law, and not before the section establishing the new commission itself is in force. So what that means is one bill doesn't work without the other. C-36 does something unusual as well, and renames the commission the Digital Safety and Data Protection Commission of Canada.
Section 52(2) reads: “If Bill C-34, introduced in the 1st session of the 45th Parliament and entitled the Safe Social Media Act, receives royal assent, then Part 3 of this Act comes into force on a day to be fixed by order of the Governor in Council, but that day must not be before the day on which section 4 of the Digital Safety Commission of Canada Act, as enacted by section 4 of the Safe Social Media Act, comes into force.”
The same pattern appears three times. In each case Parliament creates the obligation and leaves its content to later regulation, by Cabinet or by a Commission that does not exist yet, without requiring the content to be written before the obligation applies.
Deferring detail to regulation is normal and often sensible. Deferring the standard by which the central obligation will be judged, and not requiring that standard before the obligation binds, is a different thing. The three instances are set out in the table at the top of this analysis.
Bill C-34 sets a minimum age of sixteen for social media accounts. But it names no service the age applies to. Cabinet will indeed name the services later by regulation and even then the Commission can grant exemptions. So the minimum age exists, but for now it does not apply to anything.
Michael Geist, of the University of Ottawa, made this point, noting that the statute fixes the age of sixteen but leaves which services are covered, when the ban applies and to whom, and what counts as adequate age verification to a later round of regulation.
The bill uses the terms adequate age verification or age estimation measures in the effort to confirm a user's age. Age assurance is an umbrella term that was used in the Australian trial and subsequent international standards work. It is a useful term, and this analysis uses it that way. But it should be noted that Parliament did not use that specific term.
There is a second-order effect worth naming. Enforcing a restriction on under-sixteens means a service has to establish who is over sixteen, which in practice means checking the age of every user, not only the children. It is the reason the accuracy question below is not a technical footnote. It applies to the whole population. All of this needs to consider the context of the current global cybersecurity environment. In early September 2026, it was revealed that a breach at IDScan.net, an identity verification service used for age checks, exposed approximately 1.1 million Canadian driver’s licences, according to estimates reported at the time.
The bill is not silent on what proper measures look like. Section 27(2) sets out five conditions the commission must be satisfied of. The measures must:
Three of those five conditions are privacy related, which is where both these bills, C-34 and C-36, have implications on what was previously PIPEDA. The first condition carries the entire weight of the scheme, and it reads, in full, that the measures must be effective. What counts as effective is left to be determined. It has to mean more than what many websites do today, where you click to say you are eighteen or older. That would not be effective. That is the gap.
The European Commission has said as much in its own words. In the guidelines it published in July 2025 under Article 28(1) of the Digital Services Act, it sorts age assurance into three categories, self-declaration, age estimation and age verification, and states plainly that self-declaration is not considered to be an appropriate age assurance measure. Canada’s bill leaves that conclusion to be reached later, by a body that does not even exist yet.
Canada’s own Privacy Commissioner has already been told this is the hard part. In the office’s age assurance consultation, which drew forty responses from industry, civil society, academia and overseas regulators, one respondent noted that effectiveness is a precondition for processing data legally, and another drew the distinction that matters here: a technology can be effective at determining a user’s age while the mandate it serves is ineffective at reducing harm, if it cannot be broadly enforced. Respondents also argued that the acceptable forms of age assurance should be assessed and approved by a regulator rather than left to organizations to choose. That is recommendation two, made to the Privacy Commissioner two years before this bill was tabled.
There are ways to check while protecting privacy. The Australian Age Assurance Technology Trial looked at 48 different companies and more than 60 different technologies across social media, gaming, adult content, and online retail, using lab testing, school trials, and mystery shopper evaluation. Its first major finding is that age assurance can be done in Australia privately, efficiently, and effectively. The second is that there is no substantial technological limitation preventing implementation. The trial is careful to add that no single solution fits every context and that the technologies meeting those thresholds do so when carefully selected and implemented. It also built its testing on practice statements based on ISO/IEC 27566-1, the same standard discussed below. It just seems Canada is not going there.
