
Bill C-36: Is Your Business Ready?
The organizations that treat privacy as a technology architecture issue will be in a much stronger position than those that treat it as paperwork. Because ultimately, good privacy management is not just about compliance. It is about knowing your data well enough to protect it.
What Canada’s Proposed Consumer Data Act Could Mean for Businesses and Employees
Privacy legislation has a habit of sounding like something the legal department will worry about later. Until someone asks IT where the customer data is stored. Then things get interesting.
Canada’s proposed Bill C-36, the Protecting Privacy and Consumer Data Act (PPCDA), represents a significant proposed modernization of Canada’s federal private-sector privacy framework. Introduced on June 15, 2026, the bill is designed to replace Part 1 of the Personal Information Protection and Electronic Documents Act, better known as PIPEDA, with a new privacy regime designed for today’s data-driven economy.
As of September 2026, Bill C-36 is proposed legislation and has not yet come into force. Its provisions would come into force on dates established by order in council.
For business and technology leaders, however, waiting until legislation becomes law before examining the implications could be an expensive strategy.
The proposed changes reach into data governance, cybersecurity, artificial intelligence, vendor management, employee information, software architecture and the way organizations think about personal information.
Why Bill C-36 Should Matter to Business Leaders
The proposed legislation starts from a relatively straightforward principle: organizations should be able to use personal information for legitimate business purposes, but individuals should have meaningful privacy protections.
The bill would establish rules governing the collection, use and disclosure of personal information in commercial activities, while explicitly recognizing privacy as a fundamental right. The Privacy Commissioner of Canada welcomed the proposed recognition of privacy as a fundamental right, along with stronger enforcement powers and privacy impact assessment requirements.
That creates a shift in mindset.

Privacy is no longer simply a compliance checkbox.
It becomes part of business operations.
For business leaders, that means asking a very practical question:
“Do we actually know what personal information our organization collects, why we collect it, where it goes, who can access it and how long we keep it?”
If the answer involves a long pause and several people looking at the IT department, it may be time for a data audit.
The Proposed Privacy Management Program
One of the most significant changes for organizations is the proposed requirement to establish and maintain a privacy management program.
Bill C-36 would require organizations to maintain policies, practices and procedures covering areas such as protecting personal information, handling information requests and complaints, training employees and explaining privacy policies and procedures. The organization would also need to consider the volume and sensitivity of the personal information under its control.
This is where privacy becomes an operational issue.
A privacy policy sitting in an employee handbook is one thing.
A functioning privacy management program is something else.
Technology teams will very likely be the ones responsible for supporting the systems that make these programs work.
Support could look like:
- Data inventories
- Access controls
- Audit logs
- Retention rules
- Data deletion
- Encryption
- Identity management
- Backup management
- Vendor controls
- Data classification
- Privacy impact assessments
- Documentation
In other words, the legislation could turn “Where is that data?” from an awkward question into a formal business requirement.
The Third-Party Software Problem
Modern organizations rarely manage all of their corporate data themselves.
Customer relationship management platforms, payroll systems, cloud services, marketing platforms, HR systems, analytics tools, AI platforms and outsourced software development can all involve personal information.
Bill C-36 proposes that organizations remain accountable for personal information under their control even when a service provider handles that information.
The bill would require organizations transferring personal information to service providers to ensure, through contracts or other means, that the provider offers an equivalent level of protection.
That has implications for vendor selection.
The cheapest software vendor may turn into the most expensive option once privacy risk is considered.
Business leaders should be asking:
“What happens to our data when it leaves our systems?”
And:
“What happens when we want it back?”
Those two questions should be part of procurement and contract creation, not something discovered after signing on the dotted line.
AI Makes This Even More Complicated
This is where Bill C-36 becomes particularly relevant to today’s technology environment.
The proposed legislation specifically addresses automated decision systems, which it defines broadly to include technology using rules-based systems, regression analysis, predictive analytics, machine learning, deep learning, neural networks and other techniques.
Organizations using an automated decision system to make a prediction, recommendation or decision about an individual that could have a legal or similarly significant effect would have transparency obligations.
On request, an individual could be entitled to an explanation identifying the type and source of personal information used and the reasons or principal factors behind the prediction or decision. The individual would also have an opportunity to make representations to an employee capable of reviewing the decision.

This is a very different technical requirement from simply saying, “Our AI made the decision.”
It creates a potential need for:
- Data lineage
- Decision logging
- Model documentation
- Human review processes
- Explainability
- Version control
- Auditability
For organizations experimenting with AI in hiring, lending, insurance, customer service, fraud detection, employee management or other decision-making environments, this deserves serious proactive, attention.
The AI model may be the clever part; the documentation around it may become the important part.
What About Employees?
This is where organizations need to be careful about oversimplifying Bill C-36.
The proposed legislation applies to employee and applicant personal information where the organization collects, uses or discloses that information in connection with operating a federal work, undertaking or business.
That means the employee provisions are not simply a blanket new federal privacy regime covering every Canadian employer. For organizations that fall within the proposed federal scope, however, employee data becomes an important consideration.
Think about the amount of information an organization may hold about its people:
- Payroll information
- Benefits information
- Performance records
- Attendance information
- Recruiting information
- Employment history
- Training records
- Device information
- Access logs
- Location information
- Workplace communications
- Security information
- Potentially sensitive HR information
Technology teams often touch many of these systems without being the owners of the information. That creates a shared responsibility between HR, legal, security, IT and business leadership.
The question is no longer simply whether the organization has the information; it’s whether the organization can explain why it has it, how it uses it and who has access to it.
The Role of Employees
Bill C-36 is not only about what organizations can and cannot do. It also introduces protections for employees who raise concerns about potential violations.
The proposed legislation would prohibit an employer from dismissing, suspending, demoting, disciplining, harassing or otherwise disadvantaging an employee because they acted in good faith to report a suspected contravention, refused to participate in conduct that would contravene the legislation or took steps required to prevent a contravention. The bill explicitly includes independent contractors within its definition of employee for this provision.
For technology teams, this is significant.
Consider these scenarios:
- A developer who notices customer information being copied into an AI tool.
- A security professional who discovers that a vendor has inappropriate access to production data.
- A database administrator who realizes that personal information is being retained indefinitely.
- An employee who discovers that a system is making significant decisions about people without adequate oversight.
These are all privacy concerns and compliance is not just a legal issue, it’s becoming an engineering ethics issue.
Data Retention a Potential Technology Problem
One of the less glamorous parts of privacy compliance may also be one of the most technically difficult.

Data deletion.
Bill C-36 contains proposed provisions dealing with retention, disposal and requests for disposal of personal information. It also establishes a proposed framework for data mobility.
The problem is that deleting data is rarely as simple as pressing delete.
What about:
- Production databases?
- Backups?
- Data warehouses?
- Archived records?
- Analytics platforms?
- Logs?
- Third-party SaaS platforms?
- Development environments?
- Test databases?
- AI training datasets
- Shadow AI instances?
If an organization does not know where its data is replicated, it cannot confidently say that the data has been deleted. This is one reason data architecture and privacy architecture increasingly need to be considered together.
The Cost of Doing Nothing
The proposed legislation would introduce stronger enforcement mechanisms, including compliance orders, a private right of action and potentially significant penalties for certain offences. The bill proposes maximum fines for indictable offences of the greater of $25 million or 5% of an organization’s gross global revenue, and for summary conviction offences, the greater of $20 million or 4% of gross global revenue.
Those are maximum penalties, not automatic fines.
But the message is clear.
Privacy is becoming a board-level risk, and because privacy failures increasingly involve technology, it is also becoming a technology leadership issue.
What Should Businesses Do Now?
While Bill C-36 is not yet law, organizations should not treat the proposed provisions as today’s mandatory requirements. Business leaders can, and should, however, use the legislation as a useful stress test.
Business and technology leaders should consider conducting a practical review of:
- Data inventory
What personal information do you collect and where does it live?
- Data flows
Where does information move between internal systems, vendors, cloud platforms and other jurisdictions?
- Access
Who can access sensitive information and why?
- Retention
How long are you keeping information, and can you actually delete it when appropriate?
- Vendors
Do your contracts and technical controls adequately address third-party handling of personal information?
- AI
Are automated decision systems documented, explainable and subject to appropriate human oversight? Is there documentation of burgeoning AI technical debt?
- Employee information
If you are subject to the proposed federal employee provisions, do HR and IT systems adequately protect employee and applicant information?
- Documentation
Could someone outside the original development team explain how your most important data moves through the organization?
That last question is more important than it sounds.
Privacy Is Becoming Part of Good Software Engineering
The interesting thing about Bill C-36 is that much of what it encourages is already good technology practice.
- Know your data.
- Limit access.
- Document systems.
- Minimize unnecessary information.
- Protect sensitive information.
- Understand your vendors.
- Build security into architecture.
- Know how automated decisions are made.
- Do not keep data forever simply because storage is cheap.
None of these ideas should be revolutionary.
What is changing is the level of accountability surrounding them.
For business leaders, the takeaway is not to panic over a bill that has not yet become law. It is to recognize the direction of travel.
Canada’s privacy framework is being modernized for a world of cloud computing, artificial intelligence, automated decision-making and enormous volumes of personal information.
The organizations that treat privacy as a technology architecture issue will be in a much stronger position than those that treat it as paperwork. Because ultimately, good privacy management is not just about compliance. It is about knowing your data well enough to protect it.
And in 2026, that is becoming an important differentiator in business and an assessment of corporate capability.
At STEP Software, we help organizations assess, document, modernize and improve the software systems that manage critical business data. When privacy requirements expose gaps in legacy architecture, data flows or system documentation, the right technology strategy can often address the business problem without requiring an unnecessary rip-and-replace project. Reach out to our advisors if you would like to chat more about data privacy concerns in your business.
Disclaimer: This article is intended for general informational purposes and is not legal advice. Bill C-36 is proposed legislation and may be amended during the parliamentary process. Organizations should obtain legal or privacy advice about their specific obligations.


