惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
雷峰网
雷峰网
博客园 - 叶小钗
C
Check Point Blog
F
Fortinet All Blogs
A
About on SuperTechFans
Y
Y Combinator Blog
Vercel News
Vercel News
IT之家
IT之家
V
V2EX
T
Tailwind CSS Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
The GitHub Blog
The GitHub Blog
Jina AI
Jina AI
Blog — PlanetScale
Blog — PlanetScale
罗磊的独立博客
云风的 BLOG
云风的 BLOG
U
Unit 42
博客园_首页
量子位
M
MIT News - Artificial intelligence
G
Google Developers Blog
小众软件
小众软件
N
Netflix TechBlog - Medium
P
Palo Alto Networks Blog
S
Schneier on Security
T
Tor Project blog
F
Full Disclosure
C
Cyber Attacks, Cyber Crime and Cyber Security
T
Tenable Blog
T
The Blog of Author Tim Ferriss
Spread Privacy
Spread Privacy
Engineering at Meta
Engineering at Meta
GbyAI
GbyAI
Microsoft Azure Blog
Microsoft Azure Blog
Google DeepMind News
Google DeepMind News
T
Threat Research - Cisco Blogs
Know Your Adversary
Know Your Adversary
P
Proofpoint News Feed
Security Latest
Security Latest
D
Darknet – Hacking Tools, Hacker News & Cyber Security
博客园 - 司徒正美
AWS News Blog
AWS News Blog
Simon Willison's Weblog
Simon Willison's Weblog
Recorded Future
Recorded Future
L
Lohrmann on Cybersecurity
I
Intezer
L
LangChain Blog
L
LINUX DO - 热门话题

Privacy & Cybersecurity Law Blog

New Jersey Adopts New Data Broker Registration Regime and Sensitive Data Sale and Licensing Restrictions CISA Plans to Finalize Cyber Incident Reporting Regulations in September 2026 Illinois Governor Signs Frontier AI Model Law New Hampshire Amends the NHDPA to Prohibit the Sale of Children’s Personal Data European Commission Unveils Cybersecurity and AI Action Plan European Commission Refers Four Member States to CJEU Over NIS2 Transposition Delays EDPB Opens Public Consultation on New Personal Data Breach Notification Template European Commission Advances New Proposal to Expand Cloud Capacity and AI Infrastructure U.S. Supreme Court FTC Ruling Prompts Fresh Scrutiny of EU-U.S. Data Privacy Framework China Issues New Measures for Network Data Security Risk Assessment China Issues Regulations on Internet Content Multi-Channel Network Distribution Services China’s First Regulatory Framework for Virtual Companions Soon to Take Effect UK Data Protection Complaints Obligations Take Effect Vermont Enacts Significant Amendments to Data Broker Legislation Vermont Becomes 23rd State with Comprehensive Consumer Privacy Law Louisiana Enacts Comprehensive Consumer Privacy Law Connecticut Signs Comprehensive AI Bill into Law China CAC Issues Guidance on Conducting Audits Technology Companies Should Prepare for FTC Enforcement of Take It Down Act HHS Reorganizes Office for Civil Rights Oregon Prohibition on Public Body Disclosures to Data Brokers for Federal Immigration Purposes Now In Effect Connecticut Privacy Law Updates: Data Broker Rules, Geolocation Sale Ban, Surveillance Pricing Restrictions, and Genetic Data Regulations NYDFS Warns of Cybersecurity Risks from Frontier AI Models UK and Australia Announce Memorandum of Understanding on AI Security FTC Announces Settlements With Three Marketing Firms Over Allegations of Deceptive Statements About Active Listening AI-Powered Services Cybersecurity Authorities Issue Joint Guidance on the Adoption of Agentic AI Systems Colorado AI Act Amended and Effective Date Delayed European Commission Releases Draft Guidelines on High-Risk AI Under the EU AI Act Texas AG Announces Lawsuit Against Netflix for Alleged Misrepresentations Regarding User Data UK ICO Recommends Targeted Changes to PECR Rules for Online Advertising California AG Announces Record $12.75M Settlement with GM over CCPA Data Minimization and Purpose Limitation Violations Illinois Department of Human Rights Issues Regulations Governing the Use of AI in Employment Decisions Delta Dental Agrees to $2.25 Million Settlement with NYDFS Over MOVEit Data Breach Response Maryland Enacts First-of-its-Kind Ban on Surveillance Pricing for Grocery Sales UK ICO Publishes Guidance on Storage and Access Technologies CIPL Report Discusses Significant Alignment between GDPR and Global CBPR CalPrivacy Announces the Agenda for its April 30–May 1 Board Meeting CalPrivacy Requests Preliminary Comments on Notices & Disclosures, Employee Data COPPA Rule Amendment Compliance Deadline Approaches House Republicans Introduce Comprehensive Federal Privacy Bill: “SECURE Data Act” Kentucky Classifies Smart TV Data as Sensitive Alabama Becomes 21st State With Comprehensive Consumer Privacy Law CalPrivacy Director Expects CCPA Compliance Audits in 2026 Virginia Bans Sale of Geolocation Data HHS’ Office for Civil Rights Settles HIPAA Investigation of Health Care Software Company New Jersey Enacts New Restrictions on Health Care Facilities’ Use of Patient Data Washington State Enacts Law Regulating AI Companion Chatbots with Private Right of Action Guardrails for Legal AI: What California’s SB 574 Would Require of Attorneys and Arbitrators
Canada’s Proposed Social Media Ban for Children and Chatbot Regulation: Bill C-34’s Impact on Platforms
2026-07-14 · via Privacy & Cybersecurity Law Blog

