Skip to main content

Bill C-36 Hub

Training tracks: the law, translated for your job

Three self-paced tracks built from the C-36 Readiness Playbook. Each teaches the decisions its audience actually makes: executives approve risk and resourcing, marketers own consent and profiling, developers own data scope, deletion, and system evidence. Written from the bill as introduced; none of this is law yet.

Bill C-36 is proposed legislation. Lessons below reflect the bill as introduced; they may change as Parliament amends it.

Track 1

The 20-minute executive briefing

Time: about 20 minutes to read.

For: CEOs, board members, risk committees, and anyone who approves privacy risk, budget, or go-live decisions.

Lesson 1: Why C-36 matters now, before it is law

Bill C-36 would enact the Protecting Privacy and Consumer Data Act and replace PIPEDA's private-sector provisions. It reached second reading in the House of Commons in the summer of 2026 and is proposed legislation, not law. Building now is still rational, because the bill adds a federal operating layer on top of what a Law 25 program already does, rather than demanding a second program.

Build on the existing program instead of starting over. A mature Law 25 program already has accountable leadership, an inventory, privacy impact assessments, incident management, rights handling, vendor controls, and retention rules. The bill changes several thresholds and adds duties, but most of the control system survives. The board question is not "do we start over" but "what does the existing program miss at federal scale."

There is a posture rule worth adopting early: describe the organization as readiness-aligned, never compliant with a law that is not yet in force. No false certification. The board memo should also carry an explicit legal-change gate, because amendment-sensitive wording, regulator names, prescribed forms, and commencement dates will all move as the bill progresses.

Lesson 2: The 8 deltas in one page

Against a Law 25 baseline, eight upgrades deserve executive attention. Federal reach: commercial activity, federal-sector employee data, and interprovincial or international handling, decided at the data flow. Inferred information: the bill expressly counts predictions, scores, and profiles as personal information.

Children under 18: a child is under 18 and children's information is sensitive, a higher bar than Law 25's under-14 consent rule. Legitimate interest: a proposed consent exception that requires a recorded interest, a privacy impact assessment, adverse-effect balancing, and mitigations, and can never cover behavioural-influencing purposes. Transfers outside Canada: a privacy impact assessment and mitigations before disclosure or transfer abroad.

Automated decisions: systems that assist or replace judgment, not only fully automated ones, with explanation and human-review duties for legal or similarly significant effects. Disposal orchestration: deletion requests can require downstream service-provider action with documented exceptions. Regulator-ready evidence: the proposed Commission can request program materials, investigate, audit, and order measures, so the program must produce proof on demand.

Lesson 3: What the board must oversee

Every control needs exactly one accountable owner. System owners carry the technical execution; privacy advises and provides assurance. The board's accountabilities are finite: approve risk appetite, receive quarterly status, and challenge overdue critical gaps. Accepted risks are recorded with names and dates, not nodded through.

The quarterly dashboard should measure coverage, not activity. Critical control coverage: controls with an owner, approved design, evidence, and a passing test. High-risk privacy impact assessment coverage. Rights-request completion within applicable deadlines. Deletion proof: sampled actions with evidence across all in-scope stores and providers. Automated-decision review readiness for significant-effect systems. Overdue critical issues. Policy counts and training attendance do not prove control effectiveness, so do not let them into the dashboard.

The single decision the board is being asked for: approve a 180-day readiness program, appoint an executive sponsor who removes cross-functional blockers, and authorize system owners to remediate high-risk gaps before the final law is known.

Lesson 4: Budget and resourcing signals

Fund the risk and integration work before buying software. Budget in five categories: people (program lead, analysts, counsel, security, data engineering, change and training), process (assessment design, record clean-up, vendor remediation, exercises, audit), technology (configuration, connectors, identity, catalogue, deletion, case tooling, reporting), third parties (contract changes, assurance, testing, localization, exit), and a contingency for legislative amendments and remediation discoveries.

Spend in order: scope and inventory first, then high-risk controls and legal interpretation, then workflow and evidence, then integration and deletion, and only then automation and optimization. Size staffing by workload, not employee count: processing records to validate, high-risk assessments, vendors, transfer paths, automated decisions, rights and complaint volume, incidents, integrations, and training cohorts.

