Implications of Bill C-34, Canada’s proposed online safety framework, for organizations

This Insight was prepared with the assistance of Summer Law Students Mia Flett and Zoë Goetz.
This post is part of our ongoing coverage of Canada’s shifting privacy, online safety and AI landscape. For related reading, see our past Insights on Bill C-36, Canada’s proposed private-sector privacy overhaul and on the growing regulatory focus on minors online.
On June 10, 2026, the Government of Canada introduced Bill C-34, the Safe Social Media Act, which would enact the Digital Safety Act (the DSA or the Act) and the Digital Safety Commission of Canada Act, as well as make consequential amendments to other Federal legislation. The DSA would set out new duties for organizations that operate regulated social media, AI chatbot and other online services. Regulated social media services (RSMS), for example, are required to implement measures and tools which allow users to block, flag harmful content and have access to a resource person. A RSMS must also accurately flag synthetic content on the service to differentiate electronic or mechanical audio and visual representations from authentic audio and visual representations.
The Digital Safety Commission of Canada Act would create the regulator responsible for administering and enforcing those duties.
Bill C-34 responds to the rapid growth of digital and AI-driven services, including AI chatbots that interact directly and persistently with users, and aims to improve online safety, reduce the harms caused by harmful content online – particularly harms to children – and hold digital services accountable for the risks their services create. Organizations that operate or rely on social media services, AI chatbots or other interactive online services should consider whether Bill C-34 might apply to them and what it may mean for their operations.
Important note: Bill C-34 received first reading on June 10, 2026, and has since moved to second reading. It must still pass through the full legislative process before becoming law, and much of its practical scope will not be settled until draft regulations are released. The provisions discussed below reflect the Bill as introduced and may be subject to amendment.
Who Bill C-34 would apply to
The enacted DSA would impose duties on operators of three categories of “regulated services”:
- Social media services – Including user-uploaded livestreaming services and adult content services.
- AI-powered chatbot services – Which the Act treats as a distinct statutory category with tailored duties.
- Certain other online services – Websites or applications, other than social media and chatbot services, that allow users to interact with them.
A service generally becomes “regulated” when it falls within one of these defined service types and either meets a user-number threshold set by regulation or is designated by the Governor in Council. Because that threshold has not yet been set, no organization can say with certainty today whether it will be captured. The chatbot category deserves particular attention: Bill C-34 would be one of the first Canadian laws to impose safety duties directly on the operators of AI chatbot services, treating conversational AI as its own class of regulated service with tailored obligations. Notably, the Act defines a “chatbot service” without appearing to include a standalone definition of “artificial intelligence system.”
Key duties and how they differ by service type
All operators of regulated services, whether through chatbot services or general social media services, would be subject to two baseline duties:
- A duty to protect children – Including safety-by-design and age-appropriate design features, as well as age measures directed at limiting children’s exposure to pornographic content
- A duty to be transparent – Including keeping records of compliance and publishing a digital safety plan in an accessible, easy-to-read format.
Operators of social media services would face additional obligations. Where a regulated social media service is designated by regulation as subject to minimum age requirements, the operator would need “adequate” age-verification or age-estimation measures designed to prevent persons under 16 from having or being registered for an account, unless the Commission grants an exemption on the basis that the operator maintains sufficient safeguards for the protection of children.
The Act targets seven categories of harmful content and would require both social media and chatbot operators to mitigate the risk that users are exposed to that content. Social media operators would also face a duty to make non-consensually distributed intimate images (NCDII) and child sexual abuse material (CSAM) inaccessible, with reports of such content to be addressed on a 24-hour timeline. Chatbot operators would be subject to a tailored duty to act responsibly, which includes mitigating the risk of communicating harmful content, ensuring intervention in crisis situations such as where a user expresses suicidal ideation or an intention to self-harm and mitigating the risk that the chatbot itself engages in harmful behaviour, such as posing as a human or as a licensed professional.
