Part of the AI Regulation News hub.
The Privacy Commissioner of Canada has filed a submission on Privacy Act modernization calling enhanced transparency for automated decision systems a positive step
The Commissioner is not objecting to the government's proposals on automated decision systems. He is asking for the enforcement architecture that would make them mean something.
Bottom line: Not binding. This is a regulator's submission to a Treasury Board Secretariat consultation on reforming the federal Privacy Act. It changes no law and creates no obligation. Any change would require Parliament.
Who this affects: Privacy officers, general counsel and ATIP coordinators at federal institutions; public-sector program leads deploying automated decision systems; and Canadian privacy and administrative-law counsel advising on federal data handling.
Issue date: News release dated 6 August 2026. No deadline is stated in the release.
What changed: The Commissioner has put his position on the record: support for recognising privacy as a fundamental right, for mandatory breach safeguards and reporting, and for enhanced transparency requirements for automated decision systems, plus four further asks the government has not proposed.
Analysis: The four additions are the substance. Transparency about an automated decision is a disclosure duty; mandatory privacy impact assessments for high-risk activities and stronger enforcement are what determine whether anyone tests the system before it is pointed at a person.
Primary sources: OPC news release, 6 August 2026 · OPC submission on Privacy Act modernization · TBS consultation on Privacy Act modernization
- Instrument (EN)
- Submission of the Office of the Privacy Commissioner of Canada: Consultation on Privacy Act Modernization
- Authority
- Office of the Privacy Commissioner of Canada; Commissioner Philippe Dufresne
- Jurisdiction
- Canada, federal public sector
- Status
- Filed with the President of the Treasury Board on 5 August 2026; the TBS public engagement period closed 10 July 2026
- Bindingness
- Non-binding submission. No legal effect on federal institutions
- Issue date / next deadline
- News release 6 August 2026 / no deadline stated
- Recipient
- The Honourable Shafqat Ali, President of the Treasury Board of Canada
- Subject law
- Privacy Act, the federal public sector privacy statute
- Primary source
- https://www.priv.gc.ca/en/opc-news/news-and-announcements/2026/nr-c_260806/
What was filed and to whom
Privacy Commissioner Philippe Dufresne has sent his submission on Privacy Act modernization to the President of the Treasury Board, the Honourable Shafqat Ali. The Office of the Privacy Commissioner announced it in a news release dated 6 August 2026.
The submission responds to a Treasury Board of Canada Secretariat consultation on policy approaches to modernizing the Act. The Privacy Act governs how federal institutions collect, use and disclose personal information; it is the public-sector counterpart to PIPEDA and it has not kept pace with how federal programs now make decisions.
A submission from a regulator to a government consultation is advocacy, not law. Nothing in the release obliges any federal institution to do anything differently today.
Where the Commissioner agrees with the government
The release records support for several measures the government has already proposed. Those include recognising privacy as a fundamental right and including modern privacy principles in the federal public sector privacy law.
The Commissioner also welcomed proposals to make safeguards and the management, notification and reporting of privacy breaches a legal obligation under the law. Breach reporting is currently a policy expectation in the federal public sector rather than a statutory duty, which is a structural gap the release does not spell out but the proposal implies.
On automation, the release is precise and narrow: the Commissioner described enhanced transparency requirements for automated decision systems as a positive step. That is an endorsement of a proposal, not a description of a rule that exists.
The four things he asked for that were not on the table
The release lists additional measures the Commissioner proposed beyond what the government put forward. He asked for strengthened enforcement mechanisms, and for a legislative requirement to conduct privacy impact assessments for high-risk activities.
He also asked for greater authority to collaborate with other oversight bodies, and for an expanded mandate for privacy research and public education, which the release describes as essential to support Canadians and Canadian institutions in safely implementing modern technologies.
Read against the automated decision proposal, the privacy impact assessment ask is the operative one for anyone building a federal AI system. Transparency requirements attach after a system exists and is producing decisions. A statutory assessment duty for high-risk activities attaches before that, and it is the mechanism that would put an AI-driven eligibility or triage system in front of a privacy analysis as a matter of law rather than of internal policy.
What this does not tell you
The release does not describe what the government's proposed transparency requirements would actually require: no notice content, no threshold for what counts as an automated decision system, no exemption structure. Those details, if they exist, are in the TBS consultation document and the OPC submission itself, neither of which is reproduced in the release.
It also gives no legislative timetable. There is no bill number, no reading, and no commitment in the release that any of this reaches Parliament.
Federal institutions currently running automated decision systems are governed by existing instruments, not by this submission. Read the release as a signal of where the OPC will push, and as a fairly good preview of what the Office will expect to see documented if a reformed Act ever arrives.
What we did not verify
We opened and read the OPC news release at priv.gc.ca dated August 6, 2026, including the named recipient, the list of supported measures, the four additional proposals, and the Commissioner's quotation. Everything above is drawn from that page.
We did not open the OPC's full submission, the Treasury Board Secretariat consultation document, or the Privacy Act itself. We cannot tell you what the government's automated decision system transparency proposal says in detail, what high-risk activity would mean in a statutory privacy impact assessment duty, or what enforcement powers the Commissioner is asking for.
We make no claim that federal institutions must now do anything differently, and no claim about whether or when the Privacy Act will be amended. The release supports neither.
Transparency duties for automated decision systems are becoming the default ask across Canadian privacy reform, and the federal public sector is now in that conversation. The point worth carrying into a program review is the Commissioner's second ask: a statutory privacy impact assessment duty for high-risk activities would bind at design time, which is where an automated decision system can still be changed. Nothing here is law yet.
Source File
https://www.priv.gc.ca/en/opc-news/news-and-announcements/2026/nr-c_260806/
Open the OPC news release dated August 6, 2026 and confirm the recipient named as President of the Treasury Board, the sentence describing enhanced transparency requirements for automated decision systems as a positive step, and the four additional measures the Commissioner proposed.
I strongly support prioritizing the modernization of our federal public sector privacy law to allow federal institutions to successfully meet the challenges and opportunities of these digital times. ยท Philippe Dufresne, Privacy Commissioner of Canada, 6 August 2026
FAQ
Does this submission change the Privacy Act?
No. It is a non-binding submission to a Treasury Board Secretariat consultation. Amending the Privacy Act would require legislation, and the release names no bill and no timetable.
What did the Commissioner say about automated decision systems?
The release states he described enhanced transparency requirements for automated decision systems as a positive step. It does not describe what those requirements would contain.
What did he ask for beyond the government's proposals?
Four things: stronger enforcement mechanisms, a legislative requirement to conduct privacy impact assessments for high-risk activities, greater authority to collaborate with other oversight bodies, and an expanded privacy research and public education mandate.
Does this apply to private-sector organizations in Canada?
No. The Privacy Act governs federal institutions. Private-sector federal privacy law sits in a separate statute and is not the subject of this consultation.
Related briefings
Sponsored Training
Practical AI training for regulated professionals, built around verification, documentation and a defensible process. See the courses.