All insights
,

Canada’s new privacy bill: what a society with Canadian members should check now

Centre Block and the Peace Tower on Parliament Hill, Ottawa, under a clear blue sky

Canada tabled Bill C-36 on 15 June 2026 [1][2]. If it passes, it will replace Part 1 of PIPEDA, Canada’s federal private-sector privacy law, with a new Protecting Privacy and Consumer Data Act [1][3]. It is the third attempt in six years: Bill C-11 died when Parliament was dissolved in 2021, and Bill C-27 died in January 2025 [1][4]. Parliament returned on 21 September [4][5], and at the time of writing C-36 has not passed second reading [1][6]. So do nothing rash. Then check three things that hold whether or not this bill survives, because one Canadian privacy law already reaches well beyond its borders, and it is not the one in the headlines.

What the bill would actually do

The structural change is who enforces it. Oversight would move from the Privacy Commissioner of Canada to a new Digital Safety and Data Protection Commission, created by a separate bill, C-34, and reporting to a minister rather than to Parliament [1][2][7]. The Privacy Commissioner called the bill “a pivotal step for privacy in Canada” [7].

The teeth are real. The Commission could impose penalties of up to the higher of C$10 million or 3% of gross global revenue, and a conviction could bring a fine of up to the higher of C$25 million or 5% [1][2]. Individuals would gain a right to request disposal of their data, a form of erasure [1][3]. Organisations would need a privacy impact assessment before transferring personal information outside Canada [1][3][8]. Anyone using an automated decision system with a legal or similarly significant effect on people would have to describe that use publicly, explain an individual decision on request, and let the person make written representations to a human who can review it [1][3][8]. The bill defines an automated decision system as any technology that “assists or replaces the judgment of human decision-makers” [1][4]. A child’s personal information is sensitive by definition [1][2].

None of it is in force. The Act would commence on a day fixed by order in council, and not before the new Commission exists; until then PIPEDA and the Privacy Commissioner carry on [1][3]. A bill is not a law; put the date in your diary in pencil.

Does it even reach you?

The new Act, like PIPEDA, applies to personal information handled “in the course of commercial activities” [1][3][9]. The definition of commercial activity is carried over word for word, and it names one activity that catches associations directly: “the selling, bartering or leasing of donor, membership or other fundraising lists” [3][9][10].

The Privacy Commissioner’s guidance on PIPEDA is blunt about the rest. Non-profit organisations are usually not subject to the Act because they do not typically engage in commercial activities. Collecting membership fees, organising club activities, compiling a list of members’ names and addresses, mailing newsletters and fundraising are not considered commercial. Selling or leasing that membership list is [10].

Here Tecology’s view begins and the regulator’s ends. A society that charges congress delegates, sells exhibition space and publishes a subscription journal looks a good deal more commercial than a newsletter does, and the guidance does not draw that line for you. An hour with a Canadian privacy lawyer beats a month of guessing. Do not expect geography to help either. The Library of Parliament notes the bill has no explicit provision on its reach outside Canada [1], but the Privacy Commissioner applies a “real and substantial connection” test and said in a May 2026 finding that a physical presence in Canada is not required when a website is involved [11]. A membership portal that Canadians join from Canada is a website.

Quebec already applies

While Ottawa debates, Quebec’s private-sector privacy law, as amended by what everyone calls Law 25, is in force and has a much wider front door. It applies to personal information handled by anyone “carrying on an enterprise within the meaning of article 1525 of the Civil Code” [12][13]. Article 1525 defines that as “an organized economic activity, whether or not it is commercial in nature” [14]. Quebec’s regulator, the Commission d’accès à l’information, says the Act can therefore cover not-for-profit organisations, judged case by case, and that it reaches organisations located outside Quebec that handle personal information in the course of enterprise activities in Quebec [13].

If that is you, four obligations are live now, not pending:

  • A named person in charge of protecting personal information, by default the person with the highest authority in the organisation, with title and contact details published on your website [12][15].
  • Governance policies covering retention, destruction, staff roles and complaints, published on the website in simple and clear language [12][15].
  • A privacy impact assessment before communicating personal information outside Quebec, and a written agreement covering the transfer [12][16]. For a society hosted in Edinburgh or Frankfurt, every Quebec member’s record is one.
  • If a decision about a person is based exclusively on automated processing, you must tell them no later than when you tell them the decision, give them on request the information and principal factors used, and let them put observations to a staff member who can review it [12][16].

The penalties are not theoretical: administrative penalties of up to the higher of C$10 million or 2% of worldwide turnover, and fines of up to the higher of C$25 million or 4% [12][17]. If your Quebec house is in order, most of C-36 will feel familiar.

