I've written about Canada twice this summer. The first was Bill C-22 — the Lawful Access Act that passed the House in June and is now in the Senate. That bill compels electronic service providers to build interception capability and retain metadata. Its definition of "electronic service provider" is broad enough to capture a community organization running a Nextcloud instance. The case there was defensive: the government is building surveillance powers, and communities that own their stack are in a structurally different position than communities that rent.

The second was the $2.36 billion in sovereign infrastructure spending in Shared Services Canada's 2026-27 plan. That was the affirmative fiscal argument — the government is putting real money behind sovereign compute, sovereign cloud, and sovereign AI.

Bill C-36 is the third piece, and it's the one that completes the triangle.

What Bill C-36 Does

Introduced June 15, 2026, Bill C-36 enacts the Protecting Privacy and Consumer Data Act (PPCDA). It's the federal government's third attempt to modernize PIPEDA, after Bill C-11 (2020) and Bill C-27 (2022) both died on the order paper. The difference this time: it was introduced as part of a coordinated legislative package alongside Bill C-34 (Safe Social Media Act) and Bill C-22 (Lawful Access Act). The government is moving all three together.

The PPCDA is the most significant reform of Canada's private-sector privacy regime in over 25 years. Here's what it does:

Recognizes privacy as a fundamental right. PIPEDA treated privacy as a commercial obligation. The PPCDA treats it as a right. This shifts the baseline. Organizations aren't complying with a regulation — they're respecting a right. The practical effect is that exceptions to privacy protections get read narrowly, not broadly.

Replaces the regulator. The Office of the Privacy Commissioner loses private-sector enforcement. A new Digital Safety and Data Protection Commission takes over, with a designated Privacy and Consumer Data Commissioner leading PPCDA enforcement. The Commission also administers the Digital Safety Act — consolidating privacy and online safety under one body. This is a structural change with real consequences: the OPC's tradition of non-binding findings is gone. The Commission has binding order power.

Creates real penalties. Administrative monetary penalties up to $10 million or 3% of global revenue, whichever is greater. Fines up to $25 million or 5% of global revenue for indictable offences. PIPEDA's enforcement was complaints-driven and toothless. The PPCDA's enforcement is penalty-driven and has teeth.

Requires documented privacy management programs. Organizations must assign compliance responsibility, maintain a formal privacy management program, ensure service providers provide equivalent protection, and show the program to regulators on request. Under PIPEDA, organizations had flexibility to interpret broad principles. Under the PPCDA, compliance must be demonstrated, not merely asserted. Documentation is now central.

Introduces new individual rights. Right to disposal (deletion in certain circumstances). Right to data mobility (transferring personal information between organizations). Right to explanation of automated decisions with significant effects. These are GDPR-influenced rights that create operational obligations.

Heightened protections for children. Children's personal information is expressly recognized as particularly sensitive. Organizations face a higher standard. The Minister has publicly identified children's privacy as a priority area.

Automated decision system transparency. Organizations using AI or algorithmic tools for significant decisions must provide explanations on request. The PPCDA doesn't regulate AI directly — that's handled through privacy law rather than a standalone AI act (AIDA died with Bill C-27) — but the transparency requirement reaches AI systems through the privacy framework.

The Sovereignty Provisions

This is where Bill C-36 connects to the infrastructure sovereignty argument.

Cross-border transfer assessments. The PPCDA requires organizations to assess and mitigate privacy risks before sending personal information outside of Canada. This is a data sovereignty provision embedded in privacy law. It doesn't ban cross-border transfers — but it requires a documented privacy impact assessment before they happen.

Under PIPEDA, transferring data to a US cloud provider was a contractual decision. Under the PPCDA, it's a decision that requires a documented assessment of privacy risks. For an organization using AWS, Azure, or Google Cloud, that assessment has to address the CLOUD Act — because US-headquartered providers can be compelled to produce data regardless of where it's stored. The assessment has to acknowledge that risk and document mitigation.

For a community organization running its own infrastructure on Proxmox with Nextcloud, Matrix, and Keycloak, the cross-border transfer assessment is shorter: the data doesn't leave Canada because the servers are in the building. The risk assessment documents that the data stays in Canadian jurisdiction on hardware the community controls. The mitigation is structural, not contractual.

Service provider obligations. The PPCDA draws a clear distinction between organizations that control personal information and service providers that process it. Service providers are now subject to direct statutory obligations — security safeguards, breach reporting — not just contractual obligations imposed by the controlling organization.

If a service provider collects, uses, or discloses transferred personal information for a purpose other than what it was transferred for, it becomes fully subject to the PPCDA for that information. The bill creates direct legal accountability for service providers.

