Canada's proposed Protecting Privacy and Consumer Data Act would allow courts to fine an organisation up to C$25 million or 5% of its gross global revenue, whichever is greater, if it knowingly re-identifies de-identified personal information, fails to report a data breach or obstructs the new privacy regulator. That criminal tier sits above the administrative ceiling that has drawn most of the attention since Bill C-36 received first reading on June 15, 2026, and it returns to the parliamentary agenda when the House of Commons reconvenes on September 21, 2026.
In Short
Canada has written a new privacy law, still unpassed, with two kinds of punishment: ordinary regulatory fines and much bigger criminal fines for the worst, deliberate behaviour. The criminal fines would hit companies that secretly turn anonymous-looking data back into named people, cover up data leaks or get in the regulator's way, and they are calculated against worldwide sales. Nothing changes until Parliament passes the bill and the government sets a start date, but the text already shows which advertising practices would carry the most risk.
Two tiers, two sets of triggers
The bill runs to 108 pages in the version printed for first reading, with English and French texts side by side. It was tabled by the Minister of Artificial Intelligence and Digital Innovation. Most of its length is spent on Part 1, which enacts the new statute, repeals Part 1 of the Personal Information Protection and Electronic Documents Act (PIPEDA) and renames what remains of that 2000 law the Electronic Documents Act.
Enforcement is split in two. PPC Land's September 19 coverage focused on the first tier, the administrative penalty regime, which caps penalties at the greater of C$10 million and 3% of gross global revenue. The second tier, in section 145 of the new Act, is a set of criminal offences, and its numbers are larger.
The offence tier
According to the bill, an organisation that knowingly contravenes any of five specified provisions, or an order made under subsection 110(1), commits an offence. Obstructing the Privacy and Consumer Data Commissioner during an investigation or audit, or obstructing the wider Commission during review proceedings or an interim order, is caught as well. The penalties depend on how the Crown proceeds:
- On indictment, a fine not exceeding the greater of C$25 million and 5% of the organisation's gross global revenue in its financial year before the one in which it is sentenced.
- On summary conviction, a fine not exceeding the greater of C$20 million and 4% of that revenue.
The five provisions are narrow and specific. Section 58 covers reporting breaches to the Commission and notifying affected individuals when there is "a real risk of significant harm". Subsection 60(1) requires a record of every breach of security safeguards, whether reported or not. Section 69 obliges an organisation holding information that is the subject of an access request to keep it until the individual has exhausted any recourse. Section 75 bans the use of de-identified information to identify an individual, subject to listed exceptions. Subsection 144(1) prohibits employers from dismissing, demoting, harassing or otherwise disadvantaging employees who report contraventions to the Commission, and the bill extends "employee" to independent contractors for that purpose.
For a platform with C$1 billion in gross global revenue, 5% amounts to C$50 million. For smaller companies the flat figure governs, since the cap is always whichever amount is higher.
The administrative tier
The administrative penalty works differently. Section 114 sets the maximum for "all of the contraventions found to have been committed by an organization following the completion of proceedings in relation to any one investigation" - a ceiling per investigation rather than per violation. Section 115 describes the purpose of these penalties as promoting compliance rather than punishment.
Penalties flow from a notice of contravention issued by the Commissioner. According to section 107, the notice must set out the facts, the provisions breached, any penalty and any proposed order, and the organisation then has 30 days, or a longer period set in the notice, to apply to the Commission for review. Unpaid amounts become debts to the Crown, recoverable in the Federal Court within five years.
What the regulator can fine, and what it cannot
Section 113(1) is the most consequential list in the bill for compliance planning, because it restricts administrative penalties to contraventions of named provisions only. According to the text, those are: the privacy management program in subsection 9(1); the service provider protection clause in 11(1); the appropriate-purpose and purpose-recording rules in 12(1), (3) and (4); the collection limit in section 13; the new-purpose rule in 14(1); the consent requirement and the ban on over-broad consent in 15(1) and (7); the deception clause in section 16; stopping processing after consent is withdrawn in 17(2); retention in section 52; disposal on request in 54(1) and (5); security safeguards in 56(1); breach reporting in 58(1) and (3); service provider breach notice in section 61; and the published-policies requirement in 62(1).
