Bill C-36 Explained: What Canada's New Data Privacy Law Means for Your Business

‍ ‍

What Is Bill C-36 (and Is It Law Yet)? 

‍ Not yet! Bill C-36, otherwise called the Protecting Privacy and Consumer Data Act, passed only the first reading in the House of Commons on June 15, 2026, introduced by AI Minister Evan Solomon. It still needs committee review, a full House vote, and Senate approval for it to proceed into law. 

C-36 is the third attempt at modernizing the Personal Information Protection and Electronic Documents Act (PIPEDA), the 25-year-old federal privacy law that already governs most Canadian businesses. Legal commentators tracking this attempt closely expect full effect at 2030 or later, once the new commission, the Digital Safety and Data Protection Commission of Canada, writes its own rules and builds up enforcement capacity. 

What Would Actually Change for Businesses? 

If passed as written, C-36 would require businesses to explain automated decisions that affect people, also tighten what counts as valid consent, create a right to request data deletion, and force risk assessments before personal data crosses the border. None of that applies today yet. 

Automated decisions and AI transparency

If a system makes a decision with legal effects or even other significant effects on someone, e.g. denying a loan application or screening a job candidate, the business behind it would have to explain what data it used and the main factors behind the outcome. 

Consent, deletion, and children's data

Consent would have to be meaningful and explained in plain language, not buried on page fourteen of a privacy policy. People would gain the right to request deletion of their data, including deepfakes made from their likeness. Children's data gets a higher standard of care than an adult's. 

Surveillance pricing and cross-border data

The bill also targets algorithmic, real-time pricing, though it does not define or ban this outright. Minister Solomon has said he will direct the regulator to issue guidance later, likely exempting loyalty and rewards points. Businesses moving Canadians' data outside the country would need to complete a risk assessment first. That kind of review sits with securities and regulatory compliance as much as it does with IT. The bill would also create a new right that enables the porting of data, thus letting people move their information from one provider to another in a usable format. 

Penalties split into two tiers if C-36 passes as written. General violations top out at the greater of $10 million or 3% of global annual revenue. The most serious and criminal offences reach the greater of $25 million or 5%. That second figure gets the headlines. Most businesses, most of the time, would fall under the first. 

What Should BC Businesses Do About It Now?

Most BC-only businesses already answer to BC's Personal Information Protection Act, not federal law, and that stays true after C-36 passes. C-36 will matter most to businesses moving data across provincial or international lines, or ones already federally regulated. 

BC PIPA has been in force since 2004 and is recognized as substantially similar to the federal framework, which is why BC private-sector data handled within the province stays under provincial law. PIPEDA, and later C-36, picks up where a business crosses a provincial or national border. 

Waiting three years is not the smart move. Know where your customer data goes once it leaves BC, and tighten your consent language before a regulator makes you do it. If you run any automated scoring tool on customers or applicants, know what it does and why, a business cannot explain what it never checked. Have an answer ready for the day someone asks you to delete their file. 

This is the kind of question Vancouver businesses are already bringing to a technology lawyer: what does our data footprint look like right now, and what would need to change before any of this is mandatory. 

How Jiwaji Law Can Help 

From PIPEDA reviews and privacy policy redrafts to C-36 readiness planning and automated decision accountability, our technology and data law practice handles the full footprint. We also handle the securities and regulatory side when your data-protection work connects to Director and Officer compliance or securities and regulatory risk. 

‍ ‍

Ready to review your data handling and consent language before the next privacy law lands? Get in touch.

‍ ‍

Next
Next

Celebrating a Significant Result in 1060700 B.C. Ltd. v. iFortune Homes Inc.