When making the business case, compare readiness cost against delayed launches, manual request handling, vendor remediation under deadline, regulatory exposure, and loss of customer trust. Do not use maximum penalties as the only argument; the board will see through it, and the numbers may change by Royal Assent.

Lesson 5: The 180-day shape of a rollout

Phase 0, mobilize (days 0 to 15): sponsor, charter, legal watch, system owner list, evidence repository. Exit gate: scope and decision rights approved. Phase 1, discover (days 16 to 45): control crosswalk, processing inventory refresh, vendor and automated-decision inventories, baseline metrics. Exit gate: all material business units assessed, every unknown owned by someone.

Phase 2, design (days 46 to 90): policies, playbooks, templates, data fields, tool requirements, prioritized backlog. Exit gate: counsel and control owners approve the target controls. Phase 3, build (days 91 to 150): workflow configuration, integrations, notices, contracts, deletion jobs, explanation packs, training. Exit gate: critical controls operate in a test environment.

Phase 4, prove (days 151 to 180): tabletops, sample requests, transfer and deletion tests, evidence index, executive attestation. Exit gate: no unaccepted critical gap, all residual risks documented. Phase 5, sustain (ongoing): quarterly tests, annual refresh, event-triggered reviews, legislative re-baseline. Do not delay discovery while waiting for regulations: build reversible controls now and delay only the fields that depend on prescribed detail.

Lesson 6: When to call counsel

Counsel confirms scope, provincial overlap, notices, exceptions, contractual language, and the final enacted text. Call early on the consent-exception decision tree: requested product or service, security or safety, and legitimate interest each have evidentiary requirements, and targeted advertising, personalized pricing, and behavioural nudging cannot ride the business-activity or legitimate-interest exceptions at all.

Counsel also owns the legislative watch. Three scenarios are worth planning for explicitly: the bill advances largely intact, in which case complete the build and finalize legal language; material amendments arrive, in which case run a clause-level impact review and update only the affected modules; or the bill stalls or is replaced, in which case keep the controls that improve Law 25 and PIPEDA operations, retire bill-specific labels, and preserve the reusable evidence.

One dependency counsel should track specifically: the bill's commencement provision is linked to an order in council and to Royal Assent of the Safe Social Media Act. Triage a material legal event within 5 business days, issue owner impacts within 10, and approve the revised plan within 20.

Executive next step

Brief the board with the board readiness memo, anchor the program on the legitimate-interest and automated-decisions deltas, and look up private right of action and administrative monetary penalties before the risk discussion.

Track 2

Consent and campaigns: the marketer's track

Time: about 35 minutes to read.

For: marketing, growth, CRM, and partnerships teams that own consent journeys, audience building, ad targeting, and martech vendors.

Lesson 1: Consent is the default route in campaigns

The bill keeps consent as the default basis when no exception clearly applies. Each purpose must be recorded at or before collection, and a new purpose needs a fresh record before the data is used for it. Collect only what is necessary for the recorded purposes; the campaign that harvests fields "just in case" is building an inventory liability.

The consent copy has a prescribed job: plain-language information, the consequences of consenting, and the names or types of third parties that will receive the data. Do not condition a product or service on consent beyond what is necessary to provide it. Product and legal should own a consent and preference standard together: purpose, version, timestamp, channel, and withdrawal status for every permission, synced across every touchpoint.

Withdrawal is where campaigns fail audits. It must work operationally across channels, downstream systems, and vendors, not only in the original sign-up form. Test the withdrawal path the way you test the sign-up path: from the unsubscribe click to the email platform, the data warehouse, the ad audience, and the vendor deletion confirmation.

Lesson 2: Legitimate interest is not a marketing basis

The bill's proposed legitimate-interest exception is a gated assessment, not a fallback. The organization must record the specific interest, show the processing is necessary for it, pass the reasonable-person expectation test, weigh the interest against foreseeable adverse effects, and put mitigations in place. Legal reviews the assessment before any collection begins.