The omissions are as informative as the inclusions. Section 57, which requires a privacy impact assessment before personal information leaves Canada, is not on the list. Neither is section 63, which contains the new right to an explanation of automated predictions, recommendations and decisions. Nor is the data mobility provision in section 72. Contravening those provisions could still produce a finding, a compliance agreement or an order, but not a penalty on its own. Re-identification under section 75 is also absent from the administrative list - it is handled instead as a potential criminal offence when done knowingly.
Three defences sit inside section 113(3). No penalty may be imposed if the organisation was complying with an approved certification program covering the provision at the time, if a prosecution for the same act has been instituted, or if the organisation "establishes that it exercised due diligence to prevent the contravention". The factors a decision-maker must weigh include any financial benefit obtained from the contravention and the organisation's ability to pay.
Inferred data and the persuasion carve-out
Two definitional choices matter more to advertising than the fines. The first is in section 2, which defines personal information as "information about an identifiable individual, including information that is inferred about the individual". Modelled attributes, propensity scores and segment memberships attached to an identifiable person would sit inside the statute on that wording, not beside it.
The second concerns the exceptions to consent. Section 18(1) lets an organisation collect or use information without knowledge or consent for listed business activities - providing a requested product or service, securing its systems, keeping a product safe, and anything later prescribed by regulation. Section 18(3) creates a legitimate interest exception, available only after the organisation has described its interest, carried out a privacy impact assessment, and taken reasonable measures against foreseeable adverse effects. Both exceptions carry the same condition: the information must not be collected or used "for the purpose of influencing the individual's behaviour or decisions".
That phrase closes both routes to personalised advertising. Where the purpose of processing is to shape what someone buys, clicks or believes, the bill points back to consent. Europe's experience runs the other way: the GDPR permits legitimate interest for direct marketing in principle, and the resulting disputes have been lengthy. An EDPB case digest covered in March 2026 analysed 62 one-stop-shop decisions and five binding decisions on how that balancing test was applied and misapplied. Canada's drafting avoids part of that argument by removing behavioural influence from the exception altogether.
Section 12 adds a reasonableness test that applies "whether or not consent is required". Organisations must weigh, among other factors, "whether there are less intrusive means of achieving those purposes at a comparable cost and with comparable benefits". Section 13 then limits collection to what is necessary for purposes recorded at or before the point of collection - a data minimisation rule expressed in Canadian terms.
Consent that names third parties
For consent to be valid under section 15(3), the organisation must disclose, at or before the time it asks, the purposes, the manner of processing, "any reasonably foreseeable consequences", the specific type of information involved, and "the names of any third parties or types of third parties to which the organization may disclose the personal information". Section 15(4) requires all of that in plain language that the target audience "would reasonably be expected to understand".
Express consent is the default. Section 15(5) allows implied consent only where it is appropriate given the individual's reasonable expectations and the sensitivity of the information. Section 15(7) bars organisations from making a product or service conditional on consent to processing "beyond what is necessary to provide the product or service", and section 16 invalidates any consent obtained through "deceptive or misleading practices".
Transparency obligations follow the data after collection. Under section 62(2), organisations must publish a description of the legitimate interest activities they rely on, a general account of any automated decision system that makes predictions, recommendations or decisions with a legal or similarly significant effect, and the retention periods applied to sensitive information. Under section 63(3), an organisation answering an access request must name the third parties, or types of third parties, to which it disclosed the requester's information, "including in cases where the disclosure was made without the consent of the individual". Responses are due within 30 days under section 67, extendable by a maximum of 30 days, and a missed deadline counts as a refusal.
One further provision targets a long-standing list-building practice. Section 51 removes the consent exceptions for electronic addresses collected with software "designed or marketed primarily" to generate or harvest them, and requires express consent in those cases.
De-identified is not anonymized
The bill draws a hard line between two operations. To de-identify is to modify information so that an individual "cannot be directly identified from it, although a risk of the individual being identified remains". To anonymize is to modify it so there is "no reasonably foreseeable risk in the circumstances" of identification, directly or indirectly, "by any means". Subsection 2(2) states that de-identified information "does not cease to be personal information", while subsection 6(5) takes anonymized information outside the Act entirely. The distinction mirrors the one set out in PPC Land's explainer on de-identification.
