Digital Policy
Bill C-36: Canada's Privacy Reform Makes Third Attempt, Strategic Considerations Behind AI's Absence
In June 2026, the Canadian federal government introduced Bill C-36, proposing to replace PIPEDA with new legislation, marking the third privacy reform attempt in six years. Unlike previous efforts, this bill does not bundle AI legislation and consolidates regulatory bodies, while opening exceptions for AI training data. This article analyzes the strategic logic behind it and its impact on industry.
On June 15, 2026, the Canadian federal government once again launched reform of private-sector privacy law. Bill C-36, introduced by newly appointed "Minister for Artificial Intelligence and Digital Innovation" Evan Solomon, proposes to replace the more than two-decade-old PIPEDA with the "Protecting Privacy and Consumer Data Act" (PPCDA). This is the third attempt in six years, following C-11 in 2020 and C-27 in 2022. The previous two bills both "died" because they were unable to complete their passage through Parliament. On the surface, this is just a repeated legislative effort, but a deeper look at the content and timing of Bill C-36 reveals that Canada is adjusting its overall digital governance strategy: the decoupling of privacy reform from AI regulation, the consolidation of regulatory authority, and the creation of exceptions for AI training data all show that Ottawa is trying to find a new balance between protecting citizens and controlling regulatory burden.
Three Times in Six Years: Why Is Reform So Difficult?
Canada's privacy law reform has been difficult. PIPEDA's basic framework has remained unchanged since it took effect, while the digital economy has undergone earth-shaking change. The implementation of GDPR and the emergence of Quebec's Law 25 have put pressure on the federal level to adopt unified standards. However, the failure of C-11 and C-27 was not due to a lack of consensus, but to overly broad legislative scope and unfavorable political cycles. C-27 in particular tied privacy reform to AI regulation (AIDA), and AIDA's controversial nature became a drag on the entire bill. Industry, academia, and civil society disagreed on the strictness and jurisdictional boundaries of AI regulation, causing the bill to stall at the committee stage. This time, Bill C-36 simply strips out AI entirely and deals only with privacy—clearly a lesson learned from past failures.
What's Different This Time: AI Absence and a New Regulator
The most notable difference between Bill C-36 and C-27 is that it no longer contains a standalone AI act. This does not mean AI is unimportant, but rather that the government has chosen to address it separately in the "National AI Strategy" released on June 4. That strategy explicitly mentions the need to modernize privacy law, yet remains silent on AI legislation. This means Canada will not introduce comprehensive AI regulation like the EU's Artificial Intelligence Act in the short term, but will rely on existing laws, including the forthcoming updated privacy law, to address AI risks. Another major change is the consolidation of regulatory architecture. Bill C-36 proposes moving private-sector privacy oversight from the Office of the Privacy Commissioner (OPC) to a new, not-yet-established body called the "Digital Safety and Data Protection Commission." This commission grows out of the online harms bill C-34 currently under consideration, meaning privacy and personal data protection will be merged with online safety regulation. This "one commission, multiple mandates" model is unprecedented in Canada, intended to reduce regulatory fragmentation, but it also raises concerns about the concentration of power.
Industry Impact: Compliance Adjustments and AI Training ExceptionsFor businesses, the PPCDA retains most of the core provisions from the earlier draft: it is consent-based, but adds exceptions such as "commercial activities" and "legitimate interests"; it distinguishes between de-identification and anonymization, with anonymized information not subject to the law and the standards relaxed; the breach notification requirement still uses the "real risk of significant harm" standard. The most notable change is the explicit permission to train AI models on publicly available information under certain conditions without obtaining consent. This exception directly responds to the AI industry's demand for data access. Of course, this exception is not unlimited: it must align with reasonable expectations and must not be used to influence individual behavior or decisions. This means AI companies can freely use publicly available online data to a certain extent, but still need to handle sensitive information with caution. At the same time, because provincial privacy laws in Canada still exist, businesses will face an even more complex compliance puzzle after the federal bill passes.
Significance for Canada: A Piece of the Digital Strategy
The privacy reform bill was introduced two weeks after the release of the AI strategy—a telling piece of timing. A modern, predictable privacy law is the foundation of a country's AI competitiveness. Canada has a strong AI research ecosystem, but commercialization has long been constrained by insufficient data liquidity and vague rules. If Bill C-36 passes, it will provide a unified federal framework, especially the AI training exception, which is expected to attract more businesses to keep data processing in Canada. Additionally, merging privacy regulation with digital security reflects the government's desire to address digital risks in a "one-stop" manner and improve enforcement efficiency. However, this may also cause privacy protection to be marginalized in security-first discourse, which warrants continued attention.
Global Trends and Future Outlook
Canada is not alone. Global privacy regulation is moving toward a mix of "Europeanization" and "localization." The GDPR has become the de facto benchmark, but countries make adaptive modifications in the details. Canada's introduction of a GDPR-style legitimate-interest exception, without fully copying it, reflects pragmatism. At the same time, AI regulation is showing a trend from comprehensive legislation toward industry-embedded regulation. The United States still lacks unified privacy legislation at the federal level, while the EU's AI regulatory framework has just landed. Canada chose privacy first, then AI, to avoid another impasse over a massive "super bill." In the next 3 to 10 years, we can expect that many details of the PPCDA will be left to subsequent regulations, such as the data mobility framework and cross-border transfer rules, which will determine whether Canada can maintain an "adequacy decision" with the EU and thus sustain cross-border data flows. The role of the new regulatory commission will also gradually become clear; its enforcement strength and rule-making will shape the long-term direction of Canada's digital market.
Long-Term Trends: The Strategic Fulcrum of Data GovernanceThe next battlefield of privacy reform is not on Parliament Hill, but in regulators' rule-making authority. Bill C-36 itself is a framework; what truly affects the industry are the regulations introduced afterward. Enterprises should abandon a "wait-and-see" mindset and adjust their data compliance systems in advance in line with the draft requirements of the PPCDA, particularly regarding de-identification and the management of AI training data. For Canada, the success of this legislation concerns not only privacy, but also whether it can establish a data advantage in the global AI race. If Canada can build a data governance system that both protects citizens' rights and supports innovation, it will become a "rule bridge" in the digital age—and that is precisely where its strategic significance lies.
Evidence route · canadatechdaily
canadatechdaily frames this note through Tech Canada / AI & Innovation / Clean Energy Tech: Tech Canada / AI & Innovation / Clean Energy Tech explains the local editorial angle. Source links should be opened before the summary is reused; dates, names and status changes still need checking.