Language selection

Government of Canada

Search

Canada Elections Act

Version of section 446.6 from 2026-06-18 to 2026-06-21:


Marginal note:Required contents

  •  (1) The policy for the protection of personal information of a registered party or of an eligible party must be publicly available in both official languages, be written in plain language and

    • (a) designate a privacy officer who is responsible for overseeing the party’s compliance with the policy;

    • (b) include the name and contact information of the privacy officer;

    • (c) state the types of personal information in relation to which the party carries out its activities;

    • (d) explain, using illustrative examples, how the party carries out its activities in relation to personal information, such as by indicating whether it does so online or through the use of cookies;

    • (e) describe the training related to the protection of personal information that is offered to the party’s employees and volunteers who may have access to the personal information that is under its control; and

    • (f) require the party to protect the personal information that is under its control through physical, organizational and technological security safeguards with a level of protection proportionate to the sensitivity of the personal information;

    • (g) require the party to take appropriate steps in the case of the loss of, unauthorized access to or unauthorized disclosure of personal information that is under its control as a result of a breach of its security safeguards, including by, as soon as feasible, informing the individual whose personal information has been lost, accessed or disclosed if it is reasonable in the circumstances to believe the breach creates a real risk of significant harm to the individual;

    • (h) require the party to ensure, by contract or otherwise, that any person or entity to which it transfers personal information provides a level of protection of the personal information equivalent to that which the party is required to provide under the policy;

    • (i) require the privacy officer or their delegate to attend at least one meeting per calendar year relating to the protection of personal information held by the Chief Electoral Officer; and

    • (j) prohibit the party, as well as any person or entity acting on the party’s behalf, including the party’s candidates, electoral district associations, officers, agents, employees, volunteers and representatives, from

      • (i) providing false or misleading information to individuals about the purposes for which the party collects personal information,

      • (ii) selling personal information under the party’s control, or

      • (iii) disclosing personal information under the party’s control to the public for the purpose of causing harm.

  • Marginal note:Real risk of significant harm — factors

    (2) For the purposes of paragraph (1)(g), the factors that are relevant to determining whether a breach of security safeguards creates a real risk of significant harm to an individual include

    • (a) the sensitivity of the personal information involved in the breach; and

    • (b) the probability that the personal information has been, is being or will be misused.

  • Marginal note:Definition of significant harm

    (3) For the purposes of this section, significant harm includes bodily harm, humiliation, damage to reputation or relationships, loss of employment, business or professional opportunities, financial loss, identity theft, negative effects on the credit record and damage to or loss of property.

  • 2026, c. 2, s. 47
  • 2026, c. 20, s. 36

Page Details

Date modified: