Step 5 ships /practice/ and the six practice-area pages (construction,
technology, energy, insurance, shareholder, cross-border) from one route, and
adds the mechanical §4 gate Pouya ruled for.
check:claims — §4 Forbidden becomes a build error
scripts/check-claims.mjs greps dist/**/*.html for 10 patterns, each carrying
the incident that put it there. It strips <style> and non-JSON-LD <script>
first (a bare sweep for "leading" returned 26 hits, 25 of them
var(--leading-body)), self-tests every pattern against fixtures before
sweeping, and refuses a missing, empty or stale dist/. Wired into /build
Phase 5 and both deploy paths.
Q54 — six conduct undertakings publish, and §4 gains a third class
Conduct undertakings sit apart from credentials and offerings: the gate is
that Pouya said it in terms. The strings live in CONDUCT_UNDERTAKINGS so a
softening is one visible diff. (e) and (f) replace the third-person sentences
already on /arbitration/ rather than joining them.
Q49, Q50 recorded as rulings. §7 records the SES us-east-1 stray identity's
deletion. R11 holds typescript at its current major, with the peer-range
reason recorded.
Three facts corrected, two of them already shipped
- The LAT gloss said mediation "before filing and continuing after filing";
the Tribunal names mediation for "Before you apply" only and its second
sentence is about negotiation. An ellipsis in docs/01 had deleted it.
- "Connection allocation" is not an Ontario term.
- "The 2026 privacy statute" does not exist — Bill C-27 died without royal
assent. Struck from docs/03 rather than corrected in place.
ADR Chambers struck from /arbitration/ and from docs/01 item 3 (Pouya,
2026-08-30): the source establishes what the firm publishes, not that an
outside neutral can be appointed under its rules.
claims-auditor gains a second lens — for every quoted source, whether the
sentence beneath stays inside what the quotation establishes. Four shipped
defects had that shape and none of them is greppable.
CLAUDE.md gains a convention: never truncate the output of a check you intend
to believe. `npm run check | tail -3` returns warnings, hints and a blank line
and drops the errors line; it was reported as passing four times while
astro check was exiting 1 with 10 type errors.
Gates, exit status read directly, not through a pipe:
npm run check exit=0
npm run lint exit=0
npm run build exit=0
npm run check:claims exit=0
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Md3GndFqWPzK78xAoebsg5
59 KiB
Canadian privacy and AI legislation status, and technology-dispute context
Committed under AGENTS.md R14 and the CLAUDE.md rule it encodes: anything a
spec makes a claim about must be reachable from the repository. Every fact
the six /practice/* pages state about the world is checkable here or it is
not published.
Retrieved 2026-08-29.
⚠️ THIS FILE EXISTS BECAUSE A SPEC NAMED A STATUTE THAT DOES NOT EXIST.
docs/03-content-spec.md§Practice areas listed "the 2026 privacy statute" among the market context for/practice/technology/. There is no 2026 Canadian privacy statute, federal or Ontario. Bill C-27 — which would have enacted the Consumer Privacy Protection Act and the Artificial Intelligence and Data Act — died without royal assent when the 44th Parliament's first session ended, and was never reinstated. PIPEDA remains the operative federal private-sector statute. Caught before a word of it reached a page, and only because the check was run rather than the phrase trusted.
⚠️ A statute, a bill and a regulation all move. Bill C-36 in particular was at second reading on the retrieval date and could be law, or dead, by the time anyone reads this. Re-check before cutover.
Topic as researched: Canadian technology / data / AI dispute context — privacy legislation status as at 2026-08-29, Ontario public-sector and health privacy statutes, data residency law, and Canadian arbitral-institution rules for technology/AI disputes
Sources
| Kind | Source | URL |
|---|---|---|
| statute | LEGISinfo — Bill C-27 (44-1), Digital Charter Implementation Act, 2022 — Parliament of Canada | https://www.parl.ca/legisinfo/en/bill/44-1/c-27 |
| statute | LEGISinfo bills data (JSON), 44th Parliament 1st Session — Parliament of Canada | https://www.parl.ca/legisinfo/en/bills/json?parlsession=44-1 |
| institution | House of Commons Procedure and Practice, Fourth Edition (2025), Ch. 8 — Prorogation and Dissolution | https://www.ourcommons.ca/procedure/procedure-and-practice-4/ch08-7-e.html |
| statute | Personal Information Protection and Electronic Documents Act (S.C. 2000, c. 5) — Justice Laws Website | https://laws-lois.justice.gc.ca/eng/acts/P-8.6/FullText.html |
| statute | LEGISinfo bills data (JSON), 45th Parliament 1st Session — Parliament of Canada | https://www.parl.ca/legisinfo/en/bills/json?parlsession=45-1 |
| statute | LEGISinfo — Bill C-36 (45-1), An Act to enact the Protecting Privacy and Consumer Data Act — Parliament of Canada | https://www.parl.ca/legisinfo/en/bill/45-1/c-36 |
| statute | Bill C-36 (45-1), first reading text — Parliament of Canada | https://www.parl.ca/DocumentViewer/en/45-1/bill/C-36/first-reading |
| statute | Statutes of Canada 2026, c. 9 — An Act respecting cyber security … — Justice Laws Website | https://laws-lois.justice.gc.ca/eng/AnnualStatutes/2026_9/ |
| statute | Bill C-8 (45-1), royal assent text — Parliament of Canada | https://www.parl.ca/DocumentViewer/en/45-1/bill/C-8/royal-assent |
| regulator | Summary of privacy laws in Canada — Office of the Privacy Commissioner of Canada | https://www.priv.gc.ca/en/privacy-topics/privacy-laws-in-canada/02_05_d_15/ |
| regulator | Guidelines for processing personal data across borders — Office of the Privacy Commissioner of Canada | https://www.priv.gc.ca/en/privacy-topics/airports-and-borders/gl_dab_090127/ |
| regulator | Announcement: Commissioner concludes consultation on transfers for processing — Office of the Privacy Commissioner of Canada | https://www.priv.gc.ca/en/opc-news/news-and-announcements/2019/an_190923/ |
| statute | Personal Health Information Protection Act, 2004 — Ontario e-Laws consolidated text (JSON endpoint behind https://www.ontario.ca/laws/statute/04p03) | https://www.ontario.ca/laws/api/v2/legislation/en/act-content/statute/04p03 |
| regulation | O. Reg. 329/04 (GENERAL) under PHIPA — Ontario e-Laws consolidated text (JSON endpoint) | https://www.ontario.ca/laws/api/v2/legislation/en/act-content/regulation/040329 |
| statute | Freedom of Information and Protection of Privacy Act — Ontario e-Laws consolidated text (JSON endpoint behind https://www.ontario.ca/laws/statute/90f31) | https://www.ontario.ca/laws/api/v2/legislation/en/act-content/statute/90f31 |
| statute | Municipal Freedom of Information and Protection of Privacy Act — Ontario e-Laws (JSON endpoint) | https://www.ontario.ca/laws/api/v2/legislation/en/act-content/statute/90m56 |
| statute | Enhancing Digital Security and Trust Act, 2024 — Ontario e-Laws consolidated text (JSON endpoint behind https://www.ontario.ca/laws/statute/24e24) | https://www.ontario.ca/laws/api/v2/legislation/en/act-content/statute/24e24 |
| regulation | Ontario e-Laws — regulations made under the Enhancing Digital Security and Trust Act, 2024 (JSON endpoint) | https://www.ontario.ca/laws/api/v2/legislation/en/act-reg/regulation?title=enhancing%20digital%20security%20and%20trust%20act%2C%202024&sort=citation |
| regulation | O. Reg. 51/26 (CYBER SECURITY) under the Enhancing Digital Security and Trust Act, 2024 — Ontario e-Laws (JSON endpoint) | https://www.ontario.ca/laws/api/v2/legislation/en/act-content/regulation/260051 |