Australia has since moved from trial to enforcement. Its social media minimum age took effect on 10 December 2025. By mid-January eSafety reported that about 4.7 million age-restricted accounts had been removed or restricted, with a further 300,000 blocked by the start of March. The regulator is careful about that number: it counts accounts rather than individuals, many children hold several, and it includes inactive accounts.
The March 2026 compliance report is where the caution lies. eSafety had to pivot from monitoring compliance to enforcing it. It set out significant concerns about the compliance of Facebook, Instagram, Snapchat, TikTok and YouTube. Civil penalties of up to $49.5 million are available. The difficulty in Australia has been getting the platforms to take reasonable steps, more than getting teenagers to stop trying to get around it.
The measure is doing something. eSafety surveyed about 900 Australian parents and carers of children aged 8 to 15 in January and February 2026. Half said their child had an account on at least one platform before the restrictions. Afterwards it was 31 percent. Canada is setting the same age. The difference is that Australia named the services and Canada has not.
Australia has also answered the question C-34 leaves open. eSafety’s regulatory guidance, issued in September 2025, takes a principles-based approach rather than prescribing a technology, but it states that measures will not count as reasonable steps if they rely entirely on self-declaration, or if they allow a deactivated user to immediately create a new account, or if they sweep in substantial numbers of users who are not covered. That is a workable middle ground between naming a technology and saying nothing at all. Notably, the Australian Information Commissioner has an independent role monitoring the privacy provisions of the same scheme.
Canada has done its own work on this. The Office of the Privacy Commissioner did a consultation on age assurance, and that was published in 2025. It is on Parliament's own reading list for Bill C-34. That makes what C-36 does next difficult to explain.
Section 21 states that an operator must integrate into every regulated service the design features respecting the protection of children set out in the regulations. Yet, while Parliament creates the obligation, the details of required design features are up to the new regulator. Nor does the Act require those regulations to exist before the duty applies.
This is the third time the same pattern appears. The minimum age applies to no service, the age check has no standard, and the design duty has no design features.
Bill C-34 defines a child as a person under eighteen years of age. The Act’s protections for children run to that definition: the categories of harmful content that concern children, the duty to protect children, and the design duty in section 21. Bill C-36 uses the same threshold. On the definition of childhood, the two bills agree.
The minimum age for a social media account is sixteen. So the Act creates a group it treats two ways at once. A sixteen- or seventeen-year-old is a child for every protective purpose in the statute, and old enough to hold an account. Nothing in the bill explains the gap, and nothing reconciles the two numbers.
It matters because it decides what a platform has to build. An operator needs to know both whether a user may hold an account, which turns on sixteen, and whether the heightened duties owed to children apply to that account, which turns on eighteen. Those are two determinations, not one, and they have to be held at the same time. The age check that satisfies the account restriction does not by itself answer the second question, because the two provisions are asking different things.
There may well be a reason. Different obligations reasonably attach at different ages, and sixteen is a recognized threshold in several contexts, including in the Act’s own definition of content that sexually victimizes a child. So the government may have chosen deliberately. Neither bill says so, and neither backgrounder explains it. Stating the reason would be valuable to stakeholders. An unexplained choice is easier to defend than an unexplained inconsistency, and operators building to both thresholds need to know which one governs when they conflict.
The strange thing about these two bills is that the second one repeals a section of the first. Section 122 of the Digital Safety Act, one of the two statutes Bill C-34 creates, requires the new Commission to consult the Privacy Commissioner before issuing age verification guidance or making regulations on design features, and to give reasons if it declines that advice. This is not approval. It is a duty to ask and explain.
Section 18 of Bill C-36 repeals it. Section 17 leaves privacy rights on the list of things the Commission must take into account when it makes regulations and issues guidance, and adds the purpose of the new privacy Act to that list, to the extent the Commission considers appropriate. So C-34 says one thing about consulting the Privacy Commissioner, and C-36 removes it completely. The new Commission becomes the body that weighs privacy, not the Privacy Commissioner, with no duty to seek outside advice or to explain why it did not follow it.
This has not gone unnoticed. Michael Geist has written on the repeal, reading it as a consequence of privacy responsibility shifting to the new commission.
C-36 goes so far as to even change the very name of the Commission, replacing references to the “Digital Safety Commission of Canada Act” with “Digital Safety and Data Protection Commission of Canada Act.”
