JUN 17, 2026

Canada Bill C-36: New AI Privacy Rules for Businesses

Bill C-36 is a federal bill, introduced June 15, 2026, that would enact the Protecting Privacy and Consumer Data Act (PPCDA), replacing PIPEDA's privacy provisions — Canada's 25-year-old private-sector privacy law. It is not yet in force. If passed, it would recognize privacy as a fundamental right, add new rules for sensitive data and automated decision-making, and introduce penalties up to 5% of global revenue. Businesses using AI on Canadian personal data should understand it now, even though the timeline isn't fixed.

Canada'S New AI Privacy Law What Businesses Must Know

Key Takeaways

  • Bill C-36 was introduced June 15, 2026, and had completed only first reading when Parliament rose for the summer; it is proposed legislation, not current law.
  • The PPCDA would replace PIPEDA's privacy provisions, introduce a new regulator (the Digital Safety and Data Protection Commission of Canada), and create Canada's first administrative monetary penalty regime for general privacy violations.
  • Personal information would be redefined to expressly include information inferred about a person — a direct hit to how AI profiling, scoring, and recommendation systems are typically built.
  • Sensitive personal information (health, biometric, genetic, children's data, and more) would get materially stronger protection, with direct implications for what enters LLMs, RAG pipelines, and AI agents.
  • The bill introduces a statutory distinction between de-identified data (still personal information) and anonymized data (outside the Act) — a distinction most AI teams currently treat far too loosely.
  • Penalties would scale up to the greater of $25 million or 5% of global revenue for the most serious offences, once the regime is actually in force.
  • Coming into force is not automatic on royal assent — it depends on a separate Order in Council tied to a companion bill and a new regulator becoming operational, which is why "prepare now, panic never" is the right posture.

Artificial intelligence is moving faster than most regulation can track, and Bill C-36 is Canada's most serious attempt yet at closing that gap. For any business building or deploying AI systems that touch personal data, this is the point where AI privacy stops being a someday concern and starts becoming a present-tense planning question — even though, as you'll see below, the actual legal deadline is still some way off.

Is Bill C-36 Law Yet?

Direct answer: No. Bill C-36 received first reading in the House of Commons on June 15, 2026, and is not law. It must still pass second reading, committee study, third reading, and Senate review, then receive royal assent — and even then, its privacy obligations don't switch on automatically.

Parliament rose for the summer on June 18, 2026, with regular sittings scheduled to resume September 21, 2026. Bill C-36 is expected to begin second reading debate once the House returns in the fall. From there it proceeds to committee, where amendments are likely, before third reading and Senate consideration.

There's a further wrinkle worth understanding before you make any architecture decisions based on this bill: even after royal assent, the PPCDA's privacy provisions require a separate Order in Council before they take effect. That Order is sequenced behind a companion bill (the Digital Safety Act, Bill C-34) also receiving royal assent, and behind the new Digital Safety and Data Protection Commission of Canada becoming operational. In practical terms, privacy reform in Canada is now tied to the construction of an entirely new regulator from scratch — not just the passage of a statute. Several legal observers and privacy commentators have flagged this sequencing as the reason the PPCDA's substantive obligations are unlikely to bind businesses for at least a couple of years, even in an optimistic scenario.

What this means for you: you are not out of compliance with the PPCDA today, because it doesn't yet exist as law. PIPEDA, Quebec's Law 25, Alberta's PIPA, and British Columbia's PIPA already apply to any AI system touching personal information right now, and they are being actively enforced. The PPCDA is the direction things are heading — planning around it early is cheap; retrofitting under a compliance deadline later is not.

What Is Bill C-36? What Is the PPCDA?

Bill C-36 is the legislative vehicle; the PPCDA is the law it would create. Introduced by the Minister of Artificial Intelligence and Digital Innovation as part of Canada's national AI strategy, the bill is the federal government's third attempt in six years to modernize private-sector privacy law, following Bill C-11 (2020) and Bill C-27 (2022), both of which died on the Order Paper.