| regulation | O. Reg. 52/26 (DIGITAL TECHNOLOGY AFFECTING INDIVIDUALS UNDER AGE 18) under the Enhancing Digital Security and Trust Act, 2024 — Ontario e-Laws (JSON endpoint) | https://www.ontario.ca/laws/api/v2/legislation/en/act-content/regulation/260052 |
| institution | Bill 194, Strengthening Cyber Security and Building Trust in the Public Sector Act, 2024 — Legislative Assembly of Ontario | https://www.ola.org/en/legislative-business/bills/parliament-43/session-1/bill-194 |
| institution | Bills — 44th Parliament, 1st Session — Legislative Assembly of Ontario | https://www.ola.org/en/legislative-business/bills/parliament-44/session-1 |
| institution | Bill 61, Ontario Artificial Intelligence, Talent and Innovation Strategy Act, 2025 — Legislative Assembly of Ontario | https://www.ola.org/en/legislative-business/bills/parliament-44/session-1/bill-61 |
| statute | Kids' Online Safety and Privacy Month Act, 2025 — Ontario e-Laws consolidated text (JSON endpoint) | https://www.ontario.ca/laws/api/v2/legislation/en/act-content/statute/25k25 |
| regulator | Directive on Service and Digital — Treasury Board of Canada Secretariat | https://www.tbs-sct.canada.ca/pol/doc-eng.aspx?id=32601 |
| regulator | Direction on the Secure Use of Commercial Cloud Services: Security Policy Implementation Notice (SPIN 2017-01) — Government of Canada | https://www.canada.ca/en/government/system/digital-government/digital-government-innovations/cloud-services/direction-secure-use-commercial-cloud-services-spin.html |
| institution | ADRIC Arbitration Rules, effective 01 March 2025 — ADR Institute of Canada, Inc. (PDF) | https://adric.ca/rules/ADRIC-Arbitration-Rules-2025.pdf |
| institution | Rules & Codes — ADR Institute of Canada | https://adric.ca/rules-codes/ |
| institution | Artificial Intelligence and Arbitration: A Perfect Fit? — ADR Institute of Canada | https://adric.ca/artificial-intelligence-and-arbitration-a-perfect-fit/ |
| institution | Who We Are — Canadian International Internet Dispute Resolution Centre (CIIDRC) | https://ciidrc.org/about-ciidrc/ |
| institution | CIIDRC Supplemental Rules — Canadian International Internet Dispute Resolution Centre | https://ciidrc.org/domain-name-disputes/ciidrc-supplemental-rules/ |
| institution | CIRA Domain Name Dispute Resolution Policy (reproduced by CIIDRC, a CIRA-approved provider) | https://ciidrc.org/domain-name-disputes/cdrp-policy/ |
| institution | Rules of Procedure — VanIAC (Vancouver International Arbitration Centre) | https://vaniac.org/arbitration/rules-of-procedure/ |
Verbatim quotations
LEGISinfo — Bill C-27 (44-1), Digital Charter Implementation Act, 2022 — Parliament of Canada
https://www.parl.ca/legisinfo/en/bill/44-1/c-27 — retrieved 2026-08-29
An Act to enact the Consumer Privacy Protection Act, the Personal Information and Data Protection Tribunal Act and the Artificial Intelligence and Data Act and to make consequential and related amendments to other Acts
Digital Charter Implementation Act, 2022
At consideration in committee in the House of Commons
Second reading and referral to committee on Monday, April 24, 2023
44th Parliament, 1st session (November 22, 2021 to January 6, 2025)
LEGISinfo bills data (JSON), 44th Parliament 1st Session — Parliament of Canada
https://www.parl.ca/legisinfo/en/bills/json?parlsession=44-1 — retrieved 2026-08-29
"NumberCode":"C-27" ... "StatusNameEn":"At consideration in committee in the House of Commons"
"LatestCompletedMajorStageNameEn":"Second reading"
"ReceivedRoyalAssent":false
"ReceivedRoyalAssentDateTime":null
"DidReinstateInNextSession":false
"IsSessionOngoing":false
"ParliamentNumber":44, "SessionNumber":1
House of Commons Procedure and Practice, Fourth Edition (2025), Ch. 8 — Prorogation and Dissolution
https://www.ourcommons.ca/procedure/procedure-and-practice-4/ch08-7-e.html — retrieved 2026-08-29
Government bills which have not received royal assent before prorogation die and, in order to be proceeded with in the new session, must be reintroduced as if they had never existed.
All items on the Order Paper including government and private members' bills die.
Personal Information Protection and Electronic Documents Act (S.C. 2000, c. 5) — Justice Laws Website
https://laws-lois.justice.gc.ca/eng/acts/P-8.6/FullText.html — retrieved 2026-08-29
Personal Information Protection and Electronic Documents Act
Act current to 2026-06-21 and last amended on 2025-03-04.
4 (1) This Part applies to every organization in respect of personal information that (a) the organization collects, uses or discloses in the course of commercial activities; or (b) is about an employee of, or an applicant for employment with, the organization and that the organization collects, uses or discloses in connection with the operation of a federal work, undertaking or business.
4.1.3 An organization is responsible for personal information in its possession or custody, including information that has been transferred to a third party for processing. The organization shall use contractual or other means to provide a comparable level of protection while the information is being processed by a third party.
(grep over the full text for the phrases "outside Canada", "stored in Canada", "within Canada" and "localiz" returned exit status 1 and zero lines; instrument check on the same file returned 113 occurrences of "personal information")
LEGISinfo bills data (JSON), 45th Parliament 1st Session — Parliament of Canada
https://www.parl.ca/legisinfo/en/bills/json?parlsession=45-1 — retrieved 2026-08-29
(185 bills in the session; a regex scan of every LongTitleEn and ShortTitleEn for /privacy|personal information|artificial intelligence|consumer privacy|data protection|cyber|digital charter/i returned exactly two: C-8 and C-36)
"NumberCode":"C-8" ... "An Act respecting cyber security, amending the Telecommunications Act and making consequential amendments to other Acts" ... "StatusNameEn":"Royal assent received" ... "ReceivedRoyalAssentDateTime":"2026-06-15T06:15:00-04:00"
"NumberCode":"C-36" ... "An Act to enact the Protecting Privacy and Consumer Data Act, to amend the Personal Information Protection and Electronic Documents Act and to make amendments to other Acts" ... "StatusNameEn":"At second reading in the House of Commons" ... "ReceivedRoyalAssent":false
"PassedHouseFirstReadingDateTime":"2026-06-15T11:18:34.507-04:00"
(a regex scan of every 45-1 bill title for /intellig/i returned 0 matches)
LEGISinfo — Bill C-36 (45-1), An Act to enact the Protecting Privacy and Consumer Data Act — Parliament of Canada
https://www.parl.ca/legisinfo/en/bill/45-1/c-36 — retrieved 2026-08-29
An Act to enact the Protecting Privacy and Consumer Data Act, to amend the Personal Information Protection and Electronic Documents Act and to make amendments to other Acts
Sponsor: Minister of Artificial Intelligence and Digital Innovation
At second reading in the House of Commons
First reading: Completed Monday, June 15, 2026
Royal Assent: Not received
Bill C-36 (45-1), first reading text — Parliament of Canada
https://www.parl.ca/DocumentViewer/en/45-1/bill/C-36/first-reading — retrieved 2026-08-29
This enactment enacts the Protecting Privacy and Consumer Data Act to govern the protection of personal information of individuals while taking into account the need of organizations to collect, use or disclose personal information in the course of commercial activities.
