top of page

Canada’s Privacy Law is Getting a Full Rebuild: What Bill C-36 Means for Your Business

June 19, 2026
By Pere Eze, PAE Legal

On June 15, 2026, the federal government introduced Bill C-36, formally titled An Act to enact the Protecting Privacy and Consumer Data Act, to amend the Personal Information Protection and Electronic Documents Act and to make amendments to other Acts. If passed, the bill will entirely replace Part 1 of the Personal Information Protection and Electronic Documents Act (PIPEDA). It represents the most significant overhaul of Canada’s private-sector privacy framework in more than 25 years.

This reform follows the failure of Bill C-27 (introduced in 2022), which died on the Order Paper when Parliament was prorogued in 2025. Bill C-36 arrives shortly after the release of Canada’s national AI strategy, indicating the government's determination to advance the legislation. Organizations should begin preparing now rather than waiting for Royal Assent.

1. A New Law Replaces PIPEDA

Bill C-36 replaces the privacy provisions of PIPEDA with a new statute called the Protecting Privacy and Consumer Data Act (PPCDA). The remaining electronic documents provisions of PIPEDA will be renamed the Electronic Documents Act and will continue separately.

The changes extend beyond structure. The definition of personal information has been expanded to include inferred information. Organizations that use data analytics or generative AI to predict or infer details about individuals should take note: such inferred data will be treated as personal information under the PPCDA.

One of the most important symbolic changes is the formal recognition of privacy as a fundamental right. This is more than a statement in the preamble. Privacy considerations must now be integrated into business decisions from the outset, including at the product design stage, before launching marketing campaigns, and before entering into data-sharing arrangements.

2. A New Regulator with Real Enforcement Power

A key structural change in Bill C-36 is the creation of the Digital Safety and Data Protection Commission of Canada. Oversight will shift from the Office of the Privacy Commissioner, which operated under an ombudsman model of investigation and recommendation, to this new Commission with stronger enforcement authority.

The Commission will have the power to:

  • Issue binding orders against non-compliant organizations;

  • Impose administrative monetary penalties of up to $10 million or 3 percent of global annual revenue, whichever is greater, for general violations; and

  • Levy penalties of up to $25 million or 5 percent of global annual revenue for the most serious offences.

 

The Commission will also oversee the proposed Digital Safety Act. As a result, businesses should anticipate that privacy issues will be reviewed alongside digital safety, AI governance, consumer protection, and platform accountability, an approach that is broader than anything contemplated under PIPEDA.

3. Stricter, More Prescriptive Consent Rules

Consent continues to be the primary basis for collecting, using, or disclosing personal information under the PPCDA. However, the bill raises the bar considerably compared to PIPEDA. Valid consent must now be informed through clear, plain-language information that details the purposes, methods, reasonably foreseeable consequences, types of personal information involved, and any third-party recipients.

At the same time, the PPCDA introduces important exceptions to the consent requirement. These include a legitimate-interest exception (subject to safeguards requiring organizations to balance their needs against potential adverse effects on individuals) and exceptions for routine business activities, such as service delivery, security, and safety. These exceptions provide some flexibility in situations where obtaining consent would be impractical, while still protecting individuals from misuse. The bill also sharpens the line between express and implied consent, invalidates consent secured through deceptive practices, and maintains individuals’ right to withdraw consent with reasonable notice. As a result, many current privacy policies and checkbox-style consent mechanisms may fall short under the new rules.

4. New Individual Rights: Deletion, Portability, and Automated Decisions

The PPCDA expands individuals’ rights regarding their personal data. It introduces a right to request disposal of personal information when the data was handled contrary to the Act, when consent has been withdrawn, or when the information is no longer needed for its original purpose. “Dispose” means permanently and irreversibly deleting or anonymizing the information, not merely archiving it.

Individuals will also be able to request that their personal information be transferred to another organization, aligning with emerging open banking and consumer-directed data initiatives.

