Skip to main content

Bill C-36 Hub

Glossary: the bill's language, in plain words

Thirty-six terms from the proposed Protecting Privacy and Consumer Data Act, defined without the legalese. Each entry carries a C-36 context line that ties the term to the bill as introduced. Other hub pages link here when a definition matters mid-explanation.

Bill C-36 is proposed legislation. Definitions below reflect the bill as introduced; they may change as Parliament amends it.

Protecting Privacy and Consumer Data Act (PPCDA)

The name of the federal statute Bill C-36 would enact. It would repeal and replace Part 1 of PIPEDA, the private-sector provisions that have governed commercial privacy in Canada since 2000.

C-36 context: As introduced on June 15, 2026, the bill sits at second reading in the House of Commons. It is proposed legislation, not law, and no commencement date has been set.

Personal information

Information about an identifiable individual: names, emails, and addresses, but also identifiers like IP addresses, device IDs, and behavioural records when they can be linked to a person.

C-36 context: The proposed definition expressly includes inferred personal information, closing a gap that let organizations argue scores and profiles were not really personal data.

Inferred personal information

Information inferred about an individual: predictions, propensity scores, audience segments, risk ratings, and other model or rule outputs attributed to a person.

C-36 context: Because inferences count as personal information under the bill, organizations must inventory model outputs and analytics tables, apply retention rules to them, and include them in access requests and deletion responses.

Substantially similar law

A provincial privacy law that the federal government has recognized as offering protections equivalent to the federal standard. Quebec's law has held this status under PIPEDA.

C-36 context: Where a substantially similar provincial law governs an activity within that province, it continues to apply there. The overlap question is per data flow, so map each flow to the federal statute, the provincial law, or both.

Sensitive personal information

Personal information that warrants a higher level of protection because of its nature: health data, financial details, location traces, credentials, biometrics, and information about children. Sensitivity triggers express consent and stricter safeguards.

C-36 context: Children's information is listed as sensitive, so any organization that touches under-18 data inherits the high-protection defaults.

Minor (under-18)

A person under 18 years of age. The bill sets the child threshold at 18, higher than the under-14 marker some practitioners still anchor on from Quebec rules.

C-36 context: Under-18 data is sensitive by default. Organizations need an overlay across journeys: age-appropriate notices, best-interests reviews, consent mapping against Law 25's under-14 parent-consent rule, and short retention defaults.

Organization

The actor the bill's duties attach to. In the proposal it covers associations, partnerships, persons, companies, and other private-sector bodies handling personal information in commercial activity.

C-36 context: Proposed federal reach extends to commercial activity, federal-sector employee and applicant data, and interprovincial or international handling, subject to exemptions for substantially similar provincial laws. Scope is decided at the data flow, not the office address.

Service provider

An organization that processes personal information on behalf of, and under the instructions of, another organization: cloud hosts, analytics vendors, email platforms, payment processors. The provider may only use the data for the documented purpose.

C-36 context: Contracts must guarantee equivalent protection: purpose limitation, confidentiality, safeguards, subprocessor control, rights support, retention and verified deletion, incident assistance, and audit rights. A deletion request can require downstream provider action.

Legitimate interest

A proposed consent exception for processing an organization can justify as pursuing a genuine interest that outweighs foreseeable adverse effects, where a reasonable person would expect the activity.

C-36 context: It is a gated decision, not a shortcut. The bill's proposal requires a recorded interest, a privacy impact assessment, an adverse-effect balancing test, and mitigations before collection begins. It cannot cover targeted advertising, personalized pricing, or behavioural nudging.

Appropriate purposes

The objective test every collection, use, and disclosure must pass: would a reasonable person consider the purpose appropriate in the circumstances? No amount of consent wording saves an inappropriate purpose.

C-36 context: Purposes must be recorded at or before collection, and a new purpose requires a fresh record before the data is used for it.

Automated decision system

A technological system that assists or replaces human judgment using rules, regression, predictive analytics, machine learning, deep learning, or neural networks. Hiring screens, credit models, fraud scores, and recommendation engines all sit in this bucket.

C-36 context: The definition deliberately covers systems that assist decisions, not only fully automated ones. The key duties attach where the decision has a legal or similarly significant effect.

Explanation of automated decisions

The proposed duty to explain, on request, how an automated decision was reached: the prediction, recommendation, or decision itself; the types of information used and their sources; the important factors; and the effect.

C-36 context: Organizations must publish plain-language notice of the systems they use for significant decisions and keep an explanation pack ready: decision purpose, system role, key factors, limitations, human contribution, and how to request human review.

Human review

The proposed right to have a decision with legal or similarly significant effects reviewed by a person who has real discretion to change the outcome.

C-36 context: The reviewer must see relevant evidence, be able to depart from the system output, explain the result, and record the decision. A reviewer who only rubber-stamps a model score is not a meaningful safeguard.

Access request

An individual's request to know whether an organization holds their personal information, what it is, how it has been used, and to whom it has been disclosed.

C-36 context: The request operation must trace a person across systems and vendors, verify identity proportionately, apply the bill's exceptions with legal review, and respond in plain language within the applicable period, still to be confirmed in the final text and regulations.

Correction

The right to have inaccurate personal information corrected and, where appropriate, to have the correction communicated to recipients the organization previously shared the data with.

C-36 context: Correction intersects with automated decisions: a person who gets an explanation of a significant decision can challenge the underlying data and the reasoning.

Deletion / disposal

The proposed right to have personal information deleted or anonymized, including where its retention is no longer necessary for the purpose it was collected for.

C-36 context: Disposal is an orchestration problem, not a button. The request can require deletion to propagate to service providers, reach derived and inferred data, handle backups and archives, and be documented with exceptions where a legal hold or other ground requires temporary preservation.

Data portability

The proposed right to receive personal information in a structured, commonly used format and have it transmitted to another organization.

C-36 context: Portability operates under designated data mobility frameworks, whose details the bill leaves to later regulation, so the operational shape of this right is still open.

Data mobility framework

A designated framework enabling portability and interoperability between organizations: the standards, formats, and handoff rules that make data movement workable in practice.

C-36 context: The bill leaves the designation and mechanics of these frameworks to future action. Build rights workflows that assume the framework detail will arrive later.

Transfer assessment

The proposed assessment required before disclosing or transferring personal information outside Canada: mapping the flow, the parties, and the foreign legal environment, rating the risk, and recording mitigations.

C-36 context: Quebec teams already run similar assessments for transfers outside Quebec; the proposal extends the trigger to every exit from Canada and pairs it with a privacy impact assessment.

Cross-border transfer

Any disclosure or transfer of personal information outside Canada: cloud storage abroad, foreign subprocessors, offshore support access, and international analytics pipelines.

C-36 context: The proposal adds a privacy impact assessment and mitigation plan as a precondition for the transfer. Contracts and technical controls (encryption, key control, minimization, segregation) must be in place before approval, not after.

Privacy Commissioner of Canada

The proposed regulator for the PPCDA: the office that would investigate complaints, conduct audits, request program materials, and issue binding orders.

C-36 context: The bill moves the Commissioner from ombudsman to enforcer, with order-making power and the ability to impose administrative monetary penalties. Organizations should prepare an indexed evidence room and a regulator-response playbook.

Personal Information and Data Protection Tribunal

The proposed specialist tribunal that would hear appeals from the Commissioner's orders and decisions, and review certain penalty matters.

C-36 context: The Tribunal gives the enforcement regime a dedicated appeal layer. Its exact procedures and membership will be set in the bill and regulations, so treat process details as pending.

Administrative monetary penalties

Financial penalties the regulator could impose for contraventions of the bill, without going through criminal prosecution. This is the sharp edge of the proposed enforcement regime.

C-36 context: The bill creates the penalty power and sets its structure; confirm exact amounts and calculation rules against the bill text itself, not summaries, since they may change through amendments.

Private right of action

The proposed right for individuals to bring a civil claim in court following specified final findings, decisions, agreements, or convictions under the regime.

C-36 context: This is a litigation-exposure channel as well as a compliance one. Organizations should preserve decision evidence, connect complaint handling to litigation hold, and manage privilege around investigation records.

Privacy management program

The proposed statutory accountability program: documented policies, named leadership, training, risk assessment, safeguards, and ongoing monitoring, scaled to the organization's size and data risk.

C-36 context: The Commission can request program materials during an investigation or audit. The evidence standard is operational proof, not a policy binder: completed assessments, timestamped approvals, logs, and test results.

Privacy impact assessment (PIA)

A structured assessment of necessity, proportionality, foreseeable harm, and mitigations for a processing activity, approved before the activity begins.

C-36 context: The bill's proposal adds new triggers to the Law 25-style PIA: legitimate-interest processing, transfers outside Canada, and material system changes, plus enhanced assessment for children, sensitive data, biometrics, and high-impact automated decisions.

Breach of security safeguards

The loss of, unauthorized access to, or unauthorized disclosure of personal information. Every breach must be recorded; notification to the regulator and affected individuals applies where the statutory threshold is met.

C-36 context: Current PIPEDA and Law 25 incident duties stay in force. The proposal would add its own notification and record-keeping duties, so keep a dual-law playbook and add a PPCDA decision module without replacing the in-force rules.

De-identified information

Personal information with direct identifiers removed, where the individual could still be identified through reasonably foreseeable means, for example by linking to auxiliary data.

C-36 context: De-identified information stays within the bill's personal-information controls, subject to tailored provisions. Removing names is de-identification, not anonymization.

Anonymized information

Personal information that has been irreversibly and permanently modified, under generally accepted best practices, so that no reasonably foreseeable risk of identifying the individual remains.

C-36 context: Only true anonymization takes data outside the bill's scope. Organizations should document the risk method, context, assumptions, tests, and ongoing review, because a technique that can be reversed with outside data is de-identification, and a claimed anonymization that fails is a liability.

Employee personal information

Personal information collected from, about, or relating to employees, applicants, and other personnel: payroll, performance, health accommodations, and screening data.

C-36 context: The proposal's federal reach includes federal-work employee and applicant data, a scope expansion against PIPEDA's old employment carve-out. HR programs need their own applicability record.

Business transaction

A proposed consent exception for specified commercial transactions such as mergers and acquisitions, where disclosing personal information is necessary for the transaction to proceed.

C-36 context: The exception is conditional: necessity, notice, and safeguards for the transaction data room must be worked out with counsel before a deal uses it.

Publicly available information

Information in categories the regulations designate as publicly available, which the bill treats differently from other personal information for certain consent purposes.

C-36 context: The categories are prescribed, so the operative list does not exist yet. Do not build reliance on a category until the regulation names it.

Retention

Keeping personal information only as long as necessary for the purpose it was collected for, then destroying it or anonymizing it. Retention rules must be set up front, not invented after the fact.

C-36 context: Each retention rule needs a start event (collection, account closure, contract end), a duration tied to business need and legal hold, an action (delete or anonymize), and evidence that it ran, including in backups, lakes, and provider systems.

Complaint

An individual's route to the Commissioner when an organization refuses a request, mishandles their information, or otherwise breaches the proposed duties.

C-36 context: The complaint workflow is receive, preserve, investigate, remedy, and learn. Complaints and investigations feed the private right of action, so preserve records and privilege from the first notice.

Prescribed

Defined by regulation rather than by the statute itself. Wherever the bill says a requirement is prescribed, the detail will come from regulations that do not exist yet.

C-36 context: This is a build-versus-bind boundary. Build the workflow and capture the core facts now; keep prescribed fields configurable and do not hard-code assumptions about what the regulations will say.

Reading further

For terms that predate the bill, the main privacy glossary covers PIPEDA, Law 25, CASL, and AI-governance concepts in the same plain language. The hub'sLaw 25 to C-36 delta map shows how these terms change real programs, and training tracks turn them into role-specific lessons.