<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>legal - STEP Software</title>
	<atom:link href="https://www.stepsoftware.com/tag/legal/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.stepsoftware.com</link>
	<description>Custom Software Development</description>
	<lastBuildDate>Wed, 16 Sep 2026 13:07:25 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.1</generator>

<image>
	<url>https://www.stepsoftware.com/wp-content/uploads/2025/02/FaviconFoxOnDark_512-150x150.png</url>
	<title>legal - STEP Software</title>
	<link>https://www.stepsoftware.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Bill C-36: Is Your Business Ready?</title>
		<link>https://www.stepsoftware.com/bill-c-36-is-your-business-ready/</link>
		
		<dc:creator><![CDATA[STEP Software]]></dc:creator>
		<pubDate>Thu, 17 Sep 2026 11:00:00 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[artificial intelligence]]></category>
		<category><![CDATA[budget]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[legal]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[software development]]></category>
		<guid isPermaLink="false">https://www.stepsoftware.com/?p=5415</guid>

					<description><![CDATA[<p>The organizations that treat privacy as a technology architecture issue will be in a much stronger position than those that treat it as paperwork. Because ultimately, good privacy management is not just about compliance. It is about knowing your data well enough to protect it.</p>
<p>The post <a href="https://www.stepsoftware.com/bill-c-36-is-your-business-ready/">Bill C-36: Is Your Business Ready?</a> first appeared on <a href="https://www.stepsoftware.com">STEP Software</a>.</p>]]></description>
										<content:encoded><![CDATA[<p class="wp-block-paragraph">What Canada&#8217;s Proposed Consumer Data Act Could Mean for Businesses and Employees</p>



<p class="wp-block-paragraph">Privacy legislation has a habit of sounding like something the legal department will worry about later. Until someone asks IT where the customer data is stored. Then things get interesting.</p>



<p class="wp-block-paragraph">Canada&#8217;s proposed Bill C-36, the <strong>Protecting Privacy and Consumer Data Act (PPCDA)</strong>, represents a <a href="https://justice.canada.ca/eng/csj-sjc/pl/charter-charte/c36_1.html" target="_blank" rel="noopener">significant proposed modernization</a> of Canada&#8217;s federal private-sector privacy framework. Introduced on June 15, 2026, the bill is designed to replace Part 1 of the Personal Information Protection and Electronic Documents Act, better known as <a href="https://laws-lois.justice.gc.ca/eng/acts/p-8.6/" target="_blank" rel="noopener">PIPEDA</a>, with a new privacy regime designed for today&#8217;s data-driven economy.</p>



<p class="wp-block-paragraph">As of September 2026, Bill C-36 is <strong>proposed legislation and has</strong> <a href="https://www.parl.ca/legisinfo/en/bill/45-1/c-36" target="_blank" rel="noopener"><strong>not yet come into force</strong></a>. Its provisions would come into force on dates established by order in council.</p>



<p class="wp-block-paragraph">For business and technology leaders, however, waiting until legislation becomes law before examining the implications could be an expensive strategy.</p>



<p class="wp-block-paragraph">The proposed changes reach into data governance, cybersecurity, artificial intelligence, vendor management, employee information, software architecture and the way organizations think about personal information.</p>



<h2 class="wp-block-heading">Why Bill C-36 Should Matter to Business Leaders</h2>



<p class="wp-block-paragraph">The proposed legislation starts from a relatively straightforward principle: organizations should be able to use personal information for legitimate business purposes, but individuals should have meaningful privacy protections.</p>



<p class="wp-block-paragraph">The bill would establish rules governing the collection, use and disclosure of personal information in commercial activities, while explicitly recognizing privacy as a fundamental right. The Privacy Commissioner of Canada welcomed the proposed recognition of privacy as a fundamental right, along with stronger enforcement powers and privacy impact assessment requirements.</p>



<p class="wp-block-paragraph">That creates a shift in mindset.</p>



<figure class="wp-block-image size-full"><img fetchpriority="high" decoding="async" width="1024" height="561" src="https://www.stepsoftware.com/wp-content/uploads/2026/09/DIAGRAM_CheckBoxes.png" alt="Data and check boxes" class="wp-image-5412" srcset="https://www.stepsoftware.com/wp-content/uploads/2026/09/DIAGRAM_CheckBoxes.png 1024w, https://www.stepsoftware.com/wp-content/uploads/2026/09/DIAGRAM_CheckBoxes-300x164.png 300w, https://www.stepsoftware.com/wp-content/uploads/2026/09/DIAGRAM_CheckBoxes-768x421.png 768w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph"><strong>Privacy is no longer simply a compliance checkbox.</strong></p>



