2026 Review of the Privacy Act
Submission of the Information Commissioner
July 2026
Table of contents
- Message from the Commissioner
- Replacing “personal information” with “personal data”
- Personal information sensitivity spectrum
- Automated decision systems
- Information sharing and control
- Compassionate disclosure
- Business or professional contact information
- Ministerial advisers and staff members
- Incorporating privacy requests into the Access to Information Act
Message from the Commissioner
I am pleased to submit my comments on the Government of Canada’s "2026 Review of the Privacy Act: Policy Approaches" consultation document, published on April 2, 2026. Consistent with my submissions in 2019 and 2021 in response to Justice Canada’s previous reviews of the Privacy Act, this submission focuses exclusively on issues that have direct implications for the Access to Information Act and its regime.
I welcome the Government’s renewed attention to this important reform initiative. Modernization of the Privacy Act is indeed long overdue. However, it is imperative that any amendments to the Privacy Act, or to the broader administrative and policy framework that supports it, be designed with full consideration of their impact on the right of access. Reforms must not inadvertently weaken existing access rights, create new barriers to transparency, or introduce operational or legal gaps that undermine the effectiveness of the Access Act.
In my view, several elements of the Policy Approaches document suggest that the potential consequences on the right of access have not been sufficiently examined. As the Government proceeds, it must ensure that the modernization of the privacy regime is undertaken in a manner that preserves the balance between access and privacy rights essential to the integrity of both regimes. These rights are foundational to democratic accountability, public trust, and effective oversight.
Caroline Maynard
Information Commissioner of Canada
Replacing “personal information” with “personal data”
Currently, “personal information” is defined in the Privacy Act as “information about an identifiable individual that is recorded in any form” and includes a non-exhaustive list of examples as well as exceptions to the definition. Throughout its 2026 Review of the Privacy Act: Policy Approaches document, the Treasury Board Secretariat (TBS) uses the terms “personal information” and “personal data” interchangeably. TBS proposes replacing “personal information” in the Privacy Act with “personal data” and creating a new definition. The reason for this, it states, is because “the current definition limits personal information to data that is recorded in any form. The new definition would remove that requirement.”
Because the Privacy Act and the Access to Information Act currently share the same definition of “personal information,” it is not yet clear how the proposed shift to “personal data” would interact with the Access to Information Act. Clarifying this relationship will be important to ensure that changes to the Privacy Act do not have unintended consequences on the right of access.
Recorded vs unrecorded
If TBS’s policy goal is to provide privacy protections for unrecorded personal information, TBS could propose to remove “recorded in any form” from the definition of personal information in the Privacy Act for these purposes. TBS did indicate that the right of access under the Privacy Act should only apply to recorded personal data. However, “recorded in any form” must also be maintained in the Access to Information Act, as this statute’s entire structure is premised on access to information in “records”.
Personal information vs personal data
Other than including unrecorded personal information, TBS did not provide a definition for “personal data”, nor did it articulate a need to move away from the term “personal information”, i.e., information about an identifiable individual.
The term “personal information” has long been defined in Canadian legislation and jurisprudence. It can currently be found in 460 federal laws and regulations. By contrast, “personal data” occurs in only 7 federal laws and regulations, all pertaining to international agreements with other countries that use this terminology.
Personal data is generally understood to be broader than personal information, encompassing any information that relates to an identified or identifiable individual. Different pieces of information, which together can lead to the identification of a particular person, may also be considered personal data. For example, personal data that has been de-identified, encrypted or pseudonymized but can be used to re-identify a person is still considered personal data in the European Union and the UK.
While the protection of such categories of information might be appropriate from a privacy security perspective, the Policy Approaches document does not address whether the definition of “personal information” would be amended in consequence, or how different definitions would be reconciled across the Privacy Act and the Access to Information Act. This could have a significant impact on the rights of access provided in both Acts.
Privacy requests under the Privacy Act
The Privacy Act provides individuals with a right of access to their personal information. Because TBS has not defined “personal data”, it is unclear how this amendment could impact the right of access under the Privacy Act. A broader definition would seem to reflect greater access; however, taken in combination with other proposals, it appears that the result could be one of less access through privacy requests.
For example, TBS proposes adding a definition for de-identified personal data to the Privacy Act, which is personal data that has been modified “so that an individual cannot be directly identified from it, though a risk of the individual being identified remains”. The proposal states that because individuals cannot be readily identified, de-identified data is not accessible through a privacy request. This definition introduces new thresholds of risk of re-identification and “readily identified” without explanation and is not consistent with the treatment of similar data in jurisdictions that use the term “personal data”. These jurisdictions provide distinctions between the kinds of information required to re-identify the data and treat data holders differently depending on what additional re-identification information they have access to.
