Articles

Canada's Bill C-36: What the Protecting Privacy and Consumer Data Act Means for Organizations

Bill C-36 introduces the Protecting Privacy and Consumer Data Act (PPCDA), replacing PIPEDA with stronger consent rules, cross-border transfer requirements, and penalties up to 5% of global revenue. Here is what organizations need to know.

Concord Team · Published Sat Jul 11 2026

Canada's Bill C-36: What the Protecting Privacy and Consumer Data Act Means for Organizations

On June 15, 2026, the Canadian government introduced Bill C-36, the Protecting Privacy and Consumer Data Act (PPCDA), marking the most significant proposed overhaul of federal private-sector privacy law in more than two decades. If enacted, the PPCDA would replace the core privacy provisions of the Personal Information Protection and Electronic Documents Act (PIPEDA), a framework that has governed commercial data practices in Canada since 2000 but has not kept pace with the realities of modern data collection, artificial intelligence, and cross-border data flows.

This is not Canada's first attempt at reform. Bill C-11, introduced in November 2020, died when Parliament dissolved in August 2021. Bill C-27, introduced in June 2022, progressed further but was lost when Parliament prorogued in January 2025. Bill C-36 represents the third legislative effort in six years, and it arrives with both structural lessons from its predecessors and a broader political mandate tied to Canada's National Artificial Intelligence Strategy.

For privacy, compliance, and legal leaders at organizations that operate in or collect data from Canada, the question is no longer whether reform is coming, but how to prepare for a law that introduces meaningfully stronger obligations, a new enforcement body with binding authority, and penalties that rival those under the GDPR.

What Bill C-36 Changes: The Core Framework

At its foundation, the PPCDA replaces Part 1 of PIPEDA with a standalone privacy statute that formally recognizes privacy as a fundamental right. While the practical implications of that recognition will become clearer through enforcement and case law, it signals a shift in how privacy considerations should factor into organizational decision-making: earlier, not as an afterthought.

The legislation maintains consent as the default legal basis for collecting, using, and disclosing personal information, but tightens the requirements significantly. Valid consent now requires plain-language disclosure of the purposes, methods, reasonably foreseeable consequences, types of information involved, and third-party recipients. Consent obtained through false, misleading, or deceptive practices is invalid. Individuals retain the right to withdraw consent on reasonable notice.

Beyond consent, the PPCDA introduces two notable exceptions. A business activities exception permits collection and use without consent for purposes such as providing requested products or services, information security, and product safety, though this exception does not extend to disclosure. A legitimate interest exception allows collection, use, and disclosure without consent when a reasonable person would expect the activity, the information is not used to influence the individual's behavior or decisions, and a documented privacy impact assessment supports the determination.

That behavioral influence restriction is significant. Neither the business activities exception nor the legitimate interest exception can be relied upon when the purpose is influencing an individual's behavior or decisions. In practical terms, this means targeted advertising, personalized pricing, and behavioral nudging will require express consent under the PPCDA, regardless of how the data was originally collected.

Cross-Border Data Transfers: New Obligations

For organizations that transfer personal information outside Canada, whether to affiliates, cloud providers, or service partners, the PPCDA introduces explicit pre-transfer requirements that go beyond PIPEDA's existing accountability framework.

Before disclosing or transferring personal information internationally, organizations must complete a privacy impact assessment in accordance with prescribed requirements, implement risk mitigation measures such as contractual privacy protections, adherence to approved codes of practice, or participation in a certification process recognized by the regulator, and provide assessment copies to the regulator on request.

This framework bears structural similarities to the GDPR's transfer impact assessment requirements and reflects the Canadian government's emphasis on treating data as a strategic national asset. Organizations that currently rely on standard contractual clauses or internal policies alone will need to evaluate whether their existing transfer mechanisms satisfy the PPCDA's more prescriptive requirements.

Children's Data and Sensitive Information

The PPCDA introduces a statutory definition of sensitive personal information, a category that PIPEDA recognized in principle but never formally defined. The legislation enumerates specific categories: children's data, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic information, health information, biometric information capable of uniquely identifying an individual, and sexual orientation information.

Children are defined as individuals under 18 years of age, and organizations face a higher standard when handling their personal information. The Commissioner must consider the best interests of children when exercising powers under the Act, and the legislation applies particular scrutiny to practices involving personalized pricing, loyalty analytics, targeted advertising, age assurance, and child-facing services.

For organizations that process data from users in Canada, this means evaluating whether existing age verification, data minimization, and consent practices meet the higher threshold the PPCDA establishes for minors.

