Canada Protecting Privacy and Consumer Data Act (Bill C-36)

Introduced 15 June 2026 to replace PIPEDA after Bill C-27 died on the order paper; creates an order-making Privacy Commissioner, administrative penalties, and rules for automated decision systems and de-identified data.

JurisdictionCanada
CategoryPrivacy & Data Protection
StatusProposed
Latest development

Analysis

I need to correct the premise first: Bill C-36 was tabled in Parliament, but the search results do not show that it is already in force as of the date you provided. The official federal materials indicate it was introduced to modernize Canada’s private-sector privacy regime and would repeal Part 1 of PIPEDA if enacted, but the current legal baseline remains PIPEDA unless and until Bill C-36 receives Royal Assent and comes into force.[2][4][7][8][13]

Because your request requires direct, clickable source links for every significant statement, I can give you a structured, source-backed analysis below using the official materials available in the search results and clearly flagging where the analysis is based on the bill text/proposed regime, not enacted law.[2][4][10][13]

Key Requirements

  • Scope and purpose: Bill C-36 would create the Protecting Privacy and Consumer Data Act and would replace Part 1 of PIPEDA for private-sector privacy governance in Canada, according to the official bill text and government announcement.[2][4][13]
  • Meaningful consent and plain-language transparency: The government says the bill would require meaningful consent and plain-language explanations of how personal information is handled.[4]
  • Children’s information: The bill would set higher standards for organizations handling children’s information, according to the federal announcement.[4]
  • Automated decision-making transparency: The bill would require organizations to be transparent about their use of automated decision making for significant decisions about individuals.[4]
  • Right to deletion: The bill would provide Canadians a right to request deletion of their personal information in certain circumstances.[4]
  • Purpose limitation and responsible use: The government says personal information must be used responsibly, transparently, and for appropriate purposes, including to prevent unfair or inappropriate uses such as surveillance pricing.[4]
  • Data mobility: The bill would support data mobility, allowing Canadians to move their personal information securely between organizations where a framework applies.[4]
  • Cross-border transfer safeguards: The bill would require privacy safeguards and risk assessments before personal information is transferred outside Canada, as described by the government announcement.[4]
  • Enforcement model: The bill would create an order-making regulator and strengthen enforcement, including administrative monetary penalties and higher fines for serious offences.[4][10][13]
  • Regulator redesign: The bill would shift private-sector privacy oversight from the current OPC structure to a new Digital Safety and Data Protection Commission of Canada, with a designated Privacy and Consumer Data Commissioner.[4][10][13]

Compliance Challenges

  • Consent design at scale: Organizations will need to rewrite privacy notices and consent flows to satisfy a meaningful consent standard and plain-language expectations, which is operationally difficult in multi-product or multi-jurisdiction environments.[4][13]
  • Automated decision governance: Companies using scoring, ranking, recommendation, fraud detection, or eligibility models will need controls to explain when automated decisions are used and how they affect individuals.[4]
  • Data inventory and deletion workflow complexity: A deletion right requires defensible retention schedules, identity verification, exceptions handling, and downstream deletion propagation across vendors and backups.[4]
  • Children’s data classification: Distinguishing child users from adults and applying enhanced protections is difficult in consumer-facing products, especially where age is uncertain or accounts are shared.[4]
  • Cross-border transfer assessments: The government’s proposed cross-border safeguards imply organizations will need vendor due diligence, transfer assessments, and documented risk controls before sending data abroad.[4]
  • Regulatory shift and uncertainty: Because the bill would move enforcement to a new commission and change the oversight architecture, organizations face transition uncertainty until final text, regulations, and guidance are settled.[10][13]

Real-world examples and analogous cases

  • Canadian privacy enforcement has already involved compliance failures and regulatory investigations under PIPEDA, which signals that documentation, consent, and safeguards remain recurring pain points under the current framework.[7][9][14]
  • Industry concerns about Bill C-36 focus on higher penalties, a private cause of action, and broader enforcement exposure, which legal and policy analyses have highlighted as material compliance risks for businesses.[1][5][6]
  • Organizations that rely heavily on AI or automated profiling will be most exposed, because the bill explicitly targets transparency around automated decision-making for significant decisions.[4][6][11]

Implementation Best Practices

  • Build a data map first: Inventory personal information flows, systems, vendors, cross-border transfers, retention periods, and automated decision systems so obligations can be assigned to owners and controls.[4][7][13]
  • Rewrite notices and consent UX: Replace dense privacy notices with layered, plain-language disclosures aligned to the bill’s meaningful consent and transparency direction.[4]
  • Create an automated decision register: Document model purpose, inputs, outputs, human review points, fairness testing, explainability notes, and customer disclosure language for each high-impact system.[4][11]
  • Formalize deletion operations: Define request intake, identity verification, exception handling, record keeping, backup handling, and vendor deletion SLAs to support the deletion right.[4]
  • Strengthen vendor governance: Update contracts, transfer assessments, and audit rights for processors/service providers, especially for cross-border data transfers.[4]
  • Adopt a privacy management program: The OPC’s PIPEDA materials already emphasize complaint handling and privacy compliance management, which remain a strong baseline for the proposed regime.[7][9][14]
  • Use structured privacy risk frameworks: Align internal controls with recognized privacy governance practices and documented accountability structures, even before final implementing guidance is issued.[7][9][14]