What the Act leaves out matters as much as what it covers. Several well-identified harms to children, ones regulators have worked on for years, fall outside it.
Private messaging is not included, so direct messages are out entirely, which is where sextortion and bullying happen. The Canadian Centre for Child Protection publishes the numbers. In 2025 it recorded 2,827 sextortion reports, up from 963 in 2021. Of the under-18 reports where gender was recorded, about 84 percent involved boys. Across 2020 to 2025 the total is 14,153.
That same private messaging sits inside Roblox and other games, and it is not addressed either. Neither are services that do not enable public communication, marketplaces and advertising, or maps and navigation.
Fraud is not covered at all. With data from the Canadian Anti-Fraud Centre, the Competition Bureau reported in March 2026 that Canadians lost more than $704 million to fraud in 2025, with reported losses since 2022 now above $2.4 billion, and that only 5 to 10 percent of frauds are reported.
One of the largest omissions in this entire package is not the category of content. It is the architecture that decides what content a child sees. The government has demonstrated it understands that. Canadian Heritage's own explanation of the bill online states that online harms are not only the result of individual behaviour, but are also shaped by how digital services are designed and how they are operated, and it names what these features are. They are algorithmic recommendation systems, engagement-based feeds, autoplay, and endless scrolling. These are some of the more concerning practices that lead to the harms that have been discussed in this analysis.
Those features are a proper diagnosis, but they do not appear in the legislation. Neither the word recommender nor the term feed appears anywhere in Bill C-34.
The duty to act responsibly for social media services is a duty to mitigate the risk that the user will be exposed to harmful content. The content that reaches a user, not the design. Sections 31 through 41 are built entirely on that exposure model, as opposed to design. The one duty in the Act that governs how a social media service is designed, section 21, is the empty duty described above.
What that looks like in drafted form already exists. The European Commission’s Article 28 guidelines devote a section to recommender systems, and the requirements are specific: platforms should regularly test and adapt their recommender systems, consulting minors, guardians and independent experts; they should prioritise accuracy, diversity, inclusivity and fairness when setting the objectives, parameters and evaluation strategies of those systems; they should not collect behavioural data capturing a minor’s activity off the platform; and where they do process behavioural data, it should not be so extensive as to capture all or most of what a minor does on the service. Separately, the guidelines say minors should not be exposed to persuasive design features aimed predominantly at engagement, and they name them: indefinite scrolling, autoplay, and notifications artificially timed to regain a minor’s attention.
Those are the same features Canadian Heritage named. The difference is that one of them is written down as an expectation a regulator will assess, and the other is a paragraph on a departmental web page.
It is worth being precise about the comparison. Article 28(1) is broadly drafted too, and the detail came from guidelines rather than from the statute. So the EU deferred as well. The difference is not deferral, it is that the European regulator has published, and Canada’s has not been created.
This is not an isolated reading. The Canadian Civil Liberties Association has argued that the bill should specify age-appropriate design requirements rather than leave them to regulation, naming privacy by default, limits on profiling and limits on endless scrolling as the sorts of requirements that would provide real protection. In Policy Options, Natasha Tusikov and Blayne Haggart went further, arguing that the duty to act responsibly is a form of corporate social responsibility that asks platforms to police themselves, and that rules need to address design and business models rather than relying on operators to implement adequate measures. Their prescription and mine differ, but the diagnosis is the same. What this analysis adds is the textual evidence: neither term appears anywhere in the bill.
The Act also shows that its drafters knew how to leave room for what has not been invented yet. Section 53(e) lets the Commission add any other harmful chatbot behaviour by regulation, so the chatbot duties can grow as the techniques do. The social media duties have no equivalent open category. The future-proofing was written on one side of the Act and not the other.
The Digital Safety Act applies the age restriction only to social media. It does not apply it at all to chatbots run by artificial intelligence. What that means is that a child can be barred from Facebook or Instagram, but nothing in the Act stops him or her from opening a companion app such as Character AI, or a general assistant such as ChatGPT, and forming a relationship that is not healthy, or using the tool for unhealthy purposes.
