Bill C-34 identifies real online harms, but its minimum-age provisions risk turning child safety into age-verification infrastructure for ordinary internet access.
· 32 min read
This is a long piece, so the short version is: Bill C-34 gets part of the problem right. Platforms should be held accountable for harmful design, weak safety systems, and failures to protect children. But sections 27 to 29 risk turning child safety into age-verification infrastructure for ordinary internet access. That architecture deserves explicit parliamentary debate, not future regulations and Commission guidance.
Children should be protected online.
That is such an obvious statement it feels stupid to write. Of course children should not be left to fend for themselves against harassment, sextortion, bullying, eating disorder pipelines, self-harm content, addictive design, synthetic sexual abuse material, non-consensual intimate imagery, and reccomendation systems that can take a normal moment of teenage vulnerability and turn it into a machine-fed spiral.
Of course platforms should not be allowed to build engagement engines for children, profit from them, and then act as though the consequences are an unfortunate mystery.
Of course, the answer is not "do nothing".
But obvious statements are where bad digital policy loves to hide. Because Bill C-34, Canada's approach to this problem, does not merely ask whether children should be protected online. It asks a different question: should access to major online spaces depend on age verification or age estimation? That is not really the same question, one is about child safety, the other is about infrastructure.
Bill C-34, the Safe Social Media Act, identifies a real problem. It contains several ideas that point in the right direction. Then it introduces a minimum-age regime that risks turning child safety into generalized age assurance for online public life.
This is, once again, the same move Ottawa keeps making on digital policy. Start with a real harm. Describe it in language no one reasonable wants to oppose. Reach for a broad technical or legal framework. Push the hard implementation details into regulations, guidance, and future discretion. Then act surprised when people who understand how systems behave ask: "what exactly is being built?"
The details, apparently, are where democracy goes to die.
The second question is the one that matters
The public debate around C-34 will be framed around the surface-level question: Should children be protected online?
Yes. Obviously. That's easy. Next question.
The harder question is the second one, hiding in the details. Should Canadians have to pass through age-verification or age-estimation systems before participating in online spaces? That's the question C-34 quietly creates.
The government's own backgrounder says online services shape how people in Canada communicate, access information, and participate in civic and cultural life. That is correct. Social media is not just entertainment. It's not just TikTok dances, Instagram filters, Reddit arguments, influencer slop, and whatever fresh hell is happening on X this week. It's also where politicians make announcements, journalists find sources, emergency information spreads, public agencies communicate, unions mobilize, artists publish, local communities organize, marginalized people find each other, and ordinary Canadians participate in public life.
The modern public square is ugly. It's privately owned, algorithmically distorted, surveillance-funded, outrage-driven, and often terrible. It is still, perhaps unfortunately, a public square.
That is why the minimum-age provisions in C-34 are so serious. The government cannot describe online services as part of civic and cultural life, and then casually create a legal path to age-gate access to them. If access to social media is access to public discourse, then access controls on social media are access controls on public discourse.
That does not automatically make every restriction illegitimate. It does not mean children have an unlimited right to use every platform in every context. It does not mean platforms should be free to ignore harm. But it does mean that Parliament should treat this as a major change to how Canadians participate online.
Instead, C-34 treats it as a minor implementation detail.
The bill tries to do too much at once
The thing about Bill C-34, is it's not really one bill. It is a platform accountability bill, a child safety bill, an age-verification bill, a pornography access bill, an AI chatbot bill, and a Digital Safety Commission bill all stapled together under one title.
Some of those pieces deserve serious debate on their own. Some are defensible. Some are dangerous. Some are underdeveloped. Some may be salvageable with amendments. But combining all of them into one sprawling framework makes the entire bill harder to understand, harder to scrutinize, and harder to support. This matters because the platform accountability parts of the bill aren't inherently absurd. There is a real case for duties on large social media services. There is a real case for digital safety plans, better reporting tools, blocking tools, age-appropriate design, synthetic content labelling, and obligations around child sexual exploitation material and non-consensual intimate imagery. A narrower bill focused on those duties could probably attract broad support, I'd probably throw my whole support to it and my entire schtick is complaining about Canadian digital policy.