If enacted, the PPCDA would repeal the privacy provisions of PIPEDA and replace them with a modernized framework built around a few structural shifts:

  • A fundamental-right framing. Privacy would be recognized as a fundamental right in the bill's purpose clause, alongside the existing balancing test between individual privacy interests and organizations' legitimate needs.
  • A new regulator. Private-sector privacy oversight would move from the Office of the Privacy Commissioner of Canada to the newly created Digital Safety and Data Protection Commission of Canada, led by a dedicated Privacy and Consumer Data Commissioner.
  • Real enforcement teeth. Order-making powers and administrative monetary penalties — something PIPEDA has never had for general privacy violations.
  • AI-aware definitions. Personal information would expressly include information inferred about an individual, which matters enormously for AI systems built on prediction and profiling rather than directly collected data.

It's still fundamentally a consent-based, principles-based regime — the PPCDA doesn't reinvent Canadian privacy law from scratch so much as substantially strengthen and modernize it.

What Would the PPCDA Actually Change?

Stripped of legislative language, the core proposed changes are:

  • Organizations would need meaningful consent, with plain-language explanations of how personal information is handled — dense legal notices buried in onboarding flows wouldn't be sufficient in spirit, though the bill retains the existing legal standard of "valid consent" (express by default, implied as the exception) rather than adopting a new statutory "meaningful consent" test.
  • New and expanded exceptions to consent would be introduced, including for defined business activities and a "legitimate interest" exception, several of which are tied to privacy impact assessments.
  • Individuals would gain a right to disposal (deletion or data anonymization) of their information, and a new data mobility (portability) right — though data mobility wouldn't take effect until separate implementing regulations exist.
  • Businesses would need transparency around automated decision-making, plus a new right for individuals to seek human review of automated decisions with a legal or similarly significant effect.
  • Cross-border data transfers would require a privacy impact assessment before personal information is disclosed or transferred outside Canada.
  • A mandatory privacy management program would become a statutory requirement, not just best practice.
  • Children's personal information would receive materially stronger protection.
  • Penalties would be tiered, up to the greater of $10 million or 3% of global revenue for administrative violations, and up to the greater of $25 million or 5% for the most serious offences.

This is squarely an AI compliance and data governance story. It's why AI privacy and general privacy compliance can no longer be treated as separate workstreams inside an organization.

Sensitive Personal Information Under Bill C-36

Direct answer: The PPCDA introduces a statutory, open-ended definition of sensitive personal information tied to a heightened expectation of privacy — expressly including health, genetic, and biometric data, racial or ethnic origin, political and religious beliefs, sexual orientation, and children's information.

Unlike a fixed checklist, this is a contextual category: information becomes "sensitive" based on the privacy expectation attached to it, not just a static list. That matters for AI systems in a specific way. Health records, biometric identifiers, and demographic attributes are exactly the kind of data that:

  • gets pasted into LLM prompts by employees trying to move quickly
  • ends up embedded in vector databases powering RAG systems
  • feeds AI analytics and scoring models
  • passes through third-party AI APIs with data-handling terms nobody on the team has actually read

Sensitive information processed by AI systems would carry a higher compliance bar under the PPCDA than routine contact or transactional data — which means it deserves a higher bar for how it's handled operationally, today, regardless of when the bill takes effect.

Is De-Identified Data Still Personal Information?

Direct answer: Under the PPCDA's proposed framework, yes — de-identified data generally remains personal information and stays inside the Act, while only fully anonymized data (meeting a "no reasonably foreseeable risk of re-identification" standard) falls outside it entirely.

This is a distinction worth getting right, because the terms get used interchangeably in most boardrooms and most AI vendor documentation:

  • Anonymization alters data so individuals theoretically cannot be re-identified. Done properly, anonymized data would fall outside the PPCDA's scope entirely — but the actual technical standard for what counts is left to future regulations, and true anonymization is genuinely hard to achieve at scale.
  • De-identification removes direct identifiers but retains some re-identification risk, particularly when combined with other datasets. Under the PPCDA's own definitions, de-identified information stays inside the Act's protection.
  • Pseudonymization replaces identifiers with tokens or keys, but the mapping back to the individual still exists somewhere.
  • Encryption protects data in transit or at rest but says nothing about whether the underlying content is identifying once decrypted or processed.