Section 53 of the Act requires the operators of AI-driven chatbots to take adequate measures to reduce the risk of four kinds of behaviour: posing as a human; posing as a medical, legal or other licensed professional and giving advice on that basis; using manipulative engagement techniques that encourage emotional attachment causing social withdrawal or disconnection from reality; and encouraging self-harm, suicide or serious violence.
The third of those deserves particular attention. Manipulative engagement techniques is the language that links directly to the attention economy, doing whatever holds the attention of a user. It is worth noting that the bill puts this language into statute. The same idea has been argued in the United States: the state attorneys general accused Meta of using psychologically manipulative features, though the case settled with no admission of liability. In New Mexico, a court went further and found Meta’s platforms to be a public nuisance, ordering new safeguards for minors and comparing them to a polluting factory.
Meta settled with 51 attorneys general for up to $17.1 billion, which they described as the largest state consumer protection settlement outside the tobacco settlements of the 1990s. That was their comparison, not mine.
The phrase appears once in the entire bill, and only here. A statute called the Safe Social Media Act makes its clearest statement about manipulative design in the provisions that do not govern social media.
While we are covering a great many harms, Bill C-34 builds in the importance of preserving the benefits of these technologies. Its purposes expressly include enabling people in Canada to take part fully in public discourse online and to benefit from chatbot services while reducing the risk of harm, and its measures must not unreasonably or disproportionately limit expression.
For children in rural areas, for disabled young people, and for abused youth, online communities have proven to be an important and often the only place they can find something to relate to. The same is true of education: assistive technology, video instruction and tutoring reach children that a classroom alone does not, and they reach them furthest where distance and cost are the barrier. It is the yin and yang of social media: the positive effects and the negative ones come from the same platforms.
These bills are aimed purely at the operators. What they miss, in terms of online safety, is parental and guardian responsibility.
MediaSmarts, an organization that looks closely at how children and technology interact, surveyed just over a thousand Canadian children aged nine to seventeen. It found that 77 percent own a smartphone, that most were given their first between the ages of 11 and 13 by a parent or guardian, and that 80 percent keep the phone in their bedroom overnight. So it is parents who are providing children with these handheld computers.
That overnight figure is the one to sit with. It is not that the household is where sole responsibility sits. It is that a good deal of the exposure happens there, and that no federal statute reaches it. A bill aimed at operators can require an age check and a safety plan. It cannot decide what time a phone leaves a bedroom.
The educators surveyed above put this first. Asked what contributes to student mental health problems in their schools, 92 percent named lack of parental involvement and communication, ranking it above social media use at 84 percent. The people closest to the children put the household at the top of the list.
There is a serious argument against this framing and it deserves stating. Respondents to the Privacy Commissioner’s consultation put it directly: there has been a constant downloading of responsibility onto parents and children to act within their limited resources in the face of predictable harms, and society does not hold parents responsible for preventing access to other legal but restricted products such as cigarettes and alcohol. Others noted the bind parents are in between enforcing a restriction and letting a child fit in socially.
This is not a counsel of despair. The same Gallup survey that measured the hours also found that active parenting practices measurably reduce the mental health harms associated with heavy social media use. The household is not powerless. It is simply not addressed by either bill.
This isn’t a problem this legislation can fix alone, nor is it one parenting can fix alone. Both are the solution.
What follows are not positions. They are the places where, on reading the two bills against the standards, the guidance and the practice of comparable jurisdictions, questions remain open that committee is well placed to examine.
This cannot be a blame game. The courts are one way public policy is being influenced, in the United States and elsewhere, but everyone has a role here, including parents, educators and the platforms themselves. It cannot be a gripe aimed at social media companies, given the benefits these models do indeed provide.
For committee, by amendment to section 32 of the Digital Safety Act
The question for committee is whether the duty to act responsibly should reach engagement design as well as exposure to content. If it should, the drafting is not difficult, because the risk mitigation duty with its listed factors is already in section 32. A further paragraph addressed to engagement design would put the feed inside a structure that already exists, and there is drafted language in the European guidelines to work from. Two subsidiary questions follow: whether the harm being mitigated is named in the amendment itself, and whether the Commission is asked to explain publicly what these techniques are and how they work on adults and children alike.
