Canada's government introduced a bill called C-36 that would replace the country's 25-year-old private-sector privacy law with tougher rules and fines of up to 10 million Canadian dollars or 3 percent of a company's global revenue, whichever is larger. It matters to marketers, advertisers and any business handling Canadian personal data, because the bill would change what counts as valid consent, add new exceptions for things like fraud prevention and business activities, and hand enforcement to a new commission with real penalty power instead of the current, more limited privacy office. Nothing has changed yet: the bill still needs to pass committee review, a Senate vote and royal assent, and Canada's Parliament reconvenes on September 21, 2026, to continue that work.

A bill introduced in June returns to the spotlight as Parliament reconvenes

Canada's House of Commons introduced Bill C-36 on June 15, 2026, a piece of legislation that would enact the Protecting Privacy and Consumer Data Act and repeal the consumer-facing provisions of the Personal Information Protection and Electronic Documents Act, according to the bill's official text published by the House of Commons of Canada. The bill, sponsored by the Minister of Artificial Intelligence and Digital Innovation, sat at first reading through the summer recess. Parliament reconvenes on September 21, 2026, according to a LinkedIn post from Luis Alberto Montezuma, a data and privacy policy commentator, putting the bill back on the legislative calendar for advertisers, data brokers and platforms that handle Canadian personal information.

The timing matters for a specific reason. PIPEDA, in force since 2001, has anchored Canadian privacy compliance for a quarter-century, and this is not the first attempt to replace it. Two earlier bills, C-11 in 2020 and C-27 in 2022, proposed similar reforms and died on the parliamentary order paper without reaching royal assent. Bill C-36 is the third attempt, and its text, running to more than 300 pages including bilingual French and English columns, sets out the most detailed enforcement architecture of the three.

The legislation would not stand alone. According to the LinkedIn post referencing the bill, the European Data Protection Board is separately scheduled to hold its 123rd plenary meeting on September 17, 2026, a date that falls just days before Canada's Parliament returns. The two developments are not formally connected, but they sit inside the same week of the regulatory calendar that privacy teams operating across multiple jurisdictions will need to track. PPC Land has previously covered how the EEA functions as a distinct compliance zone with its own consent architecture, a contrast worth holding in mind when assessing how Canada's proposed regime would differ.

What the bill would actually change

The core of Bill C-36 is a new statute, the Protecting Privacy and Consumer Data Act, that would replace Part 1 of PIPEDA rather than amending it piecemeal. According to the bill's text, the new act is designed "to support and promote digital commerce by protecting personal information that is collected, used or disclosed in the course of commercial activities," language that keeps PIPEDA's underlying premise: privacy protection and commercial data use are meant to coexist, not to be treated as opposing goals.

Several structural changes stand out for organizations that collect, use or disclose personal information in the course of commercial activities in Canada, or that operate a federal work, undertaking or business touching Canadians' data.

A new commission replaces the existing privacy office

Under the current PIPEDA regime, the Office of the Privacy Commissioner of Canada investigates complaints but has limited direct penalty power. Bill C-36 would fold privacy oversight into the Digital Safety and Data Protection Commission of Canada, the same body originally proposed under Bill C-34, the Safe Social Media Act, according to the bill's text. One member of that Commission would be designated the Privacy and Consumer Data Commissioner, taking on the complaint-investigation and audit functions the current Privacy Commissioner performs today, while gaining new powers to issue notices of contravention that can carry reviewable penalties and binding orders.

The broader Commission, not just the individual Commissioner, would also take on research, public education, guidance development, consultations and the review of contravention notices, according to the bill. That is a wider institutional mandate than PIPEDA's current enforcement structure provides, and it mirrors, in general shape, the kind of standing regulatory apparatus that European data protection authorities already operate under.

Penalties reach into eight figures

The bill's text sets the maximum administrative penalty at the greater of 10,000,000 Canadian dollars or 3 percent of an organization's gross global revenue in the financial year before the one in which the penalty is imposed, according to section 114 of the bill. That formula, the higher of a flat figure or a percentage of global turnover, mirrors the structure used in the GDPR's own penalty regime, though the specific figures differ. The bill is explicit that this mechanism exists "to promote compliance with this Act and not to punish," language drawn directly from section 115 of the text.

Separate from administrative penalties, the bill also creates offence provisions carrying criminal-style punishment for certain violations, and it establishes a private right of action, allowing individuals to sue organizations directly for damages arising from a contravention of the act, according to the bill's text. Penalties collected under the administrative regime are payable to the Receiver General, the bill specifies, and unpaid amounts become debts recoverable through the Federal Court, with a five-year limitation period on recovery proceedings.

A penalty may not be imposed, according to the bill, where an organization was already in compliance with an approved certification program covering that provision at the time of the contravention, where a prosecution for the same act or omission has already been instituted, or where the organization can establish it exercised due diligence to prevent the contravention. The Commission, in setting a penalty amount, must weigh factors including the organization's ability to pay, any financial benefit obtained from the contravention, and the likely effect the penalty would have on the organization's ability to continue operating.

