The federal government has introduced legislation to replace Canada's 25-year-old commercial privacy laws with a new regulatory regime that treats privacy as a fundamental human right, restricts corporate surveillance pricing, and establishes a unified digital regulator with the power to levy penalties of up to $25 million or 5 percent of global revenue.
Titled the Protecting Privacy and Consumer Data Act (PPCDA) and tabled in the House of Commons as Bill C-36, the proposed law repeals Part 1 of the Personal Information Protection and Electronic Documents Act (PIPEDA), which has governed Canada's commercial data transactions since 2000.
Sponsored by the Honourable Evan Solomon, Minister of Artificial Intelligence and Digital Innovation, the bill is currently at second reading in the House of Commons. It is the federal government's third attempt to reform private-sector privacy rules in six years, following the expiration of Bill C-11 in 2021 and Bill C-27 in January 2025. Bill C-36 is a legislative pillar of the federal government's national strategy, AI for All: Canada's National Artificial Intelligence Strategy, launched on June 4, 2026, by Prime Minister Mark Carney.
"Canadians deserve strong privacy protections in a rapidly changing digital world," Minister Solomon said when introducing the bill. "The Protecting Privacy and Consumer Data Act will give Canadians more control over their personal information, strengthen protections for children and give businesses clearer rules to innovate responsibly. This is how we build trust in new technologies, including AI, by making sure Canadians know their data is protected and companies are accountable."
For background on the predecessor legislation and why it failed to pass, see Why Canada's Bill C-27 Died in Parliament.
What is Bill C-36?
Bill C-36 reorganizes federal data protection and digital regulation across four distinct parts:
- Part 1: The Protecting Privacy and Consumer Data Act (PPCDA): The new commercial data protection statute that replaces Part 1 of PIPEDA. It governs how companies collect, use, disclose, and retain personal information during commercial activities.
- Part 2: The Electronic Documents Act: Repeals Part 1, Parts 3 to 5, and Schedules 1 and 4 of PIPEDA, renaming the remaining statute as the Electronic Documents Act to regulate federal public sector electronic documents.
- Part 3: The Digital Safety and Data Protection Commission of Canada Act: Amends the Digital Safety Commission of Canada Act to rename the regulator the Digital Safety and Data Protection Commission of Canada. This creates a single regulator responsible for both digital safety and private-sector privacy.
- Part 4: Consequential and Coordinating Amendments: Adjusts related federal laws, including the Access to Information Act, Competition Act, Telecommunications Act, Broadcasting Act, and Canada Evidence Act, to enable joint investigations and regulatory coordination.
Privacy as a Fundamental Human Right
A central change in Bill C-36 is the legal baseline established in Section 5 of the PPCDA.
Under PIPEDA, the statutory purpose balanced an individual's right to privacy against an organization's commercial need to process personal information. Section 5 of the PPCDA alters this balance by explicitly recognizing privacy as a fundamental human right:
"The purpose of this Act is to establish, in an era in which data is constantly flowing across borders and geographical boundaries and significant economic activity relies on the analysis, circulation and exchange of personal information, rules to govern the protection of personal information in a manner that recognizes the fundamental right of privacy of individuals with respect to their personal information and the need of organizations to collect, use or disclose personal information for purposes that a reasonable person would consider appropriate in the circumstances."
Philippe Dufresne, the Privacy Commissioner of Canada, issued a formal statement on June 15, 2026, welcoming the provision:
"The tabling of Bill C-36 represents a pivotal step for privacy in Canada," Dufresne stated. "I am pleased to see many of my recommendations reflected in the new Bill. In particular, I welcome proposals to recognize privacy as a fundamental right, an explicit recognition of the best interests of children, requirements to conduct privacy impact assessments, and stronger enforcement powers."
Strict Protections for Children's Data
Bill C-36 introduces Canada's first dedicated statutory code for minors under 18 years of age:
- Statutory Definition (Section 2): Defines a "child" as any individual under 18 years of age.
- Heightened Expectation of Privacy (Section 4): Automatically classifies a child's personal information alongside health, genetic, and biometric data as information carrying a heightened expectation of privacy.
- Exercise of Rights (Section 4): Allows parents, guardians, or tutors to exercise privacy rights on behalf of a child, unless the child chooses to exercise those rights independently and is capable of doing so.
- Non-Derogable Right to Erasure (Section 54(2)(d)): While businesses may reject an adult's deletion request if destroying data would disrupt an ongoing product or service, Section 54(2)(d) explicitly bars businesses from using this defense against children. Minors have an absolute right to demand data disposal.
