The Privacy Commissioner Has Told Ottawa Where Privacy Act Reform Should Go. Here Is What It Means for Your Institution.
The federal Privacy Act, the law that governs how government institutions collect, use, and protect personal information, is being modernized. On August 5, 2026, the Privacy Commissioner of Canada filed his formal views with the Treasury Board. If you lead a federal institution, that submission is an early map of what may be coming, and it is worth reading before the wording is settled.
The headline is straightforward. The Commissioner broadly supports the direction of reform. The value for executives is in the detail, because that is where he asks Ottawa to push harder.
A few of the moves that caught our attention:
- Breach rules with real deadlines. Not simply a duty to manage breaches, but fixed timelines to notify affected people and the Commissioner, and a power for his office to inspect your breach records.
- Mandatory Privacy Impact Assessments that name AI directly. The submission calls for assessments in high-risk situations, including high-impact AI systems and the training of models on personal information. If your institution is deploying AI, this one is aimed squarely at you.
- Genuine order-making powers. The Commissioner wants the ability to issue binding orders, rather than only asking an institution to publish a corrective plan and hoping it follows through. Enforcement with teeth changes the calculus for every program lead.
- A firm no to one proposal. The government floated moving personal-information access requests into the Access to Information Act. The Commissioner pushed back, and his reasoning matters for how your access and privacy function is structured.
None of this is law yet. It is a submission on a discussion paper, which is exactly why now is the moment to understand it. No good picking up speed if you are on the wrong road, and the road here is still being drawn.
We have read the submission closely and distilled it into a plain-language client briefing built for public sector leaders. It sets out where the Commissioner supports the government, where he wants more, the two proposals he singled out, and the identifiability standard he wants written into the Act. It is made to be read in one sitting by people who do not have time to work through the full submission, generating their own interpretations.
Request the Client Briefing
Download the full Client Briefing here
Newport Thomson. Canadian privacy and data compliance, translated into plain language.