<p class="wp-block-paragraph">It becomes part of business operations.</p>



<p class="wp-block-paragraph">For business leaders, that means asking a very practical question:</p>



<p class="wp-block-paragraph"><strong>“Do we actually know what personal information our organization collects, why we collect it, where it goes, who can access it and how long we keep it?”</strong></p>



<p class="wp-block-paragraph">If the answer involves a long pause and several people looking at the IT department, it may be time for a <a href="https://www.stepsoftware.com/the-cost-of-doing-data-what-the-data-center-boom-means-for-it-budgets/">data audit</a>.</p>



<h2 class="wp-block-heading">The Proposed Privacy Management Program</h2>



<p class="wp-block-paragraph">One of the most significant changes for organizations is the proposed requirement to establish and maintain a <a href="https://www.priv.gc.ca/en/privacy-topics/privacy-laws-in-canada/the-personal-information-protection-and-electronic-documents-act-pipeda/pipeda-compliance-help/pipeda-compliance-and-training-tools/gl_acc_201204/" target="_blank" rel="noopener"><strong>privacy management program</strong></a>.</p>



<p class="wp-block-paragraph">Bill C-36 would require organizations to maintain policies, practices and procedures covering areas such as protecting personal information, handling information requests and complaints, training employees and explaining privacy policies and procedures. The organization would also need to consider the volume and sensitivity of the personal information under its control.</p>



<p class="wp-block-paragraph">This is where privacy becomes an operational issue.</p>



<p class="wp-block-paragraph">A privacy policy sitting in an employee handbook is one thing.</p>



<p class="wp-block-paragraph">A functioning privacy management program is something else.</p>



<p class="wp-block-paragraph">Technology teams will very likely be the ones responsible for supporting the systems that make these programs work.</p>



<p class="wp-block-paragraph">Support could look like:</p>



<ul class="wp-block-list">
<li>Data inventories</li>



<li>Access controls</li>



<li>Audit logs</li>



<li>Retention rules</li>



<li>Data deletion</li>



<li>Encryption</li>



<li>Identity management</li>



<li>Backup management</li>



<li>Vendor controls</li>



<li>Data classification</li>



<li>Privacy impact assessments</li>



<li>Documentation</li>
</ul>



<p class="wp-block-paragraph">In other words, the legislation could turn &#8220;Where is that data?&#8221; from an awkward question into a formal business requirement.</p>



<h2 class="wp-block-heading">The Third-Party Software Problem</h2>



<p class="wp-block-paragraph">Modern organizations rarely manage all of their corporate data themselves.</p>



<p class="wp-block-paragraph">Customer relationship management platforms, payroll systems, cloud services, marketing platforms, HR systems, analytics tools, AI platforms and outsourced software development can all involve personal information.</p>



<p class="wp-block-paragraph">Bill C-36 proposes that organizations remain accountable for personal information under their control even when a service provider handles that information.</p>



<p class="wp-block-paragraph">The bill would require organizations transferring personal information to service providers to ensure, through contracts or other means, that the provider offers an equivalent level of protection.</p>



<p class="wp-block-paragraph">That has implications for vendor selection.</p>



<p class="wp-block-paragraph">The cheapest software vendor may turn into the most expensive option once privacy risk is considered.</p>



<p class="wp-block-paragraph">Business leaders should be asking:</p>



<p class="wp-block-paragraph"><strong>“What happens to our data when it leaves our systems?”</strong></p>



<p class="wp-block-paragraph">And:</p>



<p class="wp-block-paragraph"><strong>“What happens when we want it back?”</strong></p>



<p class="wp-block-paragraph">Those two questions should be part of procurement and contract creation, not something discovered after signing on the dotted line.</p>



<h2 class="wp-block-heading">AI Makes This Even More Complicated</h2>



<p class="wp-block-paragraph">This is where Bill C-36 becomes particularly relevant to today&#8217;s technology environment.</p>



