7 minutes read

Canada’s Bill C-36: Key Privacy Changes Every Business Should Know

Canada's Bill C-36 Key Privacy Changes Every Business Should Know - icon

Table of Contents

Introduction

Bill C-36, the Protecting Privacy and Consumer Data Act, is Canada’s third attempt to modernize federal private sector privacy law for the digital economy. The federal government introduced this bill after Bill C-27 died on the order paper in 2025, itself a successor to Bill C-11 in 2020. The PPCDA codifies privacy as a fundamental right and applies to all private sector organizations engaged in commercial activities across Canada, including foreign businesses that collect or process personal data about individuals in Canada.

PPCDA will repeal and replace Part 1 of PIPEDA. The remaining parts of PIPEDA become the Electronic Documents Act, preserving rules around electronic documents and signatures. This consolidation creates a standalone Consumer Data Act with clearer obligations. The key changes are driven by increased digital safety concerns, rapid growth of artificial intelligence, cross-border e-commerce, and the federal government’s goal of aligning with global standards like the EU’s GDPR.

Bill C-36 was tabled on June 15, 2026, and is at first reading. Businesses should not wait for Royal Assent. Consider a Canadian DTC brand using a US-based email provider: under PPCDA, that brand must disclose personal information transfers outside Canada, document safeguards, and obtain appropriate consent. For online retailers and SaaS providers, this is a core trust and economic growth factor affecting marketing, analytics, UX, and vendor contracts.

New Regulatory Framework: Digital Safety and Data Protection Commission

Bill C-36 shifts private sector privacy enforcement from the Office of the Privacy Commissioner (OPC) to the new Digital Safety and Data Protection Commission of Canada, created under Bill C-34. The existing Office of the Privacy Commissioner will focus on public-sector privacy going forward. The bill intends to strengthen enforcement through the newly established Commission.

The Commission’s structure includes five full-time members appointed by the Governor in Council, including a dedicated privacy and consumer data commissioner responsible for administering the PPCDA. A specialized consumer data division handles privacy and consumer data disputes, approvals, and orders. The Commission’s remit covers regulatory oversight of private sector privacy, digital safety and data protection, online platforms, and certain AI-driven services.

New powers include binding order-making authority, audits, the ability to demand production of privacy management documentation, and requirements to conduct privacy impact assessments for high-risk processing. The Commission can impose penalties up to C$10 million or 3% of an organization’s gross global revenue, whichever is greater. The new regulator can issue binding orders for compliance, and will oversee both privacy and digital safety regulations.

Consider a retailer using a surveillance pricing algorithm that adjusts prices based on browsing history. Under this regulatory oversight framework, the Commission could investigate whether that system complies with transparency and consent requirements, and order changes if it does not.

court

Strengthening Privacy Rights: Fundamental Right, New Individual Controls and Remedies

PPCDA explicitly recognizes privacy as a fundamental right, elevating it alongside other core civil rights and shaping how regulators and courts interpret business obligations. This creates a heightened expectation for how organizations handling personal information treat individual data.

Individuals gain the right to request data disposal and mobility. The new “right to disposal” requires organizations to delete personal information upon written request, unless legal or contractual retention obligations prevent it. The distinction between permanent deletion and anonymization matters: de-identified data remains regulated due to re-identification risk, while only irreversibly anonymized data falls outside scope.

Bill C-36 defines “child” as under 18 years old. Children’s personal information is designated as sensitive by default, triggering stricter consent expectations and the Commission’s duty to consider the best interests of the child. Organizations must apply heightened safeguards for children’s data, including parental consent mechanisms for sites or apps accessible by minors.

Bill C-36 introduces a private right of action for individuals. Beyond regulatory penalties, individuals can sue organizations for losses caused by contraventions once preconditions are met, such as a Commission finding or conviction. This private right of action means businesses face litigation risk in addition to regulatory exposure. Practical implications: you need robust data subject request workflows, logs of requests and responses, and child-specific data handling policies.

Accountability and Privacy Management Programs: What Businesses Must Build

Bill C-36 emphasizes accountability and governance for data management. Organizations must implement documented privacy management programs covering policies, procedures, safeguards, training, and complaint handling, proportionate to the volume and sensitivity of personal information processed. These mandatory privacy management programs are a core requirement, not optional guidance.

Organizations must designate individuals responsible for compliance, similar to a Data Protection Officer concept. Contact details and program documentation must be available to the Commission on request. A compliant documented privacy management program should include:

  • Data inventory and mapping
  • Lawful bases for processing
  • Retention schedules
  • Vendor and cross-border transfers governance
  • Security safeguards
  • Incident response procedures

Ongoing monitoring is expected: periodic internal data privacy audits, updates reflecting new technologies like artificial intelligence tools, and records of decisions around “legitimate interests” or business activities exceptions. E-commerce merchants can use Pandectes to automate data scanning, cookie categorization, consent logs, and reporting as part of their privacy management programs.

Small and medium-sized businesses should start with a baseline program modeled on GDPR best practices, then localize for PPCDA specifics, rather than waiting for regulations to fill every gap.

Make Your Shopify Store GDPR & Cookie Compliant in Minutes
Automatically manage cookie consent, block tracking before user approval, and stay compliant with GDPR, CCPA, LGPD, UK GDPR and Google Consent Mode v2 β€” without coding.

Consent remains the default basis for personal information use under Bill C-36. Bill C-36 includes stricter consent requirements compared to previous regulations. Valid consent requires plain-language disclosure of purposes and methods, data types collected, third-party recipients, and reasonably foreseeable consequences. Organizations must provide plain-language disclosures for consent, and individuals can withdraw consent on reasonable notice under PPCDA.