Canada’s Proposed Social Media Ban for Children and Chatbot Regulation: Bill C-34’s Impact on Platforms

John Salloum and Maryna Polataiko from Osler, Hoskin & Harcourt LLP report that Canada is contemplating a social media ban for children under 16—among other measures—through a new online safety regime that takes aim at harmful material, platform accountability and synthetic content.

Bill C-34, the Safe Social Media Act, was introduced on June 10, 2026, and would create two new statutes: the Digital Safety Act (the “DSA” or the “Act”) and the Digital Safety Commission of Canada Act. If passed, Bill C-34 would establish a comprehensive legal framework intended to govern online safety, reduce harms from online content and establish transparency and accountability requirements for operators of regulated services such as social media sites, chatbots and other online services.

Regulated Social Media, Chatbot and Online Services

The Act's duties apply to three types of “regulated services.” A service is generally regulated when it falls within a defined service type and either meets a user number threshold set by regulation or is designated as regulated by the Governor in Council.

  • Social Media Services. Social media services are websites or applications whose primary purpose is to facilitate communication among users by enabling them to access and share content. These include adult content and live streaming services. Duties under the Act do not apply to private messaging features on social media services.
  • Chatbot Services. Chatbot services are AI systems that (i) communicate over the internet; (ii) are publicly accessible via websites or applications; (iii) use natural language interfaces to provide adaptive, human-like responses in a conversational format; (iv) can simulate sustained human-like relationships through multiple interactions or sessions; and (v) generate content or responses that are not fully predetermined by system developers or operators. These do not include AI systems that exclusively serve purposes specified in the regulations.
  • Online Services. Online services are websites or applications other than social media or chatbot services that allow users to interact with them, excluding those whose primary purpose is the sale or advertisement of goods or services, or directories, search results, maps or navigation tools. Online services must first fall within a category established by the Governor in Council to be regulated. Duties under the Act do not apply to private messaging features on online services.

Telecommunications service providers offering basic internet connectivity would be exempt from duties under the Act.

The Act would not require operators to proactively search for harmful content, though regulations may require technological means to prevent child sexual abuse material (“CSAM”) from being uploaded.

Regulated Content

The Act would target seven categories of harmful content: Non‑consensual disclosure of intimate images (“NCDII”), CSAM, content that induces a child to harm themselves, content used to bully a child, content that foments hatred, content that incites violence, and terrorism or violent extremism content. It would also establish requirements specific to pornographic content and synthetic content.

Duties of Operators

The DSA would impose two baseline duties on all operators of regulated services: a duty to protect children, including safety-by-design features and — where an operator has “reasonable grounds” to suspect its service provides access to pornographic content —age verification or estimation measures to mitigate the risk of persons under 18 being exposed to such content, as well as a duty to be transparent through compliance record-keeping.

For social media operators, the child protection duty would also include age estimation or verification measures “designed to prevent" persons under 16 from holding accounts where specified by regulation, subject to a Commission exemption for “adequate safeguards.” The duty to be transparent would extend to include digital safety plans. Additionally, a duty to act responsibly would include measures against harmful content, user guidelines, blocking and reporting tools, bot-amplified and synthetic content labeling, an identifiable resource person, and preservation requirements following certain content take-downs. A duty to make content inaccessible would impose 24-hour take-downs of NCDII and CSAM, as well as notice and appeal processes.

For chatbot operators, the duty to be transparent would similarly contemplate digital safety plans. Further, the duty to act responsibly would include measures against harmful content, emergency intervention obligations, and measures against harmful behavior such as posing as a human or licensed professional, using manipulative engagement techniques, and encouraging self-harm.

For operators of online services, the baseline transparency duty would similarly be supplemented with digital safety plans.

Remedies and Enforcement

The Digital Safety Commission of Canada would administer and enforce the Act. Canadians could make submissions about harmful content, harmful behavior, or non-compliance with the Act, as well as complaints seeking take-down orders for NCDII or CSAM.

The Commission would have extensive enforcement powers, including investigating complaints, holding hearings, conducting inspections under warrant, and issuing compliance orders.

Subject to a due diligence defense, administrative monetary penalties would reach the greater of 10 million Canadian dollars or 3% of gross global revenue, and offenses could carry fines up to the greater of 20 million Canadian dollars or 5% on indictment and $15 million or 4% on summary conviction. For affiliated groups, “gross global revenue” would mean the group’s revenue.