Canada is preparing for its biggest private-sector privacy law reform in more than two decades. Introduced on June 15, 2026, Bill C-36 would enact the Protecting Privacy and Consumer Data Act (PPCDA), replacing Part 1 of PIPEDA and creating a new framework for how organizations collect, use, and disclose personal information.
The proposed law aims to strengthen privacy protections for Canadians while supporting responsible innovation, artificial intelligence, and the digital economy. If passed, it would introduce new obligations for businesses, stronger enforcement powers, and greater accountability for organizations handling personal information. Here’s what businesses need to know.
What is Canada’s Bill C-36?
Canada’s latest Bill C-36 is proposed federal legislation that would modernize Canada’s private-sector privacy framework.
The bill would:
- Enact the Protecting Privacy and Consumer Data Act (PPCDA)
- Repeal Part 1 of PIPEDA and replace it with the new framework
- Establish a new Digital Safety and Data Protection Commission of Canada
- Introduce stronger enforcement and penalties
- Create new rules for consent, data governance, automated decision systems, and cross-border data transfers
According to the Government of Canada, the PPCDA represents the most significant reform of Canada’s private-sector privacy law in over 25 years.
Importantly, Bill C-36 is not yet law. It must still complete the legislative process before any of its requirements take effect.
Guide
Who would need to comply with Canada’s Bill C-36?
If your business collects, uses, or shares the personal information of people in Canada, this law applies to you. Businesses located outside Canada may also fall within its scope if they handle the personal information of individuals in Canada as part of their commercial activities. This includes a wide range of businesses, such as E-commerce stores, SaaS companies, Technology and AI companies, and Advertising and marketing platforms, among others.
The law is not limited to large enterprises. Small and medium-sized businesses that handle personal information as part of their commercial activities would also need to comply.
Who is excluded?
The PPCDA would not apply to:
- Personal or household activities
- Certain journalistic, artistic, or literary activities
- Information that has been properly anonymized in accordance with the law
In addition, public-sector privacy matters remain governed by separate federal and provincial privacy laws.
Why is Canada amending PIPEDA?
Canada’s federal privacy law, the Personal Information Protection and Electronic Documents Act (PIPEDA), was written before most Canadians had smartphones. When it came into force in 2000, today’s digital economy did not exist. A lot has changed since then.
Businesses now rely on:
- Cloud services
- Behavioral advertising
- Cross-border data processing
- Artificial intelligence
- Automated decision-making systems
Canada’s privacy amendment, Bill C-36, aims to update the data protection rules to reflect how data is collected and used today, without compromising individuals’ privacy rights.
Key changes to Canada’s privacy law businesses should know
Privacy becomes a fundamental right
One of the most significant aspects of the bill is its recognition of privacy as a fundamental right.
“The purpose of this Act is to establish — in an era in 20 which data is constantly flowing across borders and geographical boundaries and significant economic activity relies on the analysis, circulation and exchange of personal information — rules to govern the protection of personal information in a manner that recognizes the 25 fundamental right of privacy of individuals with respect to their personal information and the need of organizations to collect, use or disclose personal information for purposes that a reasonable person would consider appropriate in the circumstances.”
Bill C-36
The PPCDA would require organizations to protect personal information while still allowing businesses to collect, use, and disclose data for purposes that a reasonable person would consider appropriate in the circumstances. This principle will likely influence how regulators evaluate business practices and compliance decisions.
Stronger accountability requirements
Bill C-36 places accountability at the center of compliance. Organizations would be responsible for personal information under their control, including information handled by service providers on their behalf.
The bill would require organizations to:
- Designate one or more individuals responsible for privacy compliance
- Maintain a privacy management program
- Implement policies, procedures, and governance measures
- Train employees on privacy practices
- Establish processes for handling complaints and requests
For many businesses, compliance will move beyond privacy policies and become an ongoing governance function.
Privacy management programs become mandatory
Every organization subject to the law would be required to implement and maintain a privacy management program. The program must include documented policies, practices, and procedures covering areas such as:
- Protection of personal information
- Complaint handling
- Staff training
- Privacy governance
Businesses must also consider the volume and sensitivity of the personal information they handle when designing these programs. For those that have not yet formalized their privacy practices, this could be one of the most significant operational changes introduced by the bill.
Higher standards for children’s data
The PPCDA places special emphasis on protecting children’s personal information. Organizations will be held to a higher standard when handling children’s data. A child is an individual under 18 years of age, and the PPCDA identifies children’s personal information as sensitive information. This means those providing products or services to children may face increased compliance obligations and heightened scrutiny from regulators.
More meaningful consent requirements
Consent remains a cornerstone of the proposed law. To obtain valid consent, organizations would need to provide individuals with clear information about:
- Why personal information is being collected, used, or disclosed
- How it will be handled
- Any reasonably foreseeable consequences
- The specific types of information involved
- Third parties that may receive the information
The information must be presented in clear, understandable language. The bill also prohibits organizations from requiring individuals to consent to unnecessary data collection as a condition of receiving a product or service.
