Fact sheet: New rules to help make social media safer for children and Canadians
The Government of Canada has introduced Bill C-34, the Safe Social Media Act, to help make online services safer, especially for children and young people.
The bill would create new duties for certain social media services and artificial intelligence chatbot services. These services would be required to identify risks, reduce exposure to harmful content, publish safety plans, and be accountable to a new Digital Safety Commission.
The goal is to make online services safer by requiring companies to take responsibility for the systems they design, operate, and profit from.
Contents
- Purpose and Scope of the Safe Social Media Act
- Protecting Children and Age Assurance
- Harmful Content and Freedom of Expression
- AI Chatbots and Synthetic Content
- Privacy, Private Communications, Data and Law Enforcement
- Oversight, Transparency and Enforcement
- Innovation, International Context, and Next Steps
Purpose and Scope of the Safe Social Media Act
An overview of why the Act is required and its key components.
Why are new rules being proposed?
Social media platforms and Artificial Intelligence (AI) chatbot services can help people connect, learn, and express themselves. But they can also expose users, especially children, to serious risks.
These risks can include cyberbullying, sexual exploitation, non-consensual sharing of intimate images, content that encourages self-harm or suicide, content that incites violence, and harmful AI-generated or manipulated content.
The bill is based on the idea that online safety is not only about individual posts. It is also about the systems platforms use, including content promotion, design features, reporting tools, moderation processes. It is about the way content can spread quickly to large audiences.
What services would be covered under the Act?
The Safe Social Media Act would apply to certain social media services and AI chatbot services.
Social media services and AI chatbot services would be covered where they meet the criteria set out in the legislation and regulations. The bill would also allow the Governor in Council, through regulations, to bring additional categories of online services into scope in the future if they pose a significant risk of harm to children in Canada. Additional categories of online services would only be subject to narrow set of obligations related to protection of children.
This flexibility is intended to help the law keep pace with changing technology and user behaviour.
Why does the bill focus on services instead of individual posters?
The Safe Social Media Act regulates online services, not individual posters. Many harmful acts online are already addressed through the Criminal Code and other laws. Those laws focus mainly on individuals who commit offences.
The Safe Social Media Act would add a different kind of accountability. It would require regulated services to reduce the risks created by their own systems.
Platforms design the features that recommend, amplify, monetize and moderate content. The bill would require them to take responsibility for those systems and the risks they create.
Protecting Children and Age Assurance
How the Act aims to better protect children online.
How does the Safe Social Media Act protect children?
A central goal of the bill is to better protect children online. The Duty to Protect Children addresses this goal by requiring regulated services to implement design features on their platforms that keep children safe online. These design features will be set out in regulations.
The Duty to Protect Children also introduces a minimum age requirement of 16 for certain social media accounts. This would be supported by age-verification or age-estimation measures. Services could be exempted by the Commission if they show that they have sufficient safeguards in place to protect children on their services.
The Duty would also include an age threshold of 18 for access to pornographic content, also supported by age-verification or age-estimation measures.
These requirements would need to be implemented in a way that protects privacy. Services would be required to limit the collection, use, retention and disclosure of personal information needed for age-assurance purposes.
How does age verification and estimation in the Safe Social Media Act affect my privacy?
The bill is designed to address privacy concerns related to age checks by requiring age-assurance measures to be both highly effective and privacy-protective.
The Digital Safety Commission would consider whether the collection or use of personal information is limited to the purpose of the measures services implement, whether they protect personal information, and whether personal information is deleted when it is no longer needed.
The Commission would also be required to consult the Privacy Commissioner, and take into consideration any recommendations it makes, before issuing guidelines or making regulations on age verification or age estimation.
Harmful Content and Freedom of Expression
How the Act addresses harmful content while respecting freedom of expression.
How does the Safe Social Media Act respect freedom of expression?
One of the core pillars of the Safe Social Media Act is to enable people in Canada to participate fully in public discourse and exercise their freedom of expression online. Harmful content can prevent people from participating online. Nothing in the Act would require regulated services to implement measures that unreasonably or disproportionately limit users’ expression.
The bill defines seven types of harmful content. These definitions were carefully drafted to narrowly capture online content that causes significant harm to people in Canada. Under the regime, regulated social media services and chatbot services would have to take steps to mitigate the risk that users on their services be exposed to these types of harmful content.
The bill would also require the Commission to consider freedom of expression when making regulations or issuing guidelines.
What do regulated services have to do to address harmful content?
Regulated social media services would have a duty to act responsibly, which includes a requirement to mitigate users’ exposure to the seven types of harmful content. These steps could include measures such as warnings, content demotion, limits on sharing, blocking tools, or content removal.
Regulated chatbot services would also have their own duty to act responsibly, which includes a requirement to mitigate the risk that their chatbot communicates harmful content to users.
To fulfill this obligation, regulated services are not required to proactively monitor or remove all harmful content. Instead, the bill would create a risk-based framework focused on systems, transparency, and accountability that allows regulated services to have flexibility in how they fulfill their obligations. In other words, they would be required to put in place adequate measures to reduce exposure to the seven types of harmful content, but the bill would allow room for innovation and flexibility to the regulated service on how to do so.
The Commission would assess whether a service’s measures are adequate. In doing so, it would consider factors such as the effectiveness of the measures, the size of the service, the service’s technical and financial capacity, and whether measures are designed or applied in a discriminatory way. It can also issue guidelines to help services understand and meet their obligations.
