Artificial intelligence is moving faster than most regulation can track, and Bill C-36 is Canada's most serious attempt yet at closing that gap. For any business building or deploying AI systems that touch personal data, this is the point where AI privacy stops being a someday concern and starts becoming a present-tense planning question — even though, as you'll see below, the actual legal deadline is still some way off.
Is Bill C-36 Law Yet?
Direct answer: No. Bill C-36 received first reading in the House of Commons on June 15, 2026, and is not law. It must still pass second reading, committee study, third reading, and Senate review, then receive royal assent — and even then, its privacy obligations don't switch on automatically.
Parliament rose for the summer on June 18, 2026, with regular sittings scheduled to resume September 21, 2026. Bill C-36 is expected to begin second reading debate once the House returns in the fall. From there it proceeds to committee, where amendments are likely, before third reading and Senate consideration.
There's a further wrinkle worth understanding before you make any architecture decisions based on this bill: even after royal assent, the PPCDA's privacy provisions require a separate Order in Council before they take effect. That Order is sequenced behind a companion bill (the Digital Safety Act, Bill C-34) also receiving royal assent, and behind the new Digital Safety and Data Protection Commission of Canada becoming operational. In practical terms, privacy reform in Canada is now tied to the construction of an entirely new regulator from scratch — not just the passage of a statute. Several legal observers and privacy commentators have flagged this sequencing as the reason the PPCDA's substantive obligations are unlikely to bind businesses for at least a couple of years, even in an optimistic scenario.
What this means for you: you are not out of compliance with the PPCDA today, because it doesn't yet exist as law. PIPEDA, Quebec's Law 25, Alberta's PIPA, and British Columbia's PIPA already apply to any AI system touching personal information right now, and they are being actively enforced. The PPCDA is the direction things are heading — planning around it early is cheap; retrofitting under a compliance deadline later is not.
What Is Bill C-36? What Is the PPCDA?
Bill C-36 is the legislative vehicle; the PPCDA is the law it would create. Introduced by the Minister of Artificial Intelligence and Digital Innovation as part of Canada's national AI strategy, the bill is the federal government's third attempt in six years to modernize private-sector privacy law, following Bill C-11 (2020) and Bill C-27 (2022), both of which died on the Order Paper.
If enacted, the PPCDA would repeal the privacy provisions of PIPEDA and replace them with a modernized framework built around a few structural shifts:
- A fundamental-right framing. Privacy would be recognized as a fundamental right in the bill's purpose clause, alongside the existing balancing test between individual privacy interests and organizations' legitimate needs.
- A new regulator. Private-sector privacy oversight would move from the Office of the Privacy Commissioner of Canada to the newly created Digital Safety and Data Protection Commission of Canada, led by a dedicated Privacy and Consumer Data Commissioner.
- Real enforcement teeth. Order-making powers and administrative monetary penalties — something PIPEDA has never had for general privacy violations.
- AI-aware definitions. Personal information would expressly include information inferred about an individual, which matters enormously for AI systems built on prediction and profiling rather than directly collected data.
It's still fundamentally a consent-based, principles-based regime — the PPCDA doesn't reinvent Canadian privacy law from scratch so much as substantially strengthen and modernize it.
What Would the PPCDA Actually Change?
Stripped of legislative language, the core proposed changes are:
- Organizations would need meaningful consent, with plain-language explanations of how personal information is handled — dense legal notices buried in onboarding flows wouldn't be sufficient in spirit, though the bill retains the existing legal standard of "valid consent" (express by default, implied as the exception) rather than adopting a new statutory "meaningful consent" test.
- New and expanded exceptions to consent would be introduced, including for defined business activities and a "legitimate interest" exception, several of which are tied to privacy impact assessments.
- Individuals would gain a right to disposal (deletion or data anonymization) of their information, and a new data mobility (portability) right — though data mobility wouldn't take effect until separate implementing regulations exist.
- Businesses would need transparency around automated decision-making, plus a new right for individuals to seek human review of automated decisions with a legal or similarly significant effect.
- Cross-border data transfers would require a privacy impact assessment before personal information is disclosed or transferred outside Canada.
- A mandatory privacy management program would become a statutory requirement, not just best practice.
- Children's personal information would receive materially stronger protection.
- Penalties would be tiered, up to the greater of $10 million or 3% of global revenue for administrative violations, and up to the greater of $25 million or 5% for the most serious offences.
This is squarely an AI compliance and data governance story. It's why AI privacy and general privacy compliance can no longer be treated as separate workstreams inside an organization.
Sensitive Personal Information Under Bill C-36
Direct answer: The PPCDA introduces a statutory, open-ended definition of sensitive personal information tied to a heightened expectation of privacy — expressly including health, genetic, and biometric data, racial or ethnic origin, political and religious beliefs, sexual orientation, and children's information.
Unlike a fixed checklist, this is a contextual category: information becomes "sensitive" based on the privacy expectation attached to it, not just a static list. That matters for AI systems in a specific way. Health records, biometric identifiers, and demographic attributes are exactly the kind of data that:
- gets pasted into LLM prompts by employees trying to move quickly
- ends up embedded in vector databases powering RAG systems
- feeds AI analytics and scoring models
- passes through third-party AI APIs with data-handling terms nobody on the team has actually read
Sensitive information processed by AI systems would carry a higher compliance bar under the PPCDA than routine contact or transactional data — which means it deserves a higher bar for how it's handled operationally, today, regardless of when the bill takes effect.
Is De-Identified Data Still Personal Information?