Enforcement mechanisms and penalties
These duties would be backed by the Digital Safety Commission of Canada, an independent regulator with substantial investigatory and enforcement powers, including the ability to summon witnesses, require the production of records, designate inspectors, hold hearings and issue compliance orders that could be enforced as orders of the Federal Court. Non-compliance could attract administrative monetary penalties of up to the greater of 3% of gross global revenue or $10 million.
Certain forms of non-compliance would also be offences, carrying fines of up to the greater of 5% of gross global revenue or $20 million on conviction on indictment and the greater of 4% or $15 million on summary conviction. This may be particularly significant for multinational organizations. Even organizations with a relatively limited Canadian presence could face substantial penalties, with larger organizations potentially facing fines that far exceed the Act’s fixed dollar amount.
Both streams are subject to a due diligence defence, and where an operator belongs to an affiliated group, gross global revenue would be measured across the group. Several features matter in particular for privacy and IP counsel:
- The age-assurance regime raises real privacy questions for the tens of millions of users who would have to be assessed
- The obligations to label synthetic content and content that has been artificially amplified intersect with emerging AI governance expectations
- A researcher access regime would allow the Commission to order operators to give accredited researchers access to the electronic data inventories behind their digital safety plans
The Bill also acknowledges the tension between online safety and free expression, requiring that measures not “unreasonably limit expression.” Organizations should also note that Bill C-36, the government’s proposed private-sector privacy overhaul, would give this same Commission privacy oversight responsibilities and rename it the Digital Safety and Data Protection Commission of Canada, meaning a single regulator would oversee both online safety and private-sector privacy.
Preparing for the Digital Safety Act
While Bill C-34 must still proceed through the legislative process and the regulations that will define much of its reach have not yet been drafted, organizations would be well-served to begin preparing now. Many of the steps below reflect good governance practice regardless of whether Bill C-34 is enacted in its current form:
- Assess whether your service is captured – Evaluate whether your offerings fall within the regulated social media, chatbot or online service definitions and whether you are likely to meet a user-number threshold set by regulation or be designated by the Governor in Council.
- Map your data and age-assurance practices – Identify what personal information age-verification or age-estimation would require, and work through the data-minimization, retention, accuracy, destruction and security questions that follow. Note that Bill C-36 would treat children’s personal information and biometric information as sensitive, which raises the bar for how any age-assurance data is handled.
- Build toward a digital safety plan – Since operators would have to publish plans describing risks, mitigation measures and the electronic data inventories behind them, begin identifying the information and internal records such a plan would require.
- Review your AI governance and labelling practices – If you deploy chatbots or generative features, revisit crisis-intervention protocols, human-impersonation safeguards and synthetic-content labelling against the Act’s proposed standards, together with the automated decision system transparency obligations proposed under Bill C-36.
- Monitor the regulations, not just the Bill – Because the Bill leaves a large number of key decisions to Cabinet and to a Commission that does not yet exist, tracking consultations and draft regulations will tell you more than tracking the Bill’s progress through Parliament.
- Audit vendor and customer contracts – If you embed third-party chatbots or online services in your own offerings, confirm who would bear compliance responsibility and whether your agreements give you the audit rights, records access, incident notification and indemnities you would need if a vendor were captured by the regime.
Key takeaways
Given the size of the potential penalties and the breadth of the Commission’s powers, the cost of early preparation is modest compared to the compliance and reputational risk of being caught unprepared once the regime takes shape. Bill C-34 and Bill C-36 are also best read together: The same Commission would oversee both regimes, and many of the steps above serve compliance under each.
We will continue to monitor Bill C-34 as it moves through the legislative process and will provide updates on any significant amendments or developments. In the meantime, if you have questions about how the proposed legislation may affect your organization’s products, data practices, vendor arrangements or compliance posture, please contact a member of our Privacy, Data Protection and Cybersecurity group. Early preparation is the best way to ensure your organization is ready to meet its obligations if and when the Digital Safety Act comes into force.
Note: This article is of a general nature only and is not exhaustive of all possible legal rights or remedies. In addition, laws may change over time and should be interpreted only in the context of particular circumstances such that these materials are not intended to be relied upon or taken as legal advice or opinion. Readers should consult a legal professional for specific advice in any particular situation.