This Act may be cited as the Protecting Privacy and Consumer Data Act.
Statutes of Canada 2026, c. 9 — An Act respecting cyber security … — Justice Laws Website
https://laws-lois.justice.gc.ca/eng/AnnualStatutes/2026_9/ — retrieved 2026-08-29
An Act respecting cyber security, amending the Telecommunications Act and making consequential amendments to other Acts (S.C. 2026, c. 9)
Assented to June 15, 2026
Bill C-8 (45-1), royal assent text — Parliament of Canada
https://www.parl.ca/DocumentViewer/en/45-1/bill/C-8/royal-assent — retrieved 2026-08-29
STATUTES OF CANADA 2026 CHAPTER 9
ASSENTED TO June 15, 2026
Part 2 enacts the Critical Cyber Systems Protection Act
Summary of privacy laws in Canada — Office of the Privacy Commissioner of Canada
https://www.priv.gc.ca/en/privacy-topics/privacy-laws-in-canada/02_05_d_15/ — retrieved 2026-08-29
Canada has two federal privacy laws that are enforced by the Office of the Privacy Commissioner of Canada: the Privacy Act, which covers how the federal government handles personal information; the Personal Information Protection and Electronic Documents Act (PIPEDA), which covers how businesses handle personal information.
PIPEDA sets the ground rules for how private-sector organizations collect, use, and disclose personal information in the course of for-profit, commercial activities across Canada.
PIPEDA generally applies to personal information held by private sector organizations that are not federally-regulated, and conduct business in: Manitoba New Brunswick Newfoundland and Labrador Northwest Territories Nova Scotia Nunavut Ontario Prince Edward Island Saskatchewan Yukon.
Date modified: 2018-01-31
Guidelines for processing personal data across borders — Office of the Privacy Commissioner of Canada
https://www.priv.gc.ca/en/privacy-topics/airports-and-borders/gl_dab_090127/ — retrieved 2026-08-29
PIPEDA does not prohibit organizations in Canada from transferring personal information to an organization in another jurisdiction for processing. However, under PIPEDA, organizations are held accountable for the protection of personal information transfers under each individual outsourcing arrangement.
Principle 4.1.3 of Schedule 1 of PIPEDA specifically recognizes that personal information may be transferred to third parties for processing. It also requires organizations to use contractual or other means to "provide a comparable level of protection while the information is being processed by the third party."
In contrast to this state-to-state approach, Canada has, through PIPEDA, chosen an organization-to-organization approach that is not based on the concept of adequacy.
Date modified: 2009-01-27
Announcement: Commissioner concludes consultation on transfers for processing — Office of the Privacy Commissioner of Canada
https://www.priv.gc.ca/en/opc-news/news-and-announcements/2019/an_190923/ — retrieved 2026-08-29
Commissioner concludes consultation on transfers for processing (September 23, 2019)
guidelines for processing personal data across borders
remain unchanged under the current law
Personal Health Information Protection Act, 2004 — Ontario e-Laws consolidated text (JSON endpoint behind https://www.ontario.ca/laws/statute/04p03)
https://www.ontario.ca/laws/api/v2/legislation/en/act-content/statute/04p03 — retrieved 2026-08-29
"title": "Personal Health Information Protection Act, 2004, S.O. 2004, c. 3, Sched. A"
"description": "Consolidation Period: From January 1, 2026 to the e-Laws currency date." / "comment": "Last amendment: 2025, c. 7, Sched. 6, s. 1-13"
12 (1) A health information custodian shall take steps that are reasonable in the circumstances to ensure that personal health information in the custodian's custody or control is protected against theft, loss and unauthorized use or disclosure and to ensure that the records containing the information are protected against unauthorized copying, modification or disposal.
Place where records kept 14 (1) A health information custodian may keep a record of personal health information about an individual in the individual's home in any reasonable manner to which the individual consents, subject to any restrictions set out in a regulation, by-law or published guideline under the Regulated Health Professions Act, 1991 …
Records kept in other places (2) A health care practitioner may keep a record of personal health information about an individual in a place other than the individual's home and other than a place in the control of the practitioner if, (a) the record is kept in a reasonable manner; (b) the individual consents; …
Disclosure outside Ontario 50 (1) A health information custodian may disclose personal health information about an individual collected in Ontario to a person outside Ontario only if, (a) the individual consents to the disclosure; (b) this Act permits the disclosure; …
(grep over the extracted plain text for "outside Canada" returned 0 matches; the only "outside Ontario" provisions are s. 44 research approval, and s. 50 disclosure)
O. Reg. 329/04 (GENERAL) under PHIPA — Ontario e-Laws consolidated text (JSON endpoint)
https://www.ontario.ca/laws/api/v2/legislation/en/act-content/regulation/040329 — retrieved 2026-08-29
"actTitle": "Personal Health Information Protection Act, 2004, S.O. 2004, c. 3, Sched. A"
"consolidationPeriod": "January 1, 2026"
(7) Despite subsection 45 (6) of the Act, the Canadian Institute for Health Information may disclose personal health information about an individual to a person outside Ontario where,
(10) Despite subsection 45 (6) of the Act, Ontario Health may disclose personal health information about an individual to a person outside Ontario where,
(a grep over the extracted text for "outside canada", "in canada", "outside ontario" and "stored" returned 3 lines, all of them disclosure-permission or health-number provisions; none imposes a storage-location requirement)
Freedom of Information and Protection of Privacy Act — Ontario e-Laws consolidated text (JSON endpoint behind https://www.ontario.ca/laws/statute/90f31)
https://www.ontario.ca/laws/api/v2/legislation/en/act-content/statute/90f31 — retrieved 2026-08-29
"title": "Freedom of Information and Protection of Privacy Act, R.S.O. 1990, c. F.31"
"description": "Consolidation Period: From July 1, 2026 to the e-Laws currency date." / "comment": "Last amendment: 2026, c. 2, Sched. 7"
Privacy safeguards (5) The head of an institution shall take steps that are reasonable in the circumstances to ensure that personal information in the custody or under the control of the institution is protected against theft, loss and unauthorized use or disclosure and to ensure that the records containing the personal information are protected against unauthorized copying, modification or disposal. 2024, c. 24, Sched. 2, s. 5. / Section Amendments with date in force (d/m/y) 2024, c. 24, Sched. 2, s. 5 - 01/07/2025
Breach of privacy safeguards 40.1 (1) The head of an institution shall report to the Commissioner any theft, loss or unauthorized use or disclosure of personal information in the custody or under the control of the institution if it is reasonable in the circumstances to believe that there is real risk that a significant harm to an individual would result or if any other prescribed circumstances exist. 2024, c. 24, Sched. 2, s. 6.
(grep for "outside Canada" returned exit status 1 and 0 lines; instrument check on the same file returned 248 occurrences of "personal information". "in Canada" appears only at 3 law-enforcement disclosure clauses)
Municipal Freedom of Information and Protection of Privacy Act — Ontario e-Laws (JSON endpoint)
https://www.ontario.ca/laws/api/v2/legislation/en/act-content/statute/90m56 — retrieved 2026-08-29
"title": "Municipal Freedom of Information and Protection of Privacy Act, R.S.O. 1990, c. M.56"
"description": "Consolidation Period: From July 1, 2026 to the e-Laws currency date."