The adequacy question for your EU members

Canada holds an EU adequacy decision for commercial organisations, reaffirmed by the European Commission on 15 January 2024 alongside ten other jurisdictions [18]. The GDPR requires the Commission to review those decisions periodically [18]. The Library of Parliament reads that as at least every four years, so no later than 2028, and observes that replacing PIPEDA and changing the enforcer “could have an impact on this assessment” [1]. That is caution, not a prediction of trouble. If you are an EU-based society using a Canadian membership or events supplier under that decision, note the dependency in your transfer register and keep watching.

Three things to check this month

Each is an afternoon’s work. None depends on what the House of Commons does next.

Inventory what you do in Canada. One spreadsheet, one named owner. Which activities touch Canadian residents: membership, congress registration, journal subscriptions, sponsorship sales, mailing lists. Mark which a reasonable person would call commercial, using the regulator’s list above as the yardstick [10], and note which suppliers hold that data and where.

Run the Quebec check. If you have members in Quebec, test yourself against the four obligations above. Named person on the site? Plain-language policy? Transfer out of Quebec assessed and papered? Automated decisions disclosed? A truthful “not yet” with a date next to it is defensible. Silence is not.

List your automated decisions. Membership eligibility rules, abstract triage, early-bird cut-offs, scoring in an events platform. For each, can you write one plain paragraph on what the system considers and who a person can appeal to? Quebec asks this today of exclusively automated decisions [12], and C-36 would ask it of anything with a legal or similarly significant effect, whether or not a human was nominally in the loop [1][3]. We cover the same ground for Australian members and for the EU AI Act. One paragraph, written once, serves in all three places.

Whatever happens to C-36, the direction is the same as everywhere else: know what you hold, say what you do with it, and be able to explain what the software decided. Organisations that treat that as housekeeping rather than a compliance project tend to find each new bill a little less alarming than the last.