Instead, the government has bundled those ideas with a 16-year-old minimum age regime, age-verification and age-estimation powers, adult-content access restrictions, AI chatbot rules, and a powerful new regulator that will fill in much of the actual operating model later. That is how you take a broadly shared concern and turn it into a trust exercise.
The government is asking Canadians to accept the general framework now and wait for the details later. Which services will be covered? Which age-verification methods will be acceptable? How will age estimation work? How will decentralized services comply? What counts as an AI chatbot? What safeguards are enough for an exemption? How will the Commission balance privacy, expression, safety, and access?
All of that comes later. The regulations will come later. The guidance later. Commission decisions later. Technical standards later. Enforcement practice later.
That is not good enough, and is honestly a really lazy approach to legislating.
The implementation details are not administrative trivia. They are the policy. A social media age gate implemented through government ID is one kind of internet. A facial age-estimation system is another. A third-party age-assurance token is another. Device-level or app-store-level enforcement is another. Each creates different risks. Each shifts power to different institutions. Each changes the practical meaning of access. Parliament should not be asked to approve the general vibe and discover the architecture afterward.
Making this stranger, Parliament already has standalone age-verification legislation before it. Bill S-209, the Protecting Young Persons from Exposure to Pornography Act, is explicitly aimed at restricting young persons’ online access to pornographic material. If Parliament wants to debate age verification for adult content, it already has a bill through which to do that. Bill C-34 does something different. It imports age-verification logic into a much broader online safety framework covering social media, AI chatbots, platform duties, adult-content access, and a powerful new Commission. This is what happens when scope creep infects a legislative body.
There is also a political cost to this kitchen-sink approach. The good parts of the bill now have to carry the bad parts. Platform accountability gets tied to age verification. Child protection gets tied to identity infrastructure. AI chatbot regulation gets tied to social media access rules. A debate that should be specific becomes everything all at once. That helps no one except the people who benefit from confusion.
If the government wants to regulate harmful platform design, it should regulate harmful platform design. If it wants to create an age-verification regime for social media, it should say so clearly and defend that choice directly. If it wants to regulate AI chatbots, it should explain the scope of those rules on their own terms. If it wants to create a powerful Digital Safety Commission, it should be explicit about which decisions Parliament is making and which decisions it is handing to the regulator.
The good parts make the bad worse
The frustrating thing is that parts of Bill C-34 are aimed at the right target. The government correctly identifies that online harms are not only the result of individual behaviour. They are also shaped by how services are designed and operated. Features like algorithmic recommendation systems, engagement-based feeds, autoplay, and endless scrolling can amplify harmful content and increase exposure, especially for young users.
That's the correct analysis. So regulate that. Regulate recommender systems. Regulate addictive design. Regulate dark patterns. Regulate weak reporting tools. Regulate synthetic sexual abuse material. Regulate non-consensual intimate imagery. Regulate platforms that make it easy to harass people and hard to get help. Require real transparency. Require meaningful safety plans. Require platforms to assess risk, publish what they are doing, and face consequences when they fail.
Bill C-34, to its credit, does some of this. It creates duties for regulated services. It requires safety-focused and age-appropriate design features. It requires blocking and flagging tools. It requires digital safety plans. It creates duties around harmful content. It has provisions aimed at content that sexually victimizes children or revictimizes survivors. It addresses intimate content communicated without consent, including deepfake sexual images. It creates chatbot-specific duties around harmful content, crisis situations, and manipulative behaviour.
Good. Do more of that. Please, do more of that. That's holding platforms accountable. That's the correct lane.
The problem is that the bill does not stop there. It also includes a minimum-age regime for social media accounts. Section 27 requires operators of specified regulated social media services to implement adequate age-verification or age-estimation measures designed to prevent a person under 16 from having an account or otherwise being registered with the service. That's the landmine in the bill. Not because children should be left exposed to harm. Not because platforms are fine. Not because parents should be abandoned. Not because online harms are fake.
Because age verification is not just a child safety feature. It is infrastructure.
You cannot verify only children
This is the logical conclusion and somehow the part that keeps getting skipped over.
