If you spent 2023 and 2024 preparing for the Consumer Privacy Protection Act (CPPA), you may have wondered whether that work was wasted. The CPPA was Part 1 of Bill C-27, and it died when Parliament was prorogued on 6 January 2025. It never came into force.
The good news: most of it came back. Bill C-36, introduced on 15 June 2026, contains the Protecting Privacy and Consumer Data Act (PPCDA), which keeps most of the CPPA's structure. Your CPPA preparation carries over.
What carries over
- A written privacy management program, scaled to the volume and sensitivity of what you hold.
- Purposes that a reasonable person would consider appropriate, assessed and recorded.
- Plain-language consent, express unless implied consent is clearly appropriate.
- The business activities exception, and a legitimate interest exception with an assessment first.
- Disposal on request, retention limits, de-identification, and data mobility.
- Administrative monetary penalties up to the higher of $10 million and 3% of gross global revenue.
What changed
- Transfers outside Canada need a privacy impact assessment (s. 57). The CPPA only required your privacy policy to mention international transfers. The PPCDA requires an assessment and mitigations first.
- Legitimate interest now covers disclosure, not just collection and use, and the assessment is a privacy impact assessment in a form the regulations will set (s. 18).
- Automated decisions get human review. The test is a "legal or similarly significant effect", and people can make written representations to an employee who can review the decision (s. 63(6)).
- Children are defined as anyone under 18 (ss. 2 and 4). The CPPA treated minors' information as sensitive without defining a minor.
- A new regulator, and no Tribunal. The Privacy and Consumer Data Commissioner sits inside the Digital Safety and Data Protection Commission. The CPPA's separate Personal Information and Data Protection Tribunal is gone.
- No AI act. Bill C-27 also carried the Artificial Intelligence and Data Act. Bill C-36 does not.
Do not throw away your PIPEDA program either
Until the PPCDA comes into force, PIPEDA is still the law. The safest approach is one set of controls that answers PIPEDA, the CPPA work you already did, and the PPCDA together. You complete the controls once: they show compliance with PIPEDA today and readiness for the PPCDA tomorrow. Only the genuinely new duties, mainly transfer assessments, legitimate interest assessments, and automated decision review, add work.
That is how Lavawall® treats them. PIPEDA, the CPPA, and the PPCDA are separate frameworks in the platform, mapped to the same controls, so evidence you collect once counts toward all three, and the PPCDA readiness assessment asks only about what is new.
How Lavawall® prepares you
ThreeShield built Lavawall® so the same platform covers the law in force and the one coming. The full walkthrough is in Preparing for the PPCDA on lavawall.com. In short:
- Training: security awareness and privacy law courses, including one on Bill C-36, with completion certificates as evidence that your privacy program trains staff (s. 9).
- GRC: PIPEDA, the PPCDA, Alberta PIPA, BC PIPA, Quebec Law 25, and the health privacy acts mapped to one set of controls, with policy templates and a readiness assessment that asks only about the gaps.
- Privacy impact assessments: one assessment covers every law you select, with types for transfers outside Canada, legitimate interest, and AI. An approved assessment counts as evidence for the controls that ask for it.
- SaaS discovery: finds the cloud and AI apps your staff actually use, and who uses them, so each one can be assessed before the PPCDA's transfer and automated decision rules apply.
- Monitoring and security: patching, endpoint security monitoring, and breach detection across Microsoft 365, Entra ID, and Google Workspace produce the safeguard evidence that s. 56 and PIPEDA Principle 4.7 ask for.
- Encryption checking: disk encryption status (BitLocker and FileVault) on every computer, checked continuously instead of once a year.
- Canadian data residency: the data you provide to Lavawall is all stored in Canada. Notifications may pass through Irish and American service providers, and the data residency page lists each exception.
For the requirement-by-requirement plan, read Preparing for the PPCDA on lavawall.com, or see our pages on the CPPA and the PPCDA.
ThreeShield offers a free compliance scoping call to identify which privacy laws apply to your business, where your PIPEDA program already covers the PPCDA, and what is left to do.
Book a Scoping CallThis article summarizes proposed legislation for planning. It is not legal advice. Section numbers follow the first-reading text of Bill C-36 and may change in committee.