top of page

Major Changes in Proposed Replacement for PIPEDA: What Bill C-36 Means for Your Organization




After years of stalled reform, the federal government tabled Bill C-36, the Protecting Privacy and Consumer Data Act, on June 15, 2026. Like its predecessors (Bill C11, introduced in 2020, and Bill C-27, introduced in 2022, neither of which made it through Parliament), the bill represents Canada's most significant overhaul of private-sector privacy law since PIPEDA came into force in 2000. If passed, C-36 will repeal Part 1 of PIPEDA entirely, rename the remainder the Electronic Documents Act, and replace it with a standalone privacy statute. Here is what you need to know.


How C-36 Differs from Bill C-27

Bill C-27, the Digital Charter Implementation Act, died on the Order Paper when Parliament dissolved last year. It was an omnibus bill bundling three statutes: the Consumer Privacy Protection Act (CPPA), a new Personal Information and Data Protection Tribunal Act, and the Artificial Intelligence and Data Act (AIDA). That bundling proved fatal to the bill. AI regulation was deeply contested, and dragged the privacy law down with it throughout the committee process.


Bill C-36 takes a deliberately narrower approach. The key differences are:


  • No AI legislation. AIDA has been removed entirely, a decoupling that privacy and technology law stakeholders had encouraged for years.

  • No Tribunal. C-27 proposed a dedicated Personal Information and Data Protection Tribunal to hear appeals and impose penalties. C-36 replaces that model with the newly renamed Digital Safety and Data Protection Commission of Canada, the same five-member body created days earlier under Bill C-34 (the Safe Social Media Act) to oversee online harms.

  • Privacy as a fundamental right. Unlike C-27, which was widely criticized for framing privacy as subordinate to commercial interests, C-36 legislatively entrenches privacy as a fundamental right. That framing functions as a foundational interpretive principle throughout the statute.

  • The Privacy Commissioner is sidelined. Under C-27, the Office of the Privacy Commissioner retained strong powers, including order-making authority over private-sector organizations. Under C-36, the OPC loses all private-sector jurisdiction. A new Privacy and Consumer Data Commissioner, designated by Cabinet from among the Commission's members, takes over that function.

  • Data sovereignty provisions. C-36 introduces rules governing cross-border data transfers (which will now require privacy impact assessments), codifying at the federal level protections for personal information flowing outside Canada. C-27 left that issue largely to future regulations.


What Critics Are Saying

The bill attracted significant pushback within hours of its tabling. Two concerns have dominated early commentary.


The first is what critics have called the "super-regulator" problem. Privacy law scholars have noted that the governance model is unprecedented among peer countries. Most comparable democratic jurisdictions keep data protection and online safety in structurally separate institutions. The EU maintains the GDPR framework and the Digital Services Act under different regulators. The UK divides those functions between the ICO and Ofcom. Australia divides them between the OAIC and the eSafety Commissioner. Bill C-36 collapses both functions into a single Cabinet-appointed commission, the majority of whose members are focused on content moderation rather than privacy. Critics argue this treats privacy as an adjunct of digital policy rather than as the distinct fundamental right the bill claims to enshrine.


The second concern is institutional independence. The Privacy Commissioner has been an Agent of Parliament since 2000, confirmed by resolution of both Houses and reporting directly to Parliament rather than to the executive. C-36 replaces that structure with a Commissioner designated by Cabinet, a significant reduction in formal independence. Legal observers are also questioning whether this arrangement is consistent with Canada's adequacy status under the GDPR, which requires a genuinely independent supervisory authority.


What This Means for Our Clients

Whether or not C-36 passes in its current form, its introduction signals a clear direction in the regulatory environment. Organizations should begin assessing their compliance posture now.


  • Enhanced penalties. C-36 carries administrative monetary penalties of up to $10 million or 3% of gross global revenues for a broad range of contraventions. Enforcement is expected to be more proactive than under the current PIPEDA regime.

  • Right to deletion. Individuals will have an explicit right to require organizations to dispose of their personal information. Clients holding extensive customer databases in financial services, insurance, retail, and healthcare will need to build deletion workflows and retention schedules into their systems.

  • Children's data. Children's personal information is formally classified as sensitive, triggering heightened obligations around consent, protection, and retention. Organizations that collect data from minors, directly or indirectly, should review their practices now.

  • Automated decision-making transparency. Organizations using algorithms, machine learning, or predictive analytics to make decisions about individuals will be required to disclose the nature of the system, the criteria applied, and provide a meaningful right to challenge outcomes.

  • Data mobility. Individuals will be entitled to request that their personal information be transferred to competing organizations through a regulated data mobility framework. This has significant implications for financial institutions, telecom providers, and any data-intensive business.

  • Cross-border transfers. Organizations routing Canadian personal data to foreign processors or affiliates will face new due diligence obligations, including conducting privacy impact assessments and implementing measures to mitigate risk before data is disclosed or transferred. A review of data-sharing agreements and vendor contracts is advisable now.


The legislative timeline remains uncertain. A bill of this complexity will face intensive committee scrutiny. That said, the direction of travel is clear. Our privacy professionals are available to assist with program assessments, policy drafting, and regulatory readiness planning as C-36 advances through Parliament.

 
 
bottom of page