Enhancing Digital Security and Trust Act, 2024 — Ontario e-Laws consolidated text (JSON endpoint behind https://www.ontario.ca/laws/statute/24e24)
https://www.ontario.ca/laws/api/v2/legislation/en/act-content/statute/24e24 — retrieved 2026-08-29
"title": "Enhancing Digital Security and Trust Act, 2024, S.O. 2024, c. 24, Sched. 1"
"description": "Consolidation Period: From January 29, 2025 to the e-Laws currency date." / "comment": "No amendments."
"artificial intelligence system" means, (a) a machine-based system that, for explicit or implicit objectives, infers from the input it receives in order to generate outputs such as predictions, content, recommendations or decisions that can influence physical or virtual environments, and (b) such other systems as may be prescribed;
5 (1) This section applies to such public sector entities as may be prescribed for the purposes of this section if they use or intend to use an artificial intelligence system in prescribed circumstances.
No establishment of private law duty of care 12 Nothing in the Strengthening Cyber Security and Building Trust in the Public Sector Act, 2024 , this Act or any regulation made or directive issued under this Act establishes a private law duty of care owing to any person.
Effect of failure to comply 13 Failure to comply with this Act or any regulation made or directive issued under this Act does not affect the validity of any policy, Act, regulation, directive, instrument or decision.
Ontario e-Laws — regulations made under the Enhancing Digital Security and Trust Act, 2024 (JSON endpoint)
https://www.ontario.ca/laws/api/v2/legislation/en/act-reg/regulation?title=enhancing%20digital%20security%20and%20trust%20act%2C%202024&sort=citation — retrieved 2026-08-29
current: 2 results — "regulation/260052" DIGITAL TECHNOLOGY AFFECTING INDIVIDUALS UNDER AGE 18; "regulation/260051" CYBER SECURITY
revoked: 0 results
O. Reg. 51/26 (CYBER SECURITY) under the Enhancing Digital Security and Trust Act, 2024 — Ontario e-Laws (JSON endpoint)
https://www.ontario.ca/laws/api/v2/legislation/en/act-content/regulation/260051 — retrieved 2026-08-29
"title": "CYBER SECURITY" / "actTitle": "Enhancing Digital Security and Trust Act, 2024, S.O. 2024, c. 24, Sched. 1"
"consolidationPeriod": "July 1, 2026" / "comment": "No amendments."
CONTENTS 1. Interpretation 2. Prescribed public sector entities 3. Program 4. Primary point of contact and alternate 5. Cyber security maturity assessment 6. Cyber security maturity assessment summary 7. Critical cyber security incident, report
(a case-insensitive count of "artificial intelligence" in the extracted text returned 0)
O. Reg. 52/26 (DIGITAL TECHNOLOGY AFFECTING INDIVIDUALS UNDER AGE 18) under the Enhancing Digital Security and Trust Act, 2024 — Ontario e-Laws (JSON endpoint)
https://www.ontario.ca/laws/api/v2/legislation/en/act-content/regulation/260052 — retrieved 2026-08-29
"title": "DIGITAL TECHNOLOGY AFFECTING INDIVIDUALS UNDER AGE 18" / "actTitle": "Enhancing Digital Security and Trust Act, 2024, S.O. 2024, c. 24, Sched. 1"
"consolidationPeriod": "July 1, 2026" / "comment": "No amendments."
(a case-insensitive count of "artificial intelligence" in the extracted text returned 0)
Bill 194, Strengthening Cyber Security and Building Trust in the Public Sector Act, 2024 — Legislative Assembly of Ontario
https://www.ola.org/en/legislative-business/bills/parliament-43/session-1/bill-194 — retrieved 2026-08-29
Bill 194, Strengthening Cyber Security and Building Trust in the Public Sector Act, 2024
Royal Assent received. Statutes of Ontario 2024, chapter 24
cyber security and artificial intelligence systems at public sector entities
public sector entities may be required to comply with requirements respecting the use of artificial intelligence, including requirements to provide information, to develop and implement accountability frameworks and to take steps respecting risk management
Bills — 44th Parliament, 1st Session — Legislative Assembly of Ontario
https://www.ola.org/en/legislative-business/bills/parliament-44/session-1 — retrieved 2026-08-29
(139 numbered bills, 1 through 139, listed on a single unpaginated page; a keyword scan of all titles for /privacy|personal information|freedom of information|health information|artificial intelligence|data|digital|cyber|technolog|online/i returned exactly four)
Bill 15: Kids' Online Safety and Privacy Month Act, 2025
Bill 61: Ontario Artificial Intelligence, Talent and Innovation Strategy Act, 2025
Bill 66: Kids' Online Safety and Privacy Month Act, 2025
Bill 137: Keeping Our Kids Safe Online Act, 2026
Bill 61, Ontario Artificial Intelligence, Talent and Innovation Strategy Act, 2025 — Legislative Assembly of Ontario
https://www.ola.org/en/legislative-business/bills/parliament-44/session-1/bill-61 — retrieved 2026-08-29
Bill 61, Ontario Artificial Intelligence, Talent and Innovation Strategy Act, 2025
Private member's bill
November 24, 2025 — Second Reading — Lost on division
Kids' Online Safety and Privacy Month Act, 2025 — Ontario e-Laws consolidated text (JSON endpoint)
https://www.ontario.ca/laws/api/v2/legislation/en/act-content/statute/25k25 — retrieved 2026-08-29
"title": "Kids' Online Safety and Privacy Month Act, 2025, S.O. 2025, c. 25"
"description": "Consolidation Period: From December 11, 2025 to the e-Laws currency date."
Kids' Online Safety and Privacy Month 1 The month of October in each year is proclaimed as Kids' Online Safety and Privacy Month.
2 Omitted ( provides for coming into force of provisions of this Act ). 3 Omitted (enacts short title of this Act).
Directive on Service and Digital — Treasury Board of Canada Secretariat
https://www.tbs-sct.canada.ca/pol/doc-eng.aspx?id=32601 — retrieved 2026-08-29
Information and data residency
4.3.24 Ensuring that computing facilities located within the geographic boundaries of Canada or within the premises of a GC department located abroad, such as a diplomatic or consular mission, be identified and evaluated as a principal delivery option for all sensitive electronic information and data under government control that has been categorized as Protected B or Protected C or is classified;
Date modified: 2025-08-29
Direction on the Secure Use of Commercial Cloud Services: Security Policy Implementation Notice (SPIN 2017-01) — Government of Canada
https://www.canada.ca/en/government/system/digital-government/digital-government-innovations/cloud-services/direction-secure-use-commercial-cloud-services-spin.html — retrieved 2026-08-29
SPIN No.: 2017-01 Date: November 1, 2017 Date modified: June 23, 2022
6.2.2 Data residency — Departments are expected to apply the Directive on Service and Digital when implementing safeguards for GC electronic data residency.
ADRIC Arbitration Rules, effective 01 March 2025 — ADR Institute of Canada, Inc. (PDF)
https://adric.ca/rules/ADRIC-Arbitration-Rules-2025.pdf — retrieved 2026-08-29
ADRIC ARBITRATION RULES Effective 01 March 2025
ADRIC intends these Rules for Canadian commercial disputes; however, parties can apply them to international or non-commercial disputes.
Privacy and Security of Evidence 31. Each party and its counsel are responsible for ensuring that all relevant privacy and data security requirements prescribed by law or contract in relation to evidence put forward by that party are complied with, and that the Tribunal is made aware of any steps that the Tribunal needs to take in that regard.
