Council Regulation (EU) 2019/1111, Article 27(5), concerns protective measures where a court orders the return of a child.
Finland’s practical position is one of preparation, not an established transfer power, because the legal evidence provided contains no operative AMMR provision.
Because the relevant instrument is described as an EU Regulation, it applies directly in every Member State within its subject matter.
For asylum seekers in Finland, the immediate consequence is exposure to prepared transfer procedures to Italy, if the Finnish authorities activate them.
GDPR Article 35(3)(a) requires a data protection impact assessment for systematic and extensive automated evaluation, including profiling, where decisions produce legal or similarly significant effects.
Under Article 83(2), a natural or legal person may apply only if that person does not carry on a business involving the supply of goods or services of the kind certified.
Companies in this market now face a documentation problem before they face a marketing problem, because enforcement has begun while later high-risk rules remain phased.
GDPR Article 2(1) brings personal-data processing within scope where it is wholly or partly automated, or where non-automated data form part of a filing system.
For companies deploying AI, the practical consequence is the need to map each tool against automated processing, data categories, decision effects, and documentation duties.
Under Article 35(1) GDPR, a controller must carry out a data protection impact assessment before commencing high-risk processing involving new technologies.
The follow-up point is the progress of Bill C-36, Bill C-34, and any resulting regulatory guidance.
Although Canada’s AI for All strategy does not establish a comprehensive AI statute, organizations now face a targeted compliance trajectory. This is significant because privacy reform, online safety obligations, procurement rules, standards, and sector-specific regulation are being positioned as the next legal channels. The immediate legal question is whether AI deployments give rise to obligations under existing or proposed targeted regimes, rather than under a revived AIDA. Under Article 3 GDPR, the Regulation applies to Union establishments and to non-Union controllers or processors offering goods or services to data subjects in the Union. Under Article 3 GDPR, it also applies to non-Union actors monitoring behaviour where that behaviour takes place within the Union. The GDPR is a Regulation and therefore applies directly in every Member State. For AI systems using personal data, Article 2 GDPR applies to automated processing and to processing of personal data forming part of a filing system. Council Directive 2011/16/EU on administrative cooperation in the field of taxation (DAC) is a Directive and therefore binds through national transposition.
Canada’s strategy is expressly not legislation and does not itself impose compliance obligations. Its legal significance lies in the fact that Bill C-36 and Bill C-34 are presented as early targeted examples of the same policy direction. Bill C-36 would enact the Protecting Privacy and Consumer Data Act and replace Part 1 of PIPEDA with a new federal private-sector privacy law. Bill C-34 would regulate certain AI chatbot services and social media services through online safety obligations. Under Article 35(2) GDPR, the controller must seek the advice of the data protection officer where one has been designated. Under Article 35(3) GDPR, a DPIA is required for systematic and extensive automated evaluation producing legal or similarly significant effects. Under Article 35(3) GDPR, a DPIA is also required for large-scale processing of special-category data or large-scale monitoring of publicly accessible areas. The content of the DPIA is defined by Article 35(7) GDPR. It must describe the processing operations and purposes, assess necessity and proportionality, assess risks, and identify safeguards and security measures. Under Article 35(11) GDPR, the controller must review processing where a change in risk makes such review necessary. Under Article 57 GDPR, supervisory authorities may investigate, maintain DPIA lists, advise on processing, and encourage codes of conduct and certification mechanisms. Under Article 22(1) GDPR, a data subject has the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects. Under Article 22(2) GDPR, that protection does not apply where the decision is permitted by contractual necessity, law, or explicit consent. Under Article 22(3) GDPR, cases based on contract or consent require human intervention, the right to express one’s views, and rights to contest the decision.
For organizations, the practical consequence is that governance work is required before any single Canadian AI statute emerges. The evidence supports preparation around transparency, human review, vendor commitments, data use, model governance, security, explainability, cross-border processing, and subcontracting. For chatbot and social media services, Bill C-34 signals possible obligations concerning harmful content, harmful chatbot behaviour, crisis intervention, user reporting, safety plans, records, and oversight. For private-sector privacy programs, Bill C-36 signals continued consent-based reform built around the PPCDA and many PIPEDA principles. Organizations with EU-facing activities must assess Article 3 GDPR before treating the matter as purely Canadian. Controllers using high-risk AI processing should prepare DPIAs under Article 35 GDPR before processing begins. Automated decision-making systems need a pathway for human intervention, user submissions, and contestation where Article 22(3) GDPR applies. Vendor reviews should address auditability, security, explainability, data use, service continuity, and emerging Canadian standards. The next legal step evidenced is not a dated revival of AIDA.