惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

U
Unit 42
Google DeepMind News
Google DeepMind News
Stack Overflow Blog
Stack Overflow Blog
H
Help Net Security
MongoDB | Blog
MongoDB | Blog
I
InfoQ
N
Netflix TechBlog - Medium
T
Tailwind CSS Blog
量子位
博客园 - 叶小钗
月光博客
月光博客
IT之家
IT之家
G
Google Developers Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
小众软件
小众软件
S
SegmentFault 最新的问题
Engineering at Meta
Engineering at Meta
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
aimingoo的专栏
aimingoo的专栏
云风的 BLOG
云风的 BLOG
Vercel News
Vercel News
爱范儿
爱范儿
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
宝玉的分享
宝玉的分享

MEDIANAMA

India in talks with US, Anthropic for Mythos access; no Indian firms in Project Glasswing yet Eternal Q4FY26: All Users Pay Higher Platform Fee, Only Some Get Discounts Amazon, Meta to challenge PhonePe-Google Pay dominance as UPI cap delayed since 2020 Meta failed to protect the safety of under-13s: European Commission If markets and regulators are ready for network slicing, we are ready: JIO Why defining ‘news’ won’t fix the free speech problems of draft IT Rules? #NAMA Eternal Q4FY26: Goyal Dismisses AI Disruption Risk as Zomato Quietly Builds Agentic Commerce Infrastructure Karnataka files appeal challenging the bike taxi ban lift in the Supreme Court How did WhatsApp turn 17 govt. flags into 9,400 digital arrest scam bans? Google Wallet integrates Aadhaar as digital ID, expands India’s mobile identity ecosystem Kerala HC issues notice on MediaOne’s Facebook page block in India MeitY warns VPN providers against enabling access to blocked betting platforms Shreya Singhal targeted private censorship. Today’s threat is the State #NAMA Amazon scales its quick delivery service ‘Amazon Now’ in 100 cities Can MeitY issue binding rules via advisories? Experts raise alarm over draft IT Rules #NAMA How 2019 election code of ethics became India’s three-hour content takedown mandate #NAMA Australia proposes new levy on big tech to fund news, opens draft law for consultation ‘judge, jury, executioner’: experts warn of Inter-Departmental Committee (IDC) overreach under New draft IT Rules Lowdown: TRAI flags low deployment under PM-WANI in public Wi-Fi consultation paper Why the NBFC licence matters for MobiKwik China blocks Meta-Manus deal, asserts origin-country jurisdiction: what this means for India ‘No transparency’: experts warn of expanding powers to block online speech in India #NAMA X launches standalone iOS messaging app XChat with encryption in India How India’s content takedown framework was built and where It has gone wrong #NAMA Claude Mythos puts India on alert: CERT-In, telcos, banks assess unprecedented cyber risks Explained: why did the RBI cancel Paytm’s banking licence? Meta now instantly blocks content in India Govt. asks ZEE5 to halt ‘Lawrence of Punjab’ web series release Online Gaming Rules notified, to be in effect from May 1, what are the major changes? RBI mandates additional factor authentication for e-mandates
Explainer: What Canada’s Safe Social Media Act means for ...
Aakriti Bansal · 2026-06-11 · via MEDIANAMA

The bill can be accessed here.

Canada tabled Bill C-34 at first reading on June 10, 2026, proposing two laws in one omnibus bill: the Digital Safety Act (DSA) and the Digital Safety Commission of Canada Act (DSCC Act).

The bill regulates social media platforms, AI chatbots, and other online services in Canada and establishes a new regulator, the DSCC, to enforce the regulations. Penalties reach the greater of about US$7.2 million (C$10 million) or 3% of global revenue. The bill sits at first reading and has not passed.

What the bill covers: Bill C-34 regulates three service types, each above a user count that regulators will set later:

  • Regulated social media services carry the heaviest obligations.
  • Regulated chatbot services are artificial intelligence (AI) systems that use a natural language interface, can simulate sustained human-like relationships, and generate non-predetermined responses.
  • Regulated online services are other sites or apps that the Governor in Council flags as posing a significant risk to children.

What it excludes:

  • Telecoms that provide only basic internet connectivity.
  • Private messaging features on any platform.
  • Search engines, navigation tools, and e-commerce listings.
  • Proactive content scanning, which platforms need not do, though regulators may require technology that blocks child sexual abuse material uploads.

What all operators must do: Every regulated service must build in child-protection design features, verify or estimate users’ ages when it serves pornographic content, and maintain compliance records.

What social media platforms must do:

  • Cut the risk that users encounter any of the seven harmful content categories, which are described later
  • Block under-16s from holding accounts on services regulators specify, unless the DSCC grants an exemption for adequate child-protection safeguards
  • Give users tools to block others and flag harmful content
  • Label synthetic content, and label harmful content that bots amplify
  • Provide a resource person for user concerns
  • Preserve violent or terrorist content for one year after it is removed

What chatbot services must do: Chatbot operators must cut the risk that the bot sends harmful content, interrupt the chat and steer users to human crisis help when a user voices suicidal thoughts or an intent to self-harm, and curb four named behaviours: posing as a human, posing as a licensed professional, using manipulative techniques that build emotional dependency, and encouraging self-harm or suicide.

