GS Arora

04

Nov

The Privacy Gap: Why Canada's Shifting Federal Privacy Law Still Means Real Risk for Your Small Business in 2026

Introduction: A New Bill, an Old Lesson

For several years, Canadian businesses braced for a new federal law to replace our aging privacy legislation, PIPEDA. That law was Bill C-27, and it promised sweeping reform — massive fines, new consumer rights, and dedicated AI regulation. In early 2025, it died on the order paper when Parliament prorogued and a federal election followed.

The story isn’t finished. On June 15, 2026, the federal government introduced Bill C-36, the Protecting Privacy and Consumer Data Act (PPCDA) — the third attempt in six years to overhaul federal private-sector privacy law, following Bill C-11 in 2020 and the now-dead Bill C-27 in 2022. It is not law yet, and it may not become law — but it signals that federal reform is genuinely back on the table, even as Quebec’s Law 25 continues to set the practical standard businesses are already being held to today.

For a small business owner, none of this uncertainty is a reprieve. It is the opposite. Whether or not Bill C-36 eventually passes, you are operating in a complex, fragmented privacy landscape where customer expectations are high and the cost of a single breach — in fines and reputation — can be serious.

If you collect any customer data — names, emails, phone numbers, purchase history — this guide explains the real state of privacy and cybersecurity compliance in Canada right now.

Part 1: The Current De Facto Standard — Quebec’s Law 25

While federal reform has repeatedly stalled, Quebec did not wait. Quebec’s Law 25 (formerly Bill 64) is fully in force and remains the toughest privacy law in Canada.

“But I’m not in Quebec,” you might say. “My business is in Brampton.”

Does your website receive traffic from Quebec? Do you have customers, clients, or even just email newsletter subscribers who live in Quebec? If the answer is yes, you are very likely subject to Law 25 and its significant penalties.

Key Requirements Under Law 25

  • Mandatory privacy impact assessments: required before certain new projects involving personal information, particularly those involving new technology or sensitive data
  • Explicit, granular consent: consent must be clear, specific, and freely given — not bundled into a single “I agree” checkbox covering unrelated purposes
  • A designated privacy officer: every organization must formally designate a person responsible for privacy compliance, by default the most senior person in the organization unless someone else is named
  • Mandatory breach notification: organizations must notify the Commission d’accès à l’information (CAI) and affected individuals when a breach creates a real risk of serious harm
  • The right to data portability: individuals can request their personal information be transferred to them or to another organization in a structured format
  • Severe penalties: administrative monetary penalties reaching up to $25 million or 4% of global annual revenue, whichever is greater — a figure large enough to threaten a small business’s viability outright

Because it remains the strictest standard in the country, Law 25 has become the practical benchmark that most Canadian businesses should aim for, regardless of where they’re headquartered. Notably, the core principles proposed in the now-dead Bill C-27, and largely carried forward into the new Bill C-36, closely mirror Law 25’s approach — reinforcing that this is the clear direction Canadian privacy law is heading, federally or not.

Part 2: Why Bill C-36 Matters, Even Though It Isn’t Law Yet

Bill C-36 proposes replacing PIPEDA’s privacy provisions with the Protecting Privacy and Consumer Data Act (PPCDA), overseen by a newly created regulator, the Digital Safety and Data Protection Commission of Canada. If enacted, it would introduce a more prescriptive, documentation-heavy compliance model — mandatory privacy management programs, formal legitimate-interest assessments, and substantially larger enforcement powers than PIPEDA currently provides.

The practical reality for your business today: PIPEDA remains the operative federal law, unchanged, while Bill C-36 works through Parliament. Given that its two predecessors both died before passage, there is genuine uncertainty about whether C-36 will become law, and if so, in what final form. The sensible approach is not to wait and see — it’s to build your privacy practices toward the Law 25 standard now, since that standard already applies to any business with Quebec customers and closely resembles where federal law appears headed regardless of which specific bill eventually passes.

Part 3: Why Your Old Cybersecurity Isn’t Good Enough

Privacy law and cybersecurity are two sides of the same coin. Your privacy policy is the promise you make to customers. Your cybersecurity is how you actually keep that promise.

All Canadian privacy laws — PIPEDA, which remains fully in force, and Quebec’s Law 25 alike — contain a core safeguarding principle: you are legally required to protect the personal information you hold with security measures “appropriate to the sensitivity of the information.”