A platform cannot enforce a ban on under-16 users by checking only under-16 users. It doesn't know who they are. To find out who is under 16, it has to assess everyone. It has to distinguish the 15-year-old from the 16-year-old, the 16-year-old from the 18-year-old, and the adult from the teenager. That means everyone gets pulled into the age-assurance flow.
The government may call this age verification. It may call it age estimation. It may call it privacy-preserving. It may call it proportionate. It may call it a safeguard. It may say only specified regulated services will be covered. It may say the Commission will decide what is adequate. It may say personal information must be destroyed after the age check is complete.
But the experience from the user's perspective is simple. Before you can participate, prove you're old enough. Maybe it uses government ID. Maybe it uses a third-party token. Maybe it uses facial age estimation. Maybe it uses account history. Maybe it uses behavioural signals. Maybe it uses app-store-level controls. Maybe it uses some vendor that claims to verify age without revealing identity. Maybe the platform doesn't learn your exact age but receives a pass/fail result.
Those details matter. Some versions are worse than others. But none of them answer the burning question.
Should Canadians have to pass through an age-assurance system to participate in major online public forums?
Bill C-34 appears to answer: yes, if the service is specified by regulation and the Commission considers the measures adequate.
“Age estimation” is not a magic privacy wand
The bill doesn't only talk about age verification. It also talks about "age estimation".
This is meant to sound softer. It may not require government ID. It may not require uploading documents. It may not require the platform to know exactly who you are. It may involve estimating age from signals rather than verifying identity directly.
Unfortunately, age estimation is still not harmless. If a service estimates your age from your face, that raises biometric and discrimination concerns. If it estimates your age from your behaviour, that raises surveillance concerns. If it estimates your age from account history, device signals, social graph, usage patterns, or data broker information, that raises profiling concerns. If it relies on a third-party vendor, that creates a new compliance layer between Canadians and public online participation.
And if the estimate is wrong, then what? Does a 17-year-old with a young-looking face get locked out? Does a 15-year-old who looks older get waved through? Does a privacy-conscious adult who refuses to complete an age check lose access? Does a person without conventional documentation get pushed into a harder flow? Does a trans person, a racialized person, a person with a disability, or someone who simply does not fit the training data get misclassified?
The bill says measures must not unreasonably or disproportionately limit users’ expression. That's nice language, but it doesn't actually solve the problem. It just gives the regulator a balancing exercise after the architecture has already been accepted. Once the system is built around age checks, expression becomes something the system promises not to limit too much.
The privacy safeguards don't solve the architectural problem
Bill C-34 does, to its credit, contain privacy safeguards around age verification and age estimation. The Commission must be satisfied that the measures are effective, that personal information is not collected or used except for age-verification or age-estimation purposes, that the personal information is destroyed once the verification or estimation is complete, and that it is protected until destruction.
Those safeguards are better than not having safeguards. I will give them at least that much.
They are, however, not enough. The problem is not only what happens to the data after it is collected. The problem is that access to public online spaces becomes conditional on submitting to the process in the first place.
“Do not worry, the checkpoint deletes your papers after inspecting them” is not the same as “there is no checkpoint.”
“Do not worry, the vendor only uses your face to estimate your age” is not the same as “you do not need to scan your face to participate.”
“Do not worry, the platform only receives a token” is not the same as “the platform does not get to demand proof that you are allowed to be there.”
Privacy is more than just data retention. Privacy is also freedom from unnecessary verification. Freedom from being forced into identity-adjacent systems. Freedom from being made legible as a condition of participation. Privacy is what a system forces you to reveal, what it can infer, and what other systems can connect later..
Bill C-34 tries to manage the consequences of age verification. It does not justify why age verification should become a condition of access to social media in the first place.
Section 28: "We'll figure it out later"
Section 27 of the bill is the obvious problem people will focus on because it says age-verification or age-estimation measures.
Section 28 may be even more important. In plain language, it says an operator of a specified regulated social media service must implement any measures provided for by regulations that prevent people under 16 from having an account or being otherwise registered with the service.
Any measures.
Provided for by regulations.
That is where the real implementation fight is going to happen.
This is another Canadian digital policy classic. Parliament is asked to approve the broad structure, while the operational details are pushed into regulations, guidelines, Commission decisions, and future processes. The scary part is not always fully visible at first reading. It arrives later as compliance guidance.
