Files
adr-sml/docs/reference/canada-privacy-technology.md
T
Pouya LajevardiandClaude Opus 5 6aaf089b05 feat: rule Q62 by stating the truth; strike the /med-arb/ gloss; re-stamp R18
Pouya's four rulings of 2026-09-01, applied 2026-09-02.

Q62 — RULED "state the truth", not "remove the access". /legal/privacy/
now says two people can read the intake table, names their role, and adds
the two stronger facts the false sentence had crowded out: the handler
role holds PutItem only, and adr-sml-deploy is implicitDeny on all seven
read and write actions. Wording is subject to Pouya's read-through —
Q63(a), with a TODO(pouya) beside the copy.

The ruling named one sentence; a vocabulary sweep found the falsehood in
three places, and the audit then found two more. Five paragraphs now
answer "who can see it" and change together.

The tripwire stays permanently, per ruling, and grew from two
alternatives to five. Every alternative is one string that reached dist/.
Proven both ways against the pre-correction page rebuilt from bd282aa:
exit 1 with 5 matches at dist/legal/privacy/index.html:54,67,67,68,72;
exit 0 on the corrected page, self-test 12 patterns / 36 approved
strings.

/med-arb/ — the gloss is struck with no replacement, per ruling. The
strike left "the section above" pointing at the ADRIC rule set and "the
agreement" with no antecedent; both fixed. The bare designations line
sitting under ADRIC's quoted competence requirement is also struck, which
goes beyond the ruling and is flagged for Pouya.

R18 — re-stamped, two-tier: (a)(c)(d) re-verified against a source,
(b)(e)(f)(g) held on a cadence judgement. All seven hold, no shipped
sentence changed. R18's trigger had NO cutover checklist item and had
stamped five extracts of seven; both fixed. Candidate limb (h) flagged.

R10 — fired and unsatisfied; left open on instruction.

The evidence behind the new privacy sentence was weaker than the
sentence. Re-measured: 33 of 33 roles simulated (23 of 26 carried inline
policies nobody had read; the two CDK lookup roles can read the table),
four trust policies, the CloudFormation escalation path for all five
users, 0 federated providers, root recorded. Every read path terminates
at the same two people.

Two review rounds, 36 findings. 35 fixed, 1 declined. Five of round 2's
were defects in round 1's own fixes; stopped at two per D19.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Md3GndFqWPzK78xAoebsg5
2026-09-02 07:59:50 -04:00

630 lines
60 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# Canadian privacy and AI legislation status, and technology-dispute context
Committed under AGENTS.md R14 and the CLAUDE.md rule it encodes: **anything a
spec makes a claim about must be reachable from the repository.** Every fact
the six `/practice/*` pages state about the world is checkable here or it is
not published.
**Retrieved 2026-08-29.**
> ⚠️ **THIS FILE EXISTS BECAUSE A SPEC NAMED A STATUTE THAT DOES NOT EXIST.**
> `docs/03-content-spec.md` §Practice areas listed *"the 2026 privacy statute"*
> among the market context for `/practice/technology/`. **There is no 2026
> Canadian privacy statute, federal or Ontario.** Bill C-27 — which would have
> enacted the Consumer Privacy Protection Act and the Artificial Intelligence and
> Data Act — died without royal assent when the 44th Parliament's first session
> ended, and was never reinstated. **PIPEDA remains the operative federal
> private-sector statute.** Caught before a word of it reached a page, and only
> because the check was run rather than the phrase trusted.
> ⚠️ **A statute, a bill and a regulation all move.** Bill C-36 in particular was
> at second reading on the retrieval date and could be law, or dead, by the time
> anyone reads this. **Re-check before cutover.**
> ### R18 re-check — cutover pass, 2026-09-01
>
> The trigger fired. `AGENTS.md` §12 R18 holds the per-limb findings and
> the sources; this stamp does not restate them. **The quoted bytes below
> are still the original retrieval and were not re-fetched** — what was
> re-checked is whether the *facts* they support have moved.
>
> - **(a) Bill C-36 — RE-VERIFIED UNMOVED** `[re-checked 2026-09-01 — Pouya,
> <https://www.parl.ca/legisinfo/en/bill/45-1/c-36>]`. Still at second
> reading in the House of Commons; latest completed stage is first reading,
> 2026-06-15; no advance since. `/practice/technology/`'s sentence stands as
> written.
**Topic as researched:** Canadian technology / data / AI dispute context — privacy legislation status as at 2026-08-29, Ontario public-sector and health privacy statutes, data residency law, and Canadian arbitral-institution rules for technology/AI disputes
---
## Sources
| Kind | Source | URL |
|---|---|---|
| statute | LEGISinfo — Bill C-27 (44-1), Digital Charter Implementation Act, 2022 — Parliament of Canada | <https://www.parl.ca/legisinfo/en/bill/44-1/c-27> |
| statute | LEGISinfo bills data (JSON), 44th Parliament 1st Session — Parliament of Canada | <https://www.parl.ca/legisinfo/en/bills/json?parlsession=44-1> |
| institution | House of Commons Procedure and Practice, Fourth Edition (2025), Ch. 8 — Prorogation and Dissolution | <https://www.ourcommons.ca/procedure/procedure-and-practice-4/ch08-7-e.html> |
| statute | Personal Information Protection and Electronic Documents Act (S.C. 2000, c. 5) — Justice Laws Website | <https://laws-lois.justice.gc.ca/eng/acts/P-8.6/FullText.html> |
| statute | LEGISinfo bills data (JSON), 45th Parliament 1st Session — Parliament of Canada | <https://www.parl.ca/legisinfo/en/bills/json?parlsession=45-1> |
| statute | LEGISinfo — Bill C-36 (45-1), An Act to enact the Protecting Privacy and Consumer Data Act — Parliament of Canada | <https://www.parl.ca/legisinfo/en/bill/45-1/c-36> |
| statute | Bill C-36 (45-1), first reading text — Parliament of Canada | <https://www.parl.ca/DocumentViewer/en/45-1/bill/C-36/first-reading> |
| statute | Statutes of Canada 2026, c. 9 — An Act respecting cyber security … — Justice Laws Website | <https://laws-lois.justice.gc.ca/eng/AnnualStatutes/2026_9/> |
| statute | Bill C-8 (45-1), royal assent text — Parliament of Canada | <https://www.parl.ca/DocumentViewer/en/45-1/bill/C-8/royal-assent> |
| regulator | Summary of privacy laws in Canada — Office of the Privacy Commissioner of Canada | <https://www.priv.gc.ca/en/privacy-topics/privacy-laws-in-canada/02_05_d_15/> |
| regulator | Guidelines for processing personal data across borders — Office of the Privacy Commissioner of Canada | <https://www.priv.gc.ca/en/privacy-topics/airports-and-borders/gl_dab_090127/> |
| regulator | Announcement: Commissioner concludes consultation on transfers for processing — Office of the Privacy Commissioner of Canada | <https://www.priv.gc.ca/en/opc-news/news-and-announcements/2019/an_190923/> |
| statute | Personal Health Information Protection Act, 2004 — Ontario e-Laws consolidated text (JSON endpoint behind https://www.ontario.ca/laws/statute/04p03) | <https://www.ontario.ca/laws/api/v2/legislation/en/act-content/statute/04p03> |
| regulation | O. Reg. 329/04 (GENERAL) under PHIPA — Ontario e-Laws consolidated text (JSON endpoint) | <https://www.ontario.ca/laws/api/v2/legislation/en/act-content/regulation/040329> |
| statute | Freedom of Information and Protection of Privacy Act — Ontario e-Laws consolidated text (JSON endpoint behind https://www.ontario.ca/laws/statute/90f31) | <https://www.ontario.ca/laws/api/v2/legislation/en/act-content/statute/90f31> |
| statute | Municipal Freedom of Information and Protection of Privacy Act — Ontario e-Laws (JSON endpoint) | <https://www.ontario.ca/laws/api/v2/legislation/en/act-content/statute/90m56> |
| statute | Enhancing Digital Security and Trust Act, 2024 — Ontario e-Laws consolidated text (JSON endpoint behind https://www.ontario.ca/laws/statute/24e24) | <https://www.ontario.ca/laws/api/v2/legislation/en/act-content/statute/24e24> |
