๐Ÿ“‹ GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROCโ€ฆSaaS discovery for data governanceFree enriched web chat widget๐Ÿš€ Enriched remote support without your laptop

What is the PPCDA

What is the PPCDA (Protecting Privacy and Consumer Data Act, Bill C-36)?

The PPCDA (Protecting Privacy and Consumer Data Act) is Canada's proposed federal private-sector privacy law. It is Part 1 of Bill C-36, introduced in the House of Commons on 15 June 2026, and it would replace the privacy part of PIPEDA (the Personal Information Protection and Electronic Documents Act). It is not in force. It is the law to plan for.

Plan for the PPCDA in Lavawall® See what PIPEDA already covers

Bill C-36 · proposed, not in force · replaces PIPEDA Part 1 when it starts

Definition

The PPCDA (Protecting Privacy and Consumer Data Act) is the proposed law that would govern how private-sector organizations in Canada collect, use, and disclose personal information in the course of commercial activity. It is Part 1 of Bill C-36, An Act to enact the Protecting Privacy and Consumer Data Act, to amend the Personal Information Protection and Electronic Documents Act and to make amendments to other Acts.

It turns PIPEDA's ten Fair Information Principles into specific statutory duties, adds new rights for individuals, and gives a new regulator, the Privacy and Consumer Data Commissioner within the Digital Safety and Data Protection Commission of Canada, the power to issue administrative monetary penalties of up to $10 million or 3% of gross global revenue.

It is the third attempt to replace PIPEDA. Bill C-11, the Digital Charter Implementation Act, 2020, died in 2021. Bill C-27, which contained the Consumer Privacy Protection Act (CPPA), died when Parliament was prorogued on 6 January 2025. The PPCDA keeps most of the CPPA's structure.

Where Bill C-36 stands

StepStatus
IntroducedFirst reading in the House of Commons, 15 June 2026
Current stageSecond reading in the House of Commons (as of 6 October 2026). Committee, report stage, third reading, and the Senate are still ahead.
Coming into forceOn a date set by order in council, and not before the new Digital Safety and Data Protection Commission exists
Depends onBill C-34, the Safe Social Media Act, which creates the Commission that the PPCDA's regulator sits inside
Until thenPIPEDA applies, alongside Alberta PIPA, BC PIPA, and Quebec Law 25 where they apply

Section numbers on this page follow the first-reading text of Bill C-36 and may change in committee.

Core components

Privacy management program (s. 9)

A written program covering how personal information is protected, how requests and complaints are handled, staff training, and plain-language materials, scaled to the volume and sensitivity of what you hold. The regulator can ask to see it.

Appropriate, recorded purposes (s. 12)

Every purpose must be one a reasonable person would consider appropriate, weighed on sensitivity, business need, effectiveness, less intrusive options, and proportionality, and it must be recorded before collection.

Consent in plain language (ss. 15-17)

Consent must explain the purposes, consequences, types of information, and third parties in language the audience understands. It is express unless implied consent is clearly appropriate, and it can be withdrawn.

Legitimate interest, with an assessment (s. 18)

Collection, use, or disclosure without consent is allowed for a legitimate interest that outweighs the effect on the person, but only after a privacy impact assessment and steps to reduce the risks. PIPEDA has no equivalent.

Transfers outside Canada (s. 57)

Before personal information is disclosed or transferred outside Canada, the organization must carry out a privacy impact assessment and put mitigations in place, such as contract terms or an approved certification. New in C-36.

Children under 18 (ss. 2 and 4)

A child is anyone under 18, and a child's personal information is sensitive. A parent or guardian exercises the child's rights unless the child wants to act personally and is able to.

Disposal on request (s. 54)

People can ask an organization to delete or anonymize their information when it was handled unlawfully, consent was withdrawn, or it is no longer needed. Refusals need written reasons, and service providers must delete it too.

Automated decisions (ss. 62-63)

Organizations must describe any automated decision system that could have a legal or similarly significant effect on people, explain a decision on request, and let the person make written representations to an employee who can review it.

Breaches (ss. 58-61)

Breaches that create a real risk of significant harm are reported to the Commission and notified to the people affected, every breach is recorded, and service providers must tell you about breaches as soon as feasible.