Direct answer: Under the PPCDA's proposed framework, yes — de-identified data generally remains personal information and stays inside the Act, while only fully anonymized data (meeting a "no reasonably foreseeable risk of re-identification" standard) falls outside it entirely.
This is a distinction worth getting right, because the terms get used interchangeably in most boardrooms and most AI vendor documentation:
- Anonymization alters data so individuals theoretically cannot be re-identified. Done properly, anonymized data would fall outside the PPCDA's scope entirely — but the actual technical standard for what counts is left to future regulations, and true anonymization is genuinely hard to achieve at scale.
- De-identification removes direct identifiers but retains some re-identification risk, particularly when combined with other datasets. Under the PPCDA's own definitions, de-identified information stays inside the Act's protection.
- Pseudonymization replaces identifiers with tokens or keys, but the mapping back to the individual still exists somewhere.
- Encryption protects data in transit or at rest but says nothing about whether the underlying content is identifying once decrypted or processed.
The practical takeaway for AI teams: removing a name or email address from a dataset does not automatically make it safe for unrestricted AI processing. This connects directly to how AI prompts, embeddings, and vector databases work. Vectorization converts text into numerical embeddings, and it's tempting to assume that because embeddings look like meaningless numbers, they're inherently anonymized. That assumption deserves scrutiny — research on embedding inversion has shown that, under certain conditions, meaningful portions of source text can be reconstructed from its vector representation. If the text feeding your embeddings still contains personal or sensitive data, converting it to a vector hasn't achieved anonymization; it's just changed the data's format.
How Would Bill C-36 Affect Automated Decision-Making?
Direct answer: The PPCDA would require transparency when automated systems are used to make significant decisions about individuals, and would introduce a new right for individuals to request human review of automated decisions that carry a legal or similarly significant effect.
This provision is one of the more direct hits on how enterprise AI systems actually get built. Practical scenarios where this matters:
- Credit and lending — automated eligibility or risk scoring
- Insurance — AI-assisted underwriting or claims triage
- Hiring and employee screening — resume ranking, candidate scoring, or automated interview analysis
- Fraud detection — models that flag or block transactions without a human in the loop
- Eligibility decisions — benefits, service access, or account approvals
- Pricing — algorithmic or personalized pricing models
If AI meaningfully influences a decision like these, the practical implication is that the organization would need to be able to disclose that fact and explain the decision in terms a person can actually understand — not just point to a model output. That's a design requirement as much as a legal one: systems built as opaque black boxes are harder to make compliant after the fact than systems designed from the start with an audit trail for what data went in and why a given output came out.
Does Bill C-36 Require Privacy Impact Assessments?
Direct answer: Yes, in defined circumstances — most notably before disclosing or transferring personal information outside Canada, and in connection with certain expanded consent exceptions such as the proposed "legitimate interest" basis.
A privacy impact assessment (PIA) isn't just a legal checkbox; for AI-driven organizations it's a practical inventory exercise. A useful PIA for an AI workflow should realistically evaluate:
- what personal data is being collected and why
- whether any of it qualifies as sensitive personal information
- which AI models or third-party AI vendors touch that data
- where that data is physically processed or stored, and whether it crosses borders
- how long the data is retained, and what deletion actually looks like in practice
- whether the workflow involves automated decision-making with a significant effect on individuals
- what security controls exist at each step, from ingestion to model output
Building this habit now, before it's a statutory requirement, is one of the lower-cost things an organization can do — it's mostly a documentation and process exercise rather than a technical rebuild.
How Would Bill C-36 Protect Children's Personal Information?
Direct answer: The PPCDA proposes a single definition of a child as anyone under 18, classifies children's information as sensitive by default, requires the regulator to weigh the best interests of children in exercising its powers, and sets a higher bar before an organization can refuse a child's request to delete their information.
For any organization running AI applications, recommendation systems, chatbots, or profiling that could reach or affect minors, this proposed framework would raise the bar meaningfully above standard consumer data handling. Even ahead of enforcement, it's a sensible design principle: age-gate what needs age-gating, and treat any dataset that plausibly includes minors' information as sensitive by default.
Who Would Enforce Canada's New Privacy Framework?
Direct answer: A newly created Digital Safety and Data Protection Commission of Canada would take over private-sector privacy oversight from the Office of the Privacy Commissioner, with a dedicated Privacy and Consumer Data Commissioner and, for the first time, order-making powers and administrative monetary penalties.
This is a genuine structural shift, not a rebranding. The current Office of the Privacy Commissioner has investigative and recommendation powers but, under PIPEDA, no ability to directly impose financial penalties for privacy violations. The PPCDA would change that by folding private-sector privacy enforcement into a broader commission that also oversees Bill C-34's digital-safety and online-harms mandate. The commission would investigate complaints, issue notices of contravention with proposed penalties, and conduct internal reviews of its own decisions before any appeal reaches the Federal Court. Some privacy law observers have raised questions about how quickly a brand-new, multi-mandate regulator will build up dedicated privacy expertise — worth watching as the bill moves through committee, but not something that changes what businesses should be doing to prepare today.
What Are the Penalties Under Bill C-36?
Direct answer: As introduced, the PPCDA proposes a tiered penalty structure — administrative monetary penalties up to the greater of $10 million or 3% of an organization's global gross revenue for general violations, and penal fines up to the greater of $25 million or 5% of global revenue for the most serious offences.
These figures reflect the bill as introduced at first reading and could be amended during committee study before the bill is finalized. They are meaningfully higher than anything currently available under PIPEDA, which has no general administrative monetary penalty regime for privacy violations today. The bill also includes a conditional private right of action, giving individuals a further avenue for recourse beyond regulatory enforcement.