- Guiding Principle for Regulators (Sections 86(d) and 90(d)): Directs the Commission and the Commissioner to make "the best interests of children" a mandatory consideration in every investigation, guideline, audit, and penalty determination.
Automated Decisions, Profiling, and Surveillance Pricing
The legislation places statutory limits on algorithmic profiling and artificial intelligence systems:
1. Limits on Business Consent Exceptions (Section 18)
Section 18 permits organizations to collect and use personal information without consent for specific routine business activities (such as product delivery, system security, and product safety) or for legitimate commercial interests. However, the section contains a strict limitation:
- Personal information collected under these exceptions cannot be collected or used to influence an individual's behaviour or decisions.
- Organizations cannot rely on business activity exceptions to run predictive behavioural advertising or profiling without express consent.
- According to government briefing documents, this restriction directly prohibits "surveillance pricing," where companies dynamically raise prices based on automated profiling of an individual's browsing habits, location, or perceived willingness to pay.
2. Mandatory Privacy Impact Assessments for Legitimate Interests (Section 18(4))
To rely on the "legitimate interest" exception to consent, an organization must first complete a documented Privacy Impact Assessment (PIA). The organization must identify foreseeable adverse impacts on the individual and implement measures to reduce those risks.
3. Right to an Explanation for Automated Decisions (Section 63)
Under Section 63(4), any individual subjected to an "automated decision system" that makes a prediction, recommendation, or decision carrying a legal or similarly significant effect (such as loan approvals, hiring screenings, or insurance rates) can request an explanation.
The organization must provide a plain-language explanation detailing:
- The types of personal information used;
- The source of that personal information; and
- The principal factors that led to the prediction, recommendation, or decision.
Cross-Border Data Transfers and Digital Sovereignty
Section 57 of the PPCDA establishes new requirements before personal data can leave Canada:
- Mandatory Prior Assessment (Section 57(1)(a)): An organization must conduct a formal Privacy Impact Assessment before transferring or disclosing personal information outside Canada. The assessment must evaluate the recipient jurisdiction's legal frameworks and potential data security risks.
- Mandatory Risk Mitigation (Section 57(1)(b)): The transferring organization must implement contractual privacy protections, adhere to approved codes of practice, or adopt certified compliance mechanisms to mitigate foreign access risks.
- Regulatory Inspection (Section 57(2)): The organization must provide a copy of its cross-border PIA to the Commission upon request.
A Unified Digital Regulator: The Digital Safety and Data Protection Commission
Bill C-36 eliminates the separate administrative tribunal proposed under the previous Bill C-27, replacing it with a consolidated regulatory authority.
The parent regulatory body, the Digital Safety and Data Protection Commission of Canada, consists of five full-time members appointed by the Governor in Council. The Commission operates through two specialized divisions:
| Division | Legislative Mandate | Leadership and Responsibilities |
|---|---|---|
| Digital Safety Division | Digital Safety Act (originating in digital safety and online harms legislation, alongside Bill C-34) | Regulates online platform duties, synthetic content, automated chatbots, and online child safety. |
| Privacy and Consumer Data Division | Protecting Privacy and Consumer Data Act (PPCDA) | Investigates commercial privacy violations, reviews cross-border data transfer assessments, and conducts compliance audits. Led by the designated Privacy and Consumer Data Commissioner (Section 85). |
Structure and Operations
- Five Full-Time Members: Part 3 of the bill amends the Digital Safety Commission of Canada Act to establish the Commission as a unified, arm's-length regulatory body.
- Dual Mandate: By housing privacy and digital safety in one commission, the law creates coordinated oversight for overlapping issues such as biometric age assurance, generative AI tools, and children's data exploitation.
- The Privacy and Consumer Data Commissioner (Section 85): The Governor in Council designates one Commission member as the Privacy and Consumer Data Commissioner to oversee enforcement, compliance agreements, and audits under the PPCDA.
- Specialized Division (Section 89): The Privacy and Consumer Data Division, consisting of the Commissioner and assigned Commission members, manages day-to-day commercial data enforcement.
