Detect Deepfakesby Resemble AI
Deepfake law · Canada

Deepfake Law in Canada

Canada has no dedicated federal deepfake statute. Regulation relies on Criminal Code provisions, privacy law, provincial intimate-image statutes, and renewed AI-governance debate after Bill C-27/AIDA died.

Status
enacted
Jurisdiction
Canada
Effective
Mar 2015
Statute
Criminal Code sections 162.1, 264, 372 + privacy law
Non-consensual intimate imageryCriminal harassmentFraudAI governance: no enacted AIDA replacement
Updated Jul 7, 2026 · 2 min read

Canada regulates deepfakes through a patchwork of existing Criminal Code provisions, provincial privacy law, and provincial intimate-image statutes. A dedicated federal deepfake statute has not been passed, and Bill C-27's Artificial Intelligence and Data Act did not become law.

Key provisions

Criminal Code s. 162.1 — Publication of intimate images without consent. Since 2015. Applied to AI-generated imagery in several 2023–2025 prosecutions, with courts interpreting the provision to cover deepfake imagery of identifiable persons. Penalties up to five years.

Criminal Code s. 264 — Criminal harassment. Deepfake-enabled harassment campaigns prosecuted under this section. Up to ten years for aggravated cases.

Criminal Code s. 372 — False messages / impersonation. Covers deepfake-enabled impersonation for fraud purposes.

AIDA (Artificial Intelligence and Data Act), not enacted. AIDA was proposed as part of Bill C-27 and would have created federal AI governance, including risk-management and penalty provisions. Bill C-27 died before enactment, so as of July 2026 Canada has no enacted horizontal AI statute comparable to the EU AI Act.

PIPEDA (Personal Information Protection and Electronic Documents Act). Federal privacy law covers biometric data including voice and facial features used in deepfakes.

Provincial layers

  • Quebec: Law 25 (biometric data provisions); Civil Code right to privacy doctrine provides strong civil remedies for image misuse.
  • British Columbia, Manitoba, Nova Scotia, PEI: intimate image protection acts with civil remedies.
  • Alberta, Ontario: tort of invasion of privacy developed through common law.

Enforcement context

The Canadian Centre for Child Protection and provincial police forces have been active on AI-generated CSAM cases. Criminal prosecutions of adult non-consensual deepfake cases have increased through 2024–2025.

Practical implications

For organizations operating in Canada:

  • AI service providers: no AIDA-style federal AI statute is in force, but privacy, biometric-data, consumer-protection, and criminal-law exposure remains.
  • Platforms: Criminal Code obligations plus provincial laws require content-moderation infrastructure for deepfake imagery.
  • Enterprises: moderate compliance burden; watch for a replacement federal AI bill rather than assuming Bill C-27 will revive unchanged.

Sources