Bill C-36 sharpens the distinction between express and implied consent. Implied consent is narrowed, especially for sensitive data or behavior-influencing purposes. Consent obtained through misleading practices, dark patterns, or incomplete information will be invalidated. A reasonable person standard applies: would a reasonable person consider the purpose appropriate given the circumstances?

The “business activities” exception allows certain collections without consent for core operational needs, such as fraud prevention or network security. It excludes purposes aimed at influencing an individual’s behavior or decisions. The “legitimate interest” exception requires a balancing test: benefits versus reasonably foreseeable adverse effect on individuals. Organizations must conduct privacy impact assessments for legitimate interest exceptions and document the analysis. Neither exception covers targeted advertising, personalized pricing, or other surveillance pricing practices; those require express, meaningful consent.

For a Shopify store running cookie-based remarketing, the merchant must obtain granular consent by purpose before firing advertising pixels. Using a consent management platform like Pandectes, the store can present a compliant cookie banner separating analytics from marketing consent, log each choice, and block scripts until opt-in is recorded.

Canadian building

Automated Decision Making, AI and Sensitive Data

Bill C-36 modernizes privacy rules around automated decision-making systems and artificial intelligence. Organizations are required to be transparent about automated decision-making processes that produce predictions, recommendations, or decisions with a legal or similarly significant effect on individuals, such as credit approvals, insurance quotes, or high-impact pricing decisions.

When using automated decision systems, organizations must inform individuals, provide an explanation on request covering main data sources and key factors, and offer a right to request human review. This applies to machine learning models, predictive analytics engines, and rule-based systems alike. For businesses deploying AI-driven tools, governance processes including documented logic, impact assessments, and bias testing are expected even though dedicated AI legislation from Bill C-27 did not carry forward into this bill.

Bill C-36 formalizes the definition of “sensitive” personal information. Sensitive information includes health and genetic data, biometric data capable of uniquely identifying an individual, racial or ethnic origin, political or religious beliefs, sexual orientation, and trade union membership. De-identified data remains regulated due to reasonably foreseeable risk of re-identification. Only anonymized data, where identification is not reasonably foreseeable, falls outside scope.

A retailer using an AI engine for dynamic discounts based on customer scoring would need to disclose this in its privacy policy, explain the logic on request, and offer human review. Any risks identified through impact assessments must be mitigated before deployment.

Make Your Shopify Store GDPR & Cookie Compliant in Minutes
Automatically manage cookie consent, block tracking before user approval, and stay compliant with GDPR, CCPA, LGPD, UK GDPR and Google Consent Mode v2 β€” without coding.

Cross-Border Transfers and International Data Flows

Bill C-36 tightens rules for cross-border data transfers. Privacy impact assessments are mandatory for cross-border data transfers, requiring documentation before transferring personal information outside Canada. These assessments should cover categories of data, purposes of transfer, the destination country’s legal environment, contractual and technical safeguards, and residual foreseeable risk.

The Commission or consumer data division can request these assessments at any time and may issue guidance for acceptable cross-border transfer practices. Organizations must be transparent with individuals about transferring personal information interprovincially or internationally where it creates reasonably foreseeable consequences, including naming categories of foreign service providers.

Shopify stores commonly use third-party apps, payment gateways, analytics, and marketing platforms that process data in the US or EU. For vendor contracts, review these elements:

  • Data processing locations and sub-processors
  • Contractual obligations reflecting PPCDA requirements
  • Technical safeguards (encryption, access controls)
  • Incident notification timelines
  • Cooperation with privacy impact assessments

A consent and cookie management tool like Pandectes can identify third-party scripts, map cross-border data flows, and display accurate notices aligned with both PPCDA and GDPR cross-border rules. Businesses should implement measures to keep their vendor inventory current.

Penalties, Enforcement, and Practical Steps to Get Ready

The bill establishes administrative monetary penalties for non-compliance under a two-tier regime. For certain contraventions, significant administrative monetary penalties reach up to the greater of C$10 million or 3% of gross global revenue. For most serious offenses such as obstruction, fines reach C$25 million or 5% of an organization’s gross global revenue. The proposed penalties can reach C$10 million or 3% of revenue at the lower tier alone.

Enforcement starts with investigations and notices of violation from the privacy commissioner, with rights of review and appeals to the Federal Court. The Commission applies balancing factors: organization size, data sensitivity, best interests of children, and impact on digital innovation and competition. This means the regulatory oversight does not hold SMEs to the same operational standard as large platforms, but compliance is still required.

A prioritized readiness roadmap for Canadian businesses:

  1. Map all data and vendors
  2. Update privacy notices, cookie banners, and consent flows
  3. Design a basic documented privacy management program
  4. Prepare templates for privacy impact assessments
  5. Train staff, especially marketing and product teams

Conclusion

For Shopify merchants, quick wins include implementing a compliant cookie banner with granular consent via the Pandectes GDPR Compliance Shopify app, enabling consent logging, reviewing cross-border apps, and creating playbooks for handling access, deletion, and children’s data requests. The proposed changes in the legislative process may evolve, but organizations already compliant with GDPR or CCPA and using specialized SaaS tools will adapt fastest when PPCDA comes into force. This significant overhaul of private sector privacy rules rewards early preparation.

Make Your Shopify Store Fully GDPR & CCPA Compliant Today
Pandectes GDPR Compliance App for Shopify
Share
Subscribe to learn more
pandectes

Related Articles