De-identified data receives several practical exemptions. Organisations need not act on access requests for it, amend it, dispose of it on request, keep it accurate or port it under a mobility framework. Section 21 permits the use of personal information without consent for internal research, analysis and development "if the information is de-identified before it is used", and section 20 permits using it without consent for the de-identification or anonymization process itself. Section 74 requires the technical and administrative measures to be proportionate to the purpose and the sensitivity of the data.
Section 75 is the counterweight. It forbids using de-identified information, "alone or in combination with other information", to identify an individual, except in listed cases. Those include testing security safeguards, obtaining the individual's valid consent, complying with the law, testing de-identification processes, and conducting "testing of the fairness and accuracy of models, processes and systems that were developed using de-identified personal information". Where a hashed or pseudonymous file qualifies as de-identified, matching it back to named individuals outside those exceptions is the conduct that, done knowingly, would fall within the section 145 offence tier.
Children and sensitive categories
The bill defines a child as "an individual who is under 18 years of age". A child's personal information is listed as sensitive, alongside information about racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or health information, biometric information capable of uniquely identifying a person, and sexual orientation. Sensitivity feeds into the appropriateness test, the choice between express and implied consent, security safeguards and retention periods.
Parents, guardians or tutors may exercise a child's rights under section 4, "unless the child wishes to personally exercise those rights and is capable of doing so". When an individual asks for their data to be disposed of, section 54(2)(d) lets organisations refuse on data-integrity grounds only when the information "is not in relation to a child". Both the Commission and the Division must take into account "the best interests of children" when exercising their powers, along with the size and revenue of organisations, trade obligations and "economic growth, competition and innovation in the Canadian marketplace".
Service providers and the ad tech supply chain
Section 7 puts accountability on the organisation that decides to collect information and determines its purposes, "regardless of whether the information is collected, used or disclosed by the organization itself or by a service provider". Section 19 allows transfers to service providers without knowledge or consent, and section 11 requires the transferring organisation to ensure, "by contract or otherwise", that the provider offers equivalent protection.
Service providers themselves carry only the security safeguard duty and the obligation to report breaches to the controlling organisation - unless they use the data "for any purpose other than the purposes for which the information was transferred". At that point, according to section 11(2), they become subject to every obligation in Part 1. For demand-side platforms, measurement vendors and data processors that combine client data with their own, that clause marks the boundary between a light-touch regime and full controller duties. When an individual's data is disposed of on request, section 54(5) also requires the organisation to inform any service provider that received it and ensure the provider disposes of it too.
A regulator linked to competition and telecom authorities
The institutional design is set out partly in Part 1 and partly in Part 3, which amends the Digital Safety Commission of Canada Act proposed in Bill C-34, the Safe Social Media Act. The renamed Digital Safety and Data Protection Commission of Canada would consist of five full-time members appointed by the Governor in Council. One member, other than the Chairperson, would be designated Privacy and Consumer Data Commissioner. The Commissioner and at least one other member would form a Privacy and Consumer Data Division, which approves codes of practice and certification programs.
According to Luis Alberto Montezuma, who writes on data and privacy policy, the Commissioner would take over many of the roles the Privacy Commissioner performs under PIPEDA, including complaint investigations and audits, while gaining the power to issue notices of contravention with reviewable penalties and orders.
Section 80 allows the Commission to reach agreements with the Canadian Radio-television and Telecommunications Commission and the Commissioner of Competition to coordinate complaint handling and share information, and Part 4 amends the Competition Act to let the competition side reciprocate. Section 99 permits the Commissioner to decline investigating conduct that would contravene sections 6 to 9 of Canada's anti-spam legislation or section 52.01 of the Competition Act, which leaves spam and certain misleading electronic messages with other authorities.
Certification carries weight. An organisation certified under an approved program may see a complaint on the covered issue left uninvestigated under section 98(1)(d), and compliance with such a program at the time of a contravention bars an administrative penalty. Individuals may also report suspected contraventions to the Commission confidentially under section 143.
