Michael Walsh
Associate
Article
9
On June 15, 2026, the Honourable Evan Solomon, Minister of Artificial Intelligence and Digital Innovation, introduced Bill C-36 in the House of Commons.
Formally titled An Act to enact the Protecting Privacy and Consumer Data Act, to amend the Personal Information Protection and Electronic Documents Act and to make amendments to other Acts, Bill C-36 represents the government’s third attempt to overhaul the federal private sector privacy framework since 2020.
Minister Solomon framed the bill as a watershed moment: "the moment is here," positioning privacy protection as foundational to responsible AI innovation and public trust—a core personal pillar of the government's "AI for All" strategy.
Three attempts over six years to repeal and replace Part 1 of PIPEDA:
|
Bill |
Introduced |
Status |
|
Bill C-11 |
Nov 17, 2020 |
Died on Order Paper upon dissolution |
|
Bill C-27 |
Jun 16, 2022 |
Died on Order Paper upon prorogation |
|
Bill C-36 |
Jun 15, 2026 |
Currently before Parliament |
For an up-to-date timeline of Bill C-36’s progress through Parliament, see our Bill C-36 Timeline of Developments.
The Commission is the overarching independent federal regulator established by section 4 of the Digital Safety and Data Protection Commission of Canada Act, a part of separate Bill C-34 (see our detailed bulletin on C-34 here). It is composed of five full-time members appointed by the Governor in Council. Key functions include:
The Privacy and Consumer Data Commissioner is a designated member of the Commission, appointed by the Governor in Council under s. 85(1). Key functions include:
The Privacy and Consumer Data Division is established under s. 89 and is composed of the Commissioner plus at least one other member of the Commission assigned by the Commission. The Division serves a specialized adjudicative and approval function. Key functions include:
Bill C-36 proposes many significant changes to the federal private sector privacy regime. Here are the key concepts so far:
Administrative monetary penalties are capped at the greater of $10 million and 3% of an organization’s gross global revenue (s. 114).
The most serious offences, such as knowingly contravening the breach-reporting duties, the re-identification prohibition, or a Commission order, carry fines up to the greater of $25 million and 5% of gross global revenue on indictment (s. 145).
Enforcement begins with a Commissioner-issued notice of contravention (including any proposed penalty and order), subject to review by the Commission, with appeals to the Federal Court (ss. 107, 126).
A private right of action (s. 132) allows affected individuals to sue for damages once a contravention is established, subject to a two-year limitation period.
In exercising their powers, the Commission, Commissioner, and Division must weigh enumerated factors: the purpose of the Act; the size and revenue of organizations; the volume and sensitivity of the information; the best interests of children; Canada’s international trade obligations; the importance of supporting economic growth, competition, and innovation; and any other matter of general public interest.
These factors signal a proportionate, context-sensitive approach to enforcement that expressly accounts for innovation and the circumstances of the organization.
Every organization must implement and maintain a documented privacy management program covering the protection of personal information, complaint and request handling, staff training, and explanatory materials, scaled to the volume and sensitivity of the information it holds (s. 9).
Organizations must also designate one or more individuals responsible for compliance and provide their contact information on request (s. 8), and the program must be producible to the Commission on request.
An “automated decision system” is defined broadly to include rules-based systems, regression analysis, predictive analytics, machine learning, deep learning, and neural networks.
Where such a system makes a prediction, recommendation, or decision about an individual that could have a legal or similarly significant effect, the organization must, on request, provide an explanation, including the type of personal information used, its source, and the principal factors involved (s. 63(4)-(5)).
The threshold is raised from the former “significant impact” standard under earlier reform legislation to a “legal or similarly significant effect,” and individuals have the right to make written representations to a human employee able to review the decision (s. 63(6)).
Bill C-36 draws a clear and consequential distinction between these two concepts:
For the first time, the federal statute provides a statutory definition of "sensitive" personal information:
"Sensitive" describes personal information in respect of which, taking into account the circumstances, an individual has a heightened expectation of privacy, including:
"Child" is defined as an individual under 18 years of age. The Commission must consider "best interests of children" when exercising its powers and duties.
Sensitivity drives obligations throughout the Act: security safeguards (s. 56), retention periods (s. 52), and calibration of express vs. implied consent (s. 15).
Before disclosing or transferring personal information outside Canada, an organization must:
Accountability: The organization must, on request, provide the Commission with access to or a copy of the privacy impact assessment (s. 57(2)).
Bill C-36 carries forward and broadens the consent exceptions first seen in Bill C-27's CPPA:
Business Activities (s. 18(2)): Consent not required for collection/use where the activity is:
Note: The business activities exception is limited to collection and use and does NOT extend to disclosure.
Legitimate interest (s. 18(3)): An organization may collect, use, or disclose personal information without consent for an activity in which the organization has a legitimate interest that outweighs any reasonably foreseeable adverse effect on the individual, IF:
Change from C-27: Legitimate interest now extends to disclosure (C-27 limited it to collection and use only). A documented privacy impact assessment is required as a precondition (s. 18(4)), and the record must be provided to the Commission on request (s. 18(5)).
This effectively signals an express consent requirement for any use of personal information for the purpose of influencing behaviour or decisions (e.g., targeted advertising, personalized pricing, behavioural nudging).
Bill C-36 overhauls the business transactions exception proposed under Bill C-27, adding a general requirement to de-identify personal information before transfer unless certain conditions are met.
Parties to a prospective business transaction may use and disclose personal information without consent if:
EXCEPTION (s. 22(2)): The de-identification requirement does not apply if:
Note: The exception does not apply where the transaction's primary purpose or result is the purchase, sale, or lease of personal information itself (s. 22(4)).
While Bill C-36 has a long road ahead, organizations may wish to begin considering its potential implications:
Bill C-36 must still pass through the legislative process before becoming law, including Second Reading, committee study, third reading, and reporting stage, and full consideration in the Senate, including debate and committee consideration.
We are closely monitoring Bill C-36. For more information, contact a member of our Cyber Security and Data Protection Group
CECI NE CONSTITUE PAS UN AVIS JURIDIQUE. L'information qui est présentée dans le site Web sous quelque forme que ce soit est fournie à titre informatif uniquement. Elle ne constitue pas un avis juridique et ne devrait pas être interprétée comme tel. Aucun utilisateur ne devrait prendre ou négliger de prendre des décisions en se fiant uniquement à ces renseignements, ni ignorer les conseils juridiques d'un professionnel ou tarder à consulter un professionnel sur la base de ce qu'il a lu dans ce site Web. Les professionnels de Gowling WLG seront heureux de discuter avec l'utilisateur des différentes options possibles concernant certaines questions juridiques précises.
Gowling WLG est un cabinet juridique international constitué des membres de Gowling WLG International Limited, une société à responsabilité limitée par garanties enregistrée en Angleterre, ainsi que leurs affiliés respectifs. Les membres et affiliés constituent des entités autonomes et indépendantes. Gowling WLG International Limited promeut, facilite et coordonne les activités de ses membres, mais ne fournit pas elle-même de services aux clients. Pour en savoir davantage sur notre structure, consultez notre page Avis juridique.
© 2026 Gowling WLG Tous droits réservés