For community infrastructure, this cuts both ways:

  • If your community is the service provider — hosting Nextcloud for member organizations — you now have direct statutory obligations. But you already control the stack, so meeting them is an operational matter, not a procurement negotiation.
  • If your community uses a service provider — a hosted SaaS platform — you're accountable for ensuring that provider meets equivalent protection obligations. With a hyperscaler, that means auditing a corporation's compliance with terms you didn't write. With community-owned infrastructure, it means verifying your own configuration.

Legitimate interest exception requires documentation. The PPCDA allows organizations to use personal information without consent if their legitimate interest outweighs adverse effects on the individual. But using this exception requires a privacy impact assessment, documented analysis, and public disclosure. The flexibility exists, but it's conditional on documentation that regulators can inspect.

The Compliance Asymmetry

Here's the structural argument. Bill C-36 creates a set of obligations that are easier to meet when you own the infrastructure:

| Obligation | Rented (hyperscaler) | Owned (community infrastructure) | |---|---|---| | Privacy management program | Document vendor practices you can't audit | Document your own practices | | Cross-border transfer PIA | Assess CLOUD Act exposure, document vendor mitigation | Document that data stays in jurisdiction | | Service provider oversight | Audit a corporation's compliance | Verify your own configuration | | Breach response | Depend on vendor notification timeline | You know immediately — you run the system | | Automated decision transparency | Request explanation from vendor's AI | Your AI, your documentation | | Data mobility | Export from vendor's format, test compatibility | Your format, your export | | Right to disposal | Request deletion from vendor's systems, trust the process | Delete it — you control storage |

Every one of these obligations exists under the PPCDA regardless of your architecture. The question is whether you're documenting your own decisions or documenting a vendor's assurances. The former is compliance. The latter is dependency management dressed up as compliance.

The Third Attempt Problem

Bill C-36 is the third attempt to reform PIPEDA. Bill C-11 died in 2020. Bill C-27 died in January 2025. The federal election interrupted the last attempt. There is no guarantee C-36 passes — it was introduced in June, Parliament rose for summer, and it hasn't completed second reading.

But the direction is clear across three bills and two governments:

  1. Privacy as a fundamental right, not a commercial obligation
  2. Real enforcement with real penalties
  3. Documented, structured compliance — not flexible principles
  4. Cross-border transfer assessments — data sovereignty through privacy law
  5. Service provider obligations — direct statutory accountability
  6. Children's privacy as a heightened standard
  7. Automated decision transparency

Each attempt has gotten further. C-11 didn't have penalties. C-27 added AIDA but tangled privacy with AI regulation. C-36 is focused, coordinated with the digital safety and lawful access packages, and reflects two years of stakeholder feedback since C-27. The political appetite for reform hasn't diminished — if anything, the tariff tensions with the US and the geopolitical context have strengthened the sovereignty argument that underpins the bill.

If C-36 passes, the compliance landscape for Canadian organizations changes. If it doesn't, the next attempt will go further. The pattern is not toward less regulation. It's toward more specific, more enforceable, more sovereignty-oriented regulation.

What This Means for Communities

The Bill C-22 argument was: the government can compel access to your data, so own the infrastructure to control what's compellable.

The Bill C-36 argument is: the government will require you to document how you protect data, assess cross-border risks, and manage service providers — so own the infrastructure to make compliance verifiable.

Both arguments point the same direction. The surveillance bill makes sovereignty defensive. The privacy reform bill makes sovereignty operational. Together, they make the case that owning your infrastructure is not just a philosophical preference — it's the compliance path of least resistance.

For a fire hall running a shared file server: the cross-border transfer assessment is one paragraph. "Data is stored on-premises. No cross-border transfers occur."

For a community center hosting a Matrix homeserver: the service provider obligations are met by the operator, who is the community. No third-party audit required.

For a small business using Nextcloud on a Proxmox node in the back office: the privacy management program documents what the operator already controls. No vendor SOC 2 report to request. No DPA to negotiate. No CLOUD Act risk to assess.

The PPCDA is still a bill. It may change before enactment. But the trajectory across three attempts and five years is consistent, and the compliance obligations it creates are structurally easier to meet when the community owns the stack. That's the argument, and it's getting stronger every time Parliament tries again.


Sources: Government of Canada — Backgrounder: Bill C-36, BLG — Bill C-36 (PPCDA) and privacy: What businesses need to know, Miller Thomson — Bill C-36's PIPEDA to PPCDA Shift, Osler — Canada's 2026 privacy priorities