With Bill C-36, Ottawa is overhauling privacy laws — and employers are being urged to prepare
Canada's federal government has introduced legislation that would fundamentally reshape how organizations collect, use and disclose personal information — and for federally regulated employers, the implications for day-to-day HR practice are substantial.
Bill C-36, introduced June 15, 2026, would enact the Protecting Privacy and Consumer Data Act (PPCDA), replacing the privacy provisions of the Personal Information Protection and Electronic Documents Act (PIPEDA) that have been on the books, largely unchanged, since 2000.
The gap is notable, according to Victoria McCorkindale, associate at Hicks Morley Hamilton Stewart Storie in Toronto.
"PIPEDA was created before AI existed and, frankly, 20 some odd years ago, before things were digitized. So, there's a pretty big shift in this proposed legislation in considering what organizations do collect and how that collection is done."
The implications for HR are notable when it comes to employee privacy, she says.
"If [their] policy was developed at the time of PIPEDA, I'm going to go ahead and assume that organizations are doing something quite different than they were 26 years ago. Even in the past couple years — it's a big difference.
“So, I would say getting ahead of that, putting those strategies in place before legislation is enacted, is the key piece and will make any transition significantly less onerous.”
‘Most significant change’ likely to pass
Kristine Pennington calls the proposed legislation “the most significant change to Canada's private sector privacy legislation in more than 20 years.”
And while it's the third attempt at this reform, the partner at McMillan in Toronto says it’s likely to pass.
"This time around, the federal government's linked it to their new AI strategy. So, they view it as not only part of protecting individuals in the era of AI but more so on the consumer privacy side — geared toward attracting investment and development in the area of AI."
Max Jarvie, partner at Davies Ward Phillips & Vineberg in Montreal, is also “fairly confident” that the bill will pass “in the relatively near future” because of the majority government.
A new regulator — and new teeth
The PPCDA wouldn't just update the rules. It would hand enforcement to an entirely new body.
Under the current framework, Canada's Office of the Privacy Commissioner operates largely as an ombudsman — it can investigate, demand information and make recommendations, but its powers to impose penalties are limited. That changes dramatically under Bill C-36.
The new regulator, the Digital Safety and Data Protection Commission of Canada, would have direct power to administer monetary penalties of up to the greater of $10 million or three per cent of global annual turnover. And for certain offences — including knowingly contravening breach notification requirements or obstruction — organizations could face criminal fines through a court process of up to the greater of $25 million or five per cent of global revenue.
"There is, in my view, going to be a shift for federally regulated employers from potentially viewing privacy as more of a compliance exercise to an area that poses some really significant potential risk for the business and, therefore, something that should be a strategic priority,” says Pennington.
The bill also introduces a more explicit test for whether personal information should be collected at all, according to McCorkindale, who flags the appropriate purposes provision as a meaningful departure from PIPEDA.
"It’s the idea that there's actually a stated set of factors that you need to consider — as opposed to just what would a reasonable person consider," she says. "That’s really the PIPEDA piece: ‘Is it done for a reasonable purpose?’ Now, there's case law out there as to what a reasonable purpose means, but I think setting out those factors in the legislation really hammers home that point for organizations as to 'Well, we might be able to do this, but should we, based on what we're seeing in those factors?'"
Federal, provincial considerations
The PPCDA, like PIPEDA before it, applies to federal works, undertakings or businesses — railways, banks, airlines, telecommunications companies and the like. Provincially regulated employers in most of Canada would remain outside its reach for employment-related matters.
Three provinces — Alberta, British Columbia and Quebec — have their own substantially similar legislation, and that carve-out would continue under the PPCDA.
For federally regulated employers, the good news on consent is that the existing framework largely carries over. Organizations can still collect, use and disclose employee personal information without consent, provided it's necessary to establish, manage or terminate the employment relationship — and provided they've notified employees in advance of how their information will be handled.
"The short story is that the exception to consent for employers that's currently in PIPEDA will continue to exist under the PPCDA," says Pennington.
Jarvie notes the language in the bill is essentially verbatim from the existing legislation when it comes to consent and employee information: "The same logic and interpretation would apply even after the coming into force of the PPCDA,” he says, highlighting the need for notice to be provided.
For job candidates, though, Jarvie recommends a more cautious approach.
"We've always taken the position that where the federal works undertakings or business are concerned, it's prudent practice to have a specific privacy policy that's directed at candidates and to get their consent to the privacy policy in the context of their application.”
Automated decision system provisions
If there is one area where the PPCDA breaks genuinely new ground for HR, it's the treatment of automated decision systems. The bill defines them as "any technology that assists or replaces the judgment of human decision-makers through the use of a rules-based system, regression analysis, predictive analytics, machine learning, deep learning, a neural network or other technique."
