📋 GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROC…SaaS discovery for data governanceFree enriched web chat widget🚀 Enriched remote support without your laptop

Preparing for the PPCDA

Preparing for the PPCDA (Protecting Privacy and Consumer Data Act, Bill C-36)

Complete your privacy controls once: they show compliance with PIPEDA today and readiness for the PPCDA tomorrow. This page lists what Bill C-36 keeps from PIPEDA, what it adds, and how Lavawall® helps at each step.

Start your PPCDA readiness assessment See the steps

Bill C-36 · proposed, not in force · What is the PPCDA?

Do the work once

The Protecting Privacy and Consumer Data Act (PPCDA) is Part 1 of Bill C-36. It would replace the privacy part of PIPEDA, the Personal Information Protection and Electronic Documents Act. Most of it turns PIPEDA's ten principles into specific statutory duties, so a working PIPEDA program already covers most of what it asks.

In Lavawall®, PIPEDA and the PPCDA are separate frameworks mapped to one shared set of controls. Add both, and every control you implement and evidence counts toward both laws. PIPEDA shows where you stand under the law in force; the PPCDA readiness assessment asks only about what your PIPEDA work has not already answered. There is no second assessment, no second set of evidence, and no second policy library.

The same applies to provincial law. Alberta PIPA, BC PIPA, Quebec Law 25, and the health privacy acts map to the same controls, and one privacy impact assessment can cover all of them at once.

Bill C-36 was at second reading on 6 October 2026. Section numbers follow the first-reading text and may change in committee. Lavawall updates the framework as the bill moves.

The steps, and how Lavawall® helps with each

"Already in PIPEDA" means a working PIPEDA program covers it today. "New" means Bill C-36 adds it.
StepPIPEDA todayPPCDA (Bill C-36)How Lavawall® helps
1. Name who is accountable and run a written privacy programAlready in PIPEDA (Principle 4.1)Program scaled to volume and sensitivity, with training (ss. 7-9)Policy and procedure templates mapped to both laws, a privacy officer contact record, and policy acceptance tracking
2. Train your staffAlready in PIPEDA (Principle 4.1.4)Training is part of the program (s. 9(1)(c))Security awareness and privacy law training, including a course on Bill C-36, with completion certificates as evidence
3. Know what personal information you hold and where it goesNeeded to meet Principles 4.1.3 and 4.7Needed for ss. 11, 57, and 62(2)(d)Data flows and vendor inventory with processing countries, and SaaS discovery to find the cloud apps people actually use, and who uses them
4. Assess every transfer outside CanadaBe transparent and stay accountable (Principle 4.1.3)New: a privacy impact assessment and mitigations before the transfer (s. 57)The privacy impact assessment tool's Transfer outside Canada type, suggested automatically for every cross-border flow and offshore vendor
5. Record why you collect, before you collectIdentify purposes (Principle 4.2)New: purposes assessed as appropriate and recorded first (s. 12)A general privacy impact assessment and a record-of-purposes template
6. Assess before relying on legitimate interestNot available under PIPEDANew: a privacy impact assessment of adverse effects, with steps to reduce them (s. 18)The Legitimate interest assessment type, and a control that tracks it
7. Find and govern AI and automated decisionsOpenness and accountability applyNew: describe automated decision systems, explain decisions, and allow review by an employee (ss. 62(2)(c) and 63(4)-(6))Shadow AI detection in SaaS discovery, the AI and automated decisions assessment type, and a record of whether each AI vendor may train on your data
8. Protect children's informationMeaningful consent for minors (OPC guidance)New: anyone under 18 is a child, and their information is sensitive (ss. 2 and 4)Children's controls that define each law's age (COPPA under 13, the PPCDA under 18) and steer you to the stricter rule
9. Safeguard the informationAlready in PIPEDA (Principle 4.7)Safeguards proportionate to sensitivity (s. 56)Monitoring and patching across Windows, macOS, and Linux, disk encryption checks (BitLocker and FileVault), multi-factor authentication and access reviews, and automatic control checks that keep dated evidence
10. Detect, report, and record breachesAlready in PIPEDA (ss. 10.1-10.3)Report, notify, and record (ss. 58-61)Breach detection across Microsoft 365, Entra ID, and Google Workspace, endpoint security monitoring, and incident response templates
11. Delete on request, including at service providersRetention and disposal (Principle 4.5)New: disposal on request that reaches service providers (s. 54)A disposal request procedure and vendor records that show who holds what
12. Tell people how you handle their informationAlready in PIPEDA (Principle 4.8)Plain-language policy, including transfers and automated decisions (s. 62)Privacy policy templates, the foreign processing disclosure built from your data flows, and a public Trust Centre

Privacy impact assessments: one record for every law

A privacy impact assessment (PIA) records what personal information a project, system, vendor, or transfer handles, what could go wrong for the people it is about, and what you will do about it. The PPCDA makes PIAs a legal requirement in two places: before personal information is transferred outside Canada (s. 57), and before relying on legitimate interest (s. 18). Quebec Law 25 already requires them, the Alberta Health Information Act requires custodians to submit them, and BC public bodies must complete them under FIPPA.