There is a red line marketers must internalize: targeted advertising, personalized pricing, behavioural nudging, and similar influence purposes cannot rely on the proposed business-activity or legitimate-interest exceptions. If the campaign's purpose is to influence behaviour or decisions, stop and seek another basis with counsel.

Ban casual use inside your team. Any "we have a legitimate interest in emailing our list" proposal goes to the gated assessment and the legitimate-interest template. What the team should invest in instead: precise purpose records, clean consent versioning, and one-click withdrawal that actually propagates.

Lesson 3: Automated decisions in marketing, including profiling

The bill's definition covers systems that assist decisions, not only fully automated ones. Lead scoring, churn models, next-best-offer engines, dynamic pricing, and ad-targeting segments all fall in. The key duties attach where a decision has a legal or similarly significant effect, so marketing teams must inventory every scoring and segmentation system and record whether its effects cross that threshold and why.

For systems in scope, the bill proposes a plain-language notice of the system and how it is used, an explanation on request (the prediction or recommendation, the types of information used and their sources, the important factors, the effect), and human review by a reviewer with real discretion. Work with the data team on an explanation pack for each marketing model: decision purpose, outcome, system role, key factors, limitations, human contribution, adverse effect, and how to request correction or review.

Profiling adds a consent dimension: purpose records and notices must describe the profiling plainly, and sensitive data in the inputs raises the bar to express consent. Retire the scores you cannot explain; an opaque score with a significant effect is the bill's textbook problem case.

Lesson 4: Deletion requests across martech vendors

A disposal right fails unless deletion reaches the whole chain. Marketing owns some of the hardest stores: the CDP, the email platform, analytics tools, ad audiences, suppression lists, data lakes, and the vendors behind each. When a deletion request arrives, the sequence is verify, locate, decide, execute, and close, and marketing's job is the locate-and-execute leg across its own stack.

Do not accept "deletion supported" as evidence. Run one sample deletion through each major provider, including derived data and backups, and record the outcome. Contract minimums should include rights support, retention and verified deletion, and deletion certificates. Keep a refusal record where a legal hold or another ground requires temporary preservation; the hold must be narrow, authorized, time-limited, and released promptly.

The fairness check is simple: request fulfilment should not be harder than the original sign-up. If unsubscribing takes one click but deletion takes a support ticket and two weeks, the journey is the finding.

Lesson 5: Under-18 data in audience building

Under the bill, a child is under 18, and children's information is sensitive. That changes audience building at both ends: what you collect and what you target. Decide whether a service or campaign is directed to, likely used by, or knowingly processes children's data, and apply an under-18 control overlay, not only Law 25's under-14 consent rule.

The overlay: use proportionate age assurance; treat children's data as sensitive with high-protection defaults; run a best-interests review on the purpose and prohibit manipulative design and unnecessary profiling; write age-appropriate layered notices and test comprehension; design parent, guardian, and maturing-child rights routes with identity and authority checks; and use short retention defaults with disposal when no longer needed.

Vendor restrictions bite hardest in marketing: restrict ads, analytics, profiling, model training, and onward use of children's data. No child-facing feature or campaign launches without a named child-safety reviewer, an enhanced privacy impact assessment, default settings review, vendor review, and a tested disposal path.

Marketer next step

Audit your journeys with the privacy impact assessment template, check how you handle access requests, study the legitimate-interest delta, and pin consent, inferred personal information, and minor (under-18) where your team plans campaigns.

Track 3

Building for the bill: the developer's track

Time: about 45 minutes to read.

For: engineers, data engineers, MLOps, and product engineers who own systems, logs, models, vendors, and deletion paths.

Lesson 1: Inferred data is in scope. Your models and logs are inventory items.

The bill expressly includes inferred information in personal information. That means predictions, propensity scores, segments, embeddings, and model outputs attributed to an individual are personal data, not a separate category of "analytics byproduct." They inherit the full control set: purposes, consent or exception, retention, access, correction, and deletion.

Concretely: inventory the inference stores the same way you inventory source tables. Tag each model output with its inputs, the system and version that produced it, and the individuals or segments it can be joined to. Reconcile the declared flows against reality: logs, integrations, warehouse schemas, browser tags, and subprocessors. Never mark an unverified flow as compliant.

A quality test from the playbook: pick ten high-risk records and trace each from collection to every recipient, inference, decision, backup, and deletion path. If the map cannot support an access request or a transfer assessment, it is not complete.

Lesson 2: Deletion that propagates downstream

The bill's disposal right can require deletion to reach service providers, derived data, and analytics stores. Design for deletion the way you design for failure: make it a first-class path. For each in-scope system, the request operation needs verify, locate, decide, execute, and close, with the system tasks owned by name and deadline.

The engineering checklist: a canonical subject key that joins every store; a deletion job with an ID, the systems reached, records affected, exceptions, approver, and completion date; tombstone or equivalent patterns so downstream consumers stop serving the deleted records; propagation to providers and recipients with confirmations; backup expiry that actually expires; and derived tables and feature stores, not just the source row.

Conflicts are normal and must be designed for. A rights request, complaint, investigation, legal hold, or decision-access period may require temporary preservation. The hold must be narrow, authorized, time-limited, and released promptly, and the refusal must be documented. Test deletion end to end with a sample person and record the proof; a deletion that silently fails is a critical failure.

Lesson 3: Automated-decision transparency, what to log and expose

For systems that assist or replace judgment with legal or similarly significant effects, the bill proposes three operational duties: notice of the system, explanation on request, and human review. All three are engineering problems. Maintain an automated-decision register: system, owner, decision, population, model and vendor, inputs, sources, inferences, outputs, the human role, and frequency.

Log what the explanation pack needs: the decision purpose and outcome, the system's role, key information and source types, important factors, confidence and limitations where meaningful, the human contribution, the adverse effect, and how to request correction or human review. Version the model and the explanation together; an explanation that refers to a retired model is not evidence.

Human review must be able to change the outcome. Give the reviewer the relevant evidence, correction paths, departure authority, and a turnaround SLA, and record the reasoned result. A reviewer who sees only the model score, has no time, or lacks authority is not a meaningful safeguard. Monitor accuracy, data quality, bias, drift, overrides, incidents, and complaints continuously.

Lesson 4: Cross-border transfer assessments, what engineers must document

The bill proposes a privacy impact assessment and mitigation plan before disclosing or transferring personal information outside Canada. The assessment is only as good as its facts, and the facts live in engineering: source and destination country, data, volume, and frequency; the recipient, role, affiliates, and subprocessors; storage, remote access, support, backups, and onward transfers; foreign legal and government-access factors.

Document the technical controls too: encryption and who holds the keys, minimization, localization, segregation, audit rights, and exit and deletion mechanics. Then the decision: residual risk, owner, approval, effective date, next review, and change triggers. Review triggers include a country or law change, a new subprocessor, new data or purpose, a security event, an ownership change, a contract renewal, an audit finding, or a material technology change.

Since prescribed assessment requirements are left to regulation, keep the legal criteria configurable but build the workflow and capture the core facts now. Start with the Law 25 "outside Quebec" assessments and extend the trigger to every exit from Canada.

Lesson 5: Evidence and records, the audit trail is the product

The bill's proposed Commission can request program materials, investigate, and audit. The evidence standard is simple: a policy says what should happen, evidence shows that it did. A completed assessment, a timestamped approval, a system log, a ticket history, a signed contract, a test output, or a training record counts; an assertion does not.

Build the logging to make this easy. Detect and log access, export, model use, deletion, administrative change, and provider activity with stable IDs for person, system, vendor, model, purpose, control, assessment, request, and incident. Keep the evidence room indexed: governance, controls, processing, assessments, operations, remediation, and legal change, each with an owner, status, approval, effective date, review trigger, and retention.

When the regulator comes, respond from the indexed evidence copy. Preserve originals, track every production, explain gaps accurately, and never recreate an approval after the fact. Quarterly, test one failure-prone journey end to end: rights fulfilment, deletion propagation, or new-vendor intake.

Developer next step

Pick up the privacy impact assessment, transfer assessment, and vendor review templates, study the deletion and regulator-ready evidence deltas, and pin inferred personal information and transfer assessment where your team designs systems.