Lawsuits follow findings
Section 132 creates a private right of action, but it is gated. An individual may sue for damages only after the Commissioner has made a finding of contravention that has become final - because the penalty was paid, no review was sought, the Commission confirmed it, or an appeal failed - or after a compliance agreement that does not provide for damages. A conviction under section 145 opens a separate cause of action. The structure differs from American private enforcement, where statutory damages can be claimed directly. PPC Land reported on California's SB 690 earlier this month, which would remove the private right of action for pen register and trap-and-trace claims under the California Invasion of Privacy Act arising from websites and apps, after such filings jumped from about 600 to nearly 4,000 since February 2025.
Two bills, one timetable
The coming-into-force clauses make C-36 dependent on C-34. According to section 52, most of C-36 takes effect on a date fixed by order in council, but not before Part 3 - the Commission provisions - is in force. Part 3's own start is tied to Bill C-34: if C-34 receives royal assent, Part 3 comes into force on a date fixed by order, and not before section 4 of the Digital Safety Commission of Canada Act, as enacted by C-34, takes effect. A privacy law without a commission to enforce it cannot start first.
Other provisions extend the bill's reach and its review cycle. Section 6(2) applies the Act to information moving interprovincially or internationally, while section 139(2)(b) lets the government exempt activity inside a province whose own legislation is "substantially similar". A schedule names one organisation - the World Anti-Doping Agency - as covered for its interprovincial and international activities. A coordinating amendment would repeal Division 23 of Part 5 of the Budget 2025 Implementation Act, No. 1, if the relevant C-36 section comes into force first or on the same day. And section 146 requires a parliamentary committee review five years after that section takes effect, and every five years after.
Timing overlaps with Europe. Montezuma noted that the European Data Protection Board scheduled its 123rd plenary for September 17, four days before Ottawa's return. Cross-border transfers are the obvious link: the European Commission's data adequacy decision for Canada covers commercial organisations subject to Canada's private-sector privacy law, the very law that C-36 would replace.
Why the detail matters for advertising
Canadian privacy enforcement has produced findings without money attached. The Federal Court of Appeal ruled in September 2024 that Facebook had breached PIPEDA but stopped short of ordering specific remedies. In May 2026, four Canadian regulators concluded that ChatGPT's practices breached PIPEDA and provincial statutes from the start. Neither outcome came with a penalty.
The European record suggests caution about headline ceilings. Nearly 40% of the 7.1 billion euros in GDPR fines issued since 2018 had been annulled or was under challenge by May 2026. Luxembourg's Administrative Court annulled Amazon's 746 million euro fine in March 2026 because the regulator had not carried out the fault analysis that EU case law requires. C-36 writes a due diligence defence into section 113 from the outset, which places the burden on the organisation to establish it but also makes the question central to every penalty decision.
Automated decisions are the other live front. The Dutch data protection authority fined Uber 824,990,000 euros on August 21, 2026 over fully automated decisions about drivers, and Uber has appealed. C-36's section 63(4) would require explanations of automated predictions and recommendations with legal or similarly significant effects, naming the type of information used, its source and "the reasons or principal factors" behind the outcome - yet, as the penalty list shows, a failure to explain would not by itself attract an administrative penalty.
Two bills in this area have already failed. C-11 in 2020 and C-27 in 2022 both died before royal assent, as PPC Land noted on September 19. C-36 has completed first reading only. Second reading, committee study, third reading and the Senate stages all remain, followed by regulations - on anonymization, prescribed business activities, security safeguards, data mobility frameworks, certification criteria and more - before the government fixes a start date. How much of the offence tier survives committee is a question the autumn sitting will begin to answer.
