Political News

The Price of Duty: Privacy Act Modernization and Treasury Exposure

By Sally Steele | 2026-08-06 15:33:50
The Price of Duty: Privacy Act Modernization and Treasury Exposure
Privacy Commissioner Philippe Dufresne

🔍 FORENSIC DISPATCH KEY TAKEAWAYS

  • The Statutory Shift: Privacy Commissioner Philippe Dufresne's submission to Treasury Board President Shafqat Ali proposes codifying privacy impact assessments and breach reporting directly into the Privacy Act, replacing internal executive discretion with mandatory legal duties.
  • Internal Control Collision: Elevating privacy safeguards to statutory mandates directly conflicts with the Treasury Board's core authority under Section 7 of the Financial Administration Act to maintain central expenditure control and protect the public purse.
  • The Compliance Multiplier: Transforming administrative directives into rigid statutory hurdles will drive exponential compliance overhead across federal IT procurements, compounding multi-billion-dollar infrastructure modernizations.

The Treasury Board of Canada Secretariat spent $880,114 on salaries alone in the 2023 to 2024 fiscal year just to administer its own internal Privacy Act obligations. That figure represents the administrative baseline for a single federal department operating under the current, flexible regulatory framework. On August 6, 2026, Privacy Commissioner Philippe Dufresne submitted a formal proposal to Treasury Board President Shafqat Ali that would dismantle that flexibility. Dufresne is demanding the government introduce a legislative requirement for federal institutions to conduct privacy impact assessments for high-risk activities. He further proposes making the management, notification, and reporting of privacy breaches a legal obligation under the law.

The difference between an administrative directive and a statutory obligation is the difference between a managed internal risk and unlimited external liability. By pushing these operational requirements into the text of the Privacy Act itself, the Commissioner is asking the federal government to weaponize its own legislative architecture against the public treasury. The predictable mathematical outcome is a structural multiplication of compliance costs across every federal information technology procurement, paired with an unquantifiable legal exposure for the Crown.

The Statutory Shift

The federal government’s current privacy apparatus relies heavily on executive discretion. Privacy impact assessments are governed by the Treasury Board Directive on Privacy Practices. This is an internal administrative policy, not a law. A Justice Canada policy paper analyzing the modernization of the privacy framework confirms the reality of this dynamic, noting that the application of this policy requirement "does not have force of law." The paper explicitly outlines the current liability structure, stating that "accountability for decisions on the appropriate level of mitigation for privacy risk, and acceptance of any residual risk, lies solely with the institutions."

This administrative structure gives the executive branch the operational flexibility to balance privacy safeguards against deployment speed, operational necessity, and fiscal constraints. If a department needs to rapidly deploy a new digital service to administer emergency benefits or streamline border processing, the Treasury Board can weigh the privacy risks against the immediate public interest and authorize the deployment.

The government's stated rationale for overhauling this system is to build a modern and effective compliance framework. According to the Justice Canada analysis and the Privacy Commissioner's submission, modernizing the Privacy Act requires enhanced enforcement mechanisms and greater transparency, specifically regarding the deployment of automated decision systems. By codifying privacy impact assessments into the Privacy Act, the government seeks to reassure the public that their data is protected by the force of law rather than internal bureaucratic discretion.

Transforming a policy tool into a legislative mandate alters the fundamental nature of the state's liability. A directive can be waived, amended, or temporarily bypassed by the executive when national interests or severe fiscal realities demand it. A statutory requirement cannot be waived. Once enshrined in legislation, a privacy impact assessment ceases to be a flexible management exercise and becomes a rigid legal prerequisite for technological deployment. The process of assessing data flows, identifying risks, and implementing mitigation strategies will be subject to judicial review rather than internal executive approval.

Internal Control Collision

This legislative push creates a direct and structural conflict with the foundational architecture of federal financial management. Under the Financial Administration Act, RSC 1985, c F-11, Section 7, the Treasury Board is granted explicit authority over "financial management, including estimates, expenditures, financial commitments, accounts, fees or charges for the provision of services". This statutory mandate requires the Treasury Board to act as the primary guardian of the public purse, mitigating the Crown's fiscal risk and ensuring that federal expenditures are strictly controlled.

When the Privacy Commissioner pressures the Treasury Board to surrender administrative control over privacy breaches and impact assessments, he is asking the Board to violate its core mandate. An internal control collision occurs when a specialized commissioner demands statutory independence that overrides the central financial authority of the state.

If Shafqat Ali accepts these recommendations, the Treasury Board will legally bind itself to a framework where privacy compliance supersedes expenditure control. Every federal department deploying new digital infrastructure will be forced to subordinate their procurement timelines and operational budgets to the statutory approval of privacy officers. The Treasury Board will lose its ability to cap the financial bleeding on delayed software projects because the delays will be mandated by the Privacy Act. The financial management authority granted by the Financial Administration Act will be functionally subordinated to the privacy requirements demanded by the modernized legislation.

The Compliance Multiplier

The $880,114 spent by the Treasury Board Secretariat on Privacy Act administration is a warning metric. The Secretariat is a central agency; it does not process the mass volume of citizen data handled by the Canada Revenue Agency or Employment and Social Development Canada. If a legislative requirement forces mandatory privacy impact assessments for all high-risk activities, the administrative overhead will scale exponentially across the government's entire operational footprint.