<p class="wp-block-paragraph">The proposed legislation specifically addresses <a href="https://www.canada.ca/en/government/system/digital-government/digital-government-innovations/responsible-use-ai/guide-scope-directive-automated-decision-making.html" target="_blank" rel="noopener"><strong>automated decision systems</strong></a>, which it defines broadly to include technology using rules-based systems, <a href="https://www.stepsoftware.com/qa-the-cornerstone-of-great-software/" target="_blank" rel="noopener">regression analysis</a>, predictive analytics, <a href="https://www.stepsoftware.com/4-easy-to-understand-machine-learning-methods/" target="_blank" rel="noopener">machine learning</a>, deep learning, neural networks and other techniques.</p>



<p class="wp-block-paragraph">Organizations using an automated decision system to make a prediction, recommendation or decision about an individual that could have a legal or similarly significant effect would have transparency obligations.</p>



<p class="wp-block-paragraph">On request, an individual could be entitled to an explanation identifying the type and source of personal information used and the reasons or principal factors behind the prediction or decision. The individual would also have an opportunity to make representations to an employee capable of reviewing the decision.</p>



<figure class="wp-block-image size-full"><img decoding="async" width="1024" height="611" src="https://www.stepsoftware.com/wp-content/uploads/2026/09/DIAGRAM_Data.png" alt="data, security, and AI" class="wp-image-5413" srcset="https://www.stepsoftware.com/wp-content/uploads/2026/09/DIAGRAM_Data.png 1024w, https://www.stepsoftware.com/wp-content/uploads/2026/09/DIAGRAM_Data-300x179.png 300w, https://www.stepsoftware.com/wp-content/uploads/2026/09/DIAGRAM_Data-768x458.png 768w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">This is a very different technical requirement from simply saying, &#8220;Our AI made the decision.&#8221;</p>



<p class="wp-block-paragraph">It creates a potential need for:</p>



<ul class="wp-block-list">
<li>Data lineage</li>



<li>Decision logging</li>



<li>Model documentation</li>



<li>Human review processes</li>



<li>Explainability</li>



<li>Version control</li>



<li><a href="https://www.stepsoftware.com/software-audits-and-why-you-should-get-one/" target="_blank" rel="noopener">Auditability</a></li>
</ul>



<p class="wp-block-paragraph">For organizations experimenting with AI in hiring, lending, insurance, customer service, fraud detection, employee management or other decision-making environments, this deserves serious proactive, attention.</p>



<p class="wp-block-paragraph">The AI model may be the clever part; the <a href="https://www.stepsoftware.com/document-like-your-code-depends-on-it/" target="_blank" rel="noopener">documentation</a> around it may become the important part.</p>



<h2 class="wp-block-heading">What About Employees?</h2>



<p class="wp-block-paragraph">This is where organizations need to be careful about oversimplifying Bill C-36.</p>



<p class="wp-block-paragraph">The proposed legislation applies to employee and applicant personal information where the organization collects, uses or discloses that information in connection with operating a <strong>federal work, undertaking or business</strong>.</p>



<p class="wp-block-paragraph">That means the employee provisions are not simply a blanket new federal privacy regime covering every Canadian employer. For organizations that fall within the proposed federal scope, however, employee data becomes an important consideration.</p>



<p class="wp-block-paragraph">Think about the amount of information an organization may hold about its people:</p>



<ul class="wp-block-list">
<li>Payroll information</li>



<li>Benefits information</li>



<li>Performance records</li>



<li>Attendance information</li>



<li>Recruiting information</li>



<li>Employment history</li>



<li>Training records</li>



<li>Device information</li>



<li>Access logs</li>



<li>Location information</li>



<li>Workplace communications</li>



<li>Security information</li>



<li>Potentially sensitive HR information</li>
</ul>



<p class="wp-block-paragraph">Technology teams often touch many of these systems without being the owners of the information. That creates a <strong>shared responsibility</strong> between HR, legal, security, IT <em>and</em> business leadership.</p>



<p class="wp-block-paragraph">The question is no longer simply whether the organization has the information; it’s whether the organization can explain <strong>why it has it, how it uses it and who has access to it</strong>.</p>



<h2 class="wp-block-heading">The Role of Employees</h2>



<p class="wp-block-paragraph">Bill C-36 is not only about what organizations can and cannot do. It also introduces protections for employees who raise concerns about potential violations.</p>



<p class="wp-block-paragraph">The proposed legislation would prohibit an employer from dismissing, suspending, demoting, disciplining, harassing or otherwise disadvantaging an employee because they acted in good faith to report a suspected contravention, refused to participate in conduct that would contravene the legislation or took steps required to prevent a contravention. The <a href="https://www.parl.ca/DocumentViewer/en/45-1/bill/C-36/first-reading" target="_blank" rel="noopener">bill explicitly includes</a> independent contractors within its definition of employee for this provision.</p>



