Tuesday, 29 September 2026 PDT | 12:08 PM
The 1 News Alt Logo Text Smart News for Global Indians

Fasken’s Noteworthy News: Privacy & Cybersecurity in Canada, the US, and the EU (September 2026)

Canada September 29, 2026 11:02 PM
Canada

Fasken’s Noteworthy News: Privacy & Cybersecurity in Canada, the US, and the EU (September 2026)

Google News - Canada

This is a monthly bulletin published by the Privacy and Cybersecurity group at Fasken with noteworthy news and updates. If you have any questions about the items in this bulletin, please contact any member of the Privacy and Cybersecurity group, and we will be pleased to assist.

The Office of the Privacy Commissioner of Canada Publishes Guidance on Assessing Third-Party Service Providers

The Office of the Privacy Commissioner of Canada (OPC) has published new guidance for organizations subject to Personal Information Protection and Electronic Documentation Act (PIPEDA) on assessing third-party service providers before engaging them to handle personal information. The guidance emphasizes that organizations remain accountable for personal information under their control, including where it is collected, used, disclosed or processed by a third party, and should conduct privacy due diligence to identify compliance risks, inform contractual protections and demonstrate accountability. The OPC is accepting comments on the guidance until December 4, 2026.

CEST Report on Challenges Raised by Connected Vehicles

Connected vehicles generate vast amounts of data, creating important privacy, cybersecurity, and governance challenges. A study (in French only) by the Commission de l’éthique en science et en technologie (CEST) identified key concerns, such as privacy erosion with increased monitoring, workplace monitoring, cybersecurity risks, insurance profiling, law enforcement access to vehicle data, and national security issues. The study concludes that the current legal framework is not fully equipped to address these risks, citing limited industry transparency, shortcomings of consent-based privacy models, difficulties in applying data minimization principles, and the limited effectiveness of existing oversight mechanisms. It calls for stronger regulatory measures to govern connected vehicles and related data flows.

The OPC Files Federal Court Application in Search Engine De-Listing Investigation

The OPC announced that it has filed a notice of application with the Federal Court in connection with its investigation into search engine de-listing. The proceeding is expected to address important questions about the extent to which Canadian privacy law applies to search engines and requests to remove or de-index search results containing personal information. The case will be closely watched by organizations that publish, index or otherwise make personal information discoverable online.

Federal Privacy Commissioner Comments on Proposed Consumer-Driven Banking Regulations

The OPC has submitted comments to Finance Canada on the federal government’s proposed Consumer-Driven Banking Regulations. The OPC supports the proposed framework’s goals of enabling consumers to direct the secure sharing of their financial data and reducing reliance on screen scraping, while recommending stronger privacy protections around transparency, consent exceptions for publicly available data, and safeguards proportionate to the sensitivity of financial information.

BC Privacy Commissioner Publishes Guidance on Identity Theft in BC

The Office of the Information and Privacy Commissioner for British Columbia (OIPC) has released new guidance to help public bodies and private sector organizations prevent and respond to identity theft. The quick reference guide emphasizes that identity theft often follows from a privacy breach and outlines practical steps organizations can take to reduce risk, respond quickly when incidents occur, and support affected individuals. Key recommendations include implementing appropriate safeguards, maintaining a breach response protocol, assessing the risk of harm, notifying affected individuals where appropriate, and helping individuals take protective steps such as monitoring accounts or contacting relevant institutions.

BC Privacy Commissioner Publishes Best Practices on Use of AI

The OIPC has released guidance on the use of AI tools, including generative AI, when preparing submissions or complaints to the OIPC. The guidance recognizes that AI tools can help individuals organize information and draft materials, but cautions that they may produce inaccurate, incomplete or misleading content and may create privacy risks if personal information is entered into the tool. The OIPC encourages users to verify AI-generated content, avoid submitting confidential or unnecessary personal information to AI tools, and ensure that any submission remains accurate, relevant and based on the user’s own circumstances.

BC Privacy Commissioner Publishes Updated Guidance Documents on the Processes for PIPA and FIPPA

The OIPC has updated its process guides for matters under the Personal Information Protection Act and the Freedom of Information and Protection of Privacy Act. The updated guides outline how complaints, requests for review, investigations, mediations, inquiries, time extensions, and related procedural steps move through the OIPC. The changes are particularly relevant for organizations and public bodies responding to access requests or privacy complaints, as they provide more detailed guidance on procedural expectations, timelines, discontinuance, reconsideration and when the Commissioner may decline to investigate or review a matter.