This raises several questions, such as: If an institution can re-identify the individual, will there be an obligation to do so, or will all datasets, once “de-identified”, be inaccessible through a privacy request? And if they are not accessible through a privacy request, will they be accessible through an access to information request?
Personal information exemption in the Access to Information Act
Similarly, replacing “personal information” with “personal data” risks expanding the mandatory exemption found in the Access to Information Act, particularly as it relates to the concept of identifiability, and diminishing the right of access.
Subsection 19(1) of the Access to Information Act prohibits the disclosure of information that meets the definition of “personal information” within the meaning of the Privacy Act. Subsection 19(2) of the Act provides an exception to the general prohibition against disclosure of personal information.
Section 19 is the most widely used exemption in the Access to Information Act. In 2024-25, institutions invoked this exemption in 47% of access requests, or 95,451 times.
I do not support the replacement of the term “personal information” with “personal data”. Further, I am of the view that any legislative amendments to the definition of “personal information” should be consistent with the legal standard for identifiability. The legal standard is the “serious possibility” test:
Information will be about an identifiable individual where there is a serious possibility that an individual could be identified through the use of that information, alone or in combination with other available information.Footnote 1
In a 2019 decision under the Access to Information Act, the Federal Court found that the “serious possibility” test envisions a possibility that is greater than speculation or mere possibility, but that does not reach the level of more likely than not on a balance of probabilities.Footnote 2
Questions arise on the perspective from which identifiability is to be determined, including to whom the “other available information” is available. The 2019 Federal Court decision provided some clarity on these points, in the context of an application for disclosure under the Access to Information Act:
- Information kept confidential in the hands of a government institution cannot be considered “available” for the purposes of the analysis of identifiability;
- The fact that an individual may be able to identify themselves from released information does not make the information personal; but
- The scope of “available information” cannot be limited to information available to the public, or even an informed and knowledgeable member of the public. Instead, information held by a smaller subset of the public, including a private employer, can constitute “available information” depending on the circumstances.
TBS’s proposals regarding identifiability and public availability do not appear to be consistent with this jurisprudence and risk having a negative impact on the right of access.
Personal information sensitivity spectrum
TBS proposes a spectrum of protections for various categories of personal information in order to bolster protections for sensitive information. TBS did not appear to have considered, however, how this spectrum should be considered in providing access to information. For example, would the sensitivity or non-sensitivity of the information be taken into account when institutions exercise their discretion to decide whether to disclose personal information under subsection 19(2) of the Access to Information Act; or would it constitute an additional circumstance under paragraph 19(2)(c) (for example, for de-identified personal information)?
As I have previously recommended, I am of the view that both the Privacy Act and the Access to Information Act should allow heads of government institutions to provide access to personal information where disclosure does not constitute an unwarranted invasion of privacy. This would provide a balanced approach that links the level of protection to the seriousness of the harm in disclosure to an individual’s privacy.
Some information that meets the current definition of “personal information” may not always warrant protection in some specific circumstances where the disclosure would not constitute an “unjustified invasion of a person’s privacy.” Taking into account the particular circumstances and context of the information in question ensures the protection of sensitive personal information, and disclosure of non-sensitive personal information.
Automated decision systems
Further uncertainty arises in TBS’s proposal to amend the Privacy Act to require institutions, “upon request”, to explain how an automated decision system (ADS) supported a decision and what personal data was used. TBS suggests that “this requirement would help individuals check if the data used is accurate and ask for corrections if needed. People could also ask for a human review of a decision if they believe the (system) made a mistake or used incorrect or incomplete personal data.”
Despite stating that this is an amendment to the Privacy Act, it is unclear whether this proposed request for information about an automated decision system (ADS) is properly an access to information request (for general records), a privacy request (for one’s own personal information), or another kind of request apart from either Act. How would an institution explain how an ADS supported a decision: By creating a record? By providing existing records that describe the process? If it is the latter, why must these be requested? Why couldn’t these be proactively disclosed? How could a person request review or correction if they do not have access to the personal information used by the system – if, for example, the personal information is stored in de-identified form or is not recorded?
Information sharing and control
TBS also proposes greater sharing of personal information across institutions, and the creation of designated official sources of personal information. This proposal needs to clarify whether both the sharing and receiving institutions have control of this personal information for the purposes of access to information and privacy requests. In addition, while I support the idea that TBS create a registry of official sources, it should also publish what information is held by each institution to facilitate access and privacy requests.
Finally, any new requirements to dispose of personal information that is no longer required should align with TBS’s proposal under its 2025 review of the Access to Information Act to require institutions to proactively publish their retention and disposal schedules.