| regulation | Ontario e-Laws — regulations made under the Enhancing Digital Security and Trust Act, 2024 (JSON endpoint) | <https://www.ontario.ca/laws/api/v2/legislation/en/act-reg/regulation?title=enhancing%20digital%20security%20and%20trust%20act%2C%202024&sort=citation> |
| regulation | O. Reg. 51/26 (CYBER SECURITY) under the Enhancing Digital Security and Trust Act, 2024 — Ontario e-Laws (JSON endpoint) | <https://www.ontario.ca/laws/api/v2/legislation/en/act-content/regulation/260051> |
| regulation | O. Reg. 52/26 (DIGITAL TECHNOLOGY AFFECTING INDIVIDUALS UNDER AGE 18) under the Enhancing Digital Security and Trust Act, 2024 — Ontario e-Laws (JSON endpoint) | <https://www.ontario.ca/laws/api/v2/legislation/en/act-content/regulation/260052> |
| institution | Bill 194, Strengthening Cyber Security and Building Trust in the Public Sector Act, 2024 — Legislative Assembly of Ontario | <https://www.ola.org/en/legislative-business/bills/parliament-43/session-1/bill-194> |
| institution | Bills — 44th Parliament, 1st Session — Legislative Assembly of Ontario | <https://www.ola.org/en/legislative-business/bills/parliament-44/session-1> |
| institution | Bill 61, Ontario Artificial Intelligence, Talent and Innovation Strategy Act, 2025 — Legislative Assembly of Ontario | <https://www.ola.org/en/legislative-business/bills/parliament-44/session-1/bill-61> |
| statute | Kids' Online Safety and Privacy Month Act, 2025 — Ontario e-Laws consolidated text (JSON endpoint) | <https://www.ontario.ca/laws/api/v2/legislation/en/act-content/statute/25k25> |
| regulator | Directive on Service and Digital — Treasury Board of Canada Secretariat | <https://www.tbs-sct.canada.ca/pol/doc-eng.aspx?id=32601> |
| regulator | Direction on the Secure Use of Commercial Cloud Services: Security Policy Implementation Notice (SPIN 2017-01) — Government of Canada | <https://www.canada.ca/en/government/system/digital-government/digital-government-innovations/cloud-services/direction-secure-use-commercial-cloud-services-spin.html> |
| institution | ADRIC Arbitration Rules, effective 01 March 2025 — ADR Institute of Canada, Inc. (PDF) | <https://adric.ca/rules/ADRIC-Arbitration-Rules-2025.pdf> |
| institution | Rules & Codes — ADR Institute of Canada | <https://adric.ca/rules-codes/> |
| institution | Artificial Intelligence and Arbitration: A Perfect Fit? — ADR Institute of Canada | <https://adric.ca/artificial-intelligence-and-arbitration-a-perfect-fit/> |
| institution | Who We Are — Canadian International Internet Dispute Resolution Centre (CIIDRC) | <https://ciidrc.org/about-ciidrc/> |
| institution | CIIDRC Supplemental Rules — Canadian International Internet Dispute Resolution Centre | <https://ciidrc.org/domain-name-disputes/ciidrc-supplemental-rules/> |
| institution | CIRA Domain Name Dispute Resolution Policy (reproduced by CIIDRC, a CIRA-approved provider) | <https://ciidrc.org/domain-name-disputes/cdrp-policy/> |
| institution | Rules of Procedure — VanIAC (Vancouver International Arbitration Centre) | <https://vaniac.org/arbitration/rules-of-procedure/> |
---
## Verbatim quotations
### LEGISinfo — Bill C-27 (44-1), Digital Charter Implementation Act, 2022 — Parliament of Canada
<https://www.parl.ca/legisinfo/en/bill/44-1/c-27> — retrieved 2026-08-29
> An Act to enact the Consumer Privacy Protection Act, the Personal Information and Data Protection Tribunal Act and the Artificial Intelligence and Data Act and to make consequential and related amendments to other Acts
> Digital Charter Implementation Act, 2022
> At consideration in committee in the House of Commons
> Second reading and referral to committee on Monday, April 24, 2023
> 44th Parliament, 1st session (November 22, 2021 to January 6, 2025)
### LEGISinfo bills data (JSON), 44th Parliament 1st Session — Parliament of Canada
<https://www.parl.ca/legisinfo/en/bills/json?parlsession=44-1> — retrieved 2026-08-29
> "NumberCode":"C-27" ... "StatusNameEn":"At consideration in committee in the House of Commons"
> "LatestCompletedMajorStageNameEn":"Second reading"
> "ReceivedRoyalAssent":false
> "ReceivedRoyalAssentDateTime":null
> "DidReinstateInNextSession":false
> "IsSessionOngoing":false
> "ParliamentNumber":44, "SessionNumber":1
### House of Commons Procedure and Practice, Fourth Edition (2025), Ch. 8 — Prorogation and Dissolution
<https://www.ourcommons.ca/procedure/procedure-and-practice-4/ch08-7-e.html> — retrieved 2026-08-29
> Government bills which have not received royal assent before prorogation die and, in order to be proceeded with in the new session, must be reintroduced as if they had never existed.
> All items on the Order Paper including government and private members' bills die.
### Personal Information Protection and Electronic Documents Act (S.C. 2000, c. 5) — Justice Laws Website
<https://laws-lois.justice.gc.ca/eng/acts/P-8.6/FullText.html> — retrieved 2026-08-29
> Personal Information Protection and Electronic Documents Act
> Act current to 2026-06-21 and last amended on 2025-03-04.
> 4 (1) This Part applies to every organization in respect of personal information that (a) the organization collects, uses or discloses in the course of commercial activities; or (b) is about an employee of, or an applicant for employment with, the organization and that the organization collects, uses or discloses in connection with the operation of a federal work, undertaking or business.
> 4.1.3 An organization is responsible for personal information in its possession or custody, including information that has been transferred to a third party for processing. The organization shall use contractual or other means to provide a comparable level of protection while the information is being processed by a third party.
> (grep over the full text for the phrases "outside Canada", "stored in Canada", "within Canada" and "localiz" returned exit status 1 and zero lines; instrument check on the same file returned 113 occurrences of "personal information")
### LEGISinfo bills data (JSON), 45th Parliament 1st Session — Parliament of Canada
<https://www.parl.ca/legisinfo/en/bills/json?parlsession=45-1> — retrieved 2026-08-29
> (185 bills in the session; a regex scan of every LongTitleEn and ShortTitleEn for /privacy|personal information|artificial intelligence|consumer privacy|data protection|cyber|digital charter/i returned exactly two: C-8 and C-36)
> "NumberCode":"C-8" ... "An Act respecting cyber security, amending the Telecommunications Act and making consequential amendments to other Acts" ... "StatusNameEn":"Royal assent received" ... "ReceivedRoyalAssentDateTime":"2026-06-15T06:15:00-04:00"
> "NumberCode":"C-36" ... "An Act to enact the Protecting Privacy and Consumer Data Act, to amend the Personal Information Protection and Electronic Documents Act and to make amendments to other Acts" ... "StatusNameEn":"At second reading in the House of Commons" ... "ReceivedRoyalAssent":false
> "PassedHouseFirstReadingDateTime":"2026-06-15T11:18:34.507-04:00"
> (a regex scan of every 45-1 bill title for /intellig/i returned 0 matches)
### LEGISinfo — Bill C-36 (45-1), An Act to enact the Protecting Privacy and Consumer Data Act — Parliament of Canada
<https://www.parl.ca/legisinfo/en/bill/45-1/c-36> — retrieved 2026-08-29
> An Act to enact the Protecting Privacy and Consumer Data Act, to amend the Personal Information Protection and Electronic Documents Act and to make amendments to other Acts
> Sponsor: Minister of Artificial Intelligence and Digital Innovation
> At second reading in the House of Commons
> First reading: Completed Monday, June 15, 2026
> Royal Assent: Not received
### Bill C-36 (45-1), first reading text — Parliament of Canada
<https://www.parl.ca/DocumentViewer/en/45-1/bill/C-36/first-reading> — retrieved 2026-08-29
> This enactment enacts the Protecting Privacy and Consumer Data Act to govern the protection of personal information of individuals while taking into account the need of organizations to collect, use or disclose personal information in the course of commercial activities.
> This Act may be cited as the Protecting Privacy and Consumer Data Act.
### Statutes of Canada 2026, c. 9 — An Act respecting cyber security … — Justice Laws Website
<https://laws-lois.justice.gc.ca/eng/AnnualStatutes/2026_9/> — retrieved 2026-08-29
> An Act respecting cyber security, amending the Telecommunications Act and making consequential amendments to other Acts (S.C. 2026, c. 9)
> Assented to June 15, 2026
### Bill C-8 (45-1), royal assent text — Parliament of Canada
<https://www.parl.ca/DocumentViewer/en/45-1/bill/C-8/royal-assent> — retrieved 2026-08-29
> STATUTES OF CANADA 2026 CHAPTER 9
> ASSENTED TO June 15, 2026
> Part 2 enacts the Critical Cyber Systems Protection Act
### Summary of privacy laws in Canada — Office of the Privacy Commissioner of Canada
<https://www.priv.gc.ca/en/privacy-topics/privacy-laws-in-canada/02_05_d_15/> — retrieved 2026-08-29
> Canada has two federal privacy laws that are enforced by the Office of the Privacy Commissioner of Canada: the Privacy Act, which covers how the federal government handles personal information; the Personal Information Protection and Electronic Documents Act (PIPEDA), which covers how businesses handle personal information.
> PIPEDA sets the ground rules for how private-sector organizations collect, use, and disclose personal information in the course of for-profit, commercial activities across Canada.
> PIPEDA generally applies to personal information held by private sector organizations that are not federally-regulated, and conduct business in: Manitoba New Brunswick Newfoundland and Labrador Northwest Territories Nova Scotia Nunavut Ontario Prince Edward Island Saskatchewan Yukon.
> Date modified: 2018-01-31
### Guidelines for processing personal data across borders — Office of the Privacy Commissioner of Canada
<https://www.priv.gc.ca/en/privacy-topics/airports-and-borders/gl_dab_090127/> — retrieved 2026-08-29
> PIPEDA does not prohibit organizations in Canada from transferring personal information to an organization in another jurisdiction for processing. However, under PIPEDA, organizations are held accountable for the protection of personal information transfers under each individual outsourcing arrangement.
> Principle 4.1.3 of Schedule 1 of PIPEDA specifically recognizes that personal information may be transferred to third parties for processing. It also requires organizations to use contractual or other means to "provide a comparable level of protection while the information is being processed by the third party."
> In contrast to this state-to-state approach, Canada has, through PIPEDA, chosen an organization-to-organization approach that is not based on the concept of adequacy.
> Date modified: 2009-01-27
### Announcement: Commissioner concludes consultation on transfers for processing — Office of the Privacy Commissioner of Canada
<https://www.priv.gc.ca/en/opc-news/news-and-announcements/2019/an_190923/> — retrieved 2026-08-29
> Commissioner concludes consultation on transfers for processing (September 23, 2019)
> guidelines for processing personal data across borders
> remain unchanged under the current law
### Personal Health Information Protection Act, 2004 — Ontario e-Laws consolidated text (JSON endpoint behind https://www.ontario.ca/laws/statute/04p03)
<https://www.ontario.ca/laws/api/v2/legislation/en/act-content/statute/04p03> — retrieved 2026-08-29
> "title": "Personal Health Information Protection Act, 2004, S.O. 2004, c. 3, Sched. A"
> "description": "Consolidation Period: From January 1, 2026 to the e-Laws currency date." / "comment": "Last amendment: 2025, c. 7, Sched. 6, s. 1-13"
> 12 (1) A health information custodian shall take steps that are reasonable in the circumstances to ensure that personal health information in the custodian's custody or control is protected against theft, loss and unauthorized use or disclosure and to ensure that the records containing the information are protected against unauthorized copying, modification or disposal.
> Place where records kept 14 (1) A health information custodian may keep a record of personal health information about an individual in the individual's home in any reasonable manner to which the individual consents, subject to any restrictions set out in a regulation, by-law or published guideline under the Regulated Health Professions Act, 1991 …
> Records kept in other places (2) A health care practitioner may keep a record of personal health information about an individual in a place other than the individual's home and other than a place in the control of the practitioner if, (a) the record is kept in a reasonable manner; (b) the individual consents; …
> Disclosure outside Ontario 50 (1) A health information custodian may disclose personal health information about an individual collected in Ontario to a person outside Ontario only if, (a) the individual consents to the disclosure; (b) this Act permits the disclosure; …
> (grep over the extracted plain text for "outside Canada" returned 0 matches; the only "outside Ontario" provisions are s. 44 research approval, and s. 50 disclosure)
### O. Reg. 329/04 (GENERAL) under PHIPA — Ontario e-Laws consolidated text (JSON endpoint)
<https://www.ontario.ca/laws/api/v2/legislation/en/act-content/regulation/040329> — retrieved 2026-08-29
> "actTitle": "Personal Health Information Protection Act, 2004, S.O. 2004, c. 3, Sched. A"
> "consolidationPeriod": "January 1, 2026"
> (7) Despite subsection 45 (6) of the Act, the Canadian Institute for Health Information may disclose personal health information about an individual to a person outside Ontario where,
> (10) Despite subsection 45 (6) of the Act, Ontario Health may disclose personal health information about an individual to a person outside Ontario where,
> (a grep over the extracted text for "outside canada", "in canada", "outside ontario" and "stored" returned 3 lines, all of them disclosure-permission or health-number provisions; none imposes a storage-location requirement)
### Freedom of Information and Protection of Privacy Act — Ontario e-Laws consolidated text (JSON endpoint behind https://www.ontario.ca/laws/statute/90f31)
<https://www.ontario.ca/laws/api/v2/legislation/en/act-content/statute/90f31> — retrieved 2026-08-29
> "title": "Freedom of Information and Protection of Privacy Act, R.S.O. 1990, c. F.31"
> "description": "Consolidation Period: From July 1, 2026 to the e-Laws currency date." / "comment": "Last amendment: 2026, c. 2, Sched. 7"
> Privacy safeguards (5) The head of an institution shall take steps that are reasonable in the circumstances to ensure that personal information in the custody or under the control of the institution is protected against theft, loss and unauthorized use or disclosure and to ensure that the records containing the personal information are protected against unauthorized copying, modification or disposal. 2024, c. 24, Sched. 2, s. 5. / Section Amendments with date in force (d/m/y) 2024, c. 24, Sched. 2, s. 5 - 01/07/2025
> Breach of privacy safeguards 40.1 (1) The head of an institution shall report to the Commissioner any theft, loss or unauthorized use or disclosure of personal information in the custody or under the control of the institution if it is reasonable in the circumstances to believe that there is real risk that a significant harm to an individual would result or if any other prescribed circumstances exist. 2024, c. 24, Sched. 2, s. 6.
> (grep for "outside Canada" returned exit status 1 and 0 lines; instrument check on the same file returned 248 occurrences of "personal information". "in Canada" appears only at 3 law-enforcement disclosure clauses)
### Municipal Freedom of Information and Protection of Privacy Act — Ontario e-Laws (JSON endpoint)
<https://www.ontario.ca/laws/api/v2/legislation/en/act-content/statute/90m56> — retrieved 2026-08-29
> "title": "Municipal Freedom of Information and Protection of Privacy Act, R.S.O. 1990, c. M.56"
> "description": "Consolidation Period: From July 1, 2026 to the e-Laws currency date."
