Canada is rewriting its privacy law. What a small business should do before it passes.
Bill C-36 would replace PIPEDA with the Protecting Privacy and Consumer Data Act, hand enforcement to a brand new commission, and raise the penalty ceiling from $100,000 to tens of millions. It is not law yet. Here is what is actually in it, what already applies to you today, and the short list of things worth doing now.
On June 15, 2026, the federal government tabled Bill C-36. If it passes, it will be the biggest change to Canadian private-sector privacy law in more than twenty five years, and it will apply to almost every business in the country that collects a customer’s name and email address.
That includes yours. There is no revenue floor and no employee-count exemption. A twelve-person clinic in Etobicoke and a bank both fall under the same statute, which is a fact that surprises most owners we talk to.
Before the panic emails start arriving from compliance vendors, here is the honest version: the bill is not law, it may not pass in its current form, and nothing about your obligations changed on June 15. What did change is the direction of travel, and the direction is clear enough that a handful of things are worth doing now regardless of what Parliament does next.
What the bill actually does
Bill C-36 enacts a new statute called the Protecting Privacy and Consumer Data Act, or PPCDA. To make room for it, the bill repeals Part 1 of PIPEDA, the privacy half of the law that has governed this since 2000, and renames what is left of PIPEDA to simply the Electronic Documents Act. PIPEDA as you know it goes away.
Three things in the bill matter more than the rest.
A new regulator. Private-sector privacy enforcement moves out of the Office of the Privacy Commissioner and into a newly created body, the Digital Safety and Data Protection Commission of Canada, led by a dedicated Privacy and Consumer Data Commissioner. That commission can issue binding orders, conduct audits, and levy penalties directly. Under the previous reform attempt, penalties had to route through a separate tribunal, a structure that critics said would slow enforcement to a crawl. That step is gone.
Penalties with real numbers. Today, the worst financial consequence PIPEDA can impose on a business is a $100,000 fine, and only for a narrow set of offences like failing to report a breach. Under the PPCDA, administrative monetary penalties reach the greater of $10 million or 3 percent of global gross revenue. Criminal fines on indictment, for the serious stuff, reach the greater of $25 million or 5 percent. You will see the $25 million figure quoted a lot. It is the criminal ceiling, not the ordinary enforcement number, and the distinction is worth holding onto when somebody uses it to sell you something.
A private right of action. Individuals will be able to sue for damages once a regulatory process has established that a contravention occurred, with a two year window from when they learn of the decision. This mirrors the model Quebec has been running since 2023.
Privacy Commissioner Philippe Dufresne welcomed the bill the day it was tabled, calling it a pivotal step and singling out the recognition of privacy as a fundamental right, the explicit protections for children, and the requirement for privacy impact assessments. He also noted that his own office would be handing private-sector oversight to the new commission, and said the OPC would come back to Parliament with recommendations.
The obligations, in plain language
Strip out the legal machinery and the PPCDA asks organizations to do roughly seven things.
-
Run a documented privacy management program. Written policies covering how you handle personal information, kept current. The bill explicitly says the program must account for the volume of personal information you control and how sensitive it is, which is the provision that keeps this from being a Fortune 500 exercise imposed on a florist.
-
Get meaningful consent, explained in plain language. Before collecting, you have to tell people the purposes, what you are collecting, how you will handle it, the reasonably foreseeable consequences, and who else receives it. Buried, pre-ticked, or lawyer-flavoured consent will not clear this bar.
-
Or rely on legitimate interest, carefully. There is a new exception permitting collection and use without consent where you have a legitimate interest that outweighs any adverse effect on the individual, the activity is one a reasonable person would expect, and the data is not being used to influence behaviour. Using it requires a privacy impact assessment first. This is genuinely useful for ordinary operational work, and it is not a loophole you can walk through without documentation.
-
Assess the risk before data leaves Canada. If personal information is going to a service provider outside Canada, you have to assess the privacy risk and mitigate it. For a typical small business, personal information leaves Canada constantly: your CRM, your email marketing tool, your booking system, your analytics, your helpdesk. Most of those are American. This is the obligation we expect to catch the most people off guard, and it is a direct consequence of Ottawa’s broader push on data sovereignty.
-
Disclose when a machine is making the decision. If you use an automated system to make a prediction or decision that has a legal or similarly significant effect on someone, you have to say so in general terms. Note the threshold. It is not “we use AI somewhere on the site.” It is decisions that actually land on a person, like an automated approval or denial.
-
Honour deletion and portability requests. Individuals get a right to have their information disposed of or anonymized, with exceptions, and a data mobility framework lets them ask you to send their information to another organization.
-
Report breaches. To the regulator and to affected individuals. This one is not new, and we will come back to it, because it already applies to you.
There is also a genuinely helpful piece for smaller organizations: the PPCDA provides for codes of practice and certification programs. An industry body can get a code approved by the regulator if it offers protection at least equivalent to the statute, and organizations can certify against it. In practice that should mean a dentist or a trades company eventually gets to follow a sector checklist rather than commission a legal opinion.
What is already true today
Here is the part the “new privacy law” headlines bury. PIPEDA is in force right now, it has been for a quarter century, and it already requires more than most small businesses are doing.
