Digital Policy
Bill C-36 and the PPCDA: Canada Rewrites Its Privacy Law for the Third Time, with AI Data Governance Packed into a Consumer Protection Framework
The Canadian federal government has introduced the Protecting Privacy and Consumer Data Act (PPCDA) as Bill C-36, intended to replace PIPEDA, upgrading privacy enforcement from “advisory compliance” to binding orders, fines of up to 3%–5% of global revenue, and a private right of action for consumers, while addressing automated decision-making through transparency obligations rather than standalone AI legislation. This is a restructuring of the regulatory architecture, not merely an update of statutory provisions.
Bill C-36 and the PPCDA: Canada Rewrites Privacy Law for the Third Time, Packing AI Data Governance into a Consumer Protection Framework
The last substantive overhaul of Canada’s federal privacy law was completed before the internet had been thoroughly rewritten by smartphones and the data economy. More than two decades later, the federal government is again trying to replace it—this is already the third attempt.
1. The Event: Not Replacing a Law, but Rebuilding the Enforcement Architecture
On June 15, 2026, the Canadian government introduced Bill C-36. If passed, it will replace the Personal Information Protection and Electronic Documents Act (PIPEDA) with the Protecting Privacy and Consumer Data Act (PPCDA).
On the surface, this is a legal replacement; in substance, the changes are concentrated in three areas.
First, enforcement power shifts from “recommendation” to “order.” Under the PIPEDA framework, the Office of the Privacy Commissioner of Canada promotes compliance through investigations and recommendations. The PPCDA, by contrast, centralizes regulatory authority over privacy and digital security matters in a new body—the Canadian Digital Security and Data Protection Commission—which has three functional bodies:
- Privacy and Consumer Data Commissioner: investigates and informally resolves complaints, enters into compliance agreements, conducts audits, and issues notices of violation;
- Commission: issues binding orders;
- Privacy and Consumer Data Tribunal: handles dispute resolution.
Second, penalties and rights of action come online at the same time. The Commission may impose fines of up to CAD 10 million or 3% of global revenue (whichever is higher) on non-compliant organizations; for serious indictable offences—such as violating whistleblower protections, obstructing a privacy investigation, or violating data breach notification requirements—the maximum fine rises to CAD 25 million or 5% of global revenue. In addition, where the Commissioner makes a formal finding of violation and it is not overturned on appeal by a court, affected consumers gain a private right of action to claim damages for loss or injury.
Third, compliance shifts from “principles” to “documents.” The PPCDA requires organizations to establish privacy management programs that specify personal information protection measures, procedures for handling information requests and complaints, employee training requirements, and descriptions of relevant policies and procedures. Consent rules are tightened at the same time: consent must be valid and, in principle, express, with exceptions only where it is appropriate to rely on implied consent; organizations must inform individuals in plain language of the purposes and methods of collection, the reasonably foreseeable consequences, the specific types of information sought, and the names or types of third parties that may receive the information.
2. Why Now: The Path Choices Behind Three Attempts
To understand C-36, it must be placed back into the legislative sequence.Bill C-27 once proposed establishing a “Personal Information and Data Protection Tribunal,” assigning penalty and order-making powers to the tribunal while leaving investigations with the Privacy Commissioner—a model of “separation of investigation and adjudication,” accompanied by separate AI legislation. That path was not completed.
Bill C-34, the Safe Social Media Act, established the Digital Safety Commission and enacted the Digital Safety Act and the Digital Safety Commission of Canada Act.
C-36’s approach is to merge the previous two threads: it takes over C-34’s body, renames it the Digital Safety and Data Protection Commission, and adds privacy enforcement functions to it; at the same time, it abandons C-27’s separation model and no longer includes standalone AI regulatory legislation, instead addressing automated decision-making through transparency obligations.
The direction of this trade-off is clear: Canada is choosing “regulator consolidation + absorbing AI within the existing privacy framework,” rather than European-style centralized digital legislation or U.S.-style decentralized sectoral enforcement.
The PPCDA also provides a non-exhaustive list of factors the Commission must weigh when carrying out its duties, including: the purposes of the Act, the size and revenue of the organization, the volume and sensitivity of personal information controlled by the organization, the best interests of children, the importance of respecting Canada’s international trade obligations, supporting growth in Canada’s market economy, the importance of competition and innovation, and any other public interest matters.
III. What It Means for Canadian Industry
Compliance costs will rise structurally, but unevenly. Privacy management programs, privacy impact assessments before cross-border transfers, consent management, and explainable outputs for automated decision-making will all translate into fixed costs. For large enterprises with legal and privacy teams, this is process redesign; for SMEs and early-stage startups, it may be a variable affecting product cadence and financing cadence. By writing “organization size and revenue” and “volume and sensitivity of information” into enforcement considerations, the bill effectively recognizes at the statutory level the need for differentiated enforcement—this both buffers SMEs and hands discretion to the regulator.