Lavawall® runs one assessment against every law you select. You answer each question once, and a tag under the question shows which laws ask for it, such as PIPEDA Principle 4.4, PPCDA s. 57, Quebec Law 25 s. 17, or GDPR Article 35. Six types cover the common cases: general, transfer outside Canada, legitimate interest, AI and automated decisions, Alberta HIA, and BC FIPPA.

  • Starts from your frameworks. The laws you follow are ticked automatically. A short location and audience step suggests others, such as COPPA for children in the United States or the GDPR for people in the EU.
  • Finds what needs one. Data flows that carry personal information across a border, vendors that hold it outside Canada, and AI vendors are suggested until they have an assessment.
  • Records the risk. Each risk has a likelihood, an impact on people, a mitigation, an owner, and a due date. The conclusion records the decision and the remaining risk.
  • Keeps the approval honest. Someone other than the author approves it, and changing an approved assessment sends it back for review.
  • Counts as evidence. An approved assessment appears on the controls it evidences, such as PRIV-001 and PPCDA-001, in every framework that maps them.
  • Prints for the regulator. One report shows the answers, the laws that ask for them, the risks, and the decision.

How to run a privacy impact assessment in Lavawall

SaaS discovery and the AI rules

You cannot assess a transfer or an AI tool you do not know about. Staff sign up for cloud apps with a work email every week, and many of them now include AI features that read whatever is pasted in. Under the PPCDA, an AI tool that makes or supports decisions about people needs a description in your privacy policy, an explanation on request, and a way for a person to ask an employee to review the result.

Lavawall® SaaS discovery reviews email metadata against a curated catalogue of 1,277 SaaS apps, including AI tools, and shows which services are in use and exactly who uses them. Add each one as a vendor. From there, the vendor record notes where it processes data and whether its terms stop it training on your data, and the PIA tool suggests an AI assessment until one is done.

About SaaS discovery · What is shadow AI?

Your own data stays in Canada

The data you provide to Lavawall® is all stored in Canada. Notifications may pass through Irish and American service providers; the Canadian data residency page lists each exception. That matters here: the records you keep to show PPCDA readiness stay in Canada, and you can see exactly which notification services sit outside it.

Lavawall is built, hosted, and supported in Canada by ThreeShield Information Security Corporation, a Calgary audit firm. ThreeShield tracks Bill C-36 and updates the PPCDA framework as it changes in committee.

A plan you can start this quarter

  1. Add PIPEDA and the PPCDA in the Compliance Wizard, along with any provincial law that applies to you.
  2. Answer the readiness assessment. Your PIPEDA answers carry across; the PPCDA questions show only the gaps.
  3. Map your data flows and vendors, and run SaaS discovery to find what is missing from the list.
  4. Run a transfer assessment for every flow or vendor that sends personal information outside Canada, starting with the most sensitive.
  5. Assess your AI tools and any legitimate interest you rely on.
  6. Train your staff on what Bill C-36 changes, and keep the certificates.
  7. Review once a year, and whenever the bill changes in committee.

Start your PPCDA readiness assessment →

This page summarizes proposed legislation for planning. It is not legal advice; confirm the current text of Bill C-36 before relying on it.

Frequently asked

Do I have to redo my PIPEDA compliance work for the PPCDA?
No. Most of the PPCDA (Protecting Privacy and Consumer Data Act, Bill C-36) restates PIPEDA as specific duties. In Lavawall, PIPEDA and the PPCDA are mapped to the same controls, so a control you implement and evidence once counts toward both. You complete your controls once to comply with PIPEDA today and be ready for the PPCDA tomorrow, and only the new duties are extra work.
What is new in the PPCDA compared with PIPEDA?
A privacy impact assessment before personal information is transferred outside Canada (s. 57), a privacy impact assessment before relying on legitimate interest (s. 18), purposes recorded before collection (s. 12), deletion or anonymization on request that reaches service providers (s. 54), explanation and human review of automated decisions (ss. 62-63), anyone under 18 treated as a child with sensitive information (ss. 2 and 4), and a de-identification standard (ss. 74-75).
Where should I start preparing for the PPCDA?
With transfers outside Canada. Map where personal information goes, including cloud services, support teams, backups, and AI tools, and run a privacy impact assessment for each transfer. That is the largest new duty, and the inventory also answers Quebec Law 25 and Alberta PIPA questions today.
Is the PPCDA in force?
No. Bill C-36 was introduced on 15 June 2026 and was at second reading in October 2026. It comes into force on a date set by order in council, after the Digital Safety and Data Protection Commission exists. PIPEDA applies until then.
Where does Lavawall store the data I put into it?
The data you provide is all stored in Canada. Notifications may pass through Irish and American service providers; the Canadian data residency page lists each exception.