The Protecting Privacy and Consumer Data Act (PPCDA) is Canada's proposed replacement for PIPEDA, introduced as Bill C-36 in June 2026. It is not law yet. ThreeShield helps you stay compliant with PIPEDA today and plan for the PPCDA from the same program, without doing the work twice.
The Protecting Privacy and Consumer Data Act (PPCDA) is Part 1 of Bill C-36, introduced in the House of Commons on 15 June 2026. If it passes, it replaces the privacy part of PIPEDA (the Personal Information Protection and Electronic Documents Act) and becomes Canada's federal private-sector privacy law.
It is not in force. It comes into force only on a date the government sets by order in council, and not before the new Digital Safety and Data Protection Commission exists, which depends on Bill C-34, the Safe Social Media Act. Until then, PIPEDA, Alberta PIPA, BC PIPA, and Quebec Law 25 apply as they do today.
It is the third attempt to replace PIPEDA, after Bill C-11 and the Consumer Privacy Protection Act (CPPA) in Bill C-27, both of which died. It keeps most of the CPPA's structure. See what happened to the CPPA.
| Step | Status |
|---|---|
| Introduced | First reading, House of Commons, 15 June 2026 |
| Current stage | Second reading in the House of Commons (as of 6 October 2026) |
| Coming into force | On a date set by order in council, after the Digital Safety and Data Protection Commission is established |
| Until then | PIPEDA and the provincial privacy laws apply |
A privacy impact assessment and mitigating measures, such as contract terms or an approved certification, before personal information is disclosed or transferred outside Canada. This reaches cloud services, support desks, and backups hosted abroad.
Collection, use, or disclosure without consent for a legitimate interest that outweighs the effect on the person, only after a privacy impact assessment and steps to reduce the risks. PIPEDA has no equivalent.
A child is anyone under 18 and a child's information is sensitive. A parent or guardian exercises the child's rights unless the child wants to act personally and is able to.
People can ask for their information to be deleted or anonymized when it was handled unlawfully, consent was withdrawn, or it is no longer needed, and service providers must delete it too.
An explanation of an automated decision with a legal or similarly significant effect, and the chance to make written representations to an employee who can review it.
Administrative monetary penalties up to the higher of $10 million and 3% of gross global revenue, and fines up to the higher of $25 million and 5%. Due diligence is a defence to a penalty.
The PPCDA is mostly PIPEDA written as statute, so the controls you run for PIPEDA are the controls the PPCDA asks for. In Lavawall®, PIPEDA and the PPCDA are separate frameworks on one shared set of controls: every control mapped to PIPEDA is also mapped to the PPCDA, and a control implemented and evidenced once counts toward both. You stay compliant with the law in force and see exactly what is left for the proposed one, without running a second exercise.
| What you do once | PIPEDA (in force) | PPCDA (Bill C-36) | Counts toward both |
|---|---|---|---|
| Accountable privacy officer | Principle 4.1 | ss. 7-8 | ✓ |
| Written privacy program and staff training | Principle 4.1.4 | s. 9 | ✓ |
| Service provider contracts with equivalent protection | Principle 4.1.3 | ss. 11 and 61 | ✓ |
| Meaningful consent, express for sensitive information | Principle 4.3 | ss. 15-17 | ✓ |
| Collect only what the purpose needs | Principle 4.4 | s. 13 | ✓ |
| Retention periods and secure disposal | Principle 4.5 | ss. 52 and 54 | ✓ |
| Safeguards proportionate to sensitivity (encryption, MFA, access control) | Principle 4.7 | s. 56 | ✓ |
| Breach assessment, reporting, and notification | s. 10.1 | ss. 58-59 | ✓ |
| A record of every breach | s. 10.3 | s. 60 | ✓ |
| Plain-language privacy policy | Principle 4.8 | s. 62 | ✓ |
| Access requests answered within 30 days | Principle 4.9 | ss. 63-67 | ✓ |
| Complaint handling | Principle 4.10 | s. 73 | ✓ |
| PPCDA requirement | Lavawall® provides | ThreeShield delivers |
|---|---|---|
| Privacy impact assessment before transfers outside Canada (s. 57) | ⚑ Transfer assessment form and tracking control | Data-flow inventory and the assessments |
| Legitimate interest assessments (s. 18) | ⚑ Assessment record template | Reviewed and signed off by CISSP/CISA staff |
| Recorded purposes (s. 12) | ⚑ Record of purposes template | Workshops to build the record |
| Disposal on request (s. 54) | ⚑ Procedure template | Mapping deletion through every system and service provider |
| Explanation and review of automated decisions (s. 63) | ⚑ Statement and review procedure | Inventory of automated decision systems |
| Safeguards evidence (s. 56) | ✓ Continuously | — |
Most compliance platforms reuse a control across the frameworks they ship. The question for a Canadian organization is whether PIPEDA and the PPCDA are among them. If either has to be built as a custom framework, mapping it to your existing controls is your work, and it has to be redone as the bill changes in committee. If the platform charges per framework, planning for a bill that is not law yet costs extra. Lavawall® ships PIPEDA, the CPPA, and the PPCDA pre-built on one shared control set, and ThreeShield keeps them current as Bill C-36 moves.
Related: PIPEDA compliance · the CPPA (Bill C-27) · COPPA · Quebec Law 25
Official source: https://www.parl.ca/legisinfo/en/bill/45-1/c-36
No. It is Part 1 of Bill C-36, introduced on 15 June 2026 and at second reading in October 2026. PIPEDA remains the law until the PPCDA passes and the government sets a date for it to come into force.
Yes, if it passes. Bill C-36 repeals the privacy part of the Personal Information Protection and Electronic Documents Act and renames what is left the Electronic Documents Act.
No. In Lavawall® both laws are mapped to the same controls, so the work you do for PIPEDA counts toward the PPCDA and the readiness assessment shows only what is new. ThreeShield scopes the new items (transfers outside Canada, legitimate interest, disposal, automated decisions, and children's information) in the first call.
The same way PIPEDA does. Activity inside a province with a substantially similar law can be exempted, but the PPCDA still covers federally regulated businesses and personal information that crosses provincial or national borders.
ThreeShield meets you at your current privacy maturity. Every level includes Lavawall®.
For lean IT teams and cost-conscious organizations with internal capacity
Expert guidance alongside your team, ideal for MSPs and organizations with some internal IT capacity
The privacy program delivered and kept current by ThreeShield
Start from the PIPEDA program you already have. ThreeShield finds the gaps to the proposed law and Lavawall® keeps the evidence for both.
Book a Scoping CallDIY · Supported · Done-for-You