### Enhancing Digital Security and Trust Act, 2024 — Ontario e-Laws consolidated text (JSON endpoint behind https://www.ontario.ca/laws/statute/24e24)
<https://www.ontario.ca/laws/api/v2/legislation/en/act-content/statute/24e24> — retrieved 2026-08-29
> "title": "Enhancing Digital Security and Trust Act, 2024, S.O. 2024, c. 24, Sched. 1"
> "description": "Consolidation Period: From January 29, 2025 to the e-Laws currency date." / "comment": "No amendments."
> "artificial intelligence system" means, (a) a machine-based system that, for explicit or implicit objectives, infers from the input it receives in order to generate outputs such as predictions, content, recommendations or decisions that can influence physical or virtual environments, and (b) such other systems as may be prescribed;
> 5 (1) This section applies to such public sector entities as may be prescribed for the purposes of this section if they use or intend to use an artificial intelligence system in prescribed circumstances.
> No establishment of private law duty of care 12 Nothing in the Strengthening Cyber Security and Building Trust in the Public Sector Act, 2024 , this Act or any regulation made or directive issued under this Act establishes a private law duty of care owing to any person.
> Effect of failure to comply 13 Failure to comply with this Act or any regulation made or directive issued under this Act does not affect the validity of any policy, Act, regulation, directive, instrument or decision.
### Ontario e-Laws — regulations made under the Enhancing Digital Security and Trust Act, 2024 (JSON endpoint)
<https://www.ontario.ca/laws/api/v2/legislation/en/act-reg/regulation?title=enhancing%20digital%20security%20and%20trust%20act%2C%202024&sort=citation> — retrieved 2026-08-29
> current: 2 results — "regulation/260052" DIGITAL TECHNOLOGY AFFECTING INDIVIDUALS UNDER AGE 18; "regulation/260051" CYBER SECURITY
> revoked: 0 results
### O. Reg. 51/26 (CYBER SECURITY) under the Enhancing Digital Security and Trust Act, 2024 — Ontario e-Laws (JSON endpoint)
<https://www.ontario.ca/laws/api/v2/legislation/en/act-content/regulation/260051> — retrieved 2026-08-29
> "title": "CYBER SECURITY" / "actTitle": "Enhancing Digital Security and Trust Act, 2024, S.O. 2024, c. 24, Sched. 1"
> "consolidationPeriod": "July 1, 2026" / "comment": "No amendments."
> CONTENTS 1. Interpretation 2. Prescribed public sector entities 3. Program 4. Primary point of contact and alternate 5. Cyber security maturity assessment 6. Cyber security maturity assessment summary 7. Critical cyber security incident, report
> (a case-insensitive count of "artificial intelligence" in the extracted text returned 0)
### O. Reg. 52/26 (DIGITAL TECHNOLOGY AFFECTING INDIVIDUALS UNDER AGE 18) under the Enhancing Digital Security and Trust Act, 2024 — Ontario e-Laws (JSON endpoint)
<https://www.ontario.ca/laws/api/v2/legislation/en/act-content/regulation/260052> — retrieved 2026-08-29
> "title": "DIGITAL TECHNOLOGY AFFECTING INDIVIDUALS UNDER AGE 18" / "actTitle": "Enhancing Digital Security and Trust Act, 2024, S.O. 2024, c. 24, Sched. 1"
> "consolidationPeriod": "July 1, 2026" / "comment": "No amendments."
> (a case-insensitive count of "artificial intelligence" in the extracted text returned 0)
### Bill 194, Strengthening Cyber Security and Building Trust in the Public Sector Act, 2024 — Legislative Assembly of Ontario
<https://www.ola.org/en/legislative-business/bills/parliament-43/session-1/bill-194> — retrieved 2026-08-29
> Bill 194, Strengthening Cyber Security and Building Trust in the Public Sector Act, 2024
> Royal Assent received. Statutes of Ontario 2024, chapter 24
> cyber security and artificial intelligence systems at public sector entities
> public sector entities may be required to comply with requirements respecting the use of artificial intelligence, including requirements to provide information, to develop and implement accountability frameworks and to take steps respecting risk management
### Bills — 44th Parliament, 1st Session — Legislative Assembly of Ontario
<https://www.ola.org/en/legislative-business/bills/parliament-44/session-1> — retrieved 2026-08-29
> (139 numbered bills, 1 through 139, listed on a single unpaginated page; a keyword scan of all titles for /privacy|personal information|freedom of information|health information|artificial intelligence|data|digital|cyber|technolog|online/i returned exactly four)
> Bill 15: Kids' Online Safety and Privacy Month Act, 2025
> Bill 61: Ontario Artificial Intelligence, Talent and Innovation Strategy Act, 2025
> Bill 66: Kids' Online Safety and Privacy Month Act, 2025
> Bill 137: Keeping Our Kids Safe Online Act, 2026
### Bill 61, Ontario Artificial Intelligence, Talent and Innovation Strategy Act, 2025 — Legislative Assembly of Ontario
<https://www.ola.org/en/legislative-business/bills/parliament-44/session-1/bill-61> — retrieved 2026-08-29
> Bill 61, Ontario Artificial Intelligence, Talent and Innovation Strategy Act, 2025
> Private member's bill
> November 24, 2025 — Second Reading — Lost on division
### Kids' Online Safety and Privacy Month Act, 2025 — Ontario e-Laws consolidated text (JSON endpoint)
<https://www.ontario.ca/laws/api/v2/legislation/en/act-content/statute/25k25> — retrieved 2026-08-29
> "title": "Kids' Online Safety and Privacy Month Act, 2025, S.O. 2025, c. 25"
> "description": "Consolidation Period: From December 11, 2025 to the e-Laws currency date."
> Kids' Online Safety and Privacy Month 1 The month of October in each year is proclaimed as Kids' Online Safety and Privacy Month.
> 2 Omitted ( provides for coming into force of provisions of this Act ). 3 Omitted (enacts short title of this Act).
### Directive on Service and Digital — Treasury Board of Canada Secretariat
<https://www.tbs-sct.canada.ca/pol/doc-eng.aspx?id=32601> — retrieved 2026-08-29
> Information and data residency
> 4.3.24 Ensuring that computing facilities located within the geographic boundaries of Canada or within the premises of a GC department located abroad, such as a diplomatic or consular mission, be identified and evaluated as a principal delivery option for all sensitive electronic information and data under government control that has been categorized as Protected B or Protected C or is classified;
> Date modified: 2025-08-29
### Direction on the Secure Use of Commercial Cloud Services: Security Policy Implementation Notice (SPIN 2017-01) — Government of Canada
<https://www.canada.ca/en/government/system/digital-government/digital-government-innovations/cloud-services/direction-secure-use-commercial-cloud-services-spin.html> — retrieved 2026-08-29
> SPIN No.: 2017-01 Date: November 1, 2017 Date modified: June 23, 2022
> 6.2.2 Data residency — Departments are expected to apply the Directive on Service and Digital when implementing safeguards for GC electronic data residency.
### ADRIC Arbitration Rules, effective 01 March 2025 — ADR Institute of Canada, Inc. (PDF)
<https://adric.ca/rules/ADRIC-Arbitration-Rules-2025.pdf> — retrieved 2026-08-29
> ADRIC ARBITRATION RULES Effective 01 March 2025
> ADRIC intends these Rules for Canadian commercial disputes; however, parties can apply them to international or non-commercial disputes.
> Privacy and Security of Evidence 31. Each party and its counsel are responsible for ensuring that all relevant privacy and data security requirements prescribed by law or contract in relation to evidence put forward by that party are complied with, and that the Tribunal is made aware of any steps that the Tribunal needs to take in that regard.
