On 15 June 2026 the federal government introduced Bill C-36. Part 1 of it is the Protecting Privacy and Consumer Data Act (PPCDA), the proposed replacement for the privacy part of PIPEDA, the Personal Information Protection and Electronic Documents Act. In October 2026 the bill was at second reading. It is not law yet, and it will not come into force until a date the government sets after the new Digital Safety and Data Protection Commission exists.
That gives Canadian businesses time. The question is how to use it without paying for privacy compliance twice.
Most of the PPCDA is PIPEDA, written down
PIPEDA's ten Fair Information Principles have always been broad. The PPCDA turns them into specific duties: a written privacy management program with staff training (s. 9), purposes that are appropriate and recorded (s. 12), plain-language consent (ss. 15-17), retention and disposal (ss. 52 and 54), safeguards proportionate to sensitivity (s. 56), breach reporting and records (ss. 58-61), and access and complaints (ss. 63-73).
If your PIPEDA program works today, you already do most of this. You only have to complete your controls once to comply with PIPEDA today and the PPCDA tomorrow. The trick is keeping the evidence in a form that answers both, so the day the Act comes into force is a review, not a project.
What is new
- A privacy impact assessment before personal information leaves Canada (s. 57). Cloud services, overseas support teams, backups, and analytics tools all count. This is the biggest new duty for most organizations.
- A privacy impact assessment before relying on legitimate interest (s. 18). PIPEDA has no legitimate interest basis at all; the PPCDA allows one, with an assessment first.
- Automated decisions (ss. 62-63). Describe any automated decision system that could have a legal or similarly significant effect on people, explain decisions on request, and let a person ask an employee to review the result.
- Children (ss. 2 and 4). Anyone under 18 is a child, and a child's information is sensitive. If you also serve the United States, COPPA's under-13 rule applies there too; design to the stricter rule.
- Disposal on request (s. 54), including at your service providers.
- Penalties. Administrative monetary penalties up to the higher of $10 million and 3% of gross global revenue (s. 114), and fines up to the higher of $25 million and 5% (s. 145). Due diligence, or following an approved certification program, is a defence to a penalty (s. 113).
Start with where your data goes
The transfer assessment is where to begin, because you cannot assess a transfer you do not know about. Make a list of every place personal information goes: your line-of-business apps, email, file sharing, help desk, payroll, backups, and every AI tool someone has signed up for with a work email. Record which country each one stores or reaches the data from.
That list is useful now, not just after Bill C-36 passes. Quebec Law 25 already requires an assessment before personal information leaves Quebec, and Alberta PIPA already requires you to tell people when a service provider outside Canada handles their information.
How Lavawall® prepares you
ThreeShield built Lavawall® so the same platform covers the law in force and the one coming. The full walkthrough is in Preparing for the PPCDA on lavawall.com. In short:
- Training: security awareness and privacy law courses, including one on Bill C-36, with completion certificates as evidence that your privacy program trains staff (s. 9).
- GRC: PIPEDA, the PPCDA, Alberta PIPA, BC PIPA, Quebec Law 25, and the health privacy acts mapped to one set of controls, with policy templates and a readiness assessment that asks only about the gaps.
- Privacy impact assessments: one assessment covers every law you select, with types for transfers outside Canada, legitimate interest, and AI. An approved assessment counts as evidence for the controls that ask for it.
- SaaS discovery: finds the cloud and AI apps your staff actually use, and who uses them, so each one can be assessed before the PPCDA's transfer and automated decision rules apply.
- Monitoring and security: patching, endpoint security monitoring, and breach detection across Microsoft 365, Entra ID, and Google Workspace produce the safeguard evidence that s. 56 and PIPEDA Principle 4.7 ask for.
- Encryption checking: disk encryption status (BitLocker and FileVault) on every computer, checked continuously instead of once a year.
- Canadian data residency: the data you provide to Lavawall is all stored in Canada. Notifications may pass through Irish and American service providers, and the data residency page lists each exception.
What to do this quarter
- Confirm your PIPEDA program is real: a named privacy officer, a written program, trained staff, and current policies.
- Map your data flows and vendors, including the cloud and AI apps nobody told IT about.
- Run a privacy impact assessment for each transfer outside Canada, starting with the most sensitive information.
- Decide whether you will rely on legitimate interest once it exists, and if so, assess it.
- Train your staff on what Bill C-36 changes.
For the full requirement-by-requirement plan, read Preparing for the PPCDA on lavawall.com, or see our PPCDA compliance services.
ThreeShield offers a free compliance scoping call to identify which privacy laws apply to your business, where your PIPEDA program already covers the PPCDA, and what is left to do.
Book a Scoping CallThis article summarizes proposed legislation for planning. It is not legal advice. Section numbers follow the first-reading text of Bill C-36 and may change in committee.