Notes from the IAPP Canada: Is it time to rethink longstanding privacy principles?
At the IAPP Canada conference, practitioners and policymakers debated whether foundational privacy principles — built for an earlier technological moment — still hold up in a world of AI, persistent data collection, and cross-border data flows.
Why this matters: Privacy law was mostly designed before smartphones, before cloud computing, before AI trained on everything. The rules we rely on — consent, purpose limitation, data minimization — were written for a different world. That is not a reason to throw them out. It is a reason to be honest about where they are breaking down. If the people who built those frameworks are now questioning them, that is worth paying attention to. The harder question is whether any rethink ends up protecting people more, or just giving companies cleaner legal cover to do what they were already doing.
Who should care: General readers · Privacy officers · Policy
This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.