> (a case-insensitive grep of the extracted 103,811-character text for "artificial intelligence", "machine learning" and the standalone token "AI" returned no matches; the only hits for "technolog|cyber|data|electronic" were three lines about electronic data as evidence, electronic delivery, and the clause quoted above)
### Rules & Codes — ADR Institute of Canada
<https://adric.ca/rules-codes/> — retrieved 2026-08-29
> Rules & Codes — ADR Institute of Canada
> ADRIC By-laws / Federation MoU / ADRIC Arbitration Rules / National Mediation Rules / ADRIC Med-Arb Rules
> Ethics & Professional Practice — Code of Ethics / Code of Conduct / Conflict of Interest / Complaints & Discipline Policy / Privacy Policy / Online Dispute Resolution (ODR) Vision
### Artificial Intelligence and Arbitration: A Perfect Fit? — ADR Institute of Canada
<https://adric.ca/artificial-intelligence-and-arbitration-a-perfect-fit/> — retrieved 2026-08-29
> Artificial Intelligence and Arbitration: A Perfect Fit?
> March 2, 2023
> By Robin Dodokin, Sarah McEachern, Les Honywill
> Machine learning and AI have progressed so far that their integration into the arbitral process seems inevitable, with the only question being a matter of time and degree.
### Who We Are — Canadian International Internet Dispute Resolution Centre (CIIDRC)
<https://ciidrc.org/about-ciidrc/> — retrieved 2026-08-29
> The Canadian International Internet Dispute Resolution Centre ("CIIDRC", "the Centre") serves global Internet users by providing trusted and efficient resolution of domain name disputes under the Uniform Domain Name Dispute Resolution Policy (the UDRP) and the CIRA Domain Name Dispute Resolution Policy (the CDRP).
> CIIDRC is a division of the Vancouver International Arbitration Centre, formerly known as the British Columbia International Commercial Arbitration Centre ("the Centre").
> CIIDRC's parent organization, VanIAC (formerly BCICAC), has been a service provider for the Canadian Internet Registration Authority (CIRA) since 2002, successfully managing .ca (dot ca) domain name disputes.
### CIIDRC Supplemental Rules — Canadian International Internet Dispute Resolution Centre
<https://ciidrc.org/domain-name-disputes/ciidrc-supplemental-rules/> — retrieved 2026-08-29
> CIIDRC Supplemental Rules OF THE CANADIAN INTERNATIONAL INTERNET DISPUTE RESOLUTION CENTRE (the "Centre" or the "CIIDRC" or the "Provider") FOR THE UNIFORM DOMAIN NAME DISPUTE RESOLUTION POLICY (the "Policy") AND THE RULES FOR THE UNIFORM DOMAIN NAME DISPUTE RESOLUTION POLICY (the "UDRP Rules")
> The Supplemental Rules (In effect as of May 9, 2018)
### CIRA Domain Name Dispute Resolution Policy (reproduced by CIIDRC, a CIRA-approved provider)
<https://ciidrc.org/domain-name-disputes/cdrp-policy/> — retrieved 2026-08-29
> CIRA Domain Name Dispute Resolution Policy — Version 1.3 (August 22, 2011)
> 1.1 Purpose. The purpose of this CIRA Domain Name Dispute Resolution Policy (the "Policy") is to provide a forum in which cases of bad faith registration of domain names registered in the dot-ca country code top level domain name registry operated by CIRA (the "Registry") can be dealt with relatively inexpensively and quickly.
> 1.2 Scope. The Policy sets forth the terms and conditions for resolution by arbitration of a dispute between a person (the "Registrant") who has obtained the registration of a domain name in the Registry (the "Registration") and any other person …
> 1.5 Dispute Resolution Service Provider. All Proceedings will be administered by a dispute resolution service provider approved by CIRA (the "Provider").
### Rules of Procedure — VanIAC (Vancouver International Arbitration Centre)
<https://vaniac.org/arbitration/rules-of-procedure/> — retrieved 2026-08-29
> Rules of Procedure — Domestic Arbitration Rules (as amended Sept. 1, 2020)
> International Commercial Arbitration Rules of Procedure (as amended July 1, 2022)
> International Commercial Arbitration Rules of Procedure (as amended Jan. 1, 2000)
> (the page's full navigation lists arbitration, mediation and motor-vehicle rules, forms, fee schedules and an Arbitrator Code of Conduct; no rule set, guideline or note on artificial intelligence or technology disputes appears)
---
## What this establishes
- PIPEDA — the Personal Information Protection and Electronic Documents Act, S.C. 2000, c. 5 — is the federal private-sector privacy statute in force. The Justice Laws consolidation states "Act current to 2026-06-21 and last amended on 2025-03-04."
*Source:* <https://laws-lois.justice.gc.ca/eng/acts/P-8.6/FullText.html>
- PIPEDA Part 1 applies to every organization in respect of personal information it "collects, uses or discloses in the course of commercial activities" (s. 4(1)(a)), and to employee information in connection with a federal work, undertaking or business (s. 4(1)(b)).
*Source:* <https://laws-lois.justice.gc.ca/eng/acts/P-8.6/FullText.html>
- The Office of the Privacy Commissioner of Canada states that Canada has two federal privacy laws it enforces — the Privacy Act (federal government) and PIPEDA, which "sets the ground rules for how private-sector organizations collect, use, and disclose personal information in the course of for-profit, commercial activities across Canada." PIPEDA generally applies to non-federally-regulated private-sector organizations doing business in Ontario (among other provinces and territories).
*Source:* <https://www.priv.gc.ca/en/privacy-topics/privacy-laws-in-canada/02_05_d_15/>
- Bill C-27 (44th Parliament, 1st Session) was the bill that would have enacted the Consumer Privacy Protection Act, the Personal Information and Data Protection Tribunal Act and the Artificial Intelligence and Data Act. Its short title was the Digital Charter Implementation Act, 2022.
*Source:* <https://www.parl.ca/legisinfo/en/bill/44-1/c-27>
- Bill C-27 never received royal assent. LEGISinfo records its last completed major stage as "Second reading", its status as "At consideration in committee in the House of Commons", ReceivedRoyalAssent = false, ReceivedRoyalAssentDateTime = null, IsSessionOngoing = false, and DidReinstateInNextSession = false.
*Source:* <https://www.parl.ca/legisinfo/en/bills/json?parlsession=44-1>
- The 44th Parliament's 1st session ran to January 6, 2025, and Bill C-27 had not advanced past committee when it ended.
*Source:* <https://www.parl.ca/legisinfo/en/bill/44-1/c-27>
- Under House of Commons Procedure and Practice (4th ed., 2025), "Government bills which have not received royal assent before prorogation die and, in order to be proceeded with in the new session, must be reintroduced as if they had never existed," and on dissolution "All items on the Order Paper including government and private members' bills die." Combined with the LEGISinfo record, this means the Consumer Privacy Protection Act and the Artificial Intelligence and Data Act were never enacted and do not exist as Canadian law.
*Source:* <https://www.ourcommons.ca/procedure/procedure-and-practice-4/ch08-7-e.html>
- In the 45th Parliament, 1st Session, a scan of all 185 bills found only two whose titles touch privacy, AI, cyber or data protection: C-8 and C-36. No bill in the session has "intellig" (i.e. "intelligence") anywhere in its title — there is no successor AI bill to AIDA before Parliament.
*Source:* <https://www.parl.ca/legisinfo/en/bills/json?parlsession=45-1>
- Bill C-36 (45-1), "An Act to enact the Protecting Privacy and Consumer Data Act, to amend the Personal Information Protection and Electronic Documents Act and to make amendments to other Acts", received first reading on June 15, 2026, is sponsored by the Minister of Artificial Intelligence and Digital Innovation, and its status is "At second reading in the House of Commons". Royal assent has NOT been received.
*Source:* <https://www.parl.ca/legisinfo/en/bill/45-1/c-36>
- Bill C-36 would enact the "Protecting Privacy and Consumer Data Act" to govern protection of personal information collected, used or disclosed in the course of commercial activities. It is a bill, not a statute — nothing in it is in force.
*Source:* <https://www.parl.ca/DocumentViewer/en/45-1/bill/C-36/first-reading>
- There is no "2026 privacy statute" in Canadian federal law. The only 2026 federal privacy instrument is Bill C-36, introduced 15 June 2026 and still at second reading with no royal assent, so PIPEDA remains the operative federal private-sector privacy statute as at 2026-08-29.
*Source:* <https://www.parl.ca/legisinfo/en/bills/json?parlsession=45-1>
- The one cyber/data-adjacent federal statute enacted in 20252026 is Bill C-8, "An Act respecting cyber security, amending the Telecommunications Act and making consequential amendments to other Acts", which received royal assent on June 15, 2026 and is S.C. 2026, c. 9. It enacts the Critical Cyber Systems Protection Act. It is a critical-infrastructure cyber security statute, not a privacy or AI statute.
*Source:* <https://laws-lois.justice.gc.ca/eng/AnnualStatutes/2026_9/>
- Ontario public-sector access/privacy statute: Freedom of Information and Protection of Privacy Act, R.S.O. 1990, c. F.31 (e-Laws consolidation period from July 1, 2026; last amendment 2026, c. 2, Sched. 7).
*Source:* <https://www.ontario.ca/laws/api/v2/legislation/en/act-content/statute/90f31>
- Ontario municipal-sector equivalent: Municipal Freedom of Information and Protection of Privacy Act, R.S.O. 1990, c. M.56 (e-Laws consolidation period from July 1, 2026).
*Source:* <https://www.ontario.ca/laws/api/v2/legislation/en/act-content/statute/90m56>
- Ontario health privacy statute: Personal Health Information Protection Act, 2004, S.O. 2004, c. 3, Sched. A (e-Laws consolidation period from January 1, 2026; last amendment 2025, c. 7, Sched. 6, ss. 113).
*Source:* <https://www.ontario.ca/laws/api/v2/legislation/en/act-content/statute/04p03>
- FIPPA's privacy-safeguard duty (s. 40(5)) and mandatory breach reporting to the Commissioner and notification to affected individuals (s. 40.1) were enacted by S.O. 2024, c. 24, Sched. 2, ss. 56, and the e-Laws in-force note records both as in force 01/07/2025.
*Source:* <https://www.ontario.ca/laws/api/v2/legislation/en/act-content/statute/90f31>
- Ontario's AI-relevant statute is the Enhancing Digital Security and Trust Act, 2024, S.O. 2024, c. 24, Sched. 1 (enacted by Bill 194, royal assent giving Statutes of Ontario 2024, chapter 24), consolidated from January 29, 2025 with no amendments. It defines "artificial intelligence system" as "a machine-based system that, for explicit or implicit objectives, infers from the input it receives in order to generate outputs such as predictions, content, recommendations or decisions that can influence physical or virtual environments".
*Source:* <https://www.ontario.ca/laws/api/v2/legislation/en/act-content/statute/24e24>
- Every EDSTA AI obligation is conditional on regulations: s. 5(1) applies only "to such public sector entities as may be prescribed … if they use or intend to use an artificial intelligence system in prescribed circumstances." The Act also states at s. 12 that nothing in it "establishes a private law duty of care owing to any person", and at s. 13 that failure to comply "does not affect the validity of any policy, Act, regulation, directive, instrument or decision."
*Source:* <https://www.ontario.ca/laws/api/v2/legislation/en/act-content/statute/24e24>
- Only two regulations have been made under EDSTA — O. Reg. 51/26 (Cyber Security) and O. Reg. 52/26 (Digital Technology Affecting Individuals Under Age 18); the e-Laws listing shows 2 current and 0 revoked. No AI regulation has been made, so EDSTA's artificial-intelligence sections have no prescribed entities or circumstances and impose no operative obligation as at 2026-08-29.
*Source:* <https://www.ontario.ca/laws/api/v2/legislation/en/act-reg/regulation?title=enhancing%20digital%20security%20and%20trust%20act%2C%202024&sort=citation>
- O. Reg. 51/26 (Cyber Security) under EDSTA has a consolidation period from July 1, 2026 and covers prescribed public sector entities, cyber security programs, a primary point of contact, cyber security maturity assessments and critical incident reporting. The phrase "artificial intelligence" does not appear in it.
*Source:* <https://www.ontario.ca/laws/api/v2/legislation/en/act-content/regulation/260051>
- O. Reg. 52/26 (Digital Technology Affecting Individuals Under Age 18) under EDSTA has a consolidation period from July 1, 2026 and deals with prescribed school boards and notice of disclosure of students' personal digital information. The phrase "artificial intelligence" does not appear in it.
*Source:* <https://www.ontario.ca/laws/api/v2/legislation/en/act-content/regulation/260052>
- No Ontario privacy or AI regulatory statute was enacted in 2025 or 2026. Of the 139 bills in the Ontario 44th Parliament 1st Session, only four have privacy/AI/online titles: Bill 61, the Ontario Artificial Intelligence, Talent and Innovation Strategy Act, 2025 (a private member's bill) was lost on division at second reading on November 24, 2025; Bill 137 is still at first reading; and Bills 15/66 are commemorative-month bills.
*Source:* <https://www.ola.org/en/legislative-business/bills/parliament-44/session-1>
- Bill 61, the Ontario Artificial Intelligence, Talent and Innovation Strategy Act, 2025, was a private member's bill and was lost on division at second reading on November 24, 2025 — Ontario has no AI strategy statute.
*Source:* <https://www.ola.org/en/legislative-business/bills/parliament-44/session-1/bill-61>
- The only Ontario statute with "Privacy" in its title enacted in this period is the Kids' Online Safety and Privacy Month Act, 2025, S.O. 2025, c. 25 (in force December 11, 2025). Its entire operative content is s. 1: "The month of October in each year is proclaimed as Kids' Online Safety and Privacy Month." It creates no privacy obligations.
*Source:* <https://www.ontario.ca/laws/api/v2/legislation/en/act-content/statute/25k25>
- DATA RESIDENCY — PIPEDA contains no data-localization requirement. A grep of the full Justice Laws consolidation for "outside Canada", "stored in Canada", "within Canada" and "localiz" returned zero matches (grep exit status 1), against 113 occurrences of "personal information" in the same file as an instrument check.
*Source:* <https://laws-lois.justice.gc.ca/eng/acts/P-8.6/FullText.html>
- The OPC states directly: "PIPEDA does not prohibit organizations in Canada from transferring personal information to an organization in another jurisdiction for processing. However, under PIPEDA, organizations are held accountable for the protection of personal information transfers under each individual outsourcing arrangement." Canada's approach is organization-to-organization accountability, not EU-style adequacy.
*Source:* <https://www.priv.gc.ca/en/privacy-topics/airports-and-borders/gl_dab_090127/>
- What PIPEDA requires instead of residency is accountability: Schedule 1, clause 4.1.3 — "An organization is responsible for personal information in its possession or custody, including information that has been transferred to a third party for processing. The organization shall use contractual or other means to provide a comparable level of protection while the information is being processed by a third party."
*Source:* <https://laws-lois.justice.gc.ca/eng/acts/P-8.6/FullText.html>
- The OPC reopened and then closed this question: on September 23, 2019 the Commissioner concluded the consultation on transfers for processing, confirming that the guidelines for processing personal data across borders "remain unchanged under the current law."
*Source:* <https://www.priv.gc.ca/en/opc-news/news-and-announcements/2019/an_190923/>
- DATA RESIDENCY — Ontario PHIPA imposes no requirement that personal health information be stored in Ontario or in Canada. The section headed "Place where records kept" (s. 14) is about keeping records in the individual's home or a place other than the practitioner's control, not about jurisdiction. The phrase "outside Canada" does not appear anywhere in the Act.
*Source:* <https://www.ontario.ca/laws/api/v2/legislation/en/act-content/statute/04p03>
- PHIPA s. 50 ("Disclosure outside Ontario") is a disclosure-permission rule, not a storage rule: it permits a custodian to disclose personal health information collected in Ontario to a person outside Ontario where, among other gateways, the individual consents, the Act permits the disclosure, or the disclosure is reasonably necessary for the provision of health care to the individual.