In this case though, the enforcement mechanism is the policy. The law doesn't need to say “upload your ID to use Instagram” to create ID-for-the-internet pressure. It only needs to make platforms responsible for keeping under-16 users out while giving regulators the power to decide what counts as adequate.
Platforms will do what regulated entities always do. They will minimize their regulatory risk. If the penalty for letting underage users in is severe, and the penalty for making everyone verify is mostly reputational, the incentive is obvious. Regulatory compliance teams, for completely understandable reasons, pretty much always take the path of least-resistance.
The Commission is where the real architecture will be written
Amongst other things, Bill C-34 creates a powerful "Digital Safety Commission".
Some form of expert regulator may make sense for online safety. Parliament cannot write every technical detail into a statute. Platforms change quickly. Harms evolve. Design patterns shift. Regulators can build expertise, monitor compliance, and respond to evidence in ways that Parliament often cannot. That's the charitable version of this.
The less charitable version is that Bill C-34 asks Parliament to create the machine first and find out how it works later. The Commission will not just be a passive administrator. It will shape regulations, issue guidance, assess compliance, manage complaints, conduct audits, issue orders, levy penalties, and decide whether services qualify for exemptions from the minimum-age regime.
In practice, that means many of the most important questions will be answered after the bill passes.Which services will be covered? What age-verification or age-estimation measures will count as adequate? What safeguards will be required for an exemption? How will the Commission treat federated services? What happens when a service uses a privacy-preserving token? What happens when a user refuses to complete an age check? What error rate is acceptable? What appeal process is required? What happens when the verification vendor is wrong?
A law that says “the Commission will figure it out” is still a law creating the power to figure it out. Once Parliament creates the framework, the political argument shifts. The question stops being whether Canada should build age-verification infrastructure for social media and becomes how the regulator should implement the age-verification infrastructure Parliament has already authorized.
That is exactly the wrong sequence. The hardest questions should be answered before the power is created, not after.
The exemption model proves the default is exclusion
Section 29 allows the Commission to exempt a regulated social media service from the minimum-age provisions if the Commission is satisfied that the service provides adequate safeguards for the protection of children. On paper, that sounds completely reasonable. Supporters will argue Section 29 shows this isn't a complete ban, that services can get an exemption, they just need to prove that they're safe enough.
But the structure here matters. The default is still exclusion. That means platforms are pushed into one of two models. Either exclude under-16s through age verification or age estimation, or convince the Commission that their safeguards are good enough to be exempted.
If the government believes the real problem is harmful platform design, the baseline duty should be safer design. Full stop. Not “exclude young people unless you can satisfy the regulator.” Not “age-gate first, ask for an exemption later.”
The exemption model also gives the Commission enormous influence over the shape of online childhood. What counts as adequate safeguards? Who decides? Based on what evidence? How transparent will the process be? How will children’s own perspectives be included? How will the Commission weigh privacy, expression, mental health, safety, autonomy, and access to community?
A 15-year-old is not a toddler. A 15-year-old can work. A 15-year-old can organize. A 15-year-old can write, code, publish, volunteer, protest, explore identity, seek help, and participate in civic life. Treating every person under 16 as someone to be removed from major public online spaces is not a small design choice. It's a statement about young people's agency.
This will not hit all children equally
One of the common defences of this type of legislation is that parents aren't doing enough to parent their children online. There is some truth buried in that complaint. Many parents are overwhelmed. Many do not understand the platforms their children use. Many are fighting products designed by some of the richest companies in the world to capture attention, encourage compulsion, and make opting out socially difficult. “Just parent better” is not a serious answer to that.
But a government ban does not solve the parenting problem. It often just reproduces it. Blunt bans rarely, if ever, protect the vulnerable as cleanly as their supporters imagine. Some young people will comply. The ones most likely to comply are often the ones with stable homes, attentive parents, reliable devices, supportive schools, and relatively lower risk. They are the teenagers whose parents are already involved, whose online activity is already somewhat supervised, and whose offline life gives them other places to go.