For the Commission, by regulation under section 126(1)(c)
The work has already been done. ISO/IEC 27566-1:2025, the international standard on age assurance systems, contains exactly what section 27(2) leaves out.
The standard requires that classification accuracy be determined, recorded and regularly reviewed for each configuration of a system, and stated in a practice statement. It says systems should measure and report a false positive rate and a false negative rate. It sets out outcome error parity, meaning that error rates should be consistent across demographic groups regardless of gender or ethnicity, and makes low error spread across demographics a requirement of an effective system. And it states that a system relying solely on self-asserted age, which includes ticking a box to say you are over a certain age, shall be considered ineffective for making an age-related eligibility decision.
That last sentence is the click-through example above, settled in an international standard, in normative language. Parliament wrote that its measures must be effective and left effective undefined. The definition already exists.
Whether to adopt it is a decision for the Commission under section 126(1)(c), and the questions worth putting are these. Should conformity with the standard be required, or something less? Should independent testing against the metrics it names be a condition? Should the error rates be required to hold across demographic groups? Should there be an accessible fallback for people the technology fails? And should the obligation commence before conformity assessment is available in Canada, given that a duty to be effective is difficult to enforce without a way to test it?
For the House, on section 18 of Bill C-36
Section 122 of the Digital Safety Act requires the Commission to consult the Privacy Commissioner before it issues age verification guidance or makes regulations on design features, and to give reasons if it declines the advice. Section 18 of Bill C-36 repeals it. The duty is inexpensive to comply with, and as drafted it is the only external privacy check on a decision that will determine how much personal information Canadians hand over to prove their age. Whether that check should survive is a live question for the House.
The government has a reason, and it deserves to be put fairly. If private sector privacy moves to the Commission, then consulting the Privacy Commissioner can look like consulting a body that no longer holds the file. The counter-argument is that the section was protecting independence rather than jurisdiction. The Privacy Commissioner is an Agent of Parliament. The members of the new Commission are appointed by the Governor in Council. On that reading, removing the duty removes not a redundancy but the last voice in the process that does not report to the same place as the decision maker. Committee is well placed to decide which reading is right.
Comparable countries do not merge these functions, they connect them. The United Kingdom keeps data protection with the Information Commissioner’s Office and online safety with Ofcom. Australia keeps privacy with the Office of the Australian Information Commissioner and online safety with the eSafety Commissioner, and in April 2026 those two regulators signed a memorandum of understanding covering exactly this intersection: age assurance requirements under Australia’s industry codes, and compliance with its social media minimum age obligations. The eSafety Commissioner’s stated reason is worth reading beside Canada’s repeal. She said her office knew from the outset that implementing the minimum age would have to recognise important rights, including the right to privacy.
That arrangement is already producing work. The Australian privacy regulator published guidance on the privacy dimensions of the minimum age scheme in October 2025, and further age assurance guidance in March 2026, alongside the safety regulator’s own regulatory guidance. Two bodies, two mandates, coordinated by agreement. Canada is proposing to solve the same problem by putting both mandates in one body and deleting the duty to consult.
If Parliament does decide the privacy mandate should move, there is an intermediate option on the table: replacing section 122 with a statutory duty to coordinate with the Privacy Commissioner on age assurance, on the Australian model, rather than removing the connection altogether.
For the Commission and the Minister, under sections 126(1)(r), 128 and 129
There is a requirement to review the minimum age within three years, in section 129, but nothing says what that review would measure. It just says it will be a review. Three years from now, someone will stand up and say the rule is working or that it is not, and we do not have anything that would tell us which of them is right. Naming the indicators before the clock starts is one way to avoid a Commission defining its own success after the fact.
There is a simpler version of this that the Act has already half built. Section 42 requires every operator to describe, in a public safety plan, the indicators it uses to judge whether its own measures work, and every operator chooses its own. If the Commission specified a common set, the plans would become comparable across companies and across years, and the review would have something to read. That would be a regulation rather than an amendment, which places it within the Commission's own authority rather than requiring Parliament to act.
For committee, on the Digital Safety Act and the Digital Safety Commission of Canada Act
This sits alongside the first consideration rather than against it. Both concern the same question: how much of the substance is settled by Parliament and how much is left to a regulator to fill in later. Reasonable people answer that differently, and where the line falls is exactly the sort of question committee exists to work out.