Enforcement Powers and Financial Penalties
The Commission possesses direct order-making and financial penalty powers, removing the multi-tier enforcement delays that characterized prior reform proposals.
| Enforcement Tool | Statutory Section | Scope and Penalties |
|---|---|---|
| Binding Compliance Orders | Section 110(1) | Order an organization to halt unlawful activity, adopt compliance measures, or publish public corrections. |
| Interim Injunctions | Section 121(1) | Issue urgent interim orders in exigent circumstances during ongoing proceedings. |
| Administrative Monetary Penalties (AMPs) | Sections 113 & 114 | Directly imposed by the Commission up to $10,000,000 or 3% of gross global revenue, whichever is greater. |
| Penal Fines (Criminal Offenses) | Section 145 | For knowing contraventions, breach concealment, or obstruction: indictable fines up to $25,000,000 or 5% of gross global revenue (summary conviction: up to $20,000,000 or 4%). |
| Private Right of Action | Section 132 | Direct statutory right for individuals to sue non-compliant companies in Federal Court or provincial superior courts for damages once a violation finding is final. |
Comparison: PIPEDA vs. Bill C-27 vs. Bill C-36
| Dimension | PIPEDA (In Force Since 2000) | Bill C-27 (Died January 2025) | Bill C-36 / PPCDA (Tabled June 2026) |
|---|---|---|---|
| Statutory Purpose | Balances individual privacy against business data needs. | Balanced individual privacy against commercial necessity. | Explicitly recognizes privacy as a fundamental human right (Section 5). |
| Children's Data | No specific statutory definition; governed by general sensitivity rules. | Minors' data recognized generally as sensitive. | Dedicated children's code (<18); heightened protection; mandatory best interests of children standard; non-derogable deletion rights. |
| Regulatory Body | Office of the Privacy Commissioner (OPC) acts as an ombudsperson. | Two-tier model: OPC investigates; separate administrative tribunal levies penalties. | Unified Digital Safety and Data Protection Commission with direct order-making and penalty powers. |
| Maximum Fines | Up to $100,000 for narrow summary offences. | Greater of $10M or 3% global revenue (AMPs); $25M or 5% for criminal offences. | Greater of $10,000,000 or 3% gross global revenue (AMPs); greater of $25,000,000 or 5% gross global revenue for criminal offences. |
| Cross-Border Transfers | Governed by general accountability principle and contractual clauses. | Treated as routine transfers to service providers without separate consent. | Mandatory Privacy Impact Assessment (PIA) and risk mitigation prior to transfer; mandatory disclosure of PIA to regulator on demand. |
| Automated Decisions | Not addressed in statute. | Right to request general explanation of automated decision systems. | Comprehensive right to plain-language explanation of factors, inputs, and logic for decisions with significant effects. |
| Surveillance Pricing | Governed under broad reasonable expectation tests. | Exceptions allowed with limited restrictions. | Strict statutory bar: Exceptions to consent are completely invalid if data is used to influence individual behaviour or decisions. |
| AI Legislation | Not addressed. | Included the Artificial Intelligence and Data Act (AIDA) within the bill. | Decoupled: Standalone AI statute removed; AI industrial policy governed under AI for All strategy; algorithmic fairness kept in PPCDA. |
Next Steps in Parliament
"As technologies evolve, protecting Canadians' privacy and ensuring online safety, especially for children, are shared priorities across government," said the Honourable Marc Miller, Minister of Canadian Identity and Culture, noting the planned coordination between Bill C-36 and the government's Safe Social Media Act (Bill C-34).
Bill C-36 is currently at second reading debate in the House of Commons. Following the conclusion of second reading, the bill will be referred to the Standing Committee on Industry and Technology (INDU) for clause-by-clause review and witness testimony from legal scholars, industry representatives, and civil liberties organizations.
Official Texts and Primary Sources
- Full Text of Bill C-36 (First Reading): The official statutory text as introduced in the House of Commons.
- Official PDF of Bill C-36: House of Commons first reading print version (45th Parliament, 1st Session).
- LEGISinfo Bill Tracker for Bill C-36: Parliamentary tracking of legislative stages, sittings, debates, and committee referrals.
- Government of Canada News Release: Official tabling announcement from Innovation, Science and Economic Development Canada (June 15, 2026).
- Government of Canada Backgrounder: Detailed technical backgrounder on the Protecting Privacy and Consumer Data Act.
- Office of the Privacy Commissioner Statement: Official statement by Privacy Commissioner of Canada Philippe Dufresne on Bill C-36.
- Canada's National Artificial Intelligence Strategy: AI for All: Official policy strategy setting the national framework for AI adoption, digital safety, and privacy reform.