*Source:* <https://www.ontario.ca/laws/api/v2/legislation/en/act-content/statute/04p03>
- PHIPA's security duty (s. 12(1)) is a reasonableness standard — "steps that are reasonable in the circumstances" to protect against theft, loss and unauthorized use or disclosure — with no location component.
*Source:* <https://www.ontario.ca/laws/api/v2/legislation/en/act-content/statute/04p03>
- O. Reg. 329/04 (General) under PHIPA likewise imposes no storage-location requirement. Its only "outside Ontario" provisions permit the Canadian Institute for Health Information and Ontario Health to disclose to persons outside Ontario in defined circumstances.
*Source:* <https://www.ontario.ca/laws/api/v2/legislation/en/act-content/regulation/040329>
- DATA RESIDENCY — Ontario FIPPA contains no data-localization requirement either. A grep of the full consolidated text for "outside Canada" returned zero matches (grep exit status 1) against 248 occurrences of "personal information" as an instrument check; the only "in Canada" occurrences are law-enforcement disclosure clauses.
*Source:* <https://www.ontario.ca/laws/api/v2/legislation/en/act-content/statute/90f31>
- The closest thing to a Canadian residency rule is a federal internal-administration policy, not a law of general application, and it is not absolute. Treasury Board's Directive on Service and Digital, s. 4.3.24, requires only that Canadian computing facilities "be identified and evaluated as a principal delivery option" for Government of Canada data categorized Protected B, Protected C or classified. It binds federal departments, not private organizations.
*Source:* <https://www.tbs-sct.canada.ca/pol/doc-eng.aspx?id=32601>
- The cloud direction commonly cited for "data must stay in Canada" (SPIN 2017-01) does not itself set a residency rule: its s. 6.2.2 says only that "Departments are expected to apply the Directive on Service and Digital when implementing safeguards for GC electronic data residency."
*Source:* <https://www.canada.ca/en/government/system/digital-government/digital-government-innovations/cloud-services/direction-secure-use-commercial-cloud-services-spin.html>
- ARBITRAL INSTITUTIONS — The ADR Institute of Canada's current ADRIC Arbitration Rules (effective 01 March 2025) contain no provision on artificial intelligence, machine learning, or technology disputes. A case-insensitive grep of the full 103,811-character extracted text for "artificial intelligence", "machine learning" and the token "AI" returned no matches. The only data-related clause is a party-responsibility rule for privacy and data security of evidence.
*Source:* <https://adric.ca/rules/ADRIC-Arbitration-Rules-2025.pdf>
- ADRIC's published Rules & Codes are: ADRIC By-laws, Federation MoU, ADRIC Arbitration Rules, National Mediation Rules, ADRIC Med-Arb Rules, Code of Ethics, Code of Conduct, Conflict of Interest, Complaints & Discipline Policy, Privacy Policy, and an Online Dispute Resolution (ODR) Vision. None is specific to technology, data or AI disputes.
*Source:* <https://adric.ca/rules-codes/>
- ADRIC's only AI-related publication located is an article, not a rule or guideline: "Artificial Intelligence and Arbitration: A Perfect Fit?", dated March 2, 2023, by Robin Dodokin, Sarah McEachern and Les Honywill. It is commentary about AI's likely role in arbitration, not institutional guidance to arbitrators or parties.
*Source:* <https://adric.ca/artificial-intelligence-and-arbitration-a-perfect-fit/>
- There IS a Canadian arbitral institution with rules specific to one class of technology dispute: the Canadian International Internet Dispute Resolution Centre (CIIDRC), a division of the Vancouver International Arbitration Centre (VanIAC, formerly BCICAC), which resolves domain-name disputes under the UDRP and CIRA's CDRP and has been a CIRA service provider since 2002.
*Source:* <https://ciidrc.org/about-ciidrc/>
- CIIDRC publishes its own Supplemental Rules for the UDRP, in effect as of May 9, 2018, which govern communications, complaints and annexes, panelist appointment, fees, word limits and file format for domain-name proceedings.
*Source:* <https://ciidrc.org/domain-name-disputes/ciidrc-supplemental-rules/>
- The CIRA Domain Name Dispute Resolution Policy, Version 1.3 (August 22, 2011), provides for "resolution by arbitration" of disputes over bad-faith registration of .ca domain names, administered by a dispute resolution service provider approved by CIRA.
*Source:* <https://ciidrc.org/domain-name-disputes/cdrp-policy/>
- VanIAC's own Rules of Procedure page lists only its Domestic Arbitration Rules (as amended Sept. 1, 2020) and International Commercial Arbitration Rules of Procedure (as amended July 1, 2022 and Jan. 1, 2000), plus mediation and motor-vehicle rules. No AI or technology-dispute rule set or guidance note appears.
*Source:* <https://vaniac.org/arbitration/rules-of-procedure/>
---
## What this does NOT establish
**Read this section before writing copy.**
- **Does "the 2026 privacy statute" referred to in docs/03-content-spec.md line 299 exist?**
- *Searched:* LEGISinfo bill records for the 44th Parliament 1st Session (all 412 bills) and 45th Parliament 1st Session (all 185 bills), fetched as JSON from parl.ca; the LEGISinfo bill pages for C-27, C-36 and C-8; the Justice Laws consolidation of PIPEDA and the 2026 annual statutes index; the Ontario e-Laws consolidated statute database; and the Legislative Assembly of Ontario's complete bill list for the 44th Parliament 1st Session (139 bills).
- *Outcome:* NO SUCH STATUTE EXISTS. Nothing enacted federally or in Ontario in 2025 or 2026 is a privacy statute. The nearest real things are (a) federal Bill C-36, introduced 15 June 2026, which WOULD enact the Protecting Privacy and Consumer Data Act — but it is at second reading with no royal assent; (b) federal Bill C-8 / S.C. 2026, c. 9, a cyber security statute, not privacy; and (c) Ontario O. Regs. 51/26 and 52/26 in force 1 July 2026, which are regulations under a 2024 Act, not a statute. Any public-page copy relying on "the 2026 privacy statute" as market context is asserting something that is not law. If the intent was "pending federal privacy reform", the accurate framing is Bill C-36 (45-1), first reading 15 June 2026, still before the House.
- **Did the Consumer Privacy Protection Act or the Artificial Intelligence and Data Act ever come into force in any form?**
- *Searched:* LEGISinfo C-27 page and JSON record (royal assent flags, reinstatement flags, session-ongoing flag); a scan of all 185 bills in the 45th Parliament 1st Session for any bill title containing "intellig", "artificial intelligence", "consumer privacy" or "data protection"; House of Commons Procedure and Practice 4th ed. on prorogation and dissolution.
- *Outcome:* No. C-27 died without royal assent and was not reinstated; no successor AI or CPPA bill has been introduced in the 45th Parliament. Canada has no federal AI statute as at 2026-08-29.
- **Is there any Canadian federal or Ontario legal requirement that personal data be stored in Canada?**
- *Searched:* Full-text greps of PIPEDA, Ontario FIPPA, PHIPA and O. Reg. 329/04 for "outside Canada", "within Canada", "stored in Canada" and "localiz"; the OPC's Guidelines for processing personal data across borders and its 2019 consultation conclusion; Treasury Board's SPIN 2017-01 and the Directive on Service and Digital.
- *Outcome:* No such requirement was found in any of them, and the OPC states the opposite for PIPEDA. NOT CHECKED, and outside the scope asked: the public-sector residency provisions in British Columbia's FIPPA and Nova Scotia's PIIDPA, which are the usual real source of the belief that "Canadian data must stay in Canada". Do not assert anything about those provinces from this artefact.
- **Does any Canadian arbitral institution publish formal guidance (as distinct from rules) on the use of AI in arbitration or mediation?**
- *Searched:* ADRIC's page sitemap (175 pages) grepped for ai/artificial/tech/rule/code/guideline/protocol; the ADRIC Rules & Codes index; the full text of the ADRIC Arbitration Rules effective 01 March 2025; VanIAC's Rules of Procedure page and site navigation.