Compassionate disclosure
I have and will continue to recommend that consideration be given to amending section 26 of the Privacy Act and section 19 of the Access to Information Act (the sections relating to personal information), in order to give the head of an institution the discretion to disclose personal information about a deceased individual to a parent or close relative for compassionate reasons, as long as the disclosure is not an unreasonable invasion of the deceased’s privacy.
Although the Act allows for disclosure of personal information where it is in the public interest to do so, my office has conducted investigations where the deceased’s personal information could not be disclosed to the grieving family members because the public interest in disclosure “clearly outweighing any invasion of privacy that could result from the disclosure” could not be identified.
Such an amendment would allow the institution to take into account competing contextual factors, and decide whether to disclose the personal information based on these factors, including compassionate reasons.
This exemption already exists in many provincial access to information and privacy laws, notably the laws of Alberta, Saskatchewan, Manitoba, Ontario, New Brunswick, Prince Edward Island and Newfoundland and Labrador.
I maintain that compassionate disclosure would best be addressed by legislative reform.
Business or professional contact information
The disclosure of the name, title, and business or professional address and telephone number of an employee should be permitted if it appears on a record in the course of a business, professional or official activity.
Currently, institutions are under an obligation not to disclose such information unless the individual to whom the information relates consents to the disclosure, the information is publicly available, or the disclosure is in accordance with section 8 of the Privacy Act. This type of information, usually found in email messages and on business cards, is routinely disclosed in the private sector. Therefore, the Act should be amended to permit the disclosure of business or professional contact information in response to access requests, either in circumstances where there is no unreasonable invasion of privacy or by excluding it from the definition of “personal information.”
Ministerial advisers and staff members
While paragraph 3(j) of the Privacy Act sets out an exception for information about individuals who are or were officers or employees of government institutions that relates to their position or functions, paragraph 3(j.1) sets out a much narrower exception for information about ministerial advisers and staff. Specifically, the paragraph 3(j.1) exception applies only to the fact that an individual is or was a ministerial adviser or staff member, and the individual’s name and title, on records created after June 21, 2019.
I am of the view that the scope of the exception relating to ministerial advisers or staff members should be more consistent with paragraph 3(j) to allow for greater transparency.
Incorporating privacy requests into the Access to Information Act
TBS proposes incorporating individuals’ right to access their own personal information into the Access to Information Act. I would support a harmonized framework leading to a clearer, more efficient, and more user-friendly process for both requesters and institutions. In an environment of limited resources, a well-designed unified access model presents an opportunity to modernize how we work by bringing together processes, expertise, and resources to support more seamless and responsive service delivery.
Greater alignment between access rights and privacy rights could reduce duplication and delays and better advance the legislative objectives of our respective Acts. An assessment of costs, benefits, and operational impacts would help position the model for success and maximize its value for institutions’ Access to Information and Privacy (ATIP) units, the offices of both Commissioners, and above all, Canadians.
Any unified legislative framework for handling all access requests and related complaints aimed at enhancing efficiency and coherence must ensure that the federal right of access and collateral privacy rights are not diminished. It must also ensure that the necessary resources are in place to support its implementation. Several implementation considerations and opportunities for clarification would need to be addressed if this change were pursued, including:
- Coordination of processes to simplify making and responding to requests;
- Harmonization of complaint grounds and admissibility requirements, including applicable timelines;
- Alignment of time extension provisions;
- Consideration of the specific exemptions provided for in each Act; and
- Review of filing timelines and grounds for review before the Federal Court.
Additional clarification would also be beneficial regarding certain aspects of the proposal. In particular, the proposal does not address whether the right of individuals to seek correction to their personal information will remain in the Privacy Act and which Commissioner would receive complaints on this subject. The proposal also does not address the current requirement in the Access to Information Act for me to consult with the Privacy Commissioner if I intend to order disclosure of information that has been exempted under section 19 as personal information.
In addition, as described above, despite referring to privacy requests as personal data requests, TBS does not mention whether the definition of “personal information” would be amended in the Access to Information Act, or how different definitions would be reconciled across the two Acts. The concept of “personal data” is not raised in TBS’s current review of the Access to Information Act.
Addressing these issues presents an opportunity to harmonize the “access rights” found in the two regimes, and while it may result in a more coherent, efficient, and sustainable system—one that better serves requesters and institutions while making optimal use of limited public resources - it may also give rise to unintended consequences. The simultaneous review of the Access to Information Act and the Privacy Act presents an ideal opportunity to establish effective legislative solutions that provide predictability and stability for all parties involved through a durable statutory framework.
A more in-depth consultation process with the Privacy Commissioner and myself would be essential to ensure coherence between the two regimes and to mitigate the risks mentioned above.