The practical takeaway for AI teams: removing a name or email address from a dataset does not automatically make it safe for unrestricted AI processing. This connects directly to how AI prompts, embeddings, and vector databases work. Vectorization converts text into numerical embeddings, and it's tempting to assume that because embeddings look like meaningless numbers, they're inherently anonymized. That assumption deserves scrutiny — research on embedding inversion has shown that, under certain conditions, meaningful portions of source text can be reconstructed from its vector representation. If the text feeding your embeddings still contains personal or sensitive data, converting it to a vector hasn't achieved anonymization; it's just changed the data's format.

How Would Bill C-36 Affect Automated Decision-Making?

Direct answer: The PPCDA would require transparency when automated systems are used to make significant decisions about individuals, and would introduce a new right for individuals to request human review of automated decisions that carry a legal or similarly significant effect.

This provision is one of the more direct hits on how enterprise AI systems actually get built. Practical scenarios where this matters:

  • Credit and lending — automated eligibility or risk scoring
  • Insurance — AI-assisted underwriting or claims triage
  • Hiring and employee screening — resume ranking, candidate scoring, or automated interview analysis
  • Fraud detection — models that flag or block transactions without a human in the loop
  • Eligibility decisions — benefits, service access, or account approvals
  • Pricing — algorithmic or personalized pricing models

If AI meaningfully influences a decision like these, the practical implication is that the organization would need to be able to disclose that fact and explain the decision in terms a person can actually understand — not just point to a model output. That's a design requirement as much as a legal one: systems built as opaque black boxes are harder to make compliant after the fact than systems designed from the start with an audit trail for what data went in and why a given output came out.

Does Bill C-36 Require Privacy Impact Assessments?

Direct answer: Yes, in defined circumstances — most notably before disclosing or transferring personal information outside Canada, and in connection with certain expanded consent exceptions such as the proposed "legitimate interest" basis.

A privacy impact assessment (PIA) isn't just a legal checkbox; for AI-driven organizations it's a practical inventory exercise. A useful PIA for an AI workflow should realistically evaluate:

  • what personal data is being collected and why
  • whether any of it qualifies as sensitive personal information
  • which AI models or third-party AI vendors touch that data
  • where that data is physically processed or stored, and whether it crosses borders
  • how long the data is retained, and what deletion actually looks like in practice
  • whether the workflow involves automated decision-making with a significant effect on individuals
  • what security controls exist at each step, from ingestion to model output

Building this habit now, before it's a statutory requirement, is one of the lower-cost things an organization can do — it's mostly a documentation and process exercise rather than a technical rebuild.

How Would Bill C-36 Protect Children's Personal Information?

Direct answer: The PPCDA proposes a single definition of a child as anyone under 18, classifies children's information as sensitive by default, requires the regulator to weigh the best interests of children in exercising its powers, and sets a higher bar before an organization can refuse a child's request to delete their information.

For any organization running AI applications, recommendation systems, chatbots, or profiling that could reach or affect minors, this proposed framework would raise the bar meaningfully above standard consumer data handling. Even ahead of enforcement, it's a sensible design principle: age-gate what needs age-gating, and treat any dataset that plausibly includes minors' information as sensitive by default.

Who Would Enforce Canada's New Privacy Framework?

Direct answer: A newly created Digital Safety and Data Protection Commission of Canada would take over private-sector privacy oversight from the Office of the Privacy Commissioner, with a dedicated Privacy and Consumer Data Commissioner and, for the first time, order-making powers and administrative monetary penalties.

This is a genuine structural shift, not a rebranding. The current Office of the Privacy Commissioner has investigative and recommendation powers but, under PIPEDA, no ability to directly impose financial penalties for privacy violations. The PPCDA would change that by folding private-sector privacy enforcement into a broader commission that also oversees Bill C-34's digital-safety and online-harms mandate. The commission would investigate complaints, issue notices of contravention with proposed penalties, and conduct internal reviews of its own decisions before any appeal reaches the Federal Court. Some privacy law observers have raised questions about how quickly a brand-new, multi-mandate regulator will build up dedicated privacy expertise — worth watching as the bill moves through committee, but not something that changes what businesses should be doing to prepare today.

What Are the Penalties Under Bill C-36?

Direct answer: As introduced, the PPCDA proposes a tiered penalty structure — administrative monetary penalties up to the greater of $10 million or 3% of an organization's global gross revenue for general violations, and penal fines up to the greater of $25 million or 5% of global revenue for the most serious offences.