- *Outcome:* None found. ADRIC's only AI material located is a 2023 commentary article and a 2026 conference session page ("The AI-Ready Neutral: Practical Essentials for Arbitrators and Mediators"), neither of which is institutional guidance. The conference page itself was NOT fetched — only its URL appeared in the sitemap — so nothing should be claimed about its content.
- **Do ICDR Canada or the Canadian Arbitration Association publish technology- or AI-specific rules?**
- *Searched:* Keyword web search naming ADRIC, VanIAC, CCAC and ICDR Canada together with AI guidance; their own sites were not individually fetched.
- *Outcome:* Not established either way. Neither icdr.org nor the Canadian Arbitration Association's site was retrieved, so no claim can be made about what they do or do not publish.
- **Coming-into-force status of the Critical Cyber Systems Protection Act (S.C. 2026, c. 9) — which of its provisions are actually operative.**
- *Searched:* The LEGISinfo C-8 page, the royal assent text summary, and the Justice Laws Annual Statutes 2026 c. 9 landing page.
- *Outcome:* Royal assent (15 June 2026) is confirmed, but the coming-into-force provisions were not read in full. Do not assert that the Critical Cyber Systems Protection Act is in force; assert only that it was enacted.
- **What S.O. 2026, c. 2, Sched. 7 (the most recent FIPPA amendment) actually changes.**
- *Searched:* Ontario e-Laws statute record for S.O. 2026, c. 2, identified as the Plan to Protect Ontario Act (Budget Measures), 2026 (Bill 97), assented to April 24, 2026; the schedule's text was not extracted.
- *Outcome:* Identified as a budget-measures omnibus amendment to FIPPA; its substance was not read and must not be characterised.
---
## Searches run
- `WebSearch: Bill C-27 Digital Charter Implementation Act status LEGISinfo died on Order Paper prorogation`
- `WebSearch: PIPEDA Personal Information Protection and Electronic Documents Act S.C. 2000 c. 5 justice laws`
- `WebFetch: https://www.parl.ca/legisinfo/en/bill/44-1/c-27`
- `WebFetch: https://www.parl.ca/legisinfo/en/bill/44-1/c-27/json`
- `WebFetch: https://laws-lois.justice.gc.ca/eng/acts/P-8.6/`
- `curl: https://laws-lois.justice.gc.ca/eng/acts/P-8.6/FullText.html (then grep for residency terms; grep exit status read directly rather than through a pipe, after an initial `grep ... | head` gave a misleading exit code)`
- `curl: https://www.parl.ca/legisinfo/en/bills/json?parlsession=44-1 (412 bill records, keyword scan)`
- `curl: https://www.parl.ca/legisinfo/en/bills/json?parlsession=45-1 (185 bill records, keyword scan + 'intellig' scan + full royal-assent list)`
- `WebFetch: https://www.parl.ca/legisinfo/en/bill/45-1/c-36`
- `WebFetch: https://www.parl.ca/DocumentViewer/en/45-1/bill/C-36/first-reading`
- `WebFetch: https://www.parl.ca/legisinfo/en/bill/45-1/c-8`
- `WebFetch: https://www.parl.ca/DocumentViewer/en/45-1/bill/C-8/royal-assent`
- `WebFetch: https://laws-lois.justice.gc.ca/eng/AnnualStatutes/2026_9/`
- `WebSearch + WebFetch: https://www.ourcommons.ca/procedure/procedure-and-practice-4/ch08-7-e.html (prorogation and dissolution)`
- `Ontario e-Laws: discovered the JSON API behind the ontario.ca/laws SPA (the HTML pages return only a JS shell to any fetcher, and WebFetch got nothing) by reading /laws/static/js/main.dbd400db.js; base https://www.ontario.ca/laws/api/v2/legislation`
- `e-Laws API: /en/currency-date -> "August 26, 2026"`
- `e-Laws API: /en/act-content/statute/04p03 (PHIPA) + extraction of ss. 12, 13, 14, 50 and residency grep`
- `e-Laws API: /en/act-content/regulation/040329 (O. Reg. 329/04 under PHIPA) + residency grep`
- `e-Laws API: /en/act-content/statute/90f31 (FIPPA) + ss. 40, 40.1 + residency grep with exit status read`
- `e-Laws API: /en/act-content/statute/90m56 (MFIPPA)`
- `e-Laws API: /en/act-content/statute/24e24 (Enhancing Digital Security and Trust Act, 2024) + full text extraction`
- `e-Laws API: /en/act-reg/regulation?title=enhancing+digital+security+and+trust+act,+2024 (complete list of regulations made under EDSTA: 2 current, 0 revoked)`
- `e-Laws API: /en/act-content/regulation/260051 and /260052 (O. Reg. 51/26 and 52/26) + 'artificial intelligence' count`
- `e-Laws API: /en/act-content/statute/s26002 (S.O. 2026, c. 2 = Plan to Protect Ontario Act (Budget Measures), 2026, assented April 24, 2026)`
- `e-Laws API: /en/act-content/statute/25k25 and /s25025 (Kids' Online Safety and Privacy Month Act, 2025)`
- `WebSearch: Ontario Enhancing Digital Security and Trust Act 2024 in force FIPPA amendments Bill 194`
- `WebSearch: 'Enhancing Digital Security and Trust Act' Ontario regulation O. Reg. cyber security 2026 July 1 2026`
- `WebFetch: https://www.ola.org/en/legislative-business/bills/parliament-43/session-1/bill-194`
- `curl + scrape: https://www.ola.org/en/legislative-business/bills/parliament-44/session-1 (all 139 bills, unpaginated, keyword scan)`
- `WebFetch: ola.org bills 61, 66 and 137 (44-1)`
- `WebFetch: https://www.priv.gc.ca/en/privacy-topics/airports-and-borders/gl_dab_090127/ + curl to verify the page title and Date modified`
- `curl: https://www.priv.gc.ca/en/privacy-topics/privacy-laws-in-canada/02_05_d_15/ (Summary of privacy laws in Canada)`
- `WebSearch (priv.gc.ca only) + WebFetch: https://www.priv.gc.ca/en/opc-news/news-and-announcements/2019/an_190923/`
- `WebSearch (canada.ca only) + curl: SPIN 2017-01 and https://www.tbs-sct.canada.ca/pol/doc-eng.aspx?id=32601 (Directive on Service and Digital, s. 4.3.24)`
- `WebSearch: ADRIC artificial intelligence arbitration guideline rules technology disputes`
- `curl + pdftotext: https://adric.ca/rules/ADRIC-Arbitration-Rules-2025.pdf (103,811 chars extracted) + AI/technology grep`
- `curl: https://adric.ca/sitemap_index.xml and /page-sitemap.xml (175 pages) + ai/artificial/tech/rule/guideline grep`
- `curl: https://adric.ca/rules-codes/ and https://adric.ca/artificial-intelligence-and-arbitration-a-perfect-fit/`
- `WebSearch: VanIAC Vancouver International Arbitration Centre artificial intelligence guidelines rules 2025 2026`
- `curl: https://vaniac.org/arbitration/rules-of-procedure/ and https://vaniac.org/`
- `curl: https://ciidrc.org/ , /about-ciidrc/ , /domain-name-disputes/cdrp-policy/ , /domain-name-disputes/ciidrc-supplemental-rules/`
- `BLOCKED, recorded so a later reader does not mistake silence for absence: canlii.org returned HTTP 403 to WebFetch; cira.ca returned a Cloudflare HTTP 403 to both WebFetch and curl (the CDRP policy was therefore sourced from CIIDRC, a CIRA-approved provider, not from CIRA itself); adric.ca/rules/ returned HTTP 403 to curl although the rules PDF on the same host returned 200; canada.ca returned 403 to WebFetch but 200 to curl with a browser user-agent.`