The bill preserves PIPEDA's consent-based foundation. Section 15 requires an organization to obtain an individual's valid consent before collecting, using or disclosing their personal information, and section 16 voids any consent obtained through false or misleading information or deceptive practices. Section 17 gives individuals the right to withdraw consent at any time, subject to legal, contractual or reasonable notice constraints, after which the organization must stop the relevant collection, use or disclosure as soon as feasible.

Where the bill adds detail is in the exceptions. Section 18 permits an organization to collect or use personal information without consent for defined "business activities," a list that includes providing a product or service the individual requested, securing the organization's information systems, and ensuring product or service safety, provided a reasonable person would expect the collection for that activity and the information is not used to influence the individual's behaviour or decisions. Section 18(3) adds a broader "legitimate interest" basis, allowing collection, use or disclosure without consent where the organization's interest outweighs any reasonably foreseeable adverse effect on the individual, subject to a documented privacy impact assessment identifying the interest, the foreseeable risks and the steps taken to mitigate them.

Other named exceptions cover research and development purposes where information is de-identified before use, prospective business transactions where information is de-identified until the deal closes, fraud prevention and investigation, debt collection, and disclosures made in the public interest, including emergencies threatening life, health or security. The bill defines de-identification and anonymization as distinct concepts: de-identifying information means modifying it so an individual cannot be directly identified, while a risk of re-identification may remain, whereas anonymizing means modifying information "irreversibly and permanently" so that no reasonably foreseeable risk of identification exists "by any means," according to the bill's definitions section. PPC Land's Explainer series has covered the de-identification distinction in the context of the EDPB's own anonymisation framework, adopted earlier this year, and the same conceptual line runs through the Canadian bill.

New rights around automated decisions

Section 63(4) of the bill would require organizations, on request, to explain any prediction, recommendation or decision made about an individual using an automated decision system, where that outcome could have a legal or similarly significant effect on them. The explanation must identify the type of personal information used, the source of that information, and the reasons or principal factors that produced the outcome, according to the bill's text. Section 63(6) further requires organizations to give individuals an opportunity to make written representations to an employee capable of reviewing the decision. This provision would apply to any organization using automated scoring, targeting or eligibility systems that draw on Canadian personal information, a category that includes a meaningful share of programmatic advertising and marketing technology infrastructure.

Breach notification and cross-border transfers

The bill would keep PIPEDA's breach-notification framework largely intact in structure: organizations must report to the Commission and notify affected individuals when a breach of security safeguards creates a real risk of significant harm, a standard the bill retains from the current law, with the factors used to assess that risk including the sensitivity of the information involved and the probability of misuse.

Section 57 introduces a specific requirement for disclosures or transfers of personal information outside Canada. Before any such transfer, an organization must carry out a privacy impact assessment and implement measures to mitigate identified risks, which the bill's text lists as potentially including contractual privacy protection measures, adherence to an approved code of practice or certification process, or other prescribed measures. That structure again echoes mechanisms found in European data protection law, though the bill does not import GDPR's adequacy-decision model directly.

Where the bill sits in the legislative process

Bill C-36 has completed only first reading, the stage at which a bill's text is formally introduced and printed but before committee study, substantive debate or amendment begins. The bill must still pass second reading, committee review, third reading in the House of Commons, and the equivalent stages in the Senate, before it can receive royal assent and come into force. The bill's own coming-into-force provisions, in both the main enactment and the consequential amendments affecting the Digital Safety and Data Protection Commission of Canada Act, specify that the relevant sections take effect on a day or days fixed by order in council, meaning implementation would not be automatic even after passage.

That process has already claimed two predecessor bills. Bill C-11, introduced in 2020, and Bill C-27, introduced in 2022, both proposed comparable reforms to Canada's federal private-sector privacy law and both died when Parliament prorogued before they reached royal assent. Bill C-36 restructures the enforcement model compared with its predecessors: rather than splitting investigation and penalty-imposition between a Privacy Commissioner and a separate tribunal, as Bill C-27 proposed, the new bill houses both functions inside the Digital Safety and Data Protection Commission, a structural choice aimed at avoiding the delay that critics attributed to the earlier tribunal split.

Why this matters for marketers and advertisers

Canada's advertising and programmatic ecosystem operates substantially under PIPEDA today, and the current law's absence of an administrative monetary penalty regime has long been cited by privacy advocates as a gap compared with European enforcement. PPC Land has reported extensively on how that gap shows up in practice. In a ruling covered in September 2024, Canada's Federal Court of Appeal found that Facebook had breached PIPEDA in its handling of user data shared with third-party apps, including in the Cambridge Analytica matter, but the court stopped short of ordering specific remedies, a limitation tied directly to PIPEDA's current enforcement structure. Bill C-36's penalty regime, with its 10 million dollar or 3 percent floor, would close much of that gap.