These figures reflect the bill as introduced at first reading and could be amended during committee study before the bill is finalized. They are meaningfully higher than anything currently available under PIPEDA, which has no general administrative monetary penalty regime for privacy violations today. The bill also includes a conditional private right of action, giving individuals a further avenue for recourse beyond regulatory enforcement.

Bill C-36 vs. PIPEDA: What's Changing for Businesses?

Bill C-36 vs. PIPEDA: What's Changing for Businesses?
AreaPIPEDA (current law)PPCDA (as proposed in Bill C-36)
Legal basis for processingMultiple lawful bases (consent, contract, legal obligation, legitimate interest, etc.)Still primarily consent-based, with a narrower legitimate-interest exception layered in
Sensitive dataClosed list of "special category" dataOpen-ended, context-dependent category
Data mobilityNot providedNew right, pending implementing regulations
Sensitive informationNo standalone statutory categoryNew open-ended statutory category tied to heightened privacy expectation
Automated decision-makingNo specific statutory provisionsNew transparency requirements and a right to human review for significant automated decisions
Privacy impact assessmentsNot a general statutory requirementRequired for cross-border transfers and certain consent exceptions
AccountabilityAccountability principle, no mandated program structureMandatory privacy management program required
RegulatorOffice of the Privacy Commissioner of CanadaDigital Safety and Data Protection Commission of Canada
Enforcement powersInvestigation and recommendations; limited order-making in narrow contextsOrder-making powers, administrative monetary penalties, private right of action
PenaltiesNo general AMP regime for privacy violationsUp to the greater of $10M or 3% (general); up to the greater of $25M or 5% (serious offences)

Bill C-36 vs. GDPR: What Businesses Need to Know

Bill C-36 vs. GDPR: What Businesses Need to Know
AreaGDPR (EU)PPCDA (as proposed)
Legal basis for processingMultiple lawful bases (consent, contract, legal obligation, legitimate interest, etc.)Still primarily consent-based, with a narrower legitimate-interest exception layered in
Sensitive dataClosed list of "special category" dataOpen-ended, context-dependent category
Automated decision-makingRight not to be subject to solely automated decisions with legal/significant effect (Article 22), subject to exceptionsRight to human review of automated decisions with legal or similarly significant effect
Impact assessmentsDPIAs required broadly for high-risk processingPIAs required for specific triggers (cross-border transfer, certain consent exceptions)
EnforcementIndependent national data protection authorities in each member stateSingle federal commission, also responsible for digital-safety matters
Maximum penaltiesUp to €20 million or 4% of global annual turnoverUp to the greater of $25M CAD or 5% of global revenue (most serious offences)
Cross-border transfersAdequacy decisions, standard contractual clausesNew PIA requirement before international transfer; broader adequacy question for Canada is one some commentators are watching as the new commission takes shape

The two frameworks are directionally aligned — both push toward stronger individual rights, higher penalties, and more transparency around automated decisions — but they're not identical, and "GDPR-compliant" is not shorthand for "PPCDA-ready."

Canadian Provincial Privacy Laws Still Matter

Federal reform doesn't erase the provincial layer. Depending on where your organization operates or whose data you handle, you may also need to account for:

  • Quebec's Law 25, already fully in force, with its own consent, automated-decision-making, and penalty framework
  • Alberta's PIPA (Personal Information Protection Act)
  • British Columbia's PIPA

Historically, PIPEDA has stepped back for intra-provincial commercial activity in provinces with privacy legislation the federal government has declared "substantially similar" — a structure the PPCDA is expected to largely preserve, though this is worth confirming as the bill moves through committee. This isn't a simple either/or. Organizations operating across provinces should work out which federal and provincial requirements actually apply to their specific data flows rather than assuming one framework covers everything. This article isn't legal advice — that determination is worth making with counsel.

Canada's AI Regulation and Privacy Rules in 2026

It's worth being precise about what Bill C-36 is and isn't. The PPCDA is privacy legislation, not a standalone AI statute. Canada's earlier attempt at dedicated AI regulation, the Artificial Intelligence and Data Act (AIDA), was part of Bill C-27, which died on the Order Paper in 2025. As of this update, Canada does not have a dedicated federal AI law in force or in progress — its national AI strategy leans on modernizing existing frameworks like privacy law, rather than introducing new AI-specific rules, at least for now.