Automated Decision-Making and AI

Unlike its predecessor Bill C-27, which included a standalone Artificial Intelligence and Data Act (AIDA), Bill C-36 does not contain separate AI legislation. Instead, AI governance is addressed through the PPCDA's automated decision-making provisions, privacy impact assessment requirements, and the broader regulatory framework the government is building through separate instruments.

The PPCDA defines automated decision systems broadly, encompassing rules-based systems, regression analysis, predictive analytics, machine learning, deep learning, and neural networks. When these systems make predictions, recommendations, or decisions that have a legal or similarly significant effect on an individual, organizations must provide explanations on request, including the types and sources of information used and the principal factors in the decision.

Individuals also gain the right to submit written representations that must be reviewed by a human employee. This creates a practical obligation for organizations using AI in credit scoring, hiring, fraud detection, customer service, pricing, and risk assessment to build explanation and human review capabilities into their systems.

The government has framed this approach as complementary to its National AI Strategy, positioning privacy protection as essential to responsible AI innovation and public trust.

A New Enforcement Architecture

Perhaps the most consequential structural change in Bill C-36 is the creation of the Digital Safety and Data Protection Commission of Canada, a new independent regulator that replaces the current Privacy Commissioner's oversight role with significantly expanded authority.

Under PIPEDA, the Privacy Commissioner operates primarily through investigation, recommendation, and referral. The Commissioner can name organizations in public findings and seek court orders, but cannot directly impose penalties or issue binding compliance orders. This has long been recognized as a gap in Canada's enforcement framework, particularly when compared to European data protection authorities.

The PPCDA changes this fundamentally. The new Commission is a five-member body with a dedicated Privacy and Consumer Data Commissioner who leads investigations, issues notices of contravention, enters compliance agreements, and conducts audits with broad powers including summons and premises entry authority. A specialized Privacy and Consumer Data Division handles dispute resolution, mediates complaints, and approves codes of practice and certification programs.

Critically, the Commission can issue binding orders and impose administrative monetary penalties directly, without routing through a separate tribunal or court process. This eliminates a procedural layer that slowed enforcement under Bill C-27's proposed three-body model (Privacy Commissioner, separate Tribunal, Federal Court) and brings Canada's enforcement velocity closer to what organizations already experience under the GDPR.

Penalties That Demand Attention

The PPCDA introduces a two-tiered penalty structure that represents a dramatic escalation from PIPEDA's enforcement toolkit:

  • Administrative monetary penalties of up to the greater of $10 million CAD or 3% of gross global revenue for contraventions of the Act.
  • Criminal fines on indictment of up to the greater of $25 million CAD or 5% of gross global revenue for the most serious offences, including failures to comply with breach reporting requirements.

For context, a mid-market organization with $200 million in annual revenue would face potential administrative penalties of up to $6 million and criminal fines of up to $10 million. These numbers place the PPCDA in the same tier as the GDPR's penalty framework and signal that Canada intends compliance to carry real financial weight.

The PPCDA also introduces a private right of action at the federal level for the first time. Individuals whose privacy rights are violated may sue organizations directly for damages once a contravention has been established through a Commissioner finding, Commission review, or Federal Court ruling. Claims must be brought within two years of the individual becoming aware of the relevant decision.

What Changed from Previous Attempts

Organizations that tracked Bill C-27 will find much of the PPCDA's substance familiar, but several notable changes reflect lessons learned from parliamentary debate and stakeholder feedback:

  • Legitimate interest now extends to disclosure, not just collection and use as under Bill C-27. This provides more flexibility for certain data-sharing arrangements, subject to the behavioral influence restriction.
  • The business transactions exception requires de-identification before transfer as a general rule, with a narrow exception when de-identification would undermine the transaction's objectives. Bill C-27 did not impose this default.
  • The automated decision-making threshold has shifted from "significant impact" to "legal or similarly significant effect," aligning more closely with GDPR terminology and narrowing the scope of the obligation.
  • The regulatory architecture is consolidated. Bill C-27 proposed a three-body system. The PPCDA's single Commission with internal divisions is designed to accelerate enforcement timelines and reduce jurisdictional friction.
  • No standalone AI legislation. The removal of AIDA means AI obligations flow through privacy law rather than a separate statute, simplifying the compliance picture for organizations operating across jurisdictions.

What This Means for Multi-Jurisdictional Compliance

For organizations already managing compliance with the GDPR, CCPA/CPRA, LGPD, and the growing patchwork of US state privacy laws, Bill C-36 adds another layer, but one that shares significant structural commonality with existing frameworks.

