On this page
If your business collects customer names, emails, payment details, or health information — and nearly every business does — the rules you operate under are about to change. On June 15, 2026, the federal government introduced Bill C-36, which would repeal the private-sector half of PIPEDA (the privacy law that’s governed Canadian businesses for two decades) and replace it with a new law: the Protecting Privacy and Consumer Data Act, or PPCDA.
Status as of 5 July 2026: proposed, not law. Bill C-36 has only passed First Reading, with Second Reading expected in the fall after Parliament returns on September 21. But the direction is clear, the penalties are serious, and the smart move for a Northern Ontario business isn’t to wait — it’s to get your house in order while there’s runway.
Here’s the plain-English version of what’s coming and what to do about it.
What Bill C-36 actually changes
PIPEDA has always asked businesses to handle personal information responsibly, but it was light on specifics and lighter on enforcement. The PPCDA flips both. Three shifts matter most:
1. Privacy becomes something you have to document, not just do
The centrepiece of the PPCDA is a required Privacy Management Program. Every organization would need documented policies and procedures covering how it protects personal information, how it handles complaints and access requests, and how it trains staff — scaled to the amount and sensitivity of the data you hold. The bar moves from “we’re careful with customer data” to “show us your written program.” For most small businesses, that written program simply doesn’t exist yet.
2. A new regulator with real teeth
The PPCDA creates the Digital Safety and Data Protection Commission of Canada and a Privacy and Consumer Data Commissioner with powers PIPEDA’s watchdog never had: the ability to audit organizations, compel information, enter premises, issue binding compliance orders, and levy fines.
3. Fines that are meant to be felt — and the right to be sued
The proposed penalties are tiered. Administrative penalties can reach the greater of $10 million or 3% of a company’s gross global revenue, and serious, knowing violations can hit the greater of $25 million or 5%. Bill C-36 also introduces a private right of action — meaning individuals could sue your business directly for damages once a contravention is established, within a two-year window.
”But we’re a small business in Thunder Bay — does this even apply to us?”
Most likely, yes. Like PIPEDA before it, the PPCDA is written to cover organizations that handle personal information in the course of commercial activity — and as introduced, the bill does not carve out an exemption for small businesses. The eye-watering percentage-of-global-revenue fines are clearly aimed at large corporations, so no one should picture a $10-million bill landing on a local shop. But the obligations — the documented program, proper consent, breach reporting — apply broadly. A small business is far more likely to get caught out by “we never wrote any of this down” than by a headline-grabbing fine.
What your business should start doing now
You don’t need to panic, and you don’t need a law degree. You need to start turning good intentions into documented practice. A sensible starting checklist:
- Map your data. Write down what personal information you collect, why, where it lives, and who can access it. You can’t protect — or document — what you haven’t mapped.
- Start (or formalize) a Privacy Management Program. Even a simple written set of policies for data handling, complaints, access requests, and staff training puts you ahead of most small businesses.
- Review how you get consent. Look at your forms, sign-ups, and website — are you clearly telling people what you collect and why?
- Tighten your security and breach plan. Mandatory breach reporting means you need to be able to detect, contain, and report an incident — not discover it months later.
- Check anything automated. If you use tools that make automated decisions about customers, the PPCDA leans toward transparency and a right to a human review.
- Watch how the bill evolves. It’s still moving through Parliament and the details can change — but the core expectation of documented privacy compliance is not going away.
The businesses that will struggle when this becomes law are the ones that treated privacy as an afterthought. The ones that will be fine are the ones that used this runway — the months between now and the PPCDA taking effect — to get organized.
Not sure where your business stands on any of this? DVG Systems helps Northern Ontario businesses get their data mapped, their security tightened, and the practical side of privacy compliance documented — before a new law makes it mandatory. Book a free assessment and we’ll give you an honest read on where you are and what to prioritize.
This article is general information, not legal advice. For advice specific to your business and its obligations under Bill C-36 / the PPCDA, consult a qualified privacy lawyer.