De-identification (ss. 74-75)

De-identified information is still personal information, and the measures used must be proportionate to its purpose and sensitivity. Re-identifying people is prohibited except in narrow cases, and knowingly doing it is an offence.

Penalties (ss. 113-114, 145)

Administrative monetary penalties up to the higher of $10 million and 3% of gross global revenue, and fines for offences up to the higher of $25 million and 5%. Due diligence, or following an approved certification program, is a defence to a penalty.

Private right of action (s. 132)

Once the Commissioner finds a contravention and the finding is final, the people affected can sue for damages.

What changed from the CPPA in Bill C-27

If you already prepared for the Consumer Privacy Protection Act, most of that work still applies. The differences that matter for planning are these:

  • Transfers outside Canada need a privacy impact assessment. The CPPA only required a privacy policy to mention international transfers. The PPCDA requires an assessment and mitigations before the information leaves (s. 57).
  • Legitimate interest covers disclosure, not just collection and use, and the assessment is now a privacy impact assessment in a form the regulations will set (s. 18).
  • Automated decisions get human review. The threshold changes from "significant impact" to "legal or similarly significant effect", and people can make written representations to an employee who can review the decision (s. 63(6)).
  • Children are defined. The CPPA said minors' information was sensitive without defining a minor. The PPCDA defines a child as anyone under 18 and sets out who exercises a child's rights (ss. 2 and 4).
  • "Sensitive" is defined, with a list that includes health, genetic, biometric, ethnic origin, political, religious, union, and sexual orientation information (s. 2).
  • A new regulator, and no Tribunal. The Privacy and Consumer Data Commissioner sits inside the Digital Safety and Data Protection Commission, which reviews penalties itself. The CPPA's separate Personal Information and Data Protection Tribunal is gone, and appeals go to the Federal Court.
  • No artificial intelligence act. Bill C-27 also carried the Artificial Intelligence and Data Act. Bill C-36 does not.

One set of controls for PIPEDA today and the PPCDA tomorrow

The PPCDA is mostly PIPEDA written as statute. That means the controls you run for PIPEDA are the same controls the PPCDA asks for, and you should not have to prove them twice.

In Lavawall®, PIPEDA and the PPCDA are separate frameworks mapped to one shared set of controls. Every control mapped to PIPEDA is also mapped to the PPCDA. Adopt both, and a control you implement and evidence once counts toward both: PIPEDA shows where you stand under the law in force today, and the PPCDA readiness assessment shows only what is left to add.

Already covered by a working PIPEDA program

Each row is one control in Lavawall, credited to both laws.
What you do oncePIPEDA (in force)PPCDA (Bill C-36, proposed)
Name a person accountable for privacyPrinciple 4.1ss. 7-8
Run a written privacy program and train staff on itPrinciple 4.1.4s. 9
Bind service providers to equivalent protectionPrinciple 4.1.3ss. 11 and 61
Collect only what the purpose needsPrinciple 4.4s. 13
Get meaningful consent, express for sensitive informationPrinciple 4.3ss. 15-17
Set retention periods and dispose of information securelyPrinciple 4.5ss. 52 and 54
Keep information accuratePrinciple 4.6s. 55
Protect it with safeguards proportionate to its sensitivity (encryption, multi-factor authentication, access control)Principle 4.7s. 56
Assess breaches for real risk of significant harm, report, and notifys. 10.1ss. 58-59
Keep a record of every breachs. 10.3s. 60
Publish a plain-language privacy policyPrinciple 4.8s. 62
Answer access requests within 30 daysPrinciple 4.9 and s. 8ss. 63-67
Handle complaintsPrinciple 4.10s. 73

The new work the PPCDA adds

What to addPPCDA sectionWhat Lavawall® gives you
A privacy impact assessment before personal information leaves Canadas. 57A cross-border transfer assessment form and a control to track every transfer
A recorded assessment before relying on legitimate interests. 18(3)-(5)A legitimate interest assessment record
Purposes recorded before collections. 12A record of purposes with the five-factor appropriateness test
Deletion or anonymization on requests. 54A disposal request procedure that reaches your service providers
Explanation and human review of automated decisionsss. 62(2)(c) and 63(4)-(6)An automated decision statement and a review procedure
Anyone under 18 treated as a child, with sensitive informationss. 2 and 4A control and question set for children's information
A de-identification standardss. 74-75A de-identification and anonymization standard

Why this matters when you compare tools

Most compliance platforms reuse a control across the frameworks they ship. The question for a Canadian organization is whether PIPEDA and the PPCDA are among them. If you have to build either one as a custom framework, mapping it to your existing controls is your work, and every amendment in committee means doing it again. If the platform prices each framework separately, planning for a bill that is not law yet costs extra.