That means "AI regulation in Canada" today is really a patchwork:

  • Privacy law (PIPEDA now, PPCDA once and if enacted) governs how personal information feeds AI systems
  • Sector-specific rules (financial services, health, insurance) layer on additional obligations for AI used in regulated activities
  • Provincial privacy laws apply independently in provinces with their own frameworks
  • No general AI-specific statute currently exists federally

Businesses should be cautious about treating every AI governance obligation as though it flows from Bill C-36 — much of what applies to AI systems today comes from privacy law generally, existing sector regulation, and international frameworks like the EU AI Act for companies operating across borders.

Who Needs to Prepare for Bill C-36?

Organizations that should be paying attention now include:

  • SaaS and software companies with Canadian customers
  • Companies building or deploying AI products or AI-assisted features
  • Financial services and lending
  • Healthcare and health-tech
  • Insurance
  • HR technology and applicant tracking systems
  • BPOs and outsourced service providers handling Canadian customer data
  • Retailers running personalization or pricing algorithms
  • Any data-driven business processing Canadian customer or employee information
  • Organizations relying on third-party LLM providers as part of their product or operations

If your organization touches Canadian personal information and uses AI anywhere in that pipeline, this bill is relevant to you regardless of size.

Practical AI Privacy Compliance Checklist

A working checklist for enterprise privacy and AI teams:

  • Inventory every AI system that touches personal data, internal or vendor-provided
  • Map personal-data flows end to end, from collection through model input to output storage
  • Identify where sensitive personal information appears in those flows
  • List every third-party LLM or AI API provider in use, and review their data-handling terms
  • Review cross-border processing — where is data actually stored and processed?
  • Identify any automated decision-making with a legal or significant effect on individuals
  • Document how automated decisions are made and explainable, in plain language
  • Review current consent language against how AI systems actually use the data collected
  • Test deletion workflows end to end, including whether data persists in vendor systems or model caches
  • Confirm how children's data is identified and handled, if applicable
  • Run a privacy impact assessment on at least your highest-risk AI workflow
  • Review data retention schedules and minimize what's kept
  • Implement redaction or de-identification before data reaches AI systems, not after
  • Review AI vendor contracts for data-processing, retention, and sub-processor terms
  • Establish audit trails showing what data moved where, and why
  • Document your AI privacy governance program in writing

What Businesses Should Do Now

None of the PPCDA's obligations are enforceable today, and treating them as though they already were would be inaccurate. But the direction is clear enough — and consistent enough with what PIPEDA, Quebec's Law 25, and international frameworks already require — that a few concrete steps make sense regardless of when the bill takes effect:

  1. Conduct an AI data inventory. You can't protect what you haven't mapped.
  2. Identify your highest-risk AI workflows — the ones touching sensitive data or making significant decisions about people.
  3. Review your AI vendors and LLM providers for how they handle, retain, and process the data you send them.
  4. Strengthen data minimization — send AI systems only what they actually need.
  5. Prepare a privacy impact assessment template you can apply as new AI projects come online.
  6. Review automated decision systems for explainability and the practical ability to support human review.
  7. Establish governance documentation now, so you're not reconstructing it under deadline pressure later.
  8. Test your privacy controls, particularly redaction and deletion, rather than assuming they work as designed.

Where AI Privacy Technology Fits

Most privacy failures in AI systems aren't the result of bad intent — they're the result of standard architecture quietly routing raw, unredacted data into third-party models as a matter of routine operation. Once information leaves your environment and is ingested by an external model, retroactively scrubbing it is nearly impossible. That's the underlying reason PII discovery, sensitive-data detection, redaction, and anonymization have moved from "nice to have" to core AI infrastructure for enterprises serious about privacy.