<p class="wp-block-paragraph"><strong>For technology teams, this is significant.</strong></p>



<p class="wp-block-paragraph">Consider these scenarios:</p>



<ul class="wp-block-list">
<li>A developer who notices customer information being copied into an AI tool.</li>



<li>A security professional who discovers that a vendor has inappropriate access to production data.</li>



<li>A database administrator who realizes that personal information is being retained indefinitely.</li>



<li>An employee who discovers that a system is making significant decisions about people without adequate oversight.</li>
</ul>



<p class="wp-block-paragraph">These are all privacy concerns and compliance is not just a legal issue, it’s becoming an engineering ethics issue.</p>



<h2 class="wp-block-heading">Data Retention a Potential Technology Problem</h2>



<p class="wp-block-paragraph">One of the less glamorous parts of privacy compliance may also be one of the most technically difficult.</p>



<figure class="wp-block-image size-full"><img decoding="async" width="1024" height="448" src="https://www.stepsoftware.com/wp-content/uploads/2026/09/DIAGRAM_GarbageCan.png" alt="Digital Garbage Can" class="wp-image-5414" srcset="https://www.stepsoftware.com/wp-content/uploads/2026/09/DIAGRAM_GarbageCan.png 1024w, https://www.stepsoftware.com/wp-content/uploads/2026/09/DIAGRAM_GarbageCan-300x131.png 300w, https://www.stepsoftware.com/wp-content/uploads/2026/09/DIAGRAM_GarbageCan-768x336.png 768w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph"><strong>Data deletion.</strong></p>



<p class="wp-block-paragraph">Bill C-36 contains proposed provisions dealing with retention, disposal and requests for disposal of personal information. It also establishes a proposed framework for data mobility.</p>



<p class="wp-block-paragraph">The problem is that deleting data is rarely as simple as pressing delete.</p>



<p class="wp-block-paragraph">What about:</p>



<ul class="wp-block-list">
<li>Production databases?</li>



<li>Backups?</li>



<li>Data warehouses?</li>



<li>Archived records?</li>



<li>Analytics platforms?</li>



<li>Logs?</li>



<li>Third-party SaaS platforms?</li>



<li>Development environments?</li>



<li>Test databases?</li>



<li>AI training datasets</li>



<li><a href="https://www.stepsoftware.com/questions-from-the-c-suite-shadow-ai/" target="_blank" rel="noopener">Shadow AI</a> instances?</li>
</ul>



<p class="wp-block-paragraph">If an organization does not know where its data is replicated, it cannot confidently say that the data has been deleted. This is one reason <a href="https://www.stepsoftware.com/?s=data+architecture" target="_blank" rel="noopener">data architecture</a> and privacy architecture increasingly need to be considered together.</p>



<h2 class="wp-block-heading">The Cost of Doing Nothing</h2>



<p class="wp-block-paragraph">The proposed legislation would introduce stronger enforcement mechanisms, including compliance orders, a private right of action and potentially significant penalties for certain offences. The bill proposes <a href="https://www.osler.com/en/insights/reports/the-protecting-privacy-and-consumer-data-act-bill-c-36-key-obligations-and-enforcement-overview/" target="_blank" rel="noopener">maximum fines</a> for indictable offences of the greater of $25 million or 5% of an organization&#8217;s gross global revenue, and for summary conviction offences, the greater of $20 million or 4% of gross global revenue.</p>



<p class="wp-block-paragraph">Those are maximum penalties, not automatic fines.</p>



<p class="wp-block-paragraph">But the message is clear.</p>



<p class="wp-block-paragraph">Privacy is becoming a board-level risk, and because privacy failures increasingly involve technology, it is also becoming a technology leadership issue.</p>



<h2 class="wp-block-heading">What Should Businesses Do Now?</h2>



<p class="wp-block-paragraph">While Bill C-36 is not yet law, organizations should not treat the proposed provisions as today&#8217;s mandatory requirements. Business leaders can, and should, however, use the legislation as a useful stress test.</p>



<p class="wp-block-paragraph">Business and technology leaders should consider conducting a practical review of:</p>



<ol class="wp-block-list">
<li>Data inventory</li>
</ol>



<p class="wp-block-paragraph">What personal information do you collect and where does it live?</p>



