Canada's federal private-sector privacy law is the Personal Information Protection and Electronic Documents Act. PIPEDA. It came into force in 2000. It predates the iPhone, Facebook, the commercial cloud, and the entire modern data brokerage industry. It has been the governing law for a quarter century.
The Office of the Privacy Commissioner describes PIPEDA as setting "the ground rules for how private-sector organizations collect, use, and disclose personal information in the course of for-profit, commercial activities across Canada." That framework — written when most organizations stored data on premises and data breaches were rare events — is still in force today.
Multiple attempts to replace it have failed. Bill C-11 (2020) died. Bill C-27 (2022) reached committee study, had its last meeting September 26, 2024, and died when Parliament was prorogued in January 2025. The much-criticized PIPEDA continued to govern by default.
On June 15, 2026, the Minister of Artificial Intelligence and Digital Innovation, Evan Solomon, introduced Bill C-36, the Protecting Privacy and Consumer Data Act. First reading the same day. It is the third attempt in six years.
What the Bill Does Right¶
Three things stand out from the bill as introduced.
Privacy as a fundamental right. The Act's purpose section frames privacy as a fundamental right. This is language privacy advocates and the Commissioner had pressed for across the previous two attempts. It matters because it changes the interpretive lens. When privacy is a consumer protection issue, it gets balanced against commercial interests. When it is a fundamental right, the burden shifts.
Real enforcement powers. The bill establishes the Digital Safety and Data Protection Commission of Canada, with the power to issue orders and impose administrative monetary penalties. The expected penalty ceiling is the greater of C$25 million or 5% of gross global revenue — the same range as the previous Bill C-27's CPPA. This is a meaningful step up from PIPEDA's enforcement model, where the Privacy Commissioner could investigate and recommend but had limited power to compel or fine.
Children's privacy. The bill explicitly recognizes the best interests of children. The Privacy Commissioner welcomed this in his June 15 statement. For community infrastructure — youth programs, community centers, schools — explicit recognition of children's privacy rights in federal law is a signal that data segregation and age-gating are becoming legal expectations, not optional features.
What the Bill Gets Wrong¶
The most consequential feature of C-36 is not what it does but who it puts in charge.
Bill C-36 strips the Privacy Commissioner of Canada of authority over private-sector privacy law. The Commissioner — an independent Agent of Parliament, confirmed by resolution of both the Senate and the House, reporting directly to Parliament — is replaced as the private-sector regulator by a Cabinet-designated member of a five-person commission. That commission was created days earlier under Bill C-34 to police online harms: social media bans, age verification, content moderation, AI chatbot regulation. Bill C-36 renames it the Digital Safety and Data Protection Commission and adds private-sector privacy to its mandate.
Michael Geist, Canada's foremost privacy policy commentator, called the consolidation "unprecedented among Canada's democratic allies" and "a stunning abrogation of good policy development." His argument is structural: the Privacy Commissioner is an independent officer of Parliament whose job is to hold government itself to account. A Cabinet-appointed commission whose chair and majority are occupied by members focused on online content enforcement is a serious downgrade in independence. An Agent of Parliament has a direct line to the legislature. A Cabinet appointee has a direct line to the minister.
The concern is not abstract. Canada's private-sector privacy law governs how banks, airlines, insurers, retailers, and every commercial entity in the country handles personal information. These are contexts unrelated to social media or chatbots. Moving enforcement from an independent specialist regulator to a generalist commission with a content-moderation mandate risks privacy enforcement being deprioritized against competing objectives — especially when the commission is also responsible for the politically charged file of online harms.
The OpenMedia partnership with UBC students found the enforcement gap is the structural problem. Their March 2026 survey of 78 Canadian youth found 93.6% consider data privacy important, but only 3.8% feel confident in their understanding of Canadian privacy law. The gap between caring and feeling equipped to act is real. Bill C-36 tightens rights on paper, but by moving enforcement away from an independent Agent of Parliament toward a distracted commission, rights that are stronger on paper risk being enforced by a regulator with many other priorities.
The Province That Did Not Wait¶
While Ottawa stalled through three failed attempts, Quebec moved.
Law 25 overhauled Quebec's private-sector privacy law through a staged rollout. The bulk of the new obligations — mandatory breach reporting, tightened consent rules, mandatory data protection officers — came into force September 22, 2023. The data portability right followed on September 22, 2024. Quebec residents can now obtain their computerized personal information in a structured, commonly used format and have it sent to another organization.