More recently, four Canadian privacy regulators concluded a joint investigation into ChatGPT, finding that OpenAI's practices had breached PIPEDA and equivalent provincial statutes from the outset, with the British Columbia and Alberta offices taking a stricter position than the federal commissioner on how scraped training data should be treated. That investigation illustrated both PIPEDA's continuing relevance to AI-driven advertising and measurement technology, and the fragmented character of Canada's current privacy landscape, where a federal statute coexists with separate provincial regimes in Quebec, British Columbia and Alberta. Bill C-36 does not eliminate that fragmentation; it replaces only the federal layer.

The stakes extend beyond companies headquartered in Canada. When Cognitiv, a deep learning advertising technology company, opened its first office outside the United States in Vancouver earlier this year, PPC Land noted that the move placed the company's data collection and machine learning operations inside a regulatory perimeter shaped by both PIPEDA and British Columbia's own Personal Information Protection Act. Any advertising technology vendor, demand-side platform or data management company with Canadian operations, Canadian data subjects, or Canadian employees handling personal information would need to reassess its compliance posture against Bill C-36's provisions if the bill advances, particularly around the automated decision-making transparency obligations and the new documentation requirements attached to the legitimate-interest exception.

The private right of action the bill introduces is also a departure worth flagging. PIPEDA today does not give individuals a direct statutory route to sue for damages; complainants generally proceed through the Privacy Commissioner's investigation process or, in limited circumstances, the Federal Court. A private right of action tied to a contravention of the act, layered on top of an administrative penalty regime reaching into the tens of millions of dollars for large advertisers and data processors, would represent a materially different risk calculation for any organization whose programmatic, measurement or identity infrastructure touches Canadian personal information.

What happens next

The immediate marker to watch is the resumption of parliamentary business on September 21, 2026. Bill C-36 will need to clear second reading and committee study before its provisions can be amended, and the bill's own text builds in substantial delegated authority: multiple sections, including those governing prescribed certification programs, prescribed factors for penalty calculation, and prescribed circumstances for various consent exceptions, depend on regulations that have not yet been drafted. Even a bill that clears all three readings and receives royal assent would not take full effect until those regulations exist and the government fixes a coming-into-force date by order in council.

Given the fate of Bill C-11 and Bill C-27, prediction is difficult. What is different this time is the specificity of the enforcement architecture on the table, and the fact that Bill C-36 arrives inside a broader federal digital policy agenda that already includes the Safe Social Media Act and Canada's National Artificial Intelligence Strategy. Whether that context helps the bill survive where its predecessors did not will depend on committee negotiations that have not yet begun.

Timeline

  • 2001: The Personal Information Protection and Electronic Documents Act comes into force, becoming Canada's primary federal private-sector privacy statute.
  • 2020: Bill C-11 proposes replacing PIPEDA's consumer privacy provisions; the bill dies without reaching royal assent.
  • 2022: Bill C-27 proposes a three-part reform including a Consumer Privacy Protection Act and a separate enforcement tribunal; the bill dies when Parliament prorogues in January 2025.
  • September 10, 2024: Canada's Federal Court of Appeal rules that Facebook breached PIPEDA in its handling of user data shared with third-party apps, without ordering specific remedies.
  • May 2026: Four Canadian privacy regulators conclude a joint investigation finding that ChatGPT's practices breached PIPEDA and provincial equivalents from the outset.
  • June 15, 2026: Bill C-36, enacting the Protecting Privacy and Consumer Data Act, receives first reading in the House of Commons.
  • Earlier this year: Cognitiv opens its first office outside the United States in Vancouver, placing its data operations inside Canada's federal and British Columbia privacy regimes.
  • September 17, 2026: The European Data Protection Board is scheduled to hold its 123rd plenary meeting.
  • September 21, 2026: Canada's Parliament reconvenes, returning Bill C-36 to the legislative calendar.

Summary

Who: Canada's federal government, through the Minister of Artificial Intelligence and Digital Innovation, introduced the bill; it would affect any organization collecting, using or disclosing personal information in the course of commercial activities in Canada, including advertising technology vendors, data brokers and platforms handling Canadian data.

What: Bill C-36 would enact the Protecting Privacy and Consumer Data Act, replacing the consumer-facing provisions of PIPEDA with a new statute featuring administrative penalties of up to 10 million Canadian dollars or 3 percent of global gross revenue, a new Digital Safety and Data Protection Commission of Canada with direct enforcement powers, a private right of action, and new transparency obligations for automated decision-making systems.

When: The bill received first reading on June 15, 2026. Canada's Parliament reconvenes on September 21, 2026, to resume legislative business, including further consideration of the bill.

Where: The bill applies to organizations operating in Canada or handling the personal information of Canadians in the course of commercial activities, federal works, undertakings or businesses, and interprovincial or international data flows involving Canadian organizations.

Why: PIPEDA has governed Canadian private-sector privacy since 2001 without a meaningful administrative penalty regime, a gap that has surfaced in cases including the Federal Court of Appeal's 2024 Facebook ruling and the 2026 joint investigation into ChatGPT. Bill C-36 is the third legislative attempt in six years to close that gap, following two predecessor bills that died before reaching royal assent, and its outcome will determine whether Canada moves toward an enforcement model closer to the one already operating in the European Union.