Organizations that use these systems to make predictions, recommendations or decisions that could have a legal or similarly significant effect on an individual would be required to disclose that use, explain individual decisions on request, and give affected employees and candidates the ability to make written representations to a reviewer.
That last right — the ability to submit written representations — is new to Bill C-36 and wasn't in the earlier Bill C-27.
"There's a host of new transparency obligations, and those coupled with the administrative burden of answering those queries and providing that level of transparency might make some HR teams think twice before they're implementing automated decision systems," says Pennington. "But I recognize that a number of workplaces will still want to use these systems."
In the employment context, “whether or not someone is going to get a promotion or something that has some material effect on their bonus or a disciplinary matter, or for candidates, whether or not they advance in the interview process — all of these are significant decision points and would all come within the scope of this transparency obligation,” says Jarvie.
McCorkindale says that the explanation obligation will have real teeth.
"If an organization is doing that on the recruitment side, I think there needs to be an understanding for HR that whatever they're doing could end up publicized. So, be sure of what program they're using, how that program is assessing the information and just [have] those assurances."
Due diligence with AI tools
Practically, this means HR and procurement teams will need to do deeper diligence with AI tools, says Pennington.
"[It’s about] training to ensure that they're doing appropriate diligence on these systems or their capabilities before they're onboarded and implemented," she says. "By diligence, I mean really understanding how the system will make a prediction or recommendation or decision — not only to ensure that the decision complies with the PPCDA, but because the organization will need to understand that in order to appropriately respond to inquiries from employees and job applicants about the system."
If an employer using AI or a third party, they need to know what that information is being collected and the definition of “personal,” says McCorkindale, “because I think sometimes that can be misunderstood."
Cross-border data flows
Jarvie calls the cross-border data transfer requirements "perhaps the most consequential change" for employers. Under the PPCDA, organizations that transfer personal information outside Canada must first conduct a privacy impact assessment (PIA) and implement measures to mitigate identified risks. This obligation applies to transfers to service providers, affiliates and parent companies alike.
This would apply to payroll systems and employee management platforms provided by vendors that process data outside Canada or are headquartered in other jurisdictions, according to Jarvie.
"The question is ‘Where is that information going and is that information going to be protected in that recipient jurisdiction… in a way that's adequate for Canadian privacy law standards?’" he says. "The concern here, of course, is how to do this assessment and first understand where the information is going… which countries and whose hands it's going to be in?
“And then assessing for risk against, for example, a jurisdiction where perhaps there are not privacy laws of general application that protect people’s information as a general proposition or where the rule of law may be weaker than it is in Canada, or where there might be national security laws that are much more intrusive."
Pennington notes that when Quebec introduced similar cross-border PIA requirements a few years ago, many organizations turned to internal checklists and templates to manage the administrative burden.
“I expect that we'll see some federally regulated employers follow suit and want to develop internal PIA compliance tools if this requirement passes.”
The right to request disposal
The PPCDA also introduces a meaningful right for individuals to request that organizations dispose of their personal information in certain circumstances — including where consent has been withdrawn, where the information was collected in contravention of the Act, or where it's no longer necessary for the provision of a requested product or service.
"The main administrative burden here is just understanding where the data is located so that you can fulfill the request to the extent possible," says Jarvie.
He notes the obligation intersects with other statutory requirements — occupational health and safety legislation, for instance, may require records related to workplace incidents to be retained for up to 10 years regardless of a privacy request.
McCorkindale ties it back to a broader theme.
"In order to appropriately dispose of information, you have to know what information you're actually collecting and you have to know where it's stored," she says. "It really does all get tied together, in that sense."
How to prepare now
All three lawyers converge on a single starting point: know what data you have, why you have it, and where it goes.
"The main thing that HR should be doing at this point… would be undertaking some kind of data mapping," says Jarvie. "Essentially, to map within the organization where information is flowing — into what systems, into what vendor systems — and, to the extent possible, to understand when it's crossing an international border."
For larger organizations with many legacy systems and federated systems and business units that might be operating somewhat independently or affiliate, the data mapping exercise alone is a significant undertaking, he says: “It can be quite a big lift to get started.”
Pennington says that many of the PPCDA's requirements either mirror or build on existing PIPEDA language or on guidance Canada's privacy regulators have already issued. So, HR teams can work with privacy professionals now to identify which provisions they should already be treating as best practice.
"Organizations are going to have to make a number of decisions: ‘Who is going to receive these requests? Will they be dealt with directly by HR, or when should they be escalated to someone like the organization's privacy officer?"
Employers that are using a lot of automated decision systems might also consider developing template explanations about these decisions and predictions to make sure that they have all of the necessary content and they're in plain language, says Pennington, “and also so that they're in a better position to be able to provide those explanations to an individual within the response timelines."