For organizations that use AI or algorithmic tools, the bill introduces transparency requirements for automated decision systems. When an automated decision, prediction, or recommendation has a legal or similarly significant effect on an individual, that person may request an explanation of how the decision was made and what personal information was used. Businesses applying AI to hiring, credit decisions, fraud detection, targeted pricing, or risk scoring should begin documenting their systems now.

5. Children’s Privacy and Surveillance Pricing

Bill C-36 defines a “child” as anyone under the age of 18 and imposes a higher standard of care for organizations handling children’s personal information. This change complements the proposed Safe Social Media Act (Bill C-34), which would prohibit children under 16 from using social media platforms. Together, these measures reflect a strong legislative focus on protecting minors online.

The PPCDA also addresses “surveillance pricing,” the practice of using personal data to set individualized prices in ways that may be unfair or exploitative. Organizations engaged in personalized pricing, loyalty analytics, or behavioural advertising should monitor regulatory developments in this area.

6. New Concepts: Sensitive, De-Identified, and Anonymized Information

Bill C-36 introduces several important new distinctions in how personal information is categorized. It creates a category of “sensitive” personal information, which refers to data for which an individual has a heightened expectation of privacy, taking into account the circumstances. Examples include children’s personal information, details revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or health information, biometric data capable of uniquely identifying an individual, and information concerning sexual orientation. The list is non-exhaustive, so regulators and courts may identify additional categories based on context.

The bill also establishes, for the first time, a clear and consequential distinction between de-identified and anonymized information. De-identified information is data from which identifying elements have been removed, but where re-identification remains technically possible. In contrast, anonymized information is personal information that has been irreversibly modified so that no individual can be identified. Anonymized information falls entirely outside the scope of the PPCDA, while de-identified information remains subject to the Act.

Organizations that currently rely on de-identification techniques as a compliance strategy will need to reassess their technical standards to ensure they meet the PPCDA’s requirements and align with generally accepted best practices.

7. Private Right of Action

Under PIPEDA, individuals had no direct right to sue organizations for privacy breaches. The PPCDA introduces a private right of action, which could expose organizations to civil litigation and potential class actions. This represents a significant shift in compliance risk.

What Organizations Should Be Doing Now

Bill C-36 is at first reading and must still pass through second reading, committee study, third reading, Senate review, and Royal Assent before becoming law. Many operational details will be set out in future regulations. However, proactive organizations can use this time effectively by:

  • Auditing current data collection practices against the PPCDA’s stricter consent requirements, including the new legitimate interests and business activities exceptions;

  • Developing and documenting a comprehensive privacy management program that covers policies, staff training, complaint handling, and accountability measures;

  • Reviewing privacy policies and consent mechanisms to ensure they use plain language and meet the heightened standards for valid consent;

  • Mapping personal information flows, including storage locations, access controls, and retention periods, to prepare for deletion and portability requests;

  • Conducting privacy impact assessments for higher-risk activities, particularly those involving AI, automated decision-making, or children’s data;

  • Assessing whether AI or automated decision tools can generate clear explanations of their outputs and the personal information they rely on;

  • Identifying any handling of children’s data and evaluating whether existing safeguards meet the higher standard of care;

  • Designating a privacy lead responsible for implementing and maintaining the privacy management program; and

  • Updating commercial contracts, vendor agreements, and M&A due diligence processes to reflect the PPCDA’s expanded obligations.

 

Canada’s privacy law has remained largely unchanged since most Canadians acquired their first smartphone. Bill C-36 signals a clear end to the era of flexible, principles-based, and lightly enforced privacy compliance. The question for businesses is not whether to prepare, but how quickly.

This article is intended for general informational purposes only and does not constitute legal advice. Bill C-36 has received first reading and may be amended as it advances through the legislative process. Organizations seeking advice specific to their circumstances should consult qualified legal counsel.

Contact PAE Legal for tailored privacy advice concerning your organization.

bottom of page