Digital Policy
Bill C-36 and the PPCDA: Canada’s Third Privacy Law Overhaul Is Redrawing the Compliance Boundaries of the AI Era
The Canadian federal government has introduced the Protecting Privacy and Consumer Data Act as Bill C-36, proposing to replace PIPEDA, which has been in use for more than twenty years, with the PPCDA. This is not merely a legal update, but an institutional shift in which enforcement powers, data flows, and AI transparency rules are being reset at the same time.
On June 15, 2026, the federal government of Canada introduced Bill C-36. If passed, it would replace the Personal Information Protection and Electronic Documents Act (PIPEDA) with the Protecting Privacy and Consumer Data Act (PPCDA). According to the official text of the bill as introduced and law firm interpretations, this is the federal government's third, and possibly most forceful, attempt to modernize private-sector privacy law. It does not merely modify the rules; it rebuilds the regulator itself.
I. The Event Itself: Not an Amendment, but a Skeleton Replacement
Since its introduction in 2000, PIPEDA has long operated on a "recommendation—compliance" model: the Office of the Privacy Commissioner investigates complaints and makes recommendations, but lacks the power to directly issue binding orders and fines. The core change in the PPCDA is to centralize regulatory authority over privacy and digital safety matters in a new body—the Digital Safety and Data Protection Commission of Canada.
This Commission is the successor to the "Digital Safety Commission" established by Bill C-34, the Safe Social Media Act, and has been renamed and given expanded responsibilities, acquiring a further role beyond privacy enforcement and digital safety. With respect to privacy oversight, the PPCDA establishes three bodies:
- Privacy and Consumer Data Commissioner: investigates and informally resolves privacy complaints, enters into compliance agreements, conducts audits, and issues notices of violation;
- Commission: issues binding orders;
- Privacy and Consumer Data Division: handles dispute resolution.
This is clearly different from the approach of Bill C-27. C-27 sought to leave complaint investigations with the Privacy Commissioner and separately establish a "Personal Information and Data Protection Tribunal" responsible for financial penalties and orders; the PPCDA does not take this decentralized path, but instead lets the same Commission hold both investigation and enforcement powers.
II. Why Now: Three Threads Converge
First, the enforcement gap has long existed. For more than two decades, privacy enforcement in Canada's private sector has mainly relied on reputational mechanisms and voluntary compliance, gradually falling behind the regulatory intensity of major trading partners. The PPCDA explicitly writes "respecting Canada's international trade obligations" and "supporting economic growth, competition, and innovation in the Canadian market" into the factors for the Commission to consider in performing its duties, indicating that legislators face two simultaneous pressures: rules that are too weak would undermine credibility in cross-border data flows, while rules that are too heavy would squeeze domestic businesses.Second, AI governance has no place for standalone legislation. The PPCDA does not establish a separate artificial intelligence regulatory law; instead, it incorporates AI into the privacy framework and addresses it through transparency obligations: when using automated decision systems or AI to make decisions that have a legal or significant impact on individuals, organizations must explain to individuals how the decision was made, what data was used, and which main factors were involved. This is a pragmatic compromise—rather than enacting a new law, it first attaches enforceable obligations to the existing privacy regime.
Third, institutional integration. The PPCDA and Bill C-34 share the same committee, meaning Canada is placing platform governance, privacy enforcement, and data protection into the same regulatory container, rather than having each go its own way.
III. Five Key Threads at the Rules Level
Enforcement intensity. The committee may issue binding orders, with maximum fines of CAD 10 million or 3% of global revenue (whichever is higher). For serious indictable offences such as violating whistleblower protection, obstructing privacy investigations, or violating data breach notification requirements, the maximum is CAD 25 million or 5% of global revenue. The PPCDA also creates a private right of action: after the Commissioner makes a formal finding of a violation and it is not overturned on court appeal, affected consumers may seek compensation for loss or injury.
Tightening consent rules and expanding exceptions. Consent in principle must be valid and express; implied consent may be relied on only in appropriate circumstances. Organizations must inform individuals in plain language of the purpose of collection, the manner of collection, how information will be used or disclosed, the reasonably foreseeable consequences, the specific types of information sought, and the names or types of third parties who may receive the information. At the same time, the PPCDA introduces two new exceptions: first, “business activities and reasonable expectations,” namely collection or use that is within what a reasonable person would expect and is not used to influence an individual’s behaviour or decisions; second, “legitimate interests,” provided that the interest outweighs any reasonably foreseeable adverse effect on the individual, and the organization must identify the legitimate interest, conduct a privacy impact assessment, and take reasonable mitigation measures.