Law 25 carries real teeth. The Commission d'accès à l'information can impose administrative monetary penalties of up to the greater of $10 million or 2% of worldwide turnover, with penal sanctions reaching higher. This is the gap Bill C-36 is trying to close at the federal level. Quebec's regime has been live for two years.
The contrast is instructive. Quebec built a specialist regulator with focused authority and real penalties. It did not consolidate privacy enforcement into a broader digital safety body. The model works. The federal bill, had it simply followed Quebec's institutional design — stronger powers for the existing independent Commissioner — would have addressed the enforcement gap without the independence downgrade.
What This Means for Community Infrastructure¶
The audience for this site includes Canadian communities — fire halls, town offices, small businesses, community organizers, tribal utilities — that are making infrastructure decisions right now. Bill C-36's relevance is practical, not abstract.
Rights on paper require enforcement to matter. The bill's fundamental-right framing and penalty powers are necessary conditions. They are not sufficient. If the enforcement body is overloaded, under-resourced, or structurally compromised, the rights exist in theory but not in practice. The UBC survey found the underlying structural problem is the absence of real consequences. A commission with competing mandates does not fix that — it redistributes the scarcity.
Compliance is still a continuous obligation. Like the US privacy patchwork, Canadian privacy compliance is not a one-time legal review. Bill C-36 will go through committee study, potential amendments, Senate review, and implementation regulations. The final form may differ from the first-reading text. Organizations that wait for the law to settle before taking data governance seriously will be behind. The communities that own their infrastructure can adapt their policies as the law evolves because the data layer is theirs to configure.
Quebec is the live precedent. If you operate in Quebec, Law 25 is already your compliance environment. Data portability, breach reporting, mandatory privacy officers, real penalties. The federal bill will eventually layer on top of provincial law. For communities running their own infrastructure — Nextcloud for files, Matrix for communication, Keycloak for identity — Law 25 compliance is a configuration and policy exercise. For communities on Google Workspace or Microsoft 365, it is a trust exercise with a provider whose compliance implementation you cannot inspect.
The sovereignty argument is the same one. The US privacy patchwork piece made it through fragmentation. The EU makes it through policy. Canada's version makes it through legislative reform that strengthens rights on paper while weakening the independence of the body that enforces them. All three arrive at the same place: you cannot continuously comply with evolving privacy requirements through trust agreements with third-party providers. You can comply through direct ownership of the systems that hold the data.
The tools are the same ones we deploy everywhere: Proxmox for virtualization, Nextcloud for collaboration, Matrix for communication, Keycloak for identity. Self-hosted infrastructure defaults to the simplest compliance posture — no targeted advertising, no data sales, no broker relationships. When a user exercises a right to access, deletion, or portability, the logs are in your database, not behind a provider's API. When a regulator asks for an audit trail, you produce it from your own systems.
The Bottom Line¶
Bill C-36 is better than PIPEDA. That is a low bar. A law written in 2000 cannot govern data practices in 2026. The fundamental-right framing, the penalty powers, and the children's privacy provisions are genuine improvements.
But the institutional design is a step backward. Stripping an independent Agent of Parliament of private-sector privacy authority and handing it to a Cabinet-appointed commission with a competing mandate is not modernization. It is centralization dressed as reform. The rights are stronger on paper. The enforcement is weaker in structure.
Quebec already proved the alternative: a specialist regulator with focused authority and real penalties, operating independently. The federal government chose not to follow that model.
For Canadian communities, the practical response is unchanged. The law will evolve. The enforcement body will be tested. The gap between rights on paper and rights in practice will be filled by the organizations that control their own data layer. Own the infrastructure, and the compliance follows. Rent the infrastructure, and you are trusting someone else to fill the gap — with a regulator that may or may not be paying attention.
Sources: Parliament of Canada, LEGISinfo Bill C-36, Office of the Privacy Commissioner — Statement on Bill C-36, Michael Geist — Canada's Digital Super-Regulator, Recording Law — Canada Tables Bill C-36, OpenMedia — Young Canadians Are Ready for Privacy Reform, Commission d'accès à l'information du Québec — Law 25, Osler — Canada's 2026 privacy priorities