<ol start="2" class="wp-block-list">
<li>Data flows</li>
</ol>



<p class="wp-block-paragraph">Where does information move between internal systems, vendors, cloud platforms and other jurisdictions?</p>



<ol start="3" class="wp-block-list">
<li>Access</li>
</ol>



<p class="wp-block-paragraph">Who can access sensitive information and why?</p>



<ol start="4" class="wp-block-list">
<li>Retention</li>
</ol>



<p class="wp-block-paragraph">How long are you keeping information, and can you actually delete it when appropriate?</p>



<ol start="5" class="wp-block-list">
<li>Vendors</li>
</ol>



<p class="wp-block-paragraph">Do your contracts and technical controls adequately address third-party handling of personal information?</p>



<ol start="6" class="wp-block-list">
<li>AI</li>
</ol>



<p class="wp-block-paragraph">Are automated decision systems documented, explainable and subject to appropriate human oversight? Is there documentation of burgeoning <a href="https://www.stepsoftware.com/ai-technical-debt-the-hidden-cost-can-you-feel-it/" target="_blank" rel="noopener">AI technical debt</a>?</p>



<ol start="7" class="wp-block-list">
<li>Employee information</li>
</ol>



<p class="wp-block-paragraph">If you are subject to the proposed federal employee provisions, do HR and IT systems adequately protect employee and applicant information?</p>



<ol start="8" class="wp-block-list">
<li>Documentation</li>
</ol>



<p class="wp-block-paragraph">Could someone outside the original development team explain how your most important data moves through the organization?</p>



<p class="wp-block-paragraph">That last question is more important than it sounds.</p>



<h2 class="wp-block-heading">Privacy Is Becoming Part of Good Software Engineering</h2>



<p class="wp-block-paragraph">The interesting thing about Bill C-36 is that much of what it encourages is already good technology practice.</p>



<ul class="wp-block-list">
<li>Know your data.</li>



<li>Limit access.</li>



<li>Document systems.</li>



<li>Minimize unnecessary information.</li>



<li>Protect sensitive information.</li>



<li>Understand your vendors.</li>



<li>Build security into architecture.</li>



<li>Know how automated decisions are made.</li>



<li>Do not keep data forever simply because storage is cheap.</li>
</ul>



<p class="wp-block-paragraph">None of these ideas should be revolutionary.</p>



<p class="wp-block-paragraph">What is changing is the level of accountability surrounding them.</p>



<p class="wp-block-paragraph">For business leaders, the takeaway is not to panic over a bill that has not yet become law. It is to recognize the direction of travel.</p>



<p class="wp-block-paragraph">Canada&#8217;s privacy framework is being modernized for a world of <a href="https://www.stepsoftware.com/2025-software-trends-code-chaos-cloud/" target="_blank" rel="noopener">cloud computing</a>, artificial intelligence, automated decision-making and enormous volumes of personal information.</p>



<p class="wp-block-paragraph">The organizations that treat privacy as a technology architecture issue will be in a much stronger position than those that treat it as paperwork. Because ultimately, good privacy management is not just about compliance. It is about knowing your data well enough to protect it.</p>



<p class="wp-block-paragraph">And in 2026, that is becoming an important differentiator in business and an assessment of corporate capability.</p>



<p class="wp-block-paragraph"><strong>At STEP Software, we help organizations assess, document, modernize and improve the software systems that manage critical business data. When privacy requirements expose gaps in</strong> <a href="https://www.stepsoftware.com/composable-architecture-a-smart-choice-or-risky-gambit/" target="_blank" rel="noopener"><strong>legacy architecture</strong></a><strong>, data flows or system documentation, the right technology strategy can often address the business problem without requiring an unnecessary rip-and-replace project.</strong> <a href="https://www.stepsoftware.com/advisory-division/" target="_blank" rel="noopener"><strong>Reach out to our advisors</strong></a> <strong>if you would like to chat more about data privacy concerns in your business.</strong></p>



<p class="wp-block-paragraph"><em><strong>Disclaimer:</strong></em> <em>This article is intended for general informational purposes and is not legal advice. Bill C-36 is proposed legislation and may be amended during the parliamentary process. Organizations should obtain legal or privacy advice about their specific obligations</em><em>.</em></p><p>The post <a href="https://www.stepsoftware.com/bill-c-36-is-your-business-ready/">Bill C-36: Is Your Business Ready?</a> first appeared on <a href="https://www.stepsoftware.com">STEP Software</a>.</p>]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