The formal boundary between de-identification and anonymization. Anonymized data is permanently modified so that re-identification cannot be reasonably foreseen, thereby falling outside the PPCDA; de-identified data remains personal information. Organizations may de-identify personal information without consent and use de-identified data for internal research and development, but may not use it to re-identify individuals.
Automated decision-making transparency. This is one of the ways the PPCDA addresses AI, and it is the first time Canada’s federal private-sector privacy law sets explicit explainability requirements for automated decision-making.Data Rights and Cross-Border Flows. Individuals will gain the right to request disposal or deletion of personal information when consent is withdrawn or the data is no longer needed, as well as a data portability right to require organizations to securely transfer data to another designated organization. Before disclosing or transferring personal information outside Canada, organizations must conduct a privacy impact assessment. In addition, organizations must establish a privacy management program covering safeguards, information request and complaint handling processes, employee training requirements, and descriptions of relevant policies.
IV. What It Means for Canadian Industry
The most direct impact is the rebuilding of compliance infrastructure. Privacy management programs, privacy impact assessments, legitimate interest assessments, de-identification processes, and automated decision-making explanation mechanisms—these are not one-time disclosure obligations but standing capabilities that need to be embedded in product and engineering processes. For large enterprises with mature legal teams, this is a cost; for startups with limited resources, it may become both a market entry barrier and a compliance credential when selling products to enterprise customers.
Second is data flow strategy. Privacy impact assessments before cross-border transfers will change how Canadian businesses evaluate foreign cloud services and cross-border data pipelines. In contrast, the combination of data portability and deletion rights will put pressure on product designs that rely on data retention, but will also create market demand for compliance tools, data governance, and privacy engineering.
Third, the gray area of AI training data is partially illuminated. De-identified data can be used for internal R&D, which is materially significant for Canada's AI ecosystem; but the red line of "no re-identification" also draws boundaries for dataset construction and reuse.
V. Placing It in Global Technology Competition
In terms of institutional orientation, the PPCDA is closer to the modern model in which regulators have binding order and penalty powers, rather than PIPEDA's advisory framework; at the same time, it does not take the EU-style route of standalone AI legislation, but instead embeds AI transparency requirements in privacy law. This constitutes a Canadian-style middle path: moving toward high standards in data protection while maintaining a lighter independent legislative burden in AI regulation.
The consequences cut both ways. For multinational companies, Canada may shift from a "low-friction jurisdiction" to a "compliance jurisdiction that requires separate modeling," which increases costs but also strengthens the persuasiveness of Canada's claim as a trusted data destination. For domestic companies, whether they can build compliance capabilities before being penalized will directly affect their ability to take on business from more strictly regulated markets.
VI. Possible Trajectories Over the Next Three to Ten YearsBill C-36 has not yet come into force, and its final form will depend on parliamentary review. Several directions can reasonably be expected: in its early days, the Commission will most likely focus on guidance and compliance agreements, gradually shifting to actual enforcement cases; coordination issues between the private-sector privacy law, provincial laws, and the Bill C-34 digital safety regime will continue to arise; the first contentious cases may emerge around the boundaries of the "legitimate interest" exception; and the enforcement standards for AI transparency obligations will likely be clarified gradually through individual cases rather than detailed rules.
Over a longer time horizon, what is truly worth watching is whether Canada will make the PPCDA the long-term anchor for AI governance, or layer dedicated AI legislation on top of it. That choice will determine where Canada ultimately lands between "regulatory certainty" and "speed of innovation."
Conclusion: Why This Is Strategically Significant for Canada's Technology Industry
The strategic significance lies not in how high the maximum fines are, but in the changed nature of regulatory capacity. In PIPEDA-era Canada, privacy regulation was a consultative relationship; the PPCDA seeks to turn it into an enforceable legal relationship and, for the first time, writes the obligation to explain AI decisions into federal private-sector rules.
For Canada's AI and digital industries, this means two things happening at once: compliance shifts from an "after-the-fact statement" to "part of the product architecture"; and data governance capability shifts from a legal cost item to a competitive factor that may affect financing, enterprise customer procurement, and international data cooperation. In an environment where cross-border data flows and AI system deployment move far faster than legislative cycles, Canada's choice to use privacy law to take on AI governance is a pragmatic decision and a bet that puts institutional credibility on the line. Whether it holds depends on whether enforcement is predictable—and that is precisely the variable most worth tracking over the next five years.
Evidence route · canadatechdaily
canadatechdaily frames this note through Tech Canada / AI & Innovation / Clean Energy Tech: Tech Canada / AI & Innovation / Clean Energy Tech explains the local editorial angle. Source links should be opened before the summary is reused; dates, names and status changes still need checking.