References

  1. Savoie, A. and Thibodeau, M.-O. Legislative Summary of Bill C-36: An Act to enact the Protecting Privacy and Consumer Data Act (preliminary version). Library of Parliament, 6 July 2026. https://lop.parl.ca/staticfiles/PublicWebsite/Home/ResearchPublications/LegislativeSummaries/PDF/45-1/PV_45-1-C36-E.pdf. Accessed 05 October 2026.
  2. Innovation, Science and Economic Development Canada. Backgrounder: Government of Canada introduces legislation to Protect Canadians’ Privacy in the Digital Age. Canada.ca, 15 June 2026. https://www.canada.ca/en/innovation-science-economic-development/news/2026/06/government-of-canada-introduces-legislation-to-protect-canadians-privacy-in-the-digital-age.html. Accessed 05 October 2026.
  3. Parliament of Canada. Bill C-36, An Act to enact the Protecting Privacy and Consumer Data Act, to amend the Personal Information Protection and Electronic Documents Act and to make amendments to other Acts (first reading). 15 June 2026. https://www.parl.ca/DocumentViewer/en/45-1/bill/C-36/first-reading. Accessed 05 October 2026.
  4. Blake, Cassels & Graydon LLP. Third Time’s the Charm? Canada’s Latest Approach to Reform the Federal Private-Sector Privacy Framework. Blakes, 24 June 2026. https://www.blakes.com/insights/third-time-s-the-charm-canada-s-latest-approach-to-reform-the-federal-private-sector-privacy-framew/. Accessed 05 October 2026.
  5. Gowling WLG. Bill C-36: Timeline of developments. Gowling WLG, 15 June 2026. https://gowlingwlg.com/en-ca/insights-resources/articles/2026/bill-c36-timeline-of-developments. Accessed 05 October 2026.
  6. openparliament.ca. Bill C-36 (45th Parliament, 1st Session). openparliament.ca, n.d. https://openparliament.ca/bills/45-1/C-36/. Accessed 05 October 2026.
  7. Office of the Privacy Commissioner of Canada. Statement by the Privacy Commissioner of Canada on Bill C-36, the Protecting Privacy and Consumer Data Act. OPC, 15 June 2026. https://www.priv.gc.ca/en/opc-news/speeches-and-statements/2026/s-d_260615/. Accessed 05 October 2026.
  8. Gowling WLG. Understanding Bill C-36: What organizations need to know about Canada’s proposed privacy reform bill. Gowling WLG, 24 June 2026. https://gowlingwlg.com/en/insights-resources/articles/2026/understanding-bill-c36. Accessed 05 October 2026.
  9. Government of Canada. Personal Information Protection and Electronic Documents Act, S.C. 2000, c. 5, sections 2 and 4. Justice Laws Website, n.d. https://laws-lois.justice.gc.ca/eng/acts/P-8.6/page-1.html. Accessed 05 October 2026.
  10. Office of the Privacy Commissioner of Canada. How PIPEDA applies to charitable and non-profit organizations. OPC, n.d. https://www.priv.gc.ca/en/privacy-topics/privacy-laws-in-canada/the-personal-information-protection-and-electronic-documents-act-pipeda/r_o_p/02_05_d_19/. Accessed 05 October 2026.
  11. Office of the Privacy Commissioner of Canada. PIPEDA Findings #2026-002: Joint Investigation of OpenAI OpCo, LLC. OPC, 6 May 2026. https://www.priv.gc.ca/en/opc-actions-and-decisions/investigations/investigations-into-businesses/2026/pipeda-2026-002/. Accessed 05 October 2026.
  12. Gouvernement du Québec. Act respecting the protection of personal information in the private sector, CQLR c. P-39.1. Légis Québec, n.d. https://www.legisquebec.gouv.qc.ca/en/document/cs/P-39.1. Accessed 05 October 2026.
  13. Commission d’accès à l’information du Québec. Entreprises et organisations privées: Champ d’application de la Loi. CAI, n.d. https://www.cai.gouv.qc.ca/protection-renseignements-personnels/information-entreprises-privees/champ-application-loi_entreprises. Accessed 05 October 2026.
  14. Gouvernement du Québec. Civil Code of Québec, CQLR c. CCQ-1991, article 1525. Légis Québec, n.d. https://www.legisquebec.gouv.qc.ca/en/document/cs/CCQ-1991. Accessed 05 October 2026.
  15. Commission d’accès à l’information du Québec. Entreprises et organisations privées: Responsabilité des entreprises. CAI, n.d. https://www.cai.gouv.qc.ca/protection-renseignements-personnels/information-entreprises-privees/responsable-protection-renseignements-personnels-entreprise. Accessed 05 October 2026.
  16. Commission d’accès à l’information du Québec. Entreprises et organisations privées: Utilisation et communication de renseignements personnels. CAI, n.d. https://www.cai.gouv.qc.ca/protection-renseignements-personnels/information-entreprises-privees/utilisation-communication-renseignements-personnels. Accessed 05 October 2026.
  17. Commission d’accès à l’information du Québec. Entreprises et organisations privées: Sanctions. CAI, n.d. https://www.cai.gouv.qc.ca/protection-renseignements-personnels/information-entreprises-privees/sanctions-entreprises-poursuites. Accessed 05 October 2026.
  18. European Commission. Commission finds that EU personal data flows can continue with 11 third countries and territories. Press release IP/24/161, 15 January 2024. https://ec.europa.eu/commission/presscorner/detail/en/ip_24_161. Accessed 05 October 2026.

The Tecology Brief

Get insights like this in your inbox.

Occasional, considered notes on academic digital — never noisy, unsubscribe in one click.

By subscribing you agree to our Privacy Policy. We only ever send The Tecology Brief — unsubscribe in one click, any time.

More insights

Rows of labelled red, black, yellow and blue levers in a railway signal box
Digital Strategy
Australia’s privacy law now asks how your algorithms decide
From 10 December 2026, organisations covered by Australia’s Privacy Act must explain their automated decision-making in their privacy policies. Here is what counts, whether the law reaches you at all, and why it is worth an afternoon this month.
7 min read
Read article
The Berlaymont building, headquarters of the European Commission, with EU flags in front
AI in Academia
The AI Act deadline moved. Here is what did not
The EU pushed its high-risk AI deadlines back to 2027 and 2028 — but the transparency duties that touch your website went live on 2 August 2026. Here is which deadline is which, and what to check this week.
6 min read
Read article
A plate of chocolate chip cookies on a wooden table
Digital Strategy
The cookie banner rules changed in February. Most websites haven’t noticed
The Data (Use and Access) Act quietly rewrote the UK’s cookie consent rules in February — fewer cookies now need consent, and the fines for getting it wrong are thirty-five times bigger. Here is what an association or university web team should do about it.
4 min read
Read article

Start a conversation

Tell us about the work you’re doing.

The best projects start with understanding the work behind them. Book a 30-minute call — no pitch deck, no pressure, just a conversation about what you’re trying to do.

Or email info@tecology.co — we reply within one working day.

Privacy Settings
This website uses cookies to enhance your browsing experience on our website and our services. You may revoke or change your consent settings at any time.

Accept all Essential only