Since November 1, 2018, if you suffer a breach of security safeguards involving personal information and it creates a real risk of significant harm to anyone, you must report it to the Privacy Commissioner and notify the affected individuals. Not eventually. As soon as feasible. And separately, you must keep a record of every breach, including the small ones that did not meet the reporting threshold, for 24 months, in enough detail that the OPC can verify you assessed them properly.
Failing to report a qualifying breach is one of the few things PIPEDA can actually fine you for today, up to $100,000.
In our experience, the breach log is the single most commonly missing item at a small business. Not because anyone decided to skip it, but because nobody ever mentioned it existed. A laptop goes missing, a misdirected email sends one client’s invoice to another client, a former employee’s account was never disabled. Each of those is a breach of security safeguards. Each one belongs in a log with a date, what happened, what information was involved, and your reasoning about whether it hit the harm threshold. That log is a spreadsheet. It takes an afternoon to start and five minutes an incident to maintain, and it is the first thing a regulator asks for.
Two other things already apply and have nothing to do with Bill C-36:
Quebec’s Law 25. It binds any organization that handles the personal information of a Quebec resident, wherever that organization sits. If you are a Toronto retailer who ships to Montreal, you are in scope. It has been fully in force since 2023, its penalties are already in the tens of millions at the ceiling, and it already carries a private right of action for punitive damages where an infringement is intentional or the result of gross negligence. The federal bill is catching up to Quebec, not leading it.
PHIPA, if you are in Ontario healthcare. Personal health information held by a health information custodian is governed provincially by PHIPA, and Bill C-36 does not change that. If you run a clinic, PHIPA remains your primary obligation for patient records, and the federal statute governs the rest of your commercial activity, like your marketing list and your staff-facing tools. We wrote about where that line sits in PHIPA-compliant AI for Ontario clinics, and none of it changes because of this bill.
Will it pass?
Nobody knows, and anyone who tells you otherwise is guessing.
This is Ottawa’s third attempt. Bill C-11 in 2020 and Bill C-27 in 2022 both died before becoming law. C-36 got first reading on June 15, 2026 and sits at second reading in the House of Commons, which means it has not been through committee, has not been amended, has not been voted on, and has not seen the Senate. Committee study is where the last two attempts absorbed most of their damage.
Even if it passes, it comes into force by Order in Council, meaning the government picks the date. Expect a transition period, and expect regulations to fill in a lot of the operational detail that the statute leaves open.
So the realistic planning horizon is not “comply by September.” It is “this is probably the shape of the law within a couple of years, and roughly none of the work is wasted if it changes.”
The short list
If you run a small business in Ontario and you want to spend the least effort for the most protection, here is where we would put it. All five of these are useful today under PIPEDA, and all five are prerequisites for the PPCDA if it lands.
-
Write down what personal information you hold and where it lives. Not a formal data map. A one page list: what you collect, which tool it sits in, which country that tool is in, and who has access. Most owners have never done this and are genuinely surprised by the answer. Everything else on this list depends on it.
-
Start the breach log. A spreadsheet with five columns, retained 24 months. This is already required. See above.
-
Fix the privacy policy so it matches reality. The most common problem we find is not a missing policy, it is a policy that was copied from a template in 2019 and describes tools the business no longer uses while omitting three it does. A policy that misdescribes your actual practices is worse than a short accurate one.
-
Look hard at where your customer data physically sits. Make the list from step 1, then note which vendors process data outside Canada and whether their contracts say anything about it. You do not need to repatriate everything, and for most businesses that would be an overreaction. You do need to know, because the cross-border assessment obligation is coming and because it is a reasonable question to be able to answer today.
-
Delete what you do not need. The cheapest privacy control ever invented. Old form submissions, exported spreadsheets sitting in someone’s Downloads folder, a mailing list of people who have not opened anything since 2021. Data you do not hold cannot be breached, cannot be requested, and cannot be the subject of a deletion demand.
Notice what is not on this list: buying a compliance platform, commissioning an audit, or paying for a certification that does not exist yet. Those may make sense for you at some point. None of them make sense in August 2026 in response to a bill at second reading.
Why we think this is worth your attention anyway
The instinct to ignore a bill that has not passed is a good instinct, and we generally share it. The reason we are writing about this one is that the underlying trend does not depend on the bill.
Every jurisdiction that matters to a Canadian business has moved the same direction in the last five years. Quebec did it in 2023. Europe did it in 2018 and has been enforcing steadily since. The rest of Canada is late, and the reason the federal government is on its third attempt is that the political will keeps surviving even when the legislation does not.
Meanwhile the practical risk has moved independently of the law. The reason a small business gets burned by a data problem in 2026 is almost never a regulator. It is a supply chain compromise in software they did not know they were running, or a vendor with administrator access to their systems getting breached, both of which we have written about this month in the npm worm and the N-central compromise. The legal exposure and the operational exposure are converging on the same advice: know what you hold, hold less of it, and know who can reach it.
That advice was correct before Bill C-36 and it will be correct if the bill dies in committee. The only thing the bill changes is the price of ignoring it.
If you want a second opinion on where your customer data actually lives, or help writing a privacy policy that describes what your business genuinely does, send us a note. We are a Toronto studio, we build the systems that hold this data, and we would rather you got this right early than expensively.