Framework Dimension Administrative Policy (Current) Statutory Requirement (Proposed)
Governing Instrument Treasury Board Directive on Privacy Practices Modernized Privacy Act (Statutory Mandate)
Enforcement Mechanics Internal Executive Discretion & Treasury Board Oversight Judicial Review & Statutory Compliance Audits
Privacy Impact Assessments Flexible, risk-proportional internal approval process Mandatory legal prerequisite prior to system deployment
Breach Reporting Administrative protocol & internal mitigation Binding legal duty creating direct Crown liability
Procurement Impact Managed timelines & internal risk acceptance Permanent structural cost overruns & supplier risk pricing

High-risk activities in the current public sector invariably involve automated decision systems, cloud infrastructure migrations, and cross-departmental data sharing networks. Writing a privacy impact assessment for a modern automated system requires specialized legal, technical, and privacy personnel. The compliance burden will not be limited to the salaries of federal employees. External contractors, software vendors, and system integrators will immediately bake the cost of these statutory impact assessments into their procurement bids.

To understand the scale of this multiplier, the baseline cost of modernizing federal digital infrastructure must be quantified. According to the Office of the Auditor General's 2023 performance audit, Employment and Social Development Canada’s Benefits Delivery Modernization Programme—a project designed to migrate Old Age Security and other core benefits to a new IT platform—carried an initial cost estimate of $1.75 billion before experiencing widespread cost increases. Subsequent government projections place the total estimated cost of the modernization program at $6.6 billion over its 10-year lifecycle.

That $6.6 billion represents the cost of deploying a massive digital system under the current, flexible administrative rules. Under the present Treasury Board Directive on Privacy Practices, the department conducts an internal assessment, accepts the residual risk, and begins processing applications to clear backlogs. If this process is made a statutory requirement, the department cannot legally deploy the system until a comprehensive impact assessment is finalized, submitted, and potentially audited by the Privacy Commissioner's expanded mandate. During that delay, the state continues to pay legacy operational costs while funding the development of the delayed system.

Furthermore, the government’s reliance on third-party cloud service providers means that the statutory burden will flow down the supply chain. When federal departments negotiate service level agreements with major technology vendors, the vendors will price the legal risk of statutory breach notification into their contracts. The Crown will pay a premium for software simply because the Privacy Act makes the Crown a higher-risk client. The federal government already struggles to deploy commercial software within initial budget estimates. Introducing a rigid legal requirement for privacy assessments prior to deployment guarantees that structural cost overruns will become a permanent, unavoidable feature of federal procurement. The math is straightforward. When a process that currently does not have the force of law is granted that force, the bureaucracy must expand to manage the resulting legal peril.

Directional Risk Analysis

The most severe fiscal threat embedded in the Commissioner's submission lies in the demand to make the management, notification, and reporting of privacy breaches a legal obligation under the law. Currently, the Crown relies on the absence of a strict, overarching statutory duty to defend itself against class-action lawsuits following mass data breaches. If breach notification and specific safeguard management are codified in the Privacy Act, any failure to perfectly execute those duties constitutes a direct breach of statutory duty.

This provides plaintiffs with a clear, legislated pathway to sue the federal government. The directional risk of this policy is entirely asymmetric. The Crown assumes all the financial liability, while the regulatory burden prevents the executive from moving nimbly to fix network vulnerabilities. If discretionary executive power is constrained by a modernized Privacy Act, the government loses the ability to triage data breaches internally or manage the fallout through administrative channels.

When a data breach occurs, the plaintiffs will not need to prove negligence in a vacuum; they will simply point to the government's failure to meet its own modernized statutory obligations. The reporting timelines and safeguard mandates demanded by the Privacy Commissioner will act as a checklist for class-action certification. Every cyber incident and data spill will immediately trigger a statutory violation. Every violation will serve as the foundation for litigation.

Existing legal constraints, such as the Crown Liability and Proceedings Act, offer defensive shielding for the treasury, but elevating privacy management to an explicit statutory duty pierces that shield. The courts will interpret the modernized Privacy Act as parliament's explicit intention to hold the Crown legally and financially accountable for digital safeguard failures.

The structural risk extends beyond litigation payouts. If the courts determine that the Crown has a statutory duty to notify individuals of breaches within a legally mandated timeframe, the technical infrastructure required to detect, isolate, and report those breaches must be built and maintained at an immense cost. The treasury will be hit twice: first by the capital expenditure required to build the statutory reporting apparatus, and second by the legal judgments when that apparatus inevitably fails to prevent a breach.

The inevitable outcome is a failure of guardianship over the Consolidated Revenue Fund. By trading the flexibility of the Treasury Board Directive on Privacy Practices for the rigid enforcement of a modernized Privacy Act, the government will expose the treasury to continuous, unquantifiable legal settlements. The demand for fundamental privacy rights will be paid for by structurally surrendering the state's financial defenses.

Sally Steele

Sally Steele

Senior Policy Analyst

Sally specializes in legislative forensics and federal transparency. She provides data-driven breakdowns of parliamentary policy, translating dense economic reports and budgetary jargon into accessible information. Her work focuses on providing the objective evidence and technical facts required to navigate the mechanics of Canadian governance.

Submit Classified Intel

Possess verifiable data, a strategic leak, or a correction regarding this dispatch? Transmit your intelligence directly to the analyst.

SECURE DROP: sally@tgwr.ca
[+] Encrypted with Proton Mail
Transmit Secure Link

Continue Reading

Dispatch

Canada Negotiates Tariff Relief Before Aug. 19 Deadline

Grant Sterling
2026-08-08 14:03:58
News

The Government of Canada is actively engaged in trade negotiations with the United States...

Read Full Report →
Dispatch

Ottawa’s Strike-Breaking Loophole Needs a Sledgehammer

Harry Featherstone
2026-08-05 16:57:41
Commentary

When federal politicians talk about protecting working families, they usually do it in fro...

Read Full Report →