Technology can help with several parts of this problem directly:

  • discovering and classifying sensitive data before it reaches an AI system
  • redacting or anonymizing that data at the point of ingestion, rather than after the fact
  • minimizing what's sent to third-party LLMs by default
  • enforcing data-handling policy in the architecture itself, rather than relying on employees remembering a rule
  • maintaining auditable records of what data moved where, which supports both privacy impact assessments and, eventually, PPCDA-style compliance documentation

This is the gap Questa AI are built to close. Questa AI's approach centers on keeping sensitive data inside a local-first environment by default and applying redaction at the ingestion layer, before information is vectorized or sent to an external model — so the compliance groundwork becomes a byproduct of how the system is architected rather than a separate project layered on top later. Whether or not you use a vendor for this, the underlying requirement is the same: as privacy law modernizes, what your architecture physically allows will matter as much as what your privacy policy says.

For organizations preparing AI systems for stricter privacy requirements, the practical next step is understanding exactly where personal information enters your AI workflows and putting controls around that entry point — before data reaches a model or a third-party service, not after something goes wrong.

Frequently Asked Questions

Bill C-36 is a federal bill, introduced June 15, 2026, that would enact the Protecting Privacy and Consumer Data Act (PPCDA) and replace the privacy provisions of PIPEDA. It is not yet law.

PPCDA stands for the Protecting Privacy and Consumer Data Act, the new privacy statute Bill C-36 proposes to create.

There isn't a standalone AI law in Canada currently. Bill C-36's PPCDA is privacy legislation with AI-relevant provisions — such as covering inferred personal information and automated decision-making — rather than a dedicated AI statute.

Not as a standalone AI law. It regulates personal information, including information inferred by AI systems and decisions made or influenced by automated systems, but it isn't an AI-specific statute like the EU AI Act.

Yes. It proposes transparency requirements for significant automated decisions and a new right for individuals to request human review.

Yes, in specific circumstances — most notably before transferring personal information outside Canada, and for certain expanded consent exceptions.

An open-ended category tied to heightened privacy expectations, expressly including health, genetic, and biometric data, racial or ethnic origin, political and religious beliefs, sexual orientation, and children's information.

Start with an AI data inventory, review your highest-risk automated decision systems and third-party AI vendors, strengthen data minimization, and document your privacy governance now — well ahead of any enforcement deadline.

Practically: discover and classify sensitive data before it reaches an AI system, redact or anonymize it at the point of ingestion rather than after, minimize what's sent to third-party models, and keep an audit trail of where data moves and why.

Conclusion

Bill C-36 isn't law yet, and treating it as though it were would be getting ahead of the facts. But the direction is settled enough — stronger rights, real penalties, and a sharper focus on how AI systems use personal information — that waiting for royal assent before you act is the more expensive path, not the safer one. The organizations that come out ahead won't be the ones that reacted fastest once the PPCDA takes effect; they'll be the ones that quietly built the data inventory, the vendor review, and the local redaction habits years before the deadline forced anyone's hand.

Abhi Author

About the author:

Abhiroop Sharma

Ex. Distinguished technology leader

Distinguished technology leader with 18+ years of progressive experience spanning AI, Web3, SaaS, eCommerce, and blockchain governance. Demonstrated success in driving digital transformation across global markets, with expertise in scaling enterprise solutions from concept to implementation. Proven track record of reducing implementation timelines by 50% and building high-performing teams across multiple organizations. Currently focused on pioneering AI implementation and Web3 integration strategies for emerging technology ventures.
Follow the expert:

Related Articles

View More
EU AI Act Deadline: 30 Days to Get Compliant
JUL 03, 2026
Privacy Cafe

EU AI Act Deadline: 30 Days to Get Compliant

The EU AI Act deadline hits August 2, 2026. See what's changing, who's affected, and the compliance checklist enterprises need before it lands.

Read More
AI Privacy Firewall: Prevent Sensitive Data Leakage
JUN 05, 2026
Privacy Cafe

AI Privacy Firewall: Prevent Sensitive Data Leakage

An AI privacy firewall detects, masks, and blocks sensitive data before it reaches AI models — reducing enterprise data leakage risk.

Read More
AI Security Riders: Why 2026 Cyber Insurance Requires Local Redaction
MAR 19, 2026
Privacy Cafe

AI Security Riders: Why 2026 Cyber Insurance Requires Local Redaction

AI security riders in 2026 cyber insurance require local redaction. Learn how to prevent data leaks, avoid claim denials, and reduce premiums.

Read More