Table of Contents [TOC]

{tocindex article="current"}

Privacy laws

Menu

  • Pricing
  • Features
    • Regulation compliance
    • GDPR (EU)
    • CCPA (California)
    • PIPEDA (Canada)
    • LGPD (Brasil)
    • KVKK (Turkey)
    • POPIA (South Africa)
    • The basics
    • 42 languages
    • User consents recording
    • Third-party cookie blocking
    • Geo targeting
    • Cookie Banner
    • Google Consent Mode v2
    • Automation
    • Automatic monthly scans
    • Automatic script blocking
    • Advanced reporting
    • Cookie Banner sharing
    • IAB TCF 2.3 integration
    • Google-certified CMP
  • Resources
    • Cookie Scanner
    • Privacy Policy Generator
    • System status
    • Roadmap
    • Changelog
  • Blog
    • Guides
    • News
    • GDPR & CCPA
    • Privacy laws
    • Compare
    • Knowledge base
  • Support
    • Help Center
    • Integrations
    • Contact us
    • Feature request
  • For partners
    • Agencies
    • Affiliates
  • separator
  • Language switcher
    • Profile
    • Billing
    • My plan
  • Sign in
  • Try now
 
  • Guides
  • News
  • GDPR & CCPA
  • Privacy laws
  • Compare
  • Knowledge base
Details
02 October 2026

Canada's Bill C-36: What It Means for Businesses

ON THIS PAGE

  • What Is Canada's Bill C-36?
  • Who Would Need to Comply with Canada's Bill C-36?
    • Biil C-36 exclusions
  • Key Changes to Canada’s Privacy Law
    • Stronger privacy accountability
    • Privacy management programs
    • Clearer consent requirements
    • Greater responsibility for service providers
    • Increased standards for children's data
    • New rules around automated decision-making
    • New rules for de-identification and anonymization
    • New requirements for cross-border data transfers
    • Stronger enforcement and financial penalties
  • Steps Businesses Can Take to Prepare for Bill C-36
  • Final Thoughts
  • Frequently Asked Questions

On June 15, 2026, Canada introduced Bill C-36, which would enact the Protecting Privacy and Consumer Data Act (PPCDA). Bill C-36 still has to move through Parliament. If passed, the PPCDA would replace Part 1 of the Personal Information Protection and Electronic Documents Act (PIPEDA).

The bill proposes new rules governing how organizations collect, use, disclose, protect, and manage Personal Information in commercial activities.

For businesses operating in Canada and organizations that handle Canadian consumers' personal information, the proposed legislation could create new compliance responsibilities. These include stronger accountability requirements, clearer consent rules, greater transparency around automated decision-making, and enhanced protections for sensitive data, including children’s personal information.

The blog article presents the key changes proposed by Bill C-36.

What Is Canada's Bill C-36?

Canada’s Bill C-36 is proposed federal legislation that would enact the Protecting Privacy and Consumer Data Act (PPCDA). If enacted, it would replace Part 1 of PIPEDA with a new privacy framework.

If passed, the proposed legislation would create a new law called the Protecting Privacy and Consumer Data Act (PPCDA), replacing PIPEDA, Canada's current data privacy law. Its stated purpose is to establish rules for protecting personal information while recognizing both individuals' privacy rights and organizations' legitimate need to collect, use, and disclose information for appropriate commercial purposes.

The bill would create new rules for user consent management, data governance, automated decision-making systems, and cross-border data transfers.

Under the proposed framework, organizations would be responsible for personal information they collected from users even when third-party service providers process that information on their behalf. Organizations would also be required to implement formal privacy management programs and designate individuals responsible for privacy compliance.

Canadian privacy law for businesses also introduces stronger enforcement and penalties.

Bill C-36 is not yet an active law— it still has to be approved by Parliament.

Note: Do not confuse Bill C-36 with an earlier bill carrying the same number. A previous Bill C-36 introduced in 2021 is related to hate propaganda, hate crimes, and hate speech. The 2026 Bill C-36 discussed here concerns users' online privacy and consumer data protection.

Who Would Need to Comply with Canada's Bill C-36?

Bill C-36 would apply to organizations that collect, use, or disclose personal information of Canada’s residents during commercial activities, including information transferred between provinces or internationally.

Businesses located outside Canada may also fall within its scope if they handle the personal information of individuals in Canada.

This means the legislation could be relevant to a broad range of organizations, including:

  • E-commerce stores and online retailers;
  • Technology companies and SaaS providers;
  • Financial services companies;
  • Telecommunications businesses;
  • Advertising and marketing platforms;
  • Businesses operating mobile apps and digital platforms;
  • Companies using customer analytics or artificial intelligence;
  • Organizations that transfer personal data to vendors or cloud providers.

