From the journal

Canada Introduces Bill C-36 to Replace PIPEDA with New Federal Privacy Law

On 15 June 2026, Canada's Minister of Artificial Intelligence and Digital Innovation, Evan Solomon, introduced Bill C-36 in the House of Commons. The bill enacts the Protecting Privacy and Consumer Data Act (PPCDA), replacing Part 1 of the Personal Information Protection and Electronic Documents Act (PIPEDA). The bill introduces order-making powers for a new Digital Safety and Data Protection Commission, administrative monetary penalties, and an expanded private right of action for affected individuals.

2 min read

Canada's Minister of Artificial Intelligence and Digital Innovation, Evan Solomon, introduced Bill C-36 in the House of Commons on 15 June 2026. The bill enacts the Protecting Privacy and Consumer Data Act (PPCDA), which replaces Part 1 of the Personal Information Protection and Electronic Documents Act (PIPEDA). The bill is at the proposed rule stage, having received first reading on 15 June 2026 and now proceeding to second reading and committee study. This is Canada's third attempt to replace PIPEDA; two previous bills (C-11 and C-27) died on the Order Paper.

The PPCDA retains a consent-based structure while granting the new Digital Safety and Data Protection Commission of Canada order-making powers and the authority to impose administrative monetary penalties. The bill creates an expanded private right of action for affected individuals, departing from PIPEDA, under which individuals could only lodge complaints with the Office of the Privacy Commissioner. Provisions governing automated decision-making and profiling align with patterns established in Quebec's Law 25 and reform legislation in other jurisdictions.

AI system operators deploying personal data processing in Canada, including recommendation engines, automated underwriting systems, generative AI products handling user data, and consumer profiling tools, must assess their compliance posture against the PPCDA if the bill is enacted. The Digital Safety and Data Protection Commission replaces the Office of the Privacy Commissioner as the enforcement body for private-sector personal data processing, with broader enforcement tools and penalty authority. Organisations currently operating under PIPEDA must plan transition programmes, though enactment timing depends on parliamentary proceedings.

Bill C-36's automated decision-making provisions and the interaction between the PPCDA and Quebec's Law 25 regime remain areas for committee scrutiny. The bill must clear second reading, committee study, and Senate proceedings before royal assent, introducing timing uncertainty for operators planning compliance investment. The scope of the private right of action, broader than PIPEDA's complaint-only model, may increase litigation exposure for large-scale data processors.

We advise AI system operators, data controllers, and financial institutions on Canadian privacy law compliance and the implications of Bill C-36 for AI-driven data processing. Work we undertake includes PIPEDA-to-PPCDA transition assessments, automated decision-making compliance reviews, privacy impact assessments for AI deployments, and coordination between Canadian and EU/UK privacy and AI regulatory obligations.

Source: Government of Canada, Press Release: Tabling of Bill C-36, 15 June 2026

AI Regulatory

More from the journal

See all
Illia Prokopiev

MLR Registration and the FCA Cryptoasset Gateway to 25 October 2027

This matter concerns the transition of a United Kingdom cryptoasset business from FCA registration under the Money Laundering Regulations 2017 to Part 4A permission under the Financial Services and Markets Act 2000. The question is whether MLR registration gives conversion, grandfathering, priority, or a right to continue after 25 October 2027, and what an affected firm should do before the gateway closes. This analysis assumes an existing UK-facing cryptoasset business, no relevant Part 4A permission, and an intention to continue after commencement.

Illia Prokopiev

Matched-Category Analysis of the Hong Kong Stablecoin Issuer Route and the Singapore Digital Payment Token Service Route

This matter concerns whether current licensing data supports a commercial comparison between Hong Kong’s stablecoin issuer route and Singapore’s digital payment token service route. The question is whether the proposition remains legally accurate as of 12 August 2026. “Commercially useful” is assumed to mean useful for selecting a market-entry and operating model, not proof that either regulator is more permissive.

Illia Prokopiev

ESMA's 2026 Custody Resilience CSA and the Rules That Actually Bind

ESMA’s 2026 Common Supervisory Action is a coordinated national review of digital operational resilience in crypto-asset custody. It will test whether selected crypto-asset service providers can demonstrate effective controls across six announced workstreams. The legal questions are which requirements are binding, how national competent authorities may assess control effectiveness, and what consequences may follow from a deficiency. This analysis assumes that the firm is permitted under MiCA Article 59 to provide custody and administration within Article 3(1)(17).