Delaware Significantly Expands its State Privacy Law

On September 2, 2026, Delaware’s governor signed Bill HB 380, the most significant amendment to the Delaware Personal Data Privacy Act since its 2023 enactment. The amended law takes effect January 1, 2027. The amendment substantially lowers the law’s applicability thresholds (from 35,000 to 10,000 consumers generally) and, notably, creates a new trigger under which any third party that receives personal data from a covered controller becomes independently subject to the law regardless of volume.

Federal Trade Commission Targets Practices that Personalize Pricing Based on Personal Data

The Federal Trade Commission has issued a proposed enforcement policy statement on “personalized pricing,” which it describes as the use of personal data to set prices based on what a business believes an individual consumer is willing to pay. The proposed statement does not seek to ban personalized pricing outright but signals that businesses may face enforcement risk under Section 5 of the Federal Trade Commission Act (FTC) if they fail to clearly and conspicuously disclose that pricing is personalized, the basis for the personalization, and the types of personal data used. The FTC is seeking public comment on the proposed statement, with comments due September 25, 2026.

Rhode Island Introduces AI Scribe Disclosure Requirements

Rhode Island has become the first US state to require disclosure and opt-out procedures relating to AI medical scribes, underscoring growing regulatory focus on transparency where AI is used in healthcare settings. The Act took effect immediately upon passage on June 22, 2026, meaning that all covered healthcare providers and facilities must comply immediately.

New Model Rules Seek to Clarify Succession of Digital Assets and Data

As digital assets, online accounts, personal data and other forms of "digital remains" become increasingly important in estate planning and succession disputes, new Model Rules have been developed to address growing legal uncertainty in this area. The proposed framework aims to clarify who may access, manage and inherit a deceased person's digital assets and data, while safeguarding privacy, security and dignity. The Model Rules seek to harmonize approaches across Europe and would, if adopted into legislation, override conflicting service provider terms of service, providing greater certainty for individuals, heirs, legal professionals and technology companies navigating digital estates.

GDPR does not Apply to Deceased Individuals

In a decision (in French only) dated June 17, 2026, the French Conseil d’État (highest administrative authority) confirmed that General Data Protection Rights (GDPR) may only be exercised by the data subject and generally cease upon that person’s death, except where specific legal provisions allow actions related to estate administration or the handling of the death itself. The case involved a husband who challenged the processing and disclosure of his deceased wife’s health data by an insurance company and sought intervention from the French data protection authority (CNIL). The CNIL dismissed the complaint on the basis that the GDPR does not apply to the personal data of deceased individuals.

The Conseil d’État upheld that position, finding that the husband could not exercise his late wife’s data protection rights, did not qualify as a “data subject” in relation to her personal data, and therefore lacked standing to pursue the complaint before the CNIL.

CRA Provision in Force since September 11, 2026

Manufacturers have 24 hours to report any actively exploited vulnerability or serious incident affecting digital products sold in the EU through the designated reporting platform, the Single Reporting Platform. The Single Reporting Platform (SRP) is the online tool developed, operated and maintained by European Union Agency for Cybersecurity (ENISA) to enable manufacturers and, once applicable, open-source software stewards to meet their reporting obligations under the Cyber Resilience Act (CRA) for actively exploited vulnerabilities and severe incidents having an impact on the security of products with digital elements made available on the EU market.

The Fasken Privacy and Cybersecurity group recently published the following article, which might be of interest.

We are pleased to announce that 11 Fasken lawyers have been recognized in the 2027 edition of The Best Lawyers in Canada™ for their work in Privacy and Data Security Law.

View the full list of recognized lawyers.

Best Lawyers is a well-established peer-review publication that has identified leading legal professionals across jurisdictions and practice areas for over 30 years.

We are also proud to share that Fasken has been ranked Band 2 in the Chambers Canada 2027 Guide for Privacy and Data Protection.

Seven of our lawyers – Alex Cameron, Daniel Fabiano, Julie Uzan-Naulin, Daanish Samadmoten, Sam Delechantos, Soleïca Monnier and Nareg Froundjian – have also been individually recognized for their outstanding work in this area.

View the full Chambers Canada rankings.

Chambers is a leading legal directory that ranks law firms and lawyers based on in-depth research and client feedback across practice areas and jurisdictions.

As one of the longest-standing and leading practices in privacy and cybersecurity, our dedicated national privacy team of over 30 lawyers offers a wide range of services. From managing complex privacy issues and data breaches to advising on the EU General Data Protection Regulation and emerging legal regimes, we provide comprehensive legal advisory services and are trusted by clients from all sectors. Our group is recognized as a leader in the field, earning accolades such as the PICCASO ‘Privacy Team of the Year’ award and recognition from Chambers Canada, Canadian Legal Lexpert Directory, and Best Lawyers in Canada. For more information, please visit our website.