Regulated social media services would also be required to make inaccessible in Canada two of the most egregious types of harmful content on their service: (1) content that sexually victimizes a child or re-victimizes a survivor, and (2) intimate content communicated without consent.
AI Chatbots and Synthetic Content
Overview of how the Act addresses AI chatbots and synthetic content.
How does the Safe Social Media Act specifically address AI chatbots?
The bill would regulate certain AI chatbot services because they can interact directly and repeatedly with users, including children, and can provide unsafe responses, encourage harmful behaviour, simulate companionship, or use manipulative engagement techniques. In some cases, users may become emotionally dependent on a chatbot or be directed toward harmful actions.
Under the bill, regulated chatbot services would need to take steps to reduce the risk that they communicate harmful content or engage in harmful behaviour. They would also need measures to interrupt a conversation when a user appears to be in crisis, such as expressing suicidal thoughts or an intention to self-harm, and direct that user to appropriate human support. And finally, regulated chatbot services would need to prevent their chatbot from engaging in harmful behaviour, including deceptively posing as a human being, encouraging self-harm or using manipulative engagement techniques.
How does the Safe Social Media Act address deepfakes and synthetic content?
The bill would require regulated social media services to take reasonable steps to label synthetic images, audio and video that look like they could be real. This includes deepfakes and other AI-generated material. The purpose of this obligation is to help people in Canada better understand when they are seeing or hearing content that has been artificially generated or manipulated.
This obligation would be flexible. The Commission would consider what is technically feasible, how effective the labelling measures are, whether they avoid incorrectly labelling content, and the size and capacity of the service.
Privacy, Private Communications, Data and Law Enforcement
What is in the Act with regards to privacy, private communications, data and law enforcement.
What does the Safe Social Media Act mean for my private conversations?
The bill would not apply to private messaging. This means that private messaging services and direct messaging features on social media services would be outside the scope of the regime.
If a regulated chatbot service is involved in an otherwise private conversation, obligations on chatbot services will apply, which only concern the output of the chatbot. This means, for example, that a chatbot must be programmed in a way that mitigates the risk that it communicates harmful content to users, but the bill would not require the service to moderate harmful content communicated by users themselves. The obligations on social media services would not apply to the conversation.
The bill focuses first on services where content can spread publicly and quickly at scale. Private messaging raises different issues, including encryption and expectations of privacy.
Does the Safe Social Media Act require platforms to notify the police about my content?
The bill does not create a mandatory reporting duty to police.
Instead, the Commission would issue guidelines on when platforms should notify the Royal Canadian Mounted Police (RCMP) about content that gives rise to reasonable grounds to suspect there is a risk that someone will commit an act that would cause death or serious bodily harm to another individual.
These guidelines would be developed with privacy considerations in mind and in consultation with the Privacy Commissioner and the RCMP. The bill does require regulated social media and AI chatbot services be transparent about their policies and practices on reporting to law enforcement.
How does the Safe Social Media Act treat my data?
The Safe Social Media Act would not create a general data-retention or lawful-access regime.
The bill would not give police new access rights to user information. Law enforcement would still need the appropriate legal authority, such as a warrant or production order, to obtain information.
Some limited preservation and record-keeping duties would apply to services for regulatory purposes. For example, services are required to preserve certain harmful content that has been made inaccessible and keep records showing how they are complying with the Act.
Oversight, Transparency and Enforcement
Overview of how the Act will be enforced.
Who would oversee this new regime?
The bill would create a new Digital Safety Commission to oversee and enforce the regime.
The Commission would be led by three to five Governor in Council-appointed Commissioners. It would combine oversight, enforcement, research, guidance, education, and user-support functions in one organization.
The Commission would review regulated services’ Digital Safety Plans, gather information, conduct inspections and investigations, issue guidance, and take enforcement action where needed.
How will the public know if platforms are abiding by their responsibilities?
Regulated services would have to publicly publish Digital Safety Plans.
These plans would explain how a service identifies and reduces risks, what tools and systems it uses, and how it meets its legal duties.
Digital Safety Plans are intended to improve transparency and help the Commission assess whether services are taking meaningful steps to keep users safer.
How would the Safe Social Media Act be enforced?
The Commission will work with regulated services to ensure compliance with the Act. If a regulated service does not meet its obligations, the Commission could take enforcement action, including through compliance orders and administrative monetary penalties. The bill would allow penalties of up to 3% of gross global revenue or $10 million, whichever is higher, to promote compliance.
The amount of a penalty would depend on factors set out in the Act, such as the service’s compliance history, its ability to pay, and whether it benefitted from the violation.
Innovation, International Context, and Next Steps
How the Act supports innovation and how it compares to international online safety frameworks.
How does the Safe Social Media Act support innovation while improving safety?
The bill is intended to be flexible and outcomes-based.
It would not require every service to use the same tools or technology. Services would be able to choose how best to meet their obligations, based on their size, design, resources, and risks.
This approach is intended to support responsible innovation while ensuring that companies build and operate services with safety in mind.
How does Canada’s approach stack up internationally?
Canada’s proposed approach is similar to online safety regimes in other democratic jurisdictions, including the United Kingdom, the European Union and Australia.
These regimes focus on platform accountability, child protection, transparency, risk assessment, and independent oversight.
Canada’s approach reflects those international trends while being tailored to Canadian law, including the Canadian Charter of Rights and Freedoms and Canada’s privacy framework.
What happens next?
Bill C-34 would need to be studied and passed by Parliament before becoming law.
If passed, further regulations, guidance and implementation steps would follow, including the establishment of the Digital Safety Commission.