In 2026, cyber threats targeting small businesses continue to grow more sophisticated, and small businesses remain a primary target precisely because attackers assume — often correctly — that their defences are weaker than a large enterprise’s. This means your safeguarding obligation carries a genuinely higher practical bar than it did even a few years ago. “Appropriate” cybersecurity in 2026 is no longer simply having antivirus software installed. It generally means:

  • Multi-factor authentication (MFA) enabled on every system that stores or accesses customer data
  • Encryption at rest and in transit for any database containing personal information
  • Regular, tested backups stored separately from your primary systems, so a ransomware event doesn’t destroy your only copy of customer data
  • Documented access controls, limiting which employees can view or export sensitive customer information based on genuine business need
  • A written incident response plan, so your team knows exactly what to do — and who to notify, and by when — in the first hours after a suspected breach

A data breach exposing customer emails and purchase history, later traced to a failure to enable MFA, is a straightforward violation of your legal duty to safeguard that data — under PIPEDA today, and under Law 25 if any Quebec residents are affected.

Part 4: A 4-Step Action Plan for Brampton Small Businesses

Federal law may still be in transition, but your responsibility is not waiting for it to resolve. Here is a practical plan to protect your business and your customers in 2026.

Step 1: Know Your Data — Complete a Data Map

You cannot protect what you don’t know you have. Document, in a simple spreadsheet:

  • What categories of personal information you collect (names, emails, payment details, purchase history, browsing behaviour)
  • Where each category is stored (your CRM, your e-commerce platform, spreadsheets, email inboxes)
  • Who inside your business has access to each category, and why
  • Which third parties (payment processors, marketing platforms, shipping providers) you share any of it with

Step 2: Create a Formal Privacy Management Program

This is the single most important lesson carried forward from both Law 25 and the now-dead Bill C-27 — and it’s the model Bill C-36 would likely make mandatory federally if enacted. A genuine program includes:

  • A written privacy policy that accurately reflects your actual data practices, not a generic downloaded template
  • A named individual responsible for privacy compliance within your organization
  • A documented process for handling customer access, correction, and deletion requests
  • A written breach response procedure, prepared before you need it, not improvised during an actual incident

Step 3: Revamp Your Consent Process

Stop hiding consent inside dense fine print. Move to an active, opt-in model:

  • Separate consent checkboxes for genuinely distinct purposes (marketing emails vs. account communications, for example) rather than one blanket checkbox covering everything
  • Plain-language explanations of what you’re collecting and why, presented at the point of collection rather than buried in a linked policy
  • An easy, clearly signposted way for customers to withdraw consent at any time

Step 4: Implement Reasonable Cybersecurity — Starting This Week

Begin with the fundamentals rather than waiting for a comprehensive overhaul:

  • Enable multi-factor authentication on every account with access to customer data
  • Confirm your backups are actually running, tested, and stored separately from your live systems
  • Restrict data access to only the employees who genuinely need it for their role

Conclusion: The Future of Privacy Is Arriving, Whether or Not the Law Keeps Pace

Don’t let the ongoing uncertainty around federal legislation lull your business into a false sense of security. Customer expectations, the enforcement power of provincial regulators like Quebec’s CAI, and the persistent risk from cybercriminals have already created a higher practical standard than PIPEDA alone requires — and Bill C-36 signals that federal law is trying to catch up to that reality, even if it takes another attempt or two to get there.

By treating customer data with the seriousness it deserves now, you’re not just positioning your business for whatever law eventually passes — you’re building your single greatest asset: genuine customer trust. A Brampton small business that can demonstrably show it takes privacy seriously holds a real competitive advantage over those still waiting for a law to force their hand.

If you need help building a privacy program that meets today’s Law 25 standard, or want your practices reviewed against where federal law appears to be heading, contact GS Arora Law to speak with our business law team.

Disclaimer: The information provided in this blog is for general informational purposes only and should not be considered legal, tax, financial, or professional advice. Bill C-36 was introduced in Parliament on June 15, 2026, and had not received Royal Assent as of publication; it may be amended or may not become law. Regulations and procedures may change over time and vary by jurisdiction. For guidance tailored to your specific situation, please consult a qualified professional.

GS Arora
🔑

Free Consultation

Get expert legal guidance tailored to your needs

+1
✓ 100% Confidential
✓ No Hidden Fees
✓ Quick Response