 

The proposed Act specifically covers personal information handled in commercial activities. It would also apply to certain employee and job applicant information handled by federally regulated businesses.

Biil C-36 exclusions

The bill contains several exclusions, including:

  • Federal government institutions already subject to the Privacy Act;
  • Individuals handling information solely for personal or domestic purposes;
  • Certain journalistic, artistic, or literary activities;
  • Anonymized information, as required by the law.

Key Changes to Canada’s Privacy Law

Bill C-36 introduces stronger privacy accountability, clearer consent requirements, greater responsibility for service providers, higher standards for children's data, new rules on automated decision-making and cross-border data transfers, and requires privacy management programs.

If enacted, the bill would introduce these Bill C-36 requirements for companies:

Stronger privacy accountability

Accountability would become central to compliance. Organizations would be responsible for personal information under their control, including information handled by third-party service providers that process it on their behalf.

The bill would require organizations to:

  • Designate one or more individuals responsible for privacy compliance.
  • Maintain a privacy management program.
  • Implement privacy policies and procedures.
  • Train employees on privacy practices.
  • Establish processes for handling complaints and requests.

Privacy management programs

Organizations would need to establish and maintain a formal privacy management program. The program should include privacy policies, practices, and procedures for:

  • Data protection
  • Complaint handling
  • Employee training
  • Documentation explaining privacy policies and procedures.

The program's scale would need to reflect the volume and sensitivity of personal information the organization handles.

Clearer consent requirements

Consent would remain required for collecting, using, or disclosing personal information.

To collect valid consent, organizations would need to explain to individuals the purposes for processing their data, the types of personal information involved, how the information will be used or disclosed, and how individuals could object to data processing.

Organizations will be required to present a privacy notice in language reasonably understandable by individuals.

The bill would also require organizations to limit data processing beyond what is necessary to provide a requested product or service.

Greater responsibility for service providers

When transferring personal information to a service provider, organizations must implement an adequate level of data protection.

This could be achieved through contracts or other mechanisms. Thus, vendor risk assessments, data-processing agreements, and contracts would become more important for businesses using cloud services, CRM platforms, payment processors, marketing providers, and other third parties.

Increased standards for children's data

Bill C-36 creates higher standards and compliance obligations for handling children's data, since children's personal information would be classified as sensitive information.

The PPCDA defines a child as an individual under 18 years of age.

New rules around automated decision-making

Bill C-36 addresses growing concern about artificial intelligence and automated decision-making.

Organizations would have to disclose general information about their use of automated systems that make predictions, recommendations, or decisions about individuals where those decisions could have legal or similarly significant effects.

When automated decision-making is used to make a significant decision about an individual, they could request an explanation describing the personal information used and how the result was achieved.

These requirements may be particularly relevant to lending, insurance, employment, fraud prevention, or finance businesses that use AI or automated systems regularly.

New rules for de-identification and anonymization

Bill C-36 distinguishes between de-identified and anonymized information and set different requirements for these types of information.

  • Anonymized information is permanently and irreversibly modified information so that individuals cannot reasonably be identified. Handling of anonymized information will not be regulated by Canada’s privacy regulation.
  • De-identified information means that direct identifiers are removed, but the risk of re-identification still exists. Organizations must use technical and administrative methods to lower re-identification risks, related to the data's sensitivity and purpose. De-identified information remains personal information and would therefore be regulated under Bill C-36, meaning organizations must still protect it and follow compliance requirements.

New requirements for cross-border data transfers

Cross-border data processing is another area that has new regulations. Organizations transferring personal information outside Canada must ensure that service providers offer data protection and must comply with applicable transparency and safeguard obligations under the law.

Bill C-36 introduces mandatory requirements for information transferred or disclosed outside Canada.

Key cross-border transfer requirements include:

  • Mandatory Privacy Impact Assessment (PIA)
    Organizations must complete a documented PIA under Section 57 before transferring or disclosing personal information internationally.
  • Scope of assessment
    The PIA must evaluate the categories of data, transfer purposes, the destination country’s legal environment, contractual and technical safeguards, and any foreseeable residual risks.
  • Risk mitigation
    Organizations must implement active measures to protect data transferred abroad, such as robust contractual privacy protections or adherence to approved codes of practice and certification processes.
  • Regulator access
    Companies must provide a copy of or access to their cross-border PIA to the Digital Safety and Data Protection Commission upon request.
  • Ongoing accountability
    Organizations remain responsible for personal information processing, regardless of where they are based and in cases when they share information with third parties.