Data reuse has gained a narrow opening. The PPCDA formally distinguishes “de-identified data” from “anonymized data”: anonymized data, after permanent modification such that no reasonably foreseeable risk of re-identification remains, falls outside the scope of the Act; de-identified data remains personal information, but organizations may use it for internal research and development without individual consent, while being explicitly prohibited from using de-identified data to re-identify individuals. For Canadian AI teams that rely on data training and model iteration, this boundary line may matter more than any penalty provision.
Data portability becomes a competitive tool. Individuals will have the right to require an organization to transfer their data securely and directly to another designated organization. Such “data mobility” frameworks are generally regarded internationally as a means of reducing switching costs and weakening the lock-in effects of incumbent platforms; their actual effect depends on interoperability standards rather than on the right itself.The right to deletion fills the tooling gap. PIPEDA grants individuals the right to access their data and challenge its accuracy, but lacks an explicit deletion tool. The PPCDA allows individuals to request disposal or deletion of personal information when consent is withdrawn or the data is no longer needed.
Cross-border data flows now come with a prior procedural requirement. Organizations must complete a privacy impact assessment before disclosing or transferring personal information outside Canada. For Canadian businesses that make extensive use of U.S. cloud infrastructure and data centers, this is a routine compliance step.
IV. What It Means for Global Tech Competition
Putting the PPCDA into an international frame of reference makes three trends clearer.
First, global privacy enforcement is shifting from “informed consent” to “accountability + risk.” The focus of compliance is no longer obtaining consent once, but continuously proving that organizations have the ability to manage risk—the privacy management program is a product of this approach.
Second, AI explainability is being absorbed into privacy law, rather than left to dedicated legislation. The PPCDA requires organizations that use automated decision-making systems or AI to make decisions that have a legal or significant impact on individuals to explain to individuals how the decisions are made, what data was used, and what major factors were involved. This is a form of “embedded” governance: rather than waiting for an AI law, it first uses the existing privacy framework to cover the most direct individual-rights risks. The cost is a relatively narrow scope—it constrains the external explanation of decisions, not model training, data sources, or systemic risk.
Third, tying fines to global revenue is already baseline practice. The PPCDA’s two tiers of 3% and 5% are on the same logical track as the European Union’s General Data Protection Regulation (GDPR), whose penalty design caps fines at a percentage of global annual turnover. The essence of this design is to align enforcement deterrence with a company’s global scale, rather than with the size of the local market.
V. What May Happen in the Next 3–10 Years
Short term (1–3 years): The bill still needs to go through the parliamentary process and has not yet taken effect. The real observation window is the first enforcement actions after it takes effect—how the Commission uses its order-making powers, how it defines the “overriding” standard in the “legitimate interest” exception, and how it handles privacy impact assessments that rely on that exception will determine whether this framework remains on paper or produces case law.
Medium term (3–5 years): The interpretive space for the automated decision-making explanation obligation will become a focus. What counts as a “legal or significant effect”? How should lines be drawn among recommendation systems, pricing systems, hiring screening, and credit assessment? Once these boundaries are defined through enforcement or judicial channels, they will directly determine the design constraints for Canadian AI products.Long term (5–10 years): Two structural tensions will persist. First is the layering of federal and provincial privacy laws—provincial regimes such as Quebec’s Bill 25 and British Columbia’s FIPPA operate in parallel with the federal framework, and businesses operating across provinces will face multiple sets of rules. Second is whether dedicated AI legislation is still necessary—when privacy laws take on some AI transparency functions, whether Canada will once again attempt standalone AI legislation like C-27, or maintain this embedded approach over the long term, will affect its position and credibility in international AI governance negotiations.
Conclusion: The Long-Term Trends Truly Worth Continued Attention
The essence of Bill C-36 and PPCDA is not an increase or decrease in compliance burden, but Canada laying the underlying regulatory infrastructure for a data-driven economy.
The strategic significance of this for Canada’s future tech industry lies in this: Canada is using “enforcement capacity” rather than “volume of legislation” to define its level of digital governance. Over the past two decades, PIPEDA has been widely seen as a framework lacking teeth; advisory compliance struggled to create deterrence and struggled to provide leverage in international interoperability negotiations. PPCDA concentrates investigation, orders, penalties, and a private right of action in a single agency, attempting to change that impression.
But the variable that truly determines success or failure is not in the text of the statute, but in two unanswered questions: whether the regulator can build professional capacity that matches the pace of technological evolution; and whether the narrow gate “de-identified data may be used for internal R&D” will ultimately be interpreted as a legitimate channel for AI training data, or as an exception tightened case by case.
If the former holds, Canada gains an underappreciated asset in global AI competition—a predictable, risk-based set of rules for data use; if the latter tightens, companies will be forced to move training and inference out of Canada, and the modernization of privacy law will instead become a push factor for industry outflow.
This, then, is the Canadian homework most worth tracking over the next decade.
Evidence route · canadatechdaily
canadatechdaily frames this note through Tech Canada / AI & Innovation / Clean Energy Tech: Tech Canada / AI & Innovation / Clean Energy Tech explains the local editorial angle. Source links should be opened before the summary is reused; dates, names and status changes still need checking.