The seven harmful content categories:

  • Intimate content shared without consent,
  • Content that sexually victimises a child or revictimises a survivor,
  • Content that pushes a child toward self-harm, including disordered eating and suicide content,
  • Content that bullies a child,
  • Content that foments hatred,
  • Content that incites violence,
  • Terrorism or violent extremism content.

Two carve-outs apply. The hate definition spares content that merely offends, discredits, or humiliates. The child sexual abuse and terrorism definitions spare material that serves a legitimate purpose, such as journalism, art, education, medicine, science, or justice, where it poses no undue risk to children.

What a digital safety plan must contain: Platforms must file and publish a digital safety plan with the DSCC. The plan must cover:

  • Risk assessments and mitigation measures, with effectiveness indicators,
  • The volume and type of harmful content the platform moderated,
  • User flags the platform received and acted on,
  • Synthetic content labelling,
  • Compliance resourcing, including automated decision-making,
  • Any law enforcement notifications.

Operators may strip trade secrets, confidential commercial information, and the underlying data inventory from the public version.

What the DSCC is and how it works: The DSCC is a new federal body of three to five full-time members, appointed for renewable terms of up to five years, and led by a Chairperson who holds deputy-head status. Its mandate covers:

  • Enforcing the DSA,
  • Investigating complaints about child sexual exploitation content and non-consensual intimate imagery,
  • Issuing guidelines and regulations,
  • Accrediting researchers to access the platform data.

The DSCC must consult the Privacy Commissioner before issuing age-verification guidelines and coordinate with the Canadian Radio-television and Telecommunications Commission (CRTC) and the Royal Canadian Mounted Police (RCMP).

How complaints work: Any person in Canada can flag harmful content or a chatbot’s harmful behaviour to the DSCC. For child sexual abuse material and non-consensual intimate imagery, a person can file a formal complaint, but only after they exhaust the platform’s own process first. If the DSCC does not dismiss the complaint, it must order the platform to hide the content while it investigates, then order permanent removal if it finds reasonable grounds.

How researchers get platform data: The DSCC can accredit researchers and educators whose work serves the act’s purposes. Once accredited, they can read the data inventories in the platforms’ safety plans, and the DSCC can order a platform to hand over the underlying data itself, under confidentiality, security, and privacy conditions. If a platform violates that order, the researcher can file a complaint with the DSCC. The Commission can publish the names of accredited researchers and the projects it has cleared.

How the DSCC enforces compliance: The Commission holds wide investigative powers. It can summon witnesses, compel evidence, and name inspectors who, under a warrant, can enter premises (including remotely), copy data, and demand assistance. It can order an operator to take or stop an action and register that order with the Federal Court.

The penalty process proceeds through notices of violation, and an operator can instead make representations, pay the penalty, or sign a binding undertaking. The Commission can name violators publicly and publish their undertakings.

Protections built into the bill: Two confidentiality protections stand out. An employee who files a submission can ask the DSCC to shield their identity, and unauthorised disclosure carries criminal penalties. Separately, when the DSCC receives a user’s chatbot inputs and the bot’s replies, it treats them as confidential if the operator and user agreed to keep them private, a notable safeguard given how much of the bill targets chatbots. Operators can also flag trade secrets and confidential commercial information, which the Commission must protect.

What the penalties are:

  • Administrative: the greater of about US$7.2 million (C$10 million) or 3% of global revenue.
  • Criminal, on indictment: the greater of about US$14.4 million (C$20 million) or 5% of global revenue.
  • Criminal, on summary conviction: the greater of about US$10.8 million (C$15 million) or 4% of global revenue.

The bill bars jail time for unpaid fines and says penalties aim to drive compliance, not to punish.

What the bill leaves undecided: Bill C-34 sets up the structure but leaves key specifics to regulations that cabinet and the DSCC will write later, so even after it passes, some basic questions stay open:

  • Which platforms are covered? The rules apply only above a user-count threshold, but the bill never sets that number.
  • What “child-protection design features” must platforms build in? The bill requires them, but does not describe them.
  • How must platforms verify age? The bill mandates age checks but leaves the acceptable methods to regulation.
  • Which online services beyond social media and chatbots must comply? This third bucket only fills once the cabinet designates categories.

How this fits the global age-verification wave: Canada’s under-16 account rule joins a fast-moving global push to keep younger children off social media. Australia implemented the world’s first under-16 ban in December 2025, and VPN downloads surged as the codes took effect. France voted for an under-15 ban, while Spain and Indonesia moved on similar measures.

Canada’s bill leans toward a duties-and-design model over a blanket cutoff, placing it among a smaller set of design-first approaches. University of Ottawa law professor Michael Geist called the volume of decisions left to cabinet and the future commission “astonishing,” predicting the law will take years to implement.

Why this matters for India: India is debating its own version of this question. Several states moved first:

  • Karnataka proposed an under-16 ban.
  • Andhra Pradesh proposed an under-13 ban.
  • Goa is examining similar measures.

Legal experts question whether states hold jurisdiction over internet policy. The central government is reportedly preparing a graded national framework with three age brackets (8-12, 12-16, 16-18) rather than a single ban. The Internet Freedom Foundation (IFF) calls such restrictions disproportionate, warning they ignore engagement-maximising platform design and risk deepening India’s digital gender divide.

Canada’s chatbot duties, its researcher data-access regime, and its privacy-aligned age verification all raise questions India’s framework has yet to resolve.

Also read: