Skip to main content

Bill C-36 Hub

The tool finder

Six capabilities your privacy program may need for Bill C-36 readiness. For each one: what it must do, the questions to ask any vendor, and how it connects to the bill's proposed duties. Buy capabilities after defining the operating need, never before.

No sponsored listings, no affiliate links, no vendor names. This finder describes capabilities so you can evaluate any tool on your own terms. Run each candidate through the demo scripts below, with your data, before you score it.

Capability 1 of 6

Deletion orchestration

How it maps to C-36: the bill proposes a disposal right, deletion or anonymization, with downstream service-provider action and documented exceptions. See the deletion delta.

What the capability must do

  • Schedule and run deletion across production, data lakes, analytics, logs, archives, endpoints, email, and backups
  • Propagate deletion to service providers and record their confirmation, not just the request
  • Pause for legal holds: narrow, authorized, time-limited, and released promptly
  • Produce deletion proof: job ID, systems reached, records affected, exceptions, approver, completion date

Questions to ask vendors

  • Show me one sample deletion running end to end, from request to provider confirmation.
  • How do backups and archives get handled without breaking restore?
  • What happens to derived data, inferred profiles, and model features?
  • How is a legal hold applied, authorized, and released?
  • What does the deletion proof look like, and can I export it without your help?

Capability 2 of 6

Transfer assessments

How it maps to C-36: the bill proposes a PIA and mitigations before disclosure or transfer outside Canada. Start with the free transfer assessment template.

What the capability must do

  • Keep a transfer register: flow, countries, data types, volume, recipients, subprocessors, onward transfers
  • Trigger assessment workflows for transfers outside Canada, with mitigation plans and approvals
  • Flag re-assessment triggers: country or law change, new subprocessor, new purpose, security event
  • Link each assessment to its contracts and technical controls, versioned with approvers and review dates

Questions to ask vendors

  • How does the register detect a new destination country?
  • What triggers a re-assessment, and who gets told?
  • Show the path from assessment to approval to expiry.
  • How are foreign legal and government-access risk factors recorded?
  • Can I run the workflow with our own fields, or am I locked into yours?

Capability 4 of 6

Access and correction request handling

How it maps to C-36: access, correction, disposal, explanation, and review duties all run through one request operation. The tool has to carry the whole journey, not just the intake form.

What the capability must do

  • Intake requests across every public channel, with identity verification sized to the risk of the request
  • Route search tasks to system and vendor owners with deadlines and completeness attestations
  • Support redaction and a second review of every refusal or exception
  • Deliver responses securely in plain language, with reasons and recourse
  • Report volume, age, extensions, refusals, rework, and complaints monthly

Questions to ask vendors

  • Walk me through one request from intake to response without switching tools.
  • How do you verify identity without over-collecting?
  • Show how a refusal gets a second review before it goes out.
  • How are third-party records handled in a search?
  • What does the metrics dashboard actually measure, deadline by deadline?

Capability 5 of 6

Automated-decision transparency

How it maps to C-36: the bill proposes explanation and human-review duties for decisions with legal or similarly significant effects, including systems that assist decisions rather than fully automate them.

What the capability must do

  • Keep a register of systems that assist or replace judgment: owner, decision, population, inputs, outputs, human role
  • Generate explanation packs on request: factors, reasons, information types used, effect
  • Route human-review cases to authorized reviewers with turnaround, real discretion, and reasoned results
  • Track accuracy, data quality, bias and impact testing, drift, overrides, incidents, and complaints

Questions to ask vendors

  • Show the explanation a person would actually receive, not a developer log.
  • How does a reviewer see the evidence, depart from the output, and record the decision?
  • What stops the human review from being a rubber stamp in practice?
  • How do you test for bias and drift, and where do the results live?
  • When the model changes, is the explanation pack regenerated?

Capability 6 of 6

Records and evidence

How it maps to C-36: a regulator-ready evidence room turns the readiness program into something you can prove. Assertions without owners, approvals, and test results do not count.

What the capability must do

  • Keep an immutable audit trail of assessments, approvals, decisions, and changes
  • Index an evidence room mapped to controls, owners, and test results
  • Run control tests with results, issue registers, remediation plans, and closure approvals
  • Export the control and evidence package without vendor assistance

Questions to ask vendors

  • Show me the full export of our evidence package, no professional services required.
  • What prevents someone from editing an approval after the fact?
  • How do issues move from finding to remediation to closure?
  • Can I map one control to every piece of evidence behind it?
  • How are superseded versions kept separate from the current record?