Timeline
- 2001: PIPEDA comes into force as Canada's federal private-sector privacy law
- 2020: Bill C-11 proposes replacing PIPEDA and later dies before royal assent
- 2022: Bill C-27 proposes comparable reform and later dies before royal assent
- September 10, 2024: Federal Court of Appeal rules Facebook breached PIPEDA without ordering specific remedies
- March 12, 2026: Luxembourg's Administrative Court annuls Amazon's 746 million euro GDPR fine over the missing fault analysis
- March 2026: EDPB case digest on legitimate interest covers 62 one-stop-shop decisions
- May 2026: Four Canadian privacy regulators conclude ChatGPT breached PIPEDA and provincial laws
- May 2026: Analysis finds nearly 40% of 7.1 billion euros in GDPR fines annulled or under challenge
- June 15, 2026: Bill C-36 receives first reading in the House of Commons, tabled by the Minister of Artificial Intelligence and Digital Innovation
- August 21, 2026: Dutch regulator fines Uber 824,990,000 euros over automated decisions about drivers
- September 2026: California legislature passes SB 690, narrowing CIPA private lawsuits
- September 17, 2026: Scheduled date of the European Data Protection Board's 123rd plenary
- September 19, 2026: PPC Land details C-36's administrative ceiling of C$10 million or 3% of global revenue
- September 21, 2026: Canada's House of Commons reconvenes, with C-36 at first reading
Related PPC Land coverage
- Canada's Bill C-36 sets $10 million privacy fines as Parliament returns - The earlier overview of the bill's administrative penalties, consent exceptions, automated decision rights and cross-border rules.
- German court ends Meta's hosting shield, 250,000 euros per fake ad - A Frankfurt ruling on Meta's ad auction that also places C-36 alongside diverging privacy regimes elsewhere.
- Firms face up to 4% turnover fines under Montenegro's new data law - A parallel privacy statute with its own turnover-based fine ceilings and 2027 application dates.
- Canadian Federal Court of Appeal rules Facebook breached Privacy Laws - The 2024 PIPEDA decision that declared a violation without specific remedies.
- Canadian regulators find ChatGPT privacy rules broken from the start - The joint federal and provincial investigation into OpenAI concluded in May 2026.
- Eight years of GDPR: 40% of the EUR7.1B in fines annulled or under challenge - How much headline European enforcement survives judicial review.
- Luxembourg court annuls Amazon's EUR746M GDPR fine, sends case back to regulator - The March 2026 ruling that turned on the regulator's missing fault assessment.
- Why Amazon no longer has to pay its EUR746M GDPR fine - a legal breakdown - The three legal arguments behind the annulment, relevant to C-36's due diligence defence.
- Dutch regulator fines Uber 825 million euros over automated driver blocking - A nine-figure penalty for fully automated decisions and inadequate information.
- EDPB's damning digest: how 'legitimate interest' fails in practice - Case analysis of the balancing test that C-36's section 18(3) handles differently.
- California lawmakers pass SB 690, cutting CIPA tracking lawsuits - A US bill narrowing a private right of action for website and app tracking claims.
- EDPB's first-ever DPIA template finally lands - but experts want more - The European template for impact assessments comparable to those C-36 requires under sections 18 and 57.
Summary
Who: Canada's federal government, through the Minister of Artificial Intelligence and Digital Innovation, which tabled Bill C-36; organisations that collect, use or disclose personal information in commercial activities involving Canadians, including advertisers, ad tech vendors, data processors and platforms; and a proposed Digital Safety and Data Protection Commission of Canada with a Privacy and Consumer Data Commissioner.
What: Bill C-36 would enact the Protecting Privacy and Consumer Data Act. Beyond administrative penalties of up to the greater of C$10 million and 3% of gross global revenue per investigation, section 145 creates criminal offences carrying fines of up to the greater of C$25 million and 5% on indictment, or C$20 million and 4% on summary conviction, for knowingly contravening rules on breach reporting, breach records, retention during access requests, re-identification of de-identified data, whistleblower protection and compliance orders, and for obstructing the regulator. The bill also defines inferred information as personal information and bars the business activity and legitimate interest exceptions where data is used to influence behaviour or decisions.
When: The bill received first reading on June 15, 2026. The House of Commons reconvenes on September 21, 2026. Coming into force depends on orders in council and on Bill C-34, the Safe Social Media Act, receiving royal assent first.
Where: Canada, covering commercial activity within provinces not exempted under substantially similar provincial laws, federal works and businesses, and personal information moving interprovincially or internationally.
Why: PIPEDA, in force since 2001, has produced findings against companies such as Facebook and OpenAI without penalties attached. C-36 is the third attempt since 2020 to replace it, and its two-tier enforcement design, gated private right of action and restrictions on behaviour-influencing processing would determine how much financial and legal exposure data-driven advertising carries in Canada.
Discussion