The Commission will decide whether measures against harmful content are adequate, what design features are required, what an adequate age check is, and what a compliant safety plan looks like. Almost none of that is settled in the statute. The reassurance that its powers are bounded therefore has to come from somewhere, and at present it comes from very little: members appointed by the Governor in Council, no duty to consult the Privacy Commissioner once section 122 is repealed, and thirty-one separate heads of regulation-making power under section 126(1). Two options are worth weighing: naming the limits of those powers in the Act, and requiring reasons when the Commission departs from advice it has sought. Neither is expensive, and both speak to the objection, already being raised from several directions, that the Act hands a great deal to a body that does not yet exist.
For government, in designing the Commission before it is established
Canada has a long history of creating arm’s length agencies and commissions, from the Canada Revenue Agency to the Privacy Commissioner. It is much better at creating them than at deciding how they should be designed, governed and evaluated. As we have seen with the CRA, weak oversight has contributed to service standard shortfalls and to internal misuse of powers. Other arm’s length bodies have a history of scope creep, taking on broader powers without checks from elected offices. Whether that record is reviewed before another such body is built, and whether what is learned is made public, is a question worth putting to the government.
The gap is not a matter of opinion. Carey Doberstein of the University of British Columbia argued in Canadian Public Administration in 2026 that Canadian scholarship on arm’s length agencies remains largely absent from the international literature on agencification. He says the field has tended to examine these bodies after a scandal rather than study how they should be designed in the first place. He identifies three unresolved problems: how to tell whether such a body is performing, who is accountable when something goes wrong in an organization deliberately separated from ministers, and how to keep a body independent when government controls the appointments.
All three land on the Digital Safety Commission. It will decide whether measures against harmful content are adequate, what design features are required and what an adequate age check is. Its members are appointed by the Governor in Council. Nothing in the Act says how its performance will be judged.
There is a precedent worth putting in front of committee. The Conservative government’s Federal Accountability Act of 2006 amended the Salaries Act to provide that the Governor in Council may establish a Public Appointments Commission, to set guidelines for appointments to agencies, boards, commissions and Crown corporations, approve and review the selection processes ministers propose, and report annually to the Prime Minister for tabling in both Houses. A chairperson was nominated in April 2006. The nomination did not survive committee, and the Commission was shelved.
The secretariat, however, was created as a federal department by order in council, reporting directly to the Prime Minister. It continued for years. Treasury Board reporting for 2009-10 records that because the Commission was not established or operational, the secretariat’s work was completed in draft, subject to approval by a Commission that did not exist, with no permanent staffing. By 2012 the CBC reported that millions had been spent supporting a commission that had never come into being. The Commission was never established.
That is the same pattern described earlier in this analysis, twenty years before these bills. A power written as may rather than must, an institution left to a later decision that never came, and machinery funded to support a body that did not arrive. It is also a case where how the body was designed and who was appointed to lead it turned out to be one problem: the Commission failed because its first appointment was contested, which is precisely the vulnerability Doberstein identifies.
The drafting fix in recommendation one is small and sits inside a structure the bill already has. Section 32 sets a risk-mitigation duty with adequacy factors; a further paragraph addressed to engagement design would not require a new regime. The harder question at committee will be whether that can be done without reopening the expression arguments that sank the previous online harms bill.
The minimum age applies only to services Cabinet specifies, the standard for an adequate age check is undefined, and the design features do not exist. The planning question is therefore not compliance but sequencing: which obligations commence before their standards are written, and what a client is expected to have built by then. C-36 cannot commence before the new Commission exists, so a privacy transition and a safety transition are tied together.
Educators play a critical role in identifying outcomes, as they are often first on the ground to see them. Whether a child still comes in and falls asleep at their desk is the kind of reality check policy makers depend on. Neither bill reaches the classroom, the household, or private messaging, which is where much of what teachers actually see takes place. What the Act does reach is the seven categories of content and, eventually, the design of the services. The gap between those two things is the space provincial policy and school practice will continue to occupy, and the federal instrument was never built to close it.
Legislation and government
International
Research
Commentary