Skip to main content

Bill C-36 Hub

Canada's third attempt to replace PIPEDA.

Here is what it means for a company like yours. This hub tracks Bill C-36, the proposed Protecting Privacy and Consumer Data Act, through Parliament and translates the draft into plain, operational guidance for teams that already did Law 25.

Status: Bill C-36, second reading, House of Commons. Not law yet. First reading: June 15, 2026. Last checked October 1, 2026.

For teams that did Law 25

I did Law 25. What is new for me?

Eight upgrades deserve immediate attention. A Law 25 control can be reused only after its trigger, scope, decision rule, evidence, and owner are mapped to the proposed federal requirement. Open each delta below.

1. Federal reach

The proposal would cover commercial activity, federal-sector employee data, and interprovincial or international handling, subject to exemptions. Where PIPEDA already applied, the new statute is broader. You need a record-level jurisdiction and flow rule, not a single "we are covered" determination.

If a substantially similar provincial law governs an intra-provincial activity, it continues to apply there. The overlap question is per data flow, so map applicability at the flow level.

What changes in practice

Add a jurisdiction column to your data inventory: for every flow, record why it falls under the proposed federal statute, a substantially similar provincial law, or both. Revisit any flow that crosses provincial or national borders.

2. Inferred information counts as personal information

The definition of personal information expressly includes information inferred about an individual. Scores, segments, predictions, profiles, and model outputs you derive from other data are in scope, not just the inputs you collected.

This closes a gap many teams left in their Law 25 inventories: derived attributes were documented as analytics metadata rather than personal information. Under C-36 they attract the same duties, including access, correction, and disposal.

What changes in practice

Extend your data inventory to list inferred outputs: risk scores, customer segments, churn predictions, recommendation profiles, and any model output tied to an individual. Tag their lineage, retention, and where they are disclosed.

3. Children's information starts at under 18

Under the proposal, a child is under 18, and children's information is listed as sensitive. Law 25's consent rule for children draws the line at 14. If your controls stop at 14, teens aged 14 to 17 are uncovered.

Sensitive information attracts heightened protection duties. Treat the under-18 population as a distinct control layer across collection, use, disclosure, and security, not as an extension of the under-14 consent workflow.

What changes in practice

Build an under-18 control overlay across every product surface: age detection, consent flows, default privacy settings, and marketing exclusions. Do not rely on Law 25's under-14 rule alone.

4. Legitimate interest: a gated consent exception

The proposed legitimate-interest exception lets an organization collect, use, or disclose personal information without consent, but only when a recorded interest outweighs the foreseeable adverse effects on the individual. The gate requires a documented interest, a privacy impact assessment, an adverse-effect analysis, and mitigation measures.

This is the consent exception most likely to be misused. Casual "we have a legitimate interest" reasoning will not survive scrutiny without the recorded analysis behind it.

What changes in practice

Create a gated assessment that blocks any legitimate-interest use until the interest is recorded, a PIA is completed, adverse effects are analyzed, and mitigations are in place. Ban informal use of this exception.

5. Transfers outside Canada need a PIA first

Before personal information is disclosed or transferred outside Canada, the proposal would require a privacy impact assessment and mitigations. Law 25 teams already do transfer assessments, but for Quebec-origin transfers. The C-36 trigger is any Canada-origin outbound flow.

The duty attaches before the transfer happens. Your existing transfer assessment workflow needs a new gate: no outbound disclosure without a completed PIA and documented mitigations.

What changes in practice

Adapt your Quebec transfer assessment to a Canada-origin trigger. Inventory every cross-border disclosure, including processors and sub-processors, and run the assessment before the first transfer, not after.

6. Automated decisions: explanation and human review

Systems that assist or replace human judgment can trigger explanation and human-review duties when they produce legal or similarly significant effects on individuals. This reaches beyond fully automated decisions: decision-support systems are in scope too.

Law 25 teams inventoried exclusively automated decisions. The C-36 lens is wider, so your inventory needs to capture assistive systems like scoring and recommendation engines.

What changes in practice

Broaden the automated-decision inventory beyond exclusively automated systems. For each system, document the effect it can have on individuals, what explanation you provide, and how a person can request human review.

7. Disposal orchestration, including downstream

Disposal requests can require deletion or anonymization and downstream service-provider action, with documented exceptions. Deleting a row in your own database is not enough when copies live with processors.

You need deletion propagation: a defined path from request intake to every downstream holder, plus refusal records for documented exceptions where disposal does not apply.

What changes in practice

Build deletion propagation into your request workflow: map which service providers hold personal information, define the disposal instruction you send them, track completion, and record the reason for any documented exception.

8. Regulator-ready evidence

The proposed Privacy Commissioner can request program materials, investigate, audit, and order measures. The question is not whether you have policies, but whether you can produce the evidence behind them on demand.

"We already do PIAs" is not enough if the PIA gate misses legitimate-interest uses or transfers outside Canada. Each control needs its trigger, scope, decision rule, evidence, and owner mapped to the proposed federal requirement.

What changes in practice

Create an indexed evidence room: every program control filed with its trigger, scope, decision rule, evidence, and owner. Run quarterly control tests so the materials are current before the regulator ever asks.

The hub

Everything in one place

Where to go next