(a case-insensitive grep of the extracted 103,811-character text for "artificial intelligence", "machine learning" and the standalone token "AI" returned no matches; the only hits for "technolog|cyber|data|electronic" were three lines about electronic data as evidence, electronic delivery, and the clause quoted above)
Rules & Codes — ADR Institute of Canada
https://adric.ca/rules-codes/ — retrieved 2026-08-29
Rules & Codes — ADR Institute of Canada
ADRIC By-laws / Federation MoU / ADRIC Arbitration Rules / National Mediation Rules / ADRIC Med-Arb Rules
Ethics & Professional Practice — Code of Ethics / Code of Conduct / Conflict of Interest / Complaints & Discipline Policy / Privacy Policy / Online Dispute Resolution (ODR) Vision
Artificial Intelligence and Arbitration: A Perfect Fit? — ADR Institute of Canada
https://adric.ca/artificial-intelligence-and-arbitration-a-perfect-fit/ — retrieved 2026-08-29
Artificial Intelligence and Arbitration: A Perfect Fit?
March 2, 2023
By Robin Dodokin, Sarah McEachern, Les Honywill
Machine learning and AI have progressed so far that their integration into the arbitral process seems inevitable, with the only question being a matter of time and degree.
Who We Are — Canadian International Internet Dispute Resolution Centre (CIIDRC)
https://ciidrc.org/about-ciidrc/ — retrieved 2026-08-29
The Canadian International Internet Dispute Resolution Centre ("CIIDRC", "the Centre") serves global Internet users by providing trusted and efficient resolution of domain name disputes under the Uniform Domain Name Dispute Resolution Policy (the UDRP) and the CIRA Domain Name Dispute Resolution Policy (the CDRP).
CIIDRC is a division of the Vancouver International Arbitration Centre, formerly known as the British Columbia International Commercial Arbitration Centre ("the Centre").
CIIDRC's parent organization, VanIAC (formerly BCICAC), has been a service provider for the Canadian Internet Registration Authority (CIRA) since 2002, successfully managing .ca (dot ca) domain name disputes.
CIIDRC Supplemental Rules — Canadian International Internet Dispute Resolution Centre
https://ciidrc.org/domain-name-disputes/ciidrc-supplemental-rules/ — retrieved 2026-08-29
CIIDRC Supplemental Rules OF THE CANADIAN INTERNATIONAL INTERNET DISPUTE RESOLUTION CENTRE (the "Centre" or the "CIIDRC" or the "Provider") FOR THE UNIFORM DOMAIN NAME DISPUTE RESOLUTION POLICY (the "Policy") AND THE RULES FOR THE UNIFORM DOMAIN NAME DISPUTE RESOLUTION POLICY (the "UDRP Rules")
The Supplemental Rules (In effect as of May 9, 2018)
CIRA Domain Name Dispute Resolution Policy (reproduced by CIIDRC, a CIRA-approved provider)
https://ciidrc.org/domain-name-disputes/cdrp-policy/ — retrieved 2026-08-29
CIRA Domain Name Dispute Resolution Policy — Version 1.3 (August 22, 2011)
1.1 Purpose. The purpose of this CIRA Domain Name Dispute Resolution Policy (the "Policy") is to provide a forum in which cases of bad faith registration of domain names registered in the dot-ca country code top level domain name registry operated by CIRA (the "Registry") can be dealt with relatively inexpensively and quickly.
1.2 Scope. The Policy sets forth the terms and conditions for resolution by arbitration of a dispute between a person (the "Registrant") who has obtained the registration of a domain name in the Registry (the "Registration") and any other person …
1.5 Dispute Resolution Service Provider. All Proceedings will be administered by a dispute resolution service provider approved by CIRA (the "Provider").
Rules of Procedure — VanIAC (Vancouver International Arbitration Centre)
https://vaniac.org/arbitration/rules-of-procedure/ — retrieved 2026-08-29
Rules of Procedure — Domestic Arbitration Rules (as amended Sept. 1, 2020)
International Commercial Arbitration Rules of Procedure (as amended July 1, 2022)
International Commercial Arbitration Rules of Procedure (as amended Jan. 1, 2000)
(the page's full navigation lists arbitration, mediation and motor-vehicle rules, forms, fee schedules and an Arbitrator Code of Conduct; no rule set, guideline or note on artificial intelligence or technology disputes appears)
What this establishes
- PIPEDA — the Personal Information Protection and Electronic Documents Act, S.C. 2000, c. 5 — is the federal private-sector privacy statute in force. The Justice Laws consolidation states "Act current to 2026-06-21 and last amended on 2025-03-04." Source: https://laws-lois.justice.gc.ca/eng/acts/P-8.6/FullText.html
- PIPEDA Part 1 applies to every organization in respect of personal information it "collects, uses or discloses in the course of commercial activities" (s. 4(1)(a)), and to employee information in connection with a federal work, undertaking or business (s. 4(1)(b)). Source: https://laws-lois.justice.gc.ca/eng/acts/P-8.6/FullText.html
- The Office of the Privacy Commissioner of Canada states that Canada has two federal privacy laws it enforces — the Privacy Act (federal government) and PIPEDA, which "sets the ground rules for how private-sector organizations collect, use, and disclose personal information in the course of for-profit, commercial activities across Canada." PIPEDA generally applies to non-federally-regulated private-sector organizations doing business in Ontario (among other provinces and territories). Source: https://www.priv.gc.ca/en/privacy-topics/privacy-laws-in-canada/02_05_d_15/
- Bill C-27 (44th Parliament, 1st Session) was the bill that would have enacted the Consumer Privacy Protection Act, the Personal Information and Data Protection Tribunal Act and the Artificial Intelligence and Data Act. Its short title was the Digital Charter Implementation Act, 2022. Source: https://www.parl.ca/legisinfo/en/bill/44-1/c-27
- Bill C-27 never received royal assent. LEGISinfo records its last completed major stage as "Second reading", its status as "At consideration in committee in the House of Commons", ReceivedRoyalAssent = false, ReceivedRoyalAssentDateTime = null, IsSessionOngoing = false, and DidReinstateInNextSession = false. Source: https://www.parl.ca/legisinfo/en/bills/json?parlsession=44-1
- The 44th Parliament's 1st session ran to January 6, 2025, and Bill C-27 had not advanced past committee when it ended. Source: https://www.parl.ca/legisinfo/en/bill/44-1/c-27
- Under House of Commons Procedure and Practice (4th ed., 2025), "Government bills which have not received royal assent before prorogation die and, in order to be proceeded with in the new session, must be reintroduced as if they had never existed," and on dissolution "All items on the Order Paper including government and private members' bills die." Combined with the LEGISinfo record, this means the Consumer Privacy Protection Act and the Artificial Intelligence and Data Act were never enacted and do not exist as Canadian law. Source: https://www.ourcommons.ca/procedure/procedure-and-practice-4/ch08-7-e.html
- In the 45th Parliament, 1st Session, a scan of all 185 bills found only two whose titles touch privacy, AI, cyber or data protection: C-8 and C-36. No bill in the session has "intellig" (i.e. "intelligence") anywhere in its title — there is no successor AI bill to AIDA before Parliament. Source: https://www.parl.ca/legisinfo/en/bills/json?parlsession=45-1
- Bill C-36 (45-1), "An Act to enact the Protecting Privacy and Consumer Data Act, to amend the Personal Information Protection and Electronic Documents Act and to make amendments to other Acts", received first reading on June 15, 2026, is sponsored by the Minister of Artificial Intelligence and Digital Innovation, and its status is "At second reading in the House of Commons". Royal assent has NOT been received. Source: https://www.parl.ca/legisinfo/en/bill/45-1/c-36
- Bill C-36 would enact the "Protecting Privacy and Consumer Data Act" to govern protection of personal information collected, used or disclosed in the course of commercial activities. It is a bill, not a statute — nothing in it is in force. Source: https://www.parl.ca/DocumentViewer/en/45-1/bill/C-36/first-reading
- There is no "2026 privacy statute" in Canadian federal law. The only 2026 federal privacy instrument is Bill C-36, introduced 15 June 2026 and still at second reading with no royal assent, so PIPEDA remains the operative federal private-sector privacy statute as at 2026-08-29. Source: https://www.parl.ca/legisinfo/en/bills/json?parlsession=45-1
- The one cyber/data-adjacent federal statute enacted in 2025–2026 is Bill C-8, "An Act respecting cyber security, amending the Telecommunications Act and making consequential amendments to other Acts", which received royal assent on June 15, 2026 and is S.C. 2026, c. 9. It enacts the Critical Cyber Systems Protection Act. It is a critical-infrastructure cyber security statute, not a privacy or AI statute. Source: https://laws-lois.justice.gc.ca/eng/AnnualStatutes/2026_9/
- Ontario public-sector access/privacy statute: Freedom of Information and Protection of Privacy Act, R.S.O. 1990, c. F.31 (e-Laws consolidation period from July 1, 2026; last amendment 2026, c. 2, Sched. 7). Source: https://www.ontario.ca/laws/api/v2/legislation/en/act-content/statute/90f31
- Ontario municipal-sector equivalent: Municipal Freedom of Information and Protection of Privacy Act, R.S.O. 1990, c. M.56 (e-Laws consolidation period from July 1, 2026). Source: https://www.ontario.ca/laws/api/v2/legislation/en/act-content/statute/90m56
- Ontario health privacy statute: Personal Health Information Protection Act, 2004, S.O. 2004, c. 3, Sched. A (e-Laws consolidation period from January 1, 2026; last amendment 2025, c. 7, Sched. 6, ss. 1–13). Source: https://www.ontario.ca/laws/api/v2/legislation/en/act-content/statute/04p03
- FIPPA's privacy-safeguard duty (s. 40(5)) and mandatory breach reporting to the Commissioner and notification to affected individuals (s. 40.1) were enacted by S.O. 2024, c. 24, Sched. 2, ss. 5–6, and the e-Laws in-force note records both as in force 01/07/2025. Source: https://www.ontario.ca/laws/api/v2/legislation/en/act-content/statute/90f31
- Ontario's AI-relevant statute is the Enhancing Digital Security and Trust Act, 2024, S.O. 2024, c. 24, Sched. 1 (enacted by Bill 194, royal assent giving Statutes of Ontario 2024, chapter 24), consolidated from January 29, 2025 with no amendments. It defines "artificial intelligence system" as "a machine-based system that, for explicit or implicit objectives, infers from the input it receives in order to generate outputs such as predictions, content, recommendations or decisions that can influence physical or virtual environments". Source: https://www.ontario.ca/laws/api/v2/legislation/en/act-content/statute/24e24
- Every EDSTA AI obligation is conditional on regulations: s. 5(1) applies only "to such public sector entities as may be prescribed … if they use or intend to use an artificial intelligence system in prescribed circumstances." The Act also states at s. 12 that nothing in it "establishes a private law duty of care owing to any person", and at s. 13 that failure to comply "does not affect the validity of any policy, Act, regulation, directive, instrument or decision." Source: https://www.ontario.ca/laws/api/v2/legislation/en/act-content/statute/24e24
- Only two regulations have been made under EDSTA — O. Reg. 51/26 (Cyber Security) and O. Reg. 52/26 (Digital Technology Affecting Individuals Under Age 18); the e-Laws listing shows 2 current and 0 revoked. No AI regulation has been made, so EDSTA's artificial-intelligence sections have no prescribed entities or circumstances and impose no operative obligation as at 2026-08-29. Source: https://www.ontario.ca/laws/api/v2/legislation/en/act-reg/regulation?title=enhancing%20digital%20security%20and%20trust%20act%2C%202024&sort=citation
- O. Reg. 51/26 (Cyber Security) under EDSTA has a consolidation period from July 1, 2026 and covers prescribed public sector entities, cyber security programs, a primary point of contact, cyber security maturity assessments and critical incident reporting. The phrase "artificial intelligence" does not appear in it. Source: https://www.ontario.ca/laws/api/v2/legislation/en/act-content/regulation/260051
- O. Reg. 52/26 (Digital Technology Affecting Individuals Under Age 18) under EDSTA has a consolidation period from July 1, 2026 and deals with prescribed school boards and notice of disclosure of students' personal digital information. The phrase "artificial intelligence" does not appear in it. Source: https://www.ontario.ca/laws/api/v2/legislation/en/act-content/regulation/260052
- No Ontario privacy or AI regulatory statute was enacted in 2025 or 2026. Of the 139 bills in the Ontario 44th Parliament 1st Session, only four have privacy/AI/online titles: Bill 61, the Ontario Artificial Intelligence, Talent and Innovation Strategy Act, 2025 (a private member's bill) was lost on division at second reading on November 24, 2025; Bill 137 is still at first reading; and Bills 15/66 are commemorative-month bills. Source: https://www.ola.org/en/legislative-business/bills/parliament-44/session-1
- Bill 61, the Ontario Artificial Intelligence, Talent and Innovation Strategy Act, 2025, was a private member's bill and was lost on division at second reading on November 24, 2025 — Ontario has no AI strategy statute. Source: https://www.ola.org/en/legislative-business/bills/parliament-44/session-1/bill-61
- The only Ontario statute with "Privacy" in its title enacted in this period is the Kids' Online Safety and Privacy Month Act, 2025, S.O. 2025, c. 25 (in force December 11, 2025). Its entire operative content is s. 1: "The month of October in each year is proclaimed as Kids' Online Safety and Privacy Month." It creates no privacy obligations. Source: https://www.ontario.ca/laws/api/v2/legislation/en/act-content/statute/25k25
- DATA RESIDENCY — PIPEDA contains no data-localization requirement. A grep of the full Justice Laws consolidation for "outside Canada", "stored in Canada", "within Canada" and "localiz" returned zero matches (grep exit status 1), against 113 occurrences of "personal information" in the same file as an instrument check. Source: https://laws-lois.justice.gc.ca/eng/acts/P-8.6/FullText.html
- The OPC states directly: "PIPEDA does not prohibit organizations in Canada from transferring personal information to an organization in another jurisdiction for processing. However, under PIPEDA, organizations are held accountable for the protection of personal information transfers under each individual outsourcing arrangement." Canada's approach is organization-to-organization accountability, not EU-style adequacy. Source: https://www.priv.gc.ca/en/privacy-topics/airports-and-borders/gl_dab_090127/
- What PIPEDA requires instead of residency is accountability: Schedule 1, clause 4.1.3 — "An organization is responsible for personal information in its possession or custody, including information that has been transferred to a third party for processing. The organization shall use contractual or other means to provide a comparable level of protection while the information is being processed by a third party." Source: https://laws-lois.justice.gc.ca/eng/acts/P-8.6/FullText.html
- The OPC reopened and then closed this question: on September 23, 2019 the Commissioner concluded the consultation on transfers for processing, confirming that the guidelines for processing personal data across borders "remain unchanged under the current law." Source: https://www.priv.gc.ca/en/opc-news/news-and-announcements/2019/an_190923/
- DATA RESIDENCY — Ontario PHIPA imposes no requirement that personal health information be stored in Ontario or in Canada. The section headed "Place where records kept" (s. 14) is about keeping records in the individual's home or a place other than the practitioner's control, not about jurisdiction. The phrase "outside Canada" does not appear anywhere in the Act. Source: https://www.ontario.ca/laws/api/v2/legislation/en/act-content/statute/04p03