For businesses, this means reviewing consent flows, privacy notices, and user experiences to ensure they are transparent and easy to understand.
Manage cookie consent for your site
Deploy a compliant cookie banner and manage consent the easiest way
Get started for free14-day free trialCancel anytime
New expectations for automated decision systems
Bill C-36 reflects growing concern about artificial intelligence and automated decision-making.
The law defines automated decision systems broadly, covering technologies that assist or replace human decision-making, including machine learning, predictive analytics, deep learning, neural networks, and rules-based systems. The PPCDA introduces obligations related to automated decision systems and provides individuals with greater visibility into decisions made using automated processing.
Organizations that use algorithms to make decisions affecting individuals should expect greater scrutiny and may need to provide clearer explanations of how these systems operate.
Clear rules for de-identification and anonymization
The PPCDA distinguishes between de-identified and anonymized information. This distinction is important.
De-identified information remains subject to privacy obligations because the risk of re-identification still exists. Anonymized information, by contrast, must be permanently and irreversibly modified so that individuals cannot reasonably be identified.
These provisions encourage the responsible use of privacy-enhancing technologies while supporting innovation, research, and product development.
New requirements for cross-border data transfers
Cross-border data processing is another major focus of the bill. Organizations transferring personal information outside Canada must ensure that service providers offer data protection and must comply with applicable transparency and safeguard obligations under the law.
Businesses that rely on international vendors, cloud providers, or global service providers should review their data transfer practices and vendor management processes.
Greater control over personal information
Bill C-36 would give individuals more control over how organizations handle their personal information. The bill allows Canadians to request that an organization dispose of their personal information in certain circumstances. While this is not a broad “right to be forgotten” like the GDPR‘s right to erasure, it does provide Canadians with a mechanism to ask organizations to stop retaining information that is no longer needed or that they no longer want the organization to hold.
The bill also strengthens other individual rights, including the ability to access personal information held by an organization, request corrections to inaccurate information, and move their information between organizations through approved data mobility frameworks.
For businesses, this means having clear processes in place to respond to requests relating to access, correction, disposal, and data mobility within the timelines required by the law.
Stronger enforcement and larger penalties
One of the notable changes proposed by Bill C-36 is its enforcement regime. The amendment seeks to establish the Digital Safety and Data Protection Commission of Canada, which would administer the PPCDA and have the authority to issue binding orders. A designated Privacy and Consumer Data Commissioner would oversee privacy-related enforcement and compliance activities.
Organizations that fail to comply could face penalties up to:
- $10 million or 3% of global annual revenue, whichever is greater
- $25 million or 5% of global annual revenue, whichever is greater, for the most serious offences
These penalties would represent a substantial increase from Canada’s current enforcement framework.
What businesses should do now
Although Bill C-36 has not yet become law, organizations should begin preparing.
Practical steps include:
- Review Privacy Governance: Assess whether you have a designated privacy lead and documented privacy management processes.
- Audit Personal Data Flows: Understand what personal information you collect, where it is stored, who has access to it, and whether it is transferred outside Canada.
- Evaluate Consent Practices: Review consent banners, privacy notices, sign-up forms, and preference centers to ensure they provide clear and meaningful information.
- Assess Vendor Relationships: Examine contracts with service providers and determine whether they provide appropriate protections for personal information.
- Review AI and Automated Decision Systems: Identify any technologies used to make or support decisions about individuals and document how those systems operate.
- Strengthen Children’s Privacy Protections: Organizations that collect information from children should review their practices and prepare for heightened compliance expectations.
Final thoughts
Bill C-36 signals a major shift in Canadian privacy law. The proposed legislation goes beyond traditional consent requirements and introduces a broader accountability framework built around governance, transparency, responsible innovation, and stronger protections for individuals.
For businesses, compliance will increasingly depend on demonstrating that privacy risks are identified, assessed, and managed throughout the data lifecycle. While the bill may still change as it moves through Parliament, organizations that begin preparing now will be better positioned to adapt if the PPCDA becomes law.
Comply with Canada’s consent requirements
Install CookieYes on your site and manage cookie consent effortlessly
Get started for free14-day free trialCancel anytime
FAQs on Bill C-36
Yes. The bill focuses on organizations handling the personal information of individuals in Canada. Businesses located outside Canada may still fall within the scope of the law if they collect, use, or disclose Canadians’ personal information as part of commercial activities.
Bill C-36 proposes replacing Part 1 of Canada’s current federal privacy law, the Personal Information Protection and Electronic Documents Act (PIPEDA), with a new law called the Protecting Privacy and Consumer Data Act (PPCDA).
If passed, the PPCDA would become Canada’s primary private-sector privacy law, introducing updated rules for consent, privacy management programs, children’s data, automated decision systems, data mobility, and enforcement. As of now, however, PIPEDA remains in force, and the PPCDA has not yet become law. Businesses must continue complying with PIPEDA until Bill C-36 completes the legislative process and comes into effect.