 

Note that the bill includes strict requirements for international transfers and for information transferred between provinces. This means that organizations should assess what personal information they process, why they process it, and whether information moves between provinces or across international borders.

Stronger enforcement and financial penalties

The proposed legislation would introduce significant financial consequences for certain violations.

The amendment would establish the Digital Safety and Data Protection Commission of Canada, which would administer the bill and have the authority to issue binding orders.

Breaches of Bill C-36 could reach penalties up to:

  • CAD $10 million or 3% of global annual revenue from the preceding financial year, whichever is greater
  • CAD $25 million or 5% of global annual revenue, whichever is greater, for the most serious offences.

 

This would be a substantial increase from Canada's current enforcement framework.

The legislation also provides for investigations, audits, compliance agreements, and orders requiring organizations to take corrective measures.

Use a Consent Management Platform (CMP) like CookieScript to comply with PIPEDA, Bill C-36, and other privacy laws globally, and avoid penalties for non-compliance.

In 2025, CookieScript received its fourth consecutive badge in a row as the leader on G2, a peer review site, and became the best CMP on the market for a whole year!

Register for free Show pricing plans

Steps Businesses Can Take to Prepare for Bill C-36

Although Bill C-36 has not yet become final law, businesses can begin reviewing their privacy practices now.

Take these steps to prepare for Bill C-36:

  1. Conduct a data audit
    Start by conducting a comprehensive data inventory. Identify all personal data you collect, process, and store, where it comes from, why it is used, who has access to it, and which third parties receive it.
  2. Obtain valid consent
    Review your privacy notices and consent mechanisms. Provide transparent privacy notices, so that customers should be able to understand what information you collect, for what reasons, and how to object to the collection.
  3. Establish a privacy management program
    This can include documented policies, breach-response procedures, employee training, complaint-handling processes, data retention schedules, and clearly assigned responsibility for privacy compliance.
  4. Assess vendor relationships
    Identify service providers that handle personal information and determine whether they provide appropriate privacy and security protections.
  5. Review AI or automated decision-making
    Document AI or automated decision-making systems, how they work, what data they use, and how the result is reached. When their output could significantly affect individuals, allow for meaningful human review.
  6. Strengthen children's privacy protections
    If you collect information from children, review your data collection practices and prepare for heightened expectations.

Final Thoughts

Bill C-36 represents a major shift in Canadian privacy law. It focuses on personal information management, organizational accountability, meaningful consent, automated decision-making, vendor oversight, and stronger enforcement.

Businesses should be able to demonstrate that they can identify and manage privacy risks throughout the data lifecycle.

Monitor Bill C-36 as it moves through Parliament. The legislation may be amended before becoming law. Preparing early can help organizations get ready before new obligations become enforceable and can also strengthen customer trust, data governance, and cybersecurity practices regardless of the bill's final form. Privacy teams, legal departments, security professionals, and business leaders should work together to manage personal information flows in a compliant way.

Frequently Asked Questions

What is Canada’s Bill C-36?

Canada’s Bill C-36 is proposed federal legislation that would enact the Protecting Privacy and Consumer Data Act. It is intended to modernize rules governing the collection, use, disclosure, and protection of personal information in commercial activities. If enacted, it would replace Part 1 of PIPEDA with a new privacy framework.

Which businesses would need to comply with Bill C-36?

Bill C-36 would generally apply to organizations that collect, use, or disclose personal information in the course of commercial activities. It would affect e-commerce stores and online retailers, technology companies and SaaS providers, financial services companies, telecommunications businesses, advertising and marketing platforms, businesses operating mobile apps and digital platforms, and other businesses.

How can businesses prepare for Canada’s Bill C-36?

Start by conducting a comprehensive data inventory, then obtain valid consent, establish a privacy management program, assess vendor relationships, review AI or automated decision-making, strengthen children's privacy protections, and use a CMP like CookieScript for consent management.

 
  • About CookieScript
  • Terms of Service
  • Privacy Policy
  • Pricing
  • Resources
  • Cookie Scanner
  • Privacy Policy Generator
  • System status
  • Sitemap
  • Changelog
  • Alternatives
  • CookieBot
  • Termly
  • OneTrust
  • Iubenda
  • Cookie Information
  • CookieFirst
  • Illow
  • Blog
  • Guides
  • News
  • GDPR & CCPA
  • Privacy laws
  • Knowledge base
  • Support
  • Help center
  • Contact us
  • Integrations
  • Request a feature
  • Roadmap
  • For Partners
  • For agencies
  • For Affiliates

Copyright ©2026 CookieScript


main version