The young people in the most vulnerable positions, the ones this legislation is supposed to protect, are also the ones most likely to route around the system. A teenager in an abusive household may need online access their parents don't approve of. A queer or trans teenager in an unsafe home may need pseudonymous communities. A young person being bullied may need somewhere outside their school and family environment to talk. A teenager experiencing exploitation may need access to information, support, or people who can help. A young person with unstable housing, poor family support, or mental health struggles may not experience the internet as a frivolous distraction. They may experience it as one of the few places where they can find privacy, language, community, or escape.
Those are exactly the young people who are least helped by a policy that assumes parents are available, safe, and capable of acting as the main enforcement layer. They are also exactly the young people least likely to respond to a ban by calmly logging off. They will find older accounts, shared accounts, fake birthdays, VPNs, foreign services, alternate app stores, browser versions, private servers, smaller platforms, gaming chats, encrypted groups, or whatever workaround appears five minutes after implementation. Teenagers are very good at bypassing rules written by adults who believe “create account” is a meaningful control boundary.
The result is predictable. Lower-risk teenagers are more likely to be blocked from mainstream services. Higher-risk teenagers are more likely to remain online, but in less visible and less accountable spaces. If young people are pushed away from large regulated platforms with safety teams, reporting tools, transparency obligations, parental controls, and public scrutiny, where do they go? Smaller services. Foreign services. Less moderated spaces. Private communities. Encrypted groups. Platforms with no Canadian presence, no meaningful reporting tools, no compliance staff, and no easy way for regulators to intervene.
A policy can succeed on paper while making harm harder to see. It can reduce the number of under-16 accounts on mainstream platforms while increasing the number of vulnerable young people using less visible workarounds. It can make adults feel that a boundary has been drawn while pushing the hardest cases into places where the boundary is least enforceable. It can make the problem quieter without making young people safer.
That is the recurring failure of blunt access bans. They are easiest to enforce against the people least likely to be in danger, and easiest to evade by the people whose danger is already hardest to detect. One just needs to look at the failure of Australia's attempt to confirm this. If the government’s goal is to protect vulnerable young people, it should be very careful about policies that reward invisibility.
Bill C-34 also seems to assume that social media still means one company, one platform, one database, one login system, and one operator with practical control over the whole service. That is how Facebook works. That is how Instagram works. That is how TikTok works. That is mostly how Reddit works.
It is however, not how the modern social web is evolving. Mastodon is not one service. It is thousands of independently operated servers speaking a shared protocol. Lemmy is not one service. It is a federated network of communities and instances. Bluesky is more centralized in practice today, but its underlying protocol is explicitly designed around federated components: personal data servers, relays, app views, feed generators, and labelers.
Bill C-34 keeps talking about “the operator” as though there is always one obvious entity with the ability to enforce the law across the service. In federated systems, that assumption falls apart entirely. Who is the operator of Mastodon? The non-profit developing the software? The administrator of mastodon.social? The person running a tiny instance for twenty friends? The Canadian instance that displays a post? The foreign instance where the post originated? The user who self-hosts? The relay? The app? The moderation service? There's no single front door, no single entity in control. That's the whole point.
A centralized platform can comply with an age-verification mandate by putting a checkpoint in front of account creation. That is obviously bad for privacy, but at least the implementation model is obvious. A federated platform cannot do that without either pushing the mandate down to every participating server, breaking interoperability with servers that do not comply, or recreating centralized control layers on top of a system designed not to have them. Every option is bad.
If every Mastodon or Lemmy instance has to implement age verification, the law becomes impossible for small community-run servers to comply with. If large instances block non-compliant instances, the fediverse fractures along regulatory lines. If app stores, clients, relays, or hosting providers become responsible, enforcement shifts away from the actual social interaction layer and toward infrastructure choke points. If only large services are covered, then the law creates a strange two-tier internet where centralized platforms are age-gated and federated systems sit in a legal grey zone until regulators decide what to do with them.
The government says online services shape civic and cultural life. The federated social web is part of that life. It is one of the few serious attempts to build social media that is not entirely controlled by a handful of giant companies. It is exactly the kind of architecture a digital sovereignty agenda should want more of: portable identity, interoperable protocols, smaller communities, local moderation, user choice, and less dependence on monopolistic platforms.
Bill C-34 seems to have no idea what to do with that, and that should worry anyone who cares about decentralization. A law that only works cleanly when applied to centralized platforms will tend to favour centralized platforms. They have compliance teams. They have lawyers. They have trust and safety departments. They have identity vendors. They have policy staff. They can absorb regulatory complexity and turn it into a moat. Small federated services simply cannot.
The result is perverse. A bill supposedly aimed at making social media safer may end up entrenching the very platform model that made social media so powerful, so addictive, and so difficult to govern in the first place. At this point it's not just a privacy problem. It's a competition problem. It's an interoperability problem. It's a digital sovereignty problem. It is a sign that the government is trying to regulate the social internet as though the only possible model is the centralized corporate platform.
That is probably the worst possible lesson to take from the past two decades. If Canada wants safer social media, it should not write laws that make decentralized alternatives harder to operate. It should be encouraging smaller communities, open protocols, user-controlled moderation, portability, and pluralism. Instead, Bill C-34 risks telling the independent social web: become more like the platforms, or become legally impossible.
The access-control logic will spread
The problem with age gates is that they rarely remain isolated. Once a service has to know whether a user is over 16 for social media access, why stop there? If the same service hosts adult content, it may also need to know whether a user is over 18. If the service has AI chatbots, it may need age-specific safeguards there too. If future legislation adds new categories of content, new thresholds can be layered onto the same access-control architecture.
That's how these systems expand. The first threshold is justified by the most sympathetic case. The second threshold is easier because the infrastructure already exists. The third threshold becomes a minor administrative detail. This isn't a slippery slope argument in the lazy sense. It's a systems argument, this is just the nature of how systems evolve. When a system exists, people find uses for it. When vendors build products, they sell them. When platforms integrate compliance flows, they reuse them. When regulators learn that access can be conditioned on age, identity, or eligibility, future policy debates start from that assumption.
The real risk is not only that Bill C-34 creates an age gate for social media. It is that it normalizes age gates as a tool for governing public online life. The government will say the safeguards are narrow. Maybe they are, for now. But infrastructure has this pesky way of outliving the political assurances that created it.
Any serious under-16 social media ban immediately runs into the problem of VPNs. If a child can route traffic through another country, use foreign app stores, or access web versions of services through non-Canadian endpoints, enforcement becomes harder. That does not mean enforcement is impossible, but it does mean that the pressure quickly moves outward.
First, platforms must verify age. Then, they must detect evasion. Then, app stores need to cooperate. Then, payment systems, device makers, browsers, operating systems, and network providers are asked to help. Then VPNs become suspicious because they allow users to bypass geography-based restrictions. Then privacy tools start looking like compliance problems.
This is not an abstract concern. It is the same pattern we see again and again in internet regulation. The first law targets a sympathetic harm. The enforcement problem then becomes an argument for expanding the law’s reach. Each additional layer is justified as necessary because the previous layer was incomplete. And because children are involved, anyone objecting can be accused of defending harm, it's why "think of the children" is an argument governments the world over instantly reach for.
Privacy is not suspicious
The worst argument for this kind of policy is the “nothing to hide” argument. Maybe people who care about privacy should not be online, the argument goes. Maybe if they refuse to verify themselves, that is fine. Maybe it is even good. Maybe the people with the most to hide will leave.
This is, in the nicest way possible, deranged.
Privacy is not evidence of guilt. Anonymity is not inherently illegitimate. Pseudonymity is not a loophole. The ability to speak, read, explore, and participate without tying every action to a verified identity is not a concession to criminals. It is one of the conditions that makes a free and democratic society possible.
People have things to hide because people have lives. They have medical questions, political beliefs, religious doubts, sexual identities, family problems, workplace complaints, private fears, unpopular opinions, and thoughts they have not finished thinking yet.
The people who most need privacy are often the people most harmed when systems demand verification. Vulnerable youth. Abuse victims. Whistleblowers. Journalists. Political dissidents. Queer and trans people. People in small communities. People without stable documentation. People seeking sensitive information. People who are not doing anything wrong and still don't want to be turned into a compliance record.