Useful official resources and frameworks

Recent Updates

  • 15 June 2026: The federal government introduced Bill C-36 to modernize Canada’s private-sector privacy law.[4][10]
  • 19 August 2026: The official Justice Canada bill page shows Bill C-36 was tabled in the House of Commons on that date, with the bill text indicating it would repeal Part 1 of PIPEDA and create a new commission structure.[13]
  • As of the official materials surfaced in search results, no Royal Assent or coming-into-force date is shown, so compliance deadlines for the new regime are not yet fixed in the sources reviewed.[2][4][13]
  • Enforcement timing remains contingent on legislative progress and any future regulations, so organizations should treat the current text as a proposed framework rather than a settled deadline regime.[2][13]

Official update sources

Related Regulations

  • PIPEDA: Bill C-36 would repeal Part 1 of PIPEDA and re-enact a modernized federal private-sector privacy framework, so PIPEDA remains the key baseline for transition planning until the new law is in force.[2][7][8][13]
  • Privacy Act: The OPC explains that the Privacy Act governs federal public-sector personal information handling, while PIPEDA governs federal private-sector privacy.[9]
  • Privacy Commissioner/OPC framework: Current OPC complaint and oversight processes under PIPEDA provide the closest operational model for what organizations may expect during any transition period.[7][14]
  • Bill C-34 / digital safety regime: Government and legal analyses indicate Bill C-36 would interact with a broader digital safety framework and a new commission structure.[4][6][13]
  • Cross-border transfer and de-identification concepts: Bill C-36’s proposed treatment of anonymized/de-identified information and cross-border transfer safeguards intersects with existing privacy engineering and data governance controls discussed in law-firm analyses.[1][5][6]

Official links for related regimes

Industry Impact

  • Technology and digital platforms will likely face the largest implementation burden because of automated decision-making disclosure, deletion workflows, and transfer controls.[4][6][11]
  • Retail and adtech are especially exposed to the bill’s concern about surveillance pricing and more granular transparency over consumer data use.[4][5]
  • Financial services and insurance may need tighter model governance because their eligibility, pricing, and fraud systems often rely on automated or semi-automated decisioning.[4][6]
  • Health, education, and child-facing services will likely need stronger age-assurance and child-data controls due to the bill’s emphasis on children’s information.[4]
  • Cross-border SaaS and cloud vendors may need more robust transfer assessments and contractual safeguards because the government has signaled stronger protection requirements before foreign transfers.[4]

Industry analysis sources

Sources

If you want, I can next turn this into a company-ready compliance checklist or a gap assessment matrix mapped to Bill C-36 requirements.

Recent developments

  • — Dentons said Bill C-36 would interact with Bill C-34 and could significantly affect online service providers. The firm noted that the bill would largely replace PIPEDA while clarifying scope for interprovincial, international, and anonymized data. (source)
  • — Al Jazeera reported that Bill C-36 addresses AI-related privacy risks, including transparency for automated systems and stronger protections for children’s data. The article also noted the bill’s framework for de-identified data and its broader digital-economy implications. (source)
  • — Teresa Scassa analyzed Bill C-36 as a substantial rewrite of Canada’s private-sector privacy law. The commentary focused on how the proposal builds on earlier reform bills while changing the structure of privacy governance and enforcement. (source)
  • — Torys described Bill C-36 as a major reform that could bring administrative monetary penalties up to the greater of 3% of global revenue or $10 million. The firm said the bill could also create a private cause of action and a three-tier enforcement regime. (source)
  • — Canadian Lawyer reported that the bill combines familiar privacy reforms with new elements, reflecting the government’s latest attempt to update Canada’s privacy law. The article framed the proposal as a significant overhaul for privacy and compliance teams. (source)
  • — Michael Geist criticized Bill C-36 as modernizing privacy law while also delaying full implementation until 2030. The post argued that the bill continues Canada’s long-running privacy reform effort after earlier failed attempts. (source)
  • — DLA Piper said Bill C-36 was introduced on June 15 and would replace Part 1 of PIPEDA if enacted. The firm highlighted major changes including a new regulator, stronger enforcement tools, and a privacy framework that treats privacy as a fundamental right. (source)
  • — A legal news report summarized Bill C-36 as requiring valid consent, plain-language disclosures, and stronger deletion rights for consumers. It also emphasized the creation of a new enforcement structure for private-sector privacy oversight. (source)
  • — The Government of Canada tabled Bill C-36, the Protecting Privacy and Consumer Data Act, to modernize federal private-sector privacy law. The bill would recognize privacy as a fundamental right, strengthen children’s data protections, and add deletion rights and clearer consent requirements. (source)
  • — Privacy Commissioner Philippe Dufresne commented on Bill C-36 and noted that it would shift private-sector privacy responsibilities from the OPC to a new Digital Safety and Data Protection Commission of Canada. He highlighted the bill’s expanded enforcement powers, including orders and administrative monetary penalties. (source)

Related regulations

Put it into practice

Browse all regulations · Compliance deadlines · Latest updates