惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

G
Google Developers Blog
人人都是产品经理
人人都是产品经理
爱范儿
爱范儿
云风的 BLOG
云风的 BLOG
Last Week in AI
Last Week in AI
H
Hackread – Cybersecurity News, Data Breaches, AI and More
B
Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
H
Help Net Security
B
Blog RSS Feed
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
N
Netflix TechBlog - Medium
S
SegmentFault 最新的问题
The Cloudflare Blog
I
InfoQ
美团技术团队
博客园 - 三生石上(FineUI控件)
MyScale Blog
MyScale Blog
酷 壳 – CoolShell
酷 壳 – CoolShell
博客园 - 司徒正美
L
LangChain Blog
A
About on SuperTechFans
T
The Blog of Author Tim Ferriss
Y
Y Combinator Blog

Privacy & Cybersecurity Law Blog

FTC Rescinds 2021 Policy Statement on Health App Data Breaches EU Cyber Resilience Act Reporting Obligations Take Effect for Manufacturers Delaware Expands State Privacy Law Dutch DPA Fines Uber Over Automated Decisions Affecting Drivers European Commission Designates ChatGPT, Reddit, and Roblox Under the Digital Services Act China Issues New Rules on Cyberspace Security Inspection Court Approves Meta Settlement With 29 States Over Alleged Harms to Children and Teens FTC Proposes Enforcement Policy Statement on Personalized Pricing New Jersey Enacts the Kids Code Act with Privacy-by-Default and Safety-by-Design Obligations White House Memorandum Establishes Framework for Government-Directed Private-Sector Cyber Operations FTC, California and Utah Sue Telehealth Company Hims & Hers for Deceptive and Unlawful Privacy Practices CalPrivacy Settles with Two Data Brokers over Registration Failures and Privacy Violations New York Attorney General Releases Final Rules for SAFE for Kids Act EDPB Adopts Guidelines on Anonymous Data, Web Scraping, and Blockchain China Publishes Official Q&A on Administrative Policies for Cross-Border Data Transfers Hawaii Enacts AI Companion Disclosure and Safety Law EDPB Calls for Review of EU-U.S. Data Privacy Framework After U.S. Supreme Court Decision on FTC Independence CNIL Issues FAQs on Recommendation for Tracking Pixels in Emails European Commission Issues Guidance on the Cyber Resilience Act European Commission Issues EU AI Act Transparency Guidelines EU Digital Omnibus on AI Enters Into Force Connecticut AG Leads Multistate Settlement With 23andMe Over 2023 Data Breach CalPrivacy Targets Gig Economy Tech Platforms in First CCPA Compliance Audit New Jersey Adopts New Data Broker Registration Regime and Sensitive Data Sale and Licensing Restrictions CISA Plans to Finalize Cyber Incident Reporting Regulations in September 2026 Illinois Governor Signs Frontier AI Model Law New Hampshire Amends the NHDPA to Prohibit the Sale of Children’s Personal Data European Commission Unveils Cybersecurity and AI Action Plan European Commission Refers Four Member States to CJEU Over NIS2 Transposition Delays EDPB Opens Public Consultation on New Personal Data Breach Notification Template
Canada’s Proposed Social Media Ban for Children and Chatb...
2026-07-14 · via Privacy & Cybersecurity Law Blog

Canada’s Proposed Social Media Ban for Children and Chatbot Regulation: Bill C-34’s Impact on Platforms

John Salloum and Maryna Polataiko from Osler, Hoskin & Harcourt LLP report that Canada is contemplating a social media ban for children under 16—among other measures—through a new online safety regime that takes aim at harmful material, platform accountability and synthetic content.

Bill C-34, the Safe Social Media Act, was introduced on June 10, 2026, and would create two new statutes: the Digital Safety Act (the “DSA” or the “Act”) and the Digital Safety Commission of Canada Act. If passed, Bill C-34 would establish a comprehensive legal framework intended to govern online safety, reduce harms from online content and establish transparency and accountability requirements for operators of regulated services such as social media sites, chatbots and other online services.

Regulated Social Media, Chatbot and Online Services

The Act's duties apply to three types of “regulated services.” A service is generally regulated when it falls within a defined service type and either meets a user number threshold set by regulation or is designated as regulated by the Governor in Council.

  • Social Media Services. Social media services are websites or applications whose primary purpose is to facilitate communication among users by enabling them to access and share content. These include adult content and live streaming services. Duties under the Act do not apply to private messaging features on social media services.
  • Chatbot Services. Chatbot services are AI systems that (i) communicate over the internet; (ii) are publicly accessible via websites or applications; (iii) use natural language interfaces to provide adaptive, human-like responses in a conversational format; (iv) can simulate sustained human-like relationships through multiple interactions or sessions; and (v) generate content or responses that are not fully predetermined by system developers or operators. These do not include AI systems that exclusively serve purposes specified in the regulations.
  • Online Services. Online services are websites or applications other than social media or chatbot services that allow users to interact with them, excluding those whose primary purpose is the sale or advertisement of goods or services, or directories, search results, maps or navigation tools. Online services must first fall within a category established by the Governor in Council to be regulated. Duties under the Act do not apply to private messaging features on online services.

Telecommunications service providers offering basic internet connectivity would be exempt from duties under the Act.

The Act would not require operators to proactively search for harmful content, though regulations may require technological means to prevent child sexual abuse material (“CSAM”) from being uploaded.

Regulated Content

The Act would target seven categories of harmful content: Non‑consensual disclosure of intimate images (“NCDII”), CSAM, content that induces a child to harm themselves, content used to bully a child, content that foments hatred, content that incites violence, and terrorism or violent extremism content. It would also establish requirements specific to pornographic content and synthetic content.

Duties of Operators

The DSA would impose two baseline duties on all operators of regulated services: a duty to protect children, including safety-by-design features and — where an operator has “reasonable grounds” to suspect its service provides access to pornographic content —age verification or estimation measures to mitigate the risk of persons under 18 being exposed to such content, as well as a duty to be transparent through compliance record-keeping.

For social media operators, the child protection duty would also include age estimation or verification measures “designed to prevent" persons under 16 from holding accounts where specified by regulation, subject to a Commission exemption for “adequate safeguards.” The duty to be transparent would extend to include digital safety plans. Additionally, a duty to act responsibly would include measures against harmful content, user guidelines, blocking and reporting tools, bot-amplified and synthetic content labeling, an identifiable resource person, and preservation requirements following certain content take-downs. A duty to make content inaccessible would impose 24-hour take-downs of NCDII and CSAM, as well as notice and appeal processes.

For chatbot operators, the duty to be transparent would similarly contemplate digital safety plans. Further, the duty to act responsibly would include measures against harmful content, emergency intervention obligations, and measures against harmful behavior such as posing as a human or licensed professional, using manipulative engagement techniques, and encouraging self-harm.

For operators of online services, the baseline transparency duty would similarly be supplemented with digital safety plans.

Remedies and Enforcement

The Digital Safety Commission of Canada would administer and enforce the Act. Canadians could make submissions about harmful content, harmful behavior, or non-compliance with the Act, as well as complaints seeking take-down orders for NCDII or CSAM.

The Commission would have extensive enforcement powers, including investigating complaints, holding hearings, conducting inspections under warrant, and issuing compliance orders.

Subject to a due diligence defense, administrative monetary penalties would reach the greater of 10 million Canadian dollars or 3% of gross global revenue, and offenses could carry fines up to the greater of 20 million Canadian dollars or 5% on indictment and $15 million or 4% on summary conviction. For affiliated groups, “gross global revenue” would mean the group’s revenue.