A democracy should not treat privacy as suspicious. A democracy cannot treat privacy as suspicious. The burden should be on the state to justify intrusion, not on the public to justify privacy.
Once again, this is bad digital sovereignty
Bill C-34 also fits into a larger Canadian problem, one I've already written about at length. Canada says it wants digital sovereignty. It says it wants trustworthy infrastructure, public accountability, resilience, and the ability to make its own choices in a world dominated by foreign technology platforms. Then it keeps proposing policies that make Canadian digital life more permissioned, more compliance-heavy, more centralized, more dependent on opaque intermediaries, and less trustworthy. This is somehow mistaking digital sovereignty for digital bureaucracy.
A sovereign internet is not one where Canadians need permission slips to participate. It is not one where access to major public forums depends on verification vendors, platform compliance teams, regulator guidance, and future regulations that ordinary people will never read. It is not one where privacy tools become suspect because they complicate enforcement.
Real digital sovereignty should mean Canadians have more control over the systems they depend on. More privacy. More resilience. More domestic capacity. More public trust. More open standards. More competition. More ability to leave platforms without leaving public life. Bill C-34 points in the opposite direction when it treats access as the control point. It says: we cannot make the platforms safe enough, so we will decide who is allowed through the door.
The bill should be amended
The government can still fix this. It should keep the platform accountability parts. It should strengthen them. It should focus on the systems that create and amplify harm. Require meaningful risk assessments. Require public digital safety plans that are actually useful. Require accessible reporting and appeal mechanisms. Require strong action on child sexual exploitation material and non-consensual intimate imagery. Require safer defaults for minors. Require transparency around recommender systems. Require limits on addictive design. Require labels for synthetic content where appropriate. Require platforms to make blocking and reporting tools easy to find and easy to use. Require independent audits. Require evidence. Genuinely, I'd love to write a positive article for once.
But remove or radically narrow the minimum-age regime. At minimum, Parliament should not pass sections 27 to 29 in their current form. If the government insists on age-related protections, they should be built around age-appropriate design, not generalized age verification. The law should prohibit mandatory government ID checks, biometric age estimation, face scanning, and third-party identity verification as conditions of ordinary social media access. It should require privacy impact assessments. It should require public technical standards before implementation. It should give the Privacy Commissioner more than consultation. It should include explicit protections for anonymous and pseudonymous participation. It should ensure that refusals to complete age checks do not automatically become grounds for exclusion from public online spaces.
Most importantly, it should not outsource the real debate to future regulations. Parliament should decide whether Canada is creating age-verification infrastructure for social media. Not the Commission later. Not Cabinet later. Not compliance vendors later. Not platforms quietly implementing whatever minimizes liability.
Parliament.
Now.
In public.
The problem is the architecture
The government will say this is about safety. It is, any attempt to deny that is making the lazy version of the argument. But safety is not the only value in a democracy. Privacy matters. Expression matters. Access matters. Youth autonomy matters. Public participation matters. Technical architecture matters.
If the architecture requires everyone to prove they are old enough before entering major public online spaces, then the law has changed what the internet is. It has made participation conditional. It has made access something to be granted after verification. It has made privacy something to be balanced after the checkpoint has already been built.
Children deserve protection online. They deserve platforms that are not engineered to exploit them. Parents deserve better tools. Users deserve reporting systems that work. Survivors deserve fast action. The public deserves transparency. Regulators deserve real powers. Platforms deserve much less deference than they currently receive. But Canadians also deserve an internet where privacy is not suspicious, pseudonymity is not treated as a problem to be solved, decentralized communities are not regulated out of existence, and participation in public life does not require passing through an age-assurance system.
Bill C-34, admittedly, gets some things right. That's probably why I'm frustrated. The government correctly identified that online services shape civic life. It correctly identified that platform design can amplify harm. It correctly identified that voluntary action has not kept pace. It correctly identified that children need protection. It correctly identified that platforms need duties.
Then it reached for age verification. Once again, Ottawa found a real digital policy problem and answered it with infrastructure that should make Canadians nervous.
The issue at hand is not whether children should be protected. Obviously they should. The issue is whether protecting children requires building a system where everyone may have to prove they are allowed to participate. That's not some minor implementation detail to figure out later.
That is the whole fight.