What Bill C-36 Might Mean for Neural Privacy Rights in Canada

Bill C-36 aims to completely repeal the privacy framework established under the Personal Information Protection and Electronic Documents Act, S.C, 2000, C.5 (PIPEDA), which has served as the primary federal privacy framework governing private-sector organizations. It would replace that framework with the new Protecting Privacy and Consumer Data Act (PPCDA).

The medium through which privacy is protected remains largely unchanged. Privacy protections continue to be tied to personal information, which is broadly defined as information that can be used to identify an individual. Neural data, which is any form of information collected directly from a patients brain, collected from consumers and patients would likely fall within this category. Earlier this year, the Office of the Privacy Commissioner of Canada explicitly identified neural data as sensitive information. However, despite Parliament’s introduction of Bill C-36 to replace the current privacy framework, the legislation still does not provide explicit protections for neural rights.

  • Privacy is explicitly recognized as a fundamental right, potentially allowing courts to interpret privacy protections more broadly and in favor of individuals.
  • The collection, use, and disclosure of personal information by organizations is limited to purposes that a reasonable person would consider appropriate.
  • Organizations are permitted to bypass consent requirements in certain circumstances through a number of statutory exceptions.

The PPCDA also defined the term de-identified data, that is personal information that has been modified so that it can no longer be directly linked to a specific individual. Under the proposed PPCDA, de-identified information remains protected because it continues to be classified as personal information.

“For greater certainty, de-identified personal information does not cease to be personal information.” PPDCA, p.1, s.1

This provision would prevent BCI companies from freely using neural data simply because they removed a person’s name or other direct identifiers from the dataset. The legislation also restricts organizations from de-identifying information, using or sharing that information, and then attempting to re-identify the individuals from whom it was collected. As a result, the Act seeks to prevent neural implant companies from de-identifying neural data, sharing or analyzing it, and subsequently attempting to reconnect that data to the individuals from whom it originated.

While the new legislation may provide a stronger foundation for advocating enhanced neural-data protections than the current regulatory framework, it does not create a standalone constitutional-style neural right. Protection remains a statutory privacy right tied to the concept of personal information. The legislation also fails to explicitly recognize neural data, mental privacy, cognitive liberty, or other brain-related interests as distinct categories deserving heightened protection. This creates potential gaps in the law where neural recordings may not receive adequate protection in certain circumstances.

Given the uniquely sensitive nature of neural data, the legislation lacks the robust safeguards and guardrails that Canadians should be afforded as a fundamental right. Stronger standards are needed to govern the collection, use, and disclosure of neural information. The Act also provides organizations with considerable flexibility through numerous exceptions that may allow them to bypass privacy protections that would otherwise apply.

Leave a Reply

Discover more from Neurotech Advocacy

Subscribe now to keep reading and get access to the full archive.

Continue reading