- PHIPA s. 50 ("Disclosure outside Ontario") is a disclosure-permission rule, not a storage rule: it permits a custodian to disclose personal health information collected in Ontario to a person outside Ontario where, among other gateways, the individual consents, the Act permits the disclosure, or the disclosure is reasonably necessary for the provision of health care to the individual. Source: https://www.ontario.ca/laws/api/v2/legislation/en/act-content/statute/04p03
- PHIPA's security duty (s. 12(1)) is a reasonableness standard — "steps that are reasonable in the circumstances" to protect against theft, loss and unauthorized use or disclosure — with no location component. Source: https://www.ontario.ca/laws/api/v2/legislation/en/act-content/statute/04p03
- O. Reg. 329/04 (General) under PHIPA likewise imposes no storage-location requirement. Its only "outside Ontario" provisions permit the Canadian Institute for Health Information and Ontario Health to disclose to persons outside Ontario in defined circumstances. Source: https://www.ontario.ca/laws/api/v2/legislation/en/act-content/regulation/040329
- DATA RESIDENCY — Ontario FIPPA contains no data-localization requirement either. A grep of the full consolidated text for "outside Canada" returned zero matches (grep exit status 1) against 248 occurrences of "personal information" as an instrument check; the only "in Canada" occurrences are law-enforcement disclosure clauses. Source: https://www.ontario.ca/laws/api/v2/legislation/en/act-content/statute/90f31
- The closest thing to a Canadian residency rule is a federal internal-administration policy, not a law of general application, and it is not absolute. Treasury Board's Directive on Service and Digital, s. 4.3.24, requires only that Canadian computing facilities "be identified and evaluated as a principal delivery option" for Government of Canada data categorized Protected B, Protected C or classified. It binds federal departments, not private organizations. Source: https://www.tbs-sct.canada.ca/pol/doc-eng.aspx?id=32601
- The cloud direction commonly cited for "data must stay in Canada" (SPIN 2017-01) does not itself set a residency rule: its s. 6.2.2 says only that "Departments are expected to apply the Directive on Service and Digital when implementing safeguards for GC electronic data residency." Source: https://www.canada.ca/en/government/system/digital-government/digital-government-innovations/cloud-services/direction-secure-use-commercial-cloud-services-spin.html
- ARBITRAL INSTITUTIONS — The ADR Institute of Canada's current ADRIC Arbitration Rules (effective 01 March 2025) contain no provision on artificial intelligence, machine learning, or technology disputes. A case-insensitive grep of the full 103,811-character extracted text for "artificial intelligence", "machine learning" and the token "AI" returned no matches. The only data-related clause is a party-responsibility rule for privacy and data security of evidence. Source: https://adric.ca/rules/ADRIC-Arbitration-Rules-2025.pdf
- ADRIC's published Rules & Codes are: ADRIC By-laws, Federation MoU, ADRIC Arbitration Rules, National Mediation Rules, ADRIC Med-Arb Rules, Code of Ethics, Code of Conduct, Conflict of Interest, Complaints & Discipline Policy, Privacy Policy, and an Online Dispute Resolution (ODR) Vision. None is specific to technology, data or AI disputes. Source: https://adric.ca/rules-codes/
- ADRIC's only AI-related publication located is an article, not a rule or guideline: "Artificial Intelligence and Arbitration: A Perfect Fit?", dated March 2, 2023, by Robin Dodokin, Sarah McEachern and Les Honywill. It is commentary about AI's likely role in arbitration, not institutional guidance to arbitrators or parties. Source: https://adric.ca/artificial-intelligence-and-arbitration-a-perfect-fit/
- There IS a Canadian arbitral institution with rules specific to one class of technology dispute: the Canadian International Internet Dispute Resolution Centre (CIIDRC), a division of the Vancouver International Arbitration Centre (VanIAC, formerly BCICAC), which resolves domain-name disputes under the UDRP and CIRA's CDRP and has been a CIRA service provider since 2002. Source: https://ciidrc.org/about-ciidrc/
- CIIDRC publishes its own Supplemental Rules for the UDRP, in effect as of May 9, 2018, which govern communications, complaints and annexes, panelist appointment, fees, word limits and file format for domain-name proceedings. Source: https://ciidrc.org/domain-name-disputes/ciidrc-supplemental-rules/
- The CIRA Domain Name Dispute Resolution Policy, Version 1.3 (August 22, 2011), provides for "resolution by arbitration" of disputes over bad-faith registration of .ca domain names, administered by a dispute resolution service provider approved by CIRA. Source: https://ciidrc.org/domain-name-disputes/cdrp-policy/
- VanIAC's own Rules of Procedure page lists only its Domestic Arbitration Rules (as amended Sept. 1, 2020) and International Commercial Arbitration Rules of Procedure (as amended July 1, 2022 and Jan. 1, 2000), plus mediation and motor-vehicle rules. No AI or technology-dispute rule set or guidance note appears. Source: https://vaniac.org/arbitration/rules-of-procedure/
What this does NOT establish
Read this section before writing copy.
- Does "the 2026 privacy statute" referred to in docs/03-content-spec.md line 299 exist?
- Searched: LEGISinfo bill records for the 44th Parliament 1st Session (all 412 bills) and 45th Parliament 1st Session (all 185 bills), fetched as JSON from parl.ca; the LEGISinfo bill pages for C-27, C-36 and C-8; the Justice Laws consolidation of PIPEDA and the 2026 annual statutes index; the Ontario e-Laws consolidated statute database; and the Legislative Assembly of Ontario's complete bill list for the 44th Parliament 1st Session (139 bills).
- Outcome: NO SUCH STATUTE EXISTS. Nothing enacted federally or in Ontario in 2025 or 2026 is a privacy statute. The nearest real things are (a) federal Bill C-36, introduced 15 June 2026, which WOULD enact the Protecting Privacy and Consumer Data Act — but it is at second reading with no royal assent; (b) federal Bill C-8 / S.C. 2026, c. 9, a cyber security statute, not privacy; and (c) Ontario O. Regs. 51/26 and 52/26 in force 1 July 2026, which are regulations under a 2024 Act, not a statute. Any public-page copy relying on "the 2026 privacy statute" as market context is asserting something that is not law. If the intent was "pending federal privacy reform", the accurate framing is Bill C-36 (45-1), first reading 15 June 2026, still before the House.
- Did the Consumer Privacy Protection Act or the Artificial Intelligence and Data Act ever come into force in any form?
- Searched: LEGISinfo C-27 page and JSON record (royal assent flags, reinstatement flags, session-ongoing flag); a scan of all 185 bills in the 45th Parliament 1st Session for any bill title containing "intellig", "artificial intelligence", "consumer privacy" or "data protection"; House of Commons Procedure and Practice 4th ed. on prorogation and dissolution.
- Outcome: No. C-27 died without royal assent and was not reinstated; no successor AI or CPPA bill has been introduced in the 45th Parliament. Canada has no federal AI statute as at 2026-08-29.
- Is there any Canadian federal or Ontario legal requirement that personal data be stored in Canada?
- Searched: Full-text greps of PIPEDA, Ontario FIPPA, PHIPA and O. Reg. 329/04 for "outside Canada", "within Canada", "stored in Canada" and "localiz"; the OPC's Guidelines for processing personal data across borders and its 2019 consultation conclusion; Treasury Board's SPIN 2017-01 and the Directive on Service and Digital.
- Outcome: No such requirement was found in any of them, and the OPC states the opposite for PIPEDA. NOT CHECKED, and outside the scope asked: the public-sector residency provisions in British Columbia's FIPPA and Nova Scotia's PIIDPA, which are the usual real source of the belief that "Canadian data must stay in Canada". Do not assert anything about those provinces from this artefact.
- Does any Canadian arbitral institution publish formal guidance (as distinct from rules) on the use of AI in arbitration or mediation?
- Searched: ADRIC's page sitemap (175 pages) grepped for ai/artificial/tech/rule/code/guideline/protocol; the ADRIC Rules & Codes index; the full text of the ADRIC Arbitration Rules effective 01 March 2025; VanIAC's Rules of Procedure page and site navigation.
- Outcome: None found. ADRIC's only AI material located is a 2023 commentary article and a 2026 conference session page ("The AI-Ready Neutral: Practical Essentials for Arbitrators and Mediators"), neither of which is institutional guidance. The conference page itself was NOT fetched — only its URL appeared in the sitemap — so nothing should be claimed about its content.
- Do ICDR Canada or the Canadian Arbitration Association publish technology- or AI-specific rules?
- Searched: Keyword web search naming ADRIC, VanIAC, CCAC and ICDR Canada together with AI guidance; their own sites were not individually fetched.
- Outcome: Not established either way. Neither icdr.org nor the Canadian Arbitration Association's site was retrieved, so no claim can be made about what they do or do not publish.
- Coming-into-force status of the Critical Cyber Systems Protection Act (S.C. 2026, c. 9) — which of its provisions are actually operative.
- Searched: The LEGISinfo C-8 page, the royal assent text summary, and the Justice Laws Annual Statutes 2026 c. 9 landing page.
- Outcome: Royal assent (15 June 2026) is confirmed, but the coming-into-force provisions were not read in full. Do not assert that the Critical Cyber Systems Protection Act is in force; assert only that it was enacted.
- What S.O. 2026, c. 2, Sched. 7 (the most recent FIPPA amendment) actually changes.
- Searched: Ontario e-Laws statute record for S.O. 2026, c. 2, identified as the Plan to Protect Ontario Act (Budget Measures), 2026 (Bill 97), assented to April 24, 2026; the schedule's text was not extracted.
- Outcome: Identified as a budget-measures omnibus amendment to FIPPA; its substance was not read and must not be characterised.
Searches run
WebSearch: Bill C-27 Digital Charter Implementation Act status LEGISinfo died on Order Paper prorogationWebSearch: PIPEDA Personal Information Protection and Electronic Documents Act S.C. 2000 c. 5 justice lawsWebFetch: https://www.parl.ca/legisinfo/en/bill/44-1/c-27WebFetch: https://www.parl.ca/legisinfo/en/bill/44-1/c-27/jsonWebFetch: https://laws-lois.justice.gc.ca/eng/acts/P-8.6/curl: https://laws-lois.justice.gc.ca/eng/acts/P-8.6/FullText.html (then grep for residency terms; grep exit status read directly rather than through a pipe, after an initialgrep ... | headgave a misleading exit code)curl: https://www.parl.ca/legisinfo/en/bills/json?parlsession=44-1 (412 bill records, keyword scan)curl: https://www.parl.ca/legisinfo/en/bills/json?parlsession=45-1 (185 bill records, keyword scan + 'intellig' scan + full royal-assent list)WebFetch: https://www.parl.ca/legisinfo/en/bill/45-1/c-36WebFetch: https://www.parl.ca/DocumentViewer/en/45-1/bill/C-36/first-readingWebFetch: https://www.parl.ca/legisinfo/en/bill/45-1/c-8WebFetch: https://www.parl.ca/DocumentViewer/en/45-1/bill/C-8/royal-assentWebFetch: https://laws-lois.justice.gc.ca/eng/AnnualStatutes/2026_9/WebSearch + WebFetch: https://www.ourcommons.ca/procedure/procedure-and-practice-4/ch08-7-e.html (prorogation and dissolution)Ontario e-Laws: discovered the JSON API behind the ontario.ca/laws SPA (the HTML pages return only a JS shell to any fetcher, and WebFetch got nothing) by reading /laws/static/js/main.dbd400db.js; base https://www.ontario.ca/laws/api/v2/legislatione-Laws API: /en/currency-date -> "August 26, 2026"e-Laws API: /en/act-content/statute/04p03 (PHIPA) + extraction of ss. 12, 13, 14, 50 and residency grepe-Laws API: /en/act-content/regulation/040329 (O. Reg. 329/04 under PHIPA) + residency grepe-Laws API: /en/act-content/statute/90f31 (FIPPA) + ss. 40, 40.1 + residency grep with exit status reade-Laws API: /en/act-content/statute/90m56 (MFIPPA)e-Laws API: /en/act-content/statute/24e24 (Enhancing Digital Security and Trust Act, 2024) + full text extractione-Laws API: /en/act-reg/regulation?title=enhancing+digital+security+and+trust+act,+2024 (complete list of regulations made under EDSTA: 2 current, 0 revoked)e-Laws API: /en/act-content/regulation/260051 and /260052 (O. Reg. 51/26 and 52/26) + 'artificial intelligence' counte-Laws API: /en/act-content/statute/s26002 (S.O. 2026, c. 2 = Plan to Protect Ontario Act (Budget Measures), 2026, assented April 24, 2026)e-Laws API: /en/act-content/statute/25k25 and /s25025 (Kids' Online Safety and Privacy Month Act, 2025)WebSearch: Ontario Enhancing Digital Security and Trust Act 2024 in force FIPPA amendments Bill 194WebSearch: 'Enhancing Digital Security and Trust Act' Ontario regulation O. Reg. cyber security 2026 July 1 2026WebFetch: https://www.ola.org/en/legislative-business/bills/parliament-43/session-1/bill-194curl + scrape: https://www.ola.org/en/legislative-business/bills/parliament-44/session-1 (all 139 bills, unpaginated, keyword scan)WebFetch: ola.org bills 61, 66 and 137 (44-1)WebFetch: https://www.priv.gc.ca/en/privacy-topics/airports-and-borders/gl_dab_090127/ + curl to verify the page title and Date modifiedcurl: https://www.priv.gc.ca/en/privacy-topics/privacy-laws-in-canada/02_05_d_15/ (Summary of privacy laws in Canada)WebSearch (priv.gc.ca only) + WebFetch: https://www.priv.gc.ca/en/opc-news/news-and-announcements/2019/an_190923/WebSearch (canada.ca only) + curl: SPIN 2017-01 and https://www.tbs-sct.canada.ca/pol/doc-eng.aspx?id=32601 (Directive on Service and Digital, s. 4.3.24)WebSearch: ADRIC artificial intelligence arbitration guideline rules technology disputescurl + pdftotext: https://adric.ca/rules/ADRIC-Arbitration-Rules-2025.pdf (103,811 chars extracted) + AI/technology grepcurl: https://adric.ca/sitemap_index.xml and /page-sitemap.xml (175 pages) + ai/artificial/tech/rule/guideline grepcurl: https://adric.ca/rules-codes/ and https://adric.ca/artificial-intelligence-and-arbitration-a-perfect-fit/WebSearch: VanIAC Vancouver International Arbitration Centre artificial intelligence guidelines rules 2025 2026curl: https://vaniac.org/arbitration/rules-of-procedure/ and https://vaniac.org/curl: https://ciidrc.org/ , /about-ciidrc/ , /domain-name-disputes/cdrp-policy/ , /domain-name-disputes/ciidrc-supplemental-rules/BLOCKED, recorded so a later reader does not mistake silence for absence: canlii.org returned HTTP 403 to WebFetch; cira.ca returned a Cloudflare HTTP 403 to both WebFetch and curl (the CDRP policy was therefore sourced from CIIDRC, a CIRA-approved provider, not from CIRA itself); adric.ca/rules/ returned HTTP 403 to curl although the rules PDF on the same host returned 200; canada.ca returned 403 to WebFetch but 200 to curl with a browser user-agent.