Skip to Content

Privacy Law Is Shifting in Canada: What It Means for the Records Your Business Holds

Original commentary by John Carpay, President of the Justice Centre for Constitutional Freedoms, published in the National Post, July 27, 2026.


In a recent National Post opinion column, lawyer John Carpay argued that Canadians are losing privacy protections that took decades of court decisions to establish. Whether or not you share his reading of the politics, the column raises a question every Canadian business should be asking. As more of your information sits in third party hands under expanding disclosure rules, how much control do you actually have left, and where do you still have it?

The answer matters most for the records you hold yourself, because those are the ones still fully under your control.

What the Column Argues

Carpay’s position is that privacy is foundational to freedom of thought and expression, and that people behave differently and censor themselves when they believe they are being watched. He points to a line of Supreme Court of Canada decisions that built protection against state intrusion, including Hunter v. Southam in 1984, which established that Canadians hold a reasonable expectation of privacy under section 8 of the Charter, R v. Duarte in 1990 on secret electronic surveillance, R v. Spencer in 2014 on warrantless access to subscriber information held by internet providers, and R v. Marakah in 2017 on text messages stored on someone else’s device.

His argument is that recent federal legislation is eroding that framework. He identifies three bills in particular.

Bill C-8, the cyber security legislation, which received royal assent in June 2026, creates a framework governing critical cyber systems and gives government expanded authority over telecommunications providers.

Bill C-22, the Lawful Access Act introduced in March 2026, includes a provision allowing law enforcement and CSIS to compel a telecommunications provider to confirm whether a person is a customer, on a standard of reasonable grounds to suspect rather than the higher reasonable grounds to believe. That distinction is real and is not unique to Carpay’s analysis. Legal commentators including the Canadian Bar Association and University of Ottawa law professor Michael Geist have raised the same concern about the lowered threshold.

Bill C-34, the Safe Social Media Act introduced in June 2026, would require age and identity verification for social media access and would establish a Digital Safety Commission with substantial enforcement powers.

It should be said plainly that this is an opinion column with a clear point of view, and that the government has defended these measures as necessary to align Canadian law enforcement capability with allied countries while preserving privacy safeguards. Bill C-22 in particular has drawn criticism from multiple directions, including from technology companies and civil liberties groups, and it remains subject to parliamentary debate.

The Practical Question for Business Owners

Set the political argument aside for a moment. The underlying trend is not really in dispute. More information about individuals is being collected, retained and made accessible than at any previous point, and the rules governing who can reach it are being rewritten.

If you run a business, a clinic, a firm or an office in Ontario, that trend has a direct consequence. You are holding information about your clients, your patients and your employees. Some of it you are legally required to keep. Much of it you are keeping simply because nobody decided to stop.

Every record you retain past its useful life is exposure. It can be breached. It can be subpoenaed. It can be stolen from a storage room. It can be found in a bin behind your building. The privacy of the people who trusted you with that information depends in part on how long you choose to hold it.

Retention Is a Privacy Decision

Most organizations think of records retention as a compliance chore. It is more useful to think of it as the most direct privacy protection you can offer the people you serve.

Consider what a typical small business file room contains. Photocopied driver’s licences and health cards. Employment records for people who left years ago. Client intake forms with social insurance numbers. Banking information from a payroll change made a decade back. Old tax documents well past the period the Canada Revenue Agency requires.

None of that is protected by any court decision or any statute if it ends up in the wrong hands. The protection you can actually provide is to not have it anymore.

This is the part of privacy that is entirely within your control. You cannot influence what Parliament passes. You can decide, this quarter, that the 2014 client files in the back room get destroyed.

Building a Defensible Retention Policy

Inventory what you hold. Most organizations underestimate this substantially. Check the storage room, the offsite unit, the filing cabinets nobody opens and the closet by the back door.

Set a retention period for every category. Tax, employment, health and legal records each carry their own statutory minimums. Establish the minimum you are required to keep and treat it as the maximum you should keep.

Destroy on a schedule. Records that reach the end of their retention period should be shredded as a matter of routine, not whenever someone gets around to it.

Secure records while you still have them. Locked collection consoles keep confidential paper out of open bins from the moment an employee is finished with it.

Cover digital media in the same policy. Hard drives, backup tapes, USB keys and retired photocopiers hold recoverable data long after anyone considers them active. Deleting and reformatting do not remove it. Physical destruction does.

Keep certificates of destruction. Documentation is what turns a good intention into a defensible position if you are ever audited, investigated or sued.

Protecting Privacy and the Planet

At Norfolk Shredding, secure destruction and environmental responsibility go together. Every sheet of paper we shred is baled and recycled into new paper products, so the information is permanently gone while the material itself gets another life.

Protecting your clients’ privacy should not mean sending truckloads of paper to landfill. It does not have to.

The Takeaway

Privacy law will keep changing, and reasonable people will keep disagreeing about where the balance between security and privacy belongs. That debate will play out in Parliament and in the courts regardless of what any individual business does.

What will not change is this. The information you no longer hold cannot be exposed, subpoenaed, breached or sold. In an environment where the rules keep moving, disciplined destruction is the one privacy protection that is entirely yours to enforce.

Protect Your Clients and Your Business With Norfolk Shredding

Norfolk Shredding provides secure, certified document destruction for businesses, medical practices, law firms, financial offices and residential clients across Ontario. We offer scheduled shredding, one time purges, hard drive and electronic media destruction, and a certificate of destruction with every service, with all shredded paper recycled.

Call us today at 1-855-561-1716 for a free consultation and find out how straightforward it is to bring your records retention under control.

Reference

Carpay, John. “Our privacy had decent protection until the Liberals stepped in.” National Post, July 27, 2026. Read the original article

danger alert

IF YOU NEED TO CANCEL OR POSTPONE SERVICE, WE REQUIRE
NOTICE 48 HOURS PRIOR TO YOUR SCHEDULED SERVICE DATE.

Back to top