Lavawall® ships PIPEDA, the CPPA, and the PPCDA pre-built and mapped to the same controls, keeps them current as the bill moves, and includes every framework in the Complete tier. Adding the PPCDA beside PIPEDA adds the new requirements and nothing else.

Why it matters

For most organizations the expensive part of a new privacy law is not the principles they already follow. It is the handful of new duties that touch systems and contracts: an assessment before data leaves Canada, deletion that reaches every service provider, and a person who can review what an automated system decided.

Transfers outside Canada are the one to start on. Cloud services, help desks, backups, and analytics tools often store or reach personal information from outside the country. Under the PPCDA each of those needs an assessment before it starts. An inventory of where your personal information goes, built now, makes that a paperwork exercise later instead of a migration.

For Canadian MSPs, the PPCDA flows through to clients the way PIPEDA does. The MSP is usually a service provider, so its contracts, breach notice, deletion, and the location of its tools become part of each client's compliance picture.

How Lavawall® helps you prepare for the PPCDA

Lavawall® carries the PPCDA as a draft framework for planning, clearly marked as not in force. Add it beside PIPEDA (or Alberta PIPA, BC PIPA, or Quebec Law 25) and the readiness assessment asks only the questions your PIPEDA work has not already answered.

  • Assess against the PPCDA's requirements by section, with the same controls as PIPEDA.
  • Close the gaps with ready templates: the cross-border transfer assessment, legitimate interest assessment, record of purposes, disposal procedure, automated decision review procedure, de-identification standard, and a readiness report for leadership.
  • Train staff with a short course on what Bill C-36 would change.
  • Keep the evidence your safeguards already produce: patching, encryption, multi-factor authentication, access review, and breach detection across your endpoints, Microsoft 365, and Google Workspace.

For the full requirement-by-requirement plan, including privacy impact assessments and SaaS discovery for the AI rules, read Preparing for the PPCDA.

ThreeShield Information Security Corporation, the Calgary audit firm that built Lavawall®, tracks the bill and updates the framework as it changes in committee.

Start your PPCDA readiness assessment →

This page summarizes proposed legislation for planning. It is not legal advice; confirm the current text of Bill C-36 before relying on it.

Frequently asked

Is the PPCDA law yet?
No. The Protecting Privacy and Consumer Data Act is Part 1 of Bill C-36, which was introduced in the House of Commons on 15 June 2026 and was at second reading in October 2026. PIPEDA remains the federal private-sector privacy law until the PPCDA passes and the government sets a date for it to come into force.
When would the PPCDA take effect?
On a date set by order in council, and not before the new Digital Safety and Data Protection Commission exists. That Commission is created through Bill C-34, the Safe Social Media Act, so both bills have to pass first. Previous privacy bills have taken years, and two of them (C-11 and C-27) died before passing.
Does the PPCDA replace PIPEDA?
Yes, if it passes. Bill C-36 repeals Part 1 of the Personal Information Protection and Electronic Documents Act, the privacy part, and renames what is left the Electronic Documents Act. The PPCDA then becomes the federal private-sector privacy law.
Is the PPCDA the same as the CPPA?
No, but it is close. The Consumer Privacy Protection Act (CPPA) was Part 1 of Bill C-27 and died in January 2025. The PPCDA keeps most of its structure and adds privacy impact assessments before personal information leaves Canada and before relying on legitimate interest, human review of automated decisions, and a definition of a child as anyone under 18.
Does the PPCDA apply in Alberta, British Columbia, and Quebec?
The same way PIPEDA does. The government can exempt activity inside a province that has a substantially similar law, but the PPCDA still applies to federally regulated businesses and to personal information that crosses provincial or national borders.
Do I need to do anything before it passes?
Nothing is legally required yet. Most of the PPCDA restates what a working PIPEDA program already does, so the practical step is to find the gaps now (transfers outside Canada, legitimate interest, disposal requests, automated decisions, and children's information) and plan them, instead of starting from zero after the Act comes into force.