The PPCDA's consent requirements, legitimate interest exceptions, cross-border transfer assessments, and automated decision-making obligations all have analogues in the GDPR. Organizations with mature GDPR compliance programs will find that many of the same operational capabilities apply: privacy impact assessments, data mapping, consent management, and documented processing records.

However, the PPCDA is not a copy of the GDPR. The behavioral influence restriction on legitimate interest processing, the de-identification requirements for business transactions, and the specific enumeration of sensitive information categories create Canada-specific obligations that require distinct operational attention. Organizations cannot simply extend their GDPR programs northward without reviewing the differences.

The practical challenge for mid-market organizations operating across multiple jurisdictions is maintaining a unified compliance infrastructure that can adapt to jurisdiction-specific requirements without requiring a separate program for each law. This is where a platform approach to consent management, policy generation, privacy requests, and data mapping becomes operationally important: one system of record that can express different rules for different jurisdictions, rather than a patchwork of point tools that creates the same integration gaps the regulations themselves are trying to close.

How Organizations Should Prepare

Bill C-36 was introduced on June 15, 2026, and Parliament recesses for the summer before resuming on September 21, 2026. Second reading is expected in the fall session. Even under an optimistic legislative timeline, the bill must pass through committee study, third reading, Senate review, and Royal Assent before becoming law, and coming into force will be determined by Order in Council with a transition period.

That said, the substance of the PPCDA is largely settled. Organizations that wait for Royal Assent to begin preparation will find themselves scrambling. The more effective approach is to use the legislative window to assess readiness and close gaps now.

Map personal information flows across your organization and jurisdictions. Understand what data you collect from Canadian individuals, where it is stored, how it moves across borders, and which third parties have access. This is the foundation for every other compliance activity under the PPCDA.

Review consent mechanisms and privacy notices. The PPCDA's plain-language disclosure requirements and the behavioral influence restriction on legitimate interest processing mean that many existing consent flows will need updating. Evaluate whether your current consent management approach can support jurisdiction-specific rules, including express consent for behavioral targeting.

Assess cross-border data transfer practices. If you transfer personal information from Canada to other jurisdictions, prepare for the privacy impact assessment and risk mitigation requirements the PPCDA introduces. Document your transfer mechanisms and evaluate whether they meet the new standard.

Identify automated decision systems. Catalog AI and algorithmic tools that make predictions, recommendations, or decisions affecting individuals. Build or plan explanation capabilities and human review processes for systems with legal or similarly significant effects.

Update privacy management programs. The PPCDA requires documented policies, procedures, and practices for information protection, complaint handling, and staff training, scaled to the volume and sensitivity of information you process.

Evaluate children's data handling. If your product or service may be used by individuals under 18, assess whether your data collection, age verification, and consent practices meet the heightened obligations the PPCDA establishes.

Key Takeaways

  • Bill C-36 introduces the PPCDA, replacing PIPEDA's core privacy provisions with a modernized framework that recognizes privacy as a fundamental right.
  • Consent requirements are tightened, with new legitimate interest and business activities exceptions subject to a strict behavioral influence restriction.
  • Cross-border data transfers require documented privacy impact assessments and risk mitigation measures before disclosure outside Canada.
  • A new regulator, the Digital Safety and Data Protection Commission, gains binding order-making authority and direct penalty powers.
  • Administrative penalties reach the greater of $10 million CAD or 3% of global revenue. Criminal fines reach the greater of $25 million CAD or 5% of global revenue.
  • A federal private right of action allows individuals to sue for damages for the first time.
  • Automated decision-making provisions address AI through privacy law, with explanation and human review obligations.
  • Children's data receives heightened protection with a statutory definition and best-interests consideration.
  • Organizations should begin readiness assessments now, rather than waiting for Royal Assent, to close compliance gaps during the legislative window.

The Path Forward

Canada's third attempt at federal privacy reform arrives at a moment when the expectations placed on organizations handling personal information are higher than at any point in the past two decades. The PPCDA is not a radical departure from the direction PIPEDA was always heading, but it does close the enforcement gap that made Canada's privacy framework an outlier among peer nations.

For privacy and compliance leaders, the message is clear: the operational capabilities that matter, data mapping, consent management, privacy impact assessments, and documented governance, are the same capabilities the GDPR, CCPA/CPRA, LGPD, and now the PPCDA all require. Organizations that invest in building those capabilities as a unified system, rather than bolting on jurisdiction-specific point solutions, will be better positioned to absorb not only the PPCDA but the next regulation after it.

The legislative process still has months to run, and amendments are possible. But the direction is set. The time to prepare is now.